Applicable from its publication. This agreement supplements the Metaventus General Terms of Service (the “Terms of Service”).
1. Purpose and roles
This Data Processing Agreement (the “DPA”) governs, in accordance with article 28 GDPR, the processing of personal data that VENTUS, a simplified joint-stock company with share capital of €60,000, Rouen Trade and Companies Register 917 982 969, 14 chemin des Tilleuls, 76130 Mont-Saint-Aignan (“Metaventus”, acting as processor) carries out on behalf of the account holder (the “Customer”, acting as controller) in connection with the provision of the Services.
Where the Customer itself acts as a processor for a third party, Metaventus acts as sub-processor and the Customer warrants that its own undertakings are compatible with this DPA.
For the processing that Metaventus carries out on its own behalf (customer account management, billing, platform security, statistics), Metaventus acts as controller, in accordance with its Privacy Policy.
2. Instructions
Metaventus processes the Customer's Data solely on the Customer's documented instructions. The Terms of Service, this DPA and the use of the platform's features by the Customer and its users constitute the Customer's instructions. Metaventus informs the Customer if an instruction appears to it to infringe the GDPR.
3. Description of the processing
The detailed description (nature, purposes, categories of data and of data subjects, duration) is set out in Annex 1.
4. Confidentiality
Metaventus warrants that the persons authorised to process the Customer's Data are bound by an obligation of confidentiality and access it only to the extent necessary for their duties.
5. Security
Metaventus implements the appropriate technical and organisational measures described in Annex 2, in accordance with article 32 GDPR.
6. Sub-processors
The Customer gives general authorisation to the use of the sub-processors listed in Annex 3. Metaventus enters into a contract with each of them imposing data protection obligations equivalent to those of this DPA and remains liable for their performance.
Metaventus informs the Customer (by email or by notification within the platform) of any addition or replacement of a sub-processor at least thirty (30) days before it takes effect. The Customer may object on legitimate grounds; failing agreement, the Customer may terminate the subscription concerned before the change takes effect.
7. Assistance to the controller
Taking into account the nature of the processing, Metaventus assists the Customer through appropriate measures (primarily the platform's features): in responding to requests from data subjects exercising their rights (access, rectification, erasure, portability, objection); and in complying with its obligations under articles 32 to 36 GDPR (security, breach notification, impact assessments). Any request for assistance going beyond the standard features may give rise to reasonable billing, agreed in advance.
8. Personal data breaches
Metaventus notifies the Customer, as soon as possible after becoming aware of it, of any data breach affecting the Customer's Data, at the email address of the account administrator or administrators, with the information required by article 33(3) GDPR (nature, categories and volumes concerned, likely consequences, measures taken or proposed).
9. Transfers outside the European Union
The Customer's Data is hosted within the European Union. Certain sub-processors (Annex 3) may process data from third countries; in that case, the transfer is framed by an adequacy decision (including the EU-U.S. Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses, supplemented where necessary by additional measures.
10. Deletion and return
Throughout the term of the agreement, the Customer may export its data using the platform's features. At the end of the agreement, Metaventus deletes the Customer's Data within thirty (30) days, save where retention is required by law. On written request made before the end of that period, Metaventus confirms the deletion.
11. Records and audits
Metaventus maintains a record of the processing activities carried out on behalf of the Customer (art. 30(2) GDPR). Metaventus makes available to the Customer the information necessary to demonstrate compliance with this DPA (documentation, descriptions of measures, available certifications).
The Customer may carry out, at most once (1) in any twelve (12) month period, an audit limited to the processing carried out on its behalf, subject to thirty (30) days' written notice, at its own expense, during business hours, without access to other customers' data or to trade secrets. An on-site audit is possible only where the documentation does not provide a satisfactory answer.
12. Term and liability
This DPA applies throughout the term of the Terms of Service and for as long as Metaventus processes the Customer's Data. The liability caps and exclusions of the Terms of Service apply to this DPA.
Data protection contact: contact@metaventus.com.
13. Language
This DPA is drafted in French. Where a translation is provided for convenience, only the French version is authoritative.
Annex 1 — Description of the processing
Nature and purposes: hosting, storing, structuring and consulting the Customer's CRM data; sending electronic communications (emails, text messages, calls) at the Customer's initiative; appointment booking; invoicing the Customer's own customers; process automation; AI assistance features (at users' request); technical logging and usage statistics.
Categories of data subjects: the Customer's users; the Customer's contacts, prospects and customers; appointment attendees; recipients of communications.
Categories of data: identity and contact details (surname, first name, email, telephone, address); professional data (company, job title); commercial data (opportunities, quotes, invoices, appointments, notes); the substance of communications sent through the platform; technical data (logs, IP addresses, identifiers). The processing of special categories of data (art. 9 GDPR) is excluded (see the Terms of Use).
Duration: the term of the agreement, then deletion within 30 days (art. 10), subject to the retention periods configured by the Customer in the platform and to legal obligations.
Annex 2 — Security measures
- Encryption of traffic (TLS) across all exposed services;
- Strict segregation of data by customer account (multi-tenant);
- Fine-grained role- and permission-based access control (RBAC);
- Strong authentication: two-factor authentication available (SMS, TOTP, passkeys/WebAuthn) and mandatory for administrator roles;
- Authentication secrets stored under strong encryption (AES-256-GCM) and passwords hashed;
- Time-stamped audit logs (sign-ins, role changes, sensitive actions) with minimum retention periods that cannot be shortened;
- Automatic purging of data beyond the retention periods;
- Least-privilege policy for staff; production access restricted and individually named;
- Regular backups managed by the hosting provider (retention and restoration);
- Separate development and production environments;
- Traceability of contractual acceptances (time stamp, version, SHA-256 fingerprint).
Annex 3 — Sub-processors
| Sub-processor | Purpose | Entity / Country | Data location | Safeguards |
|---|---|---|---|---|
| Render Services, Inc. | Hosting of the application and databases | USA | European Union — Frankfurt (EU Central) | SCCs / DPF |
| Amazon Web Services EMEA SARL | Sending emails (Amazon SES) | Luxembourg | EU — Paris region (eu-west-3) | EU law; SCCs in support |
| LINK Mobility (SpotHit) | Text message routing | France (Nanterre Trade and Companies Register) | EU | EU law |
| Telnyx Ireland Ltd | Cloud telephony (calls, numbers) | Ireland | EU/USA depending on configuration | SCCs / DPF |
| Microsoft Ireland Operations Ltd (Azure) | Inter-service message bus, file storage, real-time notifications, Azure AI services | Ireland | European Union — West Europe (AI services: France Central) | EU law; SCCs in support |
| Stripe Payments Europe Ltd | Payments and subscriptions | Ireland | EU/USA | SCCs / DPF |
| OpenAI Ireland Ltd | AI features, including the real-time voice agent | Ireland | EU/USA | SCCs / DPF |
| Mistral AI | AI features (depending on the features enabled) | France | EU | EU law |
The following are not sub-processors of Metaventus: the third-party services that the Customer connects to its account on its own initiative (Google, Microsoft, Zoom, social networks, and so on) — those integrations fall within the direct relationship between the Customer and the third-party provider concerned.