Skip to main content

Template to be reviewed by legal counsel before going to production.

This document is provided for informational purposes only. It contains fields to be completed (in square brackets) and must be adapted to your actual situation by a legal professional before any publication.

Data Processing Agreement (DPA)

Last updated: [DATE DE MISE A JOUR]

This data processing agreement (hereinafter the "DPA") supplements the general terms and governs the processing of personal data carried out by [RAISON SOCIALE] (hereinafter the "Processor") on behalf of the client (hereinafter the "Controller"), in accordance with Article 28 of the GDPR.

1. Roles of the parties

With respect to prospecting data imported and processed through the Service, the Client acts as data controller and the Publisher as data processor. The Client determines the purposes and means of the processing; the Processor processes the data only on the Client's documented instructions.

2. Subject matter, duration, nature, and purpose of the processing

  • Subject matter: provision of B2B prospecting features (prospect management, sending and tracking of messages, sales pipeline, AI assistance).
  • Duration: for the duration of the contractual relationship and until erasure or return of the data.
  • Nature of the operations: collection, recording, organization, storage, consultation, transmission, erasure.
  • Purpose: to enable the Client to conduct its commercial prospecting campaigns.

3. Categories of data subjects and of data

  • Data subjects: the Client's prospects and business contacts, contact persons at the targeted organizations.
  • Categories of data: identification and professional data (name, job title, employer, business email address, phone, public profiles), history of exchanges, and pipeline status. The Client agrees not to process special categories of data through the Service.

4. Processor obligations

The Processor agrees to:

  • process the data only on the documented instructions of the Controller, including with regard to transfers outside the EU;
  • ensure confidentiality and ensure that persons authorized to process the data are bound by an obligation of confidentiality;
  • implement appropriate technical and organizational security measures (Article 32 of the GDPR);
  • assist the Controller in responding to data subjects' requests to exercise their rights;
  • assist the Controller in ensuring compliance with its obligations regarding security, breach notification, and impact assessments;
  • notify the Controller of any data breach without undue delay after becoming aware of it;
  • make available the information necessary to demonstrate compliance with these obligations and allow for reasonable audits.

5. Artificial intelligence processing (BYOK model)

AI features are implemented using the Client's API key. The data submitted to the AI passes through the Client's account with the AI provider it has chosen (Anthropic, OpenAI, or another). The Client acknowledges that it configures and controls this processing, that it is responsible for the choice of provider and the acceptance of its terms, and that it is the Client's responsibility to ensure that the data submitted to the AI is submitted on a lawful basis. The AI provider contracts directly with the Client.

6. Subprocessors

The Controller authorizes the Processor to engage the subprocessors listed in the register of subprocessors. The Processor imposes on them data protection obligations equivalent to those of this DPA and informs the Controller of any intended change, allowing the Controller to object on legitimate grounds.

7. Transfers outside the European Union

Where a subprocessor processes data outside the European Union, transfers are governed by appropriate safeguards, in particular the standard contractual clauses (SCCs) of the European Commission, supplemented where necessary by additional measures.

8. Security

The measures implemented include in particular:

  • encryption of sensitive secrets at rest (API keys, tokens, credentials) and of communications in transit (TLS);
  • workspace isolation (multi-tenant architecture, segregation of data between clients);
  • access control and logging, management of authorizations;
  • backups and restoration procedures.

9. Assistance, breaches, and audit

The Processor assists the Controller in handling data subjects' requests and data breaches. It notifies, without undue delay, any breach likely to give rise to a risk and provides the information needed for notification to the supervisory authority. The Controller may, under reasonable conditions and with prior notice, verify compliance with the obligations of this DPA.

10. Fate of the data at the end of the contract

At the end of the services, the Processor shall, at the Controller's choice, erase or return the data, and destroy existing copies, unless retention is required by law. Deleting the workspace from the application triggers the erasure of the associated data, subject to technical backups with limited rotation.

11. Relationship with the other documents

This DPA prevails, solely with respect to the protection of data processed on behalf of the Client, over the general terms. For all other matters, the general terms and the privacy policy remain applicable.