Data Processing Agreement (DPA)
Last updated: 19 June 2026
This Data Processing Agreement ("DPA") governs the processing of personal data by Olyteck ("Processor") on behalf of a Customer ("Controller") in connection with any Olyteck product (Olyteck Cyber, Olyteck Ask, Olyteck Studio, Olyteck Guard). It is incorporated by reference into the Terms of Service. The framework below applies to all products; the product-specific particulars are set out in each product's Schedule (linked in §2).
1. Parties and definitions
- Customer / Controller: the organisation that signed up for an Olyteck product and whose administrator grants it access.
- Olyteck / Processor: operating under SIRET 993 174 499 00018, France.
"personal data", "processing", "data subject", "controller", "processor" and "sub-processor" have the meanings given to them in the EU GDPR.
2. Subject-matter, products and Schedules
The subject-matter, nature and purpose of the processing, the categories of data subjects and personal data, the sub-processors engaged, and the retention windows depend on which product the Customer uses. Each product's Schedule sets out these particulars and forms part of this DPA:
Common across products: account data (Microsoft Entra OID/TID, admin work email, display name, role, session timestamps) and operational metadata (audit logs, IP addresses for abuse detection). Duration: for as long as the Customer's subscription is active, plus the retention windows in the product Schedule and §7.
Special categories (Art. 9) and criminal-conviction data (Art. 10): to the extent such data incidentally appears, the Processor does not intentionally process or single it out; the Customer remains responsible for the lawful basis of processing its own data.
3. Roles and instructions
Olyteck acts as a processor. The Customer is and remains the controller and is responsible for the lawful basis for the processing it configures (including any employment-law / works-council consultation its jurisdiction requires). Olyteck processes personal data only on the Customer's documented instructions — including the act of configuring and using the product as described in the public documentation — and will inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member-State data-protection law.
4. Processor obligations (Art. 28(3))
- Process personal data only on documented Customer instructions, including for international transfers (§6).
- Ensure that staff with access are bound by confidentiality.
- Implement the technical and organisational measures in §5 ("TOMs").
- Engage sub-processors only under §6 and only under contracts imposing data-protection obligations equivalent to those in this DPA.
- Assist the Customer with data-subject requests (Art. 12–22), DPIAs (Art. 35), prior consultations (Art. 36) and security/breach obligations (Art. 32–34) so far as reasonably possible.
- Notify the Customer without undue delay, and in any case within 72 hours, of becoming aware of a personal-data breach affecting the Customer's data.
- At the Customer's choice, delete or return all personal data at the end of the service, save where Union or Member-State law (e.g. French accounting retention) requires otherwise.
- Make available all information necessary to demonstrate compliance and contribute to audits (§8).
5. Security measures (Art. 32 — TOMs)
The following measures apply across all products; any product-specific measure (e.g. read-only Microsoft Graph access, or "no storage of message bodies") is stated in that product's Schedule.
- Encrypted transport (TLS 1.2 or higher) for all Customer-facing and Microsoft Graph traffic.
- Encryption at rest for the application database (AES-256 or equivalent provided by the host); access tokens encrypted at rest.
- Microsoft Entra ID SSO with OIDC + PKCE — no application-managed passwords, no plaintext credentials.
- Principle of least privilege for staff access; state-changing operations are CSRF-protected and audit-logged.
- Parameterised SQL throughout — no user-supplied values concatenated into queries.
- Strict per-tenant isolation: every record is bound to the owning tenant; every query filters on the server-side session's tenant identifier; cross-tenant access returns not-found.
- Daily off-site, encrypted database backups with a rolling window; restore drill at least annually.
- Incident-response runbook with a 72-hour Customer-notification target. Security contact: [email protected].
- Annual review of the TOMs; this DPA's "Last updated" date reflects the most recent revision.
6. Sub-processors and international transfers
The Customer authorises Olyteck to engage the sub-processors listed in the applicable product Schedule and in the Trust Center. Each is bound by a written contract imposing data-protection obligations equivalent to those in this DPA. The product Schedule (and the Trust Center) is the current, version-dated list.
International transfers. All current sub-processors process through their EU/EEA entities, so processing stays within the EEA. Should a sub-processor process data outside the EEA, transfers will rely on the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) and, where available, the EU-US Data Privacy Framework, with supplementary technical measures, and the Schedule will be updated first.
Change procedure. Olyteck will post any addition or replacement of a sub-processor that materially handles Customer personal data to the applicable product Schedule at least 30 days before it takes effect; Customers may subscribe to e-mail notifications of changes. The Customer may object on reasonable grounds; if the parties cannot agree on an alternative, the Customer may terminate the affected portion of the Service for cause.
7. Storage location and retention
Application servers, databases and workers run in France (Paris, PAR1) (EU-27). Product-specific retention windows are set out in each product Schedule. Windows common across products:
- Account / workspace data — for the lifetime of the subscription, plus 30 days after deletion.
- Application / operator audit log — 24 months.
- Billing records — 10 years (French accounting law).
8. Audit
Once per year and on at least 30 days' written notice, the Customer (or an independent auditor it mandates, subject to confidentiality) may audit Olyteck's compliance with this DPA. Olyteck may instead provide a summary of an independent third-party audit or security attestation where available. The Customer bears the cost of its own audits unless the audit reveals a material non-compliance, in which case Olyteck bears its reasonable costs.
9. Assistance with data-subject requests
Where a data subject exercises a GDPR right (access, rectification, erasure, restriction, portability, objection, or rights related to automated processing under Art. 22) and the request concerns data processed through the Service, Olyteck will provide reasonable technical assistance to enable the Customer to respond within the statutory deadline. Where a data subject contacts Olyteck directly, we will redirect them to the Customer.
10. Liability, precedence and termination
The liability cap in the Terms of Service also governs claims under this DPA, except where prohibited by law. This DPA terminates automatically when the underlying service agreement terminates.
Order of precedence. On any conflict regarding the processing of personal data, this DPA prevails over the Terms of Service or any other published policy. Precedence between this DPA and a signed Order Form / Master Services Agreement is set out in the Terms of Service.
11. Governing law
This DPA is governed by French law. The competent courts of France has exclusive jurisdiction, without prejudice to any mandatory consumer-protection rules that may apply.
12. Contact
For DPA questions, counter-signed copies or breach notifications, email [email protected]. Security incidents: [email protected]. Operator: Olyteck — SIRET 993 174 499 00018.