Need an officially signed copy? Open the signature form.
Data Processing Agreement (DPA)
Futuria CRM — Standard document for clients and users
Version 1.1 — Effective date: 25 May 2026
This Data Processing Agreement (“DPA”) governs the processing of personal data carried out by Glofu S.r.l. Unipersonale on behalf of clients and users of Futuria CRM services. It is a standard service document and may be accepted through a contract, order, electronic form, checkbox, electronic signature, public link or another documentable acceptance mechanism.
1. Parties and scope
1.1 This DPA applies between the client or user subscribing to or using Futuria CRM services — the “Client” or “Controller” — and Glofu S.r.l. Unipersonale, registered office at Via Merula 7, 20142 Milan (MI), Italy, VAT/Tax ID 10121290968, REA MI-2506784, certified email glofu@legalmail.it — “Glofu”.
1.2 It is made under Article 28 of Regulation (EU) 2016/679 (“GDPR”) and applies whenever Glofu processes personal data for the Client while providing Futuria CRM services.
1.3 Futuria CRM is a CRM service offered by Glofu using SaaS technology supplied by HighLevel Inc. Glofu acts towards the Client as reseller, distributor and service provider, using HighLevel Inc. as sub-processor for the Platform and its underlying technical infrastructure.
1.4 This DPA does not govern processing performed by Glofu as an independent controller, including billing, administration, management of the contractual relationship, legal compliance, security of its own account and its own communications. Those activities remain governed by the applicable privacy notices.
2. Roles of the parties
2.1 The Client determines the purposes and means of processing personal data entered, generated or managed in the Platform, including legal bases, notices, consent, configurations, segmentation, communications and enabled integrations.
2.2 Glofu processes personal data for the Client only to the extent necessary to provide, configure, maintain and support Futuria CRM services, in accordance with the Client’s documented instructions and the Platform’s functions.
2.3 HighLevel Inc. and the technical providers named in official HighLevel documentation act as sub-processors to the extent required to provide the Platform or functions actually enabled or used by the Client.
2.4 If the Client processes data for third parties, the Client remains responsible for correctly identifying roles and instructions. In that case, Glofu acts as sub-processor for that processing, within the boundaries of the Futuria CRM service.
3. Documented instructions
3.1 The Client’s documented instructions include this DPA, the applicable agreement or service order, configurations made in the Platform, support requests sent to Glofu and use of functions by the Client’s authorised users.
3.2 Glofu informs the Client if it believes an instruction infringes the GDPR or other applicable data-protection law, unless the law prohibits such notice.
3.3 Glofu is not required to carry out instructions outside the available functions, the applicable agreement or its role as reseller and distributor of the Platform.
4. Subject matter, duration and details of processing
4.1 The subject matter, nature, purposes, categories of personal data, categories of data subjects and processing period are set out in Annex 1, which forms part of this DPA.
4.2 Processing continues for the term of the contractual relationship between Glofu and the Client and for any further period technically or legally required for termination, mandatory retention, backups and secure deletion.
5. Glofu’s obligations
Within its role, the activities under its control and the information available, Glofu undertakes to:
- process personal data only on the Client’s documented instructions;
- ensure that authorised persons are bound by confidentiality obligations;
- adopt appropriate technical and organisational measures for activities under its control and, for the SaaS component, rely on the measures declared and contractually undertaken by HighLevel Inc.;
- assist the Client, where possible, in responding to data-subject rights requests;
- assist the Client, within the available information and nature of the service, with security, personal-data breaches, impact assessments and prior consultations under Articles 32–36 GDPR;
- ensure that sub-processors used for the service are bound by obligations substantially consistent with Article 28 GDPR;
- make reasonably necessary compliance information available to the Client; and
- delete or return personal data under clause 12, subject to law and technical backup retention governed by the Platform provider’s documentation.
6. Client obligations
The Client undertakes to:
- process personal data in accordance with the GDPR and applicable law;
- ensure valid legal bases, notices and consent for data entered into or processed through Futuria CRM;
- provide lawful, documented instructions compatible with the Platform’s functions;
- correctly manage users, permissions, credentials, integrations, lists, segments, content, messages and campaigns configured in the Platform;
- not enter special-category data under Article 9 GDPR, criminal-conviction or offence data under Article 10 GDPR, or other unnecessary data unless the Client has independently assessed lawfulness, necessity and compatibility with the service; and
- remain responsible for independent decisions about purposes, recipients, content and communication channels used through Futuria CRM.
