← FillWright

Data Processing Agreement

Last updated: 18 July 2026

Download a signable copy: PDF · DOCX — complete your company details and signature and return it to [email protected] for countersignature.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — VAT IT15237911001, REA RM-1576999 ("Processor", "we", "us") — and the customer that uses FillWright ("Controller", "you"). It applies whenever we process personal data on your behalf in providing the service (the "Lead Data" — the data you upload and submit through FillWright). It gives effect to Article 28 GDPR and, as applicable, the UK GDPR, and includes a CCPA/CPRA service-provider addendum. On data-protection matters this DPA prevails over the Terms. A countersigned copy is available on request at [email protected].

1. Definitions

"Applicable Data Protection Law" means the EU GDPR, the UK GDPR, and any other privacy law applicable to the processing, including the CCPA/CPRA. "Controller", "Processor", "Processing", "Personal Data", "Data Subject", and "Personal Data Breach" have the meanings in the GDPR. "Sub-processor" means any processor engaged by us to process Lead Data. "SCCs" means the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum. Details of the processing are in Annex 1; our security measures in Annex 2; our sub-processors in Annex 3.

2. Roles & scope

For the Lead Data you are the Controller (or a processor acting for a third-party controller) and we are the Processor. We process Lead Data only to provide the service and only on your documented instructions. Your instructions are set out in the Terms, this DPA, and your configuration of the service (recipes, runs, and targets). We will inform you if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law.

3. Processor obligations (Art. 28(3))

  • (a) process Lead Data only on your documented instructions, including for transfers, unless required by law (in which case we inform you first, unless the law prohibits it);
  • (b) ensure persons authorised to process Lead Data are bound by confidentiality;
  • (c) implement the technical and organisational security measures in Annex 2 (Art. 32);
  • (d) engage Sub-processors only under Section 5;
  • (e) assist you, by appropriate measures, to respond to Data Subject requests (Section 6);
  • (f) assist you with security, breach notification, data protection impact assessments, and prior consultation (Art. 32–36), taking into account the nature of processing and the information available to us;
  • (g) delete or return Lead Data at the end of the service (Section 10);
  • (h) make available the information necessary to demonstrate compliance and allow for audits (Section 11).

4. Confidentiality

We keep Lead Data confidential and grant access only to personnel who need it to provide the service and who are subject to binding confidentiality obligations.

5. Sub-processors

You grant general written authorisation for us to engage the Sub-processors listed in Annex 3. We impose data-protection obligations on each Sub-processor that are no less protective than this DPA and remain fully liable for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a Sub-processor; you may object on reasonable data-protection grounds within that period, and if we cannot address your objection you may terminate the affected part of the service.

6. Data-subject rights

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures — and the self-service tools in the application — to fulfil your obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If a Data Subject contacts us directly regarding your Lead Data, we will refer them to you and will not respond to the substance without your instruction.

7. Personal data breach

We notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Lead Data, and provide the information reasonably available to help you meet your notification obligations (Art. 33–34), including the nature of the breach, likely consequences, and measures taken or proposed.

8. Impact assessments

We provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority, to the extent they relate to our processing of Lead Data and taking into account the information available to us.

9. International transfers

Lead Data is hosted in the European Union (Germany). Where we or a Sub-processor transfers Lead Data to a country outside the EEA or the UK that is not covered by an adequacy decision, the SCCs apply and are incorporated into this DPA by reference — the EU SCCs (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable) and, for UK data, the UK International Data Transfer Addendum. You instruct and authorise these transfers for the purpose of providing the service.

10. Deletion & return

You may delete Lead Data (and everything derived from it) at any time from your dashboard. On termination of the service, at your choice we return or delete the Lead Data and existing copies within 30 days, and residual copies in encrypted backups are overwritten within 30 days, unless retention is required by law.

11. Audits & information

We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place no more than once every 12 months (or following a Personal Data Breach or where required by a supervisory authority), on at least 30 days' written notice, during business hours, subject to confidentiality, and without unreasonably disrupting our operations. We may satisfy an audit request by providing relevant third-party audit reports or certifications where available.

12. CCPA / CPRA addendum (service provider)

For Lead Data relating to California residents, we act as your "service provider". We process such data solely to perform the service and on your instructions, and we do not: (a) sell or share it; (b) retain, use, or disclose it for any purpose other than performing the service or as permitted by the CCPA; (c) retain, use, or disclose it outside our direct business relationship with you; or (d) combine it with personal information from other sources except as the CCPA permits. We certify that we understand and will comply with these restrictions.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.

14. Term

This DPA takes effect when you accept the Terms and continues for as long as we process Lead Data on your behalf. Provisions that by their nature should survive (including confidentiality, deletion, and audit) survive termination.

15. Governing law & order of precedence

This DPA is governed by Italian law, with the courts of Rome having jurisdiction, consistent with the Terms. In case of conflict: the SCCs prevail over this DPA on matters of international transfer; this DPA prevails over the rest of the Terms on data-protection matters.

Annex 1 — Details of the processing

  • Subject matter: provision of FillWright (authorized data entry on your behalf).
  • Duration: the term of your account and until deletion of the Lead Data.
  • Nature & purpose: storage and structuring of the Lead Data and its automated submission to the web forms (Targets) you configure, including optional AI-assisted suggestion of field mappings.
  • Categories of data subjects: as determined by you — for example your leads, applicants, customers, or contacts.
  • Types of personal data: as determined by you and contained in the CSV you upload (for example names and contact details, and any fields you include). You must not upload special-category data unless you have a lawful basis and instruct us accordingly.

Annex 2 — Technical & organisational measures (Art. 32)

  • Encryption in transit (TLS); credentials hashed with Argon2id.
  • Mandatory two-factor authentication for financial actions; login lockout; rate limiting.
  • Strict per-target authorization; SSRF protection on outbound requests; honeypots respected and never filled.
  • Role-based access controls and least privilege; audit logging; environment segregation.
  • Hosting in the EU (Germany); encrypted backups overwritten within 30 days.
  • Breach detection and response procedures; secure development practices.

Annex 3 — Sub-processors

  • Revolut (Revolut Bank UAB) — payment processing — European Union (Lithuania) — intra-EEA, no transfer.
  • Anthropic — optional AI assistance for form-field mapping only — United States — SCCs.
  • LangChain (LangSmith) — LLM observability (token/cost/latency only; prompt and response content redacted and not sent) — EU region.
  • Smartproxy / Decodo — regional network egress, only when you enable it for an authorized target — varies by selected region — SCCs where applicable.
  • IONOS — hosting infrastructure — European Union (Germany).
  • Redbit self-managed email system (mail.redbitapp.com) — transactional email — European Union.

Contact

Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — [email protected].