Data Processing Agreement
Data Processing Agreement (DPA)
This Data Processing Agreement is entered into pursuant to Article 28 of Regulation (EU) 2016/679 («GDPR») between the Customer (acting as Data Controller) and Oncode S.r.l. (acting as Data Processor) for the processing of personal data carried out via the Onwork platform.
- Version
- v1.0
- Effective
- 2026-04-25
Subject matter and duration
The Processor processes personal data on the Controller's behalf solely for the purpose of providing the Service under the Terms of Service. The duration of processing matches the duration of the Agreement, save for legal retention obligations.
Nature, purpose, types of data and categories of subjects
- Nature: hosting, storage, retrieval, consultation, structuring, transmission, deletion of personal data.
- Purpose: provision of the Onwork SaaS platform.
- Types of data: as set out in Annex 1 (typically identification, contact, employment, attendance, project, billing, technical/log data; geolocation if enabled by the Controller).
- Categories of subjects: employees, contractors, users, business contacts of the Controller.
Instructions of the Controller
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required by Union or Italian law to which the Processor is subject. The Processor shall inform the Controller of such legal requirements before processing, unless the law prohibits such information.
Confidentiality
The Processor ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Security measures (GDPR Art. 32)
The Processor implements technical and organisational measures to ensure a level of security appropriate to the risk, in line with Oncode S.r.l.'s ISO/IEC 27001 certification. Measures include encryption in transit and at rest, access controls, audit logging, backups and incident response. Annex 2 contains additional details.
Sub-processors
The Controller authorises the Processor to engage sub-processors listed at /sub-processors (Annex 3). The Processor will notify the Controller of intended additions or replacements of sub-processors at least 30 days in advance, providing the Controller with the opportunity to object.
The Processor shall impose on its sub-processors the same data protection obligations as set out in this DPA, by way of contract.
Assistance with data subject requests
Taking into account the nature of processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests for exercising data subject rights under Articles 15 to 22 GDPR.
Personal data breach notification
The Processor shall notify the Controller without undue delay, and in any case within 24 hours, after becoming aware of a personal data breach affecting the Controller's data. The notification shall include the information specified in Article 33(3) GDPR, to the extent available.
International transfers
Where the Processor transfers personal data outside the EEA, it shall ensure that adequate safeguards are in place under Chapter V GDPR (adequacy decisions, Standard Contractual Clauses 2021/914, Data Privacy Framework). Transfer Impact Assessments are conducted where necessary.
Audit rights
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. Audits are performed with reasonable advance notice and at the Controller's expense.
Return or deletion of data
Upon termination of the Agreement, the Processor will, at the Controller's choice, return or delete all personal data processed on behalf of the Controller, save for legal retention obligations.
Liability
Each party is liable for damages caused by its breach of the GDPR. The liability cap set out in the Terms of Service applies, without prejudice to mandatory provisions of law.
Governing law and jurisdiction
This DPA is governed by Italian law. The Court of Milan has exclusive jurisdiction over any dispute.
Annexes
- Annex 1 — Description of processing (categories of data, subjects, frequency, duration).
- Annex 2 — Technical and organisational measures.
- Annex 3 — List of sub-processors (see /sub-processors).
The full DPA, including Annexes 1–3 and signature page, is available as a signable PDF for download. For execution, contact [email protected].