Preamble
This Agreement supplements the Terms of Service and governs the processing of personal data that OutLine Digital Agency (the Processor) carries out on behalf of the customer (the Controller) in providing Omega Work.
It constitutes the contract required by GDPR art. 28(3) and, where the Controller is subject to them, by art. 28 of the UK GDPR, art. 9 of the Swiss Federal Act on Data Protection, section 18.3 of Québec’s Act respecting the protection of personal information in the private sector, and the US state privacy laws that require a written contract with a service provider or processor. It is concluded when the Controller accepts it on opening its first workspace and remains in force for as long as the Processor processes personal data on the Controller’s behalf.
- Processor
- OutLine Digital Agency (sole trader), Via Dalmazia 36, 76125 Trani (BT), Italy — VAT IT08978680729
- Controller
- The customer, as identified in the account and in the business details entered in the application.
- Privacy contact
- amministrazione@outlinedigital.it
Terms such as “personal data”, “processing”, “controller”, “processor” and “personal data breach” have the meaning given in the GDPR; where another law applies, they include the equivalent terms of that law (for example “business” and “service provider” under the CCPA).
1. Processing on documented instructions
- The Processor processes personal data only on the Controller’s documented instructions. These are: this Agreement, the Terms of Service, the service documentation, and the settings the Controller configures in the application (members and roles, permissions, public forms, integrations, retention).
- The Processor does not process the data for its own purposes, does not disclose it to third parties, does not use it for commercial analysis or to train artificial-intelligence systems.
- If a legal obligation requires the Processor to carry out further processing, it informs the Controller before doing so, unless the law prohibits this on important grounds of public interest.
- The Processor immediately informs the Controller if, in its opinion, an instruction infringes data protection law.
2. Confidentiality of authorised persons
The Processor ensures that the persons authorised to process the data — staff and contractors — are bound by a duty of confidentiality that survives the end of their engagement, receive instructions, and have access only to the data they need for their task.
Support staff access customer workspaces only through the logged temporary access described in section 8.
3. Security measures
The Processor implements the technical and organisational measures described in Annex B and on the Security Measures page, which form part of this Agreement.
The measures may be updated over time provided that the level of security is not reduced. Material changes are notified to the Controller with the same notice period as for sub-processors.
4. Sub-processors
The Controller gives the Processor general authorisation to engage other processors, on the following conditions.
- The current list is published on the Sub-processors page.
- Each sub-processor is bound by contract to data protection obligations equivalent to those of this Agreement; the Processor remains liable for their performance as for its own.
- The addition or replacement of a sub-processor is notified to the Controller at least 30 days in advance, by email and prominently in the application.
- Within that period the Controller may object on reasonable, documented data protection grounds. If it objects, the parties look in good faith for an alternative; if none is practicable, the Controller may terminate without penalty with effect from the date of the change.
| Sub-processor | Activity | Country |
|---|---|---|
| IONOS SE | Servers and storage: hosts the application, the workspace databases, uploaded files and backups. | Germany |
| Aruba S.p.A. | Relays the service’s outgoing email: invitations, password resets, notification digests and contracts. Messages contain the recipient’s name and email address, the name of the person who acted, of the workspace and of its teams, the titles of the tasks and projects they mention and, for an invitation, the message its sender typed. | Italy |
| Stripe Payments Europe, Limited | Collects subscription payments and issues receipts. It processes only the billing details of the subscriber (company name, address, VAT number, billing email, card details — which never pass through our servers). With them it receives the name of the workspace, the sign-in email address of its owner and our internal reference numbers. It has no access to the data stored in workspaces. | Ireland |
5. Assistance with data subject requests
The application gives the Controller the tools to answer data subject requests itself, without waiting for anyone: search, export of data, rectification, deletion, and a history of changes.
If a data subject contacts the Processor directly, the Processor does not act on the request and forwards it to the Controller without delay, telling the individual who the controller is.
