Skip to content

Data processing agreement (DPA)

Generic document to be validated by legal counsel before commercial use.

Generic document to be validated by legal counsel. Annex to the terms of service.

1. Parties and purpose

The Customer (controller) entrusts the publisher of Tuileur (processor) with the processing of personal data necessary to provide the Service, in accordance with GDPR article 28.

2. Instructions

The processor only processes data on the Customer's documented instructions, including for transfers outside the European Union, unless required by law.

3. Confidentiality and security

The processor ensures that authorised persons are bound by confidentiality and implements the technical and organisational measures described in the privacy policy (encryption, tenant isolation, logging, backups, traced support access).

4. Sub-processors

Hosting (European Union), transactional email, payment processing (Stripe). The Customer is informed of any change and may object.

5. Assistance

The processor assists the Customer in responding to data subject requests, with security, breach notification (within 48 hours) and impact assessments.

6. End of processing

At the end of the Service, the Customer exports its data; the processor deletes it within 90 days unless legally required to retain it.

7. Audit

The processor makes available the information necessary to demonstrate compliance and allows reasonable audits, with notice.