GDPR & Data Processing Agreement (DPA)
This Data Processing Agreement (DPA) is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") between Skillworks S.r.l. (acting as Data Processor) and the Customer (acting as Data Controller).
1. Subject Matter and Duration
This DPA governs the processing of personal data by Skillworks S.r.l. on behalf of the Customer, within the scope of the provision of the DRIN PRO services. The DPA shall remain in force for the same duration as the service contract.
2. Categories of Data Processed
The Processor processes the following categories of data on behalf of the Controller:
- User identification data (name, email, extension number);
- Communication data (calls, chat, voicemail, recordings);
- Traffic data (CDR, system logs);
- Configuration data (PBX settings, contacts, routing rules).
3. Purposes of the Processing
Data are processed exclusively for the purposes of: providing the UCaaS service, ensuring security, performing backups and disaster recovery, providing technical support, and complying with legal obligations.
4. Instructions of the Controller
The Processor processes the data exclusively in accordance with the Controller's documented instructions, unless required to do so by law. The Controller has the right to modify the instructions at any time.
5. Confidentiality
Persons authorised to process the data are subject to a confidentiality obligation or an appropriate statutory obligation of confidentiality.
6. Security Measures
The Processor implements the following technical and organisational security measures:
- TLS/SRTP encryption for all communications;
- Daily automatic encrypted backups;
- Biometric access to the datacenters;
- Fail2Ban firewall, auto-defense, static defense;
- 24/7/365 monitoring;
- ISO 27001, ISO 27017, ISO 27018 certifications;
- Datacenters in Italy, 100% renewable energy.
7. Sub-processors
The Processor may engage the following sub-processors, all GDPR-compliant:
- Yeastar (P-Series Cloud Edition PBX technology);
- Amazon Web Services (cloud infrastructure);
- OpenAI / Google / ElevenLabs / Amazon (AI services for transcription and synthesis);
- Alperia (renewable energy supply).
The Controller shall be notified of any new sub-processors with 30 days' prior notice.
8. Data Transfers
Data are primarily hosted in Italian datacenters. For third-party AI services, the transfer of data outside the EU takes place exclusively under appropriate safeguards (European Commission Adequacy Decisions, Standard Contractual Clauses).
9. Assistance to the Controller
The Processor assists the Controller in handling data subject requests (access, rectification, erasure, portability) and in notifying personal data breaches within 72 hours.
10. Data Erasure
At the end of the contract, the Processor erases all of the Controller's personal data within 30 days, save for legal retention obligations. It is possible to request data export prior to erasure.
11. Audit
The Controller has the right to carry out inspections (audits) at the Processor's premises, with 30 days' prior notice and in compliance with the datacenter's security measures.
12. Breach Register
The Processor maintains a register of all personal data breaches and notifies the Controller thereof within 24 hours of detection.
Last revision: 11 August 2026