Version 1.0

May 1, 2026

Data Processing Agreement (DPA)

Data Processing Agreement

  1. Purpose

This Data Processing Agreement (the “DPA”) sets out the conditions under which Ignito processes personal data on behalf of the Client in connection with the provision of the Ignito Platform, in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).

This DPA forms an integral part of the main agreement between the Parties.

  1. Parties

Controller (the “Client”)

Any client organization using the Ignito platform for its teams and users.

Processor

Legal information regarding the publisher of the Platform is available in the Legal Notices accessible on the Ignito website.

The Ignito Platform is operated by:

IGNITO, simplified joint-stock company (SAS)

Registered office: 24 bis rue de Picpus, 75012 Paris – France

SIREN: 101 037 117 SIRET: 10103711700013
Business activity code (APE): 58.29C – Publishing of other software

Contact: support@ignito.ai Data Protection Officer: dpo@ignito.ai

  1. Roles of the Parties

  • The Client acts as the Controller within the meaning of the GDPR.

  • Ignito acts exclusively as the Processor, processing personal data on behalf of the Client and in accordance with its documented instructions.

Ignito does not determine the purposes or essential means of the processing activities.

Clarification on technical means

Ignito makes available to the Client a standardized software platform, including analytical features and generic calculation models, without intervening in the definition of the Client’s own purposes or in the interpretation, evaluation, or decision-making use of the results produced.

The provision of these technical capabilities shall not be interpreted as a joint determination of the purposes or essential means of processing within the meaning of Article 26 of the GDPR.

  1. Description of Processing Activities

Ignito processes personal data solely for the purposes defined by the Client and in accordance with the documented instructions set out in Section 5.

A detailed description of the processing activities, categories of data, data subjects, and retention periods is set out in Annex A and in Ignito’s Privacy Policy, which is provided for information purposes.

Use of Client Data for Service Improvement and AI

Personal data processed under this Agreement is not used to train, fine-tune, or improve artificial intelligence or machine learning models intended for use by other clients, unless the Client has expressly agreed in writing.

Ignito may use aggregated and irreversibly anonymized data that no longer constitutes personal data within the meaning of applicable regulations, for statistical, research, and service improvement purposes.

  1. Documented Instructions

Ignito processes personal data solely on the basis of documented instructions from the Client.

Documented instructions include:

  • the main agreement;

  • this DPA and its annexes;

  • the functional and technical documentation of the Ignito platform;

  • the parameters and configurations defined by the Client within the platform, including enabled integrations, roles, access rights, and analytical scopes.

Traceability of instructions

The configurations, parameters, integration choices, analytical scopes, roles, and access rights defined by the Client within the Ignito platform constitute documented instructions within the meaning of Article 28 of the GDPR.

These elements are retained by Ignito for traceability purposes for the duration of the agreement.

Ignito will inform the Client if it considers that an instruction constitutes a breach of the GDPR or any other applicable provision.

The Client warrants that its instructions comply with applicable law, including Regulation (EU) 2016/679 (GDPR), labor law, and rules relating to the protection of the rights and freedoms of data subjects.

The Client remains solely responsible for determining the purposes and essential means of processing, as well as for its use of the analyses, indicators, and recommendations provided by the Ignito platform.

  1. Processor Obligations

Ignito undertakes to:

  1. process personal data solely in accordance with the Client’s documented instructions;

  2. ensure the confidentiality of the personal data processed;

  3. ensure that persons authorized to process the data are subject to an appropriate confidentiality obligation;

  4. not use personal data for its own purposes, or for commercial or advertising purposes;

  5. implement the technical and organizational measures described in Annex B;

  6. assist the Client in meeting its GDPR obligations;

  7. notify any personal data breach without undue delay;

  8. delete or return personal data at the end of the agreement.

  1. Assistance to the Controller

Ignito will assist the Client, to the extent reasonably possible and taking into account the nature of the processing, in:

  • responding to requests from data subjects exercising their rights;

  • carrying out, where applicable, data protection impact assessments (DPIAs);

  • complying with the obligations set out in Articles 32 to 36 of the GDPR;

  • cooperating with competent supervisory authorities.

