Data Processing Agreement
Purpose
This Data Processing Agreement (the “DPA”) sets out the conditions under which Ignito processes personal data on behalf of the Client in connection with the provision of the Ignito Platform, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
This DPA forms an integral part of the main agreement between the Parties.
Parties
Controller (the “Client”)
Any client organization using the Ignito platform for its teams and users.
Processor
Legal information regarding the publisher of the Platform is available in the Legal Notices accessible on the Ignito website.
The Ignito Platform is operated by:
IGNITO, simplified joint-stock company (SAS)
Registered office: 24 bis rue de Picpus, 75012 Paris – France
SIREN: 101 037 117 SIRET: 10103711700013
Business activity code (APE): 58.29C – Publishing of other software
Contact: support@ignito.ai Data Protection Officer: dpo@ignito.ai
Roles of the Parties
The Client acts as the Controller within the meaning of the GDPR.
Ignito acts exclusively as the Processor, processing personal data on behalf of the Client and in accordance with its documented instructions.
Ignito does not determine the purposes or essential means of the processing activities.
Clarification on technical means
Ignito makes available to the Client a standardized software platform, including analytical features and generic calculation models, without intervening in the definition of the Client’s own purposes or in the interpretation, evaluation, or decision-making use of the results produced.
The provision of these technical capabilities shall not be interpreted as a joint determination of the purposes or essential means of processing within the meaning of Article 26 of the GDPR.
Description of Processing Activities
Ignito processes personal data solely for the purposes defined by the Client and in accordance with the documented instructions set out in Section 5.
A detailed description of the processing activities, categories of data, data subjects, and retention periods is set out in Annex A and in Ignito’s Privacy Policy, which is provided for information purposes.
Use of Client Data for Service Improvement and AI
Personal data processed under this Agreement is not used to train, fine-tune, or improve artificial intelligence or machine learning models intended for use by other clients, unless the Client has expressly agreed in writing.
Ignito may use aggregated and irreversibly anonymized data that no longer constitutes personal data within the meaning of applicable regulations, for statistical, research, and service improvement purposes.
Documented Instructions
Ignito processes personal data solely on the basis of documented instructions from the Client.
Documented instructions include:
the main agreement;
this DPA and its annexes;
the functional and technical documentation of the Ignito platform;
the parameters and configurations defined by the Client within the platform, including enabled integrations, roles, access rights, and analytical scopes.
Traceability of instructions
The configurations, parameters, integration choices, analytical scopes, roles, and access rights defined by the Client within the Ignito platform constitute documented instructions within the meaning of Article 28 of the GDPR.
These elements are retained by Ignito for traceability purposes for the duration of the agreement.
Ignito will inform the Client if it considers that an instruction constitutes a breach of the GDPR or any other applicable provision.
The Client warrants that its instructions comply with applicable law, including Regulation (EU) 2016/679 (GDPR), labor law, and rules relating to the protection of the rights and freedoms of data subjects.
The Client remains solely responsible for determining the purposes and essential means of processing, as well as for its use of the analyses, indicators, and recommendations provided by the Ignito platform.
Processor Obligations
Ignito undertakes to:
process personal data solely in accordance with the Client’s documented instructions;
ensure the confidentiality of the personal data processed;
ensure that persons authorized to process the data are subject to an appropriate confidentiality obligation;
not use personal data for its own purposes, or for commercial or advertising purposes;
implement the technical and organizational measures described in Annex B;
assist the Client in meeting its GDPR obligations;
notify any personal data breach without undue delay;
delete or return personal data at the end of the agreement.
Assistance to the Controller
Ignito will assist the Client, to the extent reasonably possible and taking into account the nature of the processing, in:
responding to requests from data subjects exercising their rights;
carrying out, where applicable, data protection impact assessments (DPIAs);
complying with the obligations set out in Articles 32 to 36 of the GDPR;
cooperating with competent supervisory authorities.
Ignito will not respond directly to requests from data subjects without coordination with the Client, unless otherwise required by law.
Assistance provided by Ignito will be carried out:
within reasonable timeframes, taking into account the complexity and volume of requests;
through the usual support and contact channels;
without obligation to respond to manifestly unfounded, excessive, or repetitive requests.
Assistance is provided within the limits of the Processor’s reasonable technical capabilities. Any assistance beyond the normal scope of Article 28 obligations, including specific developments, complex extractions, and dedicated technical audits, may be subject to additional billing based on Ignito’s current rates, upon prior acceptance of a quote by the Client.
Data Security
Ignito implements appropriate technical and organizational measures, in line with the state of the art and proportionate to the risks, in order to ensure an appropriate level of security.
These measures are described in Annex B and include in particular:
encryption of data in transit (TLS 1.2+) and at rest (FIPS 140-2-compliant standards);
strict access control (least privilege principle, MFA for administrator access);
logging and monitoring of access and processing activities;
formalized security incident management procedures.
