Skip to main content

Data processing agreement (GDPR Art. 28)

Last updated: September 2026

This translation is provided for convenience. Only the French version is legally binding.

This document constitutes the data processing clauses within the meaning of Article 28.3 of Regulation (EU) 2016/679 (GDPR), applicable between the IT service provider (MSP) using the service, acting as controller, and Vigicap, acting as processor, for the data of the SME clients processed in the platform. It supplements the terms of use and the privacy policy.

1. Parties and allocation of roles

The controller is the MSP holding the account: it is the MSP who decides which data of its SME clients is entered into the platform, and the purposes and means of that processing. The processor is Vigicap, which processes that data on behalf of the MSP and solely on its instructions.

This allocation does not cover the whole service. For the data of the MSP's own account — names, email addresses, password hashes (argon2), roles, sign-in and audit logs of its users — Vigicap is the controller and answers for it directly, as stated in the privacy policy. These clauses apply only to the processing scope described in article 3.

The processor is NEXTLAB, the publisher of Vigicap. Its corporate name, registration number, registered office and intra-EU VAT number appear in the legal notice, which forms an integral part of this agreement.

2. Subject matter, nature and purpose of the processing

The subject matter of the processing is the provision of the Vigicap platform: white-label cyber governance enabling the MSP to run an ANSSI ReCyF assessment, keep a compliance register, produce action plans, quotes and white-label reports, and record incidents for its SME clients.

The nature of the operations carried out comprises the collection, recording, structuring, storage, consultation, use, modification, extraction (for export and document generation purposes) and erasure of the data.

Duration: the processing lasts for as long as the MSP account is active. It ends upon termination, subject to the return or deletion operations provided for in article 11.

3. Categories of data and data subjects

Data subjects: the employees and contacts of the MSP's SME clients.

Categories of data processed on behalf of the MSP:

  • identification data and professional contact details of client contacts: name, business email address, telephone, company, address, SIRET number;
  • free-text descriptions of the client's security situation, as entered by the MSP;
  • evidence documents uploaded by the MSP into assessments, registers and action plans;
  • connector credentials for the client's tools (instance URL and API tokens), encrypted at rest with AES-256-GCM.

The platform is not designed to receive special categories of data within the meaning of Article 9 GDPR, nor data relating to criminal convictions (Art. 10). As the free-text fields and the attachments are in the MSP's hands, it is for the MSP not to enter such data there, nor any personal data that is not necessary.

4. Documented instructions (art. 28.3.a)

Vigicap processes the data only on documented instructions from the controller, including where data is transferred to a third country. The MSP's documented instructions consist of:

  • these clauses, the terms of use and the privacy policy;
  • the use of the service's features by the MSP's users, each action carried out in the application constituting an instruction;
  • the settings enabled by the MSP in its workspace;
  • any further instruction sent in writing to contact@vigicap.fr.

Vigicap does not use the entrusted data for any purpose other than performing the service: it is neither sold, nor transferred, nor exploited for commercial, advertising or model-training purposes.

In accordance with the second subparagraph of Article 28.3, Vigicap immediately informs the controller if an instruction received infringes, in its opinion, the GDPR or any other applicable data protection provision.

5. Confidentiality of personnel (art. 28.3.b)

Vigicap undertakes that the persons authorised to process the data — to date, the restricted technical team providing operations and support — are bound by a contractual confidentiality obligation which survives the end of their engagement. Access to production data is limited to operating, maintenance and support needs, and takes place only where operationally necessary.

6. Security measures (art. 28.3.c and art. 32)

The following technical and organisational measures are actually implemented:

  • password hashing with argon2id;
  • authentication by JWT token stored in an httpOnly cookie, with server-side session revocation;
  • strict multi-tenant isolation, verified server-side on every access: one MSP cannot technically reach another's data;
  • encryption at rest with AES-256-GCM of connector credentials and OAuth tokens;
  • protection against server-side request forgery (SSRF) on every URL supplied by operators;
  • per-request audit log (action, timestamp, IP address);
  • rate limiting on sensitive endpoints;
  • mandatory verification of the email address before any access to the platform;
  • encryption of traffic in transit (TLS).

7. Sub-processors (art. 28.3.d)

The controller gives Vigicap a general written authorisation to engage the sub-processors listed below, which provide sufficient guarantees and are bound by protection obligations equivalent to the present ones.

  • Scaleway (France) — hosting of the application and of the data. Processing in France, by a company incorporated under French law.
  • Brevo (Sendinblue, France) — sending of transactional emails. Processing in the European Union.

Vigicap informs the controller of any addition or replacement of a sub-processor at least 30 days before it goes live, by email to the account's contact address. The controller has that period to raise a reasoned objection. Where an objection cannot be resolved between the parties, the controller may terminate the service without penalty and request the return or the deletion of its data under the conditions of article 11.

What this list does not include. The payment provider Stripe (Stripe Payments Europe, Limited, Ireland) does not appear here, and that is not an omission: it is involved only in the MSP's own subscription — billing identity, payment method, payment history — that is, in data for which Vigicap is the controller, outside the processing scope defined by this agreement. No data of an SME client is transmitted to it. That processing is described in the privacy policy.

8. Location of processing and transfers

Hosting, the database and file storage take place in France. Email sending takes place in the European Union.

Vigicap uses no artificial intelligence service: no data is transmitted to an external model. The platform's proposals (maturity levels, action plan, policies) result from deterministic rules and document templates, and are subject to human validation: no automated decision within the meaning of article 22 of the GDPR is taken.

