Data Processing Agreement
This Data Processing Agreement governs the processing carried out by BuildHype on behalf of its clients in connection with the provision of the services.
1. Subject matter and scope
This Data Processing Agreement (“DPA”) supplements the BuildHype Terms of Service when Schermo 33 S.r.l. processes personal data on behalf of a client in providing the BuildHype services.
In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data on behalf of the client, this DPA prevails.
2. Parties and privacy roles
The client determines the purposes and essential means of processing personal data entered, collected or managed through BuildHype and normally acts as data controller.
Schermo 33 S.r.l., Via Prisciano 72, 00136 Rome (RM), Italy, VAT No. IT08373631004, acts as data processor to the extent that it processes such data exclusively on behalf of the client.
When Schermo 33 S.r.l. processes data for its own purposes, such as account management, billing, security, legal compliance or direct commercial relationships, such processing is governed by the BuildHype Privacy Policy.
3. Processing on client instructions
BuildHype processes personal data exclusively on the basis of the client’s documented instructions, including those arising from use and configuration of the service, unless a legal obligation requires different processing.
The client is responsible for the lawfulness of its instructions, the legal basis for processing, the notices provided to data subjects and the accuracy of data entered into the platform.
BuildHype informs the client if it believes that an instruction violates applicable data protection law, to the extent permitted by law.
4. Confidentiality
Persons authorized by BuildHype to process personal data are bound by appropriate confidentiality obligations and may access data only to the extent necessary to perform their respective duties.
5. Security of processing
BuildHype adopts technical and organizational measures appropriate to the risk, taking into account the nature of the data, the context of processing, the state of the art and risks to the rights and freedoms of natural persons.
Measures may include access controls, credential management, communications protection, logical separation of client data, logging, backups, system updates and measures designed to ensure the confidentiality, integrity and availability of the service.
6. Sub-processors
The client authorizes BuildHype to engage sub-processors where necessary to provide the service. BuildHype requires sub-processors to comply with data protection obligations consistent with those applicable to the processing entrusted to them.
Depending on the features of the service used by the client, BuildHype may engage external providers that process personal data on behalf of Schermo 33 S.r.l.
- Aruba, for hosting, infrastructure and technical operation of the platform, to the extent that those services involve processing personal data on behalf of BuildHype.
- DeepSeek, for processing requests submitted to AI assistance features when those features are used.
- SerpApi, when an authorized AI feature requires access to results or information available on the web.
- any providers of email, security, backup or technical infrastructure services used by BuildHype to provide the service.
Other services, including Stripe, Google, Microsoft, Apple, Shopify and other integrated e-commerce platforms, may act as independent controllers, processors or in other roles depending on the specific processing and the relationship established directly with the client.
BuildHype keeps its sub-processor arrangements up to date and applies data protection obligations consistent with this DPA to parties that process data on its behalf.
7. International transfers
Where processing involves the transfer of personal data outside the European Economic Area to a country not recognized as adequate, BuildHype uses a valid transfer mechanism under applicable law, including, where relevant, the Standard Contractual Clauses approved by the European Commission.
BuildHype requires its sub-processors to adopt equivalent safeguards when carrying out international transfers subject to such requirements.
8. Data subject requests
Taking into account the nature of the processing, BuildHype assists the client, as far as reasonably possible, in responding to requests by data subjects to exercise rights provided by applicable law.
If BuildHype receives a request directly relating to data processed exclusively on behalf of the client, it may direct the data subject to the client, unless otherwise required by law.
9. Personal data breaches
In the event of a personal data breach involving data processed on behalf of the client, BuildHype informs the client without undue delay after becoming aware of it and provides the reasonably available information necessary to support applicable notification obligations.
10. Assistance with client obligations
Taking into account the nature of the processing and the information available, BuildHype provides reasonable assistance to the client in relation to applicable obligations concerning security, breach notification, data protection impact assessments and prior consultations with supervisory authorities.
11. Return and deletion of data
Upon termination of the services, at the client’s request and subject to legal retention obligations, BuildHype deletes or makes inaccessible the personal data processed on behalf of the client in accordance with technical procedures and within the time reasonably necessary to complete deletion, including any backup cycles.
Unless legal obligations or documented client instructions require otherwise, personal data processed on behalf of the client is normally deleted or made inaccessible within 90 days after termination of the service. Any residual copies in backups are deleted according to normal backup rotation cycles.
12. Information and audits
BuildHype makes available to the client the information reasonably necessary to demonstrate compliance with the obligations applicable to a data processor.
Any audits or reviews requested by the client must be proportionate, agreed in advance, conducted without compromising security, confidentiality or other clients’ data and, where appropriate, rely primarily on documentation and assessments already available.
13. Responsibilities of the parties
Each party is responsible for complying with the obligations assigned to its role under applicable law. The client is responsible for the data it chooses to process through BuildHype, the purposes pursued and the instructions it provides.
The limitations of liability set out in the Terms of Service also apply to this DPA to the extent permitted by data protection law.
14. Duration
This DPA remains effective for as long as BuildHype processes personal data on behalf of the client and continues to apply, with respect to the relevant obligations, until such data has been deleted or returned.
Annex 1 — Details of processing
| Subject matter | Provision of the BuildHype platform and features configured by the client. |
|---|---|
| Duration | For the duration of the contractual relationship and any subsequent period necessary for deletion or retention required by law. |
| Nature of processing | Collection, recording, organization, storage, consultation, use, technical transmission, modification, extraction, deletion and other operations necessary to provide the service. |
| Purpose | Provide configurators, editor, accounts, e-commerce integrations, AI support and other BuildHype features requested by the client. |
| Data subjects | Client users and collaborators, store end customers and other persons whose data is entered or processed by the client through BuildHype. |
| Categories of data | Identification and contact data, including name, email and phone number; account data; technical data such as IP address, user agent and request source; data relating to product configurations, quote requests, notes and content provided by the client or its end users; and other personal data that the client chooses to process through the service. |
| Special categories of data | BuildHype is not designed to request special categories of personal data under Article 9 GDPR. The client should not enter such data unless strictly necessary, supported by a valid legal basis and covered by a specific agreement. |
Annex 2 — Technical and organizational measures
Depending on the service and the risk, BuildHype applies reasonable measures that may include:
- authentication and authorization controls;
- least-privilege access for administrative accounts;
- protection of credentials and application secrets;
- logical separation of client data;
- protection of communications through secure protocols;
- logging and monitoring of technical and security events;
- appropriate backup and recovery procedures;
- updating and maintenance of software components;
- procedures for managing security incidents;
- assessment of providers that process personal data on behalf of BuildHype.
15. Contact
For requests relating to this DPA: info@buildhypeapp.com.
This DPA should be read together with the Terms of Service and the Privacy Policy of BuildHype.































