BuildHype
Product Configurators Integrations How it works Pricing
Log in Get Started
Data protection

Data Processing Agreement

This Data Processing Agreement governs the processing carried out by BuildHype on behalf of its clients in connection with the provision of the services.

Last updated: 23 August 2026 Data Processor: Schermo 33 S.r.l.
Contents Scope Privacy roles Client instructions Security Sub-processors Transfers Data subject rights Data breach GDPR assistance Return and deletion Audits Processing details Security measures

1. Subject matter and scope

This Data Processing Agreement (“DPA”) supplements the BuildHype Terms of Service when Schermo 33 S.r.l. processes personal data on behalf of a client in providing the BuildHype services.

In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data on behalf of the client, this DPA prevails.

2. Parties and privacy roles

The client determines the purposes and essential means of processing personal data entered, collected or managed through BuildHype and normally acts as data controller.

Schermo 33 S.r.l., Via Prisciano 72, 00136 Rome (RM), Italy, VAT No. IT08373631004, acts as data processor to the extent that it processes such data exclusively on behalf of the client.

When Schermo 33 S.r.l. processes data for its own purposes, such as account management, billing, security, legal compliance or direct commercial relationships, such processing is governed by the BuildHype Privacy Policy.

3. Processing on client instructions

BuildHype processes personal data exclusively on the basis of the client’s documented instructions, including those arising from use and configuration of the service, unless a legal obligation requires different processing.

The client is responsible for the lawfulness of its instructions, the legal basis for processing, the notices provided to data subjects and the accuracy of data entered into the platform.

BuildHype informs the client if it believes that an instruction violates applicable data protection law, to the extent permitted by law.

4. Confidentiality

Persons authorized by BuildHype to process personal data are bound by appropriate confidentiality obligations and may access data only to the extent necessary to perform their respective duties.

5. Security of processing

BuildHype adopts technical and organizational measures appropriate to the risk, taking into account the nature of the data, the context of processing, the state of the art and risks to the rights and freedoms of natural persons.

Measures may include access controls, credential management, communications protection, logical separation of client data, logging, backups, system updates and measures designed to ensure the confidentiality, integrity and availability of the service.

6. Sub-processors

The client authorizes BuildHype to engage sub-processors where necessary to provide the service. BuildHype requires sub-processors to comply with data protection obligations consistent with those applicable to the processing entrusted to them.

Depending on the features of the service used by the client, BuildHype may engage external providers that process personal data on behalf of Schermo 33 S.r.l.

  • Aruba, for hosting, infrastructure and technical operation of the platform, to the extent that those services involve processing personal data on behalf of BuildHype.
  • DeepSeek, for processing requests submitted to AI assistance features when those features are used.
  • SerpApi, when an authorized AI feature requires access to results or information available on the web.
  • any providers of email, security, backup or technical infrastructure services used by BuildHype to provide the service.

Other services, including Stripe, Google, Microsoft, Apple, Shopify and other integrated e-commerce platforms, may act as independent controllers, processors or in other roles depending on the specific processing and the relationship established directly with the client.

BuildHype keeps its sub-processor arrangements up to date and applies data protection obligations consistent with this DPA to parties that process data on its behalf.

7. International transfers

Where processing involves the transfer of personal data outside the European Economic Area to a country not recognized as adequate, BuildHype uses a valid transfer mechanism under applicable law, including, where relevant, the Standard Contractual Clauses approved by the European Commission.

BuildHype requires its sub-processors to adopt equivalent safeguards when carrying out international transfers subject to such requirements.

8. Data subject requests

Taking into account the nature of the processing, BuildHype assists the client, as far as reasonably possible, in responding to requests by data subjects to exercise rights provided by applicable law.

If BuildHype receives a request directly relating to data processed exclusively on behalf of the client, it may direct the data subject to the client, unless otherwise required by law.

9. Personal data breaches

In the event of a personal data breach involving data processed on behalf of the client, BuildHype informs the client without undue delay after becoming aware of it and provides the reasonably available information necessary to support applicable notification obligations.

10. Assistance with client obligations

Taking into account the nature of the processing and the information available, BuildHype provides reasonable assistance to the client in relation to applicable obligations concerning security, breach notification, data protection impact assessments and prior consultations with supervisory authorities.

11. Return and deletion of data

Upon termination of the services, at the client’s request and subject to legal retention obligations, BuildHype deletes or makes inaccessible the personal data processed on behalf of the client in accordance with technical procedures and within the time reasonably necessary to complete deletion, including any backup cycles.

Unless legal obligations or documented client instructions require otherwise, personal data processed on behalf of the client is normally deleted or made inaccessible within 90 days after termination of the service. Any residual copies in backups are deleted according to normal backup rotation cycles.

12. Information and audits

BuildHype makes available to the client the information reasonably necessary to demonstrate compliance with the obligations applicable to a data processor.

Any audits or reviews requested by the client must be proportionate, agreed in advance, conducted without compromising security, confidentiality or other clients’ data and, where appropriate, rely primarily on documentation and assessments already available.

13. Responsibilities of the parties

Each party is responsible for complying with the obligations assigned to its role under applicable law. The client is responsible for the data it chooses to process through BuildHype, the purposes pursued and the instructions it provides.

The limitations of liability set out in the Terms of Service also apply to this DPA to the extent permitted by data protection law.

14. Duration

This DPA remains effective for as long as BuildHype processes personal data on behalf of the client and continues to apply, with respect to the relevant obligations, until such data has been deleted or returned.

Annex 1 — Details of processing

Subject matter Provision of the BuildHype platform and features configured by the client.
Duration For the duration of the contractual relationship and any subsequent period necessary for deletion or retention required by law.
Nature of processing Collection, recording, organization, storage, consultation, use, technical transmission, modification, extraction, deletion and other operations necessary to provide the service.
Purpose Provide configurators, editor, accounts, e-commerce integrations, AI support and other BuildHype features requested by the client.
Data subjects Client users and collaborators, store end customers and other persons whose data is entered or processed by the client through BuildHype.
Categories of data Identification and contact data, including name, email and phone number; account data; technical data such as IP address, user agent and request source; data relating to product configurations, quote requests, notes and content provided by the client or its end users; and other personal data that the client chooses to process through the service.
Special categories of data BuildHype is not designed to request special categories of personal data under Article 9 GDPR. The client should not enter such data unless strictly necessary, supported by a valid legal basis and covered by a specific agreement.

Annex 2 — Technical and organizational measures

Depending on the service and the risk, BuildHype applies reasonable measures that may include:

  • authentication and authorization controls;
  • least-privilege access for administrative accounts;
  • protection of credentials and application secrets;
  • logical separation of client data;
  • protection of communications through secure protocols;
  • logging and monitoring of technical and security events;
  • appropriate backup and recovery procedures;
  • updating and maintenance of software components;
  • procedures for managing security incidents;
  • assessment of providers that process personal data on behalf of BuildHype.

15. Contact

For requests relating to this DPA: info@buildhypeapp.com.

This DPA should be read together with the Terms of Service and the Privacy Policy of BuildHype.

BuildHype

Guided product configuration for modern e-commerce.

Product Integrations Pricing Guide Log in
Privacy Cookie Terms DPA Contact
© 2026 BuildHype. All rights reserved.
Select language
English Italiano Français Deutsch Español Nederlands Polski Português Română Čeština Slovenčina Magyar Български Ελληνικά Hrvatski Slovenščina Svenska Dansk Suomi Eesti Latviešu Lietuvių Gaeilge Malti Norsk Íslenska Українська Srpski Bosanski Македонски Shqip Русский