Data Processing Agreement (DPA)

Entered into pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR). This agreement (the " DPA " or the " Agreement ") is appended to and supplements Sparktacus's Quotation and General Terms and Conditions of Sale, and sets out the framework for the processing of personal data carried out by Sparktacus on behalf of its professional Clients.

Between the undersigned

SPARKTACUS, a simplified joint-stock company (société par actions simplifiée) with share capital of EUR 100, registered with the Trade and Companies Register (RCS) of Paris under number 107 704 942, whose registered office is located at 47 rue Vivienne, 75002 Paris, France, represented by Mr R. TOUSSAINT, duly authorised, hereinafter the " Processor » ;

AND the Client identified in the Quotation and the General Terms and Conditions of Sale to which this Agreement is appended, whose contact details are set out in Annex 1, hereinafter the " Controller ».

Recitals

In connection with its services for the automation and integration of software solutions incorporating artificial intelligence components (the " Services "), Sparktacus may process personal data on behalf of the Client. This Agreement governs such processing in accordance with Article 28 of the GDPR and amended Act No. 78-17 of 6 January 1978 (the "French Data Protection Act"). It is referred to in Articles 4, 18 and 20 of the General Terms and Conditions of Sale as a separate and mandatory document, and together with the General Terms and Conditions of Sale and the Quotation forms a coherent contractual whole.

Article 1, Definitions

Capitalised terms have the meaning set out below; terms defined in the GDPR and not restated here retain the meaning given to them by the GDPR.

Article 2, Subject matter and scope of the agreement

This Agreement sets out the conditions under which Sparktacus, acting as Processor, processes the Data on behalf of the Client, acting as Controller, in connection with the Services. It applies to all Processing operations described in Annex 1.

Contractual interaction. This Agreement supplements the General Terms and Conditions of Sale and the Quotation. In the event of a conflict specifically concerning the protection of personal Data, this Agreement shall prevail on that point; for any other provision (financial terms, limitation of liability, commercial term), the General Terms and Conditions of Sale shall remain applicable. In the event of a conflict with a mandatory requirement of the GDPR or the French Data Protection Act, the legal text shall prevail.

Article 3, Allocation of roles

The Client is the sole Controller : it determines the purposes and means of the Processing operations and warrants that it has a valid legal basis (Article 6 of the GDPR) and, where applicable, satisfies the conditions of Article 9 for special categories of data. It warrants that the Data transmitted have been lawfully collected and that it has complied with its information obligations (Articles 12 to 14 of the GDPR).

Sparktacus acts as Processor and processes the Data solely on the documented instructions of the Client.

Article 4, Obligations of Sparktacus (Article 28(3) GDPR)

(a) Processing on documented instructions

Sparktacus processes the Data solely on the basis of the Client's documented instructions, including for transfers to a third country, unless required to do so by Union or French law; in that case, it shall inform the Client before Processing, unless legally prohibited from doing so. If Sparktacus considers that an instruction infringes the GDPR, it shall immediately inform the Client.

(b) Confidentiality

Sparktacus ensures that persons authorised to process the Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, this obligation persisting after the end of their duties.

(c) Security (Article 32)

Sparktacus implements the technical and organisational measures required by Article 32 of the GDPR, detailed in Annex 2.

(d) Engagement of a sub-processor

Sparktacus complies with the conditions of Articles 28(2) and 28(4) of the GDPR, as set out in Article 7.

(e) Assistance with the exercise of data subjects' rights

Taking into account the nature of the Processing, Sparktacus assists the Client, by appropriate measures and insofar as possible, in responding to requests for the exercise of rights (Chapter III of the GDPR). Any request addressed directly to Sparktacus shall be forwarded to the Client as soon as possible, without any direct response unless otherwise instructed in writing.

(f) Assistance with the obligations of Articles 32 to 36

Sparktacus assists the Client in complying with its obligations under Articles 32 to 36: security (32), notification of a personal data breach to the supervisory authority (33) and communication to data subjects (34) under the conditions of Article 6 of this Agreement, data protection impact assessment (35) and prior consultation (36).

(g) Treatment of the Data at the end of the Services

At the Client's written choice, Sparktacus deletes or returns all the Data at the end of the Services and destroys the copies, save where retention is required by Union or French law (see Article 9).

(h) Provision of information and audits

Sparktacus makes available to the Client the information necessary to demonstrate compliance with Article 28 and allows for audits to be carried out, under the following conditions: at most once every twelve (12) month period, save in the event of a confirmed personal data breach or a request from the supervisory authority; at least thirty (30) days' prior written notice; during business hours, without disproportionate disruption and with respect for the confidentiality of the other clients of the shared infrastructure; a third-party auditor that is not a competitor and is bound by confidentiality; costs borne by the Client, save where a material breach is revealed; the option for Sparktacus to provide existing audit reports, certifications or attestations.

