Data processing agreement (DPA)
Last updated:
Courtesy translation. Only the French version of this document has legal effect. It is the one that binds the parties, and the one a court would read. This translation is provided to help you understand it — where the two differ, the French text prevails.
This agreement is downloaded, not negotiated. You do not have to contact a salesperson or wait for a procurement cycle to obtain the document that lets you carry out your compliance assessment.
DRAFT TO BE VALIDATED BY A LAWYER — the structure and substance below match the requirements of article 28 of the GDPR, but the final wording must be reviewed and the signed document made available as a PDF.
1. Roles of the parties
The customer acts as controller. COMPANY NAME acts as processor, solely on behalf of the customer and on its documented instructions, for the data contained in the messages received in its inboxes.
2. Subject matter, duration and nature of the processing
Reception, temporary storage, indexing and retrieval through an application programming interface of electronic messages and SMS, for the purposes of software testing. The duration of the processing matches the duration of the subscription, and the storage period matches the retention configured by the customer.
3. Categories of data subjects and data
Determined by the customer. The service is designed to receive test data. The terms of service prohibit sending real personal data, and in particular the special categories referred to in article 9 of the GDPR.
4. Obligations of the processor
- Process the data only on the customer’s documented instructions.
- Ensure confidentiality by any person authorised to access the data.
- Implement the technical and organisational measures described in annex 2, and not reduce them during the term of the contract.
- Notify the customer of any personal data breach without undue delay, and at the latest within 48 hours of becoming aware of it.
- Assist the customer in responding to data subject requests and in carrying out impact assessments.
- Delete or return the data at the end of the contract, backups included, within thirty days.
5. Sub-processors
The list is published on the Data sovereignty page. Any addition is notified to account administrators thirty days before it takes effect, during which period the customer may object and, where applicable, terminate without penalty.
6. Transfers outside the European Union
Service data is hosted exclusively in France. The only transfer that may occur concerns billing data entrusted to Stripe, framed by the European Commission’s standard contractual clauses.
7. Audit
The customer may request the documentation of the security measures, and carry out a documentary audit once a year, subject to reasonable notice and to the confidentiality of information relating to other customers.
Annex 1 — Description of the processing
TO BE COMPLETED: detailed purposes, categories, durations, precise location.
Annex 2 — Technical and organisational measures
- Encryption in transit (TLS 1.2 minimum) and at rest.
- Logical isolation of data per organisation.
- Two-factor authentication and scoped API keys, with expiry.
- Logging of access and administrative actions.
- Encrypted backups, with restoration tested.
- Automatic deletion at the end of the configured retention period.
- Vulnerability management and patching policy.
A question about this document? hello@facteur.eu. We answer, and we would rather say “we do not know yet” than offer a reassuring approximation.