Version 1.0 — 03.09.2026
Between the Customer — the dance school using the Dance Master Pro application — (the “Controller”) and FCO SRL, Via 2 Giugno 4, 23883 Brivio (LC), Italy (the “Processor”).
1. Subject matter, duration, termination
The Processor processes personal data on behalf of the Controller in order to provide the Dance Master Pro software service under the main agreement. This DPA forms part of that agreement, takes effect with it and ends when deletion under clause 11 is complete. Subject matter, nature, purpose, data types and categories of data subjects are set out in Annex 1.
2. Controller’s instructions
The Processor processes personal data only on documented instructions. This DPA, the main agreement and the configuration the Controller makes within the application constitute the initial instruction. Further instructions are given in text form to privacy@dancemasterpro.com; oral instructions must be confirmed in text form without delay.
The Processor shall inform the Controller without delay if, in its opinion, an instruction infringes the GDPR or other data protection provisions (Art. 28(3) sentence 3 GDPR), and may suspend execution of that instruction until it is confirmed or amended.
The Processor does not process the data for its own purposes. In particular, customer data is not used to train artificial intelligence models, not aggregated beyond the individual customer and not used for advertising.
3. Obligations of the Processor
The Processor shall: process personal data only within this DPA and the instructions given; bind all persons authorised to process the data to confidentiality in writing and train them regularly; implement and maintain the measures set out in Annex 2; assist the Controller with its obligations under Art. 32 to 36 GDPR, including data protection impact assessments and prior consultation; inform the Controller without delay of any investigation by a supervisory authority that may concern the Controller’s data; maintain a record of processing activities under Art. 30(2) GDPR and make it available on request; and inform the Controller without delay if the Controller’s data is endangered by seizure, insolvency proceedings or comparable third-party events.
4. Technical and organisational measures
The measures in force at the time of signature are described in Annex 2. The Processor may adapt them over time, in particular to reflect technical progress, provided the level of protection is not reduced. Material changes are documented and communicated on request.
5. Subprocessors
The Controller grants general authorisation for the engagement of subprocessors under Art. 28(2) GDPR. Those engaged at the time of signature are listed in Annex 3 and published at https://dancemasterpro.com/en/subprocessors/.
The Processor shall inform the Controller at least 30 days before engaging a new subprocessor or replacing an existing one, by email to the address on file; the Controller may in addition subscribe to change notifications on that page. The Controller may object within 30 days on data protection grounds. If no mutually acceptable solution is found, the Controller may terminate the affected service extraordinarily.
The Processor imposes on every subprocessor obligations at least equivalent to those in this DPA and remains fully liable for the subprocessor’s performance.
6. Controller-operated integrations
The application allows the Controller to connect its own third-party accounts, in particular: cloud storage (Google Drive, Dropbox, Microsoft OneDrive) for invoice PDFs, medical certificates and photo and video content; a payment provider (Stripe) using the Controller’s own credentials; video conferencing (Zoom) using the Controller’s own credentials; and email delivery through the SMTP server configured by the Controller.
These services are selected, connected and configured by the Controller. Data is stored in the Controller’s own accounts. The Processor has no administrative access to those environments and acts there neither as controller nor as processor.
The Controller must conclude its own data processing agreements with these providers. The Processor expressly points out that a private consumer account — for example a personal Google account — is generally not sufficient for storing pupils’ personal data; a business account with a corresponding data processing agreement is required.
If the Controller disables an integration or revokes access, files already transferred remain in its own storage and under its sole control.
7. Place of processing and international transfers
Processing takes place exclusively within the European Union; the application and its databases are operated in a data centre in Frankfurt am Main, Germany. Remote access for support and maintenance also takes place exclusively from within the EU. Transfers to third countries occur only as identified in Annex 3 and only on the basis of an adequacy decision, the European Commission’s Standard Contractual Clauses or another safeguard permitted under Chapter V GDPR. Relocating processing to a third country requires the Controller’s prior consent.
8. Assistance with data subject rights
If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without delay and does not answer it itself. The Processor assists the Controller in fulfilling requests for access, rectification, erasure, restriction, portability and objection; the application provides search, edit, delete and export functions the Controller can use itself. Assistance beyond those self-service functions is provided free of charge to the extent it does not exceed reasonable effort.
