Legal
Data processing agreement
This agreement applies whenever Mellizos Services (“we”, the processor) processes personal data on behalf of a client (“you”, the controller) under GDPR Article 28. It forms part of each client agreement.
1. What we process
Only the data needed to run the process described in your agreement: typically business records such as orders, invoices, reports and the contact details of people in them. We process it only on your documented instructions.
2. Where it lives
Client data is hosted on EU servers operated by Hetzner in Frankfurt, Germany, and backed up to [Backblaze EU region]. Your data is never used to train a public model.
3. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting and processing | Frankfurt, Germany (EU) |
| Anthropic | AI model inference, where a process uses AI | [United States — confirm transfer basis and data region] |
| Resend | Sending emails produced by a process | [Region to confirm] |
| Backblaze | Encrypted backups | [EU region to confirm] |
We give at least [30 days’] notice by email before adding or replacing a sub-processor, and you may object.
4. Our commitments
- Confidentiality: only Riccardo Murgia has access to client data.
- Security: encryption in transit and at rest, least-privilege credentials, and access logging. [List specific measures.]
- Breaches: we notify you without undue delay, and within [48 hours] of becoming aware of a personal data breach.
- Assistance: we help you respond to data-subject requests and with impact assessments where relevant.
- Audit: we make available the information needed to show compliance with this agreement.
5. End of the engagement
When an engagement ends, we hand back your data in the handover pack and delete remaining copies within [30 days], except where law requires us to keep them. Backups roll off within [90 days].