Where the application’s tools are not enough, the Processor provides reasonable technical assistance, at its own cost if the need arises from a malfunction.
6. Personal data breaches
- The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the data processed on its behalf, and aims to do so within 24 hours. A first notice is given even when not all the information is available yet; the rest follows in stages, as it becomes known.
- The notification describes the nature of the breach, the categories and approximate number of individuals and records concerned, the likely consequences and the measures taken or proposed, so that the Controller can assess whether and when to notify the competent authorities and individuals within the deadlines of the law that applies to it (for example 72 hours under the GDPR and UK GDPR, or “as soon as possible” or “as soon as practicable” under the Swiss nFADP, PIPEDA and the Australian and New Zealand schemes).
- The Processor documents every breach and gives the Controller the cooperation it needs to meet its obligations towards authorities and individuals.
- Notifying authorities and individuals remains the Controller’s responsibility: the Processor does not do so on its behalf.
7. Impact assessments and prior consultation
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller with data protection impact assessments and any prior consultation of an authority, by providing technical documentation on the architecture, the security measures and the data flows of the service.
8. Support access to the workspace
- It takes place only at the Controller’s request, or for technical work needed to keep the service running or to fix a fault.
- It uses a dedicated temporary access created inside the workspace that expires automatically after 15 minutes: it neither uses nor knows the credentials of the Controller’s users.
- While it lasts, that access has the permissions of an administrator of the workspace: this is what makes it possible to see a problem as the Controller sees it. The person who uses it is bound by confidentiality (section 2) and looks only at what the request requires.
- It is recorded and visible to the Controller: each access — when it started and ended, who opened it, the reason given and the files downloaded during it — is shown to the owner and the administrators of the workspace in the admin console (Privacy and compliance) for 24 months, and the owner is notified by email when an access is opened. The full data export is blocked during a support access.
9. Audits and demonstrating compliance
The Processor makes available to the Controller all information necessary to demonstrate compliance with this Agreement and allows audits, including inspections, by the Controller or an auditor it appoints.
- Audits require at least 15 days’ notice, take place during business hours and must not affect the continuity of the service or the confidentiality of other customers’ data.
- One audit per calendar year is allowed, plus further audits after a personal data breach or at the reasoned request of a supervisory authority.
- The Controller’s auditor must not be a competitor of the Processor and must sign a confidentiality undertaking.
- The cost of additional audits requested by the Controller is borne by the Controller, unless the audit reveals a breach by the Processor.
The Processor keeps a record of the processing it carries out on the Controller’s behalf (GDPR art. 30(2)) and cooperates, on request, with the supervisory authorities in the performance of their tasks.
10. International transfers
The Processor processes the data within the European Economic Area: the infrastructure is hosted by IONOS SE in Germany, and its sub-processors are in the European Union. It does not transfer the data to third countries, except to make it available to the Controller and its users wherever they are.
- From the EU to the Controller. Where the GDPR applies to making data available to a Controller that is not covered, for that data, by an EU adequacy decision, the parties agree the EU standard contractual clauses (Commission Implementing Decision (EU) 2021/914), Module Four (processor to controller), which are incorporated into this Agreement by reference. Section 23 of the Terms of Service determines the governing law and courts; the details of the processing are those in Annex A. For those clauses: the docking clause (clause 7) does not apply; clauses 14 and 15 apply only if the Processor combines the data received from the Controller with personal data it has collected in the European Union, which it does not do; Italian law governs them (clause 17) and the courts of Italy have jurisdiction (clause 18); the parties are those named in the preamble and Annex I is Annex A to this Agreement. Making data available to a Controller in the United Kingdom, Switzerland or New Zealand relies on the European Commission’s adequacy decisions for those countries, for as long as they remain in force; the same holds for a Controller in Canada to the extent that PIPEDA applies to the data concerned, and for a Controller in the United States to the extent that it is certified under the EU-U.S. Data Privacy Framework for that data. In every other case Module Four applies.
