Data Processing Agreement (DPA)
Last updated: July 2026
1. Purpose
This agreement governs the processing of personal data that DataVigia (data processor) carries out on behalf of the customer (data controller) in the provision of the service, in accordance with Article 28 GDPR. In the event of conflict, this agreement prevails over the general terms as regards data protection.
2. Nature, purpose and instructions
DataVigia processes the data only to provide the security auditing, exfiltration and ransomware detection and anti-phishing training service, and only in accordance with the customer's documented instructions, including as regards international transfers. If it considers that an instruction infringes the GDPR or another data protection rule, DataVigia informs the customer without delay.
3. Data and data subjects
The processing covers security metadata (permissions, configurations, access logs, file and folder names), account data and the data of the customer's employees for training simulations. The data subjects are the customer's employees, administrators and contacts. The content of files is NOT processed.
4. Obligations of the processor
DataVigia processes the data only in accordance with the customer's instructions, ensures that the persons authorised to process it are subject to confidentiality, applies the technical and organisational measures set out in section 7 and assists the customer in complying with its obligations.
5. Sub-processors
The customer authorises the sub-processors listed in the annex: Supabase (hosting, European Union), Vercel (application), Anthropic (automated report generation) and Resend (email). DataVigia binds them by equivalent data protection obligations and informs the customer with reasonable advance notice of any change, the customer being able to object on legitimate grounds. Some of these suppliers, although they host the data in the European Union, belong to corporate groups subject to the legislation of third countries; DataVigia applies the appropriate contractual and technical safeguards.
6. International transfers
Where there are transfers outside the European Economic Area, appropriate safeguards apply, in accordance with the transfer mechanism valid at the time: the European Commission's Standard Contractual Clauses and, where the sub-processor is certified, the EU-US Data Privacy Framework. Transfers to countries with an adequacy decision, such as Andorra, do not require additional safeguards.
7. Security (Article 32)
Measures: encryption of connector secrets, isolation between organisations (Row Level Security), the principle of least privilege, two-step authentication for administrative access, access control and logging, request rate limiting and minimisation (no collection of file content).
8. Data breaches
DataVigia notifies the customer without undue delay, and in principle within 48 hours, after becoming aware of a personal data breach, providing the information necessary for the customer to comply with its notification duties.
9. Assistance to the controller
DataVigia assists the customer, to the extent possible and taking into account the nature of the processing, in responding to requests to exercise data subjects' rights and in complying with the obligations of Articles 32 to 36 GDPR, including DPIAs (data protection impact assessments) and prior consultation of the authority.
10. Audit
DataVigia makes available to the customer the information necessary to demonstrate compliance with the obligations of Article 28 and allows for and contributes to reasonable audits, carried out by the customer or by an auditor mandated by the customer, with prior notice and without compromising the security of other customers.
11. Return and deletion
At the end of the provision of the service, DataVigia returns or deletes, at the customer's choice, the personal data processed on its behalf, and erases the existing copies, save for any legal obligation to retain it.
12. Annex: processing details
Subject matter: provision of the DataVigia service. Duration: that of the contract. Nature and purpose: security auditing, threat detection and training. Types of data: account data, security metadata and employee data for simulations. Categories of data subjects: the customer's employees, administrators and contacts. Sub-processors: Supabase (EU), Vercel, Anthropic and Resend. The content of files is not processed.