Data Processing Agreement (DPA)
Last updated: 28 July 2026
Data processing agreement entered into under Article 28 of the GDPR, governing Puwapi's processing of personal data on the Subscriber's behalf. It forms an integral part of the terms of service.
This English version is provided for convenience only. The French version is the legally binding text and prevails in the event of any discrepancy.
- 1. Purpose and framework
- 2. Roles of the parties
- 3. Description of the processing
- 4. Processing on documented instructions
- 5. Confidentiality of personnel
- 6. Security measures (Article 32)
- 7. Subprocessors
- 8. Transfers outside the European Union
- 9. Assistance to the Controller
- 10. Notification of data breaches
- 11. Fate of the data at the end of processing
- 12. Audit and documentation
- 13. Term and changes
- 14. Contact
1. Purpose and framework
This Data Processing Agreement (“DPA”) governs the processing of personal data carried out by GHARSALLI Abdurahmen (EI) (“the Processor”) on behalf of the Subscriber (“the Controller”) in connection with the provision of the Puwapi Service. It supplements the terms of service and applies in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”).
In the event of a conflict regarding the processing of personal data, this DPA prevails over the other contractual documents.
2. Roles of the parties
For Subscriber Data processed via the Service, the Subscriber acts as controller and Puwapi as processor. The Subscriber determines the purposes and means of the processing, warrants that it has a legal basis and is entitled to entrust this data to the Processor.
Puwapi acts, by contrast, as an independent controller for account management, billing and security data, governed by the privacy policy.
3. Description of the processing
| Item | Description |
|---|---|
| Nature and purpose | Hosting and operation of the Service enabling the Subscriber to run its business (CRM, scheduling and appointments, invoicing, projects and support, forms, files, email, AI features). |
| Duration | The term of the Agreement, plus the return and deletion periods set out in section 11. |
| Categories of persons | The Subscriber's customers, prospects, contacts, patients, applicants and staff, depending on the modules used. |
| Categories of data | Identification and contact data, appointment and billing data, message and file content, and any data the Subscriber chooses to store in the Service. |
| Sensitive data | The Service is not intended to process special-category data (Art. 9 GDPR). If the Subscriber stores any, it is responsible for its lawfulness and security. |
4. Processing on documented instructions
Puwapi processes Subscriber Data only on the Controller's documented instructions, of which the Agreement and the use of the Service's features constitute the initial instructions. Puwapi informs the Subscriber if an instruction appears to it to infringe the GDPR or another applicable provision. Puwapi does not process this data for its own purposes.
5. Confidentiality of personnel
Puwapi ensures that persons authorised to process Subscriber Data are bound by a confidentiality obligation and access it only to the extent strictly necessary to provide the Service (support, operations, security). Access is limited and logged.
6. Security measures (Article 32)
Puwapi implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- encryption of communications (HTTPS, TLS 1.2 minimum, TLS 1.3 by default, obsolete versions refused) and encryption at rest of mail data (AES-256);
- hosting of servers and databases within the European Union, with Contabo GmbH (Germany), and file storage with Scaleway (France);
- access control through named accounts and roles, restricted administration access, and data isolation per organisation (tenant);
- passwords stored as cryptographic hashes and temporary account lockout after repeated failed sign-ins;
- encrypted daily backups and tested restore procedures;
- logging of access and sensitive actions;
- security patch management and periodic review of measures.
Two-factor authentication on administration access is being rolled out, with go-live planned during August 2026.
7. Subprocessors
The Subscriber authorises Puwapi to use the subprocessors listed below, which provide sufficient guarantees and are bound by obligations equivalent to those of this DPA:
| Subprocessor | Role and location |
|---|---|
| Contabo GmbH | Hosting of the infrastructure, applications and databases - European Union (Germany). |
| Scaleway | Object storage of files uploaded to the Service - European Union (France, Paris region). |
| Stripe | Payment and billing processing - EU / United States (covered by the Standard Contractual Clauses). |
| deSEC | DNS record management for the platform's domains - European Union (Germany). |
| Hostinger | Registrar and DNS hosting for domain names acquired by the Subscriber from within the Service - European Union. Processes the domain holder's details passed to the registry. |
| Anthropic | Processing of content submitted to the Service's artificial intelligence features - United States (covered by the Standard Contractual Clauses). Content is not used to train any model. Features enabled at the Subscriber's discretion. |
| Google, Apple, Microsoft | Authentication of Users who choose to sign in with a third-party account - United States. Optional sign-in method. |
Puwapi informs the Subscriber of any addition or replacement of a subprocessor with reasonable notice, allowing the Subscriber to object on legitimate data-protection grounds. If an objection is not resolved, the Subscriber may terminate the Agreement for the service concerned.
8. Transfers outside the European Union
Subscriber Data is hosted within the European Union: servers and databases in Germany, files in France. Three types of processing may involve a transfer to the United States, each covered by the European Commission's Standard Contractual Clauses: payment processing by Stripe; the artificial intelligence features, whose submitted content is passed to Anthropic; and authentication of Users who choose a Google, Apple or Microsoft account.
The last two transfers are avoidable: a Subscriber who does not enable the artificial intelligence features and whose Users sign in with an email address and password is not subject to them. No other transfer outside the European Union is carried out. A copy of the safeguards covering these transfers is provided on request to contact@puwapi.com.
9. Assistance to the Controller
Taking into account the nature of the processing, Puwapi assists the Subscriber, through appropriate technical and organisational measures:
- in responding to requests to exercise data-subject rights (access, rectification, erasure, objection, portability, restriction), in particular via the Service's export and deletion features;
- in ensuring the security of the processing (Article 32);
- in notifying data breaches and, where applicable, in carrying out a data protection impact assessment (DPIA) and prior consultation of the authority (Articles 32 to 36).
If Puwapi receives a request directly from a data subject relating to Subscriber Data, it forwards it to the Subscriber without responding itself, unless legally required to do so.
10. Notification of data breaches
In the event of a personal data breach affecting Subscriber Data, Puwapi informs the Subscriber without undue delay after becoming aware of it, and provides the information needed to enable the Subscriber to meet its obligations to notify the supervisory authority and, where applicable, the data subjects.
11. Fate of the data at the end of processing
On expiry or termination of the Agreement, the Subscriber may export its data. Puwapi keeps it in read-only mode for 30 days to allow retrieval, then, at the Subscriber's choice, returns or deletes it, along with existing copies, unless a legal retention obligation (in particular accounting) requires its retention.
12. Audit and documentation
Puwapi makes available to the Subscriber the information necessary to demonstrate compliance with the obligations of Article 28 of the GDPR. The Subscriber may request, at most once a year and at its own expense, a reasonable audit, on notice, under conditions that preserve the security and confidentiality of other customers; provision of Puwapi's security documentation may satisfy this.
13. Term and changes
This DPA takes effect upon acceptance of the Agreement and remains in force for as long as Puwapi processes Subscriber Data. It may be updated to reflect regulatory changes or subprocessors; any substantial change is notified in accordance with the terms of service.
14. Contact
For any question about data processing or to exercise the provisions of this DPA: contact@puwapi.com.