Ignito will not respond directly to requests from data subjects without coordination with the Client, unless otherwise required by law.

Assistance provided by Ignito will be carried out:

  • within reasonable timeframes, taking into account the complexity and volume of requests;

  • through the usual support and contact channels;

  • without obligation to respond to manifestly unfounded, excessive, or repetitive requests.

Assistance is provided within the limits of the Processor’s reasonable technical capabilities. Any assistance beyond the normal scope of Article 28 obligations, including specific developments, complex extractions, and dedicated technical audits, may be subject to additional billing based on Ignito’s current rates, upon prior acceptance of a quote by the Client.

  1. Data Security

Ignito implements appropriate technical and organizational measures, in line with the state of the art and proportionate to the risks, in order to ensure an appropriate level of security.

These measures are described in Annex B and include in particular:

  • encryption of data in transit (TLS 1.2+) and at rest (FIPS 140-2-compliant standards);

  • strict access control (least privilege principle, MFA for administrator access);

  • logging and monitoring of access and processing activities;

  • formalized security incident management procedures.

  1. Sub-Processors

Ignito is authorized to engage sub-processors for the performance of all or part of the Service.

The list of authorized sub-processors is set out in Annex C.

Ignito will inform the Client of any material change to this list, in particular in the event of the addition or replacement of a sub-processor, by updating Annex C or by any other appropriate means.

Ignito remains fully liable to the Client for the performance by any sub-processor of its data protection obligations in accordance with this DPA.

Ignito ensures that any sub-processor is bound by contractual obligations imposing requirements at least equivalent to those set out in this DPA, in particular regarding confidentiality, security, and GDPR compliance.

The Client has thirty (30) calendar days from the date of receipt of such notification to submit written objections, on legitimate and documented grounds related to data protection.

In the absence of objection within that period, the Client is deemed to have accepted the new sub-processor. In the event of a substantiated objection, the Parties will endeavor to find a mutually acceptable solution. If no solution is found, Ignito may terminate the service without penalty, as the security or continuity of the service can no longer be guaranteed without the relevant sub-processor.

  1. Data Transfers Outside the European Union

We favor data localization within the European Union whenever possible. However, some providers may process data outside the EU.

When personal data is transferred outside the European Economic Area, Ignito ensures that such transfers are governed by appropriate safeguards in accordance with applicable regulations, including the implementation of Standard Contractual Clauses adopted by the European Commission (primarily Module Two: Controller to Processor) or any other transfer mechanism validated by applicable regulations.

Where a transfer of personal data outside the European Union is based on Standard Contractual Clauses, Ignito implements, where necessary, supplementary measures designed to ensure a level of protection substantially equivalent to that guaranteed within the European Union, including in particular:

  • data encryption;

  • data minimization;

  • strict access restrictions.

Where required, Ignito carries out a Transfer Impact Assessment (TIA), in accordance with the recommendations of the European Data Protection Board (EDPB), to assess and document the risks associated with transfers of personal data outside the European Union.

Information regarding transfers and associated safeguards is set out in Annex C.

  1. Personal Data Breaches

In the event of a personal data breach, Ignito will:

  • notify the Client without undue delay after becoming aware of the breach and, to the extent possible and taking into account the information available at that stage, within a maximum period of forty-eight (48) hours;

  • provide the Client with the information necessary to assess the incident and fulfill its notification obligations;

  • cooperate with the Client in the management and remediation of the incident.

  1. End of Agreement – Return or Deletion of Data

Upon expiration or termination of the agreement, Ignito will, at the Client’s choice, either delete or return the personal data processed on its behalf.

By way of exception, the Client agrees that Ignito may carry out irreversible anonymization of certain personal data rather than deletion, prior to any reuse.

