Data processing agreement

This agreement governs the personal data that Studio 09 S.r.l., with its registered office at Via Pietro Borgognoni 15, 51100 Pistoia (PT), partita IVA (Italian VAT number) 01710080472 (‘we’), processes on behalf of the Customer when providing DIGO Email. It is the agreement required by Article 28 of Regulation (EU) 2016/679 (‘GDPR’). It forms part of the terms of service and is accepted upon registration. The details of the parties are set out in Annex I.

1. Subject matter, roles and precedence

For the contacts’ data that it uploads or collects with DIGO Email, the Customer is the controller and we are the processor.

If the Customer uses the service on behalf of third parties, for example as an agency, it warrants that it holds their mandate and their instructions, and it is liable accordingly. In that case the Customer is the processor and we are a sub-processor, under the same terms as this agreement (Article 28(2) and (4) GDPR). We take instructions only from the Customer.

This agreement does not cover the data of the Customer and its users (account, logins, payments, support): for these we are the controller, as described in the privacy notice.

If this agreement and the terms of service conflict, this agreement prevails as regards data protection.

2. Description of the processing

The nature, purpose, duration, data subjects and categories of data are described in Annex II.

3. The Customer’s instructions

We process the data only on the documented instructions of the Customer. The instructions are:

  • this agreement and the terms of service;
  • the Customer’s actions and settings in the dashboard, in the app, via the API and through the connected integrations (plugin for WordPress and WooCommerce, digo.sale);
  • written instructions sent to privacy@digo.email, where compatible with the operation of the service.

If the law requires us to carry out different processing, we inform the Customer before proceeding, unless that law itself prohibits us from doing so.

If an instruction appears to us to infringe the GDPR or other data protection rules, we inform the Customer immediately. We may suspend its execution until the Customer amends it or clarifies its lawfulness.

We do not transfer data outside the European Economic Area without the Customer’s instructions and without the safeguards described in section 8.

4. How we use the data

We use the contacts’ data only to provide the service. The following uses also form part of the service:

  • preventing abuse and protecting email deliverability: for each account we calculate the bounce rate and the spam complaint rate and, above the thresholds shown in the dashboard, we suspend sending from that account;
  • counting the emails sent, in order to deduct credits;
  • providing support, ensuring security and complying with legal obligations: our authorised staff access only the data needed at that time.

Except as described below for page measurement, we do not use the contacts’ data for our own purposes or for those of third parties, we do not sell them and we do not use them across different accounts. Each account has its own contacts and its own suppression list.

Reports shared via a public link are published on the Customer’s instructions, and the Customer may revoke them at any time. They show aggregate campaign figures and the links clicked, without data on individual contacts.

Measurement on DIGO Email pages. All DIGO Email pages load Google Tag Manager, which in turn loads Google Analytics 4, other Google measurement and advertising tags configured in the container, and the cookie banner managed with Consentio. This also applies to the dashboard and to the public pages seen by contacts: sign-up form, confirmation, unsubscribe, outcome messages and shared reports. We use these tools to measure the use of the website and of the service, as an independent controller, in accordance with the cookie policy. This is not processing carried out on behalf of the Customer. Specifically:

  • Google receives browsing data: page address and title, device, browser and the IP address of the connection;
  • the banner asks everyone who visits the pages, including contacts, for consent. Without consent no analytics cookies are stored, but Google may nevertheless receive cookieless signals (Google’s advanced consent mode);
  • on public pages the page address contains technical codes linked to the contact, such as the unsubscribe code, but not the contact’s email address;
  • in the dashboard, the title of a contact’s record page is the contact’s email address and searches appear in the page address: these data may therefore reach Google.

5. The Customer’s obligations

The Customer, as controller:

  • has a legal basis for each contact: freely given and demonstrable consent or, for its own customers, the limits laid down in Article 130(4) of the Codice Privacy (Italian Personal Data Protection Code). When it imports contacts as subscribers, it confirms that they have agreed to receive its emails, or that they are its customers to whom it writes within those limits, and that they are not purchased addresses or addresses harvested from the web;
  • informs the contacts about the processing (Articles 13 and 14 GDPR). Public forms accept sign-ups only after the Customer has entered in Settings the link to its own privacy notice;
  • informs the contacts that the service measures opens and clicks, by means of an invisible image and tracked links, and that it links orders from connected shops to campaigns; obtains the necessary consents (Articles 122 and 130 of the Codice Privacy). Open and click measurement can be switched off in Settings, under “Track opens and clicks”;
  • if it uses the WordPress plugin to attribute sales to campaigns, manages consent to the digo_c cookie. This is a marketing cookie that the plugin stores on the Customer’s website for 7 days, only if the visitor accepts marketing cookies in a compatible banner; without a compatible banner the cookie remains disabled. The compatible banners are listed on the Integrations page of the dashboard and in the plugin settings, as provided for in Article 7 of the terms of service. The Customer keeps the plugin up to date, configures the banner with the marketing cookie category and lists digo_c in its own cookie policy;
  • does not enter in custom fields, tags, list names or content any data concerning health, ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation, genetic or biometric data (Article 9 GDPR), or data relating to criminal convictions and offences (Article 10 GDPR). The service is not designed for such data;
  • safeguards credentials, two-step verification codes and the keys of connected shops; regenerates from the dashboard any keys it fears may have been exposed, disconnects sites it no longer uses and signs out of the app on devices it no longer uses.

