Data processing agreement
Article 28 of Regulation (EU) 2016/679 (GDPR) — version 1.1, published 23 September 2026, effective 7 October 2026 (1.0: 15 September 2026)
This agreement (the "Agreement") is part of the Terms of service (the "Terms"). It is accepted together with the Terms and applies as soon as the Customer processes personal data through the Service. A countersigned copy is available on request at [email protected].
1. Parties and roles
- The Customer, as defined in the Terms, is the controller of the personal data contained in its spaces (the "Customer Data"). If the Customer itself acts on behalf of a third party, it warrants that its instructions are authorised by that third party; SPACE UNITY is then a sub-processor.
- SPACE UNITY, a French SASU with variable capital, RCS Sedan 994 377 208, 34 route Nationale, 08140 Douzy, France (the "Publisher"), is the processor.
"Personal data", "processing", "personal data breach" and "sub-processor" have the meanings given in the GDPR.
2. Subject matter and duration
The Publisher processes Customer Data solely to provide the Service. Processing lasts for the term of the contract and then until the Customer Data is erased under section 11. Annex 1 describes the nature and purposes of the processing and the categories of data and data subjects.
3. Instructions
The Publisher processes Customer Data only on the Customer's documented instructions. These instructions consist of:
- the Terms and this Agreement;
- the Customer's configuration and use of the Service, including its automations, agents, shares and connections;
- its written requests.
The Publisher immediately informs the Customer if it considers an instruction to infringe data protection law. If Union or Member State law requires processing, the Publisher informs the Customer before carrying it out, unless that law prohibits doing so.
4. Confidentiality
People authorised to process Customer Data are bound by confidentiality and access it only as needed. In addition, support may access a user's account only with that user's prior permission, given in their settings.
5. Security
The Publisher implements the technical and organisational measures described in Annex 2, in accordance with Article 32 GDPR. It may update these measures provided the level of protection is not reduced.
6. Sub-processors
6.1. The Customer gives the Publisher general authorisation to use the sub-processors listed in Annex 3.
6.2. The Publisher informs the Customer of any addition or replacement at least 30 days in advance, by e-mail to the space owner and by updating Annex 3. The Customer may object in writing, with reasons, within that period. If the parties cannot find a solution, the Customer may terminate the affected Service without penalty and receive a refund of the unused part of any prepaid amounts.
6.3. The Publisher imposes on each sub-processor data protection obligations equivalent to this Agreement, and remains liable to the Customer for their compliance.
6.4. Services chosen by the Customer. Services that the Customer configures or connects itself are not sub-processors of the Publisher. The Customer decides how they are used and is responsible for its relationship with them. These include:
- an AI provider using the Customer's own key, or a local model;
- a space-level e-mail server;
- a connected external or vector database;
- a connected third-party account, such as mail, calendar, storage, team chat, code hosting or an API;
- any site visited by a browser skill.
7. Transfers outside the European Union
The Publisher transfers Customer Data outside the European Economic Area only on one of these bases:
- to a country covered by an adequacy decision, including the Data Privacy Framework for certified organisations;
- under the standard contractual clauses adopted by the Commission on 4 June 2021.
Transfers are supplemented by the additional measures described in Annex 2. The Customer authorises the transfers listed in Annex 3.
8. Data subject rights
The Service lets the Customer handle requests itself: to access, rectify, erase, port, restrict or object, the Customer can view, edit, export and delete data.
The Publisher forwards to the Customer, within 5 business days, any request it receives directly. It does not respond without the Customer's instructions, and it assists the Customer on reasonable request.
9. Assistance
The Publisher provides the information the Customer reasonably needs for its data protection impact assessments and any prior consultation with a supervisory authority. This includes:
- this Agreement and its annexes;
- an extract of the Publisher's record of processing activities;
- a summary of the Publisher's own impact assessments.
10. Personal data breaches
The Publisher notifies the Customer of any personal data breach affecting Customer Data without undue delay, and no later than 48 hours after becoming aware of it. Notification is sent by e-mail to the space owner.
The notification includes the information listed in Article 33(3) GDPR, as far as it is available, and is completed as soon as possible. The Publisher documents the breach and promptly takes measures to mitigate its effects.
11. End of processing
Before the contract ends, the Customer exports Customer Data using the Service's export features. After that:
- a deleted space is permanently erased after 30 days in the trash;
- a deleted account is erased immediately;
- encrypted backups that still contain Customer Data are used only to restore the Service, and are destroyed when their rotation expires, within three years at most.
On request, the Publisher certifies erasure, except where the law requires the data to be retained.
12. Audits
The Publisher makes available the information needed to demonstrate compliance with this Agreement, and answers a reasonable security questionnaire once a year.
The Customer may have an audit carried out once every 12 months, on 30 days' notice, subject to the following conditions:
- it is performed by an independent auditor bound by confidentiality;
- it is carried out at the Customer's expense;
- the auditor has no access to other customers' data;
- it does not disrupt the Service.