Anonymization is carried out using state-of-the-art methods, ensuring that the data:

  • no longer allows any direct or indirect identification of the data subjects;

  • cannot be re-identified, including through cross-referencing;

  • definitively falls outside the scope of Regulation (EU) 2016/679.

Anonymization is carried out using robust methods taking into account in particular:

  • the risk of re-identification through cross-referencing;

  • the size of the populations concerned;

  • the organizational and sectoral context.

Ignito ensures that anonymized data does not allow any individualization, including indirect, and is not used to produce analyses specific to an identifiable Client or organization.

Such anonymized data may be retained by Ignito exclusively for:

  • statistical purposes;

  • overall platform and model improvement purposes,

with no individualized or organization-specific processing being possible.

Deletion (or anonymization) extends to backups within 30 days, subject to any legal retention obligations.

  1. Audits

The Client may verify Ignito’s compliance with this DPA through a documentary audit, subject to the following conditions:

  • the audit is limited to a maximum frequency of once per twelve (12)-month period, except in the event of a confirmed security incident or legal obligation;

  • the Client notifies Ignito of its audit request in writing with a minimum thirty (30) days’ prior notice;

  • the audit is conducted during business hours and in a manner that does not disrupt the continuity of Ignito’s activities;

  • the audit is limited to the elements strictly necessary to verify compliance with this DPA;

  • information communicated in the context of the audit is subject to a strict confidentiality obligation;

  • the costs of the audit are borne entirely by the Client. In addition, the time spent by Processor personnel in assisting with the audit beyond one working day may be subject to additional billing. Applicable rates are communicated by Ignito upon prior written request from the Client and are subject to a quote accepted by the Client before any commitment.

Ignito reserves the right to frame, adjust, or restrict any audit request that could compromise system security, trade secrets, or the data of other clients.

In order to limit the operational burden associated with audits, Ignito may, where available, satisfy the Client’s request by providing:

  • security and data protection policies;

  • relevant technical documentation;

  • third-party compliance attestations or reports, where applicable.

The use of such materials may substitute, in whole or in part, for an on-site audit, subject to the Client’s acceptance.

  1. Absence of Surveillance, Individual Evaluation, and Automated Decision-Making

The Parties acknowledge that the Ignito platform:

  • does not constitute a tool for individual, continuous, or intrusive surveillance of employees or contractors;

  • is not designed to measure individual performance or to carry out professional, disciplinary, or managerial evaluations;

  • does not implement any fully automated decision-making producing legal effects or similarly significant effects on data subjects, within the meaning of Article 22 of Regulation (EU) 2016/679.

The Ignito platform provides exclusively informational and organizational analyses, indicators, and recommendations, intended to support human decision-making.

Any interpretation, decision, or action taken on the basis of results provided by the platform falls exclusively under the Client’s responsibility, which remains the sole decision-maker.

The Client undertakes to use the Ignito platform in compliance with applicable law, including in particular:

  • labor law;

  • personal data protection rules;

  • the principles of fairness, proportionality, and transparency toward data subjects.

The Client acknowledges that it is solely responsible for:

  • the prior and ongoing information of data subjects regarding the processing activities implemented;

  • compliance with applicable labor law obligations;

  • where applicable, consultation of the relevant employee representative bodies.

Ignito shall not be held liable for use of the platform:

  • for individual surveillance or disciplinary purposes;

  • for automated or quasi-automated decision-making;

  • or, more generally, for use not in compliance with applicable law or the provisions of this DPA.

  1. Governing Law

This DPA is governed by French law.

Any dispute relating to its interpretation or performance falls under the jurisdiction defined in the main agreement.

Annex A – Description of Processing Activities and Retention Periods

General principles

This policy defines the retention periods for personal data processed by Ignito in accordance with the storage limitation principle set out in Article 5(1)(e) of the GDPR.

Personal data is retained only for as long as necessary for the purposes for which it is processed, then archived or deleted in accordance with legal obligations.