The Customer is liable for the data it uploads and for the instructions it gives us.

6. Confidentiality and security

The persons we authorise to process the data are bound by confidentiality, by contract or by law, and access only the data needed for their tasks.

We apply the technical and organisational measures described in Annex III. We update them when risks or technology change, without reducing the level of protection.

7. Sub-processors

The Customer gives us general authorisation to engage sub-processors. The up-to-date list is set out in Annex IV.

  • We impose on each sub-processor, by contract, substantially the same data protection obligations as those in this agreement. We remain fully liable to the Customer for their performance. On request, we provide the Customer with a copy or summary of the relevant agreements, without the confidential parts.
  • We notify the Customer by email at least 30 days before adding or replacing a sub-processor, and we update Annex IV.
  • Within that period the Customer may object on data protection grounds by writing to privacy@digo.email. If we do not find a solution, the Customer may close the account before the change takes effect, with the same refund as provided for in the terms of service for termination following amendments.

8. Place of processing and transfers

The contacts’ data stored in the service remain in the European Union. The application, database and backups are hosted by Hostinger, con server in Germania. Emails are sent from Amazon SES in the Stockholm region (Sweden), including sign-up confirmation emails. Details are set out in Annex IV.

We do not transfer these data outside the European Economic Area without the Customer’s instructions and without the safeguards of Articles 44-46 GDPR. Where a sub-processor belongs to a group headquartered outside the EU, any access from third countries is covered by the standard contractual clauses, or by other safeguards under Articles 45-46 GDPR, provided for in its data processing agreement.

An exception applies to the browsing data collected by the measurement tools referred to in section 4, which we process as an independent controller: Google may also process them outside the European Economic Area, as stated in the cookie policy.

9. Assistance to the Customer

Using the dashboard, the Customer responds to contacts’ requests on its own. It can:

  • search for, view, correct, unsubscribe and delete a contact;
  • view the history and the proof of consent on the contact’s record page;
  • export the contacts to CSV with fields, lists, tags, totals of sends, opens and clicks, and proof of consent (date, IP, page and text).

We provide a contact’s other data, such as individual interactions with campaigns and orders, within 15 days of a request sent to privacy@digo.email.

If a contact approaches us to exercise their rights, we forward the request to the Customer without delay and do not respond on the merits, unless the Customer instructs otherwise.

On request, we provide the Customer with the information available to us concerning the security of processing, the data protection impact assessment and any prior consultation of the Italian Data Protection Authority (Garante per la protezione dei dati personali) (Articles 32-36 GDPR).

10. Personal data breaches

If we become aware of a personal data breach affecting the Customer’s data, we notify the Customer without undue delay and in any event within 48 hours, at the email address of the account’s users. If we do not have all the information immediately, we provide it in phases. The notification states:

  • the nature of the breach, the categories and approximate number of data subjects and of data records concerned;
  • the likely consequences;
  • the measures taken or proposed to address the breach and to mitigate its effects;
  • a contact point from whom information can be obtained.

Notification to the Italian Data Protection Authority and any communication to the contacts are the Customer’s responsibility; we assist the Customer with the information available to us. We document every breach, even where it does not have to be notified.

11. Retention, deletion and export

The data remain in the service for as long as the Customer uses them. Some deletions are automatic:

  • imported files are deleted as soon as they have been processed; those from imports left unfinished, after one day;
  • the details of clicked links, after 24 months;
  • failed queued jobs, which may contain contacts’ data, after 30 days;
  • application logs and backup copies, after 14 days: until then, they may also contain data already deleted in the dashboard.

When the Customer deletes a contact we erase the contact’s personal details, custom fields, lists, tags, history including the proof of consent, automation journeys and carts. The following remain, without the email address:

  • the records of sends already made, with dates of sending, opens and clicks, device type and email client, and the links clicked (the latter for up to 24 months). They serve to keep reports and usage figures accurate;
  • the orders received from connected shops (number, products, amounts), no longer linked to the contact but, if attributed to a campaign, still linked to the send;
  • a cryptographic fingerprint of the address (SHA-256 hash), stored in the send records and, if the contact had unsubscribed, bounced or reported spam, in the suppression list.

