Data processing agreement

Data processing agreement — DPA.

This draft agreement specifies the data processing carried out by NOZZL SAS on behalf of the customer organization. It must be completed and approved alongside the contract and processing appendices before it is finalized.

Parties, purpose, and duration

The customer organization determines the purposes of the training. The publisher acts as a processor to provide the ordered features. The customer’s identity, reference contract, effective date, and duration must be entered in the accepted agreement.

The processing operations include receiving and storing data, extracting documents, voice simulation, transcription, scenario generation, training analysis, and making results available. These operations take place during the service and afterward according to the agreed rules for returning and deleting data.

Individuals and data

The individuals concerned are users, administrators, and members of customer teams. The categories of data include professional identifiers, roles, training content, transcripts, results, authorized documents, and security logs.

The customer agrees to provide only the data necessary. Health data, sensitive files, and actual information about prospects must be excluded when a fictional example can achieve the objective. The application does not retain any audio files.

Instructions and confidentiality

Processing must be limited to the customer’s documented instructions and the operations necessary for the agreed service. Anyone authorized to access the data must be bound by an appropriate confidentiality obligation.

Any instruction that may violate applicable rules must be reported to the customer. Reuse for a separate purpose of the publisher’s own cannot be assumed solely because data is hosted or AI is used.

Technical and organizational measures

The safeguards include separation of organizations, role-based permissions, authentication and available two-factor authentication, and tracking of security actions. Production communications use encrypted channels.

The security appendix must specify the hosting settings, providers’ encryption at rest, administrative access, backups, tests, and incident processes actually deployed. No certification, guaranteed availability, or future measure should be presented as already verified.

Subprocessors and transfers

The online list identifies the technical service providers engaged or planned. Actual use, data categories, countries, and safeguards must be documented in the accepted appendix.

The process for notifying changes, the objection period, and the consequences of a reasoned objection remain to be agreed. Any transfer outside the European Economic Area must be covered by the applicable mechanism and, where required, the necessary assessment and supplementary safeguards. EU hosting alone does not rule out transfers.

Assistance and data breaches

The publisher assists the customer with rights requests, security documentation, and analyses necessary for its processing, within the limits of the information and features available to it.

A data breach affecting the customer must be reported to them without undue delay after it becomes known, with the information available at the time and further details as the investigation progresses. The contacts, alert channel, and allocation of tasks must be specified; no fixed contractual deadline has been added to this draft.

End of service, evidence, and audit

The choice between returning and deleting data, the export format, schedule, and handling of backups must be agreed. Legal retention obligations are identified separately.

The customer must be able to obtain the information necessary to assess the processor’s obligations. Audit procedures, confidentiality, scope, and any costs must be finalized. This online version is a basis for discussion, not evidence that an audit or legal review has already taken place.

Sources and references

Data processing agreement | Clozing