Data controller
The Customer. Définit les finalités et les moyens du traitement. Détient le pouvoir décisionnel sur les données stockées dans le coffre : choix des secrets, des destinataires, de la politique d'accès et de la durée de conservation.
Public data processing agreement template compliant with the GDPR Art. 28. For formal contractual use, request the signed version from your Controller.
Before going into the detail of the twelve articles, here is the allocation of responsibilities within the meaning of Regulation (EU) 2016/679. This structure is the foundation of all the obligations that follow.
The Customer. Définit les finalités et les moyens du traitement. Détient le pouvoir décisionnel sur les données stockées dans le coffre : choix des secrets, des destinataires, de la politique d'accès et de la durée de conservation.
ARDNTECH EI. Exécute le traitement pour le compte du Client, dans le strict respect de ses instructions documentées et dans les limites de l'objet précisé à l'article 2 du présent DPA.
Your users. Membres des organisations du Client et destinataires de partages de secrets. Bénéficient des droits Art. 15 à 22 RGPD, outillés techniquement par ARDNTECH.
This Processing Agreement (hereinafter the "DPA") supplements the ARDNTECH Terms of Use and details the respective obligations of the Controller (the Customer) and the Processor (the Publisher of ARDNTECH) within the meaning of Regulation (EU) 2016/679 (GDPR).
Processor: ARDNTECH, registered with the RCS under no. 913308706, with registered office at 24 rue de la Glau 08700 Gespunsart. DPO: dpo@aegirex.eu.
Controller: the legal entity or natural person subscribing to ARDNTECH and using the service to store and share digital secrets.
ARDNTECH is an end-to-end encrypted (zero-knowledge) secrets storage service. The Processor processes data on behalf of the Controller solely for the following purposes:
The Processor processes the following categories of data, and only these:
| Category | Data concerned | Legal basis (art. 6 GDPR) |
|---|---|---|
| User account | Email address, Argon2id hash of the master password, OpenPGP public key, optional name. | Performance of the contract (art. 6.1.b) |
| Stored secrets | Opaque OpenPGP blobs (encrypted). The Processor cannot read them. | Performance of the contract (art. 6.1.b) |
| Audit journals | Sign-in events, secret create/read/share/delete, IP, user-agent, HMAC signatures. | Legitimate interest in security (art. 6.1.f) |
| Billing | Business name, company number, address, billing email, payment history. | Legal accounting obligation (art. 6.1.c) |
The data subjects are: (a) the users authorised by the Controller to access ARDNTECH; (b) where applicable, the recipients of secret shares initiated by these users; (c) the contacts identified on invoices issued to the Controller.
Data is kept for the following periods:
The Controller expressly authorises the Processor to use the following sub-processors:
| Sub-processor | Purpose | Processing country |
|---|---|---|
| Brevo SAS | Transactional email delivery (notifications, email verification). | FR |
| Stancer SAS | Online payment processing. | FR |
| Host (to be specified in the contract) | Hosting of the application infrastructure and databases. | FR / EU |
Any change of sub-processor is notified to the Controller with a minimum 30-day notice, allowing them to exercise a reasoned right to object.
The Processor implements the following measures (indicative non-exhaustive list):
In accordance with article 33 of the GDPR, the Processor notifies the Controller of any personal data breach within 48 hours of becoming aware of it. The notification specifies the nature, scope, likely consequences and measures taken or envisaged.
The Processor provides the Controller with the tools to respond to data subject requests (right of access, rectification, erasure, portability, objection) directly from the user interface. For any request not covered by the interface, the Processor assists the Controller within 5 business days.
At the end of the contract (termination, non-renewal), the Controller has 30 days to export its data via the native portability export feature. After this period, all the Controller's data is irreversibly deleted from production databases. Encrypted backups are purged within an additional 90 days (standard retention rotation).
No data transfer to a third country outside the EU/EEA is carried out. The Processor does not use providers subject to the US CLOUD Act, FISA Section 702, or equivalent jurisdictions. If such a transfer were technically necessary in the future, the Processor would have to obtain the prior express agreement of the Controller.
The Controller may appoint an independent auditor (at its own expense) to verify the Processor's compliance with the commitments of this DPA, subject to reasonable 15-day notice and a confidentiality undertaking. The Processor also provides on request any documentation demonstrating its compliance (processing register, pentest reports, etc.). For any request: dpo@aegirex.eu.
This template constitutes a contractual commitment when annexed to a Business or Enterprise purchase order. For a digitally signed version, named and tailored to your sub-processors and your jurisdiction, send your request to your Controller or directly to the DPO of ARDNTECH EI.