Romeo Apps / Accounts Receivable Audit

Data Processing Addendum

Version: 21 July 2026. This addendum applies only to an accepted B2B Accounts Receivable Evidence Audit order. It must be executed before Romeo Apps receives any record that is not truly anonymous.

1. Parties and roles

The purchasing creditor named in the written scope acceptance is the controller. Simone Maria Romeo, operating as Romeo Apps, is the processor. The controller determines the purposes, legal basis, accuracy, recipients, and retention of the source records and confirms it is authorized to provide them.

2. Processing instructions

Romeo Apps processes data only on the controller's documented instructions to prepare the accepted factual audit. The purpose is limited to field-level chronology, document cross-checking, factual flags, promise tracking, neutral client-review drafts using controller-supplied positions, and a descriptive handoff index. Romeo Apps does not contact the controller's customer, decide legal rights, use the data for advertising or model training, sell it, or combine it with unrelated records.

3. Duration, data, and people

Processing starts only after written scope acceptance and execution of this addendum. Working copies are returned or deleted at the controller's choice no later than 30 days after delivery, unless a narrower transaction record must be retained for accounting, fraud prevention, or a documented legal dispute. Data is limited to business-contact identifiers and the minimum contract, purchase-order, invoice, delivery, acceptance, reminder, promise, and payment-reference fields needed for the audit. Data subjects may include the controller's staff and business-customer personnel. Consumer records, identity documents, bank or card details, credentials, special-category data, criminal-offence data, and unrelated customer records are prohibited.

4. Confidentiality and access

Only Romeo Apps personnel who need the records for the accepted audit may access them, and they are bound to confidentiality. Access is limited to the minimum necessary period and purpose. The controller must redact irrelevant data before transfer.

5. Security

Romeo Apps uses encrypted transport, encrypted storage where records are retained, device access controls, least-privilege access, local workspace separation, and deletion checks. Records are not accepted through public issue trackers, social-media messages, or checkout free-text fields. The controller and Romeo Apps agree the transfer route in writing after scope acceptance.

6. Subprocessors and transfers

No subprocessor may receive source records without prior written controller authorization. The approved list, processing location, purpose, and transfer safeguard are recorded in the order-specific schedule before use. A new or replacement subprocessor requires advance notice and an opportunity for the controller to object. Romeo Apps remains responsible for equivalent data-protection obligations. If no subprocessor is listed in the schedule, none is approved.

7. Assistance and incidents

Taking account of the processing, Romeo Apps will reasonably assist the controller with data-subject requests, security obligations, breach assessment, data-protection impact assessments, and regulator consultation. Romeo Apps will notify the controller without undue delay after becoming aware of a personal-data breach and provide available facts needed for the controller's response.

8. Compliance information and audit

Romeo Apps will provide information reasonably necessary to demonstrate compliance with Article 28 and permit a proportionate audit by the controller or its mandated auditor, subject to confidentiality, security, and reasonable scheduling. Romeo Apps will immediately inform the controller if an instruction appears to infringe applicable data-protection law and will pause the affected processing.

9. Return, deletion, and termination

On completion or written request, Romeo Apps returns or deletes personal data at the controller's choice and deletes existing copies unless applicable law requires retention. The controller may terminate processing immediately for a material breach. Excluded, disputed, excessive, or unsafe records are rejected and deleted without being converted into another service.

10. Order-specific schedule and execution

The binding schedule identifies the controller's legal name and contact, order ID, documented instructions, governing-law statement supplied by the controller, categories of records and people, approved transfer route, any approved subprocessor and transfer safeguard, retention choice, and authorized signatories. Romeo Apps sends that schedule after fit review. The addendum becomes effective when both parties sign it or exchange an unambiguous written acceptance that identifies the order and this version.

Contact

Data-processing and deletion requests: romeo@romeoapps.com.