DUBHCORE — Data Processing Agreement (DPA)
Agreement on the processing of data pursuant to Art. 28 GDPR
Version 1.0 — Date: 30 August 2026 — Final version Applies where the Studio/Professional is Controller and DUBHCORE is Processor of the data of the Studio's clients processed through the platform.
- Controller: the Studio/Professional (identification data in the account).
- Processor: DUBHCORE — Gelsi Andrea (sole proprietorship), VAT (P.IVA) 02826520211, registered office Via Auen 3, 39031 Brunico (BZ), Italy, info@dubhcore.com.
1. Subject matter and duration
The Processor processes personal data on behalf of the Controller for the sole purpose of providing the Service, for the duration of the service contract and until the return/deletion of the data.
2. Nature and purpose of the processing
Hosting, storage, processing and provision of the management functions (requests, appointments, calendar, messaging, documents/signatures, payments/deposits, notifications) for the management of the Controller's activity.
3. Data subjects and data categories
- Data subjects: the Studio's clients (including minors and their parents/guardians), collaborators.
- Categories: personal data/contacts; tattoo/piercing requests and body position; images; appointments; messages; documents/consents/signatures; payment/deposit data.
- Special categories (Art. 9): health-related data in the Tattoo flows (field "Scars") and Piercing (metal allergies, irritation/infection of the area, scarring, medications/conditions, pregnancy/breastfeeding). The implemented condition under Art. 9 is the explicit consent — Art. 9(2)(a), identified by the Controller (not Art. 9(2)(h); DUBHCORE is not a healthcare service). PMU does not currently provide for the collection of structured health data.
- Data of minors/guardians: processed according to the double-signature flow in the studio; for minors, consent to health data is given in the studio by the parent/guardian and linked to the specific treatment (see Privacy Policy §4-bis).
4. Documented instructions
The Processor processes the data only on the Controller's documented instructions (including those given through the use of the Service functions and these Terms/DPA), subject to legal obligations.
5. Confidentiality
The Processor's authorised personnel are bound to confidentiality.
6. Security (Art. 32)
The Processor adopts the technical/organisational measures described in Annex B (verified measures).
7. Access control and isolation
Role-based access (RBAC) and multi-tenant isolation per studio; credentials/secrets are not exposed in clear text.
8. Sub-processors
The Controller authorises the use of the sub-processors listed in Annex C. The Processor imposes on the sub-processors equivalent data protection obligations.
9. Changes to sub-processors
The Processor informs the Controller of changes to sub-processors with reasonable notice, allowing any reasoned objection.
10. International transfers
Transfers outside the EU take place with adequate guarantees. Verified: the infrastructure of the production database, storage and backups is located in the United States; the transfers are covered by the DPA of Emergent Labs Inc., which incorporates the Standard Contractual Clauses (EU Decision 2021/914) where applicable. Roles: the Customer (DUBHCORE/Studio) acts as Controller and Emergent as Processor; where the Customer in turn acts as Processor for another Controller, Emergent acts as Sub-processor. The Emergent DPA is intended to meet the requirements of Art. 28 GDPR.
11. Assistance to the Controller
The Processor assists the Controller, as far as possible, in responding to data subjects' requests (Art. 15–22) and in the obligations under Art. 32–36 (security, data breach, DPIA, prior consultation).
12. Data breach
The Processor notifies the Controller of data breaches without undue delay after becoming aware of them, providing the available useful information.
13. DPIA
The Processor cooperates, where applicable, in the impact assessment (DPIA) and in the prior consultation.
14. Cooperation with the authorities
The Processor cooperates with the competent supervisory authority within the limits of the law.
15. Return/deletion
Upon termination of the contract, at the Controller's choice, the Processor returns or deletes the data, subject to legal retention obligations. Signed documents are retained as immutable snapshots according to the Service.
16. Audit and information
The Processor makes available to the Controller the information necessary to demonstrate compliance with Art. 28 and allows reasonable audits, with agreed methods and notice.
