🌐 Deutsch
Kontakt Anmelden FoxPlan testen

Data Processing Agreement (DPA)

This DPA is an integral part of the service agreement between FoxPlan SAS and the client. It sets out how FoxPlan processes personal data as a processor, in accordance with Article 28 of the GDPR.

Last updated: 20 October 2025

In brief

  • GDPR-compliant processing: the client is controller (or processor), FoxPlan acts as processor (or sub-processor).
  • Hosting in France with Scaleway; no transfer outside the EU without safeguards.
  • Encryption in transit and at rest; strict access control; logging; backups and high availability.
  • Reversibility: return or deletion of data within 30 days (JSON); deletion certificate on request.
  • Sub-processors bound to equivalent security and confidentiality; FoxPlan remains fully responsible.
  • Incidents: the client is notified without undue delay and within 24 hours; assistance with the CNIL notification within 72 hours.
  • Audits: once a year, on one month notice, by an independent non-competing auditor.
  • Data ownership remains with the client; no resale and no marketing use.

1. Purpose and scope

This data processing agreement (the “DPA”) forms part of the service contract (the “Agreement”) between FoxPlan SAS (“FoxPlan”) and the client entity (the “Client”).

The DPA sets the terms under which FoxPlan processes personal data strictly for the performance of the Agreement, on behalf of the Client, in accordance with the GDPR (EU 2016/679) and applicable data protection laws.

It applies where the Client acts as controller (or processor) and FoxPlan acts as processor (or sub-processor). Processing activities for which FoxPlan acts as controller are governed by the FoxPlan privacy policy.

2. Definitions

Terms have the meanings set out in Article 4 of the GDPR, including “personal data”, “processing”, “controller”, “processor”, “sub-processor” and “personal data breach”.

3. Roles and responsibilities

FoxPlan as processor: FoxPlan processes personal data only on the documented instructions of the Client and strictly for the purposes of the Agreement. No use for marketing, profiling or resale.

Client as controller (or processor): the Client determines the purposes and means of the processing, ensures its lawfulness and the information given to data subjects, and provides FoxPlan with instructions that comply with the GDPR.

4. Nature, purpose and categories of data

Purpose: provision and operation of the FoxPlan service; hosting, backup and administration; account and access management; support and maintenance; anonymized analytics to improve service quality.

Categories of data: identification data (name, email), credentials, usage logs, technical metadata, and the content stored by users within the service.

Data subjects: the Client end-users, employees, contractors and authorized partners.

Duration: the term of the Agreement, plus what is required for reversibility or legal retention.

5. Location and hosting

Data is hosted in France, in data centres operated by Scaleway SAS. No transfer outside the European Union is performed without adequate safeguards, such as EU standard contractual clauses or an adequacy decision. Processing by Scaleway is governed by the Scaleway data processing agreement.

6. Security measures

FoxPlan implements appropriate technical and organizational measures to ensure confidentiality, integrity and availability, including:

  • Encryption in transit and at rest (TLS 1.2+ / TLS 1.3; AES-256 or equivalent).
  • Strict access control on a least-privilege basis, secure authentication and access logging.
  • Environment isolation and network segmentation; WAF and intrusion monitoring.
  • Secure software lifecycle, patching and vulnerability management.
  • Regular backups with tested restores, and business continuity / disaster recovery procedures.
  • Production database access limited to authorized personnel under strong authentication and logging; encrypted backups stored in secure Scaleway facilities in France.

7. Backups and high availability

  • Full daily backups of client data, retained according to internal policy and legal requirements.
  • Replication and high-availability architecture to minimize the risk of data loss.
  • Documented restore procedures, tested periodically.

8. Sub-processors

FoxPlan may engage sub-processors (hosting, backup, support, messaging). FoxPlan imposes data protection obligations equivalent to this DPA and remains fully responsible for their performance.

An up-to-date list of sub-processors is available on request at dpo@fox-plan.com.

9. Assistance with data subject rights

Taking into account the nature of the processing, FoxPlan assists the Client, insofar as possible, in fulfilling requests from data subjects (access, rectification, erasure, restriction, portability, objection) and in meeting its GDPR obligations, including support for data protection impact assessments where applicable.

10. Incident and breach notification

In the event of a personal data breach, FoxPlan notifies the Client without undue delay and within 24 hours of becoming aware of it, providing the known details: nature of the breach, categories and volume of data, likely consequences and measures taken.

FoxPlan cooperates with the Client for any required regulatory notification, including to the French CNIL within 72 hours where applicable, and for communications to data subjects if necessary.

11. Audits

The Client may conduct, or mandate, one security audit per year on one month prior written notice, through an independent, non-competing auditor, during normal business hours, without disrupting operations and subject to the FoxPlan security and confidentiality policies. Critical vulnerabilities are remediated without undue delay.

12. Reversibility: return and deletion

Upon termination of the Agreement, and at the Client option, FoxPlan returns or deletes all client personal data within 30 days, except where legal retention applies.

  • Standard export format: JSON, at no additional cost.
  • Additional extraction or assistance services are available on request and quoted separately.
  • Deletion is confirmed by a written deletion certificate on request.

13. Data ownership

The Client remains the sole owner of the personal data processed through the FoxPlan service. FoxPlan acquires no rights over that data and does not use it for any purpose other than performing the Agreement.

14. Liability

Each party is liable for its own breaches of this DPA and of applicable data protection law. FoxPlan liability is limited to direct damages proven to result from its breach of this DPA or of its GDPR obligations; FoxPlan is not liable for indirect or consequential damages, nor for damages arising from unlawful instructions given by the Client or from misuse of the services.

15. Governing law and jurisdiction

This DPA is governed by French law. Any dispute is subject to the exclusive jurisdiction of the courts of Versailles (France), without prejudice to mandatory consumer or data protection forum rules where applicable.

16. Contact and data protection officer

FoxPlan SAS, 4 Place Maurice Berteaux, 78400 Chatou, France. DPO and privacy contact: dpo@fox-plan.com. This DPA applies automatically to all clients using the FoxPlan services and is an integral part of the master service agreement.

Sie vertrauen uns