Data Processing Addendum (DPA)
Effective date: 29 December 2025
Last updated: 29 December 2025
This Data Processing Addendum (“DPA”) forms part of the agreement between WebCreationSuite s.r.l. (“WCS”, “Processor”, “we”, “us”) and the customer entity accepting this DPA (“Customer”, “Controller”, “you”) (the “Agreement”), and applies to the extent WCS processes Personal Data on behalf of Customer in connection with WCS services.
If there is any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA will prevail.
1. Parties
Processor: WebCreationSuite s.r.l.
Registered office: [â—Ź]
VAT/Tax ID: [â—Ź]
PEC: [â—Ź]
Controller: The legal entity that signs or accepts the Agreement and this DPA.
Controller details are as provided by Customer in the account, order form, or other documentation.
Privacy contact / DPO (if applicable): Antonio Marin — privacy@webcreationsuite.com
2. Definitions
Capitalized terms not defined in this DPA have the meaning given in the Agreement. In this DPA:
- “Data Protection Laws” means applicable data protection and privacy laws and regulations, including (where applicable) the GDPR, UK GDPR, and relevant US state privacy laws.
- “GDPR” means Regulation (EU) 2016/679.
- “UK GDPR” means the GDPR as incorporated into UK law.
- “Personal Data” means any information processed by WCS on behalf of Customer that relates to an identified or identifiable natural person.
- “Processing”, “Controller”, “Processor”, “Supervisory Authority” have the meanings given under applicable Data Protection Laws.
- “Sub-processor” means any Processor engaged by WCS to process Personal Data on behalf of Customer.
3. Scope and Roles
3.1 Controller and Processor. Customer is the Controller of Personal Data processed within Customer’s use of the Services. WCS acts as Processor to Customer for such Processing.
3.2 WCS as Controller for its own purposes. WCS may process certain data as an independent Controller (e.g., account administration, billing, service security, fraud prevention, and marketing to Customer where permitted). This DPA does not apply to WCS’s Processing as an independent Controller.
3.3 Services covered. This DPA applies to WCS ecosystem services provided under the Agreement, including (as currently available) PrintFlow, Parcely, and basic features of myBusiness (business management, teams/users, calendar, chat, project management), plus any additional modules released later that involve Processing Customer Personal Data.
4. Details of Processing
The subject matter, duration, nature and purpose of Processing, categories of Personal Data, and categories of Data Subjects are described in Annex 1 (Details of Processing).
5. Processor Obligations
5.1 Documented instructions. WCS will process Personal Data only on documented instructions from Customer, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by applicable law. If WCS is required by law to process outside Customer’s instructions, WCS will inform Customer of that legal requirement unless prohibited by law.
5.2 Confidentiality. WCS will ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3 Security. WCS will implement appropriate technical and organizational measures to protect Personal Data as described in Annex 2 (Security Measures).
5.4 Data protection assistance. Taking into account the nature of Processing and the information available to WCS, WCS will provide reasonable assistance to Customer to:
- respond to Data Subject requests (access, deletion, etc.);
- conduct data protection impact assessments (DPIAs) and, where applicable, consultations with Supervisory Authorities.
5.5 Breach notification. WCS will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide available information reasonably necessary for Customer to meet its obligations under Data Protection Laws.
5.6 Deletion or return. Upon termination or expiration of the Agreement, and at Customer’s choice, WCS will return or delete Customer Personal Data, unless applicable law requires storage. Details and practical method are described in Annex 1 and/or the Agreement.
5.7 Audits and compliance information. WCS will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to Section 10 (Audit Terms).
6. Customer Obligations
Customer represents and warrants that:
- it has a valid legal basis to collect and provide Personal Data to WCS and to instruct WCS to process such Personal Data;
- it has provided any required notices and obtained any required consents from Data Subjects;
- its instructions to WCS comply with Data Protection Laws;
- it will not provide Special Categories of Data (sensitive data) or regulated data (e.g., health data, payment card data) to WCS unless explicitly agreed in writing and appropriate safeguards are implemented.
7. Sub-processors
7.1 Authorization. Customer grants WCS a general authorization to engage Sub-processors for the Processing of Customer Personal Data.
7.2 Sub-processor obligations. WCS will impose data protection obligations on Sub-processors that are no less protective than those in this DPA for the relevant Processing.
7.3 Changes and objections. WCS will maintain an up-to-date list of Sub-processors in Annex 3 and/or on a public page (if available). WCS will provide notice of material changes to Sub-processors. If Customer has reasonable grounds to object, Customer may object in writing; the parties will work in good faith to address the objection, including by providing an alternative solution where feasible. If no feasible solution exists, Customer may terminate the affected Services pursuant to the Agreement.
8. International Data Transfers
8.1 Hosting region. WCS intends to host primary service infrastructure in the EEA/Europe; however, Sub-processors may operate globally.
8.2 Transfer safeguards. Where a transfer of Personal Data to a country outside the EEA/UK requires a transfer mechanism under Data Protection Laws, the parties will rely on an appropriate mechanism (e.g., SCCs and/or the UK addendum/UK transfer mechanisms), as applicable.
9. Recordkeeping
Where required by Data Protection Laws, WCS will maintain records of Processing activities performed on behalf of Customer.
10. Audit Terms
10.1 Frequency. Customer may conduct an audit no more than once per 12-month period, unless (i) required by a Supervisory Authority, or (ii) following a confirmed Personal Data breach impacting Customer.
10.2 Scope and protections. Audits will be:
- limited to information relevant to the Processing of Customer Personal Data;
- conducted during normal business hours with reasonable advance notice (at least 30 days, unless urgent);
- subject to confidentiality obligations and restrictions to protect WCS security, other customers’ data, and trade secrets.
