← Back to home

Data Processing Agreement

Last updated: 6 August 2026

1. Scope

This Data Processing Agreement ("DPA") is entered into between Giacomo Cornacchia ("Provider"), an individual entrepreneur (ditta individuale) operating under an Italian VAT number (Partita IVA), VAT number IT04199790926, and any business customer ("Customer") that uses Lavuràand whose personal data the Provider processes on the Customer's behalf. It supplements the Terms and Conditions and implements Article 28 of Regulation (EU) 2016/679 (GDPR).

In the standard consumer scenario, the Provider acts as data controller of end-user data, as described in the Privacy Policy. Where the Customer is itself a controller and the Provider processes data on the Customer's instructions (e.g. company accounts), this DPA applies.

2. Subject Matter, Nature and Purpose

  • Subject matter: hosting, processing and storage of Customer personal data strictly required to operate the Service (account data, professional profile data, generated documents, usage logs).
  • Duration: for the term of the subscription, plus deletion within 30 days of termination, except for data subject to legal retention obligations.
  • Nature and purpose: technical processing operations (storage, retrieval, transmission, erasure) performed solely to deliver the Service.
  • Categories of data subjects: Customer's employees or end users registered on the Service.
  • Categories of personal data: identifiers, professional data, technical logs; special-category data only if voluntarily uploaded by the data subject (CV content).

3. Provider Obligations

The Provider shall:

  • process personal data only on documented instructions from the Customer (including regarding international transfers), unless required by EU or Member State law;
  • ensure that persons authorised to process the data are bound by confidentiality obligations;
  • implement the technical and organisational measures in Section 6;
  • respect the conditions for engaging sub-processors in Section 4;
  • assist the Customer, taking into account the nature of the processing, in responding to data subject rights requests (Arts. 12–22 GDPR) and in meeting security, breach-notification (Arts. 32–34) and DPIA obligations (Arts. 35–36);
  • notify the Customer without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer data;
  • at the Customer's choice, delete or return all personal data after the end of the provision of services, subject to legal retention obligations;
  • make available all information necessary to demonstrate compliance and allow for audits, conducted reasonably, on notice, and without undue disruption.

4. Sub-processors

The Customer grants general written authorisation to use the sub-processors listed in Section 7. The Provider will inform the Customer of intended additions or replacements at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. Each sub-processor is bound by data protection obligations equivalent to this DPA.

5. International Transfers

Any transfer of personal data to a country outside the European Economic Area is made under Chapter V GDPR: certification under the EU–US Data Privacy Framework where applicable, otherwise Standard Contractual Clauses adopted by the European Commission, supplemented by appropriate technical measures (TLS in transit, encryption at rest). Copies of the applicable transfer mechanism are available on request at privacy@lavura.co.uk.

6. Technical and Organisational Measures

  • encryption of data in transit (TLS 1.2+) and at rest;
  • AES-256-GCM encryption of stored third-party portal credentials with a server-side master key separated from the data;
  • password hashing with salted, one-way functions;
  • role-based access control and least-privilege access to production systems;
  • logging of access and configuration changes;
  • automated backups and restore testing;
  • rate limiting, CSRF protection and dependency security review;
  • incident-response procedure with 72-hour supervisory-authority notification.

7. Current Sub-processors

Sub-processorPurposeLocation / safeguards
Vercel Inc.Application hosting, serverless functions, object storage (Vercel Blob)United States (IAD1 region), GDPR-compliant DPA, SCCs
Stripe, Inc.Payment processing and subscription billingUnited States / Ireland, GDPR-compliant DPA, SCCs, DPF
Google LLCAI cover-letter generation (Gemini API); Gmail integration when enabled by the userUnited States, GDPR-compliant terms, SCCs, DPF
Managed PostgreSQL providerPrimary databaseAs configured for the deployment; GDPR-compliant DPA, SCCs where applicable
Managed Redis providerBackground job queue (BullMQ)As configured for the deployment; GDPR-compliant DPA, SCCs where applicable
Apify Technologies s.r.o.Aggregation of public job postings from job portalsEuropean Union (Czech Republic), EU-based processing
Adzuna LtdPublic job-posting data via official APIUnited Kingdom; UK GDPR and SCCs
SMTP email providerTransactional emails (verification, password reset, notifications)As configured; GDPR-compliant DPA where applicable

"DPF" = EU–US Data Privacy Framework; "SCCs" = Standard Contractual Clauses. The Provider will keep this list current.

8. Liability and Governing Law

Each party's liability under this DPA is governed by the Terms and Conditions and applicable law. This DPA is governed by Italian law in line with the Terms. In the event of conflict between this DPA and the Terms regarding personal data protection, this DPA prevails.

9. Contact

Data protection questions: privacy@lavura.co.uk. General questions: support@lavura.co.uk.