Skip to content

Data processing agreement (DPA) template

Use this template ONLY if the TokenVeil vendor (Joopin’s Lab) provides a support service that involves potential access to the data (assisted installation, support with access to the instance, managed operations). In a standard self-hosted deployment with no vendor access, this DPA is not needed: the vendor is then not a processor (see GDPR dossier, section 1).

This template is a starting point to have reviewed by legal counsel. Bracketed fields are to be filled in.


Between:

  • [Customer organization name], hereinafter “the Controller”,
  • Joopin’s Lab, hereinafter “the Processor”,

pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR).

This agreement frames the processing of personal data that the Processor may carry out on behalf of the Controller as part of [describe the service: installation, technical support, managed operations of the TokenVeil instance].

  • Nature: [installation / maintenance / technical support] of the TokenVeil solution.
  • Purpose: ensure the operation of the pseudonymization tool deployed at the Controller’s site.
  • Duration: the duration of the service contract.
  • Categories of data that may be approached during the service: [to specify. In principle none, since the vendor does not access the pseudonymized data or the mapping in normal operation].
  • Categories of individuals: the Controller’s staff and people mentioned in the processed content.

The Processor undertakes to:

  1. process the data only on the Controller’s documented instructions;
  2. ensure the confidentiality of the persons authorized to process the data;
  3. implement the security measures of Article 32 (see the annex security-measures.md);
  4. not engage a further sub-processor without prior written authorization;
  5. assist the Controller with rights requests and impact assessments;
  6. delete or return the data at the end of the service;
  7. notify any data breach as soon as possible (and at the latest within [24/48] hours).

The data stays hosted on the Controller’s infrastructure ([location: France / EU]). The Processor performs no transfer and no copy outside that infrastructure.

The AI provider chosen by the Controller (Anthropic, Google, OpenAI, Mistral, and so on) is a further sub-processor of the Controller itself, under its own contract/DPA. It only receives pseudonymized data. This agreement does not cover that relationship.

The applicable technical and organizational measures are described in the annexed security-measures.md document, which forms an integral part of this agreement.

8. Fate of the data at the end of the contract

Section titled “8. Fate of the data at the end of the contract”

At the end of the service, the Processor [deletes / returns] any data it may have accessed and destroys existing copies, unless a legal retention obligation applies.


Done at [place], on [date].

For the Controller: ______________________

For the Processor: ______________________