Contractual appendix
Data processing agreement
Article 28 of the GDPR, version 1.4, effective October 3, 2026. This English translation is provided for convenience only; the French version prevails.
This agreement governs the processing of personal data that D&S Intelligence (the “Provider”) carries out on behalf of its client (the “Client”), in accordance with Article 28 of Regulation (EU) 2016/679 (the “GDPR”). It forms part of the contract between the parties, whatever the document that constitutes it: the accepted Quote and the Provider's general terms of sale (the “Terms of Sale”, Article 13), or the service contract and its appendices (Article 18). It is attached to the Quote or to the service contract together with its Client sheet (Appendix 1), and accepted with it.
It applies from the formation of that contract, by acceptance of the Quote or signature of the service contract, for the entire duration of the services, and then until the deletion of the data provided for in Article 10. In the event of any conflict relating to personal data between this agreement and the Quote, the Terms of Sale or the service contract, this agreement prevails, unless a provision of the service contract expressly derogates from a named article of this agreement.
1. Roles of the parties
The Client acts as controller: it determines the purposes and means of the processing carried out by means of the Automations, and is responsible for its lawfulness.
The Provider acts as processor: it processes the data on behalf of the Client, on the Client's instructions, without determining the purposes of the processing.
2. Subject matter and description of the processing
The nature and purposes of the processing, the categories of data and of data subjects, and the duration of the processing are described in Appendix 1 and, for each Client, in its Client sheet, attached to the Quote or to the service contract.
3. Instructions from the controller
The Provider processes the data only on documented instructions from the Client, including with regard to transfers outside the European Union. The accepted Quote or the service contract, this agreement, the Client sheet and any subsequent written instruction constitute these documented instructions. It does not process the data otherwise unless required to do so by Union or Member State law to which it is subject; in such a case, it informs the Client before the processing, unless that law prohibits it.
If the Provider considers that an instruction infringes the GDPR or any other data protection provision, it immediately informs the Client and may suspend the execution of the instruction concerned.
4. Confidentiality
The Provider ensures that the persons authorized to process the data have committed themselves to confidentiality, by contract or under a statutory obligation, and receive the training necessary for the protection of the data.
5. Security of processing
The Provider implements the appropriate technical and organizational measures provided for in Article 32 of the GDPR, detailed in Appendix 2, taking into account the state of the art, the costs of implementation and the risks to data subjects.
6. Sub-processing
The Client gives the Provider a general authorization to engage the sub-processors listed in Appendix 3.
The Provider informs the Client of any addition or replacement of a sub-processor, by email sent to the contact designated in the Client sheet, at least thirty (30) days before the new sub-processor processes the Client's data, specifying its identity, its address, the service and the place of processing. The Client may object in writing within that period, on legitimate grounds relating to data protection; if no reasonable alternative solution is found, either party may then terminate the services concerned without compensation. Upon request, the Provider provides the Client with the list of the sub-processors of its own sub-processors, as published by them.
The Provider imposes on its sub-processors, by contract, obligations that comply with Article 28(4) of the GDPR and offer a level of data protection equivalent to that of this agreement; for the service providers listed in Appendix 3, these obligations arise from their data processing agreements, which are provided to the Client upon request, and audits are carried out by means of their reports and certifications. The Provider remains fully liable to the Client for their performance.
Publishers of artificial intelligence models, including audio transcription and image generation services that rely on such models (the “AI Suppliers”), are, as a general rule, accessed through accounts opened in the Client's name, and the Client contracts with them directly: they are then the Client's own processors, and not those of the Provider. Where an Automation operates through an account opened in the Provider's name, the AI Supplier concerned is a sub-processor of the Provider and is listed in Appendix 3.
