Data processing agreement (summary)

Last updated: October 2026

Signed before we touch any data. The signed agreement prevails.

01

Roles

While we process your raw data to de-identify it, we act as your processor under GDPR art. 28, only on your documented instructions. The result is anonymized data, which is no longer personal data; it is licensed under the supplier agreement.

02

Location

Processing happens in EU data centers in Amsterdam and Frankfurt.

03

Security

Encryption in transit and at rest, read-only access, least-privilege access for named staff under confidentiality, and full access logging.

04

Deletion

Raw data is deleted after packaging. Access tokens are revoked when the project ends.

05

Sub-processors

Scaleway — hosting (Amsterdam) · OVHcloud — backups (Frankfurt) · Brevo — email (Paris). You're notified 30 days before any change and may object.

06

Assistance

We help with data subject requests, your DPIA and the information for your staff or works council.

07

Incidents

Notified to you without undue delay, and within 48 hours.

08

Audits

You may audit our compliance once a year, or after an incident.

Request the full DPA