Data Processing Agreement
Agreement on the processing of personal data pursuant to Article 28 GDPR, annexed to the general terms and conditions of sale. In force as of 9 September 2026.

Clause 1: Parties
This agreement is concluded between the customer organisation identified in the quotation, acting as controller, and Dixit Platform SAS, acting as processor, whose details are as follows.
Legal name: Dixit Platform SAS
Legal form: Société par actions simplifiée (simplified joint-stock company), French law
Share capital: 14,000 euros
Register: RCS Nanterre, number 882 900 590
Registered office: 146 boulevard Voltaire, 92600 Asnières-sur-Seine, France
Represented by: Robin Osmont, Directeur Général
Data protection contact: dpo@dixitplatform.com
Data protection officer: None appointed. The conditions of Article 37 GDPR are not met. A competent contact is designated above.
This Agreement, referred to as the "DPA", supplements the Main Agreement between the Parties and forms an integral part of it. The "Main Agreement" means the quotation accepted by the Customer, together with the general terms and conditions of sale and the general terms of use to which that quotation refers. This DPA is concluded for the duration of the Main Agreement.
Clause 2: Definitions
"Personal data", "processing", "controller", "processor", "personal data breach", "supervisory authority" and "data subject" have the meanings given to them in Article 4 GDPR. "Sub-processor" means any third party engaged by the Processor to carry out processing activities on behalf of the Customer. "GDPR" means Regulation (EU) 2016/679. "Customer Data" means personal data processed by the Processor on behalf of the Customer under this Agreement.
Clause 3: Subject matter and scope
3.1 Subject matter
The Processor processes Customer Data solely on behalf of and on the documented instructions of the Customer, for the purpose of providing the services set out in the Main Agreement. The Customer remains the controller. Annex 1 sets out the purposes, the nature and duration of the processing, the categories of personal data and the categories of data subjects. Any processing going beyond Annex 1, and in particular any processing for the Processor's own purposes, is prohibited.
3.2 Allocation of roles
The Parties acknowledge that the Processor acts in two distinct capacities, which must not be confused:
As processor, for the account and usage data of the Customer's users, for the topics, keywords and monitoring perimeters the Customer configures, and for the profile each user completes freely so that the summaries and alerts sent to that user are personalised, insofar as those elements are processed on the Customer's instructions. This Agreement governs that processing. The platform provides no facility for the Customer to upload its own documents, files or audio recordings, and no processing of that kind falls within the scope of this Agreement; should such a facility be introduced, the Parties would first enter into an amendment.
As controller, for the processing of publicly available data concerning the official activity of holders of public office and registered interest representatives, which forms the substance of the service. This includes the transcription and indexing of debates broadcast by the institutions themselves, in particular the sittings and committee hearings of the national parliaments and of the European Parliament as well as the public sessions of the Council of the European Union. It also includes the administration of the Processor own commercial relationship. That processing is outside the scope of this Agreement and is described in the Processor public information notice.
Clause 4: Obligations of the Processor
4.1 Documented instructions
The Processor processes Customer Data only on the documented instructions of the Customer, including with regard to transfers to a third country. Instructions are given in writing or in text form. Where an instruction is given orally it is confirmed in text form without delay. The Processor documents the instructions it receives. If the Processor considers, on reasonable grounds, that an instruction infringes the GDPR or other applicable data protection law, it informs the Customer without delay and may suspend execution of that instruction until the Customer confirms or withdraws it.
4.2 Confidentiality
The Processor ensures that every person authorised to process Customer Data is bound by a written confidentiality undertaking that survives the end of their engagement, and has been instructed in the applicable data protection rules. This is achieved through an IT charter countersigned before any access is granted, a confidentiality clause in the employment contract, and non-disclosure agreements. The Processor documents these undertakings and produces them at the request of the Customer.
4.3 Security of processing
The Processor implements and maintains for the duration of this Agreement the technical and organisational measures set out in Annex 3, which are designed to ensure a level of security appropriate to the risk within the meaning of Article 32 GDPR. The Processor may implement alternative measures provided the level of security set out in Annex 3 is not reduced. It informs the Customer of any material change at least 30 days before it takes effect, and the Customer may object within that period if the change would reduce the level of security. Changes that increase the level of security, and immediate measures required to counter an active threat, may be implemented without delay and are notified afterwards.
