BeebeeBoard legal notice

Subscription terms and conditions
for the use of BeebeeBoard

These Terms and Conditions and the Privacy Policy apply from 25 May 2018 (the date the new GDPR rules came into effect) and replace the previous versions of the Terms and Conditions and the Privacy Policy.


Subject and purpose of these Terms

1. These Terms and Conditions govern the rights and duties relating to the use of the services of the provider Poppix S.r.l. (“Poppix”), Piazza Emile Chanoux 28/A, 11100 Aosta, (hereinafter: the service provider) and the user with regard to the use of the service available on the Internet on the BeebeeBoard websites and other URLs of the service provider.

2. The provider's service essentially consists in granting the possibility of using the service on the Internet on servers controlled by the service provider, to which the user is given access and rights of use to the extent necessary. While using the software as a service (SaaS) model, the user may enter data and use various functions. BeebeeBoard's services include (but are not limited to) the website, the BeebeeBoard application, the mobile apps, the blog, the newsletters, the forum and the help sections.

3. A stable internet connection allowing a connection to the service provider's servers is a necessary condition for using the service without problems. The decision to establish this connection through one's own device is at the customer's discretion..

4. Only the service provider's Terms and Conditions are valid. Conflicting or different terms or conditions supplied by the user are not recognised by the service provider unless they have been expressly recognised as valid in a written document agreed by the parties. Where the terms conflict, these Terms and Conditions apply.

5. The term “the service provider’s website” used below refers to the website or websites of the service provider through which the service is made available by the service provider on the Internet as set out in Paragraph 1.


2. End of the contract

1. Unless explicitly agreed on an individual basis, a contract is concluded only at the end of a registration process completed successfully with written or email confirmation from the service provider, or with the supply of the service itself.

2. The user can print the text of the contract from the website during the registration procedure and before entering into the contract.

3. The user has no right to conclude the contract. The service provider is free to refuse a user’s offer to conclude a contract without having to give a reason.

4. By registering for the services available on the BeebeeBoard websites, you accept and agree to the Subscription Terms (“the Terms”) set out below, including your consent to the processing and sharing of your personal data as required to provide the BeebeeBoard service and in compliance with all data protection laws.

5. Accepting additional communications from the Poppix S.r.l. group is not required to start the subscription, but it is advisable in order to make the most of BeebeeBoard. The information sent in these communications is commercial in nature.

6. To use our services you must accept the privacy policy and the Terms and Conditions. On accepting, you confirm that you have read and understood the Terms and Conditions and the privacy policy.

7. A necessary prerequisite for registration is the user's full legal capacity and a minimum age of 18. Minors are not allowed to register. In the case of a legal person, registration must be carried out by a natural person who has unlimited legal capacity and is authorised to represent the legal person.

8. Where a company deals with third parties on behalf of the contractor and the third party is named as the contractor, the company must inform the third party in advance of the Terms and Conditions and register only with their consent and with power of representation. If this does not happen, the service provider may terminate the contract by way of exception.


3. Services provided by the service provider

1. The service provider supplies various services relating to data management.

2. The content and purpose of the services are governed by the respective contractual agreements and limited to the service features described at the end of the contract on the service provider's website.

3. The service provider may offer trial versions for the purpose of testing the service. During the trial period, use of the service is free. If the user wishes to continue using the service at the end of the trial period, they must take out a paid contract.

4. The service offered by the service provider is defined for a certain period of time as part of a “subscription”.

5. Only the user who holds the account has the right to use the service. Transfer of the user's account to third parties, or other use options offered by the user to third parties, are not permitted and entitle the service provider to terminate the contract by way of exception.


4. Obligations of users

1. The user must provide truthful information about their identity or their business and about the use of the service.

2. When using the service, the user must comply with the laws in force and refrain from any activity that damages or places excessive strain on the operation of the service or the technical infrastructure.

