Version 2026-09-16 r2, in force from 2026-09-16. Article 28 GDPR — signed online from your customer area.
Who does what, and over which processing operations.
This agreement governs the processing of personal data that PIKALI, a French limited liability company (SARL) with share capital of €100, SIRET 10403821100017, Saverne Trade and Companies Register, registered office at 37 Rue Principale, 67310 Dahlenheim, France (“Pikali”) carries out on behalf of its customer (“the Customer”) in connection with the services described in the accepted quotation.
It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”), which requires a written contract between a controller and its processor.
⚠️ This agreement does not cover the Customer's own data (name, contact details, billing): for those, Pikali is the controller and applies its privacy policy and article 19 of its terms.
This agreement supplements Pikali's terms of sale and of service and the quotation accepted by the Customer. In the event of any inconsistency concerning the protection of personal data, this agreement prevails.
Its three schedules form an integral part of it: A — description of the processing · B — security measures · C — authorised sub-processors.
The subject matter, nature, purpose and duration of each processing operation, the type of data and the categories of data subjects are described in Schedule A, in accordance with Article 28(3) GDPR.
Where a new service gives rise to processing not covered by Schedule A, that schedule is updated by written agreement between the parties — an exchange of emails is sufficient.
The undertakings required by Article 28 GDPR, and the Customer's own.
Pikali processes personal data only on the Customer's documented instructions. Such instructions consist of: the accepted quotation, this agreement and its schedules, written requests sent by the Customer (email or customer area), and the technical operations strictly necessary to perform the services ordered.
Pikali immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend its execution until written confirmation or amendment.
If Pikali is required by Union or Member State law to transfer or disclose data, it informs the Customer before processing, unless legally prohibited from doing so.
Pikali ensures that persons authorised to process the data — employees, staff and subcontractors — undertake to respect its confidentiality or are under an appropriate statutory obligation of confidentiality, and receive the necessary training.
Access to the data is limited to those persons who need it in order to perform the services, and for no longer than necessary. This undertaking survives the end of the agreement.
Pikali implements the appropriate technical and organisational measures required by Article 32 GDPR, taking into account the state of the art, costs, the nature of the processing and the risks to data subjects. These measures are set out in Schedule B.
Pikali may update these measures, provided the level of protection is never reduced.
The Customer gives Pikali general written authorisation to engage sub-processors within the meaning of Article 28(2) GDPR. Those currently involved are listed in Schedule C, and the Customer accepts them by signing this agreement.
Pikali informs the Customer in writing at least thirty days in advance of any addition or replacement of a sub-processor. The Customer may object in writing, giving reasons, within that period; failing a solution acceptable to both parties, it may terminate the affected services free of charge and without penalty.
Pikali contractually imposes on each sub-processor the same obligations as those set out in this agreement, and remains fully liable to the Customer for the performance of their obligations.
Hosting, storage and backups of the data take place within the European Union (see Schedule C).
Pikali makes no transfer outside the European Union without informing the Customer beforehand and without putting in place an appropriate safeguard under Chapter V GDPR (adequacy decision or European Commission standard contractual clauses).
⚠️ The Customer is informed that certain third-party services it chooses to embed in its website — analytics, maps, video, remotely hosted fonts, site search, social media buttons — may transmit data to parties located outside the Union. Where such a service is planned, it is identified in the quotation and its implications explained; as controller, it is for the Customer to accept it or to request an EU-hosted alternative.
Requests to exercise rights (access, rectification, erasure, restriction, portability, objection) are the responsibility of the Customer, as controller.
Pikali assists it in responding by appropriate technical measures: extraction, rectification, anonymisation or deletion of data in the website and its backups. If a request is sent directly to Pikali by a data subject, Pikali does not respond itself and forwards it to the Customer within three working days.
This assistance is included in the maintenance package within the included hours; beyond that, it is quoted before any work is carried out.
Taking into account the nature of the processing and the information available to it, Pikali assists the Customer in complying with its obligations under Articles 32 to 36 GDPR: security, notification of breaches, data protection impact assessment (DPIA) and prior consultation of the supervisory authority.
That assistance covers the technical elements within Pikali's control; it does not substitute Pikali for the Customer in assessing risks, which remains the Customer's responsibility.
Pikali notifies the Customer of any personal data breach without undue delay and no later than forty-eight hours after becoming aware of it, by email to the Customer's contact address, in accordance with Article 33(2) GDPR.
The notification describes, as far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a point of contact.
Pikali documents each breach and provides the Customer with everything needed for its own notification to the supervisory authority and, where applicable, to the data subjects. Notifying the supervisory authority is the Customer's responsibility, as controller.
Pikali maintains a record of the categories of processing activities carried out on behalf of its customers, in accordance with Article 30(2) GDPR.
It makes available to the Customer, on written request, the information necessary to demonstrate compliance with the obligations of this agreement.
The Customer may carry out an audit of compliance with this agreement, itself or through an independent auditor it appoints who is not a competitor of Pikali, once per calendar year, on thirty days' written notice.
