What this document is
It is the contract required by Article 28 of the General Data Protection Regulation when someone processes personal data on someone else's behalf. It binds both parties from the moment the organisation accepts it.
- The organisation is the controller of its mission's data: it decides whom it registers, what it keeps about each person, why and for how long, and it is the one who asks for consent when consent is needed.
- We are the processor: we store that data, show it to whoever the organisation authorises and do nothing else with it.
For the data of the account each person signs in to the panel with, we answer as controller, and that is not governed by this document but by the privacy policy.
This agreement is read together with the terms of use, of which it forms part. If anything here conflicts with them, this document prevails as far as personal data is concerned.
Who each party is
Controller: the organisation that opens its space in Abra, with the name and the details recorded in its registration on the platform. It acts through its owner or whoever that person designates.
Processor:
- Germán Ezequiel Laso Andino, libero professionista, trading as ProfBlu.
- Partita IVA: 04702090988.
- Codice fiscale: LSNGMN88S04Z600M.
- Professional activity not registered in the Registro delle Imprese (no REA number).
- Contact address: Via della Sega 1, 38080 Verdesina, Porte di Rendena (TN), Italia.
- Email for this contract: legal@profblu.com. For any data matter, privacidad@profblu.com.
No data protection officer has been appointed: the law does not require one for an activity of this size.
Where and when it is accepted
[how each organisation's acceptance of this agreement is recorded. Today Abra has no sign-up of its own: access is given by agreement with the owner, and the panel does not yet store the date or the version accepted]
Until that exists, the agreement is accepted in writing — by email to legal@profblu.com — before the organisation opens its first mission with real data.
Subject matter, nature and duration
- Subject matter: providing Abra to the organisation — opening missions, recording what is needed, who commits, what is delivered and who checks it — and, in order to provide it, processing the personal data the organisation and its team enter.
- Nature and purpose: only the operations needed for the tool to work. Collecting what the organisation and its participants write, keeping it, showing it to whoever the organisation authorises, modifying it when they modify it, sending the notices the organisation configures and deleting it when it asks us to. Nothing else.
- Duration: as long as the organisation has its space in Abra.
What data, and about whom
Categories of data subjects:
- The people on the organisation's team and those who take part in its missions: those who coordinate, those who submit requests, those who contribute, those who verify.
- The people the aid goes to, who may be minors.
- The contact persons of the entities involved.
- Anyone who receives a handover link without yet taking part.
Categories of data, as the application collects them:
- Identification and contact: name, email, phone and address.
- Each person's role in the mission, its period of validity and its areas.
- The permission to receive messages by WhatsApp: whether it was given, when, by which means and who noted it.
- The consents: the text generated, its fingerprint, who signed, in what capacity, and the scanned paper.
- The requests and the people they refer to, with the fields the organisation defines in its mission's forms, including those it marks as protected.
- What each person offers, what they commit to and what they deliver, with the photos or documents uploaded as proof.
- The messages the mission sends: recipient, subject, text and outcome.
- The audit trail: who did what, when and for what reason, and who read a protected piece of data.
Which specific fields are asked for is decided by the organisation: the forms are its own. It must not ask for special categories of data — health, origin, religion, administrative status — unless they are essential for the aid and it has a legal basis for it; Abra has no fields intended for that data.
Minors
When a mission keeps data about minors:
- it is entered by the entity that has them in its care or by whoever the organisation designates, never by the minor;
- the data that identifies the minor or allows them to be located goes in protected fields, with their own permission and with each reading noted;
- the consent is signed by an adult as guardian or legal representative, and Abra does not allow the signature to be recorded without their name, their capacity and their relationship;
- no data about the minor travels in an email, in a WhatsApp message or in a public link.
The organisation answers for the person signing truly having that authority.
We only do what the organisation tells us
We process that data solely on the organisation's documented instructions. Its instructions are this contract, the terms of use, the configuration of each mission and everything its people do in the panel.
Therefore:
- We do not use a mission's data for anything of our own. No analytics, no advertising, no profiling, no training of models, and no transfer or sale to anyone. Nothing in the code does it.
- We do not transfer it outside the European Economic Area except as stated in the list of sub-processors.
- If a law requires us to process otherwise, we will tell the organisation before doing so, unless that same law forbids it.
