Personal Data Processing Agreement
Preamble
Ofelia may act as a Processor for the Processing of data carried out on behalf of the Client, who acts as the Controller within the meaning of Regulation (EU) 2016/679 (the "Regulation"), as set out in the "Personal Data" article of the General Terms and Conditions.
Ofelia has taken note of the Regulation, and in particular of Article 28 thereof concerning the obligations imposed on any Processor acting on behalf of a controller of personal data.
This document sets out Ofelia's commitments to the Client regarding data protection in connection with the provision of the Services.
Definitions
The terms used herein have the meaning set out in the Regulation, including:
"Adequacy Decision" means a decision adopted by the European Commission establishing that a Third Country ensures an adequate level of protection of Personal Data by reason of its domestic legislation or the international commitments it has entered into.
"Data" or "Personal Data" means any information relating to an identified or identifiable natural person (hereinafter referred to as a "data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, Location Data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
"EEA" means the European Economic Area.
"Third Country" means a country that is not a member of the EU or the EEA.
"Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing; where the purposes and means of such Processing are determined by Union or Member State law, the Controller or the specific criteria for its designation may be provided for by Union or Member State law.
"Processor" means the natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Controller.
"Sub-processor" means the sub-processor engaged by the Processor which processes Personal Data on behalf of the Processor.
"Transfer outside the EU" or "Processing outside the EU" or "Transfer" means the transmission of Data from a Member State of the EU or the EEA to a Third Country, or access to Data located within an EU or EEA Member State from a Third Country (e.g., remote access to a database located in Europe).
"Processing of Personal Data" or "Processing" or "Process" means any operation or set of operations performed on Personal Data or sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
"EU" means the European Union.
"Data Breach" or "Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
Description of the Data Processing
The Data Processing carried out by Ofelia as Processor is performed for the purposes set out in Annex A.
Implementation of the Processing
Ofelia undertakes to comply with the Client's written instructions regarding the use that may be made of the Data. The list of Processing operations that Ofelia may carry out on behalf of the Client is attached as Annex A hereto – Register of Processing Activities Carried Out as Processor (Article 30 of the GDPR).
Ofelia will immediately inform the Client if one of its instructions appears likely to constitute a breach of the Regulation.
In the event that the Client considers that a new data processing operation entrusted to Ofelia requires a data protection impact assessment within the meaning of Article 35 of the Regulation, Ofelia will assist the Client in carrying out that impact assessment. This assistance may be subject to billing.
Information of Data Subjects
The Controller informs data subjects of the personal data processing carried out in connection with the Services.
Security Measures
Ofelia undertakes to implement all organizational and technical measures to ensure the physical and logical security of the Data in accordance with the state of the art and the recommendations published by Data Protection Authorities or the competent administrative authorities in matters of information security.
The security and confidentiality measures taken by Ofelia must take into account the most recent technical possibilities and the cost of their implementation, the characteristics of the processing (nature, scope, purpose, etc.), and the risks posed to the rights of data subjects.
The security measures guarantee the integrity, traceability of access, confidentiality, and availability of the Data at all times, and include in particular:
Identification and securing of premises (e.g., locked access, restricted access requiring authorization and authentication);
Logical security (e.g., firewalls, authentication and logging of access to Data, incident simulations);
Securing of Personal Data exchange flows so that they cannot be exploited by an unauthorized third party;
Logging of activity on the IT system;
Protection of IT environments through up-to-date antivirus software (programs and virus signatures);
Implementation of control procedures to ensure the level of security.
Ofelia ensures that only secure means of communication are used to process Personal Data.
Ofelia undertakes to limit access to the Data to only those authorized persons who need to know it.
Ofelia also ensures that persons authorized to process Personal Data for the purposes hereof, including its staff and the staff of any Sub-processors, are bound by an appropriate confidentiality obligation.
Ofelia's Cooperation
Ofelia undertakes to cooperate with the Client by providing it, upon written request, with all information necessary to demonstrate compliance with its obligations, and by allowing it, to that end, to carry out any verification it deems useful, the practical arrangements for which will be agreed upon.
Subsequent Sub-processing
The Client hereby authorizes the subcontracting of all or part of the processing entrusted to Ofelia, and Ofelia undertakes to engage only Sub-processors that comply with the provisions of the GDPR.
The list of Ofelia's current Sub-processors appears in Annex B. An updated version may be provided to the Client at any time upon simple request.
Ofelia guarantees compliance by its Sub-processors with the commitments it itself has made, particularly with regard to any commitments it may have made in terms of security or within standard contractual clauses or any other appropriate safeguard.
