Data Processing Agreement
The Article 28 GDPR terms on which we process personal data on your behalf. They apply automatically — you do not have to sign anything.
Last updated: 2026-08-19
1. Scope and roles
This agreement ("DPA") forms part of the Terms of Service between you ("Controller") and Mediazione Italia S.r.l. ("Processor", "we"). It governs the personal data we process on your behalf when you use AwrAiter — the content of your channels, your audience's data and anything else you bring into the Service.
For the data we process about you as our customer — your account, your billing, our logs — we are the controller and our Privacy Policy applies instead. Where the two overlap, this DPA governs the processing done on your instructions.
This DPA takes effect when you start using the Service and lasts as long as we process data for you. A copy signed by us is available on request; the terms are identical.
2. What is processed
| Subject matter | provision of the AwrAiter service: content planning, drafting, scheduling, publishing to Telegram, statistics and AI assistance |
| Duration | for as long as your account exists, plus the retention periods in section 7 of the Privacy Policy |
| Nature and purpose | storage, structuring, retrieval, transmission to Telegram and to AI providers, generation of derived text, erasure |
| Types of personal data | identifiers and profile data of your team members; any personal data contained in the content you create or import; identifiers of channels and their public statistics |
| Categories of data subjects | your team members and the people whose data appears in the content you process |
| Special categories | none — the Service is not intended for them and you undertake not to introduce them |
3. Our obligations
- We process the data only on your documented instructions — using the Service is such an instruction — unless EU or member-state law requires otherwise, in which case we tell you before processing unless the law forbids it.
- We ensure that everyone authorised to process the data is bound by confidentiality.
- We apply the technical and organisational measures described in section 10 of the Privacy Policy, appropriate under Art. 32 GDPR.
- We assist you, as far as we reasonably can, with data subject requests, with data protection impact assessments and with prior consultation of the authority (Arts. 32-36 GDPR).
- We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information we hold at the time.
- We make available the information needed to demonstrate compliance and allow audits — see section 7.
- On termination we delete your data as described in section 6.
4. Sub-processors
You give us a general authorisation to engage sub-processors. The current list, with the role and location of each, is published at awraiter.ai/legal/subprocessors and forms part of this DPA.
We impose on every sub-processor the same data protection obligations we owe you, and we remain fully liable to you for their performance. Before adding or replacing a sub-processor we update that page and announce the change in the panel at least 30 days in advance. If you have a reasonable objection on data protection grounds, tell us within those 30 days: we will look for an alternative and, if there is none, you may terminate the affected part of the Service and get back the unused part of what you paid.
5. International transfers
Our servers are in Germany. Where a sub-processor is outside the EEA, the transfer rests on the European Commission's Standard Contractual Clauses (Decision 2021/914, module three — processor to processor), or on an adequacy decision where one covers the recipient, together with the supplementary measures required by Arts. 44 ff. GDPR.
For personal data subject to UK law, the Clauses apply as amended by the ICO's International Data Transfer Addendum. For data subject to the Swiss FADP, the Clauses apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner, with references to the GDPR read as references to the FADP. Copies are available on request.
6. Return and deletion
You can export your data at any time from Settings → Account → Download my data, and erase it from Settings → Account → Delete account — deletion removes the account, and where you are the last owner, the team's channels, plans, posts, reports and uploaded files.
If you simply stop using the Service without deleting the account, the data stays available to you. Residual copies persist in rotating backups for up to 30 days after deletion. We keep nothing else unless a legal obligation requires it.
7. Audits
On request we provide the information you need to verify our compliance with this DPA. If that is not enough, you may audit us, or appoint an independent auditor who is not our competitor, once every twelve months, on 30 days' notice, during business hours, without disrupting the Service, and under confidentiality. You bear the cost unless the audit reveals a material breach on our side.
8. Order of precedence and contact
If this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.
Data protection contact: privacy.mediazioneitalia@gmail.com — Mediazione Italia S.r.l., Largo Guido Donegani 2, 20121 Milano (MI), Italia, PEC mediazioneitaliasrl@legalmail.it.