3. Users are not allowed to give their credentials to third parties. Users must handle their own data with care and prevent any misuse of the credentials by third parties.

4. The user is solely responsible for meeting the record-keeping obligations. They must make sure that the documents and the data are lawful (where this is required) and that the tax authorities can access them.


5. Notice on the right of cancellation

1. For the use of the services offered by the service provider, there is no right of cancellation.


6. Term of the contract

1. The subscription starts when the contract is signed and runs for an indefinite period.

2. Trial arrangements end automatically at the end of the trial period. No notice is required for trial versions.


7. Prices and payment terms, account suspension, account cancellation and price revisions

1. The service provider offers its services in free and paid versions. Current prices are on the pricing and payment pages.

2. Payment for a subscription can be made on a monthly or annual basis, depending on the duration of the contract offered and chosen by the user, and paid by credit card (Visa, MasterCard and Maestro) or by SEPA transfer (in countries where this payment option exists). The billing period lasts one month or one year from the date on which the user registered for the paid version, and the corresponding amount is to be paid in advance. The service provider reserves the right to add the option of buying subscriptions at a different frequency (for example on a quarterly basis) or to introduce related services with a different billing model (for example based on usage).

3. Subscription fees are payable immediately on receipt of the invoice and the amount is charged to or taken from the credit card or bank account (in countries where this payment option is available) on a monthly or annual basis until the end of the subscription contract.

4. Poppix reserves the right to change the entity issuing the invoice to a different subsidiary of the Poppix S.r.l. group if necessary.

5. No refund of the monthly or annual amount paid is provided if the subscription is cancelled before its natural expiry. When the contract is cancelled, the version of the product can be used with full functionality until the end of the period covered by the contract.

6. If the monthly or annual charges are not taken from the credit card or bank account on time (for example because of insufficient funds), access to the system is blocked immediately. As soon as payment is received, access to the system is restored. The user must transfer the full amount to the service provider's account within 4 working days.

7. If the account is deleted by the user before the end of the contract, the account will be inaccessible immediately after deletion. In this case, even if a new account is created, the remaining credit cannot be refunded or credited to the new account. The remaining amount is not returned even if the contract is terminated extraordinarily for legal reasons by the service provider for a use other than that set out in the contract.

8. The user accepts that invoices and payment reminders are sent to the email address provided by the user.

9. The service provider has the right to change the fees set at its own discretion. Any such price change must be notified in writing at least four weeks before it takes effect. The user may terminate This agreement within one month of receiving notice of the change, with effect from the moment the fee increase becomes applicable.


8. Termination of the contract

1. The user may take up the free subscription for a period of time set by the service provider. No separate notice is needed. If the user has not entered any payment information for the subscription after the trial period expires, the customer will incur no cost or obligation.

2. The subscription can be ended by a user without notice at the end of the month or year (or other billing period) relating to the billing period. The service can be terminated through the platform or by sending an email to the service provider.

3. In some cases the user can choose between an annual and a monthly subscription. If the user wishes to move from a monthly subscription to an annual one, this is possible and the subscription will be automatically extended by one year and the annual amount must be paid immediately on receipt of the invoice. The annual subscription can be cancelled up to the last day of the current year covering the subscription period. The same applies to moving from a monthly or annual subscription to another monthly or annual subscription. If the user moves from an annual subscription to a monthly one, this is possible from the last day of validity of the annual subscription. The subscription will then continue to run automatically on a monthly basis once the annual subscription has ended. A similar mechanism will apply if the service provider introduces a different billing period.

4. Each party's right to extraordinary termination remains unaffected.

5. Poppix has the right to delete the Client's data after the contract is cancelled, whatever the reason for the cancellation, and Poppix is not obliged to store the Client's data after that period. Poppix keeps only the data it is required to keep for the minimum period.

6. Poppix ensures that it is always in compliance with the General Data Protection Regulation (GDPR) and with all legislative requirements on data protection at all times.