The audit may cover only the processing carried out on the Customer's behalf, to the exclusion of any other Pikali activity and of other customers' data.
The audit takes place during business hours, without disrupting operations, and respects the confidentiality of other customers' data and Pikali's trade secrets. Pikali may respond by providing existing documentation or an independent audit report where it covers the requested scope.
Audit costs are borne by the Customer, unless the audit reveals a significant failure attributable to Pikali.
As controller, the Customer:
The Customer indemnifies Pikali against any claim arising from a breach of these obligations.
This agreement takes effect on signature and remains in force for as long as Pikali processes personal data on the Customer's behalf.
On termination, for whatever reason, and at the Customer's written choice, Pikali either returns the data (in the standard format available at Pikali on the date of the request) or deletes it, together with existing copies, unless retention is legally required.
Failing a choice expressed within thirty days, and after a written reminder that has remained unanswered, Pikali deletes the data at the end of the retention period provided for in article 15 of the terms (ninety days). Residual encrypted backups are destroyed at the end of their rotation cycle, with no possibility of reuse.
Pikali certifies the return or deletion in writing at the Customer's request.
Each party bears the consequences of its own failures, under the conditions of Article 82 GDPR. The limitation of liability in article 13.2 of Pikali's terms applies to this agreement, except where the law prohibits it, in particular in cases of gross negligence or wilful misconduct.
Where one party has paid full compensation for a damage, it may claim back from the other the share corresponding to that party's responsibility.
The following sets out exactly what the Customer accepts when signing this agreement online from its customer area.
By entering their first name, surname and role, ticking the acceptance box and confirming, the signatory:
The signature is a simple electronic signature within the meaning of articles 1366 and 1367 of the French Civil Code and of Regulation (EU) No 910/2014 (eIDAS). Recorded at the exact moment of confirmation are: the first name, surname and role entered, the timestamped date and time, the IP address, the browser used, the version of the agreement accepted and the digital fingerprint (SHA-256) of its full text.
Access to the customer area is protected by a personal access key issued to the Customer, who undertakes not to disclose it to any unauthorised third party.
In accordance with article 1356 of the French Civil Code, the parties expressly agree that the electronic records kept by Pikali shall constitute evidence between them as to the identity of the signatory, the date of signature and the content accepted, unless proven otherwise.
The signed agreement is generated as a PDF and remains permanently accessible from the customer area. A confirmation is sent by email immediately upon signature. Pikali retains it, together with its evidence, for ten years.
This agreement is drafted in French. Only the French version has contractual force; any translation is provided for information purposes and the French version prevails in the event of any discrepancy.
It is governed by French law. Failing an amicable resolution within thirty days of a written claim, any dispute falls within the exclusive jurisdiction of the courts of Saverne, France.
These form an integral part of the agreement.
The processing operations below are those entailed by Pikali's usual services. Those that do not correspond to the services actually ordered in the quotation are not carried out.
| Processing | Purpose | Data subjects | Data | Duration |
|---|---|---|---|---|
| Website hosting | Keep the website available and running | Visitors, customers and users of the website | Data entered on the site, technical logs, IP addresses | Term of the hosting contract |
| Backups | Restore the site and its data after an incident | Same | Full copy of files and database | Retention period stated in the quotation |
| Maintenance and support | Fix, update, secure, diagnose | Same, and the Customer's staff | Occasional access to the data needed for diagnosis | For the duration of the work |
| Migration of an existing site | Transfer content and accounts from an existing site to the new one | The Customer's existing customers and accounts | Accounts, orders, histories, files | For the duration of the migration, then deletion of working copies |
| Forms and orders | Deliver messages and orders to the Customer | Visitors, prospects, buyers | Identity, contact details, message content, order details | As set by the Customer |
| Sending the site's emails | Confirmations, notifications, password resets | Recipients of the messages | Email address, message content | Retention period of the sending logs |
Nature of the operations: collection, recording, organisation, storage, consultation, extraction, alteration, transmission to the Customer, erasure.
No special category data (Article 9 GDPR) is processed, save with prior written agreement providing for the corresponding specific measures (article 14).
In accordance with Article 32 GDPR, Pikali implements the following measures:
These measures may evolve with the state of the art, without ever reducing the level of protection.
The Customer authorises the following sub-processors (article 7):
| Sub-processor | Role | Data location |
|---|---|---|
| Hetzner Online GmbH (Germany) | Hosting of servers and backups | European Union (Germany, Finland) |
| LWS — Ligne Web Services (France) | Delivery of the sites' transactional emails | European Union (France) |
| Anthropic (United States) | AI model used by our internal tools to analyse a website's technical structure and to produce code — within the strict scope set out in Schedule B (no personal data of your visitors or customers is submitted to it) | Outside the European Union, covered by European Commission standard contractual clauses |
The following are not sub-processors of Pikali:
Where the Customer asks to keep its current host or imposes a provider, that provider is its own processor: Pikali is not answerable for it.
See also: terms of sale and of service · privacy policy.