Data Processing Addendum
This DPA forms part of the ProxCenter commercial documents between the Customer (Controller) and Emmanuel Revy, entrepreneur individuel (EI), trading under the commercial name ProxCenter, business establishment: 3 route de Darbonnay, 39230 Saint-Lothain, France, registered with the RNE under SIREN 885 316 455 and SIRET 885 316 455 00017 (Processor). It applies only where the Processor processes Personal Data on the Controller's documented instructions for support or another contracted service.
1. Processing details
Duration: the service term and the time needed to resolve support, plus lawful retention. Nature: access, collection, consultation, storage, analysis, transmission and deletion as needed for support. Purpose: to diagnose, respond to and resolve Customer requests. Data subjects: Customer personnel, users or persons whose data appear in support materials. Data: contact, account, technical-log and incident data submitted or authorised by the Controller.
2. Processor obligations
The Processor will process only on documented instructions unless law requires otherwise; keep authorised persons under confidentiality; implement appropriate security; assist the Controller with data-subject rights and GDPR obligations, taking account of the nature of processing; notify the Controller without undue delay after becoming aware of a personal-data breach affecting DPA data; provide reasonable compliance information; and delete or return data at the end of services unless law requires retention.
3. Sub-processors and transfers
The Controller gives general authorisation for necessary sub-processors, provided the Processor imposes materially equivalent protections and gives reasonable advance notice of a material new or replacement sub-processor, allowing an objectively justified objection. Transfers outside the EEA require a valid legal mechanism. A current sub-processor list is available on request.
4. Controller obligations and audit
The Controller must minimise the data sent for support, must not send credentials or special-category data unless strictly necessary and authorised, and remains responsible for its infrastructure and backups. The Controller may request reasonable written compliance information. Any audit must be proportionate, confidential, secure and non-disruptive; available reports may satisfy the request. This DPA prevails for conflicts concerning personal-data processing.