Article 5, Security of processing (Article 32 GDPR)

Sparktacus implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Annex 2).

Shared infrastructure, fair disclosure. The Client is expressly informed that, unless otherwise stipulated in the Quotation, the Services are hosted on an infrastructure of the virtual private server (VPS) type shared between several clients, with logical segregation (and not physical) of the environments and the Data. Sparktacus acknowledges that this architecture entails a concentration of risk on a single infrastructure; the compensating measures are set out in Annex 2. A Client requiring dedicated physical isolation shall make an express request for it, which shall be the subject of a specific Quotation.

Article 6, Personal data breach (Articles 33 and 34 GDPR)

Notification to the Client. In the event of a personal data breach affecting the Client's Data, Sparktacus notifies the Client without undue delay after becoming aware of it, and at the latest within [TO COMPLETE: time period, recommended 48 to 72 hours], in order to enable the Client to comply with its own 72-hour time period (Article 33).

The notification describes, insofar as possible: the nature of the personal data breach (the categories and approximate number of data subjects and records concerned); the contact point; the likely consequences; the measures taken or proposed. This information may be provided in phases.

Sparktacus provides reasonable assistance to the Client with its obligations under Articles 33 and 34. The decision to notify the supervisory authority and to communicate to data subjects rests solely with the Client. Sparktacus makes no external communication without the Client's prior written consent, save where it is under its own legal obligation. Every personal data breach is documented and kept available to the Client.

Article 7, Sub-processing (Articles 28(2) and 28(4) GDPR)

General written authorisation. The Client gives Sparktacus general written authorisation to engage sub-processors. The list as at the date of the Agreement is set out in Annex 3.

Prior information and right to object. Sparktacus informs the Client of any change (addition or replacement) with at least [TO COMPLETE: time period, recommended 30 days]' notice. The Client may raise reasoned objections on data protection grounds during this period; in the absence of a written objection by the expiry of the period, the change is deemed accepted.

Objection. In the event of a reasoned objection, the Parties shall seek a reasonable solution. Failing this, and if Sparktacus maintains its engagement of the sub-processor, the Client may terminate without penalty the part of the Services concerned (under the term and termination conditions of the General Terms and Conditions of Sale and of Article 9). Such termination constitutes the Client's sole remedy in this respect.

Required guarantees (Article 28(4)). Sparktacus imposes on each sub-processor the same data protection obligations as those set out in this Agreement, in particular sufficient guarantees of appropriate technical and organisational measures. Sparktacus remains fully liable to the Client for the performance by the sub-processor of its obligations. The location and, where applicable, the mechanism for the transfer outside the EU are set out in Annex 3 and are governed by Article 8.

Article 8, Transfers of data outside the European Union (Chapter V GDPR)

Principle. Sparktacus makes no transfer outside the EEA without the documented instruction of the Client and without a mechanism compliant with Chapter V of the GDPR (Articles 44 et seq.).

Hosting within the EU by default. The hosting infrastructure (VPS and host, see Annex 3, Hostinger International Ltd, Larnaca, Cyprus, EU) is by default located within the European Union; the hosting of the Data therefore does not, in principle, constitute a transfer outside the EU.

Major point of attention, access to AI models via an LLM Aggregator. Where the Services include an artificial intelligence component, Sparktacus accesses the language models via an LLM Aggregator (such as OpenRouter). Such an aggregator may route the requests, and therefore, where applicable, the Data they contain, to model providers established outside the European Union, in particular in the United States. This operation may constitute a transfer of data outside the EU within the meaning of Chapter V of the GDPR.

Transfer mechanism adopted. For any transfer outside the EU resulting from the LLM Aggregator or another sub-processor, the transfer relies on one of the following bases, in order of preference: (a) an adequacy decision of the European Commission (Article 45), or for the United States the recipient's certified membership of the EU / US Data Privacy Framework (DPF) where it is in force and covers the data concerned [TO COMPLETE: verify the DPF certification of each provider] ; (b) failing that, the standard contractual clauses (SCCs) (Article 46(2)(c)); (c) failing that, any other mechanism under Article 46 or a derogation under Article 49 where applicable and documented.

Supplementary measures. Where the mechanism so requires (in particular SCCs), Sparktacus implements and imposes supplementary technical, organisational and contractual measures ensuring an essentially equivalent level of protection: minimisation of the Data transmitted to the model, prior pseudonymisation or anonymisation where technically possible, encryption in transit, selection of providers offering sufficient guarantees (no reuse for training, controlled retention), filtering of the LLM Aggregator's routing.

