Data Processing Agreement (DPA)

Last updated: 16 May 2026

This agreement governs personal data processing performed by Anonyx SASU (processor within the meaning of GDPR article 28) on behalf of the customer (controller) in the course of using the Anonyx service. It automatically applies upon subscription to a paid plan and is an integral part of the service contract.

1. Purpose of processing

The processor processes personal data transmitted by the controller solely for the purpose of database anonymization in the context of the subscribed service.

2. Nature and purpose

Processing consists of connecting to source databases provided by the customer, reading the data, transforming it according to anonymization rules configured by the customer, and writing to the target database designated by the customer. No full copy is retained by the processor beyond the job execution duration.

3. Data categories

Data categories are determined by the customer through the content of databases connected to the service. The customer is solely responsible for the legality of these processings and for informing the data subjects.

4. Processor obligations

The processor commits to: process data per documented instructions from the controller; ensure confidentiality of authorized persons; implement appropriate technical and organizational measures (GDPR article 32); notify the controller of any breach within 48 hours of discovery; assist the controller in complying with its obligations.

5. Sub-processors

The processor may use sub-processors (host, transactional email) whose up-to-date list is available on request. Any change is subject to prior notification to the customer with possibility of motivated objection.

6. Location and transfers

All processing is performed within the European Union. No transfer outside the EU is made. The processor is not subject to the US CLOUD Act or equivalent extraterritorial provisions.

7. Return and deletion

Upon contract expiration, the processor returns or deletes processed data within 30 days, at the customer's choice. Pseudonymized technical logs are retained for 12 months for security and diagnostic purposes.

8. Audit

The customer may, under conditions set out in the service contract, request an annual audit or have an audit performed by an independent third party. Certification reports (ISO 27001 planned) are made available as they are obtained.