Version 1.0 · updated 8 September 2026
Data processing agreement
Article 28 of the GDPR. What we are allowed to do with the data you entrust to us — your customers’, your residents’, your members’, your staff’s — and what we forbid ourselves.
This agreement concerns you if you use ArkiaSuite for your activity: a company, a self-employed professional, an association, a local authority or any other public body. In that case the law calls you the controller — you are the one who decides what becomes of the data of the people you serve — and it calls us the processor: all we do is keep the machines running.
It does not concern you if you are a private individual filing your own photos and your own emails. The GDPR does not apply to purely personal matters (article 2). What protects you is our privacy policy.
How this agreement is concluded. You accept it online, by ticking « read and approved » when you create your account or place an order. That acceptance is dated and kept: it is what allows us to prove, to you and to the French data protection authority, that the agreement exists.
If your organisation requires a signed document for its records — which is the case for most public bodies — annex 3 is made to be printed and signed. The text is the same, word for word. Go to the page to sign →
Courtesy translation. This page is provided in English so that you can read it. Only the French version is legally binding: it is the one the contract is made in, and the one a French court would read. Where the two differ, the French text prevails.
1. Between whom, and about what
On one side GS Informatique, EURL, SIREN 925 179 079, 26 bis rue de la Mairie, 73460 Frontenex, France, represented by Gerald Sonzogni — the processor. On the other you, holder of the ArkiaSuite account — the controller.
This agreement governs the processing we carry out for you as part of the ArkiaSuite service. It supplements our terms and conditions of sale and our privacy policy, of which it forms an integral part. Where the three contradict one another on a data protection point, this agreement prevails.
It does not cover the data for which we are ourselves the controller: your name, your billing address, your invoices, our support exchanges. Those come under our privacy policy.
2. What we process, and why
Article 28.3 of the GDPR requires this to be written down in black and white. Here it is.
| Subject matter | To host and make available a file space, a mail service, documents, a calendar, contacts and photos. |
|---|---|
| Nature of the operations | Storage, transmission, backup, restoration, indexing for your own searches, deletion. Nothing else. |
| Purpose | To provide you with the service you subscribed to, and only that. |
| Duration | The whole term of your subscription, then the return and erasure periods of article 10. |
| Data concerned | Whatever you upload: we do not choose it and we do not know it. The detail per module is in annex 1. |
| Data subjects | The people whose data you process: your customers, residents, members, staff, suppliers, correspondents. |
One consequence, better said straight away: if you upload sensitive data within the meaning of article 9 — health, opinions, trade union membership, biometric data — you do so under your own responsibility. We cannot know what a file we do not read contains. It is for you to judge whether our level of security, described in annex 2 with nothing dressed up, suits what you entrust to us.
3. We act only on your instructions
We process your data only on your documented instruction. Your instruction is the agreement itself and the use you make of the service: what you upload, what you share, what you erase.
We touch it outside of that in three cases only, and no others:
- you ask us to, in writing or by phone, to help you out;
- a technical operation requires it — a restore, a migration, a database repair — and it is then as narrow as possible;
- the law obliges us to. In that case we tell you before acting, unless telling you is itself forbidden.
If one of your instructions seems to us contrary to the GDPR, we say so and we may suspend carrying it out.
4. Who can see your data
One person only: Gerald Sonzogni, manager and only employee of GS Informatique. There is no support team, no outsourced on-call rota, no managed services provider. That is at once our best guarantee and our limit, and we prefer to write it down.
Administrator access technically makes it possible to read your files — which is true of every host that does not do end-to-end encryption, and we do not claim to. It is used only in the three cases of article 3. Anyone who came to hold that access would be bound by a written confidentiality undertaking, surviving the end of their assignment.
5. How we protect what you upload
The technical and organisational measures of article 32 of the GDPR are set out in annex 2, with their limits. In short: every link encrypted, passwords never stored in clear text, two-factor authentication available, daily verified backups on two sites 40 km apart, and encrypted as soon as they leave our premises.
The limit, written here rather than elsewhere: at rest, on site, the disks are not encrypted. They are in a locked rack, in a private room. Encryption whose key sleeps next to the disk would have protected nothing more — but it is a lock that protects them, not mathematics, and you need to know that in order to decide.
We review these measures at least once a year, and at every change to the service.
6. Our own subprocessors
No third party touches your content. None.
