Legal

Data Processing Agreement (DPA)

Last updated: 11/10/2026

In the event of any discrepancy between the French and English versions of this document, the French version shall prevail.

This agreement, based on the example of processor clauses published by the CNIL, governs the processing of personal data carried out by Switch Compagnie (the "processor") on behalf of its clients (the "controller") as part of hosting, e-mail and technical services. It supplements the Terms and the accepted quote or contract, and must be concluded in writing with each client concerned.

This agreement forms an integral part of the general terms of sale and service. A signed copy, identifying the parties and with completed annexes, is concluded with each client concerned; in the event of any discrepancy, the signed copy prevails.

1. Purpose

These clauses set out the conditions under which the processor undertakes to carry out, on behalf of the controller, the personal data processing operations described below, in accordance with Regulation (EU) 2016/679 (GDPR) and French Law No. 78-17 of 6 January 1978.

2. Description of the processing

Nature of operations
Hosting, storage, backup, routing and receipt of e-mail, technical maintenance.
Purpose
Provision of the services subscribed to by the controller.
Categories of data
Data determined by the controller: in particular identity, contact details, e-mail content and hosted files, connection data.
Data subjects
Users, customers, members, employees or correspondents of the controller.
Retention
Duration of the service contract, followed by return and deletion as set out in section 10.
Location
Servers located in France, at Switch Compagnie's registered office address (T-Tron infrastructure, a sub-project of the association).

3. Processor obligations

  • - Process the data only for the purpose(s) described and on documented instructions from the controller, including with regard to transfers of data to a country outside the European Union or to an international organisation; immediately inform the controller if an instruction appears to infringe the GDPR or any other data protection provision.
  • - If the processor is required to process or transfer data under Union or French law, it informs the controller before processing, unless that law prohibits such information on important grounds of public interest.
  • - Ensure the confidentiality of the data and ensure that persons authorised to process it (authorised members and interns) are bound by confidentiality and receive the necessary awareness training.
  • - Respect the confidentiality of correspondence: the processor and persons acting under its authority do not access the content of the controller's e-mails and files, except on the controller's documented instructions or where strictly necessary for the security or maintenance of the service, to the extent necessary and with traceability.
  • - Take into account the principles of data protection by design and by default.
  • - Keep a record of processing activities carried out on behalf of the controller (Article 30(2) GDPR).

4. Sub-processing

The processor may engage a sub-processor to carry out specific processing activities. It informs the controller in advance and in writing of any intended change (addition or replacement); the controller has 30 days to object. The sub-processor is bound by the same obligations as those in this agreement; the initial processor remains fully liable for their performance.

Sub-processors as of the date of this document: Cloudflare, Inc. (domain DNS servers, United States). The up-to-date list is annexed to the signed copy; any addition or replacement is notified in accordance with this article.

Transfers outside the European Union: no hosted data is transferred outside the European Union without documented instructions from the controller. Where a sub-processor is established outside the Union (in particular Cloudflare, Inc., for DNS resolution), the transfer is governed by an adequacy decision (EU-US Data Privacy Framework, if the provider is certified) or, failing that, by the European Commission's standard contractual clauses.

5. Information and data subject rights

The controller is responsible for informing data subjects. The processor assists the controller, as far as possible, in responding to requests to exercise rights (access, rectification, erasure, objection, restriction, portability); if it receives such a request directly, it forwards it to the controller without delay.

6. Personal data breach notification

The processor notifies the controller of any personal data breach without undue delay after becoming aware of it, and no later than 48 hours, by e-mail to the address designated by the controller, with all useful documentation enabling the controller to notify, where necessary, the CNIL (Article 33 GDPR) and the data subjects (Article 34).

7. Assistance to the controller

The processor assists the controller in carrying out data protection impact assessments and in prior consultation of the CNIL, where applicable.

8. Security measures

  • - Encryption of communications in transit (TLS).
  • - Access to data limited to authorised members, authentication and access logging.
  • - Hosting on servers located in France.
  • - The applicable backup, encryption and incident management measures are described in the “Security measures” annex to the signed copy.

9. Data protection officer or contact

Data protection contact person: Sulivan MICHEL, president of the association. Contact: contact@switchcompagnie.eu.

10. Fate of the data

At the end of the contract, the processor, at the controller's choice, returns the data in a common format and then destroys all copies, unless there is a legal obligation to retain them, within the period set out in the signed copy, and confirms the destruction in writing.

11. Documentation and audits

The processor makes available to the controller the documentation necessary to demonstrate compliance with its obligations and allows audits, including inspections, by the controller or an auditor it has appointed, subject to reasonable notice.

12. Controller obligations

  • - Provide the processor with the data and document any instruction in writing.
  • - Ensure, beforehand and throughout the processing, compliance with GDPR obligations.
  • - Supervise the processing, including through audits.

13. Parties, term and signature

The agreement is concluded between Switch Compagnie, a French non-profit association (RNA W172010376, SIREN 917 532 293), whose registered office is at 313A Rue de la Forêt, 17700 Saint-Georges-du-Bois, France, represented by its president, as processor, and each client identified in the signed copy, as controller.

It takes effect on the date of signature or electronic acceptance of the copy, for the term of the services contract, and survives it for the return, destruction and confidentiality obligations.