9. Warranty and availability of services

1. The Application and the Service are provided as they are and Poppix expressly disclaims any further representation, warranty, condition or other term, express or implied, by statute, collateral or otherwise, including but not limited to implied warranties, conditions or other terms of good quality, fitness for a particular purpose or reasonable care and skill.

2. Poppix has the right to make operational changes to the System for improvement or for other reasons (for example to develop or replace technical equipment, or to maintain or update the software) without giving the Client notice. In some circumstances it may be necessary to suspend access to the system, generally between 21:00 and 06:00 CET. Notice of such a suspension will be given to the client in advance where possible. Poppix will not be liable for any consequence of such a suspension.

3. The service provider accepts no responsibility for the functioning of the connection to its servers in the event of power cuts and server failures outside its sphere of influence.


10. Rights of use

1. For the whole duration of this contract the service provider grants the user a simple, geographically unlimited, non-transferable, non-sublicensable and personal right to use the BeebeeBoard software made available by the provider for the supply of its services as set out in these general Terms and Conditions.

2. The user has the right to access the managed software information systems of the service provider in order to process their data.

3. The user may use the processing software only for their own business purposes and only through their own staff.

4. No intellectual property right is assigned to the customer. The software, even if individually customised, therefore remains the property of Poppix, unless otherwise agreed.

5. In relation to any and all material uploaded by the client and all client data, the client grants Poppix, its suppliers and subcontractors an irrevocable, non-exclusive worldwide licence to provide the application and all related services requested by the client. The Client warrants that it has the rights to the data and material uploaded, or that they are such as not to infringe the rights of third parties or intellectual property rights, and that they contain no obscene, offensive or inappropriate material or any material in breach of any law.

6. Poppix has the right to transfer its rights and obligations towards the Client to a company in the group or to a third party. If the client gives consent to strengthening the relationship by allowing marketing services, the material sent will relate exclusively to the legal entities connected to the Poppix S.r.l. group of companies.

7. The customer accepts that Poppix has the right to use subcontractors for any purpose, including the management and development of the software application and the storage of customer data.

8. The service provider is not obliged to give the user the source code of the software.

9. The software application and any information provided by it, with the exception of the Customer's data, is protected by copyright and other intellectual property rights and is owned or licensed. Any development or adaptation of that intellectual property made by the Customer is the property of Poppix. The Customer must notify Poppix of any actual or suspected infringement of Poppix's intellectual property rights and any unauthorised use of the software application of which the customer is aware.


11. Privacy and Customer Data

1. The service provider will treat the confidentiality of personal data in accordance with the provisions of the applicable data protection law.

2. Use of the service may require the service provider to process personal data on the user’s behalf. A separate agreement on the processing of personal data must therefore be concluded. The parties agree that the Client is the Data Controller of the data they upload to the BeebeeBoard application and that they may modify or delete that data as needed. Poppix is at all times the Data Processor on the Client’s behalf. As an appendix to these terms, the parties will enter into a data processing agreement (“DPA” or Data Processing Agreement).

3. The Client confirms that it is authorised to instruct Poppix to process such information and that all instructions given will be lawful.

4. Poppix will process the Client’s data only in accordance with the Client’s instructions and not for its own unauthorised use.

5. The Customer owns all the data provided to Poppix or to the Application. The Application allows the Customer to export records and data held by the Application, and the Customer agrees to export all data before their subscription ends.

6. Poppix guarantees the level of data protection maintained by its subcontractors.

7. Poppix will adopt all the technical and organisational security measures necessary to guarantee the safe and secure processing of the Customer's data and to prevent system information from being destroyed, lost or dispersed accidentally or unlawfully, and to prevent such information from falling into the hands of any unauthorised parties or from being misused or otherwise processed in a way contrary to data protection legislation.

