Data Processing Agreement

Document version: 7 October 2026

V1 operator-approved documents, including the documented exit procedure and supplier disclosures. Publication does not activate customer processing or constitute acceptance by a customer.

1. Parties and effectiveness

This Data Processing Agreement is between Myriam Pontiac, individual entrepreneur (micro-entreprise), trading as MP Développement Digital, SIREN 107 090 268, SIRET 107 090 268 00015, 141 rue Peton Gaudet, 42400 Saint-Chamond, France (Processor), and the agency/business identified in the accepted service order (Customer). It forms part of that contract when accepted by the parties. Publication, a Marketplace edit or installation is not a signature.

Customer must identify the business controller, its address/contact and whether Customer acts as controller or authorised processor. Where Customer is processor, it must hold the controller's authority to engage MP Développement Digital and transmit instructions. This agreement governs instructed processing; independent operator administration is covered by the privacy notice.

2. Processing specification

Subject: operation of the subscribed Revenue Recovery workspace for existing business opportunities. Nature: authorised receipt, organisation, storage, consultation, configured follow-up/handoff, outcome evidence, export, deletion and restricted security audit. Purpose: deliver the customer-instructed service, not sell data, create unrelated demand or train a general-purpose model.

Data subjects: customer business prospects/clients and authorised agency/business users. Data categories: contact identifiers, CRM references, conversation content, consent/preferences/opt-out evidence, appointments, quotes, opportunities, sourced financial evidence and necessary audit information. Ordinary processing excludes special-category and criminal-offence data. Frequency is ongoing only when authorised features are active.

Duration: the service term plus the approved exit and lawful-preservation schedule. The subscription does not automatically approve longer campaign retention. The Customer records each business's lawful purposes, permitted channels, region and retention instructions.

3. Instructions and confidentiality

MP Développement Digital processes personal data only on documented Customer instructions, including instructions about transfers. If EU or Member-State law requires other processing, MP Développement Digital informs Customer beforehand unless legally prohibited. MP Développement Digital promptly alerts Customer if an instruction appears unlawful and pauses the disputed processing pending lawful clarification.

Personnel authorised to access data must be bound by confidentiality and receive appropriate instructions. Customer grants access only to authorised persons and remains responsible for its account users, instructions, lawful basis, notices and consents. MP Développement Digital does not independently select new marketing purposes or use customer content to train general-purpose AI models.

4. Technical and organisational measures

The technical and organisational measures comprise tenant/role access separation, row-level database access policies, protected transport, server-side secrets and encrypted integration credentials, private attachment storage, audited sensitive actions, signature/access validation, effect reservation and replay controls, opt-out/budget checks, pause controls and restricted operational access. These describe the service design; they do not claim a certification.

MP Développement Digital maintains risk-appropriate controls and reviews changes without reducing the agreed protection. The current database plan's restoration limitations must be acknowledged in the annex; no unverified managed-backup recovery or disaster-recovery deadline is promised. Customer must maintain source-system records and approve the retention/backup schedule before production processing.

5. Subprocessing and international transfers

Customer may give general written authorisation only to the operator-appointed providers listed in the completed provider annex. MP Développement Digital imposes equivalent applicable protection duties on its subprocessors and remains responsible for their performance of the delegated processing. Customer-contracted CRM/transport vendors must be identified separately.

For a new or replacement subprocessor selected by the operator, MP Développement Digital gives the Customer at least 30 calendar days' written notice, by email, stating the task, entity, location and safeguards before the affected processing begins. Notice is managed manually; no automatic notification service is claimed. The Customer may object on reasoned data-protection grounds during that period. The parties seek a compliant alternative; if none is feasible, the affected processing does not begin and the affected service is terminated with return/deletion. Changes to a vendor's own downstream providers follow that vendor's applicable notice procedure: this clause does not guarantee that MP Développement Digital receives every downstream notice 30 days in advance.

International transfers require documented instructions and an applicable legal mechanism, completed contractual annexes and assessment/supplementary safeguards where required. This DPA is not itself a substitute for EU transfer standard contractual clauses or their UK/Swiss adaptations. No EEA-only guarantee is given.

6. Requests, incidents and regulatory assistance

MP Développement Digital assists Customer, taking account of the processing and available information, with individual rights, security duties, breach assessment, impact assessments and regulator consultation. MP Développement Digital routes direct customer-data requests to Customer and does not independently respond on its behalf unless authorised or required by law.

MP Développement Digital informs Customer of a personal-data breach without undue delay after becoming aware and supplies available information about its nature, affected data/persons, likely effects, mitigation and contact. Further information may be provided in stages; evidence is preserved without exposing other tenants. No fixed 24-hour incident deadline is promised by this agreement.

Customer determines and meets any authority/data-subject notification obligations applicable to it. MP Développement Digital cooperates with competent authorities and lawful instructions. A regulator's deadline is not replaced by the email-support response target.

7. Return, deletion and legal preservation

At the end of the instructed service, Customer chooses return or deletion of personal data, and copies are deleted unless EU or Member-State law requires preservation. The approved schedule must address live records, attachment storage, suppression evidence, provider copies and backups. Restricted lawful records are isolated from campaign use and retained only for their justified period.