An additional audit is possible after a personal data breach affecting the Customer. For sub-processors, the Publisher relies on their certifications and audit reports.
13. Liability
Each party's liability under this Agreement follows the Terms, subject to Article 82 GDPR.
14. Record and contact
The Publisher keeps the record required by Article 30(2) GDPR. Contact: [email protected].
Annex 1 — Description of the processing
Data subjects, depending on how the Customer uses the Service:
- users invited by the Customer;
- people whose data the Customer records: customers, prospects, employees, suppliers and contacts;
- visitors who fill in a form or use an interface published by the Customer;
- correspondents appearing in third-party accounts connected by the Customer.
Data categories are determined by the Customer. They may include:
- identity and contact details;
- professional information;
- the content of documents and messages;
- attachments;
- addresses of the people the Customer invites to a generated interface.
The following are prohibited:
- health data subject to France's certified health data hosting requirement (Article L. 1111-8 of the Public Health Code);
- payment card numbers.
Any other sensitive data is processed under the Customer's sole responsibility. The Customer must ensure a valid legal basis and adequate safeguards.
Operations:
- hosting, storage, backup and restoration;
- display, search, formula calculation and automations;
- sending e-mails on the Customer's behalf;
- AI processing: content generation, document embeddings and search, memory extraction, agents, and visual fallback for browser skills;
- synchronisation with connected services, and running browser skills;
- reading, on request, external databases that the Customer connects, without copying their content;
- support, with the user's permission;
- erasure.
Duration: the term of the contract, followed by the periods set out in section 11.
Annex 2 — Technical and organisational measures
Hosting and network
- Servers are located in Germany (netcup). Files and backups are stored in Cloudflare R2's EU jurisdiction.
- No inbound ports are exposed: traffic reaches the servers through a Cloudflare tunnel. Administration uses an encrypted private network with named individual accounts.
Encryption
- TLS for all traffic.
- Application-level AES-256 encryption, with separate dedicated keys, for:
- integration and connector tokens;
- AI provider keys;
- SMTP credentials;
- browser skill credentials and the values typed during recorded steps;
- password-type fields;
- personal access tokens.
- Recovery codes are hashed.
- Backups are encrypted before they leave the server.
Authentication and access
- Passwordless sign-in, by a single-use link valid for 10 minutes or by a passkey.
- Brute-force lockout, and session renewal at sign-in.
- A passkey or recovery code is required for administrative roles.
- Role-based access control at space and base level, with logical isolation (one database schema per base).
- Support access is possible only with the user's permission. It requires a stated reason, is read-only by default, lasts at most 30 minutes and is logged.
Logging and detection
- Logged events:
- sign-ins, failed sign-ins and lockouts;
- sensitive actions;
- support access;
- agent and connector tool calls, without message content.
- Bursts of failed authentication are detected.
- Logs are retained for 6 months.
Application protection
- Global and per-route rate limiting.
- Content Security Policy.
- Protection against requests to internal addresses when connecting to external services.
- Configuration validation at start-up.
Artificial intelligence
- Secrets are never sent to models, and screenshots are masked first.
- Only the content needed for a task is sent.
- Each user can opt out of document indexing.
- Customers can use their own provider, or a model hosted in the EU or locally.
Continuity
- Hourly encrypted backups, so no more than one hour of data can be lost.
- A sample of backups is read back weekly.
- Full restoration has been tested.
Erasure
- The trash is purged automatically after 30 days.
- Account deletion takes effect immediately and removes sign-in methods and connected accounts.
- Browser skill credentials unused for 90 days are purged.
Organisation
- Access to production data is limited to authorised staff.
- The record of processing activities and the impact assessments are kept up to date.
- A breach management procedure is in place.
- Measures and sub-processors are reviewed annually.
Annex 3 — Sub-processors
| Sub-processor | Processing | Location | Transfer safeguard |
|---|---|---|---|
| netcup GmbH | application and database hosting | Germany | — (EU) |
| Cloudflare, Inc. | network, tunnel, protection; file and backup storage (R2) | files and backups: EU; transit: global network | Data Privacy Framework; standard clauses |
| Plus Five Five, Inc. (Resend) | transactional and automation e-mails | United States | Data Privacy Framework; standard clauses |
| Chatwoot, Inc. | support chat (identification data of the user and their space) | United States | standard clauses |
| Vercel, Inc. | gateway to AI models | United States | Data Privacy Framework; standard clauses |
| Anthropic, PBC | language models | United States | standard clauses |
| OpenAI | language models; document embeddings | United States | standard clauses |
| Mistral AI | language models | France | — (EU) |
| Replicate, Inc. | image and video generation | United States | standard clauses |
| Eleven Labs, Inc. (ElevenLabs) | speech synthesis and transcription | United States | standard clauses |
Stripe and Google Analytics do not appear in this annex because they do not process Customer Data. They process billing and audience data for which the Publisher is the controller (see the Privacy policy).
This is a translation. The French version prevails.