Data Processing Addendum
Key: data_processing_addendum · Version 1.0.0 · Effective 2026-09-02T07:31:10Z · Canonical SHA-256: 6973458958ea79eef6dca00335e772af076a8108529bf87bb28906187a826a3e
2.1 Incorporation and roles
SMARTEDTECH SL, NIF B66970831, Carrer Agricultura, 16, 1º, 9ª, 08320 El Masnou, Barcelona, Spain; Registro Mercantil de Barcelona, Tomo 45858, Folio 103, Sección 8, Hoja B-501172, Inscripción 1; legal@vitrinoro.com. Trading brand: Vitrinoro.
This DPA forms part of the agreement between the Business as “Customer” and SMARTEDTECH SL as “Processor” for Customer Personal Data processed to provide Vitrinoro. It applies when Vitrinoro processes personal data on documented instructions from the Customer. Each party remains independently responsible for processing for which it determines purposes and essential means.
“Data Protection Law” means the GDPR and applicable EEA/Member-State law, UK GDPR where applicable, Swiss data law, PIPEDA and applicable provincial Canadian law, the CCPA/CPRA and other applicable U.S. state privacy laws, Türkiye Law No. 6698, and other mandatory privacy law applicable to the processing. GDPR terms such as controller, processor, data subject and personal data have their statutory meanings.
2.2 Documented instructions
Customer instructs Vitrinoro to process Customer Personal Data only to provide, secure, support and terminate the subscribed service; execute documented product settings and support requests; and comply with law. This DPA, the Terms, configured features and lawful written instructions constitute the complete instructions. Vitrinoro will notify Customer if it believes an instruction infringes applicable Data Protection Law, unless prohibited, and may suspend the affected processing while the parties resolve it.
Customer warrants that its instructions and collection are lawful and that it has provided required notices and obtained required permissions. Vitrinoro will not sell Customer Personal Data, use it for targeted advertising, or combine it with personal data received from another customer except as permitted to provide, secure or improve the service using aggregated or de-identified information.
2.3 Confidentiality and security
Persons authorised to process Customer Personal Data are bound by confidentiality. Vitrinoro will maintain technical and organisational measures appropriate to risk, including logical access control; least privilege; tenant and environment separation; encryption in transit; protected secrets and integration tokens; secure development and change control; dependency and vulnerability management; availability, backup and recovery measures; logging and incident handling; and periodic access review. Customer is responsible for account configuration, authorised users, lawful content, endpoints and credentials under its control.
2.4 Assistance
Taking account of the nature of processing and information available, Vitrinoro will reasonably assist Customer with data-subject requests, security duties, breach notifications, data-protection impact assessments and regulator consultations. If Vitrinoro receives a request concerning Customer Personal Data, it will direct the requester to Customer or act on Customer’s documented instruction unless law requires otherwise.
Vitrinoro will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data and provide available information needed for Customer’s assessment and notification. Notification is not an admission of fault. Customer must promptly provide incident contacts and cooperate in containment.
2.5 Subprocessors
Customer gives general authorisation for subprocessors necessary to provide the service. Vitrinoro will maintain a current list at `/legal/subprocessors`, impose materially equivalent data-protection obligations and remain responsible for subprocessor performance to the extent required by law. Vitrinoro will give reasonable advance notice of a new subprocessor that materially processes Customer Personal Data. Customer may object on documented, reasonable data-protection grounds; the parties will seek a practical alternative, and if none is reasonably available either party may terminate the affected feature without penalty for the unused affected period.
2.6 International transfers
Where Customer Personal Data protected by the GDPR is transferred to a country without an applicable adequacy decision, the 2021 European Commission Standard Contractual Clauses are incorporated by reference using the module matching the parties’ roles, normally Module Two (controller to processor), with SMARTEDTECH SL as data importer/exporter as factually applicable, optional docking enabled, Clause 9 Option 2, general authorisation with the notice described above, and Spanish law and Spanish courts for Clauses 17 and 18. The service description and security measures below complete the relevant annexes. The UK Addendum and Swiss adaptations apply where required. Türkiye-standard contractual or other valid transfer safeguards apply when Law No. 6698 requires them.
2.7 Return, deletion and audit
During the service, Customer may export available Customer Data using product functions. After termination or a valid deletion instruction, Vitrinoro will delete or return Customer Personal Data within the operational deletion cycle unless law requires retention. Residual encrypted backups are isolated from ordinary use and expire under the backup lifecycle.
Vitrinoro will make information reasonably necessary to demonstrate compliance available, including current security and subprocessor information. Customer may request one audit per year, and additionally after a material confirmed incident, first using independent reports and remote evidence. On-site audits require reasonable notice, confidentiality, minimal disruption, no access to other customers’ data and reimbursement of reasonable costs unless the audit identifies a material breach by Vitrinoro.
2.8 Processing details
**Subject matter:** hosting, generation, publication, domain connection, media storage, account administration, support and user-selected integrations for business websites.
**Duration:** the subscription and deletion/retention period described above.
**Nature and purpose:** collection, storage, organisation, retrieval, display, transmission, protection, support, export and deletion as instructed.
**Data subjects:** Customer owners/users/staff, business contacts, public-site visitors, leads or appointment customers whose data Customer chooses to process, and people appearing in Customer content.
**Data types:** identity/contact, account/role, business/site content, messages, appointment/free-busy data, domain/technical identifiers, media and usage/security records. Payment-card data is processed by the payment provider, not stored by Vitrinoro.
**Sensitive data:** not intended for ordinary use; Customer must not submit it unless specifically supported and lawfully authorised.
**Frequency:** continuous or as initiated by Customer and visitors.
If a conflict exists, the applicable mandatory Standard Contractual Clauses prevail over this DPA, this DPA prevails for data-processing issues, and the Terms otherwise prevail.