4.4 Sub-processing
The Customer grants the Processor a general authorisation to engage the sub-processors listed in Annex 2. Before engaging a new sub-processor, or replacing one, the Processor informs the Customer in writing at least 30 days in advance. The Customer may object within that period on reasoned data protection grounds. If the Parties cannot reach agreement, the Customer may terminate the Main Agreement, in respect of the affected services, without charge for the remaining term and with a pro rata refund of any prepaid fees.
The Processor imposes on every sub-processor, by written contract, data protection obligations equivalent to those set out in this Agreement. The Processor remains fully liable to the Customer for the performance of its sub-processors' obligations, as if the acts and omissions concerned were its own.
Demonstration of compliance at sub-processor level is made as follows. For sub-processors that publish their data processing terms as non-negotiable standard terms, the Processor provides the version it has accepted together with evidence of acceptance, and the certifications and third-party audit reports made available by that provider. The Processor also exercises, at the Customer's request and in the Customer's interest, the information and audit rights it holds against that sub-processor, and reports the outcome. The Customer holds no direct audit or inspection right against the Processor's sub-processors, and the Processor gives no undertaking on their behalf. This reflects Article 28(4) GDPR, which requires equivalent obligations to be imposed on sub-processors but does not require direct rights to be conferred on the controller.
4.5 Assistance with data subject rights
Requests from data subjects are addressed to the Customer. Where the Processor receives such a request directly, it does not respond on the merits, forwards it to the Customer without delay and confirms that it has done so.
On the documented instruction of the Customer, the Processor rectifies, erases or restricts the processing of Customer Data without delay and in any event within 5 business days. It provides Customer Data in a structured, commonly used and machine-readable format within 10 business days. It confirms performance in writing in each case. Where a request requires a technical operation that cannot reasonably be completed within those periods, the Processor informs the Customer within the period and proposes a date.
4.6 Personal data breach
The Processor notifies the Customer of any personal data breach affecting Customer Data without undue delay and in any event within 24 hours of becoming aware of it. The notification states the time and nature of the breach, the Customer Data and systems affected, the categories and approximate number of data subjects and records concerned, the time of detection, the likely consequences and the measures taken or proposed. Where the information is not available at once it is provided in phases without further undue delay. The Processor takes all reasonable measures to contain the breach and to limit its adverse effects, and assists the Customer with its obligations under Articles 33 and 34 GDPR. The Processor keeps a record of personal data breaches and makes the relevant entries available to the Customer on request.
4.7 Assistance with related obligations
The Processor assists the Customer, to a reasonable extent and within the means available to it, in complying with its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation of the supervisory authority. It makes available the information referred to in Article 30(2) GDPR. It informs the Customer without delay of any binding request from a public authority relating to Customer Data, unless prohibited from doing so by law, and does not disclose Customer Data to a public authority without first exhausting the available legal remedies where there are grounds to do so.
4.8 Return and deletion at the end of the Agreement
On expiry or termination of the Main Agreement the Customer states, within 30 days, whether it requires the return or the deletion of Customer Data. In the absence of a statement, the Processor deletes the data.
Return: the Processor provides Customer Data in a structured, commonly used and machine-readable format within 30 days of the request.
Deletion: the Processor deletes Customer Data from its active systems within 30 days, unless a legal retention obligation applies, in which case it isolates the data and protects it from any further processing.
In backups, deletion takes effect by expiry of the retention period, namely 7 days for the automated daily database backups and up to 3 months for the offline snapshot taken at least every two months. For that period the data is excluded from any active processing and is retained solely for restoration in the event of an incident, and the provisions of this Agreement continue to apply to it. The Processor issues a written record of deletion and, at the latest 3 months and 7 days after the end of the Main Agreement, confirms complete deletion in writing.
4.9 Information and audit
The Processor makes available to the Customer all information necessary to demonstrate compliance with this Agreement, and allows for and contributes to audits in accordance with Article 28(3)(h) GDPR, on the following terms, which are set out in full in Annex 4.
