Pikali
  • Home
  • Products
  • Support
  • Contact us
  • Sign in
  • FR
  • Home
  • Products
  • Support
  • Contact us
  • Sign in
  • Français
Data protection

GDPR Data Processing Agreement

Version 2026-09-16 r2, in force from 2026-09-16. Article 28 GDPR — signed online from your customer area.

Governing version. This English text is a faithful translation provided for information only. Only the French version has contractual force and prevails in the event of any discrepancy (article 18).
I. Framework
  • 1. Purpose and capacity of the parties
  • 2. Contract documents
  • 3. Description of the processing
II. Obligations of the parties
  • 4. Documented instructions
  • 5. Confidentiality and authorised persons
  • 6. Security of processing
  • 7. Sub-processors
  • 8. Data location and transfers outside the European Union
  • 9. Assistance: data subject rights
  • 10. Assistance: security, impact assessments and prior consultation
  • 11. Personal data breach
  • 12. Records and documentation
  • 13. Audit
  • 14. Customer's obligations
  • 15. Duration and fate of the data at the end of the contract
  • 16. Liability
  • 17. Electronic signature and evidence agreement
  • 18. Language, governing law and disputes
III. Schedules
  • 19. Schedule A — Description of the processing
  • 20. Schedule B — Security measures
  • 21. Schedule C — Authorised sub-processors

I. Framework

Who does what, and over which processing operations.

1. Purpose and capacity of the parties

This agreement governs the processing of personal data that PIKALI, a French limited liability company (SARL) with share capital of €100, SIRET 10403821100017, Saverne Trade and Companies Register, registered office at 37 Rue Principale, 67310 Dahlenheim, France (“Pikali”) carries out on behalf of its customer (“the Customer”) in connection with the services described in the accepted quotation.

It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”), which requires a written contract between a controller and its processor.

  • The Customer is the controller: the data concerns its visitors, prospects, customers and staff. It determines the purposes of the processing and its essential means — what data is collected, for how long, who has access to it, and on what legal basis.
  • Pikali is the processor: it acts only on the Customer's instructions and never uses such data for its own purposes. It chooses the technical means of implementation (tools, infrastructure, detailed security measures) within the framework set by this agreement.

⚠️ This agreement does not cover the Customer's own data (name, contact details, billing): for those, Pikali is the controller and applies its privacy policy and article 19 of its terms.

2. Contract documents

This agreement supplements Pikali's terms of sale and of service and the quotation accepted by the Customer. In the event of any inconsistency concerning the protection of personal data, this agreement prevails.

Its three schedules form an integral part of it: A — description of the processing · B — security measures · C — authorised sub-processors.

3. Description of the processing

The subject matter, nature, purpose and duration of each processing operation, the type of data and the categories of data subjects are described in Schedule A, in accordance with Article 28(3) GDPR.

Where a new service gives rise to processing not covered by Schedule A, that schedule is updated by written agreement between the parties — an exchange of emails is sufficient.

II. Obligations of the parties

The undertakings required by Article 28 GDPR, and the Customer's own.

4. Documented instructions

Pikali processes personal data only on the Customer's documented instructions. Such instructions consist of: the accepted quotation, this agreement and its schedules, written requests sent by the Customer (email or customer area), and the technical operations strictly necessary to perform the services ordered.

Pikali immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend its execution until written confirmation or amendment.

If Pikali is required by Union or Member State law to transfer or disclose data, it informs the Customer before processing, unless legally prohibited from doing so.

5. Confidentiality and authorised persons

Pikali ensures that persons authorised to process the data — employees, staff and subcontractors — undertake to respect its confidentiality or are under an appropriate statutory obligation of confidentiality, and receive the necessary training.

Access to the data is limited to those persons who need it in order to perform the services, and for no longer than necessary. This undertaking survives the end of the agreement.

6. Security of processing

Pikali implements the appropriate technical and organisational measures required by Article 32 GDPR, taking into account the state of the art, costs, the nature of the processing and the risks to data subjects. These measures are set out in Schedule B.

Pikali may update these measures, provided the level of protection is never reduced.

7. Sub-processors

The Customer gives Pikali general written authorisation to engage sub-processors within the meaning of Article 28(2) GDPR. Those currently involved are listed in Schedule C, and the Customer accepts them by signing this agreement.

Pikali informs the Customer in writing at least thirty days in advance of any addition or replacement of a sub-processor. The Customer may object in writing, giving reasons, within that period; failing a solution acceptable to both parties, it may terminate the affected services free of charge and without penalty.

Pikali contractually imposes on each sub-processor the same obligations as those set out in this agreement, and remains fully liable to the Customer for the performance of their obligations.

8. Data location and transfers outside the European Union

Hosting, storage and backups of the data take place within the European Union (see Schedule C).

Pikali makes no transfer outside the European Union without informing the Customer beforehand and without putting in place an appropriate safeguard under Chapter V GDPR (adequacy decision or European Commission standard contractual clauses).

