Last updated: 18 September 2026
( Contents )
This Data Processing Agreement (the “DPA”) is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”) between Made in Evolve S.r.l., with registered office at Via Rosalba Carriera 26, 41126 San Damaso, Modena (MO), Italy, tax code and VAT no. 03497200364, REA MO-392876 (“Made in Evolve” or the “Processor”), and the client that has entered into a contract, an offer or an order with Made in Evolve for the provision of services (the “Client” or the “Controller”; jointly, the “Parties”).
The DPA forms an integral part of the Main Agreement and applies whenever Made in Evolve processes personal data on behalf of the Client in the context of store management, CRM and email marketing, system integration, platform development and the Nucleo Platform SaaS. The Parties may supplement it with specific terms agreed in writing.
For the Processing covered by the DPA, the Client acts as Controller and Made in Evolve as Processor. Where the Client is itself a processor acting on behalf of its own client, Made in Evolve acts as sub-processor and the Client warrants that it holds the necessary authorisations.
The DPA does not apply to Processing for which Made in Evolve independently determines purposes and means (data of the Client’s contact persons, invoicing, management of the contractual relationship, the madeinevolve.com website), which is described in the privacy policy.
The subject matter, nature and purpose of the Processing, and the categories of Data Subjects and Personal Data, are described in Annex A. The Processing lasts for the term of the Main Agreement, plus the period required to return or delete Client Data under Section 12.
Made in Evolve does not process full payment card numbers: transactions are handled by the payment service providers chosen by the Client, and Made in Evolve accesses at most the order identifier, outcome, amount and masked references of the payment instrument. Processing of special categories of data (Articles 9 and 10 GDPR) is not envisaged, unless agreed in writing with additional safeguards.
Made in Evolve processes Client Data only on documented instructions from the Client, including with regard to transfers to Third Countries, unless required to do so by Union or Italian law; in that case it informs the Client before Processing, where the law does not prohibit it.
Documented instructions consist of the Main Agreement, this DPA, the configurations set by the Client in Nucleo Platform and in the integrated platforms (for example Shopify and Klaviyo) and any further written instructions. Made in Evolve immediately informs the Client if it considers that an instruction infringes Applicable Law and may suspend its execution pending clarification. Instructions entailing additional effort are subject to a separate commercial agreement.
Made in Evolve ensures that the persons authorised to process Client Data:
Made in Evolve implements the technical and organisational measures set out in Annex B, suitable to ensure a level of security appropriate to the risk pursuant to Article 32 GDPR. The measures are aligned with the principles of ISO/IEC 27001:2022 and of Directive (EU) 2022/2555 (NIS2), adopted on a voluntary basis, and are described in the information security policy.
Made in Evolve may update the measures as threats evolve, provided that the overall level of protection is not reduced. The Client remains responsible for the security of its own systems, the credentials of its own users and the configuration of the platforms it manages directly.
The Client grants Made in Evolve a general authorisation to engage the Sub-processors listed in Annex C. Made in Evolve imposes on each of them, by contract, data protection obligations substantially equivalent to those of this DPA and remains fully liable to the Client for the performance of the Sub-processor.
Any addition or replacement is notified to the Client with at least 30 days’ notice, by updating Annex C and by email to the Client’s contact person. Within that period the Client may object on reasonable, documented data protection grounds; if no solution is agreed in good faith, the Client may terminate without penalty the part of the Services affected by the new Sub-processor.
Client Data is primarily stored on DigitalOcean infrastructure in the Frankfurt (Germany) data centre. Where Processing involves a transfer of Client Data to a Third Country, Made in Evolve ensures that the transfer takes place:
On request, Made in Evolve provides a copy of the safeguards applied, with confidential commercial information redacted.
Taking into account the nature of the Processing and the information available, Made in Evolve assists the Client:
Assistance exceeding what is reasonably required by Applicable Law may be charged at the rates set out in the Main Agreement.
Made in Evolve notifies the Client of any Personal Data Breach concerning Client Data without undue delay and in any event within 48 hours of becoming aware of it, by email to the Client’s designated contact person. The notification contains, to the extent available: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information not yet available is provided in subsequent phases.
Made in Evolve cooperates with the Client to enable it to notify the Supervisory Authority within 72 hours (Article 33 GDPR) and to communicate the breach to Data Subjects (Article 34 GDPR). The notification does not constitute an admission of liability. Communications to Data Subjects or to the public are decided by the Client.
Made in Evolve makes available to the Client the information necessary to demonstrate compliance with Article 28 GDPR. The Client may verify compliance with the DPA:
An additional audit is permitted where required by the Supervisory Authority or following a Personal Data Breach affecting Client Data. Made in Evolve remedies any non-conformities found within a reasonable time.
Upon termination of the Services, at the Client’s choice communicated in writing, Made in Evolve returns Client Data in a structured, commonly used format or deletes it, together with existing copies, within 90 days of termination. In the absence of instructions within that period, it proceeds with deletion and, on request, confirms it in writing.