8. We also refer to our privacy policy, available at https://beebeeboard.com/normativa-privacy.


12. Changes to the services

1. The service provider periodically updates the services it provides on the Internet at its own discretion and in line with technological developments and market needs, in order to meet the intended use in accordance with the product description. This may change the content of the service, such as new or modified features and adaptations to new technologies. Since such changes are in the nature of the solution, the user cannot derive any right or claim from this.

2. The service provider is also entitled to make new paid services available and to discontinue the supply of free services. The service provider may also add further paid services on top of the subscriptions currently paid for. When changing paid services, the service provider will pay particular attention to the legitimate interests of users and will announce the changes in good time.


13. Limitation of liability

1. Claims for damages for breach of contract and unlawful acts can only be pursued if there is evidence of an act of gross intentional negligence by Poppix and/or its agents. This disclaimer does not apply to the breach of essential contractual obligations.

2. Furthermore, Poppix's liability remains unaffected in cases of personal injury and mandatory legal provisions.

3. For services provided free of charge, the service provider bears no liability beyond that specified in paragraphs 1 and 2.

4. Poppix is not liable for interruptions of the service due to force majeure, in particular in the event of failure or overload of global communication networks. For this reason, the client cannot claim a reduction of its own service obligation.

5. Poppix is not responsible for the information published on its services. The sender is responsible for its accuracy, completeness and timeliness.

6. The service provider is not liable for loss of data to the extent that the damage is due to the user's failure to meet their own backup obligations (see Section 4.4 of these general terms and conditions) and the lost data therefore cannot be restored with reasonable effort.

7. Poppix will not be liable for any damage the customer may suffer due to the lack of security measures in the transmission of data.

8. Any liability for damages is limited to the amount of the annual subscription. Liability for damages caused by data loss is limited to the amount that would have resulted with adequate data protection; this may not, however, exceed the annual subscription fee.

9. Any claims for damages by the client expire one year after they arise. This limitation does not apply if Poppix has acted with gross negligence or intent.

10. Liability under product liability law remains unaffected.


14. Changes to the Terms and Conditions

1. The service provider reserves the right to amend these terms and conditions at any time, with effect also within existing contractual relationships, provided that such amendment, taking account of the service provider's interests, is reasonable for the user; this is particularly true when the change carries no significant legal or economic disadvantage for the user, e.g. changes to the registration process or changes to the contact information.

2. All other changes to the terms and conditions will be communicated by the service provider to registered users at least 4 weeks before the intended entry into force of the changes. The changes will be communicated to the user by email. Unless the user objects within 4 weeks of receiving the notice, the usage contract will continue with the entry into force of the changes under the amended terms and conditions. In the notice of change, the service provider will inform the user of their right to object and of the consequences of an objection. In the event of an objection, the service provider has the right to terminate the contractual relationship with the user at the intended entry into force of the changes.


15. Final provisions

1. These Terms and Conditions shall be governed by and construed in accordance with Italian law, and the Italian courts shall have exclusive jurisdiction to determine any dispute concerning these Terms and / or their subject matter.

2. Any dispute concerning the formation, interpretation, performance, validity and effectiveness of this contract and, in any case, any dispute arising out of or otherwise connected with this contract shall fall within the exclusive jurisdiction of the Italian Courts, and the Court of Aosta shall have sole competence..

3. Should individual provisions of these Terms and Conditions be or become invalid, this will not affect the validity of the remaining provisions.

Effective from: 17.04.2018


Data processing agreement

Thank you for your interest. We take our customers’ privacy and security very seriously, which is why we offer an appointment agreement as external data processor that forms the basis of the relationship between you, the Client, and Poppix, on data processing under the new data protection rules known as the European Data Protection Regulation or RGPD (GDPR by its English initials).

This is a very important contract that forms the basis for processing data on your behalf and explains how your data may be processed and for what purpose.