⚠️ The Customer is informed that certain third-party services it chooses to embed in its website — analytics, maps, video, remotely hosted fonts, site search, social media buttons — may transmit data to parties located outside the Union. Where such a service is planned, it is identified in the quotation and its implications explained; as controller, it is for the Customer to accept it or to request an EU-hosted alternative.

9. Assistance: data subject rights

Requests to exercise rights (access, rectification, erasure, restriction, portability, objection) are the responsibility of the Customer, as controller.

Pikali assists it in responding by appropriate technical measures: extraction, rectification, anonymisation or deletion of data in the website and its backups. If a request is sent directly to Pikali by a data subject, Pikali does not respond itself and forwards it to the Customer within three working days.

This assistance is included in the maintenance package within the included hours; beyond that, it is quoted before any work is carried out.

10. Assistance: security, impact assessments and prior consultation

Taking into account the nature of the processing and the information available to it, Pikali assists the Customer in complying with its obligations under Articles 32 to 36 GDPR: security, notification of breaches, data protection impact assessment (DPIA) and prior consultation of the supervisory authority.

That assistance covers the technical elements within Pikali's control; it does not substitute Pikali for the Customer in assessing risks, which remains the Customer's responsibility.

11. Personal data breach

Pikali notifies the Customer of any personal data breach without undue delay and no later than forty-eight hours after becoming aware of it, by email to the Customer's contact address, in accordance with Article 33(2) GDPR.

The notification describes, as far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a point of contact.

Pikali documents each breach and provides the Customer with everything needed for its own notification to the supervisory authority and, where applicable, to the data subjects. Notifying the supervisory authority is the Customer's responsibility, as controller.

12. Records and documentation

Pikali maintains a record of the categories of processing activities carried out on behalf of its customers, in accordance with Article 30(2) GDPR.

It makes available to the Customer, on written request, the information necessary to demonstrate compliance with the obligations of this agreement.

13. Audit

The Customer may carry out an audit of compliance with this agreement, itself or through an independent auditor it appoints who is not a competitor of Pikali, once per calendar year, on thirty days' written notice.

The audit may cover only the processing carried out on the Customer's behalf, to the exclusion of any other Pikali activity and of other customers' data.

The audit takes place during business hours, without disrupting operations, and respects the confidentiality of other customers' data and Pikali's trade secrets. Pikali may respond by providing existing documentation or an independent audit report where it covers the requested scope.

Audit costs are borne by the Customer, unless the audit reveals a significant failure attributable to Pikali.

14. Customer's obligations

As controller, the Customer:

  • warrants that the data provided to Pikali was lawfully collected and that it has a valid legal basis for each processing operation;
  • informs data subjects and obtains their consent where required (in particular for non-essential cookies and marketing);
  • gives Pikali lawful and documented instructions;
  • transmits no special category data within the meaning of Article 9 GDPR (health, opinions, beliefs, sexual orientation, biometric data) nor any criminal conviction data without Pikali's prior written agreement, as such categories require specific measures;
  • appoints a contact person for data protection matters.

The Customer indemnifies Pikali against any claim arising from a breach of these obligations.

15. Duration and fate of the data at the end of the contract

This agreement takes effect on signature and remains in force for as long as Pikali processes personal data on the Customer's behalf.

On termination, for whatever reason, and at the Customer's written choice, Pikali either returns the data (in the standard format available at Pikali on the date of the request) or deletes it, together with existing copies, unless retention is legally required.

Failing a choice expressed within thirty days, and after a written reminder that has remained unanswered, Pikali deletes the data at the end of the retention period provided for in article 15 of the terms (ninety days). Residual encrypted backups are destroyed at the end of their rotation cycle, with no possibility of reuse.

Pikali certifies the return or deletion in writing at the Customer's request.

16. Liability

Each party bears the consequences of its own failures, under the conditions of Article 82 GDPR. The limitation of liability in article 13.2 of Pikali's terms applies to this agreement, except where the law prohibits it, in particular in cases of gross negligence or wilful misconduct.

Where one party has paid full compensation for a damage, it may claim back from the other the share corresponding to that party's responsibility.

17. Electronic signature and evidence agreement

The following sets out exactly what the Customer accepts when signing this agreement online from its customer area.

17.1 — What the signature means

By entering their first name, surname and role, ticking the acceptance box and confirming, the signatory:

  • accepts this agreement and its three schedules, in the version presented on that same page;
  • authorises the sub-processors listed in Schedule C (article 7);
  • represents that they are authorised to bind the Customer's business.

17.2 — Method used

The signature is a simple electronic signature within the meaning of articles 1366 and 1367 of the French Civil Code and of Regulation (EU) No 910/2014 (eIDAS). Recorded at the exact moment of confirmation are: the first name, surname and role entered, the timestamped date and time, the IP address, the browser used, the version of the agreement accepted and the digital fingerprint (SHA-256) of its full text.

Access to the customer area is protected by a personal access key issued to the Customer, who undertakes not to disclose it to any unauthorised third party.

