Data Processing Agreement — DPA

Service: Minerva — Last updated: 25 July 2026

This is a courtesy translation of the Italian original. The Italian version is the only binding text: in case of any discrepancy, and for the purposes of interpretation, the Italian version prevails. The Agreement is governed by Italian law, with jurisdiction as set out in article 13 of the Stabilidea General Terms and Conditions.

This agreement (the "DPA") is entered into between Stabilidea S.r.l., with registered office in Istrana (TV), via Don Giovanni Gattoli 16, and operating office in Montebelluna (TV), via Contea 60, Italian tax code and VAT number 05389850263 (the "Processor"), and the party subscribing to the Minerva service, as identified by the registration and billing details of its account (the "Controller"), together the "Parties".

WHEREAS the Parties are bound by the Terms and Conditions of the Minerva service and by the General Terms and Conditions of Stabilidea S.r.l. (together, the "Agreement"); whereas performance of the Agreement entails the processing of personal data controlled by the Controller by the Processor; and whereas article 10 of the General Terms and Conditions does not govern such processing,

THE CONTROLLER APPOINTS THE PROCESSOR as processor pursuant to article 28 of Regulation (EU) 2016/679 ("GDPR"), on the terms set out below. Terms not otherwise defined have the meaning given to them by the GDPR.

1. Subject matter, nature, purpose and duration

1. The processing concerns the personal data provided to the Minerva service (the "Service"), a network-accessible software platform that assists the Controller in conceiving, drafting, organising and publishing professional content intended for professional communication platforms, by means of artificial intelligence systems applied to the content provided.

2. The nature of the processing includes the collection, recording, organisation, storage, consultation, processing, retrieval and erasure operations necessary to provide the Service, as well as the development, maintenance and technical management activities set out in the Agreement. The purpose is solely the performance of the Agreement.

3. The personal data processed include: identification and professional contact details of authorised users; professional profile data connected by the user; connection data and platform usage metadata; company, tax and billing data; access credentials for third-party services activated by the Controller, stored in encrypted form; content provided to the platform, including documents, images, meeting transcripts and free-text material, together with the content generated from it. The data subjects are the users authorised by the Controller, ordinarily its staff or collaborators; the persons mentioned or depicted in the content provided, including participants in meetings whose transcripts are imported; the Controller's administrative contacts; and, where the Controller operates as an agency, the users and contacts of its client organisations.

4. The Service does not require the provision of data referred to in articles 9 and 10 of the GDPR. Where such data is provided through free-text fields or uploaded documents, the Controller warrants that an appropriate legal basis exists.

5. The Controller warrants that it has obtained, or has caused its client organisations to obtain, appropriate authority to provide the Service with documents, images and meeting transcripts relating to persons other than the user providing them and for the processing of that material through the Service; that the data subjects have received the information required by articles 13 and 14 of the GDPR, including information on the use of artificial intelligence systems; and it holds the Processor harmless from any third-party claim in this respect.

6. The processing lasts as long as the Agreement, including its maintenance and support phases.

2. The Controller's instructions

1. The Processor processes personal data solely for the performance of the Agreement and in accordance with the Controller's documented instructions, consisting of the Agreement, this DPA and any further written instructions from the Controller, including with regard to transfers to third countries.

2. It constitutes a documented instruction of the Controller to make use of the third-party services necessary for the Service to function and activated using the credentials of the Controller or of its users: the connection of the user's professional profile, for authentication to the Service and for publication of approved content; and the automatic meeting-minuting services, whose transcripts are imported by means of access keys provided by the Controller or its users. Those services are not sub-processors of the Processor; their selection, configuration and the related contractual relationships remain with the Controller.

3. The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other data protection provisions.

3. The Processor's obligations

1. The Processor warrants that the persons authorised to process the data are bound by confidentiality and have received adequate instructions, and it maintains the record referred to in article 30(2) of the GDPR.

2. The Processor assists the Controller in responding to requests to exercise data subject rights under Chapter III of the GDPR, replying within 5 working days; where a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay.

3. The Processor assists the Controller in complying with the obligations under articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to it.