7. Sub-processors
7.1 The Client authorises Glofu to use HighLevel Inc. as the principal sub-processor for the Futuria CRM SaaS Platform and the sub-processors listed by HighLevel, to the extent required by the service or functions actually enabled or used by the Client.
7.2 A sub-processor associated with a function the Client has not enabled or used is not involved in processing the Client’s data merely because it appears on HighLevel’s general list.
7.3 Sub-processors listed by HighLevel for AI functions apply only where those functions are actually enabled or used by the Client. This DPA does not itself activate AI functions.
7.4 Glofu uses a general authorisation model for sub-processors. If the list materially changes in a way relevant to the service, Glofu informs the Client by email, document publication or another reasonable channel. The Client may object for documented and reasonable data-protection grounds. If the objection cannot be resolved, the parties will consider terminating the affected function or service.
7.5 Glofu does not alter contracts between HighLevel Inc. and HighLevel’s sub-processors, but relies on HighLevel’s DPA and official documentation to pass applicable obligations along the processing chain.
7.6 Article 28(4) GDPR continues to apply to the initial processor’s responsibility for sub-processor compliance, within mandatory legal limits.
Principal sub-processors identified by official HighLevel sources, depending on the function used
| Entity | Role / purpose | Scope |
|---|---|---|
| HighLevel Inc. | CRM SaaS platform, application infrastructure, functions and related services. | Principal sub-processor for the platform component. |
| Google Cloud Platform / Google Cloud Services | Data storage and infrastructure services listed by HighLevel. | Applies according to HighLevel architecture and services. |
| Amazon Web Services (AWS) | Data storage, hosting or infrastructure services listed by HighLevel. | Applies according to HighLevel architecture and services. |
| Twilio / Mailgun | Communications, SMS, telephony or email, where those channels are used. | Applies only if the corresponding function is active or used. |
| Stripe | Payment services, where used through the Platform. | Applies only if the corresponding function is active or used. |
| Other HighLevel sub-processors | Technical, infrastructure or functional services in HighLevel’s official list. | Apply only to the extent required by functions actually enabled or used. |
8. International transfers
8.1 The Client acknowledges that the Platform is supplied through HighLevel Inc. and sub-processors that may process personal data outside the European Economic Area, including in the United States, as described in official HighLevel documentation.
8.2 Glofu authorises and documents those transfers to the extent required to provide the service, relying on the legal mechanisms declared by HighLevel, including the EU–U.S. Data Privacy Framework, UK Extension, Swiss–U.S. Data Privacy Framework, Standard Contractual Clauses and any further measures applicable under HighLevel’s DPA.
8.3 Glofu makes no additional international transfer for the Client beyond what is required for the service, unless instructed by the Client, required by law or caused by a function or integration enabled by the Client.
9. Security
9.1 Glofu adopts reasonable organisational and access measures for activities performed directly by its staff or authorised collaborators.
9.2 For the Platform’s SaaS component, technical and organisational measures are those declared by HighLevel in its official documentation, including access controls, encryption in transit and at rest, resilience, backups, application security and monitoring.
9.3 The Client remains responsible for correctly configuring users, permissions, credentials, authentication, content, lists, integrations and communication channels.
10. Personal-data breaches
10.1 Glofu informs the Client without undue delay after becoming aware of a personal-data breach affecting data processed for the Client, taking account of the service, available information and notices received from HighLevel or another sub-processor.
10.2 Notice is sent to the email address in the account, agreement or official Client communications. Glofu’s privacy contact for Client notices is privacy@futuriamarketing.com.
10.3 Within the information available, Glofu provides details useful for assessing the nature of the breach, categories and estimated volume of data or data subjects, likely consequences, and measures taken or proposed.
11. Assistance, information and audits
11.1 Within reasonable limits and taking account of the processing, Glofu assists the Client with obligations relating to data-subject rights, security, breaches, impact assessments and prior consultations.
11.2 Glofu makes reasonably necessary information available to demonstrate compliance with Article 28 GDPR and this DPA, including contracts, HighLevel documentation, security statements and information available in the Platform.
