⚠️ To be reviewed by a lawyer before signature. Courtesy translation: the French version is the only one that is binding
This English version is provided for the convenience of non-French-speaking readers. In the
event of any discrepancy of meaning or interpretation, the
French version prevails. The structure follows article 28 of the
GDPR (mandatory content of a processing agreement). The publisher's identity, the
sub-processors, the location of the data, the breach notification deadline and the backup
retention period are filled in and reflect how the service actually works. Any serious B2B
customer will ask for this document before signing.
Data Processing Agreement
This agreement supplements the Terms and applies to the
processing of personal data carried out by the Publisher on behalf of the Customer, in
accordance with article 28 of the GDPR.
1. Role of the parties
The Customer is the controller of the personal data it enters
into the Service (its own customers, prospects, contacts and employees).
The Publisher (Grégory DURAND — ECOM-INDUSTRIE, company number 521 070 284)
acts as a processor within the meaning of the GDPR for the hosting, technical
operation and maintenance of the Service.
2. Subject matter, nature and purpose of the processing
| Subject matter | Provision of customer relationship management (CRM) software as a SaaS offering |
| Nature of the operations | Hosting, storage, backup, provision through a web interface,
optional processing by third-party AI/telephony services depending on the modules enabled by the Customer |
| Purpose | To allow the Customer to manage its commercial relationships (customers, quotes,
pipeline, telephony, reports) |
| Duration | The duration of the subscription contract, plus the grace period set out in the
Terms |
3. Categories of data subjects and of data
Business contacts of the Customer (customers, prospects) and users of the Service (the
Customer's employees). Categories of data: see the detail in the
privacy policy, section 1. No “special category”
data (health, opinions, origin and the like) is processed in the normal use of the Service.
4. Obligations of the processor (Publisher)
- Process the data only on documented instructions from the Customer (normal operation of the Service).
- Ensure the confidentiality of the persons authorised to process the data (role-based access
partitioning, see the Service's role-based access control).
- Implement appropriate security measures (encryption in transit, password hashing, backups,
automatic purging according to the configured retention policy).
- Engage a sub-processor only with the Customer's prior written, general or specific
authorisation — the current list of sub-processors appears in the
privacy policy, section 4. The Customer is informed
of any change and may object to it.
- Assist the Customer in responding to requests from data subjects exercising their rights.
- Notify the Customer of any personal data breach within 72 hours of becoming aware of it.
- Delete or return all the data at the end of the service, in accordance with the arrangements
set out in the Terms (termination section).
- Make available to the Customer all information necessary to demonstrate compliance with the
obligations of this article and allow for an audit, on reasonable request.
5. Authorised sub-processors
As at the date of signature, the Customer authorises the use of the following sub-processors
(enabled according to the modules subscribed to):
| Sub-processor | Service | Safeguards |
| Hostinger International Ltd (Cyprus) | Hosting | European Union — no transfer outside the EU |
| Twilio Inc. | Telephony (optional module) | Standard contractual clauses (transfers outside the EU) |
| OpenAI / Anthropic | AI — transcription, rewriting (optional modules) | Standard contractual clauses (transfers outside the EU) |
| Pappers / API Entreprise (INSEE) | Public company financial data (optional module) | Processing in France |
6. Technical and organisational security measures
- Authentication by hashed password (never stored in clear text), minimum complexity policy.
- Optional two-factor authentication (time-based one-time codes), which the administrator may
require on administrator accounts.
- Automatic sign-in attempt throttling (protection against brute-force attacks).
- Data partitioning by user role (a sales representative only sees their own portfolio, unless
they hold the sales management or administrator role).
- End-to-end encrypted connection (HTTPS).
- Automatic daily backups, retained for 30 days.
- Automatic and irreversible purging of call recordings at the end of the retention period
configured by the Customer (actual deletion at the technical sub-processor, not only in the
local database).
- Database schema migrations tracked and versioned.
7. Audit and documentation
The Customer may request, once a year or where there is reasonable suspicion of a failure, a
documented description of the security measures in force. An on-site audit, or an audit by an
appointed provider, may be arranged on terms to be agreed (notice, cost, confidentiality).
8. Language
This agreement was drawn up in French. This English version is a courtesy translation. In the
event of any discrepancy between the two versions, the
French version shall prevail.