Data Processing Agreement
1. Parties and roles
This Data Processing Agreement ("DPA") is entered into between you ("Customer", acting as data controller) and Linoa Technologie, operated by Faiza Ammari (SIREN 530 002 815; SIRET 530 002 815 00047), 149 avenue du Maine, 75014 Paris, France, operating Calmping ("Calmping", "we", acting as data processor). It forms part of and is incorporated by reference into the Terms of Service. Where the two conflict on the processing of personal data, this DPA prevails.
2. Subject matter and duration
Calmping processes personal data only to provide the monitoring, alerting, incident-management, and status-page services you configure. Processing continues for the duration of your subscription and ends on account deletion or termination, subject to the deletion terms in section 10.
3. Nature, purpose and instructions
We process personal data only on your documented instructions, which are given through your use of the service and its configuration. We will not process personal data for any other purpose, and will inform you if we believe an instruction infringes applicable data-protection law. We will not sell personal data or use it for our own advertising or profiling.
4. Types of personal data and data subjects
Depending on how you use the service, personal data may include: account contact details (name, email); authentication data (hashed passwords, tokens); monitoring configuration and results that you enter; response evidence snippets captured from your targets; alert-recipient details; and audit/log data including IP addresses. Data subjects may include your personnel, administrators, and any individuals whose data appears in the systems or responses you choose to monitor.
5. Confidentiality
We ensure that persons authorised to process personal data are bound by an appropriate duty of confidentiality and process personal data only as needed to provide the service.
6. Security measures (Article 32)
We maintain technical and organisational measures appropriate to the risk, including: passwords hashed with bcrypt; integration keys, webhook URLs, and TOTP secrets encrypted at rest with AES-256-GCM; HttpOnly, __Host--prefixed session and CSRF cookies in production; rate limiting and an anti-abuse guard on outbound monitoring; encrypted transport (HTTPS); and daily database backups. A current summary is on the Security and Privacy pages.
7. Sub-processors
You provide general written authorisation for Calmping to engage the sub-processors listed on our Subprocessors page (currently Render for hosting, Resend for email, Stripe for billing, and browser push services, plus any integration you connect yourself). We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain responsible for their performance. We will give you notice before adding a new core sub-processor; if you object on reasonable data-protection grounds within 14 days, we will work with you in good faith or you may terminate the affected service.
8. International transfers
Where a sub-processor processes personal data outside the EEA (for example Render and Stripe in the United States), transfers are protected by an appropriate safeguard such as the EU Standard Contractual Clauses or the sub-processor's certification under the EU-US Data Privacy Framework. Details are available in each provider's own data-processing terms.
9. Assistance to the Customer
Taking into account the nature of the processing, we assist you with: (a) responding to data-subject requests to exercise their rights, including through the export and deletion features in Settings; and (b) your obligations for security, breach notification, and data-protection impact assessments, on request and taking into account the information available to us.
10. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide the information reasonably needed for you to meet your own notification obligations.
11. Deletion and return
On termination or account deletion, and at your choice, we delete or return the personal data we process on your behalf and delete existing copies, unless retention is required by law (for example accounting records kept for 10 years under Article L123-22 of the French Commercial Code). You can export your data as JSON and delete your account at any time from Settings.
12. Audits and information
On reasonable request and no more than once per year (unless required by a supervisory authority), we make available the information necessary to demonstrate compliance with this DPA, including relevant sub-processor documentation and certifications, subject to appropriate confidentiality safeguards.
13. Liability and governing law
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by French law, without prejudice to mandatory data-protection rules and the rights of data subjects.
14. Contact
Linoa Technologie, operated by Faiza Ammari (SIREN 530 002 815; SIRET 530 002 815 00047), 149 avenue du Maine, 75014 Paris, France. For DPA or data-protection requests, use the contact page.