The Customer may conduct or commission one audit per contract year, on 20 business days written notice. Audits are conducted remotely, on the basis of documentation, written responses and, where useful, a supervised screen-sharing session. The Parties record that the Processor operates no offices open to the public, no server room and no data centre of its own: all of its staff work remotely and the whole of the processing infrastructure is operated by the hosting provider named in Annex 2. There is accordingly no site under the control of the Processor at which a physical inspection could be carried out, and physical inspection of the hosting infrastructure is not within the Processor's power to grant.
Following a personal data breach affecting Customer Data that is notifiable under Article 33 GDPR, the notice period and the limit of one audit per year do not apply.
An auditor commissioned by the Customer must not be a competitor of the Processor and signs a non-disclosure agreement before the audit begins. The audit does not extend to the data or configurations of other customers of the Processor. The Customer bears the costs of any third-party auditor. The Processor does not charge for its own time up to 2 person-days per audit.
Clause 5: Obligations of the Customer
5.1 Lawfulness of the data provided
The Customer warrants that the personal data it transmits to the Processor has been collected lawfully, that it has a valid legal basis for the processing it instructs, and that it has provided the information required by Articles 13 and 14 GDPR to the data subjects concerned. Where the Customer transmits special categories of personal data within the meaning of Article 9(1) GDPR, it informs the Processor beforehand so that the Parties may agree the additional measures required, and it warrants that an exception under Article 9(2) GDPR applies.
5.2 Instructions
The Customer gives instructions that are clear, lawful and within the scope of Annex 1. It informs the Processor without delay of any error or irregularity it identifies in the results of the processing.
5.3 Cooperation
The Customer responds to requests from data subjects and, where a personal data breach concerns Customer Data, carries out the notifications required of it as controller. Each Party informs the other without delay of any contact from a supervisory authority relating to the processing governed by this Agreement.
Clause 6: International transfers
6.1 Location of processing
The platform is operated exclusively within the European Union, in the Google Cloud region europe-west1 (Saint-Ghislain, Belgium), with backups hosted within the European Union. No principal storage of Customer Data is located outside the European Union.
6.2 Remaining transfers and remote access
Two sub-processors listed in Annex 2 process Customer Data outside the European Union: the language model analysis provider and the transactional email provider. Those transfers take place only on the basis of an adequacy decision of the European Commission, the standard contractual clauses adopted by the European Commission on 4 June 2021, or another instrument recognised under Chapter V GDPR, together with supplementary measures. In addition, group companies of certain sub-processors, established outside the European Union, may access Customer Data remotely for operational and support purposes; those accesses are covered by the same instruments. Annex 2 states, for each sub-processor, the country of processing and the basis relied upon.
6.3 Transfers not provided for
Any transfer of Customer Data to a third country that is not covered by Annex 2 requires the prior written consent of the Customer.
Clause 7: Liability
Each Party is responsible for compliance with its own obligations under the GDPR. Liability between the Parties under this Agreement is subject to the following limitation.
The aggregate liability of the Processor arising out of or in connection with this Agreement is subject to the single cap stipulated in clause 16 of the general terms and conditions of sale, which covers the whole of the contractual relationship between the Parties. This Agreement establishes no separate cap and cumulates none.
This limitation does not apply, and cannot apply, in the case of wilful misconduct or gross negligence, nor in any other case in which the applicable law prohibits a limitation of liability. It does not affect the right of a data subject to bring a claim directly against either Party under Article 82 GDPR, nor the powers of the supervisory authorities. Where one Party has paid compensation in full for damage caused by processing that infringed the GDPR, it is entitled to claim back from the other Party that part of the compensation corresponding to that Party's part of the responsibility, in accordance with Article 82(5) GDPR.
Clause 8: Term, amendment and termination
This Agreement takes effect on the date of the last signature or, absent signature, on the date the Customer accepts the quotation, and remains in force for the duration of the Main Agreement, and thereafter for as long as the Processor holds any Customer Data. Amendments must be made in writing. Where a change in the applicable law or in the guidance of a competent supervisory authority requires it, the Parties agree in good faith the amendments necessary to restore compliance. Termination of this Agreement entails termination of the Main Agreement to the extent that the services concerned cannot be provided without processing Customer Data.
