Data Processing Agreement

The Article 28 GDPR clauses that apply when you process personal data through our services.

In force Last updated:

The French version of this document is the official and legally binding version. This English translation is provided for convenience only.

When you host an application with us, you may process personal data about your own users through it — the Discord identifiers of a server's members, for instance. In that case you are the controller and the KATABUMP Association acts as a processor within the meaning of Article 4(8) of Regulation (EU) 2016/679 (the "GDPR").

This agreement sets out the clauses required by Article 28(3) of the GDPR. It forms an integral part of the terms and conditions of use, supplementing Article 10 thereof.

Two separate processing operations

This agreement covers only the data you process through our services. The data we process on our own behalf — your customer account, your billing, your exchanges with support — is covered by the privacy policy, for which the Association is the controller.

1. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them in Article 4 of the GDPR. The terms "Client", "Services", "Account" and "Association" have the meaning given to them in Article 3 of the terms and conditions of use.

2. Subject matter, duration and description of the processing

  • Subject matter: the hosting and execution, on the Association's infrastructure, of the applications and data uploaded by the Client.
  • Duration: the term of the contract between the Client and the Association, as defined in Article 9 of the terms and conditions of use, extended by the residual retention periods described in Article 8 of this agreement.
  • Nature and purpose: storage, hosting, execution, logging and backup, for the sole purpose of providing the Services. The Association does not access the content of hosted applications outside the cases set out in Article 4 below.
  • Categories of data: those the Client chooses to process through the Services. The Association determines neither their nature nor their scope.
  • Categories of data subjects: those determined by the Client, typically the users of the hosted application.
Sensitive data

The Services are not designed to host data falling under Article 9 of the GDPR (health data, political opinions, religious beliefs, sexual orientation, biometric data, and so on), data relating to criminal convictions within the meaning of Article 10, or data subject to a specific certification regime. The Client undertakes not to process such data through them.

3. Documented instructions

The Association processes the Client's personal data only on the Client's documented instructions. The Client's documented instructions consist of: the terms and conditions of use, this agreement, and the settings the Client configures in the Services' interface.

Where Union or French law requires the Association to carry out processing outside those instructions, it informs the Client before processing, unless that law prohibits it from doing so on important grounds of public interest.

The Association immediately informs the Client if, in its opinion, an instruction infringes the GDPR or another applicable data protection provision.

4. Confidentiality and access

The Association ensures that persons authorised to process the Client's data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Access to hosted data is strictly limited to the staff who need it, and occurs only:

  • at the Client's request, in particular as part of a support request;
  • to ensure the maintenance, security or continuity of the infrastructure;
  • to act on a notice under the DSA or the acceptable use policy;
  • to act on a requisition or order from a competent authority.

5. Security measures

The Association implements the appropriate technical and organisational measures required by Article 32 of the GDPR, described in Article 7 of the privacy policy: encryption of communications in transit (HTTPS/TLS), password hashing, firewalls and intrusion detection, regular backups, strictly limited access, staff training, security audits and vulnerability testing, and incident management procedures.

It is for the Client to implement the security measures specific to its own application: protecting its credentials, managing its environment variables and secrets, any application-level encryption, and backups, in accordance with Article 6 of the terms and conditions of use.

6. Sub-processing

The Client grants the Association general authorisation to engage the sub-processors listed on the Subprocessors page.

The Association informs the Client of the addition or replacement of any sub-processor by updating that page. The Client has thirty (30) days from that update to raise a reasoned objection; failing agreement between the parties, the Client may terminate the contract on the terms of Article 9 of the terms and conditions of use.

The Association imposes on each sub-processor, by contract, the same data protection obligations as those set out in this agreement, and remains fully liable to the Client for that sub-processor's performance of its obligations.

7. Assistance to the controller

Data subject rights. Taking into account the nature of the processing, the Association assists the Client, by appropriate technical and organisational measures, in responding to requests to exercise the rights set out in Chapter III of the GDPR. The Client retains control of its data through the Services' interface and remains the sole point of contact for data subjects. If a request addressed directly to the Association concerns processing for which the Client is the controller, the Association forwards it to the Client without responding to it itself.

Articles 32 to 36 obligations. The Association assists the Client, within the limits of the information available to it, in ensuring compliance with its obligations regarding security, breach notification, impact assessments and prior consultation.

8. Personal data breach notification

The Association notifies the Client of any personal data breach affecting data processed on its behalf without undue delay after becoming aware of it, and in any event within a time frame allowing the Client to meet the seventy-two (72) hour deadline imposed on it by Article 33 of the GDPR.

The notification describes, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the point of contact from which more information can be obtained.

9. Fate of the data at the end of the contract

At the end of the contract, the Client can export its data through the Services' interface. Article 9 of the terms and conditions of use provides that reasonable access is granted for that purpose before final deletion.

In accordance with Article 8 of the privacy policy, the data is then deleted from production systems within thirty (30) days, and from backup systems within a maximum of ninety (90) days. Technical logs are retained for a maximum of twelve (12) months. Certain data may be retained beyond those periods where Union or French law so requires, in particular billing data, retained for ten (10) years under French tax legislation.

10. Availability of information and audit

The Association makes available to the Client the information necessary to demonstrate compliance with the obligations of this agreement, on request sent to privacy@katabump.com.

The Client may carry out an audit, including an inspection, itself or through an independent auditor it mandates. The audit takes place on the following terms: reasonable notice of at least thirty (30) days, once per twelve (12) month period save in the event of a confirmed security incident, during business hours, without disrupting operations, respecting the confidentiality of the data of the Association's other clients, and at the Client's expense.

11. Transfers outside the European Economic Area

Data is hosted primarily in France. Transfers outside the EEA are limited to those described on the Subprocessors page and are governed by the mechanisms provided for in Chapter V of the GDPR.

12. Client obligations

The Client warrants to the Association:

  • that it has a legal basis within the meaning of Article 6 of the GDPR for each processing operation it carries out through the Services;
  • that it has informed data subjects in accordance with Articles 12 to 14 of the GDPR;
  • that it complies with the terms of use of the third-party platforms concerned, in particular Discord, in accordance with Article 6 of the terms and conditions of use;
  • that its instructions are lawful and do not expose the Association to an infringement of the GDPR.

The Client indemnifies the Association against any third-party claim arising from a breach of those obligations, on the terms of Article 12 of the terms and conditions of use.

13. Acceptance and changes

This agreement is accepted by the Client by the sole fact of accepting the terms and conditions of use. If your organisation needs a signed agreement, write to us at legal@katabump.com.

Any material change to this agreement is brought to the Client's attention on the terms of Article 13 of the terms and conditions of use.

14. Contact

Data protection questions and exercise of rights: privacy@katabump.com.
Contractual questions: legal@katabump.com.

Esc
Type to search…