Roles of the parties
This agreement implements Article 28 of the General Data Protection Regulation (GDPR). It forms an integral part of the terms and conditions and applies without a separate signature.
For the personal data the Customer enters into or imports into Unileva, the Customer is the controller. Loïc Hollay (sole trader), enterprise number 1028.697.569, rue Guido Gezelle 25, 1780 Wemmel, Belgium (“the publisher”) acts as processor.
Subject matter and duration
The publisher processes this data for the sole purpose of providing the Unileva service to the Customer, for the duration of the subscription and until its deletion as provided for in the article “End of the contract”.
Data and data subjects
Data subjects: the Customer’s customers, prospects, suppliers, partners and staff, as well as its Users.
Data processed, depending on how the Customer uses the service:
- contact and company records, opportunities, activities, notes, tasks and appointments;
- custom fields created by the Customer;
- quotes and contracts, and for those signed online: the signatory’s name, image of their signature, IP address, device and timestamp;
- documents uploaded by the Customer;
- emails from the connected mailbox: the last ninety days when it is connected, then on an ongoing basis; attachments are stored only at the User’s request;
- conversations with the AI assistant, when it is activated.
The Customer refrains from entrusting special categories of data (health, opinions, biometric data) to the service without necessity and without a specific legal basis.
Customer instructions
The publisher processes the data only on documented instructions from the Customer. These instructions consist of this agreement, the Customer’s use of the service and its settings. If an instruction appears to infringe the GDPR, the publisher informs the Customer.
The publisher does not use the Customer’s data for its own purposes. It is not used to train any artificial intelligence model.
Confidentiality
Persons authorised to process the data on the publisher’s behalf are bound by a duty of confidentiality and access it only to the extent necessary for the service or for the assistance requested by the Customer.
Security
The publisher implements the technical and organisational measures provided for in Article 32 of the GDPR, in particular:
- partitioning of data by organisation, and of rights by role;
- encryption of exchanges in transit and of mailbox credentials at rest;
- passwords stored as hashes, two-factor authentication offered to every User;
- regular backups;
- an action log the Customer can consult. When the publisher accesses the Customer’s account to assist it, that access is limited to 30 minutes and recorded in this log.
Sub-processors
The Customer authorises the publisher to engage the following sub-processors:
- OVH SAS (France): hosting of the application, the database and the files;
- Amazon Web Services EMEA SARL (Ireland region): delivery of emails sent by the service (notifications, reminders);
- Mistral AI (France): AI assistant responses, only if the Customer activates it, with no model training on its data.
Emails that Users write from the service are sent from the Customer’s mail server, which is not a sub-processor of the publisher.
The publisher informs the Customer of any addition or replacement of a sub-processor one month before it takes effect. The Customer may object on legitimate grounds; failing agreement, it may terminate the subscription before the change takes effect, at no cost. The publisher imposes on each sub-processor obligations equivalent to those of this agreement.
Assistance to the Customer
The publisher helps the Customer, as far as possible, to respond to requests from data subjects (access, rectification, erasure, portability, objection), to carry out a data protection impact assessment where required and to consult the supervisory authority. Any request received directly by the publisher is forwarded to the Customer without delay.
Data breaches
The publisher notifies the Customer of any personal data breach without undue delay, and no later than 48 hours after becoming aware of it. The notification describes the nature of the breach, the data and data subjects concerned, its likely consequences and the measures taken, so that the Customer can meet its own obligations.
End of the contract
When the subscription ends, the Customer has thirty days to export its data in a standard format. The publisher then deletes it, including from backups once their rotation cycle ends, unless retention is required by law.
Audit
The publisher makes available to the Customer the information needed to demonstrate compliance with this agreement. The Customer may have an audit carried out, at its own expense, by itself or by an auditor bound by confidentiality, with thirty days’ notice and without disrupting the service.
Transfers outside the European Union
The Customer’s data is hosted in France and is not transferred outside the European Union. Any future transfer would be announced as a new sub-processor and governed by the safeguards provided for in Chapter V of the GDPR.
For any question about this agreement: hello [at] unileva.com.