4. The Processor makes available to the Controller the information necessary to demonstrate compliance with article 28 of the GDPR. The Controller may verify such compliance by written request for information and documentation, no more than once a year, except in the event of a personal data breach or a request from a supervisory authority.

4. Security measures

1. The Processor adopts the technical and organisational measures required by article 32 of the GDPR, which include: encryption of data in transit using TLS; encryption at rest of objects stored with the content storage provider; daily backups of the database at the relevant provider; encryption of the third-party service credentials supplied by the Controller, using a state-of-the-art authenticated encryption algorithm; access to the Service conditional on authentication through an external identity provider, with no passwords stored by the Processor; logical access control based on authorisation profiles, following the principle of minimisation; logical separation of each Controller's data by means of an organisation identifier applied to read and write operations; segregation of development and production environments; authentication of communications from third-party services by verification of signatures and shared secrets; logging of administrative access and of user management operations; storage of application secrets in environment variables validated at start-up; designation and instruction of the persons authorised to process the data, bound by confidentiality obligations; mandatory two-factor authentication on the working tools of authorised staff; and an internal procedure for managing and notifying personal data breaches.

2. The Processor periodically assesses and updates the adequacy of the measures adopted in the light of evolving risks.

5. Sub-processors

1. The Controller gives the Processor general authorisation to engage sub-processors in the following categories: providers of hosting and IT infrastructure services; providers of cloud content storage services; providers of network, content delivery and traffic protection services; providers of artificial intelligence models, solely for the inference operations necessary to deliver the Service; providers of transactional electronic communication delivery services; and providers of real-time application messaging services.

2. The Processor imposes on its sub-processors, by contract, the same obligations set out in this DPA, remains liable to the Controller for their performance, and gives notice of any addition or replacement 15 days in advance, allowing the Controller to object on legitimate grounds. The current list is made available on written request.

6. Transfers to third countries

1. Personal data is stored on infrastructure located in the European Union. Where specific processing activities entail a transfer to third countries, the Processor ensures that it takes place only where an adequacy decision under article 45 of the GDPR or appropriate safeguards under article 46 are in place, and makes evidence of this available on request.

2. The Processor notifies the Controller in writing of any configuration which, in its opinion, entails transfers without appropriate safeguards.

7. Personal data breach

1. The Processor notifies the Controller of any personal data breach without undue delay and in any event within 48 working hours of becoming aware of it, with the information referred to in article 33(3) of the GDPR to the extent available, and cooperates in containing its effects.

2. The Processor makes no communication to third parties or to data subjects without the prior agreement of the Controller, save where required by law.

8. No training

1. The personal data and content provided by the Controller are not used by the Processor to train, fine-tune or improve artificial intelligence models, whether its own or those of third parties.

2. The Processor configures the services of the artificial intelligence model providers used by the Service accordingly, to the extent this falls within its technical control; settings that depend on the contractual plan and on account configuration remain with whoever subscribed to them.

3. Further obligations arising from Regulation (EU) 2024/1689 are governed by the AI Act Addendum entered into between the Parties.

9. Erasure and return

1. On termination of the Agreement, for whatever reason, the Processor ceases all processing and, at the Controller's option, returns in a commonly used format or permanently erases within 60 days the personal data held on resources within its control, subject to any retention required by law, certifying this in writing on request.

10. Final provisions

1. This DPA is effective for the entire duration of the Agreement and, in the event of conflict with it — including with article 10 of the General Terms and Conditions — prevails as regards data protection matters only.

2. Where the Controller processes personal data, in whole or in part, as a processor on behalf of its own controllers, it declares that it has been authorised by them to engage the Processor, and this DPA applies to the Processor as a sub-processor within the meaning of article 28(4) of the GDPR, with the same obligations as set out in it.

3. This DPA is an appendix to and an integral part of the Agreement and is concluded in writing pursuant to article 28(9) of the GDPR by electronic acceptance of the Agreement on subscribing to the Service, or by express acceptance sent by certified electronic mail. For anything not governed here, the provisions of the Agreement apply, including those on governing law and jurisdiction in article 13 of the General Terms and Conditions.

For any communication concerning this DPA, the Processor can be reached at [email protected].