Version 1.0 · Effective 01 September 2024
Between:
The Client (hereinafter the “Controller”)
and
ENRICH CRM SAS
3 Boulevard de Sebastopol, 75001 Paris, France
RCS Paris: 932 510 217 · VAT: FR29932510217
Capital social: 100,00 €
Represented by Sylvain Charmet, CEO
(hereinafter the “Processor”)
This DPA forms an integral part of the Main Agreement between the Parties. In case of conflict between this DPA and the Main Agreement, this DPA prevails. This agreement supersedes all prior data processing terms.
“GDPR”: Regulation (EU) 2016/679
“UK GDPR”: The Data Protection Act 2018 as amended
“Personal Data Regulations”: GDPR + French Data Protection Act (Loi n°78-17)
“EEA”: European Economic Area
All terms from Article 4 GDPR apply
Controller determines purposes/means of processing
Processor acts exclusively on Controller’s documented instructions
As described in Schedule 1: CRM services, data enrichment, analytics
Controller warrants lawful basis for processing and maintenance of processing records
Process data only per instructions
Ensure confidentiality through employee NDAs
Implement security measures per Schedule 2
Notify Controller within 48 hours of breach discovery
Delete all data within 30 days post-termination
Controller approves Sub-processors listed in Schedule 3
Notification via client dashboard
14-day objection period
Transfers outside EEA: EU Standard Contractual Clauses (2021/914)
Transfers outside UK: UK International Data Transfer Addendum
Clause | Selection |
Governing Law | French Law |
Jurisdiction | Courts of Paris |
Competent Authority | CNIL |
Annual audit rights with 30 days’ notice · Costs borne by Controller
Liability capped at the contract value.
French Law · Exclusive jurisdiction of Paris Commercial Court
Element | Description |
Nature/Purpose | CRM services, data enrichment, analytics |
Data Categories | Professional contact details, company info |
Data Subjects | Controller’s customers, employees, prospects |
Retention | Service duration + 30 days |
Technical:
AES-256 encryption for login credentials and tokens
SOC 2 Type II certified infrastructure
Organizational:
Employee confidentiality agreements
Access control policies (RBAC)
Breach response protocol (<1h escalation)
Name | Service | Location | Safeguards |
AWS | Cloud Hosting | USA | SCCs + ISO 27001 |
Stripe | Payment Processing | USA | DPF Certification |
PostHog | Analytics | USA | SCCs + DPF |
Google SERP | Online research | USA | ISO 27001/27017/27018 + SOC 2/3 + DPF |