Data processing agreement
Last updated: 10 September 2026
Draft — to be reviewed by the Publisher before it is relied on against a customer. This data processing agreement (the "Agreement") is entered into under Article 28 of Regulation (EU) 2016/679 (the "GDPR") between the customer property (the "Customer", data controller) and Vesper Holdings, SAS à associé unique, RCS Marseille 943 254 441, 15B Boulevard Die, 13012 Marseille, France (the "Processor"), publisher of the Paco service. The French version is the legally operative one; this is a convenience translation.
1. Subject matter and relationship to the Terms
The Agreement governs the processing of personal data the Processor carries out on the Customer's behalf in delivering the Paco service. It forms an integral part of the terms of use and applies to every account the Customer opens. Where the Agreement and the Terms conflict on a personal-data matter, the Agreement prevails.
2. Description of the processing
| Element | Description |
|---|---|
| Nature and purpose | Hosting, automated reading and indexing of the inspection reports and mail the Customer uploads or has collected; keeping the property's register of duties; reminders and briefs to the Customer's users; support. |
| Duration | The life of the Customer's account, then the retention period in article 8. |
| Categories of data subjects | The Customer's users (owners, managers, staff); third parties named in the documents processed (engineers, inspectors, contractors); the Customer's employees whose residence or work permit is tracked; senders and recipients of collected mail if the Customer connects a mailbox. |
| Categories of data | Identity and professional contact details; role and assignment; the content of professional reports, certificates and mail and their metadata; work permit dates and numbers; phone number and messages if a user links WhatsApp; proof photos and their metadata (capture time, coordinates, device); questions asked of the assistant; technical identifiers (logs, IP address). The Customer undertakes not to entrust data falling under Article 9 GDPR. |
3. Customer obligations
The Customer warrants that it has a legal basis for the processing entrusted, that it has informed the data subjects, and that it uploads only data necessary for its property's regulatory tracking. It remains solely responsible for the lawfulness of its instructions.
4. Processor obligations
- Instructions. The Processor processes data only on the Customer's documented instructions, including for any transfer outside the European Union. Use of the service, the settings the Customer chooses and this Agreement constitute those instructions. If the Processor considers an instruction infringes the GDPR, it informs the Customer.
- Confidentiality. Persons authorised to process the data are bound by confidentiality and access the Customer's data only so far as is necessary to deliver the service, keep it secure, and provide support.
- Security. The Processor implements the measures described in article 7 of the privacy policy: encryption in transit, password hashing, encryption of mailbox credentials, strict separation between organisations, restricted access, hosting within the European Union and encrypted backups.
- Assistance. The Processor assists the Customer, by appropriate technical and organisational measures, in responding to data subjects' requests, and in meeting its security, breach-notification and impact-assessment obligations, taking into account the nature of the processing and the information available to it.
- Data breaches. The Processor notifies the Customer of any personal data breach affecting it without undue delay after becoming aware of it, with the information needed for notification to the supervisory authority.
- Records. The Processor keeps the record of categories of processing activities carried out on the Customer's behalf required by Article 30(2) GDPR.
5. Sub-processors
The Customer gives general authorisation for the following sub-processors, which are the same as those listed in the privacy policy:
| Sub-processor | Role | Location and safeguards |
|---|---|---|
| Hetzner Online GmbH | Server hosting (database, documents, mail) | Germany (EU) |
| Backblaze, Inc. | Nightly backup copy, encrypted before it leaves the server, deleted after 30 days | United States — standard contractual clauses; storage region being confirmed |
| Resend, Inc. | Sending the service's emails (acknowledgements, invitations, resets, briefs) | United States — standard contractual clauses |
| Mistral AI | Automated reading of uploaded documents; conversational assistant for organisations subject to the GDPR | France (EU) |
| Anthropic, PBC | Conversational assistant, only for organisations outside the EU or that expressly asked for this provider (option closed by default); receives the question, the recent conversation memory and a register snapshot; never a whole document nor the person's identity) | United States — standard contractual clauses |
| Twilio Inc. | WhatsApp channel (sending and receiving messages), only if the Customer switches the channel on | United States — European Commission standard contractual clauses |
| Telegram Messenger Inc. | Receiving the brief over Telegram, only if one of the Customer's users chooses that channel | Outside the EU — on the user's explicit choice (art. 49.1.a) |
| Sentry (Functional Software, Inc.) | Technical error monitoring | EU data region; no personal data is sent (sending of identifying data disabled) |
| Komoot GmbH (Photon service) | Address completion while entering the property | Germany (EU) |
| ipwho.is | May be used, only if the operator switches it on, to resolve a sign-up IP address to an approximate city (abuse check); off by default | United States — the IP address alone is sent, no result kept |
| Google LLC / Microsoft Corporation | Only if the Customer connects a Gmail / Outlook mailbox (access to its own mail via OAuth) | EU / United States — standard contractual clauses |
| Mews Systems | Property management system, only if the Customer connects it | Czechia (EU) |
| Cloudbeds, Inc. | Property management system, only if the Customer connects it | United States — standard contractual clauses |
The Processor informs the Customer of any addition or replacement of a sub-processor, by email or by updating this page (dated at the top), at least 30 days before the new sub-processor processes any of the Customer's data. The Customer may object in writing within that period; failing agreement on a solution, the Customer may close its account at no cost. The Processor imposes on each sub-processor data-protection obligations equivalent to those of this Agreement and remains fully liable to the Customer for their performance.
6. Transfers outside the European Union
Hosting, documents and the automated reading of documents take place in the European Union. Transfers outside the EU are those listed in section 5: the encrypted backup copy, the sending of the service's emails, the conversational assistant for organisations outside the EU or that expressly asked for it only, and the channels or connections the Customer or its users switch on (WhatsApp, Telegram, Google/Microsoft mailbox, Cloudbeds PMS). Each is covered by the safeguards of Chapter V GDPR, in particular the European Commission's standard contractual clauses, or by the user's explicit choice of a channel.
7. Audits
The Processor makes available to the Customer the information necessary to demonstrate compliance with this Agreement. The Customer may, at most once a year unless there is an incident or a supervisory authority requests it, have an audit carried out by itself or by an independent auditor bound by confidentiality, on 30 days' written notice, during business hours and without disrupting the service. Written answers to a reasonable questionnaire serve as the audit in the first instance.
8. Data at the end of the service
On closure of the account, the Customer can export its register and supporting documents from the service. The data is then deleted or anonymised within 12 months of closure, including from backups as they expire, subject to legal retention obligations. On the Customer's written request before that date, the Processor returns a copy of its data in a common format.
9. Liability and term
The Agreement takes effect when the account is opened and remains in force for as long as the Processor processes data on the Customer's behalf. The limitations of liability in the Terms apply to the Agreement to the extent the GDPR permits.
10. Contact
For any question about this Agreement or about data subjects' rights: contact@pacoapp.io.