Routing restriction and list of providers. The exact list of AI model providers and their location is set out in Annex 3 [TO COMPLETE: list of LLM providers and location]. Sparktacus endeavours, where the configuration allows, to restrict routing to compliant providers. The Client may, by written instruction, require processing exclusively by AI models hosted within the EU, subject to technical feasibility and, where applicable, an adjustment to the Quotation.

Sensitive data. The Client undertakes not to transmit, via the AI-component Services, any data falling within the special categories (Article 9 of the GDPR) without having informed Sparktacus in writing and without an expressly agreed reinforced transfer and security framework.

Article 9, Term, termination, return and deletion

This Agreement takes effect on the date of signature of the Quotation (or of the General Terms and Conditions of Sale) to which it is appended and remains in force for the entire duration of the Services giving rise to Processing.

At the end of the Services, at the written choice of the Client expressed within a period of [TO COMPLETE: recommended 30 days] : (a) return of all the Data in a structured and commonly used format, followed by deletion of the copies; or (b) permanent deletion of all the Data and copies. In the absence of a choice within the period, Sparktacus proceeds with deletion after a written notification that has remained unanswered.

By way of exception, Sparktacus may retain the Data strictly to the extent and for the period required by applicable law, informing the Client. Upon written request, Sparktacus provides a deletion certificate. The Data present in backups are deleted according to the rotation cycle described in Annex 2 and remain, until they are overwritten, subject to the security measures of this Agreement.

Article 10, Liability

Each Party is liable for the damage caused by the Processing under the conditions of Article 82 of the GDPR. Sparktacus is liable only where it has not complied with the obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the lawful instructions of the Client. Sparktacus's liability falls within the framework of the limitation of liability clause of the General Terms and Conditions of Sale, subject to the mandatory provisions of the GDPR. The Client indemnifies Sparktacus against the consequences of any claim arising from a failure by the Client to comply with its obligations as Controller.

Article 11, Governing law and jurisdiction

This Agreement is governed by French law and the law of the European Union, in particular the GDPR. Any dispute falls within the jurisdiction designated by the jurisdiction clause of the General Terms and Conditions of Sale [TO COMPLETE: confirm the competent court referred to in the General Terms and Conditions of Sale], after an attempt at amicable resolution.

Signatures

Annex 1, Description of the processing

To be completed for each engagement; depends on the Client's case (Article 28(3) GDPR).

Annex 2, Technical and organisational security measures (Article 32 GDPR)

Measures adapted to a shared infrastructure with logical segregation. The measures actually implemented for each engagement are specified in the Quotation; failing that, the baseline below applies.

1. Logical segregation of environments

Logical separation of the environments and Data of each client on the shared VPS (separate instances, databases and/or storage spaces); access controls preventing inter-client access. [TO COMPLETE: isolation mechanism: containerisation, dedicated accounts/schemas, separation of workflows]

2. Access management

Least privilege; access restricted to authorised persons; individual and strong authentication (MFA) for administration [TO COMPLETE: confirm MFA] ; periodic review and revocation of rights.

3. Management of secrets and credentials

Storage of secrets in an encrypted vault / manager, never in clear text; rotation and segregation of credentials per client. [TO COMPLETE: secrets management tool]

4. Encryption

Encryption in transit (TLS) on all communications; encryption at rest (storage and backups). [TO COMPLETE: scope and algorithm of encryption at rest]

5. Logging and traceability

Logging of accesses and sensitive operations; retention of logs for [TO COMPLETE: period] ; protection of the integrity of the logs.

6. Backups and continuity

Regular and encrypted backups, frequency [TO COMPLETE], rotation cycle [TO COMPLETE] ; periodic restoration tests [TO COMPLETE: frequency].

7. Vulnerability management

Application of security patches; monitoring of vulnerabilities in components. [TO COMPLETE: frequency of updates, scans/tests]

8. Concentration of risk, compensating measures (shared infrastructure)

A single shared VPS entails a concentration of risk. Compensating measures: strict logical isolation and inter-client controls (point 1); off-site backups enabling restoration in the event of compromise (point 6); monitoring and alerting on the state of the infrastructure [TO COMPLETE: monitoring arrangement] ; documented reversibility plan (point 9); option of dedicated physical isolation on request and under a specific Quotation (Art. 5).

9. Reversibility

Ability to extract the Data in a structured and commonly used format, with a view to their return or migration (see Art. 9).

10. Awareness

Awareness-raising of authorised persons regarding security and confidentiality requirements. [TO COMPLETE]

Annex 3, List of sub-processors (Articles 28(2) and 28(4) GDPR)

List current as at the date of conclusion of the Agreement. Any modification follows the prior information and right-to-object procedure of Article 7.

Specify, where applicable, whether the LLM Aggregator's routing is restricted to a whitelist of providers offering compliant guarantees (see Art. 8).