Data Processing Agreement
Last updated: 6 August 2026
1. Scope
This Data Processing Agreement ("DPA") is entered into between Giacomo Cornacchia ("Provider"), an individual entrepreneur (ditta individuale) operating under an Italian VAT number (Partita IVA), VAT number IT04199790926, and any business customer ("Customer") that uses Lavuràand whose personal data the Provider processes on the Customer's behalf. It supplements the Terms and Conditions and implements Article 28 of Regulation (EU) 2016/679 (GDPR).
In the standard consumer scenario, the Provider acts as data controller of end-user data, as described in the Privacy Policy. Where the Customer is itself a controller and the Provider processes data on the Customer's instructions (e.g. company accounts), this DPA applies.
2. Subject Matter, Nature and Purpose
- Subject matter: hosting, processing and storage of Customer personal data strictly required to operate the Service (account data, professional profile data, generated documents, usage logs).
- Duration: for the term of the subscription, plus deletion within 30 days of termination, except for data subject to legal retention obligations.
- Nature and purpose: technical processing operations (storage, retrieval, transmission, erasure) performed solely to deliver the Service.
- Categories of data subjects: Customer's employees or end users registered on the Service.
- Categories of personal data: identifiers, professional data, technical logs; special-category data only if voluntarily uploaded by the data subject (CV content).
3. Provider Obligations
The Provider shall:
- process personal data only on documented instructions from the Customer (including regarding international transfers), unless required by EU or Member State law;
- ensure that persons authorised to process the data are bound by confidentiality obligations;
- implement the technical and organisational measures in Section 6;
- respect the conditions for engaging sub-processors in Section 4;
- assist the Customer, taking into account the nature of the processing, in responding to data subject rights requests (Arts. 12–22 GDPR) and in meeting security, breach-notification (Arts. 32–34) and DPIA obligations (Arts. 35–36);
- notify the Customer without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer data;
- at the Customer's choice, delete or return all personal data after the end of the provision of services, subject to legal retention obligations;
- make available all information necessary to demonstrate compliance and allow for audits, conducted reasonably, on notice, and without undue disruption.
4. Sub-processors
The Customer grants general written authorisation to use the sub-processors listed in Section 7. The Provider will inform the Customer of intended additions or replacements at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Each sub-processor is bound by data protection obligations equivalent to this DPA.
5. International Transfers
Any transfer of personal data to a country outside the European Economic Area is made under Chapter V GDPR: certification under the EU–US Data Privacy Framework where applicable, otherwise Standard Contractual Clauses adopted by the European Commission, supplemented by appropriate technical measures (TLS in transit, encryption at rest). Copies of the applicable transfer mechanism are available on request at privacy@lavura.co.uk.
6. Technical and Organisational Measures
- encryption of data in transit (TLS 1.2+) and at rest;
- AES-256-GCM encryption of stored third-party portal credentials with a server-side master key separated from the data;
- password hashing with salted, one-way functions;
- role-based access control and least-privilege access to production systems;
- logging of access and configuration changes;
- automated backups and restore testing;
- rate limiting, CSRF protection and dependency security review;
- incident-response procedure with 72-hour supervisory-authority notification.
7. Current Sub-processors
| Sub-processor | Purpose | Location / safeguards |
|---|---|---|
| Vercel Inc. | Application hosting, serverless functions, object storage (Vercel Blob) | United States (IAD1 region), GDPR-compliant DPA, SCCs |
| Stripe, Inc. | Payment processing and subscription billing | United States / Ireland, GDPR-compliant DPA, SCCs, DPF |
| Google LLC | AI cover-letter generation (Gemini API); Gmail integration when enabled by the user | United States, GDPR-compliant terms, SCCs, DPF |
| Managed PostgreSQL provider | Primary database | As configured for the deployment; GDPR-compliant DPA, SCCs where applicable |
| Managed Redis provider | Background job queue (BullMQ) | As configured for the deployment; GDPR-compliant DPA, SCCs where applicable |
| Apify Technologies s.r.o. | Aggregation of public job postings from job portals | European Union (Czech Republic), EU-based processing |
| Adzuna Ltd | Public job-posting data via official API | United Kingdom; UK GDPR and SCCs |
| SMTP email provider | Transactional emails (verification, password reset, notifications) | As configured; GDPR-compliant DPA where applicable |
"DPF" = EU–US Data Privacy Framework; "SCCs" = Standard Contractual Clauses. The Provider will keep this list current.
8. Liability and Governing Law
Each party's liability under this DPA is governed by the Terms and Conditions and applicable law. This DPA is governed by Italian law in line with the Terms. In the event of conflict between this DPA and the Terms regarding personal data protection, this DPA prevails.
9. Contact
Data protection questions: privacy@lavura.co.uk. General questions: support@lavura.co.uk.