Clause 9: Governing law and jurisdiction
This Agreement is governed by French law. The Parties record that the GDPR is a regulation of the European Union, directly applicable and identical in substance in every Member State, so that the choice of French law does not reduce the level of protection afforded to data subjects, and that it does not affect the competence of the supervisory authority of the Customer's Member State, nor the right of a data subject to bring proceedings before the courts of their own Member State under Article 79(2) GDPR.
Any dispute relating to the interpretation or performance of this Agreement falls within the exclusive jurisdiction of the competent courts of the place of the Processor's registered office, currently the Tribunal des Activités Économiques de Nanterre, France.
Clause 10: Final provisions
In the event of a conflict between this Agreement and the Main Agreement on a matter of the protection of personal data, this Agreement prevails. If any provision is or becomes invalid, the remaining provisions are unaffected and the Parties replace the invalid provision with a lawful provision that comes closest to its purpose and best satisfies Article 28 GDPR. Annexes 1 to 4 form an integral part of this Agreement.
This agreement is annexed to the general terms and conditions of sale and applies on that basis to any current subscription. A named counterpart, carrying the identification of the parties and a signature block, is drawn up at the Customer's request.
Annex 1: Description of the processing
A1.1 Purposes
Provision of access to the political monitoring and analysis platform for the users designated by the Customer.
Production of alerts, summaries and minutes of events according to the monitoring topics defined by the Customer.
Generation of analytical exports on the perimeters defined by the Customer.
Personalisation of institutional outputs and alert emails from the profile completed by the user.
Making Customer Data and the institutional data of the subscribed perimeter available, at the user's request, through the programmatic access interfaces of the platform, including the MCP connector, to the Customer's conversational assistant application.
A1.2 Nature and duration
Continuous processing for the duration of the Main Agreement. Operations: collection, recording, organisation, structuring, storage, indexing, retrieval, consultation, use, transmission to the users designated by the Customer, making available at the user's request through the programmatic access interfaces of the platform, including the MCP connector, erasure.
A1.3 Categories of data subjects
Employees and staff of the Customer who use the platform.
Natural persons named by the Customer in its monitoring parameters, in practice holders of public office and interest representatives. The public data relating to those persons is separately processed by the Processor as controller, outside the scope of this Agreement, on the terms of clause 3.2.
A1.4 Categories of personal data
Identification and professional contact data of the users: surname, first name, professional email address, function, organisation, role and permissions, and where applicable telephone number.
Platform usage data: time of connection, IP address, user agent, authentication events.
Monitoring parameters defined by the Customer: topics, keywords, legislative files followed, alert settings and saved searches. Those parameters may name natural persons.
User profile: free text in which the user describes their role and their stakes, so that the summaries and alerts sent to that user are personalised. That text is transmitted to the language model providers listed in Annex 2, on the terms of clause 6.
Annex 2: Authorised sub-processors
The sub-processors below process Customer Data. Any change is notified in accordance with clause 4.4.
Google Cloud. Country of establishment: EU contracting entity designated in the Google Cloud Master Agreement. Evidence produced on request. Country of processing: Belgium (europe-west1). Backups: European Union. Purpose: Hosting, database, object storage, compute, messaging, secret management, logging. Transfer basis: No transfer for storage. Group access covered by the standard contractual clauses and the Data Privacy Framework.
Functional Software, Inc. (Sentry). Country of establishment: United States. Country of processing: Germany (EU region of the provider). Purpose: Monitoring of application errors. Users are identified by an opaque Keycloak identifier only. Retention 90 days. Transfer basis: Standard contractual clauses. Agreement signed on 5 June 2026.
Grafana Labs (Raintank, Inc.). Country of establishment: United States. Country of processing: European Union. Purpose: Technical logging and monitoring. Authentication logs and logs of sensitive operations. Retention periods set out in Annex 3. Transfer basis: Standard contractual clauses. Agreement signed on 5 June 2026.
AC PM LLC (Postmark). Country of establishment: United States. Country of processing: United States. Purpose: Sending of transactional emails and alert notifications to the users of the Customer. Transfer basis: Standard contractual clauses and Data Privacy Framework.
