Data processing agreement

2026-09-16

Roles

The business using Ricevia is the data controller for the personal data of its own customers. BertoProduction, as the operator of this installation, is the data processor and acts only on the documented instructions of the controller.

Subject matter and duration

Processing covers the handling of enquiries, appointment booking and the CRM records that result, for as long as the subscription is active plus the export window after termination.

Categories of data and data subjects

Data subjects: the controller’s prospective and existing customers. Categories: identification and contact data, conversation content, appointment details, and technical data such as IP address.

Sub-processors

The controller authorises the sub-processors listed in the privacy policy. We will give reasonable notice before adding or replacing a sub-processor, and the controller may object on reasonable data-protection grounds.

Security measures

We apply technical and organisational measures appropriate to the risk, including:

  • Encryption in transit for all traffic, and encryption at rest for third-party credentials.
  • Password hashing with scrypt and per-session tokens stored only as hashes.
  • Strict logical separation between customers, enforced at the data-access layer and covered by automated tests.
  • Role-based access control, audit logging of administrative actions, and rate limiting.
  • Automated retention and deletion according to the controller’s configured period.

Assistance and breach notification

We assist the controller with data subject requests through the export and erasure tools in the product. We will notify the controller without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach.

Return and deletion

On termination the controller can export all data for 30 days, after which it is deleted from live systems and from backups within the backup rotation period.

Data processing agreement · Ricevia