In both cases, the Provider configures the accounts so that the Client's data is not used to train models and, where the AI Supplier allows it, so that the retention of requests and responses is reduced to the minimum the AI Supplier offers. Depending on the AI Supplier, this configuration includes in particular: opting out of any model improvement program that allows the use of the Client's data, using an offering whose terms exclude such use where the free offering allows it, and entering into the data processing agreement offered by the AI Supplier. It is checked before the first processing of the Client's data and recorded in the Client sheet.
The chosen model, its publisher, the account holder and the country in which the model runs are agreed with the Client and recorded in the Client sheet (Appendix 1) before the model first processes any of the Client's data, including during development and acceptance testing; they constitute the Client's documented instruction within the meaning of Article 3. The Client may at any time request a configuration in which the models run within the European Union, in particular for sensitive data; this choice may change the model used and its cost. Any change to the configuration that results in a transfer outside the Union or changes the country of execution requires the Client's prior written consent; other changes are notified to the Client under the conditions of this article.
7. Assistance to the Client
Taking into account the nature of the processing, the Provider assists the Client:
- in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, objection, portability);
- in ensuring compliance with the obligations relating to security, breach notification and impact assessment set out in Articles 32 to 36 of the GDPR;
- by making available the information necessary to demonstrate its compliance.
Where a request sent directly to the Provider comes from a data subject, the Provider forwards it to the Client without delay and does not respond to it on its own initiative.
8. Personal data breach
The Provider notifies the Client of any personal data breach, including where it occurs at a sub-processor, within forty-eight (48) hours of becoming aware of it, by email sent to the contact designated in the Client sheet, so as to enable the Client to meet its own 72-hour deadline for notification to the CNIL (the French data protection authority).
The notification specifies the nature of the breach, the categories and approximate number of data subjects and records concerned, the name and contact details of the contact person at the Provider, the likely consequences, and the measures taken or proposed to address it. Information that is not yet available is provided in phases, without undue delay. The Provider documents the breach and does not notify it to the supervisory authority or to the data subjects without instructions from the Client.
9. Transfers outside the European Union
The Automations' orchestrator and their databases are hosted in the European Union, in Germany and Ireland (Appendix 3).
Other services listed in Appendix 3 may process the data outside the Union, in particular in the United States, where the Automation uses them: AI models, audio transcription, Google Workspace tools, hosting of web interfaces, image storage, social media publishing and reading of web pages. No Automation uses a service located outside the Union that is not listed in the Client sheet; adding such a service, like any change to the country in which a model runs, requires the Client's prior written consent (Articles 3 and 6).
These transfers are governed by the safeguards of Chapter V of the GDPR: the adequacy decision on the EU-U.S. Data Privacy Framework (the “EU-U.S. Framework”) where the recipient is certified under it, failing which the European Commission's standard contractual clauses (the “SCCs”). Where the account is opened in the Client's name, the SCCs are entered into between the Client and the service provider concerned; where it is opened in the Provider's name, the Provider enters into them with its sub-processor or, if the sub-processor is established in the Union, ensures that the sub-processor has entered into them with the companies of its group located outside the Union. For transfers based on the SCCs for which it is the exporter, the Provider documents the transfer impact assessment and provides it to the Client upon request. Several service providers listed in Appendix 3 whose servers are located in the Union are companies established outside the Union; any access by them from abroad is covered by the same safeguards.
Where the Client chooses a European configuration, which it may request at any time (Article 6), the Automation uses, apart from the Client's own tools, only services whose servers are located in the Union.
Upon request, the Provider assists the Client in assessing the transfers carried out on its behalf.
10. Return and deletion of data at the end of the contract
Upon expiry of the services, the Provider delivers to the Client, upon written request made within thirty (30) days, an export of the data in a structured and commonly used format, in accordance with Article 19 of the Terms of Sale or, for a Client bound by a service contract, Article 24 of that contract.
After a period of ninety (90) days, the Provider securely deletes all of the Client's data and its copies, including the orchestrator's execution data and the data held on its behalf by its sub-processors, unless retention is required by law. Backups are erased at the end of their rotation cycle. The Provider closes, or transfers to the Client, the accounts opened in its own name for the Client's Automations, and certifies the deletion in writing upon request.