Mixpanel. Country of establishment: United States. Country of processing: European Union (EU region activated). Purpose: Analysis of product usage. Transfer basis: Standard contractual clauses and Data Privacy Framework.
OpenAI. Country of establishment: United States. Country of processing: United States. Purpose: Language model analyses. Transfer basis: Standard contractual clauses. Contractual undertaking not to train on Customer Data. Agreement signed on 13 May 2026.
Google (Gemini via Vertex AI). Country of establishment: Same contracting entity as Google Cloud above. Country of processing: European Union, through the Google Cloud region europe-west1. Purpose: Language model analyses. Processing located within the European Union. Transfer basis: Covered by the Google Cloud Data Processing Addendum. Contractual undertaking not to train on Customer Data.
Two clarifications. First, the tools used internally by the Processor for customer relationship management, internal communication, documentation and source code management do not process Customer Data within the meaning of this Agreement; they contain the business contact details of the Customer's representatives, in respect of which the Processor is itself the controller. A list is provided on request. Second, the transcription of parliamentary debates and of the sessions of the Council of the European Union is carried out by Gladia, a company established in France (RCS Rennes 909 935 736) which processes the audio in France, under an agreement signed on 4 June 2026. Gladia acts on behalf of the Processor acting as a controller, on publicly broadcast recordings only, and receives no Customer Data. It therefore does not appear in the table above and is named here so that the Customer has a complete view of the processing chain.
Annex 3: Technical and organisational measures
Measures actually implemented at the date of this Agreement. Measures that are planned but not yet in place are identified as such, so that this Annex may be relied upon as a statement of fact.
A3.1 Hosting and physical security
Hosting by Google Cloud, region europe-west1 (Saint-Ghislain, Belgium). Backups hosted within the European Union. No principal storage outside the European Union.
The Processor operates no server room and no data centre of its own. Physical and environmental security of the processing infrastructure is provided by the hosting provider named in Annex 2.
All staff work remotely. Only equipment provided by the Processor may be used; personal equipment is prohibited. Full-disk encryption is enabled on delivery. Home working is governed by the IT charter: WPA2 or WPA3 wireless networks, prohibition of open public networks, separated working area, secure destruction of printed material.
A3.2 Access control and authentication
Authentication through a self-hosted Keycloak instance in the europe-west1 region. Named accounts only, no shared accounts. Single sign-on with Google and with Microsoft is supported by that instance. The MCP connector authenticates against the same instance, through a delegated authorisation under OAuth 2.0, with the same credentials and the same permissions as web access, and read-only. The user's account with the assistant's provider and their account on the platform are matched on the email address: a different address prevents the connection. The authorisation is revocable at any time, by the user and by the Processor.
Minimum password length of 12 characters with enforced complexity. Central password management.
Multi-factor authentication mandatory on all critical tools and on every access to production.
Access to the production database only through an SSL tunnel with a client certificate, and only for expressly authorised persons. Developers have no direct production access without express authorisation.
Least-privilege principle, formal authorisation policy, documented joiner and leaver process with immediate revocation of all access on departure, monthly review of access rights and of security-relevant changes.
Secrets and certificates held in Google Secret Manager and in a password manager, never in source code.
A3.3 Encryption
Encryption in transit: HTTPS with TLS 1.2 as a minimum, TLS 1.3 preferred. Certificates from trusted certification authorities only. Session tokens as JWT with RS256.
Encryption at rest on the managed database and on object storage, AES-256.
Full-disk encryption on all endpoints (FileVault on macOS, BitLocker on Windows), recovery keys held in the password manager by the technical security officer.
Planned, not yet in place: additional application-level encryption of individual fields beyond infrastructure encryption, and full documentation of secret rotation.
A3.4 Segregation
Multi-tenant segregation in a shared database, enforced at application level by a role-based permission model per customer organisation.
Strict separation of the development, pre-production and production environments. Copies of production data outside production are prohibited; test environments use data without personal identifiers.
For transparency: there is no dedicated database and no tenant-specific encryption key per customer.
A3.5 Pseudonymisation
Users are identified to the error-monitoring provider by an opaque Keycloak identifier only, not by name or email address.