Data Transfers
Ofelia does not voluntarily transfer Personal Data outside the territory of the EU or the EEA.
In the event that, for the purposes of providing the Services, Ofelia is required to carry out a Transfer of Data outside the EU or the EEA, such Processing meets the requirements of the Regulation regarding Transfers of Data outside the EU, namely:
The Processing is carried out within a Third Country benefiting from an Adequacy Decision;
The Processing is governed by standard contractual clauses published by the European Commission. In this case, Ofelia and the importing Sub-processor incorporate such standard clauses into the General Terms and Conditions and undertake to ratify them prior to the implementation of the Processing concerned;
The Processing is governed by Binding Corporate Rules (BCRs).
If the exception(s) used for the Transfer were to lapse, Ofelia undertakes to modify the chosen mechanism to replace it with a mechanism capable of governing the intended Transfer.
When Ofelia uses Sub-processors, it ensures that they have implemented appropriate technical and organizational measures to guarantee a level of protection for the transferred Data at least equivalent to that provided herein in the event of a Data Transfer (standard contractual clauses, BCRs, etc.).
Data Protection Officer
Ofelia has appointed a Data Protection Officer: the company Virtual DPO – contact@virtual-dpo.fr.
The Client provides Ofelia, upon signature of the Commercial Proposal, with the identity and contact details of its DPO.
Where the Client has not appointed a DPO, it provides Ofelia with the name and detailed contact information of a relevant contact from whom information about the Processing of Data may be obtained.
Notification in the Event of a Personal Data Breach
In the event of an incident likely to affect the security of Personal Data, of a probable or confirmed breach of the integrity of Personal Data, or of a probable or confirmed violation of the confidentiality rules applied to Personal Data, Ofelia will inform the Client as soon as possible. This information is provided to enable the Client to comply with its notification obligations to the CNIL and to data subjects, pursuant to Article 33 of the GDPR.
Ofelia will carry out the investigations necessary to provide the Client, as they progress, with all useful information on the nature and extent of the potential Data Breach and the corrective measures implemented.
Ofelia will describe the security breach and, if possible, the categories and number of data subjects affected by the breach, as well as the Data concerned.
Ofelia further undertakes to cooperate with the Client and to implement the means necessary to resolve the incident.
Notification of Third-Party Requests for Disclosure
Ofelia undertakes to notify the Client as soon as possible of any request for the transmission or consultation of Data issued by a judicial or administrative authority, before responding to it, unless the applicable law prohibits such notification for reasons of public interest.
Exercise of Rights by Data Subjects
Any natural person whose Data is collected by Ofelia on behalf of the Client has a right of access, restriction, rectification, erasure, and, where applicable, objection to processing or portability of the Personal Data concerning them, in accordance with the applicable regulations.
The rights set out in the preceding paragraph are exercised directly with the Controller.
Accordingly, Ofelia notifies the Client as soon as possible of any request to exercise the aforementioned rights and complies with the Client's instructions, provided they comply with applicable regulations and are communicated to Ofelia in advance.
Data Retention Period / Termination of Subscription
Ofelia retains the Data processed for the duration of the Subscription, unless otherwise requested by the Client or required by a legal obligation imposing a different retention period.
In any event, Ofelia undertakes to delete all Data upon the Client's first request.
Ofelia will provide the Client, upon request, with a certificate attesting to the destruction of the Data.
The Data may be subject to interim archiving for a maximum period corresponding to the applicable statutory limitation period.
Annex A – Register of Processing Activities Carried Out on Behalf of the Client
For all of these processing activities: Legal basis defined by the Client, as Controller.
1. Management of User Identities and Access, and Account Creation by Administrators
Purposes: To enable the Client (Controller) to provision and synchronize its user and administrator database, in order to assign login permissions and enable the creation of user accounts.
Data subjects: Client's Users.
Data processed: Data from the Client's HR system, used to define permissions and create user accounts (potentially: name, email, job title, department, team, country, office, fixed-term/permanent contract, remote location, employee ID, manager (reporting line), etc.). User identifier, login rights (standard user, qualified user, etc.). User connection data to the Solution. Identifiers, role, administrative actions, logs (who did what, and when).
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client.
Retention period: Duration of the contract plus the contractual reversibility period (unless a shorter period is specified by the Client as Controller).
Transfers outside the EU: Yes, Composio in the US.
Sub-processors: AWS; Composio (email and OAuth token only).
