Last updated: 2026-06-16

Data Processing Agreement (DPA)

This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of personal data carried out by BinaryCode srl ("Processor") on behalf of the Customer ("Controller") in connection with the use of the Bi-Rank platform, pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR").

1. Roles

When the Customer (e.g. an agency) uses the platform to process personal data of its own clients or third parties, the Customer is the Data Controller and BinaryCode srl is the Data Processor. BinaryCode srl processes such data only on the documented instructions of the Controller, save for legal obligations.

2. Subject, duration, nature and purpose

3. Processor obligations

BinaryCode srl, as Processor:

a) processes data only on the documented instructions of the Controller; b) ensures persons authorised to process are bound by confidentiality; c) implements appropriate security measures under Art. 32 GDPR (encryption in transit, password hashing, access controls, multi-tenant isolation, security logs); d) complies with the conditions for engaging sub-processors (section 4); e) assists the Controller, as far as possible, in responding to data subject requests; f) assists the Controller with security, breach notification and impact assessment obligations (Art. 32-36 GDPR); g) at the Controller's choice, deletes or returns the data at the end of the service, save for legal retention obligations; h) makes available the information needed to demonstrate compliance and allows reasonable audits.

4. Sub-processors

The Controller authorises the Processor to engage the sub-processors needed to deliver the service, listed in the Privacy Policy ("Processors and third parties" section). The Processor imposes equivalent data protection obligations on sub-processors and informs the Controller of significant changes, allowing objection on legitimate grounds.

5. Personal data breaches

The Processor informs the Controller without undue delay after becoming aware of a personal data breach, providing information useful to enable the Controller to comply with Art. 33-34 GDPR.

6. Transfers outside the EU

Any transfers to third countries occur only with adequate safeguards under Chapter V of the GDPR (e.g. standard contractual clauses).

7. Duration and effect

This DPA is effective for the entire duration of the processing carried out on behalf of the Controller and prevails, on data protection matters, over any conflicting clauses of the Terms of Service.

8. Contacts

Processor: BinaryCode srl — Via S. Carlo 157, 81100 Caserta (CE), Italia — privacy@binary-code.it.

Last updated: 2026-06-16.