foliade

Data Processing Agreement (DPA)

1. Parts, scope and duration

The customer is “processing manager” for the data contained in its catalogs, the contact details collected, the nominative links and the reading measurements. Damien FLANDRIN EI is a “subcontractor” for operations carried out under instruction using Foliade. This DPA takes effect with the contract and remains applicable as long as the subcontractor processes this data.

The account and billing data that Foliade processes for its own purposes are part of the privacy policy and not this DPA.

2. Description of treatment

3. Customer instructions

Documented instructions result from the contract, service settings and written requests from the customer. The subcontractor does not use the data for its own purposes and immediately informs the client if an instruction appears to contravene the GDPR or applicable law. It may suspend the instruction concerned pending lawful clarification.

Authenticated API or MCP calls constitute client instructions. The local plugin Foliade does not transmit to the subcontractor either the conversation history or the memory of the assistant; only the explicitly chosen PDF and the parameters necessary for the called tool are sent to the API.

If Union or Member State law requires unrequested processing, the processor shall inform the customer before carrying it out, unless prohibited by law.

4. Privacy and security

The people authorized to process the data are subject to an obligation of confidentiality and only access it according to their missions. The subcontractor maintains measures proportionate to the risk, in particular:

5. Subprocessors

The client gives general authorization to use the service providers below for the activities indicated:

Any addition or replacement is announced at least fifteen days before it takes effect, except in the event of a security emergency. The customer may submit a reasoned objection relating to data protection during this period. The parties seek a reasonable solution; failing this, the client may terminate the assigned function. The subcontractor imposes equivalent obligations on the service provider and remains responsible for their execution towards the client.

Stripe is involved in invoicing specific to the relationship between Foliade and the customer. No catalog content is transmitted to it; this processing therefore does not fall within the subcontracting described by this appendix.

6. International transfers

A transfer outside the European Economic Area is only carried out on the basis of an adequacy decision, standard contractual clauses accompanied by the necessary additional measures, or another recognized mechanism. On request, the subcontractor communicates useful information concerning the applicable mechanism.

7. Information and rights of individuals

The client writes the information given to readers and determines the response to their requests. Taking into account the nature of the processing, the processor provides the functions and information reasonably necessary to respond to requests for access, rectification, erasure, limitation, opposition and portability. A request received directly is transmitted to the customer without a substantive response, unless instructed or legally required.

8. Support and violations

The processor reasonably assists the customer with security, impact analyses, authority consultations and demonstration of compliance. It informs the customer without undue delay after becoming aware of a violation affecting their data and transmits to them, as they become available, the nature of the incident, the categories of data and people concerned, the probable consequences and the measures taken. The customer remains responsible for the notifications incumbent upon him.

9. Restitution and deletion

During the contract, the customer can export his data using the available functions. At the end of the service or upon lawful instruction, the data is returned or deleted, including copies, unless there is a legal retention obligation. Deletions from backups follow their normal technical cycle and the data concerned remains isolated from any current use during this period.

10. Documentation and audit

The subcontractor makes available the information necessary to demonstrate compliance with this DPA. The client may request an audit at most once a year, unless there is an incident or request from an authority, with reasonable notice. The audit must remain proportionate, confidential, conducted during business hours and not compromise security or other clients' data. Costs are borne by the customer, unless there is substantial non-compliance attributable to the subcontractor.

11. Priority and contact

In the event of a contradiction regarding the protection of the data processed for the customer, this DPA prevails over the CGV and CGU. Its French version constitutes the reference contractual version; translations are provided to facilitate reading. Requests and notifications are addressed to [email protected].