  1. Account and authentication data

Category of data
Description
Retention period
Trigger / Notes
Identity dataLast name, first name, email, avatar, organization, rolesDuration of active accountDeletion within 30 days after closure
OAuth tokens & authentication dataAccess tokens, refresh tokens, sessionsSession validity period (max. 30 days)Automatic rotation
Connection logs & IP addressesLogin history, IP addresses12 monthsSecurity and incident detection
Inactive account – notificationWarning to the user18 months of inactivityPrior notification
Inactive account – deletionAutomatic account deletion24 months of inactivityUnless justified objection or legal obligation
Billing dataInvoices, accounting information10 yearsLegal tax and accounting obligations
Security logs related to incidentsLogs related to confirmed incidentsResolution + 12 monthsTraceability and defense
  1. Synchronization data (calendars, tasks, messaging)

Category of data
Description
Retention period
Trigger / Notes
Calendar eventsGoogle Calendar, OutlookRolling 12 monthsAutomatic deletion.
TasksJira, Linear, equivalent toolsRolling 12 monthsAutomatic deletion
Messaging metadataSlack, Teams (no content)Rolling 12 monthsAutomatic deletion
Aggregated data & statisticsIndicators, analytics, opportunitiesDuration of active accountAnonymization after closure
Fully anonymized dataGlobal statisticsUnlimitedOutside GDPR scope

*Note: For events involving external third parties, the Client warrants that it has the necessary legal basis to allow synchronization of such data to the platform.

  1. Communication data

Category of data
Description
Retention period
Trigger / Notes
Transactional emailsService-related notifications12 monthsTraceability and support
In-app historyInternal messages and notificationsDuration of active accountDeletion after closure
Customer supportTickets and exchanges3 years after resolutionCustomer relationship management
Litigation-related dataElements necessary for defenseDuration of proceedings + statute of limitationsLegal obligation
  1. Technical and telemetry data

Category of data
Description
Retention period
Trigger / Notes
Application logsTechnical and application logs12 monthsMonitoring and maintenance
Security logsIncident detection and investigation12 months (or resolution + 12 months)Security
Application usage dataRaw telemetry12 monthsTechnical analysis
Anonymized metricsPerformance and stabilityUnlimitedNon-personal data
Aggregated statisticsConsolidated usage dataDuration of active accountAnonymization after closure
  1. Deletion and archiving procedures

Process
Description
Timeframe
Logical deletionMarked as deletedImmediate
Physical deletionPermanent deletion≤30 days
Backup deletionFull backup rotation≤30 days
Sub-processor deletionContractual instruction≤30 days
Intermediate archivingRestricted access, enhanced encryptionAs per legal obligations

Exceptions and derogations

Authorized extended retention

  • Legal obligations: retention in accordance with statutory periods (e.g., 10 years for accounting data)

  • Litigation: retention until all avenues of appeal are exhausted

  • Public interest: statistical archiving using anonymized data

  • Specific consent: extended retention where the data subject has given explicit consent

Security data

In the event of a security incident or investigation:

  • Extended retention of relevant logs and data

  • Duration limited to resolution of the incident + 12 months

  • Documentation of the justification

Annex B – Technical and Organizational Measures

(Article 32 GDPR)

Ignito implements appropriate technical and organizational measures, in line with the state of the art, to ensure a level of security appropriate to the risks presented by the personal data processing activities carried out on behalf of the Client.

These measures are designed in particular to ensure the confidentiality, integrity, availability, and resilience of processing systems and services, through a multi-layered approach (defense in depth) integrated from the design stage.

  1. Security governance

  • Security is integrated from the design stage of services (security by design).

  • Roles and responsibilities for security and data protection are clearly defined.

  • The Data Protection Officer (DPO) oversees GDPR compliance matters.

  • Security and data protection policies are documented, enforced, and regularly reviewed.

  1. Data protection and encryption

2.1. Encryption in transit

  • All network communications are protected by TLS 1.2 or higher encryption.

  • Unsecured protocols are prohibited in production environments.

2.2. Encryption at rest

  • Sensitive stored data, including databases, backups, and persistent storage, is encrypted at rest.