Appointment as external data processor

(ex art. 28 GDPR 2016/679)

BETWEEN
Poppix S.r.l. (“Poppix”), tax code and VAT number IT01213200072, in the name and on behalf of the legal representative pro tempore, with registered office at Piazza Emile Chanoux 28/A, 11100 Aosta, Italy (hereinafter the Data Processor)
E
The customer as defined in the “Subscription terms and conditions for the use of BeebeeBoard”
in its capacity as Data Controller (hereinafter the Data Controller)

having regard to Article 4(1) of EU Regulation 2016/679, which defines personal data as: “any information relating to an identified or identifiable natural person (the 'data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”;

having regard to art. 4 no. 2 of EU Regulation 2016/679, which defines processing as: “any operation or set of operations performed with or without the aid of automated processes and applied to personal data or sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction”;

having regard to Art. 4 no. 8 of EU Regulation 2016/679, which defines the data processor as: “the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller”;

having regard to Article 5(1) of EU Regulation 2016/679, which states: “Personal data are: a) processed lawfully, fairly and in a transparent manner in relation to the data subject («lawfulness, fairness and transparency»); b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing of personal data for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes is not, in accordance with Article 89(1), considered incompatible with the initial purposes («purpose limitation»); c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed («data minimisation»); d) accurate and, where necessary, kept up to date; every reasonable step must be taken to erase or rectify without delay data that are inaccurate having regard to the purposes for which they are processed («accuracy»); e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which they are processed; personal data may be kept for longer periods provided that they are processed solely for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, in accordance with Article 89(1), subject to the implementation of the appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of the data subject («storage limitation»); f) processed in a manner that ensures appropriate security of the personal data, including protection, by means of appropriate technical and organisational measures, against unauthorised or unlawful processing and against accidental loss, destruction or damage («integrity and confidentiality»)”;

having regard to Art. 28 of EU Regulation 2016/679, which states that: “Where processing is to be carried out on behalf of the data controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the processing meets the requirements of this regulation and ensures the protection of the rights of the data subject”;

having regard to art. 28(3) of EU Regulation 2016/679, which provides that: “Processing by a processor is governed by a contract or other legal act under Union or Member State law that binds the processor to the controller and sets out the subject matter and the duration of the processing, the nature and the purpose of the processing, the type of personal data and the categories of data subjects, and the obligations and rights of the controller”;

having regard to Recital 81 of EU Regulation 2016/679, which states: “[…] the Controller should use only processors providing sufficient guarantees, in particular in terms of expert knowledge, reliability and resources, to implement technical and organisational measures which will meet the requirements of this Regulation, including for the security of the processing. […] Processing by a Processor should be governed by a contract or other legal act under Union or Member State law, binding the Processor to the Controller, setting out the subject matter and duration of the processing, the nature and purposes of the processing, the type of personal data and categories of data subjects, taking into account the specific tasks and responsibilities of the processor in the context of the processing to be carried out and the risk to the rights and freedoms of the data subject.”

By this deed, pursuant to and for the purposes of art. 28 of EU Regulation 2016/679, the data controller APPOINTS Poppix S.r.l. (“Poppix”), tax code and VAT number IT01213200072, as external processor of the personal data entrusted to it, in the name and on behalf of the legal representative pro tempore, so that the services offered can be lawfully provided in compliance with all the rules governing the processing of personal data.


1. Subject

The parties have in place an engagement for the supply of the cloud practice management software service known as BeebeeBoard. The various functions of the BeebeeBoard services include (but are not limited to) the website, the mobile apps, the blog, the information emails, the forum and the help sections.


2. Processing

Purposes of processing
Data processing is permitted only as far as is needed to carry out the assignment to supply the cloud practice management service, and is aimed at ensuring the client can make full use of the service.
Nature of the processing
Processing may be carried out by automated or non-automated means and must be lawful and fair.
Duration
Processing may be carried out until the end of the subscription to the cloud practice management software. On termination, the Data Controller may delete all the data they have uploaded, but in any case the Data Processor will delete all the data uploaded to the platform except those that must necessarily be kept under the law.
The parties agree that this agreement and the standard contractual clauses terminate automatically if the agreement is terminated.


