Skip to content

Exclusive 50% off for 36 months for the first 100 Professional accounts, until 31 December 2026. See the programme →

Contractual documents

Data Processing Agreement (DPA)

Article 28 GDPR, applied: roles of controller and processor, further sub-processing, security, retention periods, assistance during an audit.

Version 1.1 In force since July 4, 2026 Binds the customer account

Translation provided for convenience. Only the French version is authoritative. Read the French version

Applicable from its publication. This agreement supplements the Metaventus General Terms of Service (the “Terms of Service”).

1. Purpose and roles

This Data Processing Agreement (the “DPA”) governs, in accordance with article 28 GDPR, the processing of personal data that VENTUS, a simplified joint-stock company with share capital of €60,000, Rouen Trade and Companies Register 917 982 969, 14 chemin des Tilleuls, 76130 Mont-Saint-Aignan (“Metaventus”, acting as processor) carries out on behalf of the account holder (the “Customer”, acting as controller) in connection with the provision of the Services.

Where the Customer itself acts as a processor for a third party, Metaventus acts as sub-processor and the Customer warrants that its own undertakings are compatible with this DPA.

For the processing that Metaventus carries out on its own behalf (customer account management, billing, platform security, statistics), Metaventus acts as controller, in accordance with its Privacy Policy.

2. Instructions

Metaventus processes the Customer's Data solely on the Customer's documented instructions. The Terms of Service, this DPA and the use of the platform's features by the Customer and its users constitute the Customer's instructions. Metaventus informs the Customer if an instruction appears to it to infringe the GDPR.

3. Description of the processing

The detailed description (nature, purposes, categories of data and of data subjects, duration) is set out in Annex 1.

4. Confidentiality

Metaventus warrants that the persons authorised to process the Customer's Data are bound by an obligation of confidentiality and access it only to the extent necessary for their duties.

5. Security

Metaventus implements the appropriate technical and organisational measures described in Annex 2, in accordance with article 32 GDPR.

6. Sub-processors

The Customer gives general authorisation to the use of the sub-processors listed in Annex 3. Metaventus enters into a contract with each of them imposing data protection obligations equivalent to those of this DPA and remains liable for their performance.

Metaventus informs the Customer (by email or by notification within the platform) of any addition or replacement of a sub-processor at least thirty (30) days before it takes effect. The Customer may object on legitimate grounds; failing agreement, the Customer may terminate the subscription concerned before the change takes effect.

7. Assistance to the controller

Taking into account the nature of the processing, Metaventus assists the Customer through appropriate measures (primarily the platform's features): in responding to requests from data subjects exercising their rights (access, rectification, erasure, portability, objection); and in complying with its obligations under articles 32 to 36 GDPR (security, breach notification, impact assessments). Any request for assistance going beyond the standard features may give rise to reasonable billing, agreed in advance.

8. Personal data breaches

Metaventus notifies the Customer, as soon as possible after becoming aware of it, of any data breach affecting the Customer's Data, at the email address of the account administrator or administrators, with the information required by article 33(3) GDPR (nature, categories and volumes concerned, likely consequences, measures taken or proposed).

9. Transfers outside the European Union

The Customer's Data is hosted within the European Union. Certain sub-processors (Annex 3) may process data from third countries; in that case, the transfer is framed by an adequacy decision (including the EU-U.S. Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses, supplemented where necessary by additional measures.

10. Deletion and return

Throughout the term of the agreement, the Customer may export its data using the platform's features. At the end of the agreement, Metaventus deletes the Customer's Data within thirty (30) days, save where retention is required by law. On written request made before the end of that period, Metaventus confirms the deletion.

11. Records and audits

Metaventus maintains a record of the processing activities carried out on behalf of the Customer (art. 30(2) GDPR). Metaventus makes available to the Customer the information necessary to demonstrate compliance with this DPA (documentation, descriptions of measures, available certifications).

