Canonical public document
DPA — Owevaro Operational Draft
> Published English translation confirmed by the owner on 17 August 2026. The Italian source remains canonical and prevails in the event of a discrepancy. The underlying document retains status in_review and effective_from: null.
Version 2026-08-06-legal-v4. Status: in_review, not effective. Complete, approve and execute it before real data is processed; acknowledgement or acceptance of the Terms does not constitute acceptance of the DPA. The historical dpa_accepted field is expressly non-evidentiary.
Parties, roles and priority
The Customer identified in the order or workspace is the controller for data uploaded for its own purposes. Alin Daniel Epure, Italian VAT number 17835711007, operates through Owevaro as processor. Owevaro remains an independent controller for accounts, security, billing and its own obligations. The DPA prevails over the Terms in relation to entrusted processing.
Subject matter, duration, nature and purpose
To host, protect, scan, extract, structure, view, export and delete documents and related data; to provide support and continuity. Duration: the relationship plus return, active deletion and backup rotation. Owevaro acts only on documented instructions and reports instructions that appear unlawful.
Data subjects and data
Users, creators, principals, customers, collaborators, employees, representatives and signatories. Identification, contact, professional, financial and contractual data. Special categories and data relating to criminal convictions are not part of the standard service: they are prohibited unless covered by a written agreement, documented necessity, an applicable condition under Articles 9 or 10 GDPR, specific instructions and approved supplementary measures. Generic acceptance of the DPA does not by itself authorise such data.
Processor obligations
- authorised persons bound by confidentiality;
- measures in Annex B and review proportionate to risk;
- assistance with rights, security, personal data breaches, DPIAs and consultations;
- return or deletion at the end of the relationship, unless the law requires retention;
- compliance information and proportionate, coordinated and confidential audits;
- no independent response to data subjects unless required by law or instructed.
Subprocessors and transfers
General authorisation for the providers listed in Annex C. Material changes are notified with reasonable advance notice and permit reasoned objections. Each subprocessor assumes substantially equivalent obligations. Adequacy, SCCs and supplementary measures are applied according to the actual destination and access.
Breaches
Owevaro informs the Customer without undue delay after becoming aware of a personal data breach affecting entrusted data and progressively supplements the information available concerning its nature, the categories and approximate number, consequences, contact and measures. Notification does not constitute an admission of liability.
Return and deletion
The Customer may export data and documents during the relationship. On termination, the Customer chooses return or deletion where applicable. Active systems: without undue delay and, in complex cases, within 30 days. Isolated backups: planned maximum rotation of 90 days, to be confirmed by operational evidence.
Annex A — customer processing schedule
| Field | Value to be completed before signature |
|---|---|
| Customer/controller, contacts, DPO/representative | TO_BE_COMPLETED |
| covered services and workspaces | TO_BE_COMPLETED |
| nature and purpose of instructions | TO_BE_COMPLETED |
| duration, start/end and return/deletion | TO_BE_COMPLETED |
| categories of data subjects and data | TO_BE_COMPLETED |
| special-category/criminal-offence data | PROHIBITED_BY_DEFAULT; separate exception to be approved |
| instructions concerning rights, incidents and assistance | TO_BE_COMPLETED |
| authorised transfers and safeguards | TO_BE_COMPLETED |
Annex B — technical and organisational measures
| Area | Measure | Maximum evidenced status/limitation |
|---|---|---|
| access | individual accounts, OAuth login, server-side sessions | IMPLEMENTED; provider/account and revocation to be evidenced |
| transport and secrets | TLS; secrets kept outside the repository; short-lived credentials planned | IMPLEMENTED in code; external runtime not revalidated |
| segregation | RLS, private buckets, owner/workspace checks | TESTED locally and with two-tenant synthetic provider E2E; EV-PRIV-002 |
| upload | allowlist, inspection, quarantine, ClamAV, fail-closed CDR | APPROVED_PRIVATE_EVIDENCE; PDFBox/SBOM/VPS/attributions verified, professional certified-email evidence held by the owner |
| logging | no content or tokens intended in logs | IMPLEMENTED in code; provider to be verified |
| availability | encrypted self-managed backup, restoration and suppression | TESTED with synthetic data; cross-VPS hPanel path not used |
| deletion | document/account deletion, DSAR procedure and ledger | TESTED on the provider with Auth/DB/storage cleanup and ledger; EV-PRIV-002 |
| incidents | runbook, triage matrix, Telegram and tabletop | TESTED procedurally; human substitute/availability not evidenced |
| AI | tool-free reader, schema/citations, human confirmation | fail-closed; real data prohibited |
| extended OAuth | email/calendar | fail-closed; real data prohibited |
Annex C — subprocessors
Versioned reference to SUBPROCESSORS.md. Before signature, the list applicable to the customer must be frozen, including function, data, region/access, transfer basis, DPA, onboarding date and objection procedure. Public copies do not automatically evidence the contract applicable to the account.
Signature/acceptance
Version, date, identity and capacity of the signatory, represented organisation, evidence of acceptance and delivery on a durable medium must be recorded. The prototype checkbox does not replace execution of the final version.