Abra

Data processing agreement

Data Processing Agreement

The Article 28 GDPR contract between the organisation running a mission, which decides what data is kept, and us, who keep it on its behalf.

Last revised:

Incomplete documentSome details are missing and only the owner can provide them. They are marked in the text. Until they are filled in, this document is a draft published transparently, not a final text.

What this document is

It is the contract required by Article 28 of the General Data Protection Regulation when someone processes personal data on someone else's behalf. It binds both parties from the moment the organisation accepts it.

For the data of the account each person signs in to the panel with, we answer as controller, and that is not governed by this document but by the privacy policy.

This agreement is read together with the terms of use, of which it forms part. If anything here conflicts with them, this document prevails as far as personal data is concerned.

Who each party is

Controller: the organisation that opens its space in Abra, with the name and the details recorded in its registration on the platform. It acts through its owner or whoever that person designates.

Processor:

No data protection officer has been appointed: the law does not require one for an activity of this size.

Where and when it is accepted

[how each organisation's acceptance of this agreement is recorded. Today Abra has no sign-up of its own: access is given by agreement with the owner, and the panel does not yet store the date or the version accepted]

Until that exists, the agreement is accepted in writing — by email to legal@profblu.com — before the organisation opens its first mission with real data.

Subject matter, nature and duration

What data, and about whom

Categories of data subjects:

Categories of data, as the application collects them:

Which specific fields are asked for is decided by the organisation: the forms are its own. It must not ask for special categories of data — health, origin, religion, administrative status — unless they are essential for the aid and it has a legal basis for it; Abra has no fields intended for that data.

Minors

When a mission keeps data about minors:

The organisation answers for the person signing truly having that authority.

We only do what the organisation tells us

We process that data solely on the organisation's documented instructions. Its instructions are this contract, the terms of use, the configuration of each mission and everything its people do in the panel.

Therefore:

Confidentiality

Whoever has access to this data is bound by confidentiality, and that obligation survives the end of this agreement. Today, technical access to the database is held by one single person, the owner.

Inside the organisation, who sees what is decided by the organisation itself through the roles it hands out. We enforce that arrangement; we do not choose for it.

Security measures

The ones that actually exist:

And what we do not do, so that nobody assumes it: we do not encrypt field by field inside the database, and there is no external security certification today.

Sub-processors

The organisation gives us general authorisation to use other companies to provide the service. This is the complete list as of today:

If we are going to change the list we will tell the organisation's owner at least thirty days in advance. Within that period the owner may object in writing. If the owner objects and there is no other reasonable way to provide the service, either party may terminate this agreement.

Help with people's rights

People's rights — access, rectification, erasure, portability, objection, restriction and withdrawal of consent — are exercised before the organisation, which is the controller. Our job is to make it possible for it to handle them:

If a person's request reaches us, we do not answer it on the organisation's behalf: we pass it on without undue delay and help with whatever is needed.

If there is a security breach

If we detect a security breach affecting a mission's data, we will tell the organisation without undue delay as soon as we become aware of it, at its owner's email, with what we know: what has happened, which data and how many people it affects, what consequences we foresee and what we are doing.

The 72 hours to notify the supervisory authority run for the organisation, which is the controller; our obligation is to warn it in time and to give it whatever it needs to meet that deadline.

Information and verification

The organisation may ask us in writing for the information necessary to verify that we comply with this contract, and we provide it within one month. It may also request an audit; it is agreed with reasonable notice, no more than once a year unless there has been an incident, is carried out without putting other organisations' data at risk and is at the expense of whoever requests it.

What happens when this ends

  1. Closing a mission does not delete its data: it remains stored and inactive.
  2. Final erasure happens at the organisation's request, at privacidad@profblu.com from its owner's email. It is done, except for what the law requires to be kept and the audit trail, which carries no contact details.
  3. Before deleting, if the organisation asks for it, we hand it a copy of its data in a machine-readable format.

What is the organisation's part

As controller, the organisation undertakes to:

Liability

Each party answers for its own part: the organisation for what it decides to process and for the instructions it gives, and we for complying with this contract and for what our sub-processors do.

Changes to this agreement

If we change this document, we change its revision date and give notice sufficiently in advance.

Governing law

Italian law applies, being the law of the owner's domicile, with the GDPR above it. If the organisation operates in a country with its own data protection law — in Argentina, Ley 25.326 —, it answers for complying with it.