Sub-Processors
Ignito is authorized to engage sub-processors for the performance of all or part of the Service.
The list of authorized sub-processors is set out in Annex C.
Ignito will inform the Client of any material change to this list, in particular in the event of the addition or replacement of a sub-processor, by updating Annex C or by any other appropriate means.
Ignito remains fully liable to the Client for the performance by any sub-processor of its data protection obligations in accordance with this DPA.
Ignito ensures that any sub-processor is bound by contractual obligations imposing requirements at least equivalent to those set out in this DPA, in particular regarding confidentiality, security, and GDPR compliance.
The Client has thirty (30) calendar days from the date of receipt of such notification to submit written objections, on legitimate and documented grounds related to data protection.
In the absence of objection within that period, the Client is deemed to have accepted the new sub-processor. In the event of a substantiated objection, the Parties will endeavor to find a mutually acceptable solution. If no solution is found, Ignito may terminate the service without penalty, as the security or continuity of the service can no longer be guaranteed without the relevant sub-processor.
Data Transfers Outside the European Union
We favor data localization within the European Union whenever possible. However, some providers may process data outside the EU.
When personal data is transferred outside the European Economic Area, Ignito ensures that such transfers are governed by appropriate safeguards in accordance with applicable regulations, including the implementation of Standard Contractual Clauses adopted by the European Commission (primarily Module Two: Controller to Processor) or any other transfer mechanism validated by applicable regulations.
Where a transfer of personal data outside the European Union is based on Standard Contractual Clauses, Ignito implements, where necessary, supplementary measures designed to ensure a level of protection substantially equivalent to that guaranteed within the European Union, including in particular:
data encryption;
data minimization;
strict access restrictions.
Where required, Ignito carries out a Transfer Impact Assessment (TIA), in accordance with the recommendations of the European Data Protection Board (EDPB), to assess and document the risks associated with transfers of personal data outside the European Union.
Information regarding transfers and associated safeguards is set out in Annex C.
Personal Data Breaches
In the event of a personal data breach, Ignito will:
notify the Client without undue delay after becoming aware of the breach and, to the extent possible and taking into account the information available at that stage, within a maximum period of forty-eight (48) hours;
provide the Client with the information necessary to assess the incident and fulfill its notification obligations;
cooperate with the Client in the management and remediation of the incident.
End of Agreement – Return or Deletion of Data
Upon expiration or termination of the agreement, Ignito will, at the Client’s choice, either delete or return the personal data processed on its behalf.
By way of exception, the Client agrees that Ignito may carry out irreversible anonymization of certain personal data rather than deletion, prior to any reuse.
Anonymization is carried out using state-of-the-art methods, ensuring that the data:
no longer allows any direct or indirect identification of the data subjects;
cannot be re-identified, including through cross-referencing;
definitively falls outside the scope of Regulation (EU) 2016/679.
Anonymization is carried out using robust methods taking into account in particular:
the risk of re-identification through cross-referencing;
the size of the populations concerned;
the organizational and sectoral context.
Ignito ensures that anonymized data does not allow any individualization, including indirect, and is not used to produce analyses specific to an identifiable Client or organization.
Such anonymized data may be retained by Ignito exclusively for:
statistical purposes;
overall platform and model improvement purposes,
with no individualized or organization-specific processing being possible.
Deletion (or anonymization) extends to backups within 30 days, subject to any legal retention obligations.
Audits
The Client may verify Ignito’s compliance with this DPA through a documentary audit, subject to the following conditions:
the audit is limited to a maximum frequency of once per twelve (12)-month period, except in the event of a confirmed security incident or legal obligation;
the Client notifies Ignito of its audit request in writing with a minimum thirty (30) days’ prior notice;
the audit is conducted during business hours and in a manner that does not disrupt the continuity of Ignito’s activities;
the audit is limited to the elements strictly necessary to verify compliance with this DPA;
information communicated in the context of the audit is subject to a strict confidentiality obligation;
the costs of the audit are borne entirely by the Client. In addition, the time spent by Processor personnel in assisting with the audit beyond one working day may be subject to additional billing. Applicable rates are communicated by Ignito upon prior written request from the Client and are subject to a quote accepted by the Client before any commitment.
Ignito reserves the right to frame, adjust, or restrict any audit request that could compromise system security, trade secrets, or the data of other clients.
In order to limit the operational burden associated with audits, Ignito may, where available, satisfy the Client’s request by providing:
security and data protection policies;
relevant technical documentation;
third-party compliance attestations or reports, where applicable.
The use of such materials may substitute, in whole or in part, for an on-site audit, subject to the Client’s acceptance.
