Data Processing Agreement
This Data Processing Agreement (DPA) supplements the Terms of Sale for B2B customers (SoloCore, BusinessCore and Max plans) and describes the roles and responsibilities of each party under the General Data Protection Regulation.
Preamble
This DPA applies to the contractual relationship between PrivateCore as publisher and its professional customers. It clarifies each party's GDPR role, the security guarantees the publisher provides, and how data-subject rights are handled. It forms an integral part of our general terms of sale.
Article 1: Roles and processing regimes
The Customer is the controller for all personal data processed through the PrivateCore software (customer, employee, supplier and transaction data, and so on). The Customer determines the purposes and means of that processing.
The publisher's role depends on the hosting mode chosen by the Customer, as stated on their quote and invoices. Two regimes coexist, and one Customer may move from one to the other.
- "At my place" mode: occasional processorship. The instance runs on the Customer's own hardware. The publisher hosts nothing and holds no copy of the data. It acts as a processor within the meaning of article 28 GDPR only for remote maintenance explicitly accepted by the Customer (a Tailscale tunnel the Customer switches on), software updates deployed to their machine, and technical support they request.
- "Online" mode: permanent processorship. The instance runs on servers rented by the publisher in France. The publisher is a processor within the meaning of article 28 GDPR for all hosted data, for the whole duration of the contract, and every obligation in this agreement applies to it without restriction.
Article 2: Subject matter, nature and duration of processing
- Subject matter. Supply, hosting where applicable, maintenance and support of a business-management software package.
- Nature of the operations. Storage, consultation, backup, restoration, defect correction and, on instruction, export or erasure.
- Purpose. To let the Customer run their own management system. The publisher pursues no purpose of its own: the data is never analysed, aggregated, used to train a model, or exploited commercially.
- Duration. The term of the contract, extended by the return period set out in article 13.
Article 3: Categories of data and of data subjects
The categories of personal data processed depend on how the Customer uses the software; the publisher has no prior knowledge of their content:
- End-customer data (contact details, commercial relationship history).
- Employee and applicant data (contact details, schedules, payroll, working time, absences).
- Supplier and contractor data.
- Transaction data (invoices, payments, accounting).
In "At my place" mode, this data stays physically on the Customer's machine and is neither collected nor stored by the publisher. In "Online" mode, it is hosted in the Customer's dedicated instance, in France.
Article 4: Special categories of data
The Customer undertakes not to process health data within the meaning of article 9 GDPR in an instance hosted by the publisher. Hosting such data on behalf of a third party requires the "Hébergeur de Données de Santé" certification provided for by article L.1111-8 of the French public health code, which the publisher does not hold at this date.
Customers concerned (healthcare professionals, ambulance services, medico-social organisations) use "At my place" mode, in which health data never leaves their premises and the publisher only intervenes for occasional maintenance, by invitation and under logging.
The other special categories (opinions, beliefs, trade-union membership, biometric data) are not required by the software. Should the Customer nonetheless process them, they inform the publisher so that the security measures can be reassessed jointly.
Article 5: Documented instructions
The publisher acts only on the Customer's written instructions (email, support ticket, signed quote). Any instruction contrary to the GDPR or to French law will be flagged to the Customer and may justify suspending the intervention.
In "Online" mode, the day-to-day operation of the instance (hosting, backup, technical supervision) constitutes a standing instruction arising from the contract itself.
Article 6: Confidentiality
Publisher staff with potential access to the data (currently the founder only) are bound by a written confidentiality undertaking that survives the end of their assignment.
Article 7: Security measures
The publisher implements the following technical and organisational measures, common to both modes:
- Encryption at rest (AES-256) and in transit (TLS 1.3 for web traffic, WireGuard through Tailscale for remote administration).
- Strong authentication by certificate and private key for any administrator access.
- Immutable audit logs, timestamped, cryptographically signed and available to the Customer.
- Artificial-intelligence processing executed locally on the Customer's instance: by default, no content is sent to a third-party AI provider. Only the Mistral AI integration described in article 8, when the Customer switches it on, sends the documents or datasets the Customer chooses. The publisher trains no model on the Customer's data.
Measures specific to "At my place" mode: full-disk encryption through Apple FileVault; remote access impossible until the Customer switches it on.
Measures specific to "Online" mode: a dedicated instance per Customer, with its own database and its own container, with no database shared between Customers; encrypted daily backups kept for a rolling 14 days and stored off the backed-up machine; publisher access to content limited to operating the service, support and service restoration, and logged.
Article 8: Sub-processing
The Customer gives general authorisation to the sub-processors listed below. Any addition or replacement is notified to the Customer at least thirty (30) days before it goes live; the Customer may object on legitimate data-protection grounds and, failing a solution, terminate without penalty.
- Scaleway SAS (France): hosting of instances in "Online" mode. No role in "At my place" mode.
- Infomaniak Network SA (Switzerland): delivery of transactional emails sent by the instance (invoices, acknowledgements, notifications), where the Customer uses the publisher's mail service rather than their own.
- 650 Industries, Inc., trading as Expo (United States): relay of the mobile apps' push notifications to Apple and Google. The data sent is the device token, the title and short text of the notification (which may name a person or a business object, such as an order) and routing data pointing to the relevant screen.
- Apple Inc. and Google LLC (United States): delivery of those notifications to the device, through the APNs and Firebase Cloud Messaging services, with the same data.