The fingerprint serves solely to honour unsubscribes, bounces and complaints even after deletion and to recognise the address if it is entered again. It is neither displayed nor exported. It is pseudonymised data, not anonymous data: anyone who knows the address can recalculate it. It is kept until the account is closed; it is removed from the suppression list if the person signs up again and confirms the subscription.

Rows rejected during an import (row number, value and reason) remain in the import summary until the account is closed.

Suppressed addresses are managed separately for each account. In addition, Amazon SES keeps its own suppression list, common to the entire platform, of addresses that have produced a permanent bounce or a spam complaint: nothing is sent to these addresses, even if the bounce or complaint arose from a send by another customer.

As regards export, section 9 applies.

12. End of processing

Closure by the Customer. The Customer may close the account from Settings or from the app. Logins and sending stop immediately, scheduled campaigns are cancelled and the app is disconnected. The deletion of all the account’s data also starts immediately: contacts, fingerprints, sends, statistics, orders, images and sending domains. It normally completes within a few minutes; if it fails, we repeat it every night and in any case complete it within 30 days. Before closing, the Customer exports from the dashboard whatever it needs (section 9). We provide the other data, such as campaigns, statistics and orders, in a structured format within 30 days, if the Customer requests them before closure as provided for in Article 13 of the terms of service.

Termination for other reasons. If the relationship ends for another reason provided for in the terms of service, for example termination by us or the closure of an account that was never activated or has been suspended for a long time, we notify the Customer by email. For 30 days from the notice, the Customer may export the data from the dashboard or request them from us. We then close the account and delete the data as described above.

Logs, queued jobs and backup copies are deleted within the periods set out in section 11. We keep no other copies of the contacts’ data, unless required by law. On request, we confirm the deletion in writing.

13. Audits and inspections

We make available to the Customer the information necessary to demonstrate compliance with this agreement and with Article 28 GDPR. We allow for and contribute to audits, including inspections, conducted by the Customer or by an independent auditor mandated by the Customer and bound by confidentiality.

  • As a rule, one audit is carried out per year, with at least 30 days’ written notice. Further audits are possible after a data breach or at the request of an authority.
  • An audit begins with a documentary review: written questions and a description of the measures. If that is not sufficient, an inspection follows, during business hours and without access to other customers’ data.
  • The costs of inspections are borne by the Customer, unless non-compliance on our part comes to light.

14. Duration, amendments, liability, governing law and competent court

  • Duration. This agreement remains in force for as long as the contract for the service. The obligations concerning the data continue until the data have been deleted.
  • Acceptance. The Customer accepts this agreement upon registration, together with the terms of service. The version and date of acceptance are recorded in the account.
  • Amendments. The rules of the terms of service apply: notice at least 30 days in advance, except for amendments required by law or urgently needed for security reasons, and the option to close the account with the refund provided for therein.
  • Liability. Each party is liable for its own obligations. Between the parties, the limitations of liability in the terms of service apply, to the extent permitted by law. These limitations do not reduce the rights of data subjects or the liability towards them under Article 82 GDPR.
  • Governing law and competent court. Italian law and the competent court provided for in the terms of service apply.

Annex I. The parties

PartyDetails
CustomerThe person or organisation that holds the account: for those purchasing as a business, the company, professional or entity stated in the billing details; otherwise, the person stated at registration, with the sender name and address set in Settings. Controller, or processor where acting on behalf of third parties. Contact: the email address of the account’s users.
ProviderStudio 09 S.r.l., Via Pietro Borgognoni 15, 51100 Pistoia (PT), partita IVA 01710080472. Processor, or sub-processor where the Customer acts on behalf of third parties. Data protection contact: privacy@digo.email.
ActivityProvision of the DIGO Email email marketing platform.