Absence of Surveillance, Individual Evaluation, and Automated Decision-Making
The Parties acknowledge that the Ignito platform:
does not constitute a tool for individual, continuous, or intrusive surveillance of employees or contractors;
is not designed to measure individual performance or to carry out professional, disciplinary, or managerial evaluations;
does not implement any fully automated decision-making producing legal effects or similarly significant effects on data subjects, within the meaning of Article 22 of Regulation (EU) 2016/679.
The Ignito platform provides exclusively informational and organizational analyses, indicators, and recommendations, intended to support human decision-making.
Any interpretation, decision, or action taken on the basis of results provided by the platform falls exclusively under the Client’s responsibility, which remains the sole decision-maker.
The Client undertakes to use the Ignito platform in compliance with applicable law, including in particular:
labor law;
personal data protection rules;
the principles of fairness, proportionality, and transparency toward data subjects.
The Client acknowledges that it is solely responsible for:
the prior and ongoing information of data subjects regarding the processing activities implemented;
compliance with applicable labor law obligations;
where applicable, consultation of the relevant employee representative bodies.
Ignito shall not be held liable for use of the platform:
for individual surveillance or disciplinary purposes;
for automated or quasi-automated decision-making;
or, more generally, for use not in compliance with applicable law or the provisions of this DPA.
Governing Law
This DPA is governed by French law.
Any dispute relating to its interpretation or performance falls under the jurisdiction defined in the main agreement.
Annex A – Description of Processing Activities and Retention Periods
General principles
This policy defines the retention periods for personal data processed by Ignito in accordance with the storage limitation principle set out in Article 5(1)(e) of the GDPR.
Personal data is retained only for as long as necessary for the purposes for which it is processed, then archived or deleted in accordance with legal obligations.
Account and authentication data
Category of data | Description | Retention period | Trigger / Notes |
|---|---|---|---|
| Identity data | Last name, first name, email, avatar, organization, roles | Duration of active account | Deletion within 30 days after closure |
| OAuth tokens & authentication data | Access tokens, refresh tokens, sessions | Session validity period (max. 30 days) | Automatic rotation |
| Connection logs & IP addresses | Login history, IP addresses | 12 months | Security and incident detection |
| Inactive account – notification | Warning to the user | 18 months of inactivity | Prior notification |
| Inactive account – deletion | Automatic account deletion | 24 months of inactivity | Unless justified objection or legal obligation |
| Billing data | Invoices, accounting information | 10 years | Legal tax and accounting obligations |
| Security logs related to incidents | Logs related to confirmed incidents | Resolution + 12 months | Traceability and defense |
Synchronization data (calendars, tasks, messaging)
Category of data | Description | Retention period | Trigger / Notes |
|---|---|---|---|
| Calendar events | Google Calendar, Outlook | Rolling 12 months | Automatic deletion. |
| Tasks | Jira, Linear, equivalent tools | Rolling 12 months | Automatic deletion |
| Messaging metadata | Slack, Teams (no content) | Rolling 12 months | Automatic deletion |
| Aggregated data & statistics | Indicators, analytics, opportunities | Duration of active account | Anonymization after closure |
| Fully anonymized data | Global statistics | Unlimited | Outside GDPR scope |
*Note: For events involving external third parties, the Client warrants that it has the necessary legal basis to allow synchronization of such data to the platform.
Communication data
Category of data | Description | Retention period | Trigger / Notes |
|---|---|---|---|
| Transactional emails | Service-related notifications | 12 months | Traceability and support |
| In-app history | Internal messages and notifications | Duration of active account | Deletion after closure |
| Customer support | Tickets and exchanges | 3 years after resolution | Customer relationship management |
| Litigation-related data | Elements necessary for defense | Duration of proceedings + statute of limitations | Legal obligation |
Technical and telemetry data
Category of data | Description | Retention period | Trigger / Notes |
|---|---|---|---|
| Application logs | Technical and application logs | 12 months | Monitoring and maintenance |
| Security logs | Incident detection and investigation | 12 months (or resolution + 12 months) | Security |
| Application usage data | Raw telemetry | 12 months | Technical analysis |
| Anonymized metrics | Performance and stability | Unlimited | Non-personal data |
| Aggregated statistics | Consolidated usage data | Duration of active account | Anonymization after closure |
Deletion and archiving procedures
Process | Description | Timeframe |
|---|---|---|
| Logical deletion | Marked as deleted | Immediate |
| Physical deletion | Permanent deletion | ≤30 days |
| Backup deletion | Full backup rotation | ≤30 days |
| Sub-processor deletion | Contractual instruction | ≤30 days |
| Intermediate archiving | Restricted access, enhanced encryption | As per legal obligations |
Exceptions and derogations
Authorized extended retention
Legal obligations: retention in accordance with statutory periods (e.g., 10 years for accounting data)
Litigation: retention until all avenues of appeal are exhausted
Public interest: statistical archiving using anonymized data
Specific consent: extended retention where the data subject has given explicit consent
Security data
In the event of a security incident or investigation:
Extended retention of relevant logs and data
Duration limited to resolution of the incident + 12 months
Documentation of the justification
Annex B – Technical and Organizational Measures
(Article 32 GDPR)
Ignito implements appropriate technical and organizational measures, in line with the state of the art, to ensure a level of security appropriate to the risks presented by the personal data processing activities carried out on behalf of the Client.