11.3 Audits and reviews should preferably be documentary and remote, with reasonable written notice and due regard for confidentiality, security, other clients’ rights and the Platform’s technical limits. Direct access to HighLevel systems, data centres or infrastructure is governed exclusively by HighLevel documentation and processes.
11.4 Manifestly excessive, repeated, unnecessary or out-of-scope requests may be handled under economic and operational terms to be agreed, subject to mandatory law.
12. Return and deletion of data
12.1 During the agreement, the Client may export or delete data using Platform functions, within technical limits and account permissions.
12.2 On termination, at the Client’s request and within the Platform’s technical limits, Glofu assists the Client in returning or exporting personal data before deletion.
12.3 After termination, Glofu deletes or arranges deletion of personal data processed for the Client in accordance with the timing and methods technically applicable to the service and HighLevel chain, subject to law, protection of rights, administrative retention and backups managed under secure progressive-deletion procedures.
13. Limitations and liability
13.1 Glofu is responsible for this DPA within its role, activities under its control and mandatory liabilities under applicable law.
13.2 This DPA does not transfer the Controller’s responsibilities to Glofu, including legal bases, notices, consent, content, lists, campaigns, instructions, configurations, integrations, user management and use of the Platform.
13.3 Subject to mandatory law, the parties’ liability remains subject to the limitations, exclusions and conditions in the principal agreement or applicable terms of service.
14. Publication, updates and applicable version
14.1 Glofu may provide this DPA through a public link, electronic contract, Futuria CRM template or another digital method. The version applicable to a Client is the version accepted by that Client or incorporated into the relevant agreement, order, form or activation flow.
14.2 Glofu may update this DPA for legal, technical or organisational changes or alignment with HighLevel documentation. Material changes are communicated by email, document publication or another reasonable channel.
14.3 If a change materially affects processing of the Client’s personal data, the Client may object on documented and reasonable grounds within the period specified in the notice or, if none is specified, within 30 days. Without objection, continued use constitutes acceptance, unless law or contract requires otherwise.
15. Governing law and jurisdiction
This DPA is governed by Italian law. Subject to mandatory jurisdiction, the courts of Milan have exclusive jurisdiction over any dispute.
16. Final provisions
16.1 Invalidity of one clause does not affect the remaining provisions.
16.2 This DPA may be accepted electronically, including through an online form, checkbox, electronic signature, order form, public link incorporated into a contract or another mechanism capable of documenting acceptance.
16.3 If this DPA conflicts with another contractual document, this DPA prevails only for processing personal data for the Client, unless a later specific document expressly provides different privacy terms.
Annex 1. Processing details
| Element | Detail |
|---|---|
| Subject matter | Provision, configuration, maintenance and support of Futuria CRM services. |
| Nature of processing | Collection, recording, organisation, storage, consultation, use, disclosure, transmission, extraction, deletion and other operations required by Platform functions and Client instructions. |
| Purposes | CRM and contact management, marketing and sales automation, communications, integrations, support, security and technical operation of the service. |
| Data categories | Data determined by the Client, including identifiers, contact and commercial or CRM data, communications, notes, preferences, statistics, files or attachments uploaded by the Client, and technical data required for the service. |
| Data-subject categories | Clients, leads, prospects, business contacts, end users, suppliers, representatives, authorised Client users and other people whose data the Client enters or processes through the Platform. |
| Special categories | Not envisaged as ordinary processing. The Client must not enter them without independently assessing lawfulness, necessity and compatibility with the service. |
| Duration | The contractual term and any further period required for termination, export, deletion, backup, legal obligations or protection of rights. |
Annex 2. HighLevel sources used
Information about HighLevel, sub-processors, transfers and security was drafted solely from these official HighLevel sources, consulted on 25 May 2026:
| Official source | URL |
|---|---|
| HighLevel Customer Data Processing Addendum | https://www.gohighlevel.com/data-processing-agreement |
| HighLevel Sub-processors | https://www.gohighlevel.com/sub-processors |
| HighLevel Privacy & Security | https://www.gohighlevel.com/privacy-and-security |
If those sources change, Glofu may update this DPA to stay aligned with the supply chain actually applicable to the service.
Annex 3. Acceptance
This DPA is valid when accepted by signature, order, electronic form, checkbox, electronic signature, public link incorporated into a contract or another documentable method of contractual acceptance. For Futuria CRM contract templates, acceptance may be collected through the electronic-signature or approval flow supplied by the Platform.

