Customer Data Processing Addendum
This Data Processing Addendum ("DPA") applies where Enzo Tedeschi Web Developments ("ETW", "we") processes personal data on Customer's behalf as part of hosting and operating Customer's Site — for example, information a Site visitor submits through a contact form or booking request. For this data, Customer is the data Controller and ETW is the data Processor. This DPA is incorporated by reference into our Terms of Service.
Subject matter and duration
The subject matter of processing is the technical hosting and operation of Customer's Site, including any forms or booking features Customer enables on it. Processing continues for the term of Customer's subscription, plus any post-termination retention period described in our Privacy Policy.
Categories of data subjects
Visitors to Customer's Site who submit information through a contact form, booking request, or similar feature Customer has enabled.
Categories of personal data
Name, email address, and any message or booking details a visitor submits. ETW does not process payment card data on Customer's behalf — Site visitors are not charged through the platform today.
Subprocessors
ETW uses the following subprocessors to provide the Services:
- DigitalOcean — infrastructure hosting for Customer's Site;
- Cloudflare — DNS, CDN, and edge routing; and
- SendGrid — delivery of transactional emails generated by Customer's Site (e.g. contact-form or booking notifications).
ETW will provide reasonable advance notice before adding or replacing a subprocessor that will process personal data under this DPA.
Security measures
ETW isolates each hosting account using CloudLinux LVE containers, encrypts sensitive credentials at rest, and restricts server access to authorized ETW personnel.
Assistance and incident notification
ETW will provide reasonable assistance to Customer in responding to a data subject's access, deletion, or portability request concerning data collected through Customer's Site, and will notify Customer without undue delay upon confirming a security incident affecting that data.
Data location
Personal data covered by this DPA is processed and stored on infrastructure located in the United States.