The Customer sends authenticated return/deletion instructions to support@mpddrecover.com with subject DPA. The operator verifies authority, scope, lawful preservation and secure delivery, documents a feasible timetable, tracks completion and explains any residual provider copies. Existing request registration and partial contact anonymisation do not constitute an end-to-end export or tenant-deletion service. Neither export within 30 days nor live-data deletion within 60 days of termination is guaranteed by this version. Mandatory legal duties and deadlines continue to apply. Uninstalling does not erase the source CRM or cancel a separately managed subscription.

8. Demonstration of compliance and audits

MP Développement Digital makes necessary compliance information available and permits proportionate audits/inspections by Customer or an independent authorised auditor, subject to confidentiality and protection of other customers. Parties agree reasonable scope, method and scheduling; those arrangements must not prevent legally required access or urgent incident/regulator action.

Costs for genuinely additional bespoke assistance may be agreed in writing in advance. No undisclosed audit fee or mandatory paid upgrade is created. This agreement does not limit mandatory data-subject remedies or statutory liability. Data-processing clauses prevail over conflicting service terms for this subject matter.

9. Contract particulars and approved V1 supplier disclosures

The accepted order identifies the Customer's legal name, form, address, authorised representative, actual controller/processor chain, businesses, start date and instructions. Sections 2–4 and the schedules below form the processing and security annexes. Both parties evidence acceptance; each customer completes its own particulars.

The operator has approved the verified supplier disclosures and the prudent limitations on residual copies as sufficient for V1. Account-by-account contracts or further supporting documents are not a separate V1 activation condition. This document does not claim a provider signature or completed transfer assessment. Optional AI/monitoring and special-category processing are outside the current authorised scope.

Retention and exit schedule

These operator-approved periods are the retention policy, not evidence that every deletion is automated. Conversations: 730 days; attachments: 365 days; audit records: 2,555 days; maintenance-run history: seven days. Conversation, attachment and audit periods are measured from the relevant record's creation unless lawful customer instructions specify a necessary earlier deletion; retention is not restarted by unrelated activity.

The existing application holds conversation/attachment/audit duration parameters but has no verified comprehensive age-based purge for those records. The seven-day maintenance-history purge is scheduled. The operator must track and execute the other approved periods through a controlled procedure; the document does not certify that such a procedure is already operational.

Support correspondence: 24 months after ticket closure. Account administration: during the contract, then five years after its end in restricted archives for claims. Required accounting records: ten years from the relevant financial-year close. Preserve only records necessary for the stated purpose; lawful holds record scope, grounds and review date.

For opt-outs, keep only the minimum identifier or suppression evidence necessary to honour the objection; exclude it from campaigns. Contacts, quotes, opportunities and sourced outcome records follow necessary documented customer instructions, without overriding erasure duties or using account/accounting periods to retain full CRM content.

Exit: authenticated return/deletion requests are scoped and a feasible completion timetable is documented, with secure delivery and completion evidence. The current implementation does not substantiate fixed 30-day export or 60-day active-data deletion after termination. Those deadlines are not contractual guarantees in this version. Mandatory rights and applicable deadlines remain unaffected.

Residual copies: restrict access, prohibit campaign reuse, request deletion where provider controls permit, and track expiry. If a backup is restored, reapply the recorded deletion instructions before returning data to normal use. No claim of immediate deletion of every physical copy or a universal expiry is made.

Supabase: the current account is Free and the primary database is in Ireland. No managed restoration entitlement or account-specific residual-backup expiry is verified. Database backups do not include the stored attachment files; those require separate Storage API deletion. No seven-day Supabase expiry is promised.

Vercel documents infrastructure backups retained for 30 days. That is a published vendor cycle, not proof of an individual deletion date or the retention of every request log, cache or deployment. Resend documents standard-plan email/log retention of 30 days, backups of seven days, and deletion of remaining data within 90 days after account termination; these are different triggers, and account applicability must be confirmed. Outlook is used only for support: the 24-month support policy does not establish automatic mailbox/archive purge or the expiry of Microsoft's residual copies.

Vendor references: Supabase backups · Vercel backup cycle · Resend retention.

Providers, processing locations and transfer safeguards

This inventory distinguishes operator vendors from the customer's own providers. Public vendor documents establish available terms, not proof that every required account agreement and transfer assessment has been completed. The operator has accepted the verified Vercel, Supabase and Resend disclosures as sufficient documentation for V1; missing account-by-account documents are not a separate launch condition. No unverified signature or account-specific exception is claimed.

For an EEA transfer, the exporter must document the receiving entity and country and a valid Chapter V basis. Where standard contractual clauses are used, record the relevant controller-to-processor or processor-to-processor module, complete annexes and assess whether supplementary measures are required. A UK transfer needs the applicable UK mechanism; Swiss transfers need the applicable adaptations. An adequacy decision may be used only after its applicability to the actual recipient and processing has been verified. No agreement signature, DPF certification or completed transfer assessment is claimed here.

Contact and operator identification

Myriam Pontiac — entreprise individuelle / micro-entreprise, trading as MP Développement Digital. SIREN 107 090 268; SIRET 107 090 268 00015. Business address: 141 rue Peton Gaudet, 42400 Saint-Chamond, France. Publication director: Myriam Pontiac. TVA non applicable, art. 293 B du CGI.

Email support and privacy/DPA contact: support@mpddrecover.com. First support response within 24 hours of receipt, including weekends and public holidays. This is an initial response commitment, not a resolution deadline or continuous live support. Use subject Privacy or DPA. Do not send passwords, API keys or full customer files by ordinary email. Necessary identity checks use a suitable secure channel.