17. Controller's obligations
The Controller guarantees the lawfulness of the processing (for health data, the implemented condition under Art. 9 is the explicit consent under Art. 9(2)(a), collected through the platform function before the structured health data), provides the notices and collects the consents towards its clients (incl. handling of minors with consent given in the studio by the guardian), gives lawful instructions and correctly configures the access of its personnel.
18. Liability
Each party is liable in accordance with the GDPR and the applicable law, within the limits of their respective roles.
19. Contact
DUBHCORE — info@dubhcore.com.
ANNEX A — Description of the processing
- Purposes: operational management of the Studio's activity through the Service.
- Types of processing: collection, recording, organisation, storage, consultation, use, communication to recipients/sub-processors, deletion.
- Data subjects: clients (incl. minors), parents/guardians, Studio collaborators.
- Data categories: see §3 (incl. health data for piercing and data of minors/guardians).
- Duration: duration of the contract; retention according to DUBHCORE's Data Retention Schedule V1.
ANNEX B — Technical and organisational measures (VERIFIED in the code)
- Passwords with bcrypt; authentication with JWT.
- RBAC (role control) and multi-tenant isolation per studio.
- Least privilege on health data (Art. 9) — server-side: the structured health responses of the treatment are returned by the API only to owner/manager, assigned professional and the client concerned; redacted (not transmitted) to reception, unassigned professionals, other studios and other clients. The operational summary of the Piercing is kept separate from the health responses.
- Encryption (Fernet) of Google tokens and payment credentials.
- Private Object Storage with access control (no public URLs; no exposed paths).
- Rate limiting on public endpoints (key by real IP).
- Audit logging of actions (author/action/object/timestamp).
- Immutable snapshots of signed documents.
- Normalisation of email at login/registration.
- Infrastructure backups (managed by Emergent — verified): production database with automatic rotating backups (hourly 7 days, daily 7 days, weekly 4 weeks, monthly 12 months, yearly 1 year) and continuous point-in-time recovery over the last 7 days; storage in the United States.
- Regions (verified): production database, storage and backups in the United States.
ANNEX C — Sub-processors (only services actually used)
| Provider | Service/Purpose | Data categories | Place of processing | Transfer outside the EU | Guarantee |
|---|---|---|---|---|---|
| Stripe | Payments/subscriptions + Stripe Connect (deposits) | Payment/billing data | EU/USA (PARTIAL, not verified) | Yes | Stripe DPA/DPP + SCC (online acceptance). Stripe may act as autonomous Controller for certain processing |
| OAuth + Google Calendar (read-only import) | Account identifiers, calendar events | EU/USA (PARTIAL, not verified) | Yes | Google Data Processing Terms + SCC (online acceptance) | |
| Emergent (+ MongoDB Atlas, AWS/SES, Cloudflare via Emergent) | Hosting/infrastructure, managed Object Storage, email (managed Resend/SES) | All hosted categories | United States (VERIFIED; Cloudflare: edge/distributed, region not verified) | Yes (USA) | Emergent DPA + SCC EU 2021/914 |
Note:Expo/EASis used exclusively for build/distribution of the mobile app and does not process the personal data of end users during normal use: it is not listed as a runtime sub-processor.Apple Calendaris on-device (not a sub-processor). The DPAs are perfected via online acceptance (no separate handwritten signature). Duration of infrastructure logs: not communicated or confirmed by the provider (managed by Emergent within its own infrastructure; no unverified numerical period is stated).
Annex C revision (verified audit): the current services are Stripe, Google, Emergent (infra chain: MongoDB Atlas, AWS/Amazon SES in the USA and Cloudflare (edge/distributed, region not verified) via Emergent — Emergent DPA + SCC EU 2021/914). Stripe may act as an autonomous Controller for certain payment/compliance/anti-fraud processing (not a mere sub-processor); Google is limited to OAuth + Calendar. The DPAs are perfected via online acceptance (no separate handwritten signature). Expo/EAS = build/distribution tool, not a runtime sub-processor of client data. Apple Calendar is on-device (not a sub-processor). Google Fonts and Unsplash are NOT included (localised assets). Duration of infrastructure logs: not communicated or confirmed by the provider (no unverified numerical period is stated).