Data Processing Agreement (DPA)
Preliminary version — last revised: 15 June 2026. The final version will be published before commercial launch and will form an integral part of the SaaS agreement.
1. Background
This Data Processing Agreement ("DPA") supplements the Terms of Service of the Digital Product Passport service ("DPP", "the Service") provided by Kaboom Srl, with registered office at Via Castellamonte 1, 10138 Turin, Italian Tax Code/VAT No. IT-11178000011 ("Data Processor", "we") to the Customer ("Data Controller"). This DPA governs the processing of personal data carried out by the Data Processor on behalf of the Data Controller pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").
2. Roles and Subject Matter
The Customer is the Data Controller of the personal data uploaded to or generated within the Platform. Kaboom Srl acts as the Data Processor and processes the data solely on the basis of the Data Controller's documented instructions and for the purposes of providing the Service.
3. Duration of Processing
The processing shall continue for the duration of the contractual relationship between the Customer and Kaboom Srl. The provisions regarding deletion or return of data (Article 11 of this DPA) shall apply upon termination of the relationship.
4. Nature and Purpose of Processing
The processing is automated in nature and has the following purposes: (a) the provision of the Digital Product Passport supply chain traceability Service; (b) the generation of public digital passports for the Customer's products; (c) the anchoring of supply chain data on the blockchain DAC; (d) the provision of technical and operational support.
5. Categories of Personal Data Processed
- Identification data of the Customer's team members (first name, surname, business email, role)
- Account data and credentials (managed via the Zitadel identity provider)
- Activity log data (access logs, modifications, audit trail)
- Contact data of the Customer's suppliers and clients, where entered by the Customer into the Platform
Note: supply chain data (batches, products, processing operations) does not in itself constitute personal data. It becomes such to the extent that it contains identifying references to natural persons (e.g. the name of an operator).
6. Categories of Data Subjects
- Customer personnel with access to the Platform
- Contact persons of the Customer's suppliers and clients (where entered as contacts)
- Visitors to the public passport (minimal browsing data collected for analytics)
7. Authorised Sub-processors
The Customer authorises Kaboom Srl to engage the following sub-processors for the provision of the Service:
- Microsoft Ireland Operations Ltd (Azure) — cloud hosting (EU)
- Zitadel GmbH — identity and authentication management (EU/CH)
- HashiCorp, Inc. — secrets management via Vault, on a self-hosted basis (EU)
- IPFS / Pinata / Filebase — decentralised storage for public assets (EU/USA, where applicable subject to SCCs)
- Quadrans Foundation — operator of the underlying blockchain DAC network (EU)
- Sentry GmbH — error monitoring (EU)
Kaboom Srl shall notify the Customer with at least 30 days' prior notice of any change to the list. The Customer may object to a change within the same period, with the right to terminate without penalty if the objection cannot be accommodated.
8. Technical and Organisational Security Measures
Kaboom Srl adopts appropriate measures to ensure a level of security commensurate with the risk, in particular:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Multi-tenant architecture with data isolation per organisation
- Blockchain keys held in a dedicated vault for each organisation
- Administrative access secured with multi-factor authentication
- Comprehensive audit log of all write operations on the data
- Backups managed on Microsoft Azure infrastructure with 30-day retention
- Continuous monitoring and documented incident response procedures
9. Data Subject Rights
Kaboom Srl, in its capacity as Data Processor, shall assist the Data Controller in responding to requests from Data Subjects relating to the rights set out in Articles 15-22 GDPR (access, rectification, erasure, portability, restriction, objection). Requests received directly by the Data Processor shall be forwarded to the Data Controller within 5 business days.
10. International Transfers
Processing takes place primarily within the European Economic Area (Microsoft Azure West Europe). Any transfers to third countries (e.g. US-based IPFS services) are carried out on the basis of Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Article 46 GDPR.
11. Personal Data Breach Notification
Kaboom Srl shall notify the Data Controller of any personal data breach of which it becomes aware, without undue delay and in any event within 48 hours, providing the information necessary for any notification to the supervisory authority pursuant to Article 33 GDPR.
12. Audit and Inspection
The Data Controller has the right to verify the Data Processor's compliance with this DPA, once per year upon reasonable notice, including through inspections or audits carried out by independent third parties bound by confidentiality obligations. Kaboom Srl shall make available, on request, any relevant certifications or audit reports already in its possession (e.g. ISO 27001, SOC 2 where applicable).
13. Deletion or Return of Data
Upon termination of the contractual relationship, the Customer may export its data within 30 days. After that period, Kaboom Srl shall delete the data from the Platform and from backups, save as required by statutory retention obligations. The cryptographic hashes already anchored on the blockchain DAC, being immutable by their very nature, cannot be removed; such hashes do not contain personal data in clear text.
14. Limitation of Liability
The Data Processor's limitations of liability are governed by Article 8 of the Terms of Service, without prejudice to the mandatory provisions of Article 82 GDPR concerning joint and several liability for damage caused by the processing.
15. Governing Law and Jurisdiction
This DPA is governed by Italian law. Any dispute shall be subject to the exclusive jurisdiction of the Court of Turin, without prejudice to the mandatory provisions of the GDPR and the Italian Privacy Code (Legislative Decree 196/2003, as amended).
16. Contacts
For requests relating to data processing, please write to info@kaboom.cloud. The Customer is requested to indicate "DPA — DPP" in the subject line.
Preliminary draft prepared for the provisional test deployment. The legally binding version will be reviewed by a privacy/legal consultant before commercial release of the Service and will fully supersede this one.
Questions about the DPA?
Write to us, we respond within one business day.