3. Type of personal data

The Data Processor does not access or use the data uploaded to the platform, except where necessary to maintain or provide the service, or to comply with legal obligations or binding orders from a government body. In any case, given the service offered, the data subjects' data processed can be assumed to belong to the following categories: a) ordinary and special category data of clients; b) ordinary data of operators
The Data Controller is always responsible for the accuracy, integrity, content and reliability of the personal data processed by the Data Processor.


4. Category of Data Subjects

The information processed concerns the employees/operators of the data controller and its clients and any of their family members.


5. Obligations of the Processor

The Data Processor has the task and the responsibility of fulfilling and scrupulously observing the provisions of the data protection legislation in force, the measures and the opinions of the Garante (Italy's data protection authority).

Instructions

  • The Processor processes the data on behalf of the Controller solely for the performance of the contractual obligations in place and in particular for carrying out the activity of supplying the cloud practice management software service;
  • The data processor does not view the data uploaded to the platform by the data controller;
  • The processor only stores the data provided by the controller;

Persons authorised to process
The Processor shall take reasonable steps to ensure the reliability of any staff member who may have access to the personal data covered by the processing. The Processor guarantees that:

  • the staff who process personal data are duly appointed to do so;
  • authorised staff are instructed on how processing is carried out, on the security measures to be applied and on company procedures for the protection of personal data;

Use of other Processors
From the effective date of this agreement the Data Controller authorises the Data Processor to engage other processors (sub-processors). The Processor undertakes:

  • to carry out adequate due diligence on each additional processor to ensure it can provide the level of protection of the Data Controller's personal data, including but not limited to sufficient guarantees to put in place appropriate technical and organisational measures so that the processing meets the requirements of the GDPR and of this agreement;
  • to provide the Data Controller with all the full details of the processing of data by other processors;
  • to ensure a satisfactory basis for transferring personal data to another Country on behalf of the Data Controller, if a Sub-processor is based in or stores personal data in a non-EU country;
  • to inform the Data Controller if Sub-Processors are replaced, so giving the Controller the opportunity to object to such changes where the Sub-Processor does not process the data in line with the relevant data protection laws;
  • to allow the data controller to end the subscription to the service, without having to observe the normal notice period, in the event that Sub-processors are replaced;

Communication, disclosure and transfer of personal data
The data of the data subjects may be transferred to the United States, as some suppliers are based in the United States. In any case, those suppliers participate in and have certified their compliance with the EU-US Privacy Shield Framework. In any event, the Data Processor undertakes to:

  • not to disclose the data processed;

Security and organisational measures
Taking into account the available technology and its implementation cost, the scope, the context and the purpose of the data processing, the nature, subject, context and purpose of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Data Processor undertakes to adopt the security measures expressly provided for in Art. 32 of EU Regulation 679/2016 and in any case all the measures provided for by the other rules in force on the protection of natural persons with regard to the protection and circulation of data.
In assessing the appropriate level of security the Data Processor takes particular account of the risks presented by the processing, arising in particular from the destruction, loss, alteration, unauthorised disclosure of, or access to, the personal data stored, whether accidental or unlawful.
The Data Processor undertakes to prepare and update the risk assessment and, in any event, to draw up and periodically update one or more documents recording the choices made, evidencing compliance with the rules on the protection of individuals with regard to the processing of data and the movement of data;

Assistance/Exercise of rights
The data processor is obliged to assist the data controller with appropriate technical and organisational measures, taking into account the nature of the processing, in order to fulfil the controller's obligation to respond to requests for the exercise of the data subject's rights, and to that end undertakes to:

