Who is who
You decide what Mediastilo reads and publishes for you, so you are the controller of the personal data in it: names in the stories you cover, your team’s accounts, readers’ details if your site passes any on. Mediastilo is your processor: we handle that data only to run the service you asked for.
What the agreement covers
Article 28(3) of the GDPR lists what a processor agreement has to contain. Ours covers each point:
- The processing itself: subject matter, duration, nature and purpose, the types of personal data and the people they concern.
- Your instructions: we process your data only on your documented instructions.
- Confidentiality: everyone who handles it is bound to keep it confidential.
- Security: the technical and organisational measures we take under Article 32.
- Sub-processors: we use only the providers on our published list, bind them to the same obligations, and tell you before adding one.
- Your people’s rights: we help you answer requests to access, correct or delete personal data.
- Breaches and assessments: we help you meet your duties under Articles 32 to 36, including notifying breaches without undue delay.
- The end: when you leave, we return or delete your data, as you choose.
- Proof: we give you the information needed to show all of this, and allow for audits.
Security measures, in short
- The platform and its database run in Nuremberg, Germany.
- Credentials for your site are encrypted at rest with AES-256-GCM, per brand, and never shown back in full.
- Access inside your account follows roles: owner, admin and member.
- Your content shapes your drafts only and never trains a model shared with other customers.
How to get it signed
Tell us your organisation’s name and who signs for it through the contact page. We send the agreement for signature, usually within two business days. If your organisation has its own template, send that instead and we will work through it with you.
Public bodies: the agreement can be attached to your procurement contract or purchase order.