All legal pages

Data processing agreement

The contract governing our processing of personal data on your behalf, under article 28 GDPR.

Last updated: August 3, 2026

1. Parties and purpose

This agreement (the "DPA") is entered into between JIPUP, 60 rue François Ier, 75008 Paris, France (the "Processor"), and the customer subscribing to the service (the "Controller").

It sets out the terms on which the Processor processes, on behalf of the Controller, the personal data held in the Controller's CRM as part of providing the service.

It supplements the general terms of the service, of which it forms an integral part. In case of conflict between the two, this DPA prevails on all matters concerning the processing of personal data.

Acceptance

This DPA is deemed concluded upon subscription to the service or connection of a CRM. A signed copy is available on request at hello@jipup.com.

2. Definitions

"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given to them in article 4 of Regulation (EU) 2016/679 (the "GDPR").

"Customer Data" means the personal data the Processor accesses or processes on behalf of the Controller in connection with the service, as described in Annex 1.

3. Role of each party

The Controller determines the purposes and means of processing Customer Data. It warrants that it has a valid legal basis for that processing, that it has informed data subjects as required by articles 13 and 14 GDPR, and that it is entitled to entrust that data to the Processor.

The Processor processes Customer Data solely to provide the service, on documented instructions from the Controller. It pursues no purposes of its own.

The Processor's processing, for its own purposes, of user account data (identity, email, billing) is carried out in a separate capacity as controller, described in the Privacy policy and excluded from this DPA.

4. Documented instructions

The following constitute documented instructions from the Controller: the general terms, this DPA, the settings made in the service interface (connecting a CRM, enabling an agent, run scope and frequency, approving or rejecting proposed actions), and any written instruction sent to the Processor.

The Processor informs the Controller if it considers that an instruction infringes the GDPR or another applicable data protection provision.

The Processor processes Customer Data outside those instructions only where required by Union or Member State law; in that case it informs the Controller beforehand, unless prohibited by law.

5. Confidentiality

The Processor ensures that persons authorised to process Customer Data are bound by a contractual or statutory duty of confidentiality and are informed of the requirements applicable to that processing.

Access to Customer Data is limited to those who need it to operate the service or handle a support request.

6. Security of processing

The Processor implements the appropriate technical and organisational measures required by article 32 GDPR. Those measures are described in Annex 2 and set out, in their current state, on the Security page.

Those measures may evolve, provided the overall level of security is not reduced.

7. Sub-processing

The Controller gives general authorisation for the Processor to engage sub-processors to deliver the service. The current list constitutes Annex 3 to this DPA.

Technical providers are named there and published on the Subprocessors page. Data enrichment providers appear as a category; their named list, with their location, is provided to the Controller on request at hello@jipup.com, under a confidentiality undertaking, within fifteen (15) days. That reservation, justified by trade secrecy, restricts neither the information owed to the Controller nor its right to object as set out below.

The Processor notifies active account holders by email before adding or replacing a sub-processor with access to Customer Data. The Controller then has thirty (30) days to object in writing on reasonable data protection grounds. Failing agreement, it may terminate the affected service without penalty.

The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Controller for their performance.

8. Assistance with data subject rights

Taking into account the nature of the processing, the Processor makes available to the Controller the interface features needed to access, rectify and delete the data processed.

Where a data subject contacts the Processor directly to exercise rights over Customer Data, the Processor does not respond on its own initiative: it forwards the request to the Controller without undue delay and assists it, as far as possible, in responding.

9. Compliance assistance

The Processor assists the Controller, taking into account the nature of the processing and the information available to it, in complying with articles 32 to 36 GDPR: security of processing, breach notification, impact assessment and prior consultation.

That assistance is provided at no additional cost as far as it falls within the Processor's legal obligations. A request going significantly beyond that scope may be charged at a reasonable rate, communicated in advance.

10. Personal data breach

The Processor notifies the Controller of any personal data breach affecting Customer Data as soon as possible after becoming aware of it, and in any event within a timeframe allowing the Controller to meet the 72-hour deadline in article 33 GDPR.

The notification describes, as far as the available information allows: the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences, and the measures taken or proposed to address it.

11. Transfers outside the European Union

Customer Data is hosted within the European Union. Some sub-processors, identified as such in Annex 3, are established outside the European Union or may access data from there for operational and support purposes.

Those transfers are governed by the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, supplemented where relevant by additional measures or by an adequacy mechanism applicable to the sub-processor concerned.

12. Documentation and audit

The Processor makes available to the Controller the information needed to demonstrate compliance with article 28 GDPR, including the documents published on the Security and Subprocessors pages, and answers to reasonable security questionnaires.

The Controller may carry out an audit, itself or through an independent auditor bound by confidentiality, limited to one audit per twelve (12) month period, save in the event of a proven security incident or a request from a supervisory authority. The audit is subject to thirty (30) days' written notice, takes place during business hours, does not disrupt operation of the service and gives access to no other customer's data.

13. Data on termination

On disconnection of the CRM, access tokens are deleted immediately and all access to CRM data ceases.

On termination of the contract, the Processor deletes Customer Data within 30 days, unless a written request for return is made before that period expires. Return is made in a structured, commonly used format.

Only data whose retention is required by a legal obligation, in particular accounting obligations, is kept beyond that period, for the duration set by that obligation and with no other use. Backups are purged according to their rotation cycle.

14. Liability and governing law

Each party is liable for damage caused by processing that infringes the GDPR under the conditions set out in article 82 thereof. The limitations of liability stated in the general terms apply to this DPA, to the extent permitted by applicable law.

This DPA is governed by French law. Any dispute falls within the jurisdiction of the French courts, save where a mandatory provision states otherwise.

15. Annex 1 — Description of the processing

Subject matter
Analysis, cleaning, deduplication, enrichment and updating of the records held in the Controller's CRM.
Nature of the operations
Reading, analysing, comparing, retaining metrics and examples, proposing changes, writing after approval, deleting on instruction.
Purpose
Provision of the subscribed service: improving the data quality of the Controller's CRM.
Duration
The term of the contract, plus the retention periods set out in section 13.
Categories of data subjects
Contacts, prospects, customers and business counterparts recorded in the Controller's CRM; service users designated by the Controller.
Categories of data
Identification data (first name, last name), business contact details (email, phone), professional data (job title, company, tenure), commercial relationship data (history, record owner, sales stage), technical record identifiers.
Special categories
None. The service is not intended for the processing of data covered by article 9 GDPR, nor data relating to criminal convictions. The Controller undertakes not to submit any.

16. Annex 2 — Security measures

  • Encryption of communications in transit (TLS); the service is reachable over HTTPS only.
  • Application data hosted within the European Union, with a provider subject to the GDPR.
  • CRM access by delegated authorisation (OAuth 2.0), without holding the Controller's credentials, revocable by the Controller at any time.
  • Logical isolation of workspaces: every request is bound to the authenticated workspace.
  • Passwords stored as a non-reversible cryptographic hash (bcrypt).
  • Production access limited to people with an operational need, bound by a duty of confidentiality.
  • Logging of access and of operations performed on data.
  • Human approval of changes proposed by agents before they are written to the CRM.
  • Minimisation: retention of aggregate metrics and a limited volume of real examples, with no full replication of the CRM.

The current state of those measures, including work in progress, is published on the Security page.

17. Annex 3 — Sub-processors

The list of authorised sub-processors, with their role, the data involved and their location, is kept up to date on the Subprocessors page. It forms an integral part of this DPA.

Data enrichment providers appear there as a category, with their number, the nature of the data sent and their location. Their named list is provided on request under the terms of section 7.