Each new processing activity is assessed to establish whether its purpose can be achieved with pseudonymised data. The assessment is recorded in the data protection impact assessments.
A3.6 Logging and traceability
Logging of sensitive operations through Grafana Cloud (Loki, EU region) and Google Cloud Logging, on a dedicated log backend with restricted access.
Retention: twelve months at most for detailed authentication logs, three months at most for usage and navigation logs, including the content of queries and of connector calls, seven days for cloud logging.
Automatic alerting on connections outside usual hours, bulk exports, repeated failed authentication attempts and changes to administrator accounts. Monthly review.
A3.7 Availability, backup and continuity
Automated daily database backups with 7 days retention, replicated across two EU regions. Offline snapshot taken at least every two months and retained for 3 months.
Recovery objectives: RPO 24 hours and RTO 24 hours for the platform and the production database. Recovery in the second EU region by manual switchover. There is no active multi-region redundancy with automatic failover; a stricter objective requires a separate agreement.
Formal business continuity and disaster recovery plan with a named crisis team, mobilisation within 30 minutes and customer communication within 1 to 4 hours according to severity.
Documented restoration test: a backup from the last seven days is restored to a test instance, integrity is verified, the actual duration is measured against the RTO objective and the result is recorded. This test is carried out at least once a year and after any major change to the data architecture.
A3.8 Vulnerability and change management
Automatic operating system and browser updates. Weekly review of application dependencies for known vulnerabilities. Planned and traced updating of critical libraries.
Secure development practices: separation of environments, secret scanning in pre-commit, branch protection, mandatory multi-factor authentication on the source repository.
A3.9 Organisational measures
Named responsibilities: technical security officer Antoine Carbonell (Président), data protection officer for internal purposes Robin Osmont (Directeur Général), contact dpo@dixitplatform.com.
Mandatory security training through the French ANSSI SecNumacadémie programme within 30 days of joining, with annual refresher training and phishing and social engineering awareness.
Written confidentiality undertakings for all staff, surviving the end of the engagement.
Documentation available on request: information security policy, IT charter, retention policy, artificial intelligence usage policy, business continuity and disaster recovery plan, data subject rights procedure, personal data breach procedure, authority request procedure, record of processing activities under Article 30 GDPR (controller and processor sections), information systems map, data protection impact assessments.
Annual review of the effectiveness of the measures in this Annex, with an additional review after any significant incident, any major change of technology stack or any relevant change in the law. Sub-processor commitments are reviewed at least every six months.
Annex 4: Audit modalities
Notice: 20 business days, in writing. No notice required following a personal data breach affecting Customer Data that is notifiable under Article 33 GDPR.
Frequency: One audit per contract year. The limit does not apply following a notifiable personal data breach affecting Customer Data.
Form: Remote, on the basis of documentation, written responses to a questionnaire and, where useful, a supervised screen-sharing session. There is no site under the control of the Processor at which a physical inspection could be carried out (see clause 4.9).
Scope: The processing carried out on behalf of the Customer, and the measures set out in Annex 3. Excludes the data, configurations and environments of other customers, and excludes the infrastructure of the hosting provider, which is not operated by the Processor and is not under its control.
Sub-processors: No direct audit or inspection right against sub-processors. Demonstration of compliance is made in accordance with clause 4.4: accepted terms, evidence of acceptance, certifications and third-party audit reports, and the exercise by the Processor of its own rights on behalf of the Customer.
Auditor: May be the Customer or a third party commissioned by it. A third party must not be a competitor of the Processor and signs a non-disclosure agreement before the audit begins.
Confidentiality: The audit report is confidential between the Parties.
Costs: The Customer bears the costs of any third-party auditor. The Processor does not charge for its own time up to 2 person-days per audit.
Documentary alternative: At the choice of the Customer, and in place of all or part of an audit: the most recent external data protection audit report, the information systems map, the record of processing activities under Article 30(2) GDPR, the retention policy, the personal data breach procedure, and the certifications and compliance attestations of the sub-processors.
*Version in force since September 9, 2026. Every published version is archived at a permanent address, listed on the Legal documents page.*