Data processing agreement
This agreement forms part of the terms of service between Robin Bonnin (the "Processor") and the customer (the "Controller"). It applies to the personal data the Processor processes on the customer's behalf in providing Pomelow, in accordance with Article 28 GDPR.
1. Subject matter, nature and duration
- Subject matter and nature: hosting and operating the Pomelow apps (mail, calendar, chat and video calls, documents, file storage, tasks and any other add-ons the customer turns on): storing, backing up, transmitting and displaying data.
- Data subjects: the members of the customer's organization and the people they correspond with.
- Data: members' identity and contact details, content (emails, messages, documents, files, calendars, tasks), and the related metadata and technical logs. The customer alone decides what content is uploaded, including any sensitive data.
- Duration: the term of the subscription, then until the deletion that follows the closure of the organization (30 days after the request).
2. Processor's obligations
- Process the data only on the customer's documented instructions, which are these terms and the customer's use of the service; tell the customer if an instruction appears to infringe the GDPR.
- Ensure that people authorized to access the data are bound by confidentiality.
- Implement the security measures in section 4.
- Help the customer, as far as possible, respond to data subjects' requests, notably through the exports available in the admin portal.
- Help the customer meet its obligations on security, breach notification and impact assessments, taking into account the information available to the Processor.
- Notify the customer of any personal data breach without undue delay and at the latest 48 hours after becoming aware of it, with the information available.
- Make available the information needed to demonstrate compliance with this agreement, and allow an audit on a reasoned request, with 30 days' notice, at the customer's expense and at most once a year.
3. Subprocessors
The customer authorizes the subprocessors listed on the Subprocessors page. The Processor informs the customer by email at least 30 days before adding or replacing one; the customer may object on reasonable grounds and, failing a solution, cancel its subscription. The Processor imposes on each subprocessor obligations equivalent to those in this agreement.
4. Security measures
- Hosting with Scaleway, in France (Paris region); databases reachable only over a private network.
- Encrypted connections (HTTPS/TLS) on every address of the service.
- Single sign-on for every app, with two-factor authentication available; organizations kept apart in the identity directory.
- Daily database backups and a nightly backup of every mailbox, on separate storage.
- Administrative access to the infrastructure restricted to the operator, with credentials never committed to source code.
- Regular updates of the open-source software the service is built from.
5. Transfers outside the European Union
Customer content is hosted in the European Union. No transfer outside the Union takes place without appropriate safeguards under Chapter V GDPR; any transfer by a subprocessor is stated on the Subprocessors page.
6. End of processing
Before closure, the customer can retrieve its data using the available exports and downloads. At the end of the closure period, the Processor deletes the customer's data and its members' accounts, unless the law requires them to be kept.