1 June 2025
This agreement is intended to ensure the compliance of the personal data processing carried out by Saalz on behalf of the Client, in accordance with Articles 28.3 and 28.4 of Regulation (EU) 2016/679 (GDPR).
This agreement governs the personal data processing carried out by Saalz for the Client in connection with the use of the Saalz CRM platform.
Saalz acts exclusively on the Client's documented instructions, unless required to do otherwise by a provision of Union or French law. In that case, Saalz will inform the Client of that obligation, unless prohibited by law.
Saalz will inform the Client if, in its view, an instruction constitutes an infringement of the GDPR or of any other applicable regulation.
Saalz implements appropriate technical and organisational measures to guarantee the confidentiality, integrity, availability and resilience of systems and data (detailed in Annex 1).
Access to data is strictly limited to authorised staff and subject to a confidentiality undertaking.
Saalz makes available to the Client all the information necessary to demonstrate compliance with the obligations set out in this agreement.
Upon reasoned request and where there is serious evidence of non-compliance, the Client may audit the processing carried out, directly or through an independent auditor, with 30 days' notice. Such audits will be carried out during business hours and within reasonable limits of frequency.
Saalz undertakes to cooperate with supervisory authorities upon request.
Saalz has general authorisation to engage sub-processors (see the list of sub-processors, kept up to date).
Saalz will inform the Client of any change at least 8 days before a new sub-processor is added, so that the Client may raise a reasoned objection. Failing an objection within that period, the new sub-processor will be deemed accepted.
Saalz contractually imposes on its sub-processors data protection commitments equivalent to those set out in this DPA.
Data is hosted within the European Union (Hetzner Cloud, Germany). Certain sub-processors may occasionally process data outside the EU under standard contractual clauses (SCCs) approved by the European Commission.
No transfer outside the EU is carried out without a legal framework compliant with the GDPR (Chapter V).
Saalz assists the Client:
Requests to exercise rights received directly by Saalz will systematically be forwarded to the Client, unless specifically agreed otherwise.
In the event of a personal data breach, Saalz will inform the Client without undue delay after becoming aware of it.
The notification will include in particular:
Where not all the information is immediately available, Saalz will provide the details progressively as they are obtained.
On expiry of the contract, the Client's data is retained for a period of 12 months to allow for possible reactivation.
After that period, the data is permanently deleted, unless legal obligations provide otherwise. Backups follow the same deferred erasure policy.
The Client remains responsible for the lawfulness of the data collected and processed through Saalz. Saalz acts solely as a technical processor.
In the event of serious and repeated failure by either party to comply with the obligations of this agreement, the other party may suspend or terminate the agreement.
This agreement is governed by French law. Any dispute will fall within the exclusive jurisdiction of the courts having jurisdiction over SITENCO's registered office.