17.3 — Evidence agreement

In accordance with article 1356 of the French Civil Code, the parties expressly agree that the electronic records kept by Pikali shall constitute evidence between them as to the identity of the signatory, the date of signature and the content accepted, unless proven otherwise.

17.4 — Retention and copy

The signed agreement is generated as a PDF and remains permanently accessible from the customer area. A confirmation is sent by email immediately upon signature. Pikali retains it, together with its evidence, for ten years.

18. Language, governing law and disputes

This agreement is drafted in French. Only the French version has contractual force; any translation is provided for information purposes and the French version prevails in the event of any discrepancy.

It is governed by French law. Failing an amicable resolution within thirty days of a written claim, any dispute falls within the exclusive jurisdiction of the courts of Saverne, France.

III. Schedules

These form an integral part of the agreement.

19. Schedule A — Description of the processing

The processing operations below are those entailed by Pikali's usual services. Those that do not correspond to the services actually ordered in the quotation are not carried out.

ProcessingPurposeData subjectsDataDuration
Website hosting Keep the website available and running Visitors, customers and users of the website Data entered on the site, technical logs, IP addresses Term of the hosting contract
Backups Restore the site and its data after an incident Same Full copy of files and database Retention period stated in the quotation
Maintenance and support Fix, update, secure, diagnose Same, and the Customer's staff Occasional access to the data needed for diagnosis For the duration of the work
Migration of an existing site Transfer content and accounts from an existing site to the new one The Customer's existing customers and accounts Accounts, orders, histories, files For the duration of the migration, then deletion of working copies
Forms and orders Deliver messages and orders to the Customer Visitors, prospects, buyers Identity, contact details, message content, order details As set by the Customer
Sending the site's emails Confirmations, notifications, password resets Recipients of the messages Email address, message content Retention period of the sending logs

Nature of the operations: collection, recording, organisation, storage, consultation, extraction, alteration, transmission to the Customer, erasure.

No special category data (Article 9 GDPR) is processed, save with prior written agreement providing for the corresponding specific measures (article 14).

20. Schedule B — Security measures

In accordance with Article 32 GDPR, Pikali implements the following measures:

  • Encryption in transit: HTTPS enforced on all delivered sites, with automatically renewed certificates; file transfers and server access over encrypted protocols (SSH, SFTP).
  • Access control: named accounts, long unique passwords kept in a vault, two-factor authentication on administrative access, least-privilege principle, removal of access as soon as it is no longer required.
  • Segregation: each customer site has its own isolated environment and its own database credentials; no customer's data is reachable from another customer's environment.
  • Backups: daily, replicated to a second European Union region, with a check that each backup completed successfully.
  • Security updates applied to systems and application components, according to the maintenance package subscribed to.
  • Logging of administrative access and sensitive operations, allowing an incident to be reconstructed.
  • Minimisation: Pikali extracts and copies only the data required for the work in hand, and deletes its working copies once it is complete.
  • Transmission of credentials: credentials entrusted by the Customer travel through a dedicated channel in the customer area and are never exchanged by email.
  • AI assistance — strict scope: Pikali uses an AI model to analyse a website's technical structure and to produce code (Schedule C). The personal data of the Customer's visitors and customers is not submitted to it: the assistance covers code, configuration, structure and public content. Where a diagnosis requires examining real records, they are counted or anonymised, never copied into the model.
  • Continuity: monitoring of servers and site availability, documented restoration procedure.

These measures may evolve with the state of the art, without ever reducing the level of protection.

21. Schedule C — Authorised sub-processors

The Customer authorises the following sub-processors (article 7):

Sub-processorRoleData location
Hetzner Online GmbH (Germany) Hosting of servers and backups European Union (Germany, Finland)
LWS — Ligne Web Services (France) Delivery of the sites' transactional emails European Union (France)
Anthropic (United States) AI model used by our internal tools to analyse a website's technical structure and to produce code — within the strict scope set out in Schedule B (no personal data of your visitors or customers is submitted to it) Outside the European Union, covered by European Commission standard contractual clauses

The following are not sub-processors of Pikali:

  • the payment provider (SumUp) and banking institutions, which act as independent controllers for payment data under their own regulatory obligations. The Customer contracts with them directly;
  • the domain name registrar and any third-party service subscribed to directly by the Customer in its own name.

Where the Customer asks to keep its current host or imposes a provider, that provider is its own processor: Pikali is not answerable for it.

See also: terms of sale and of service · privacy policy.

Pikali

Publisher of e-commerce modules for PrestaShop and WooCommerce, and builder of custom business software for small and mid-sized companies — in France and internationally.

Navigation

  • Home
  • Products
  • PrestaShop modules
  • WooCommerce plugins
  • Support
  • Contact

Contact

  • France · across Europe
  • contact@pikali.fr

Legal

  • Legal notice
  • Terms of sale
  • Data processing (GDPR)
  • Privacy

© Pikali — All rights reserved.

Extranet