The Customer may carry out, at most once (1) in any twelve (12) month period, an audit limited to the processing carried out on its behalf, subject to thirty (30) days' written notice, at its own expense, during business hours, without access to other customers' data or to trade secrets. An on-site audit is possible only where the documentation does not provide a satisfactory answer.

12. Term and liability

This DPA applies throughout the term of the Terms of Service and for as long as Metaventus processes the Customer's Data. The liability caps and exclusions of the Terms of Service apply to this DPA.

Data protection contact: contact@metaventus.com.

13. Language

This DPA is drafted in French. Where a translation is provided for convenience, only the French version is authoritative.


Annex 1 — Description of the processing

Nature and purposes: hosting, storing, structuring and consulting the Customer's CRM data; sending electronic communications (emails, text messages, calls) at the Customer's initiative; appointment booking; invoicing the Customer's own customers; process automation; AI assistance features (at users' request); technical logging and usage statistics.

Categories of data subjects: the Customer's users; the Customer's contacts, prospects and customers; appointment attendees; recipients of communications.

Categories of data: identity and contact details (surname, first name, email, telephone, address); professional data (company, job title); commercial data (opportunities, quotes, invoices, appointments, notes); the substance of communications sent through the platform; technical data (logs, IP addresses, identifiers). The processing of special categories of data (art. 9 GDPR) is excluded (see the Terms of Use).

Duration: the term of the agreement, then deletion within 30 days (art. 10), subject to the retention periods configured by the Customer in the platform and to legal obligations.

Annex 2 — Security measures

  • Encryption of traffic (TLS) across all exposed services;
  • Strict segregation of data by customer account (multi-tenant);
  • Fine-grained role- and permission-based access control (RBAC);
  • Strong authentication: two-factor authentication available (SMS, TOTP, passkeys/WebAuthn) and mandatory for administrator roles;
  • Authentication secrets stored under strong encryption (AES-256-GCM) and passwords hashed;
  • Time-stamped audit logs (sign-ins, role changes, sensitive actions) with minimum retention periods that cannot be shortened;
  • Automatic purging of data beyond the retention periods;
  • Least-privilege policy for staff; production access restricted and individually named;
  • Regular backups managed by the hosting provider (retention and restoration);
  • Separate development and production environments;
  • Traceability of contractual acceptances (time stamp, version, SHA-256 fingerprint).

Annex 3 — Sub-processors

Sub-processorPurposeEntity / CountryData locationSafeguards
Render Services, Inc.Hosting of the application and databasesUSAEuropean Union — Frankfurt (EU Central)SCCs / DPF
Amazon Web Services EMEA SARLSending emails (Amazon SES)LuxembourgEU — Paris region (eu-west-3)EU law; SCCs in support
LINK Mobility (SpotHit)Text message routingFrance (Nanterre Trade and Companies Register)EUEU law
Telnyx Ireland LtdCloud telephony (calls, numbers)IrelandEU/USA depending on configurationSCCs / DPF
Microsoft Ireland Operations Ltd (Azure)Inter-service message bus, file storage, real-time notifications, Azure AI servicesIrelandEuropean Union — West Europe (AI services: France Central)EU law; SCCs in support
Stripe Payments Europe LtdPayments and subscriptionsIrelandEU/USASCCs / DPF
OpenAI Ireland LtdAI features, including the real-time voice agentIrelandEU/USASCCs / DPF
Mistral AIAI features (depending on the features enabled)FranceEUEU law

The following are not sub-processors of Metaventus: the third-party services that the Customer connects to its account on its own initiative (Google, Microsoft, Zoom, social networks, and so on) — those integrations fall within the direct relationship between the Customer and the third-party provider concerned.

SHA-256 fingerprint

2c42cec7b72b8b9913f95823664d450b1d89639a3af778c2022c80fb89dbec15

It is verified against the plain-text version above — not the PDF, and not this page, whose formatting changes the bytes.

All documents

Ready to bring all your tools together?

Create your free account in two minutes: CRM, telephony, marketing, appointments and customer service — all in one place, with AI built in.

No credit card required