Distinct from the above: when the MSP connects its PSA or its RMM and pushes an action as a ticket, Vigicap transmits the client's name, the title, the recommendation, the priority and the due date of the action, together with the name of the person it is assigned to, to the instance the MSP has configured. The location of that instance is chosen by the MSP, not by Vigicap, and may be outside the European Union (several PSA vendors are American). That transfer falls under the controller's instructions and its own contracts; Vigicap is only the technical executant of it and never triggers it on its own initiative.

9. Assistance with data subject requests (art. 28.3.e)

As the data subjects are the contacts of the MSP's SME clients, their requests for access, rectification, erasure, restriction, objection and portability are addressed to the MSP, as controller. Vigicap assists it by the following means:

  • a full export available on a self-service basis in the application (Audit log → Full export, JSON), covering all of the MSP's data — accounts, clients and contacts, assessments and answers, register, action plans, risks, incidents, quotes, ISO 27001 file and audit log. The exact scope, the exclusions and the reasons for them are detailed on the reversibility page;
  • the application's editing and deletion functions, allowing the MSP itself to rectify or erase a record, an action or an attachment;
  • failing that, assistance on written request to contact@vigicap.fr, handled within a timeframe allowing the controller to reply within one month (art. 12.3 GDPR).

If a data subject contacts Vigicap directly, their request is not dealt with on the merits: it is forwarded without delay to the competent controller, who answers it.

10. Assistance with security, breaches and impact assessments (art. 28.3.f)

Taking into account the nature of the processing and the information available to it, Vigicap assists the controller in complying with its obligations under Articles 32 to 36 GDPR.

Personal data breach notification: Vigicap notifies the controller without undue delay after becoming aware of a personal data breach affecting its data, and undertakes to do so within 48 hours where materially possible, so as to leave it the time to notify the supervisory authority within the 72-hour deadline of Article 33. The notification states, within the limits of the known facts: the nature of the breach, the categories and approximate volume of data and data subjects concerned, the likely consequences and the measures taken or envisaged. Missing information is communicated as it becomes available. It is for the controller to notify the CNIL and, where applicable, the data subjects.

Data protection impact assessment (DPIA) and prior consultation: on written request, Vigicap provides the descriptive information required (nature of the processing operations, data flows, security measures, sub-processors, locations) to enable the controller to carry out an impact assessment under Article 35 or a prior consultation under Article 36. Vigicap does not carry out the DPIA in the controller's place.

11. Fate of the data at the end of the service (art. 28.3.g)

The controller may export its data at any time from the application, without any involvement from Vigicap: reversibility therefore does not depend on the end of the contract.

At the end of the service, Vigicap proceeds, at the controller's choice, to return the data or to delete it, as well as to destroy the existing copies. Connector credentials are deleted immediately when the corresponding connector is disconnected.

Two limitations should be known rather than discovered: no automatic purge is in place to date — the data is retained for the entire duration of the contractual relationship and its deletion is carried out manually on written request, the service applying no automated retention period; and account deletion is not yet available on a self-service basis in the application, it is exercised by contacting contact@vigicap.fr. Nor does Vigicap commit to a timeframe for overwriting any backups kept by the hosting provider, which it does not control; this point may be specified in the bilateral agreement mentioned in article 14.

12. Demonstration of compliance and audit (art. 28.3.h)

Vigicap makes available to the controller, on written request, the information necessary to demonstrate compliance with the obligations of this agreement: description of the processing operations and of the data flows, security measures actually implemented, up-to-date list of the sub-processors and of their locations, and information corresponding to article 30.2 GDPR.

The controller may carry out an audit, or have one carried out by an independent third party it mandates, once a year and in the event of a data breach affecting its data. The audit is subject to reasonable notice (30 days), is carried out at the controller's expense, under conditions that do not disrupt the service and under a confidentiality agreement. It may not cover the data of Vigicap's other customers.

Clarification: as it holds no certification, Vigicap cannot substitute a third-party audit report for this information. The response takes the form of a completed security questionnaire and, where appropriate, a technical discussion. The audit reports and certifications of the sub-processors are those published by the sub-processors themselves.

13. Records and documentation

Vigicap undertakes to keep and to keep up to date the record of the categories of processing activities carried out on behalf of controllers, provided for in article 30.2 GDPR, and to communicate it on request to the controller or to the supervisory authority.

14. Scope of this document and signed bilateral agreement

This document constitutes Vigicap's standard data processing terms: it applies as of right to every MSP using the service, without signature, and forms an integral part of the terms of use.

A countersigned bilateral data processing agreement restating these clauses is available on simple request to contact@vigicap.fr, for controllers who wish to hold a signed instrument — in particular for their own compliance documentation or for the processing chain towards their own clients. That agreement will be signed in the name of the legal entity as soon as it is registered; in the meantime the commitment is made personally by the operator of the service and will be confirmed by the entity's countersignature.

15. Changes and contact

Any substantial change to these clauses — in particular the list of sub-processors, the processing locations or the security measures — is brought to the controllers' attention by email, within the notice periods provided for in article 7 where the change concerns a sub-processor.

Single point of contact for any request relating to this agreement (exercise of rights, audit, data breach, signed agreement): contact@vigicap.fr. The controller retains the right to lodge a complaint with the CNIL (cnil.fr).

This document describes Vigicap's commitments and does not constitute legal advice. For the application of these rules to your own situation, please consult your legal adviser.