Data processing agreement
This agreement (the "Agreement") is entered into under Article 28 of Regulation (EU) 2016/679 ("GDPR") between:
- SARL Jérémy Devos, 15 rue Louis Seigneur, 59170 Croix, France, registered under number 939 628 038, publisher of the WyndPath service, hereinafter "the Processor";
- the holder of the WyndPath account, hereinafter "the Controller".
It is accepted by the mere use of the service and forms an integral part of the terms of use. No separate signature is required; a signed copy may be requested at [email protected].
Article 1. Subject matter and definitions
The Agreement governs the processing of personal data carried out by the Processor on behalf of the Controller in the course of providing the WyndPath API. The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in Article 4 GDPR. In case of conflict, the Agreement prevails over the general terms as regards data protection.
Article 2. Description of the processing
The characteristics of the processing are set out in Annex 1. The Controller remains solely responsible for assessing the lawfulness of the collection it initiates, the purposes it pursues and the retention periods it applies in its own systems.
Article 3. Documented instructions
The Processor processes the data only on documented instructions from the Controller. Each API call constitutes an instruction: the URL submitted determines the data fetched. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR or another provision of Union or Member State law, and may then suspend its execution.
The Processor does not use the data processed on behalf of the Controller for any purpose of its own. It does not exploit that data for statistical or advertising purposes, nor to train models, and transfers it to no third party.
Article 4. Confidentiality
The Processor ensures that persons authorised to process the data are bound by a duty of confidentiality, contractual or statutory, and receive the necessary training. As at the date of the Agreement, access to production systems is restricted to the managing director.
Article 5. Security
The Processor implements the appropriate technical and organisational measures required by Article 32 GDPR, described in Annex 2. It undertakes not to lower the overall level of protection during the term of the Agreement.
Article 6. Sub-processors
The Controller gives general authorisation for the use of the sub-processors listed in Annex 3. The Processor imposes on them, by contract, data protection obligations equivalent to those of the Agreement, and remains fully liable for their performance.
Any addition or replacement is published on the data protection policy page at least fifteen days before it goes live. The Controller may object in writing within that period on data protection grounds; failing agreement, it may terminate its subscription at no cost and obtain a refund of the unused portion.
Article 7. Data subject rights
The Controller handles requests to exercise rights over the data it has collected. The Processor assists it by appropriate technical measures, insofar as possible, and forwards without delay any request it receives directly.
It is expressly recalled that the Processor does not retain the content of the pages returned: it is therefore materially unable to search, rectify or erase data collected by the Controller.
Article 8. Assistance
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in complying with the obligations laid down in Articles 32 to 36 GDPR, in particular as regards security, breach notification and data protection impact assessments.
Article 9. Personal data breach
The Processor notifies the Controller of any personal data breach concerning it without undue delay and no later than 48 hours after becoming aware of it. The notification states the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. The Processor documents every breach and retains that documentation.
Article 10. Fate of the data at the end of the contract
At the end of the provision of services, the Processor deletes the data processed on behalf of the Controller. The technical logs described in Annex 1 are deleted automatically after 90 days. Accounting records are kept for ten years pursuant to tax and accounting obligations, the sole exception to deletion.
Article 11. Audit
The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR. It allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it, subject to reasonable notice of thirty days, a frequency of once per year save in the event of a security incident, a confidentiality undertaking from the auditor, and the costs being borne by the requesting party.
Article 12. Transfers outside the European Union
Processing takes place within the European Union. Transfers to sub-processors established outside the Union are covered by the standard contractual clauses adopted by the European Commission on 4 June 2021 and, where the provider is certified, by the Data Privacy Framework. Those clauses are deemed incorporated into the Agreement.
Article 13. Liability, term and governing law
The Agreement takes effect upon creation of the account and remains in force for as long as the Processor processes data on behalf of the Controller. Each party is liable for damage caused by processing which infringes the GDPR, under the conditions of Article 82 thereof. The Agreement is governed by French law; failing amicable settlement, the courts within the jurisdiction of the Douai Court of Appeal shall have jurisdiction, subject to mandatory rules of jurisdiction.
Annex 1. Description of the processing
- Nature
- Fetching, transmission and return of publicly accessible pages, on the Controller's instruction.
- Purpose
- Provision of the WyndPath API, usage-based billing and technical diagnostics.
- Duration
- Term of the subscription. Page content: not retained. Technical metadata: 90 days.
- Categories of data
- Data published by data subjects on the pages targeted by the Controller, whose scope it alone determines. On the Processor's side: URLs called, timestamps, volumes, account identifiers.
- Data subjects
- Any person whose data appears on the targeted pages, together with the users of the customer account.
- Special categories
- None. The Controller undertakes not to have data falling under Article 9 GDPR, or relating to minors, collected.
Annex 2. Technical and organisational measures
- Encryption: encrypted transport on all entry points; encryption at rest of target credentials entrusted by the customer.
- Access control: API key revocable per account; console sign-in by one-time code; server access by key, restricted to the managing director.
- Isolation: browsing sessions, cookies and credentials are isolated per account and never shared between customers.
- Minimisation: page content is neither written to disk nor durably cached; only technical metadata is logged.
- Availability: encrypted backups, tested restore, service monitoring.
- Traceability: logging of administrative access and of operations on accounts.
- Deletion: automatic daily purge of logs beyond 90 days.
Annex 3. Authorised sub-processors
| Provider | Country | Role | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Allemagne | Hébergement des serveurs et des bases de données | UE |
| Webshare Software Company | États-Unis | Fourniture des adresses IP de sortie (proxys) | CCT |
| Stripe Payments Europe, Ltd. | Irlande | Paiement des abonnements et facturation | UE / CCT |
| Brevo SAS | France | Envoi des e-mails transactionnels (code de connexion, factures) | UE |
| Cloudflare, Inc. | États-Unis | Protection anti-robot du formulaire, acheminement des e-mails entrants | CCT / DPF |
| Google Ireland Limited | Irlande | Mesure d'audience du site public (hors console) | UE / CCT |
SCC: standard contractual clauses. DPF: Data Privacy Framework.