9. Personal data breaches
The Processor shall notify the Controller of any personal data breach without undue delay and no later than 48 hours after becoming aware of it (Art. 33(2) GDPR).
The notification is made in text form to the contact address on file and contains, as far as known: the nature of the breach; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Information not immediately available is supplied as soon as it is.
The Processor assists the Controller with its obligations under Art. 33 and 34 GDPR and documents every incident. Notifications to a supervisory authority or to data subjects on the Controller’s behalf are made only on the Controller’s instruction.
10. Audit rights
The Controller may verify compliance with this DPA (Art. 28(3)(h) GDPR). The Processor makes available: this DPA and its annexes; the current description of technical and organisational measures; the record under Art. 30(2) GDPR; evidence of the confidentiality undertakings of its personnel; and the certifications and audit reports of the subprocessors engaged.
Where this evidence is not sufficient, the Controller may carry out an on-site inspection once a year, and additionally where there are concrete indications of an infringement, during normal business hours, itself or through an auditor bound to secrecy who is not a competitor of the Processor. Inspections are announced 14 days in advance and conducted so as not to disrupt operations unreasonably. Additional inspections may be charged at cost.
11. Deletion and return after termination
Before the contract ends, the Processor provides the Controller with the means to export its data in a common, machine-readable format.
On termination, access to the application is blocked. Data then remains in a blocked state for 30 days, so that accidental cancellations can be reversed and outstanding exports completed.
At the Controller’s choice, the data is then either returned or permanently deleted (Art. 28(3)(g) GDPR). If the Controller makes no choice within the period, the data is deleted. Deletion extends to backup copies, at the latest at the end of the applicable backup cycle of 30 days. Deletion is confirmed in writing on request.
Statutory retention obligations. The Controller is itself responsible for securing, before deletion, any data it must retain under commercial and tax law — in Germany in particular under § 147 AO and § 257 HGB — which concerns invoices and payment records above all. The Processor expressly draws attention to this obligation before blocking and provides the necessary export functions, but does not owe retention beyond the period stated.
Documents stored in the Controller’s own cloud storage under clause 6 are unaffected by deletion: they reside solely in the Controller’s own environment.
12. Liability
Art. 82 GDPR applies externally. Internally the parties bear damage in proportion to their share of responsibility. Limitations of liability in the main agreement remain unaffected save where they concern liability under Art. 82 GDPR.
13. Final provisions
Amendments require text form, including any waiver of this form requirement. In case of conflict, this DPA prevails on data protection matters. Should any provision be invalid, the remainder stays in force. Italian law applies, subject to the mandatory provisions of the GDPR and of the national data protection law applicable to the Controller. Place of jurisdiction: Lecco, Italy.
Annexes: 1 Processing overview · 2 Technical and organisational measures · 3 Subprocessors
This agreement forms part of the main agreement and takes effect with it. The version in force is published at https://dancemasterpro.com/en/dpa/; we notify you of material changes in advance.
Annex 1 — Processing overview
Purpose. Operation of management software for dance schools: pupil and membership administration, class and room scheduling, attendance, teaching staff and their remuneration, payments and invoicing, events and competitions, a family portal, optional photo and video galleries and an optional AI assistant.
Categories of data subjects. Pupils, predominantly minors; parents and legal guardians; teaching and administrative staff of the school; administrative users; emergency contacts.
Types of data. Master data (name, date of birth, address, tax or social security number where recorded); contact data including parents’ email addresses; contract and course data, memberships and their validity; attendance and assessments; payment data, outstanding balances, invoices and SEPA mandates including IBAN; health-related data under Art. 9 GDPR — the existence and expiry date of a medical fitness certificate, where the certificate document itself is stored in the Controller’s cloud storage and only the administrative data remains in the application; image and audio data — photos and videos of events, where only metadata and small preview images remain in the application and the original files reside in the Controller’s cloud storage; consent records for image publication; usage data such as login times, email delivery logs and gallery access logs; and free-text notes entered by the Controller.
Art. 9 GDPR: the Controller decides whether and to what extent health-related data is recorded; the corresponding functions can be switched off entirely in the settings.
Minors: the Controller is responsible for obtaining the consent of legal guardians, in particular for publishing images and videos, for which German law additionally requires compliance with § 22 KUG.
Duration. For the term of the main agreement, thereafter as set out in clause 11.