  • to respond promptly to the Data Controller to any request they make;
  • to provide their cooperation, so as to allow the Data Controller to respond fully and promptly to the requests and/or orders of the supervisory authorities or of the judicial authority concerning the processing operations and to data subjects' requests to exercise their rights, as well as any other request from data subjects;
  • to provide prompt assistance and cooperation in the event of a request for data portability or for the exercise of the right to be forgotten by data subjects, in line with the current legal requirements;

Support/Security measures
The data processor is required:

  • to inform the Controller, in the event of a personal data breach, without undue delay and in any case within 24 hours of becoming aware of or reasonably suspecting a personal data breach. The processor must provide sufficient information to allow the Data Controller to meet any obligation to report a personal data breach.
  • to adopt together with the Controller, immediately or in any case without undue delay, every measure needed to remedy data breaches, including, where appropriate, to mitigate their possible adverse effects;

Support/accountability information
The data processor is required:

  • to make available to the controller all the information needed to demonstrate compliance with EU Regulation 2016/679 and with the other provisions on the protection of natural persons with regard to the processing of personal data;
  • to inform the data controller immediately:
    • of requests and applications received from data subjects, either individually or through representatives and associations;
    • of any communication received from the Garante per la protezione dei dati personali or other authorities;
    • of any check or inspection by the Garante per la protezione dei dati personali (Italy's data protection authority) or other authorities, as well as of any report and any document relating to that inspection and check;
    • of any communication addressed to the Garante per la protezione dei dati personali or to other authorities, including counterarguments and defence submissions, before they are sent, subject to agreement with the Data Controller;
    • of any fact or act that may give rise to the obligation, the burden or the opportunity of an action aimed at complying with the rules and practices on the protection and circulation of data;

6. General conditions

For everything not expressly provided for in this deed, reference is made to the general provisions in force on the protection of personal data, and it is noted that this designation carries no right to receive any specific fee and/or allowance and/or additional reimbursement

7. Brief description of the infrastructure, the security measures adopted and the processing methods

Archives and production programs reside on servers located in European data centres owned by Amazon Inc. Such information will not be transferred or replicated outside the chosen region without the prior consent of the data subject.
The IT infrastructure is run on virtual servers on which an incremental, automatic, mirrored backup is performed (data is always stored in two separate locations) by Amazon Inc. Poppoix also guarantees a daily automatic backup and allows on-demand backups to be created. These last two backups are managed entirely by the Data Controller and are stored with a retention period of 30 days.
Perimeter security for the network infrastructure is handled by integrated network Firewalls, and data communications to and from outside are encrypted using the TLS (Transport Layer Security) protocol, which encrypts the information entered. TLS is a secure, tested standard, used for online banking, for example, and you can recognise it by the “s” after “http” in the URL shown in the browser (so https: // ..) or by the padlock symbol shown on the browser tab.
Customers use services and technologies built in every part to withstand DDoS attacks, with scalable, efficient encryption functions (for example EBS, S3, Glacier, Oracle RDS, SQL Server RDS and Redshift).
Authentication and authorisation credentials for the systems are managed according to appropriate security standards and are not available to Poppix.

8. List of sub-processors

In order to provide its services to the Data Controller, Poppix S.r.l., as Data Processor, will make use of the following parties, acting as Sub-Processors:

  • The Rocket Science Group, LLCAtlanta, Georgia, United States
    Purpose of the processing: Sending, tracking and backing up the emails sent by BeebeeBoard
  • Mobile Solution s.r.l.Via Melzo n.12, 20129 Milano – P.iva 03020690131
    Purpose of processing: Delivery of SMS sent by and through BeebeeBoard
  • Intercom, IncSan Francisco, California, United States
    Purpose of processing: Support and monitoring of the platform
  • Amazon, IncEurope Region
    Purpose of processing: Cloud services for storing the data and the platform
  • OneSignal, IncSan Mateo, California, United States
    Purpose of processing: Delivery of push notifications sent by BeebeeBoard.
  • Stripe, IncSan Francisco, California, United States
    Purpose of the processing: Management of online payments