Legal
Template being finalised: the passages in brackets will be completed, and the whole document reviewed by a legal professional before opening to the public.
This is a translation of the French text, provided for convenience. In case of any difference, the French version prevails.
Data processing agreement (DPA)
This agreement applies when you use Elpis to process personal data of your customers, prospects or visitors (article 28 of the GDPR). It is part of the terms of use.
1. Roles
- You are the controller: you decide why and how this data is used.
- Elpis ([TO BE COMPLETED: company name]) is the processor: we process this data only to provide the Service and on your documented instructions (your settings, your approvals).
2. Data and data subjects
- Data subjects: your prospects, customers, website visitors, e-mail correspondents.
- Data: identity and business contact details, content of the e-mails exchanged, sign-ups on your website’s forms, purchase history (sent by your Stripe account).
- Duration: the lifetime of your account, or until you delete the data, the business or the account.
3. Our commitments
- process the data only on your instructions, and tell you if an instruction seems to us to breach the GDPR;
- ensure confidentiality: access limited to the people who need it, bound by confidentiality;
- secure the data: encryption in transit, isolation of each account’s data at database level (Row Level Security), audit log, keys and secrets kept out of the code;
- use only the processors listed in the privacy policy, and inform you of any change;
- help you answer requests from data subjects (contact export as CSV, deletion, unsubscribe list honoured everywhere);
- notify you of any data breach concerning you without undue delay, and at the latest within 48 hours of becoming aware of it;
- delete the data at the end of the Service, after letting you export it.
4. Your commitments
- have a lawful basis for each contact you import or prospect;
- inform the data subjects;
- follow the rules on prospecting (B2B: a message related to the person’s business and an unsubscribe link; B2C: prior consent).
5. Transfers outside the European Union
Some processors are located in the United States. Transfers are covered by the European Commission’s standard contractual clauses. [TO BE COMPLETED: list of safeguards per provider.]
6. Audit
On written and reasonable request, we make available the information needed to demonstrate compliance with these obligations. [TO BE COMPLETED: terms.]
Last updated: September 30, 2026