- United Kingdom. For a Controller subject to the UK GDPR, transfers to the Processor rely on the UK’s adequacy regulations for the European Economic Area. Should these cease to apply, the parties agree the EU standard contractual clauses (Module Two) together with the UK International Data Transfer Addendum issued by the Information Commissioner, incorporated by reference.
- Switzerland. For a Controller subject to the Swiss nFADP, transfers to the Processor rely on the Federal Council’s recognition of the adequacy of the countries concerned. Should this cease to apply, the parties agree the EU standard contractual clauses with the adaptations required for Switzerland: the FDPIC is the competent supervisory authority for transfers under Swiss law, and “Member State” includes Switzerland for the purpose of individuals’ rights.
- If a transfer outside the EEA ever becomes necessary for a sub-processor, the Processor gives notice under section 4 and makes it only with one of the safeguards of Chapter V of the GDPR, stating it in the sub-processor list.
- Transfers resulting from services connected by the Controller are made under the Controller’s responsibility.
- Requests from authorities. If a court or public authority asks the Processor for access to the Controller’s data, the Processor checks that the request is lawful, contests it where there are reasonable grounds to do so, hands over only what is strictly required and, unless the law forbids it, tells the Controller beforehand.
11. United States: service-provider terms
Where the Controller is a “business” subject to the California Consumer Privacy Act (CCPA) or a “controller” subject to another US state privacy law, the Processor acts as its service provider (or processor). The Controller discloses the personal information to the Processor only for the limited and specified business purpose of providing the service described in Annex A, and the Processor:
- does not sell or share the personal information, and does not use it for cross-context behavioural or targeted advertising;
- does not retain, use or disclose it for any purpose — including a commercial purpose — other than providing the service under the contract, nor outside the direct business relationship with the Controller;
- does not combine it with personal information that it receives from another source or collects from its own dealings with the individual, except as those laws allow a service provider to do;
- complies with the obligations those laws place on service providers and processors, and gives the personal information the level of privacy protection they require, including the security measures in Annex B;
- notifies the Controller within five business days if it determines that it can no longer meet those obligations;
- lets the Controller take reasonable and appropriate steps to make sure that the information is used consistently with the Controller’s own obligations (sections 3 and 9) and, on notice, to stop and remedy any unauthorised use;
- helps the Controller answer the requests of individuals (section 5), and binds its sub-processors, by written contract, to the same obligations (section 4);
- keeps the information confidential, and deletes or returns it when the service ends (section 13).
Regulated data. The service is not designed for protected health information under HIPAA or for payment-card data: the Processor is not a “business associate” and has not signed a business associate agreement, and the Controller must not store such data in its workspaces.
Security incidents. Section 6 also covers the notice that US state laws require from a company that maintains data on behalf of its owner.
12. Canada, Australia and New Zealand
For a Controller subject to one of the laws below, the Processor processes the data only to provide the service, protects it with the safeguards described in this Agreement and assists the Controller as described in sections 5 to 9. In addition:
- Canada (PIPEDA, and the Personal Information Protection Acts of Alberta and British Columbia)
- The Controller remains accountable for the personal information it entrusts to the Processor for processing. The Processor uses it only for the purposes of the service, gives it protection comparable to that which the Controller must provide, and tells the Controller under section 6 of any breach of security safeguards, so that the Controller can assess whether there is a real risk of significant harm, report it and keep its record of breaches. The information is stored and processed outside Canada — in the countries shown in the sub-processor list — where it is subject to the law of those countries and may be accessed by their courts and authorities under that law; telling the individuals so, and naming those countries where the law requires it (as in Alberta), is the Controller’s responsibility.
