Last updated: 18 July 2026
Download a signable copy: PDF · DOCX — complete your company details and signature and return it to [email protected] for countersignature.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — VAT IT15237911001, REA RM-1576999 ("Processor", "we", "us") — and the customer that uses FillWright ("Controller", "you"). It applies whenever we process personal data on your behalf in providing the service (the "Lead Data" — the data you upload and submit through FillWright). It gives effect to Article 28 GDPR and, as applicable, the UK GDPR, and includes a CCPA/CPRA service-provider addendum. On data-protection matters this DPA prevails over the Terms. A countersigned copy is available on request at [email protected].
"Applicable Data Protection Law" means the EU GDPR, the UK GDPR, and any other privacy law applicable to the processing, including the CCPA/CPRA. "Controller", "Processor", "Processing", "Personal Data", "Data Subject", and "Personal Data Breach" have the meanings in the GDPR. "Sub-processor" means any processor engaged by us to process Lead Data. "SCCs" means the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum. Details of the processing are in Annex 1; our security measures in Annex 2; our sub-processors in Annex 3.
For the Lead Data you are the Controller (or a processor acting for a third-party controller) and we are the Processor. We process Lead Data only to provide the service and only on your documented instructions. Your instructions are set out in the Terms, this DPA, and your configuration of the service (recipes, runs, and targets). We will inform you if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law.
We keep Lead Data confidential and grant access only to personnel who need it to provide the service and who are subject to binding confidentiality obligations.
You grant general written authorisation for us to engage the Sub-processors listed in Annex 3. We impose data-protection obligations on each Sub-processor that are no less protective than this DPA and remain fully liable for their performance. We will give you at least 30 days' notice of any intended addition or replacement of a Sub-processor; you may object on reasonable data-protection grounds within that period, and if we cannot address your objection you may terminate the affected part of the service.
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures — and the self-service tools in the application — to fulfil your obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If a Data Subject contacts us directly regarding your Lead Data, we will refer them to you and will not respond to the substance without your instruction.
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Lead Data, and provide the information reasonably available to help you meet your notification obligations (Art. 33–34), including the nature of the breach, likely consequences, and measures taken or proposed.
We provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority, to the extent they relate to our processing of Lead Data and taking into account the information available to us.
Lead Data is hosted in the European Union (Germany). Where we or a Sub-processor transfers Lead Data to a country outside the EEA or the UK that is not covered by an adequacy decision, the SCCs apply and are incorporated into this DPA by reference — the EU SCCs (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable) and, for UK data, the UK International Data Transfer Addendum. You instruct and authorise these transfers for the purpose of providing the service.
You may delete Lead Data (and everything derived from it) at any time from your dashboard. On termination of the service, at your choice we return or delete the Lead Data and existing copies within 30 days, and residual copies in encrypted backups are overwritten within 30 days, unless retention is required by law.
We make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits take place no more than once every 12 months (or following a Personal Data Breach or where required by a supervisory authority), on at least 30 days' written notice, during business hours, subject to confidentiality, and without unreasonably disrupting our operations. We may satisfy an audit request by providing relevant third-party audit reports or certifications where available.
For Lead Data relating to California residents, we act as your "service provider". We process such data solely to perform the service and on your instructions, and we do not: (a) sell or share it; (b) retain, use, or disclose it for any purpose other than performing the service or as permitted by the CCPA; (c) retain, use, or disclose it outside our direct business relationship with you; or (d) combine it with personal information from other sources except as the CCPA permits. We certify that we understand and will comply with these restrictions.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
This DPA takes effect when you accept the Terms and continues for as long as we process Lead Data on your behalf. Provisions that by their nature should survive (including confidentiality, deletion, and audit) survive termination.
This DPA is governed by Italian law, with the courts of Rome having jurisdiction, consistent with the Terms. In case of conflict: the SCCs prevail over this DPA on matters of international transfer; this DPA prevails over the rest of the Terms on data-protection matters.
Redbit S.r.l.s., Viale della Grande Muraglia 494, 00144 Roma, Italy — [email protected].