11. Records and audit
The Provider maintains a record of the categories of processing activities carried out on behalf of its clients, in accordance with Article 30(2) of the GDPR.
The Provider makes available to the Client the information necessary to demonstrate compliance with this agreement: a description of the measures in Appendix 2, answers to a questionnaire, and reports and certifications of its sub-processors. In addition, once a year and subject to thirty (30) days' notice, the Client may carry out an audit, including an inspection, either directly or through an independent auditor who is bound by a confidentiality obligation and is not a competitor of the Provider. The audit takes place during business hours, without disrupting the Provider's business, and at the Client's expense. The annual limit and the notice period do not apply to an audit following a personal data breach or requested by a supervisory authority.
12. Contact
Any question relating to this agreement may be sent to contact@ds-intelligence.tech. The Provider has not appointed a data protection officer, as such an appointment is not mandatory in view of its activities.
13. Liability
The parties' liability under this agreement is governed by Article 16 of the Terms of Sale or, for a Client bound by a service contract, by Article 19 of that contract. The caps set out therein apply only once to all claims based on those documents and on this agreement.
Loss or alteration of data hosted by the Provider or by its sub-processors, where it results from a breach by the Provider of its security or backup obligations, constitutes direct damage; compensation for it is limited to the cost of reconstituting that data, within those caps. These provisions limit neither the rights that data subjects derive from Article 82 of the GDPR nor the powers of the supervisory authority; each party alone bears any administrative fines imposed on it.
14. Applicable version and amendments
The version of this agreement applicable to the Client is the one in force on the date of formation of the contract that makes it applicable (acceptance of the Quote or signature of the service contract). A copy is provided to the Client on that date, together with its Client sheet; earlier versions are archived by the Provider and provided upon request.
A new version applies to the Client only once the Client has accepted it in writing; failing that, the version the Client accepted continues to apply. By way of exception, Appendix 3 evolves under the conditions of Article 6, and the Client sheet under the conditions of Articles 3 and 6.
Appendix 1: description of the processing
The table below describes the general framework. For each Client, a completed sheet, the “Client sheet”, is attached to the Quote or to the service contract and accepted with it; it prevails over the general framework. It is supplemented or amended in writing, with the Client's agreement, under the conditions of Articles 3 and 6.
| Item | Description |
|---|---|
| Nature of the processing | Hosting, automated execution, consultation, transmission, structuring and erasure of data, as part of the operation of the Automations. |
| Purpose | Execution of the automated business processes defined by the Client in the Quote. |
| Categories of data subjects | Depending on the Automation: the Client's customers and prospects, the Client's employees, suppliers, correspondents. |
| Categories of data | Identification and contact data, professional data, content of documents and communications submitted to the system. No special categories of data within the meaning of Article 9 of the GDPR, unless expressly stated in the Client sheet. |
| AI models and services outside the Union | For each Automation: the model, its publisher, the account holder (Client or Provider) and the country in which it runs; the other services located outside the Union that it uses and the safeguard governing the transfer; or the statement “European configuration”. Entered in the Client sheet at the time of the Quote or of the service contract, and at the latest before the model first processes any of the Client's data. |
| Automated decision-making | No Automation alone takes a decision that produces legal effects concerning a person or similarly significantly affects them, within the meaning of Article 22 of the GDPR, unless expressly stated in the Client sheet. |
| Duration | Duration of the services, plus the reversibility period provided for in Article 10. |
Appendix 2: security measures
The Provider applies the following measures.
- Access: only persons authorized by the Provider and bound by confidentiality (Article 4) access the administration consoles of the services in Appendix 3 and of the accounts used for the Automations, through named accounts protected by two-factor authentication where the service offers it; access that is no longer needed is withdrawn.
