under Article 28 of Regulation (EU) 2016/679 · Version 1.0 · effective from 21/09/2026
1.1. This Agreement is entered into between the Customer that accepts the Terms and Conditions of the Roundabout platform (the “Customer”, controller) and Roundabout S.r.l., Corso Castelfidardo 30/a, 10129 Turin, Italy, VAT no. 12027720015 (“Roundabout”, processor).
1.2. This Agreement forms part of the Terms and Conditions and applies to the personal data that the Customer, or people acting on its behalf, enter into or make available in the Platform, and which Roundabout processes on its behalf (“Customer Data”). The subject matter, nature, purposes, types of data and categories of data subjects are described in Annex A.
1.3. This Agreement does not apply to processing for which Roundabout is the controller, described in the Privacy Notice and in the Privacy Notice for Creators: user accounts, creator data collected from public sources, invoicing, and the running of managed campaigns.
1.4. In the event of conflict between this Agreement and the Terms, this Agreement prevails on data protection matters.
2.1. Roundabout processes Customer Data only on the Customer’s documented instructions, including as regards transfers outside the European Economic Area, unless required to do otherwise by Union or Italian law. In that case it informs the Customer before processing, unless the law prohibits it.
2.2. The Customer’s instructions comprise this Agreement, the Terms, the Customer’s use of the Platform’s features, and any further written instructions agreed between the parties.
2.3. Roundabout informs the Customer immediately if it considers that an instruction infringes the GDPR or other data protection law.
2.4. The Customer warrants that it has a valid legal basis for the Customer Data, that it has informed the data subjects, and that the instructions it gives comply with the law.
Roundabout authorises only those people who need it in order to provide the service to process Customer Data, and binds them to confidentiality by contract or by law.
4.1. Roundabout implements technical and organisational measures appropriate to the risk, under Article 32 GDPR, described in Annex C.
4.2. Roundabout may update these measures, provided the overall level of protection is not reduced.
5.1. Roundabout informs the Customer without undue delay, and in any event within 48 hours, after becoming aware of a breach affecting Customer Data.
5.2. The notification contains, so far as available, the information the Customer needs in order to notify the supervisory authority and, where necessary, the data subjects (Articles 33 and 34 GDPR): the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information not immediately available is provided as soon as it is.
5.3. Notifying the authority and the data subjects is the Customer’s responsibility as controller.
6.1. Taking into account the nature of the processing, Roundabout assists the Customer by appropriate technical and organisational measures in responding to data subject requests (Articles 15–22 GDPR). The Platform already allows account data to be exported and deleted; for other requests the Customer may write to [email protected].
6.2. If a data subject approaches Roundabout directly about Customer Data, Roundabout forwards the request to the Customer without responding on the merits, unless instructed otherwise.
6.3. Roundabout assists the Customer, with the information available to it, in data protection impact assessments and prior consultation with the authority (Articles 35 and 36 GDPR).
7.1. The Customer gives Roundabout general written authorisation to engage sub-processors. Those currently used are listed in Annex B.
7.2. Roundabout notifies the Customer, by email or in the Platform, of the addition or replacement of a sub-processor at least 30 days in advance. Within that period the Customer may object on reasonable data protection grounds. If the parties cannot find a solution, the Customer may terminate the paid plan without penalty, with a refund of the part of the period already paid for and not used.
7.3. Roundabout imposes on each sub-processor, by contract, data protection obligations substantially equivalent to those in this Agreement, and remains liable to the Customer for their performance (Article 28(4) GDPR).
8.1. Customer Data is stored in Italy. Some sub-processors may process it outside the European Economic Area, as indicated in Annex B.
8.2. Any transfer takes place only under one of the safeguards provided by Chapter V of the GDPR: an adequacy decision, including the EU–US Data Privacy Framework for participating organisations, or the standard contractual clauses approved by the European Commission (Decision (EU) 2021/914).
9.1. Roundabout makes available to the Customer the information necessary to demonstrate compliance with this Agreement and with Article 28 GDPR.
9.2. The Customer may request an audit, including through an independent auditor bound by confidentiality. The audit is conducted first and foremost on the basis of documents and written answers. An on-site audit at Roundabout is agreed with at least 30 days’ notice, no more than once a year except in the event of a data breach or a request from an authority, during business hours and without access to other customers’ data. The costs are borne by the Customer.
The parties’ liability under this Agreement is governed by Article 82 GDPR and, to the extent permitted by law, by the Terms and Conditions.
This Agreement applies for as long as Roundabout processes Customer Data on the Customer’s behalf, and in any event for the duration of the Terms.
12.1. Before closing the Workspace the Customer may export its data from the Platform.
12.2. Within 90 days of the end of the relationship Roundabout deletes Customer Data, or irreversibly anonymises it, unless Union or Italian law requires it to be retained. At the Customer’s written request, it confirms that deletion has taken place.
12.3. Data that Roundabout processes as an independent controller, as set out in section 1.3, is excluded.
13.1. Roundabout may update this Agreement to align it with the law or with guidance from the authorities, following the procedure for amending the Terms.
13.2. This Agreement is governed by Italian law. Disputes are subject to the jurisdiction set out in the Terms.
| Item | Description |
|---|---|
| Subject matter and nature | storage, organisation, consultation, processing (including with artificial intelligence tools), sharing by link and deletion of Customer Data in the Platform |
| Purposes | providing the Customer with the Platform: analyses, quotes, campaign management, reports, collaboration with team members and invited partners |
| Types of data | contact and role data (name, email, company, function); content entered by the Customer (briefs, notes, comments, documents, logos); comments left on shared quotes |
| Categories of data subjects | the Customer’s contacts, collaborators and clients; people who receive or comment on quotes shared by the Customer |
| Special categories of data | none. The Customer undertakes not to enter any |
| Duration | the duration of the Terms, plus the period in section 12 |
| Sub-processor | Service | Place of processing | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | hosting, database, storage, service emails | Italy (Milan region) | — |
| OpenAI Ireland Limited | text processing with AI, via API | EU and United States | safeguards provided in OpenAI’s data processing agreement |
| Google Ireland Limited (Firebase Authentication) | authentication of invited team members | United States | standard contractual clauses |
Roundabout’s other suppliers do not process Customer Data and therefore do not appear here: they are listed in the Privacy Notice and in the Privacy Notice for Creators, where Roundabout acts as controller.