- Québec
- This Agreement is the written contract required by section 18.3 of the Act respecting the protection of personal information in the private sector. The Processor uses the personal information only to carry out the service; applies the measures in Annex B to protect its confidentiality; does not keep it after the contract has ended (section 13); notifies the Controller’s person in charge of the protection of personal information without delay of any violation or attempted violation, by any person, of an obligation concerning the confidentiality of the information; and allows that person to carry out any verification relating to confidentiality (section 9). Before information is communicated outside Québec, the Controller must carry out the privacy impact assessment required by section 17 of that Act: the Processor gives it the information it needs — where the data is stored, who the sub-processors are, the security measures, and the legal framework that applies in the European Union.
- Australia
- The Controller keeps effective control of the personal information: it decides who may access it and can access, change, retrieve and delete it at any time; the Processor handles it only to store it and make it available to the Controller and its users, and binds its sub-processors to the same obligations. On that basis, providing the information to the Processor is intended to be a use by the Controller rather than a disclosure for the purposes of Australian Privacy Principle 8; whether it is one is for the Controller to assess. If the Processor has reasonable grounds to suspect unauthorised access to the information, its unauthorised disclosure or its loss, it notifies the Controller under section 6, so that the Controller can complete its assessment within the 30 days that the Notifiable Data Breaches scheme allows; the parties agree that any notification to the Office of the Australian Information Commissioner and to individuals is made by the Controller.
- New Zealand
- The Processor holds the personal information as the Controller’s agent, for safe custody and processing, and does not use or disclose it for its own purposes: under section 11 of the Privacy Act 2020 the information is treated as held by the Controller, which remains responsible for it, and sending it to the Processor is not a disclosure outside New Zealand under information privacy principle 12. The Processor notifies privacy breaches under section 6, so that the Controller can notify the Privacy Commissioner and the people affected as soon as practicable where serious harm is likely.
13. What happens at the end
- The Controller can export the data itself, in open formats, throughout the relationship.
- When the contract ends, the workspace remains accessible in read-only mode for 30 days, to allow export.
- After that period the Processor deletes the personal data without undue delay, and in any case within the following 30 days; copies in backups cease to exist as the rotation runs its course, at the latest about three months after the deletion. Data is kept longer only where EU or Member State law requires it.
- On request, the Processor confirms deletion in writing.
14. Order of precedence
In case of conflict, the standard contractual clauses (where they apply) prevail over this Agreement, and this Agreement prevails over the Terms of Service as regards personal data. Liability is governed by the Terms of Service.
Annex A — Details of the processing
- Subject matter
- Provision of an online project and work-management service.
- Duration
- The term of the service contract, plus the 30-day export window.
- Nature and purpose
- Collection, recording, organisation, structuring, storage, retrieval, consultation, transmission to the services configured by the Controller, erasure — solely to run the application as the Controller has configured it.
- Frequency
- Continuous, for as long as the service is used.
Categories of data subjects — depending on how the Controller uses the service:
- employees, partners and contractors of the Controller who are members of the workspace;
- guests invited to individual projects (customers, suppliers, freelancers);
- people who fill in the Controller’s public forms;
- people named in tasks, comments, notes and attachments.
Categories of personal data:
| Category | Examples | Where it appears |
|---|---|---|
| Identification and contact data | name, email address, job title, profile picture | Members, guests, public forms |
| Work data | assignments, due dates, progress, comments, status updates | Projects, tasks, goals, portfolios |
| Time data | time recorded on tasks and projects | Time tracking, reports |
| Usage and security data | sign-ins, sessions, history of changes | Activity log |
| Content of files and free text | anything the Controller’s users write or upload | Tasks, comments, attachments, forms |
| Special categories (GDPR art. 9) | only if the Controller’s users enter them in free text or attachments — Omega Work never asks for them | Tasks, comments, attachments |
Annex B — Security measures
The technical and organisational measures adopted by the Processor are described in full on the Security Measures page, which forms part of this Agreement. In brief: a separate database for each workspace, encryption of traffic in transit, encryption at rest of the credentials of connected services, passwords stored only as a hash, role- and permission-based access control, temporary and logged support access, daily backups of the databases, event logging.