These measures are designed in particular to ensure the confidentiality, integrity, availability, and resilience of processing systems and services, through a multi-layered approach (defense in depth) integrated from the design stage.
Security governance
Security is integrated from the design stage of services (security by design).
Roles and responsibilities for security and data protection are clearly defined.
The Data Protection Officer (DPO) oversees GDPR compliance matters.
Security and data protection policies are documented, enforced, and regularly reviewed.
Data protection and encryption
2.1. Encryption in transit
All network communications are protected by TLS 1.2 or higher encryption.
Unsecured protocols are prohibited in production environments.
2.2. Encryption at rest
Sensitive stored data, including databases, backups, and persistent storage, is encrypted at rest.
Encryption mechanisms are based on recognized standards, FIPS 140-2 compliant or equivalent.
2.3. Key management
Encryption keys are securely stored, protected, and managed.
Strict policies on rotation, access, and separation of duties are applied in accordance with industry best practices.
Network and infrastructure security
Production, test, and development environments are strictly isolated.
Network access is restricted by strict filtering rules (ingress / egress).
Infrastructure is hosted with recognized cloud providers meeting high security and compliance standards.
Systems are hardened in accordance with best practices and kept up to date through regular security patches.
3.1. Perimeter protection
A Web Application Firewall (WAF) is deployed to protect against common attacks such as SQL injection, XSS, CSRF, and automated scans.
Rate limiting, filtering, and malicious traffic detection mechanisms are enabled.
Access and identity management
The least privilege principle is applied to all system and data access.
Access to sensitive environments is strictly limited to authorized personnel on a need-to-know basis.
Multi-factor authentication (MFA) is mandatory for administrator and privileged access.
Access rights are subject to regular reviews.
4.1. Access traceability and logging
Access to systems and sensitive operations are logged.
Logs are protected against tampering, accessible only to authorized personnel, and retained for a limited period.
Secure software development
Ignito applies a Secure Development Lifecycle (SDLC).
Software updates are subject to:
peer code reviews;
automated tests integrated into the continuous integration pipeline.
Third-party dependencies are monitored to identify and remediate known vulnerabilities.
Development, test, and production environments are strictly separated.
Monitoring, logging, and detection
Systems and applications are subject to continuous monitoring to detect anomalies, failures, or suspicious behavior.
Application and technical logs are collected and stored securely.
Access to logs is strictly restricted.
Incident management and data breaches
Ignito has a formalized security incident management procedure.
This procedure covers in particular:
incident detection and analysis;
containment and remediation;
assessment of the impact on personal data;
documentation of the incident.
In the event of a personal data breach, Ignito notifies the Client without undue delay, in accordance with the DPA and the GDPR.
Business continuity and resilience
Regular backup mechanisms are implemented to ensure data availability.
Backups are protected against unauthorized access.
Restoration procedures are periodically tested.
Architectures are designed to minimize single points of failure and strengthen operational resilience.
Sub-processor management
Technical sub-processors are selected on the basis of security and compliance guarantees.
They are bound by contractual commitments including confidentiality and data protection obligations.
Data transfers outside the European Union are governed by recognized mechanisms such as SCC, DPF, or equivalent.
Awareness and confidentiality
Persons authorized to process personal data are subject to a confidentiality obligation.
Access to personal data is limited to persons whose functions require it.
Continuous evaluation and improvement
Security measures are regularly assessed and updated to take into account:
the evolving threat landscape;
the state of the art;
regulatory and technical developments.
Annex C – Sub-Processors and Non-EU Transfers
The transfers of personal data outside the European Union referred to in this annex may include transfers for technical transit purposes, in particular via content delivery networks (CDNs), hosting, or ancillary service provision.
Where indicated, certain sub-processors do not carry out any persistent storage of personal data and are involved solely in transient or technical processing.
Sub-processors
AWS (EU – Paris)
Logto (EU)
Dash0 (EU)
Customer.io (EU)
Sub-processors with potential non-EU transfers
Cloudflare (CDN – Global)
Vercel (CDN – Global)
Mailgun (email – Global)
Google (identity and account services – Global)
Microsoft (identity and account services – Global)
Slack (identity and account services – Global)
Framer (marketing website – US – Global)
Each sub-processor is governed by appropriate safeguards (SCC, DPA, DPF), in accordance with Ignito’s sub-processor and non-EU transfer register.
For any legal or regulatory questions, please contact: legal@ignito.ai