2. Ingestion and Indexing of the Knowledge Base (RAG)
Purposes: To ingest, vectorize, and index the content of the client's knowledge base to enable its use by the AI agent.
Data subjects: All individuals whose data is included in the client database imported by the Client via its user interface.
Data processed: Any data included in the client database imported by the Client via its user interface.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client.
Recipients: This data is not intended to be processed by a natural person. Access is possible only in connection with the "Support" processing activity.
Retention period: Duration of the contract plus the contractual reversibility period (unless a shorter period is specified by the Client as Controller).
Transfers outside the EU: Yes, OpenAI and LangSmith in the US (Standard Contractual Clauses).
Sub-processors: AWS, OpenAI, LangSmith.
3. Hosting of the Database
Purposes: To host data imported by the Client on the Solution.
Data subjects: Users and individuals whose data appears in the database imported by the Client.
Data processed: All data included in the database imported by the Client.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client.
Recipients: This data is not intended to be processed by a natural person. Access is possible in connection with the "Management of User Support Requests" processing activity.
Retention period: Duration of the contract plus the contractual reversibility period (unless a shorter period is specified by the Client as Controller).
Transfers outside the EU: Service providers' servers located in Europe.
Sub-processors: AWS.
4. Hosting of Data Related to User Prompts
Purposes: To retain the Prompts and responses exchanged via the Solution in order to ensure conversational continuity, quality monitoring, and traceability.
Data subjects: Client's Users, individuals mentioned in the Prompts and in the responses.
Data processed: User identifier, text content of prompts, text content of responses.
Sensitive data: Not in principle, but Ofelia has no control over the content of Prompts and responses.
Recipients: This data is not intended to be processed by a natural person. Access is possible in connection with the "Management of User Support Requests" processing activity.
Retention period: 12 months.
Transfers outside the EU: Yes, LangSmith in the US.
Sub-processors: LangSmith, AWS.
5. Analysis of Prompts and Formulation of Responses
Purposes: To interpret the user prompt, query the database via the Solution, generate a response, and deliver it in the user's business messaging application.
Data subjects: Client's Users, individuals mentioned in the Prompts or in the client database imported by the Client via its user interface.
Data processed: Text content of prompts, any data included in the client database imported by the Client via its user interface.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client.
Recipients: The User who initiated the Prompt, if the response generated by the Solution includes personal data.
Retention period: Prompts and responses generated are retained for 30 days by OpenAI.
Transfers outside the EU: Yes, OpenAI in the US (Standard Contractual Clauses).
Sub-processors: AWS, OpenAI.
6. Execution of Actions in Third-Party Tools
Purposes: To execute, following validation by the User in their business messaging application, actions in the third-party tools to which they are connected (creating a ticket, sending a message, updating a record, scheduling an event, etc.).
Data subjects: Client's Users, individuals mentioned in or affected by the content of the action (message recipients, ticket assignees, event participants, etc.).
Data processed: User data, actions executed (if they include personal data), data relating to the individuals who are recipients of the action.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client or the nature of the actions to be executed.
Recipients: Any person with access to the result of the action, if it contains personal data.
Retention period: 30 days.
Transfers outside the EU: Yes, Composio in the US (Standard Contractual Clauses).
Sub-processors: Composio.
7. Configuration and Execution of Business Processes
Purposes: To enable the client's process owners to configure business processes, and to execute those processes (orchestration, approvals, automated actions) at the request of Users.
Data subjects: Client's Users, approvers, individuals named in the variables or attachments of the processes (employees, the client's customers, third parties).
Data processed: Data relating to users and approvers. Any data that may be present for the purposes of configuring and executing the processes.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client or the nature of the processes to be executed.
Recipients: Individuals with access to the results, documents, or actions generated by the processes, if they contain personal data.
Retention period: Duration of the contract plus the contractual reversibility period (unless a shorter period is specified by the Client as Controller).
Transfers outside the EU: Service providers' servers located in Europe.
Sub-processors: AWS.
8. Management of User Support Requests
Purposes: To manage user support requests.
Data subjects: Client's Users.
Data processed: Content of the support request submitted from the conversational agent, and the conversational context transmitted. All data that support staff may access to resolve the support request.
Sensitive data: Not in principle, but Ofelia has no control over content imported by the Client.
Recipients: Support team.
Retention period: Duration of the contract, to ensure support follow-up (unless a shorter period is requested by the Client as Controller).
Transfers outside the EU: Service providers' servers located in Europe. Support team members in Canada (Adequacy Decision).
Sub-processors: Zendesk and Jira.
Annex B – List of Authorized Sub-processors