Annex II. Description of the processing

ItemDescription
Data subjects
  • The Customer’s contacts: subscribed, pending confirmation, unsubscribed and suppressed.
  • Anyone who signs up through the Customer’s forms or integrations, even if they do not subsequently confirm.
  • The customers of connected shops. Their email address is used solely to recognise an existing contact and is not stored. Orders are stored only if linked to a contact or to a click on a campaign; carts only if linked to a contact.
  • Any persons appearing in the texts and images uploaded by the Customer.
Categories of data
  • Contact details and profile: email, first name, surname, custom fields chosen by the Customer (text, number or date, for example a date of birth), lists, tags, status and source.
  • Consent and history: date, IP, browser, page and text of the consent; subscription confirmation; unsubscribes with date and IP; for imports, the confirmation given by the Customer regarding the origin of the contacts, with date and user.
  • Sends and interactions: date and outcome of each send, bounces and spam complaints, opens and clicks with dates and counts, links clicked, device type and email client, automatic opens (for example those generated by Apple Mail Privacy Protection), A/B test variant. We do not record the IP address for opens and clicks.
  • Connected shops: orders (number, status, amounts, products, originating campaign), abandoned carts (products, amounts, link to the cart), the digo_c click code, which attributes a sale to the campaign clicked within the last 7 days.
  • Automations: the contact’s entry into and progress through automated journeys.
  • Content: email texts and images; imported files, deleted after processing; rows rejected from imports.
  • Cryptographic fingerprint (hash) of the address, for suppressions and send logs.
Special categories of dataNone. The Customer must not enter data covered by Articles 9 and 10 GDPR (section 5).
Nature and operationsCollection through forms, API, integrations and imports; recording, organisation into lists and tags, storage and consultation; sending of campaigns, automations, A/B tests, resends to non-openers and test emails; subscription confirmation, handling of unsubscribes, bounces and complaints; measurement of opens and clicks, if enabled; sales attribution and abandoned carts; reports, including shared reports; export and deletion.
PurposeProviding the Customer with the email marketing service, including the uses described in section 4.
FrequencyContinuous, for the entire duration of the contract.
Duration and retentionFor as long as the contract, plus the deletion periods in sections 11 and 12.

Annex III. Technical and organisational measures

AreaMeasure
ConnectionsPages, API and app use HTTPS only. The server instructs browsers always to use HTTPS for one year (HSTS) and sends security headers. Configuration files cannot be reached from the web.
Dashboard accessPasswords stored only as bcrypt hashes. Optional two-step verification with an authenticator app: the secret is encrypted (AES-256), each code is valid only once and recovery codes are stored only as hashes.
Keys and devicesShop API keys are shown only once and can be regenerated or revoked from the dashboard. Keys and app access codes are stored only as SHA-256 hashes. Signing out of the app deletes the code for that device. Changing the password immediately disconnects all of the user’s devices; closing the account disconnects those of all users.
Limits on attemptsRate limits on login, two-step verification, registration, password recovery, public forms, API and app. At most one confirmation email per day per address and a daily cap per account. Forms have a hidden field to block bots.
Separation between accountsAll data belong to an account. Users’ requests are filtered by their account and automated operations filter explicitly by account. Suppressions and sending reputation are kept separate for each account. Each sending domain belongs to a single account and is verified in the DNS (DKIM, with DMARC mandatory).
Links in emailsConfirmation links are signed and valid for 7 days. Tracked links are signed and cannot lead to addresses other than those entered by the Customer. Unsubscribe links and report links use random codes; shared reports can be revoked from the dashboard.
MinimisationFor opens and clicks we do not record the IP address, only device type and email client. Orders and carts are kept only if linked to a contact or a campaign. Automatic deletions as set out in section 11.
Abuse controlNew accounts are verified before they can send. Sending is automatically suspended above the bounce and complaint thresholds. Notifications from Amazon and Stripe are accepted only with a verified signature.
BackupNightly copy of the database, uploaded images and configuration, with an integrity check. Copies are kept for 14 days on the same server, with access restricted to the system administrator. There is not yet a copy in another location.
LogsApplication logs are rotated daily and deleted after 14 days.
StaffAccess to data only for authorised persons bound by confidentiality, with personal credentials. Only the system administrator of Studio 09 has access to the server and the database.

Annex IV. Sub-processors

ProviderServiceDataLocationSafeguards
Amazon Web Services EMEA SARL, LuxembourgAmazon SES (email sending) and Amazon SNS (bounce and complaint notifications)Recipients’ email addresses, email content with personalised data, delivery outcomes, bounces and complaintsEU, eu-north-1 region, Stockholm (Sweden)AWS data processing agreement (AWS GDPR Data Processing Addendum), with standard contractual clauses for any transfers
HostingerApplication server, database and backup copiesAll the data described in Annex IIEU, GermanyThe provider’s data processing agreement, Article 28 GDPR

List updated as at 3 October 2026.

The following are not sub-processors, because they do not process contacts’ data on behalf of the Customer:

  • Google (Tag Manager and Analytics 4) and Consentio: measurement and consent tools that we use as an independent controller on DIGO Email pages (section 4);
  • Stripe: collects the Customer’s payments and processes only the Customer’s payment data;
  • Expo: sends the app notifications to the Customer’s devices. Notifications contain only campaign names and statuses, account status and aggregate figures, never contacts’ data.

These providers are described in the privacy notice and in the cookie policy.

Version in force from 5 October 2026.

Terms of servicePrivacy policyCookie policyData processing agreementAccount deletionCookie preferences
Italiano English Español Français Deutsch