Data Processing Agreement (DPA)
Last updated: June 1, 2026
This Data Processing Agreement ("DPA") forms an integral part of the General Terms of Sale and applies when Technologie Sobriété Soutenable (TSS) processes personal data on behalf of a business customer in the context of the DEPOSIUM® service. It is entered into by adhesion: it applies automatically, without separate signature, upon subscription to a business plan. A signed version may be provided on request at [email protected].
1. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "sub-processor" have the meaning given to them by Regulation (EU) 2016/679 (GDPR). "Customer" means the business subscriber; "TSS" means Technologie Sobriété Soutenable, publisher of DEPOSIUM®.
2. Subject matter and roles of the parties
In the context of the service, the Customer acts as controller and TSS as processor. TSS processes the personal data contained in the documents and content imported by the Customer solely to provide the service. The details of the processing (subject matter, duration, nature, purpose, categories of data subjects and data) are set out in Annex I.
3. Processing on documented instructions
TSS processes the data only on the Customer's documented instructions, as embodied in the Terms of Use/Sale, the service configuration and any subsequent written instruction. TSS informs the Customer if an instruction appears to infringe the GDPR or other applicable law. TSS never uses the Customer's content to train its AI models.
4. Confidentiality
TSS ensures that persons authorised to process the data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and access the data only to the extent necessary to provide the service.
5. Security of processing (art. 32)
TSS implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, described in Annex II (including encryption in transit and at rest, access control, hosting in the European Union, logging).
6. Sub-processors
The Customer gives general authorisation for the use of sub-processors to provide the service. The up-to-date list is set out in Annex III. TSS imposes on each sub-processor data protection obligations equivalent to those of this DPA. TSS informs the Customer of any intended addition or replacement with reasonable prior notice (at least 30 days), allowing the Customer to object on legitimate data protection grounds.
7. Transfers outside the European Union
Application data is hosted at rest in the European Union. Where a sub-processor is established outside the EU or is a company subject to third-country law, any transfer is framed by the appropriate safeguards of art. 46 GDPR: an adequacy decision (including the EU–US Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses.
8. Assistance to the controller
Taking into account the nature of the processing, TSS assists the Customer, through appropriate technical and organisational measures, in responding to data subjects' requests to exercise their rights (access, rectification, erasure, restriction, portability, objection), and in complying with its obligations regarding security, breach notification, data protection impact assessments (DPIA) and prior consultation, insofar as reasonable and in light of the information available to TSS.
9. Personal data breaches
TSS notifies the Customer of any personal data breach concerning it without undue delay after becoming aware of it, providing the information reasonably available to enable the Customer to meet its own notification obligations (art. 33 and 34 GDPR).
10. Return and deletion of data
At the end of the provision of the service, and at the Customer's choice, TSS returns the personal data and/or deletes it, together with existing copies, unless legally required to retain it. Return and export options are available from the account area.
11. Audit and provision of information
TSS makes available to the Customer the information necessary to demonstrate compliance with the obligations of this DPA and allows for and contributes to audits, including inspections, by the Customer or a mandated auditor, under reasonable conditions (notice, confidentiality, proportionate frequency). Sub-processors' certifications and reports (see Annex III) may be provided for this purpose.
12. Liability
The parties' liability under this DPA applies in accordance with art. 82 GDPR and, where applicable, within the liability limits set out in the Terms of Sale.
13. Term
This DPA applies for the entire duration of the processing of data by TSS on behalf of the Customer, i.e. for the duration of the subscription and until the return or deletion of the data.
14. Governing law
This DPA is governed by French law. Disputes fall under the jurisdiction of the courts of Montpellier.
Annex I — Details of the processing
Subject matter: provision of the DEPOSIUM® document analysis service.
Duration: term of the subscription.
Nature and purpose: import, indexing, enrichment, search and AI querying of the Customer's content.
Categories of data subjects: determined by the Customer (depending on the content of imported documents — e.g. the Customer's employees, clients, contacts).
Categories of data: determined by the Customer (any data present in imported documents; the Customer refrains from importing special categories within the meaning of art. 9 without an appropriate legal basis).
Annex II — Technical and organisational security measures
• Encryption of data in transit (TLS) and at rest.
• Application and database hosting in the European Union (Amsterdam).
• Role-based access control and strong authentication (MFA available).
• Data segregation by account/workspace.
• Access logging and traceability.
• Backups and continuity plan.
• Use of certified sub-processors (SOC 2, ISO 27001, etc. — see Annex III).
• Commitment not to use content to train models.
Annex III — Sub-processors
The up-to-date list of sub-processors (inference operators, hosting, payment), along with their locations, certifications and transfer mechanisms, is detailed in the Privacy Policy (Hosting and data transit section), with links to each sub-processor's trust pages.