Last updated: 2026-06-16
Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of personal data carried out by BinaryCode srl ("Processor") on behalf of the Customer ("Controller") in connection with the use of the Bi-Rank platform, pursuant to Art. 28 of Regulation (EU) 2016/679 ("GDPR").
1. Roles
When the Customer (e.g. an agency) uses the platform to process personal data of its own clients or third parties, the Customer is the Data Controller and BinaryCode srl is the Data Processor. BinaryCode srl processes such data only on the documented instructions of the Controller, save for legal obligations.
2. Subject, duration, nature and purpose
- Subject: provision of the Bi-Rank platform (Piattaforma white-label di GEO (Generative Engine Optimization) per agenzie).
- Duration: for the term of the service agreement.
- Nature and purpose: hosting, processing, analysis and storage of data entered by the Controller for the service's features.
- Types of data: identification and contact data, data relating to analysed sites and content, and any other data entered by the Controller.
- Categories of data subjects: end clients, contacts and representatives of the Controller.
3. Processor obligations
BinaryCode srl, as Processor:
a) processes data only on the documented instructions of the Controller; b) ensures persons authorised to process are bound by confidentiality; c) implements appropriate security measures under Art. 32 GDPR (encryption in transit, password hashing, access controls, multi-tenant isolation, security logs); d) complies with the conditions for engaging sub-processors (section 4); e) assists the Controller, as far as possible, in responding to data subject requests; f) assists the Controller with security, breach notification and impact assessment obligations (Art. 32-36 GDPR); g) at the Controller's choice, deletes or returns the data at the end of the service, save for legal retention obligations; h) makes available the information needed to demonstrate compliance and allows reasonable audits.
4. Sub-processors
The Controller authorises the Processor to engage the sub-processors needed to deliver the service, listed in the Privacy Policy ("Processors and third parties" section). The Processor imposes equivalent data protection obligations on sub-processors and informs the Controller of significant changes, allowing objection on legitimate grounds.
5. Personal data breaches
The Processor informs the Controller without undue delay after becoming aware of a personal data breach, providing information useful to enable the Controller to comply with Art. 33-34 GDPR.
6. Transfers outside the EU
Any transfers to third countries occur only with adequate safeguards under Chapter V of the GDPR (e.g. standard contractual clauses).
7. Duration and effect
This DPA is effective for the entire duration of the processing carried out on behalf of the Controller and prevails, on data protection matters, over any conflicting clauses of the Terms of Service.
8. Contacts
Processor: BinaryCode srl — Via S. Carlo 157, 81100 Caserta (CE), Italia — privacy@binary-code.it.
Last updated: 2026-06-16.