10.3 Costs. Customer bears its own audit costs. If an audit reveals material non-compliance by WCS, WCS will promptly remediate and (where appropriate) discuss reasonable cost allocation.
11. Liability
Liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by applicable law.
12. Term and Termination
This DPA remains in effect for the duration of the Agreement and for as long as WCS processes Customer Personal Data on behalf of Customer.
13. Order of Precedence
In the event of a conflict:
- this DPA governs Processing of Customer Personal Data;
- the Agreement governs all other terms.
14. Contact
Questions about this DPA: privacy@webcreationsuite.com
Annex 1 — Details of Processing
A. Subject matter
Provision of WCS services and related support, including hosting, storage, transmission, processing, display, and management of Customer content and operational data.
B. Duration
For the term of the Agreement, plus any retention period configured by Customer and/or required by applicable law, as described below.
C. Nature and purpose
WCS processes Customer Personal Data to:
- provide and operate the Services (including PrintFlow, Parcely, myBusiness modules);
- perform authentication and account management for Customer users;
- provide customer support and troubleshoot issues;
- ensure service security, prevent abuse, and maintain logs;
- enable integrations explicitly configured by Customer.
D. Categories of Data Subjects
- Customer end users (employees, contractors, team members)
- Customer’s contacts/clients (where Customer uploads such data)
- Website visitors interacting with Customer-controlled features (if any)
E. Types of Personal Data (typical)
Depending on Customer usage and configuration, Personal Data may include:
- Identity/contact data: name, email, phone (if provided), company, role
- Account/auth data: user ID, hashed credentials, authentication tokens
- Support/helpdesk data: ticket content, messages, attachments, metadata
- Chat/project data: messages, task titles/descriptions, project metadata, attachments
- PrintFlow/Parcely operational data: shipping/print job metadata, addresses (if uploaded), delivery notes, labels, attachments
- Technical data: IP address, device/user-agent, timestamps, logs, diagnostics
- Cookie/consent choices: "wcs_consent" status (if used)
F. Special Categories of Data
Not intended to be processed. Customer should avoid uploading special categories unless explicitly agreed in writing with additional safeguards.
G. Processing operations
Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, restriction, deletion, and destruction.
H. Retention and deletion/return
- Customer may request deletion/export as supported by the Services.
- Upon termination, WCS will delete or return Customer Personal Data within a commercially reasonable period, unless legal retention is required.
- Backups: data may persist in backups for a limited period, after which it is overwritten per WCS backup lifecycle.
Annex 2 — Security Measures (Technical & Organizational Measures)
WCS implements measures appropriate to the risk, which may include:
A. Organizational controls
- Access control policy (least privilege), role-based access where applicable
- Security awareness and confidentiality obligations for personnel
- Incident response procedures and escalation paths
- Vendor/Sub-processor review process
- Change management for production systems (where applicable)
B. Technical controls
- Encryption in transit (TLS) for service endpoints
- Encryption at rest for storage systems where supported by infrastructure
- Authentication controls (strong password policy, optional/where available MFA)
- Logging and monitoring of security-relevant events
- Network protection (firewalls/WAF/CDN protections where applicable)
- Segmentation between environments (e.g., prod vs staging) where applicable
- Backup and restore procedures with periodic verification (where applicable)
- Vulnerability management and patching practices
C. Physical security
- Physical security controls are primarily provided by WCS hosting providers and data center operators.
WCS may update these measures over time, provided the overall level of security is not materially reduced.
Annex 3 — Sub-processors (Indicative)
WCS may engage the following categories of Sub-processors. Exact details (entity name, purpose, and region) may be maintained on a Sub-processor list page and updated from time to time.
| Sub-processor | Purpose | Processing Location | |---|---|---| | Contabo | Cloud hosting / compute / storage | Europe (EEA) | | Cloudflare | CDN, WAF/security, performance | Global (configuration may route globally) | | bunny.net | CDN / performance | Global | | Qbox Mail | Transactional and marketing email delivery | [â—Ź] | | Amazon Web Services (optional) | Email and/or infrastructure components (e.g., SES) | [â—Ź] |
WCS will provide notice of material updates to Sub-processors as described in Section 7.
Annex 4 — US State Privacy Addendum (CCPA/CPRA – Service Provider / Contractor)
If and to the extent the California Consumer Privacy Act, as amended by the CPRA (“CCPA/CPRA”), applies and Customer is a “Business”, then for Personal Information processed on behalf of Customer:
-
Role. WCS acts as Customer’s Service Provider and/or Contractor (as applicable) for the limited business purpose of providing the Services under the Agreement.
-
No sale/share. WCS will not sell or share Personal Information processed on behalf of Customer.
-
Limited use. WCS will not retain, use, or disclose such Personal Information for any purpose other than performing the Services and related permitted business purposes specified in the Agreement, unless otherwise permitted by CCPA/CPRA.
-
No combination. WCS will not combine Personal Information processed on behalf of Customer with Personal Information received from another person/entity or collected from WCS’s interaction with consumers, except as permitted by CCPA/CPRA.
-
Assistance. Upon Customer’s reasonable request, WCS will assist Customer in responding to consumer requests to the extent applicable to WCS’s processing role.
-
Sub-processors. WCS will impose CCPA/CPRA-consistent restrictions on Sub-processors that process Personal Information on behalf of Customer.
This Annex applies only to the extent required by CCPA/CPRA and does not expand WCS’s obligations beyond what is required under applicable law.
Ultimo aggiornamento: 9/5/2026