- Segregation: each Client has its own login credentials for the services that process its data and, where the Automation stores data, a database of its own; one Client's data is never used for another Client's Automations. The workflows of all Clients run on a single n8n Cloud instance reserved for the Provider: segregation there relies on these separate credentials and databases, not on separate environments.
- Encryption: data encrypted in transit (TLS) and at rest by the hosting providers listed in Appendix 3; the disks of the Provider's workstations are encrypted.
- Secrets: API keys and credentials are kept in n8n's encrypted credential store and in a password manager, never in a source code repository or in an email.
- Retention in the orchestrator: workflow execution data is kept for no more than thirty (30) days, unless a different period is set in the Client sheet.
- Backups: daily backup of the Automations' databases by their hosting provider and at least weekly export of the workflows; a restoration is tested at least once a year.
- Logging: access and administration logs kept by the hosting providers, to the extent they offer them; a register of personal data breaches kept by the Provider.
- Minimization: only the data necessary to execute the process passes through the Automation.
- AI Suppliers: opt-out from training and minimum retention, configured under the conditions of Article 6.
- Workstations: security updates applied and automatic session locking.
- Continuity: monitoring of the Automations in production and a documented recovery procedure.
- Review: annual review of these measures and of the sub-processors; any change that reduces the protection of the data is notified to the Client.
Appendix 3: sub-processors
| Sub-processor | Service | Location and safeguard |
|---|---|---|
| n8n GmbH (Berlin, Germany) | Hosting and execution of the Automations orchestrator (n8n Cloud) | Germany |
| Supabase Pte. Ltd (Singapore), Supabase group | Databases for the Automations | Servers in the European Union (Ireland or Germany, depending on the project); any access from abroad governed by the SCCs in its data processing agreement |
| Vercel Inc. (Covina, California, United States) | Hosting of the Automations' web interfaces, where the Quote so provides (computing region set within the Union where the project allows) | European Union and United States; company certified under the EU-U.S. Framework |
| Cloudflare, Inc. (San Francisco, United States) | File storage for the Automations, where the Quote so provides | European Union (storage under EU jurisdiction); company certified under the EU-U.S. Framework |
| Railway Corporation (San Francisco, United States) | Hosting of web interfaces for the Automations, where the Quote so provides | Region set for each project and stated in the Client sheet; company certified under the EU-U.S. Framework |
| OpenAI Ireland Limited (Dublin, Ireland), OpenAI group | AI models, where the account is opened in the Provider's name | United States, or European Union for a project created in the European region; SCCs between OpenAI Ireland Limited and the companies of its group located outside the Union |
| Anthropic Ireland, Limited (Dublin, Ireland), Anthropic group | AI models, where the account is opened in the Provider's name | United States; SCCs in Anthropic's data processing agreement |
| Google Cloud France (Paris, France), Google group | Gemini AI models and Google Workspace tools, where the account is opened in the Provider's name | European Union and United States; Google LLC certified under the EU-U.S. Framework |
| AssemblyAI, Inc. (New York, United States) | Audio transcription, where the account is opened in the Provider's name | United States, or European Union through its European endpoint; company certified under the EU-U.S. Framework |
| Cloudinary Ltd. (Israel) and its subsidiary Cloudinary Inc. (Santa Clara, United States) | Image storage and delivery, where the Quote so provides | United States; Cloudinary Inc. certified under the EU-U.S. Framework |
| Buffer, Inc. (San Francisco, United States) | Social media scheduling and publishing, where the Quote so provides | United States; company certified under the EU-U.S. Framework |
| SideGuide Technologies, Inc., trading as Firecrawl (United States) | Reading of public web pages whose address is provided by the Client, where the Quote so provides | United States; company not certified under the EU-U.S. Framework: the Provider sends it only the addresses of those pages, without any other data of the Client |
Any change to this list is notified to the Client under the conditions of Article 6. AI Suppliers whose account is opened in the Client's name are not included in it: they are the Client's own processors.