Ukraine solidarity. Service offered free to Ukrainian businesses for as long as the war lasts. Request free access
DPA GDPR · Art. 28

Data Processing Agreement

Public data processing agreement template compliant with the GDPR Art. 28. For formal contractual use, request the signed version from your Controller.

 Template - last updated - 01/08/2026 Native GDPR Zero-knowledge Hosting in France

Preamble

Overview

The three GDPR rolesat a glance.

Before going into the detail of the twelve articles, here is the allocation of responsibilities within the meaning of Regulation (EU) 2016/679. This structure is the foundation of all the obligations that follow.

Data controller

The Customer. Définit les finalités et les moyens du traitement. Détient le pouvoir décisionnel sur les données stockées dans le coffre : choix des secrets, des destinataires, de la politique d'accès et de la durée de conservation.

Data processor

ARDNTECH EI. Exécute le traitement pour le compte du Client, dans le strict respect de ses instructions documentées et dans les limites de l'objet précisé à l'article 2 du présent DPA.

Data subjects

Your users. Membres des organisations du Client et destinataires de partages de secrets. Bénéficient des droits Art. 15 à 22 RGPD, outillés techniquement par ARDNTECH.

Article 1

1. Identification of the parties

This Processing Agreement (hereinafter the "DPA") supplements the ARDNTECH Terms of Use and details the respective obligations of the Controller (the Customer) and the Processor (the Publisher of ARDNTECH) within the meaning of Regulation (EU) 2016/679 (GDPR).

Processor: ARDNTECH, registered with the RCS under no. 913308706, with registered office at 24 rue de la Glau 08700 Gespunsart. DPO: dpo@aegirex.eu.

Controller: the legal entity or natural person subscribing to ARDNTECH and using the service to store and share digital secrets.

Article 2

2. Subject matter and purposes of processing

ARDNTECH is an end-to-end encrypted (zero-knowledge) secrets storage service. The Processor processes data on behalf of the Controller solely for the following purposes:

  • Storage of opaque cryptographic blobs (secrets encrypted with the Controller's public key, never decryptable on the server side).
  • Authentication, account management, organisation membership management.
  • Issuance of operational notifications (opt-in HIBP leak alert, member invitation, audit alert).
Article 3

3. Categories of data processed

The Processor processes the following categories of data, and only these:

Category Data concerned Legal basis (art. 6 GDPR)
User account Email address, Argon2id hash of the master password, OpenPGP public key, optional name. Performance of the contract (art. 6.1.b)
Stored secrets Opaque OpenPGP blobs (encrypted). The Processor cannot read them. Performance of the contract (art. 6.1.b)
Audit journals Sign-in events, secret create/read/share/delete, IP, user-agent, HMAC signatures. Legitimate interest in security (art. 6.1.f)
Billing Business name, company number, address, billing email, payment history. Legal accounting obligation (art. 6.1.c)
Article 4

4. Categories of data subjects

The data subjects are: (a) the users authorised by the Controller to access ARDNTECH; (b) where applicable, the recipients of secret shares initiated by these users; (c) the contacts identified on invoices issued to the Controller.

Article 5

5. Retention periods

Data is kept for the following periods:

  • User account: as long as the account is active, deleted within 30 days of explicit request or termination.
  • Secrets: as long as the user does not delete them. Irreversible and immediate deletion on user action.
  • Audit journals: 13 months (CNIL recommended duration for traceability), then anonymised archiving.
  • Billing data: 10 years (legal obligation, French Commercial Code L123-22).
  • Technical application logs (outside audit): 30-day rolling window, automatic IP anonymisation beyond.
Article 6

6. Authorised sub-processors

The Controller expressly authorises the Processor to use the following sub-processors:

Sub-processor Purpose Processing country
Brevo SAS Transactional email delivery (notifications, email verification). FR
Stancer SAS Online payment processing. FR
Host (to be specified in the contract) Hosting of the application infrastructure and databases. FR / EU

Any change of sub-processor is notified to the Controller with a minimum 30-day notice, allowing them to exercise a reasoned right to object.

Article 7

7. Technical and organisational security measures

The Processor implements the following measures (indicative non-exhaustive list):

  • End-to-end encryption of secrets (OpenPGP.js v6, ECC curve25519, AES-256-GCM SEIPDv2).
  • Key derivation from the master password via Argon2id (5 passes, 256 MiB, parallelism 4).
  • Cryptographic HMAC-SHA-256 audit chain, verifiable, O(1) detection of any tampering.
  • TLS 1.3 mandatory in transit, HSTS preload, Let's Encrypt or Buypass certificates renewed automatically.
  • Two-factor authentication (TOTP RFC 6238 + email) with encrypted recovery codes.
  • Daily encrypted backups, retained 30 days, restoration tested quarterly.
  • Annual penetration test by a PASSI (at the opening of paid plans).
Article 8

8. Personal data breach notification

In accordance with article 33 of the GDPR, the Processor notifies the Controller of any personal data breach within 48 hours of becoming aware of it. The notification specifies the nature, scope, likely consequences and measures taken or envisaged.

Article 9

9. Data subject rights

The Processor provides the Controller with the tools to respond to data subject requests (right of access, rectification, erasure, portability, objection) directly from the user interface. For any request not covered by the interface, the Processor assists the Controller within 5 business days.

Article 10

10. Return / deletion at end of contract

At the end of the contract (termination, non-renewal), the Controller has 30 days to export its data via the native portability export feature. After this period, all the Controller's data is irreversibly deleted from production databases. Encrypted backups are purged within an additional 90 days (standard retention rotation).

Article 11

11. Transfers outside the European Union

No data transfer to a third country outside the EU/EEA is carried out. The Processor does not use providers subject to the US CLOUD Act, FISA Section 702, or equivalent jurisdictions. If such a transfer were technically necessary in the future, the Processor would have to obtain the prior express agreement of the Controller.

Article 12

12. Audit and cooperation

The Controller may appoint an independent auditor (at its own expense) to verify the Processor's compliance with the commitments of this DPA, subject to reasonable 15-day notice and a confidentiality undertaking. The Processor also provides on request any documentation demonstrating its compliance (processing register, pentest reports, etc.). For any request: dpo@aegirex.eu.

Get started

Need the version
signed and personalised?

This template constitutes a contractual commitment when annexed to a Business or Enterprise purchase order. For a digitally signed version, named and tailored to your sub-processors and your jurisdiction, send your request to your Controller or directly to the DPO of ARDNTECH EI.

Native GDPR, Art. 28 compliant
Zero-knowledge: the publisher does not read your secrets
Hosting in France, French jurisdiction
AGPL-3.0 code, auditable end to end
EU sub-processors only, listed in Art. 6