- Cloudflare, Inc. (United States): tunnel for the privatecore.fr marketing site only. No PrivateCore service data travels through that channel.
The following integrations are off by default and only bring in a sub-processor if the Customer switches them on from their own instance, by entering a key, a token or a setting:
- Stripe Payments Europe Ltd (Ireland, with onward sub-processing by Stripe, Inc. in the United States): online collection and pay-at-table. The data sent is the amount, the order identifier and the transaction metadata; the card number is never stored by the publisher.
- Google Ireland Ltd: retrieval of public reviews through the Places API, and issuance of cards in the Google Wallet format (cardholder name, card identifier).
- Functional Software, Inc., trading as Sentry (United States): tracking of the instance's technical errors. The data sent is the error traces (message, stack trace, route concerned), without the SDK's default personal data and after masking of tokens, email addresses and sensitive fields; it is hosted in the provider's European region where that region is chosen.
- Mistral AI SAS (France): text recognition on documents sent by the Customer, and fine-tuning of a model from the dataset the Customer builds. The data sent is those documents and that dataset, with customer data anonymised by default.
- Twilio Inc. (United States): SMS sending and telephony. The data sent is the recipient's number and the message text; for calls, the caller's number and the call audio stream.
- Brevo (France): SMS sending. The data sent is the recipient's number and the message text.
- Meta Platforms Ireland Ltd (Ireland, with onward sub-processing by Meta Platforms, Inc. in the United States): publishing on Facebook and Instagram, WhatsApp messaging and reading of advertising metrics. The data sent is the published content, the number and messages of WhatsApp contacts, and the Customer's account token.
- HubSpot (headquartered in the United States): import of contacts, deals and companies from the Customer's HubSpot account. The data sent is the access token and the search criteria; the imported data comes from the Customer's account.
- Telegram (headquartered outside the European Union): cash-discrepancy alert sent to the channel chosen by the Customer. The data sent is the alert text (date, card takings received and expected, discrepancy found) and the channel identifier.
- Qonto (France): reading of the transactions on the Customer's business bank account for reconciliation. The data sent is the access token; the data received is the bank transactions.
- Bridge (France): aggregation of bank accounts and, under a separate setting, initiation of transfers. The data sent is the access token and, for a transfer, the beneficiary, their IBAN and the amount; the data received is the bank accounts and transactions.
The publisher contractually imposes on each of them protection obligations equivalent to those in this agreement and remains fully liable to the Customer for their performance. For integrations switched on by the Customer, the publisher answers for the configuration and the transmission; the provider's own terms govern the processing it carries out.
Article 9: Transfers outside the European Union
Data processed on the Customer's behalf is stored within the European Union: on their own hardware in "At my place" mode, on servers located in France in "Online" mode. It is neither stored nor backed up outside the EU or EEA; only the flows described below leave it.
Two flows leave the Union without the Customer switching anything on: email delivery by Infomaniak, in Switzerland, a country covered by a European Commission adequacy decision; and push-notification delivery by Expo, Apple and Google, which carries the title and short text of the notification, framed by the standard contractual clauses and, where applicable, by the EU-US Data Privacy Framework.
If the Customer switches on Stripe, the Google services, Sentry, Twilio, Meta or HubSpot, the corresponding data is sent to those providers, whose transfers outside the Union are framed by the standard contractual clauses and, where applicable, by the EU-US Data Privacy Framework. For Sentry, traces stay hosted within the Union where the provider's European region is chosen.
If the Customer switches on the Telegram alert, the alert text is sent to a provider established outside the Union; that alert carries only amounts and a date.
Mistral AI, Brevo, Qonto and Bridge are established in France: switching them on entails no transfer outside the Union on the publisher's part.
Article 10: Data-subject rights
The publisher assists the Customer, as far as reasonable and taking into account the nature of the processing, in responding to requests to exercise rights (access, rectification, erasure, portability, objection) from data subjects.
As those requests are addressed to the Customer in their capacity as controller, the Customer remains responsible for the final answer. Where a data subject contacts the publisher directly, the publisher refers them to the Customer without handling the substance of the request.
Article 11: Breach notification and assistance
In the event of a personal-data breach affecting the processing carried out on the Customer's behalf, the publisher informs the Customer within a maximum of 48 hours of detection, with the elements they need to make their own notification to the CNIL if required.
The publisher also assists the Customer, on request, in carrying out data-protection impact assessments and in the prior consultation of the supervisory authority, in accordance with articles 32 to 36 GDPR.
Article 12: Audit
The Customer may audit the publisher's infrastructure, on 30 days' written notice. One audit per year is free of charge; any additional audit is at the Customer's expense (publisher time billed at the applicable rate). The audit may be carried out by the Customer or by a third party of their choosing, subject to a confidentiality undertaking.
Article 13: End of processing
"At my place" mode. All personal data processed stays physically with the Customer. The publisher has no data to return or erase server-side, since it holds no copy.
"Online" mode. On termination, the publisher makes a full export of the data available to the Customer, in open formats usable without PrivateCore, for thirty (30) days. After that period, the instance and its backups are irreversibly erased and an erasure certificate is issued on request.
In both cases, the publisher erases its own intervention logs within 90 days at most, unless a legal retention obligation applies.
This DPA is available on written request to dpo@privatecore.fr for formal signature.
Ready to take back control?
A bespoke install, an answer from the founder, and a Mac Mini you buy yourself or we deliver configured.