- If an instruction from the organisation seems to us contrary to the GDPR, we will say so.
Confidentiality
Whoever has access to this data is bound by confidentiality, and that obligation survives the end of this agreement. Today, technical access to the database is held by one single person, the owner.
Inside the organisation, who sees what is decided by the organisation itself through the roles it hands out. We enforce that arrangement; we do not choose for it.
Security measures
The ones that actually exist:
- All traffic travels encrypted with TLS.
- Access depends on each person's role in their organisation and in their mission, and organisations are isolated from one another.
- Contact details and protected data are in separate tables, with their own permission, and every reading of a protected piece of data is noted.
- The audit trail is append-only: neither the application nor a person with access to the panel can edit or delete it.
- Public handover links carry a single-use code of which only the fingerprint is stored, and that page cannot be embedded in another website.
- [backups of the environment in which the organisation runs its mission: frequency, where they are kept and for how many days. The demonstration environment has no scheduled backups]
And what we do not do, so that nobody assumes it: we do not encrypt field by field inside the database, and there is no external security certification today.
Sub-processors
The organisation gives us general authorisation to use other companies to provide the service. This is the complete list as of today:
- Hetzner Online GmbH — hosting of the server, in Nuremberg (Germany). Within the EEA.
- IONOS SE — delivery of outgoing email, from its Spanish region. Within the EEA.
- Meta Platforms Ireland Ltd. — delivery of WhatsApp messages, only if the organisation switches that channel on and only to those who gave their permission. Today it is switched off. If it is switched on, Meta may process the number and the text of the message outside the EEA, under the safeguards of Chapter V of the GDPR.
If we are going to change the list we will tell the organisation's owner at least thirty days in advance. Within that period the owner may object in writing. If the owner objects and there is no other reasonable way to provide the service, either party may terminate this agreement.
Help with people's rights
People's rights — access, rectification, erasure, portability, objection, restriction and withdrawal of consent — are exercised before the organisation, which is the controller. Our job is to make it possible for it to handle them:
- The organisation consults and corrects contacts and records from its own panel, ends a participation and revokes a consent.
- Abra today has no export and no final erasure from the panel. Both are requested from us at privacidad@profblu.com from the owner's email and we carry them out ourselves.
If a person's request reaches us, we do not answer it on the organisation's behalf: we pass it on without undue delay and help with whatever is needed.
If there is a security breach
If we detect a security breach affecting a mission's data, we will tell the organisation without undue delay as soon as we become aware of it, at its owner's email, with what we know: what has happened, which data and how many people it affects, what consequences we foresee and what we are doing.
The 72 hours to notify the supervisory authority run for the organisation, which is the controller; our obligation is to warn it in time and to give it whatever it needs to meet that deadline.
Information and verification
The organisation may ask us in writing for the information necessary to verify that we comply with this contract, and we provide it within one month. It may also request an audit; it is agreed with reasonable notice, no more than once a year unless there has been an incident, is carried out without putting other organisations' data at risk and is at the expense of whoever requests it.
What happens when this ends
- Closing a mission does not delete its data: it remains stored and inactive.
- Final erasure happens at the organisation's request, at privacidad@profblu.com from its owner's email. It is done, except for what the law requires to be kept and the audit trail, which carries no contact details.
- Before deleting, if the organisation asks for it, we hand it a copy of its data in a machine-readable format.
What is the organisation's part
As controller, the organisation undertakes to:
- Have a legal basis for every piece of data it enters and be able to demonstrate it.
- Inform people of what it keeps about them, why and with whom, and draft its mission's consent with that content. The text of the consent is its own: Abra prints it and keeps it in custody, it does not write it.
- Enter only the data it needs, and keep it accurate and up to date.
- Answer for the data of minors as stated above.
- Note a person's WhatsApp permission only if that person gave it.
- Look after its team's access.
- Not run a mission with real data in a demonstration environment.
Liability
Each party answers for its own part: the organisation for what it decides to process and for the instructions it gives, and we for complying with this contract and for what our sub-processors do.
Changes to this agreement
If we change this document, we change its revision date and give notice sufficiently in advance.
Governing law
Italian law applies, being the law of the owner's domicile, with the GDPR above it. If the organisation operates in a country with its own data protection law — in Argentina, Ley 25.326 —, it answers for complying with it.