This Data Processing Addendum ("DPA") forms part of the agreement between NAVIGATING FRANCE ("Processor") and the customer accepting these terms ("Controller") for use of the Navigating France service. It governs processing of personal data carried out by the Processor on behalf of the Controller under Article 28 GDPR.
1. Subject matter and duration
Subject matter: provision of the Navigating France platform. Duration: for as long as the Processor processes personal data on behalf of the Controller.
2. Nature and purpose
Hosting, storage, retrieval, structuring, transmission, and deletion of personal data the Controller submits to the Service to obtain the contracted features (checklist, document storage, translations, guided assistant).
3. Types of data and categories of data subjects
- Data subjects: the Controller's users, family members, and any third parties whose data the Controller chooses to upload.
- Categories: identification data, contact data, civil status, immigration status, document content uploaded by the Controller, free-text inputs to the Navigating France assistant.
4. Obligations of the Processor
- Process personal data only on documented instructions from the Controller.
- Ensure persons authorised to process data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Art. 32 GDPR).
- Assist the Controller in fulfilling data subject requests and Art. 32–36 obligations.
- Notify the Controller without undue delay of any personal data breach.
- On termination, return or delete personal data at the Controller's choice.
5. Sub-processors
The Controller authorises the use of the sub-processors listed in the Privacy Policy. The Processor remains liable for their performance. The Processor will give 30 days' notice of any intended change and the Controller may object on reasonable data-protection grounds.
6. International transfers
Where personal data is transferred outside the EU/EEA, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and any supplementary measures necessary in light of the destination country.
7. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based access, MFA on administrative accounts, least-privilege service tokens.
- Row-level security on customer data; audit logging.
- Regular dependency and security scanning, vulnerability response process.
- Backups with defined RPO/RTO, tested restore.
8. Audit
On reasonable prior notice, the Controller may audit the Processor's compliance with this DPA once per year, or following a personal data breach. Audits not to disrupt operations and subject to confidentiality.
9. Liability and governing law
Liability under this DPA follows the underlying Terms. This DPA is governed by French law.
For a countersigned copy on company letterhead, write to hello@navigatingfrance.com.