Client Data whose retention is required by Union or Italian law (in particular contractual, tax and accounting documents, retained for 10 years under Article 2220 of the Italian Civil Code) is excepted; it remains protected by the DPA and is deleted at the end of the prescribed period. Backup copies are overwritten in the ordinary rotation cycle.
Each Party is liable for damage caused by the Processing under the criteria of Article 82 GDPR. The limitations and exclusions of liability in the Main Agreement also apply to obligations arising from the DPA, to the extent permitted by law and except for wilful misconduct or gross negligence. The Client warrants that Client Data has been collected in compliance with Applicable Law, with adequate information to Data Subjects and a valid legal basis, and holds Made in Evolve harmless from the consequences of unlawful instructions.
The DPA enters into force upon conclusion of the Main Agreement and remains effective for the entire duration of the Processing carried out on behalf of the Client, including the phase under Section 12. The DPA is governed by Italian law. The Court of Modena has exclusive jurisdiction over any dispute, without prejudice to the mandatory jurisdiction protecting Data Subjects.
In the event of conflict between the DPA and the Main Agreement, the DPA prevails on matters of personal data protection. The invalidity of one clause does not affect the others. Made in Evolve may update the DPA to align it with Applicable Law or with decisions of the authorities; material changes are notified with 30 days’ notice. For any matter relating to the DPA the Client may write to privacy@madeinevolve.com.
| Element | Description |
|---|---|
| Subject matter | Processing of Client Data necessary to deliver the Services set out in the Main Agreement. |
| Nature | Collection, recording, storage, consultation, use, disclosure to Sub-processors, alignment between systems, extraction, erasure, by electronic means, including through artificial intelligence functions (Atomo assistant) operating solely on the individual Client’s data. |
| Purpose | Operational management of the online store; CRM and email marketing on behalf of the Client; integration between eCommerce platform, ERP, PIM, logistics and payments; development, maintenance and support of the platforms; provision and support of Nucleo Platform. |
| Duration | The term of the Main Agreement, plus the return or deletion period (Section 12). |
| Categories of Data Subjects | End customers and prospective customers of the Client; users of the Client’s websites and online stores; employees and contractors of the Client who use the platforms. |
| Categories of Personal Data | Identification data (first name, last name, customer identifiers); contact data (email, telephone, addresses); orders and transactions (products, amounts, status, payment outcome, without full card numbers); browsing behaviour (pages visited, events, device, IP address); marketing preferences and consents; credentials and access logs of the Client’s users. |
| Special categories | Not envisaged. |
| Location of Processing | European Union (DigitalOcean data centre in Frankfurt); Third Countries only for the Sub-processors in Annex C, with the safeguards indicated there. |
Measures implemented by Made in Evolve pursuant to Article 32 GDPR and aligned with the principles of ISO/IEC 27001:2022.
| Sub-processor | Country | Purpose of Processing | Transfer safeguard |
|---|---|---|---|
| DigitalOcean LLC | USA (data centre: Frankfurt, Germany) | Hosting and cloud infrastructure for Nucleo Platform and Made in Evolve systems | Data stored in the EU; SCCs and DPF for support access |
| Google (Google Ireland Ltd. / Google LLC) | Ireland / USA | Workspace (email, documents, SSO), Cloud, Analytics, Tag Manager, reCAPTCHA, Ads, Gemini | SCCs and DPF |
| Microsoft (Microsoft Ireland Operations Ltd. / Microsoft Corp.) | Ireland / USA | Microsoft 365, Clarity, Copilot | SCCs and DPF |
| Meta Platforms Ireland Ltd. | Ireland / USA | Pixel and advertising campaigns on behalf of the Client | SCCs and DPF |
| Twilio Inc. (SendGrid) | USA (EU data residency) | Transactional emails and notifications | SCCs and DPF |
| Klaviyo Inc. | USA | Email marketing and CRM on behalf of the Client | SCCs and DPF |
| Shopify International Ltd. | Ireland (Shopify group: Canada / USA) | The Client’s eCommerce platform, accessed by Made in Evolve to deliver the Services | Adequacy (Canada); SCCs and DPF |
| Slack Technologies LLC (Salesforce) | USA | Internal communication and communication with the Client | SCCs and DPF |
| Asana Inc. | USA | Project management | SCCs and DPF |
| Notion Labs Inc. | USA | Project documentation | SCCs and DPF |
| Figma Inc. | USA | UX/UI design | SCCs and DPF |
| GitHub Inc. (Microsoft) | USA | Source code and CI/CD pipelines | SCCs and DPF |
| Fireflies.ai Corp. | USA | Meeting transcription, only with prior notice to participants | SCCs |
| OpenAI (OpenAI OpCo LLC / OpenAI Ireland Ltd.) | USA / Ireland | AI functions (text, code, analysis; Atomo assistant), on plans that exclude model training | SCCs and DPF |
| Anthropic PBC | USA | AI functions (text, code, analysis; Atomo assistant), on plans that exclude model training | SCCs and DPF |
Sub-processors are involved only to the extent required by the individual Client’s Services; changes to the list are notified in accordance with Section 7.
This English version is provided for convenience; in case of discrepancy the Italian version prevails.