The version applicable to your relationship is the one presented and accepted during registration or the applicable activation process. You can save this page using your browser’s Print function.
1. Parties and scope
Giampaolo Rao, Via Carpinetana Ovest 18, 00037 Segni (RM), Italy; tax code RAOGPL76L15C858V; info@omniagents.it (“Provider”). The Customer identified in the order entrusts the Provider only with processing actually carried out on its behalf. This DPA supplements the Business terms and prevails on data-protection matters. The Customer is controller; if acting for another controller, it must be authorised to appoint the Provider as subprocessor. For its own commercial, tax and security obligations, the Provider acts as controller under the privacy notice.
2. Subject, duration and purposes
The engagement covers the agreed functions of the Business environment: connecting devices and authorised channels, transit of permitted data, generic notifications, support and any managed operations expressly identified in the order. It lasts for the relationship and the time needed to return or delete entrusted data. Local software may acquire, organise, search, process and export content on Customer instructions; this does not establish that the Provider receives or stores it. Resale of content, advertising and general model training by the Provider are excluded.
The Business environment belongs to the individual organisation and its authorised users. Software operates on Mac and Windows and may connect the iPhone and Android apps. Presets, roles and APIs do not by themselves extend Provider instructions or access to data.
Relay service status. The currently published relay transits permitted flows and does not provide a persistent Meta-content queue for retrieval while the computer is offline. The offline queue approved for a subsequent release is not active in the published service. Recovery of every event received offline is not guaranteed. Any activation will require an updated description of processing, limits and retention before it begins.
3. Data and data subjects
Depending on enabled functions: user, role, organisation and device identifiers; contact details; technical notification tokens; access and delivery metadata; permitted Meta content in transit and content voluntarily sent to support. Data subjects may include Customer users, personnel, customers, suppliers and correspondents. Content from Google sources is not authorised to transit through the relay. Special-category, criminal-offence and children’s data require assessment and specific instructions before being entrusted to the Provider. The environment inventory identifies actual categories and sources.
4. Instructions and confidentiality
The Provider acts on documented Customer instructions, including authorised configuration, support requests and transfer instructions. If law requires different processing, it informs the Customer where permitted. It flags instructions it considers inconsistent with applicable rules and suspends the affected operation pending clarification. Access is limited to authorised persons bound by confidentiality. The Customer ensures lawful sources, notices, user authorisations and instructions.
5. Security measures
Measures are proportionate to risk and described in the environment’s technical annex with their actual status and limitations: access and permission controls, transport protection, credential protection, minimisation, updates and incident handling. Device encryption, backups, restoration and availability also depend on Customer configuration and are not presumed to be managed by the Provider. No completed audit, certification, encrypted offline Meta queue, already-completed deletion or unverified SLA is claimed. The Security document also applies.
6. Providers involved
The provider register distinguishes roles and services. Cloudflare supports the relay and its technical data; Google Firebase delivers generic push alerts, involving Apple APNs on iPhone; Aruba handles service and support email; Sites by OpenAI on Cloudflare hosts the website and telemetry described in the privacy notice. Only services actually processing data on the Customer’s behalf fall within the engagement. Before processing begins, the annex identifies the contracting entity, countries/regions, categories and applicable safeguards. A Google, Meta or AI account chosen by the Customer does not automatically become our subprocessor.
7. Authorisation and transfers
The Customer authorises subprocessors named in the applicable annex. Additions or replacements are notified at least 30 days in advance with sufficient information for a substantiated data-protection objection. The parties assess a solution; if no suitable solution is available, they arrange termination of the affected function and return or deletion of data. The Provider imposes obligations consistent with this DPA and remains responsible as required by law. Transfers outside the EEA require a valid basis and applicable assessments and measures; server location alone does not exclude third-country access.
8. Rights and cooperation
Taking account of processing and available information, the Provider assists the Customer with data-subject requests, impact assessments and necessary consultations. It forwards requests concerning entrusted data without deciding their substance unless instructed or legally required. The Customer identifies an authorised contact and provides timely instructions. Requests may be sent to info@omniagents.it without credentials or unnecessary content.
9. Personal data breaches
On becoming aware of a breach of entrusted personal data, the Provider informs the Customer without undue delay, supplying and updating available information: nature, known categories and affected subjects, likely consequences, measures taken or proposed and contact details. Initial notice does not await completion of an investigation. The Provider cooperates in containment and preserves relevant evidence. Notifications to authorities and individuals remain the responsibility of those required by law; no additional operational response time is promised unless agreed.
10. Return and deletion
At termination, at the Customer’s choice, the Provider returns or deletes entrusted data and copies under its control, except for legally required retention. Actual deadlines and copies are specified in the environment annex. Customer local copies, exports, external backups and provider-account data require separate actions. Local disconnection does not establish remote revocation. Relay associations and mobile tokens are removed according to the outcomes of the applicable procedures; technical records and received statistics follow their declared purposes and retention. The Provider confirms only actions actually completed under its control.
11. Information and audits
The Provider makes available information necessary to demonstrate compliance and allows relevant audits by the Customer or a confidentiality-bound representative. Arrangements protect systems and other customers’ data without preventing necessary or regulatory checks. Access to or testing of third-party systems requires the relevant authorisation. Documentary evidence does not replace further examination when needed.
12. Annexes and effectiveness
Before data is entrusted to the Provider, the order and annexes identify parties, contacts, enabled functions, data and subjects, duration, actual providers, countries, transfers, measures and return/deletion terms. Publishing this text does not by itself create a Business environment, appointment or acceptance. Earlier editions and receipts remain distinct. Reference: Articles 28 and 32 of the GDPR.
Legal sources: GDPR — Articles 6, 21, 28, 32 and 33.
For information: info@omniagents.it.