  • Encryption mechanisms are based on recognized standards, FIPS 140-2 compliant or equivalent.

2.3. Key management

  • Encryption keys are securely stored, protected, and managed.

  • Strict policies on rotation, access, and separation of duties are applied in accordance with industry best practices.

  1. Network and infrastructure security

  • Production, test, and development environments are strictly isolated.

  • Network access is restricted by strict filtering rules (ingress / egress).

  • Infrastructure is hosted with recognized cloud providers meeting high security and compliance standards.

  • Systems are hardened in accordance with best practices and kept up to date through regular security patches.

3.1. Perimeter protection

  • A Web Application Firewall (WAF) is deployed to protect against common attacks such as SQL injection, XSS, CSRF, and automated scans.

  • Rate limiting, filtering, and malicious traffic detection mechanisms are enabled.

  1. Access and identity management

  • The least privilege principle is applied to all system and data access.

  • Access to sensitive environments is strictly limited to authorized personnel on a need-to-know basis.

  • Multi-factor authentication (MFA) is mandatory for administrator and privileged access.

  • Access rights are subject to regular reviews.

4.1. Access traceability and logging

  • Access to systems and sensitive operations are logged.

  • Logs are protected against tampering, accessible only to authorized personnel, and retained for a limited period.

  1. Secure software development

  • Ignito applies a Secure Development Lifecycle (SDLC).

  • Software updates are subject to:

    • peer code reviews;

    • automated tests integrated into the continuous integration pipeline.

  • Third-party dependencies are monitored to identify and remediate known vulnerabilities.

  • Development, test, and production environments are strictly separated.

  1. Monitoring, logging, and detection

  • Systems and applications are subject to continuous monitoring to detect anomalies, failures, or suspicious behavior.

  • Application and technical logs are collected and stored securely.

  • Access to logs is strictly restricted.

  1. Incident management and data breaches

  • Ignito has a formalized security incident management procedure.

  • This procedure covers in particular:

    • incident detection and analysis;

    • containment and remediation;

    • assessment of the impact on personal data;

    • documentation of the incident.

  • In the event of a personal data breach, Ignito notifies the Client without undue delay, in accordance with the DPA and the GDPR.

  1. Business continuity and resilience

  • Regular backup mechanisms are implemented to ensure data availability.

  • Backups are protected against unauthorized access.

  • Restoration procedures are periodically tested.

  • Architectures are designed to minimize single points of failure and strengthen operational resilience.

  1. Sub-processor management

  • Technical sub-processors are selected on the basis of security and compliance guarantees.

  • They are bound by contractual commitments including confidentiality and data protection obligations.

  • Data transfers outside the European Union are governed by recognized mechanisms such as SCC, DPF, or equivalent.

  1. Awareness and confidentiality

  • Persons authorized to process personal data are subject to a confidentiality obligation.

  • Access to personal data is limited to persons whose functions require it.

  1. Continuous evaluation and improvement

  • Security measures are regularly assessed and updated to take into account:

    • the evolving threat landscape;

    • the state of the art;

    • regulatory and technical developments.

Annex C – Sub-Processors and Non-EU Transfers

The transfers of personal data outside the European Union referred to in this annex may include transfers for technical transit purposes, in particular via content delivery networks (CDNs), hosting, or ancillary service provision.

Where indicated, certain sub-processors do not carry out any persistent storage of personal data and are involved solely in transient or technical processing.

Sub-processors

Sub-processors with potential non-EU transfers

  • Cloudflare (CDN – Global)

  • Vercel (CDN – Global)

  • Mailgun (email – Global)

  • Google (identity and account services – Global)

  • Microsoft (identity and account services – Global)

  • Slack (identity and account services – Global)

  • Framer (marketing website – US – Global)

Each sub-processor is governed by appropriate safeguards (SCC, DPA, DPF), in accordance with Ignito’s sub-processor and non-EU transfer register.

For any legal or regulatory questions, please contact: legal@ignito.ai