No hosting company, no rented data centre, no backup at a storage operator, no antivirus service in the cloud, no analytics tool. Your files and your emails are readable only by our own machines, in Frontenex and in Faverges. That is what sets us apart most sharply from the offers you compare us with, and it is also what costs us most.
Three third parties do intervene, on something other than your content. Here they all are:
| Who | What for | What they see |
|---|---|---|
| Stripe Payments Europe |
To take card payments | Your card and your billing address, never your content. We never have your card number. |
| Have I Been Pwned |
To check that a chosen password does not appear in a known breach | Five characters of a hash. Neither the password, nor the address, nor the username leaves. |
| Let’s Encrypt |
To issue the certificates that encrypt your connections | The domain names, nothing else. |
You authorise us to use these three. If we had to add a fourth, we would tell you at least one month beforehand. You could then object, and cancel with no charge and no penalty if we kept to our choice.
7. No transfer outside Europe
Your data does not leave the European Union. It does not in fact leave Savoie and Haute-Savoie, apart from the journey to your screen.
We are subject to no extraterritorial data disclosure law. GS Informatique is a French company, owned by a French person, whose machines are all in France: the American CLOUD Act, which lets a United States authority demand data from a company under American law wherever it is stored, cannot apply to us. That is a difference in kind, not in degree, from hosting at Microsoft, Google or Amazon — including when they announce servers in France.
Any legal demand reaching us would therefore come from a French or European authority, within a judicial framework you can contest. We would tell you about it, unless the law forbade it.
8. If someone exercises their rights with you
Access, rectification, erasure, portability, objection: those requests are addressed to you, and it is for you to answer them. We help you.
In practice, most of the time you will need nobody: you can export, correct and delete yourself, at any time, without asking us for anything. If a case goes beyond what the interface allows, write to contact@arkiasuite.fr: we answer within 5 working days, and we do not charge for that help.
If a data subject contacts us directly, we do not answer in your place: we refer them back to you and we let you know.
We help you in the same way with your obligations under articles 32 to 36: impact assessment, prior consultation of the supervisory authority, security. Our part is to give you the information only we hold.
9. If our data is breached
We tell you within 48 hours of the moment we become aware of it. That deadline is not chosen at random: the law gives you 72 hours to notify the supervisory authority, so you have 24 left in which to decide.
The message will tell you, at the very least:
- what happened, and when;
- which categories of data and how many people are concerned, as far as we can establish;
- the likely consequences;
- what we have already done, and what we recommend you do.
If everything is not known after 48 hours, we send what we know and complete it afterwards. We do not notify the supervisory authority in your place — the law does not allow us to: that is your obligation, not ours.
We will also tell you if we received a court order concerning your data, so far as the law allows us to.
10. What happens to your data when you leave
You wait for nothing from us to get your files back. They are downloadable at any time, in their original format, for the whole term of the agreement and for the 30 days that follow its end. Leaving us requires no permission from anyone.
After those 30 days, we erase everything: the account, the files, the mail, the calendar, the contacts, the photos. The backup copies disappear in their turn within 30 days at the latest, the time it takes for the rotation to come round — so 60 days at most after the end of the agreement for the last trace.
We then keep only the data the law obliges us to keep: invoices for 10 years (accounting obligation) and connection logs for 1 year (host obligation). Neither of them contains your content.
On request, we send you a certificate of erasure, dated and signed. It is free, and it is often the document missing from a public body’s file.
11. Checking that we tell the truth
On simple request we provide you with all the information needed to demonstrate compliance with article 28 — including the detail of our security measures and the up-to-date list of our subprocessors.
You may have an audit carried out, once a year, by yourself or by an independent auditor you appoint, with 30 days’ notice and subject to a confidentiality undertaking. We answer it in good faith and free of charge.
And one thing almost nobody else can offer you: come and see. Our servers are in Frontenex, at an address you can type into a GPS. We welcome customers who want to see the rack, the disks and the backups with their own eyes, by appointment. A security audit that ends with a ten-minute visit is worth more than a framed certificate.
12. Records, liability, term
We keep the record of categories of processing carried out on your behalf, required by article 30.2 of the GDPR, and we send it to you on request.
Each party answers for its own breaches under articles 82 and 83 of the GDPR. For the rest — the extent and cap of our contractual liability — article 8 of the terms and conditions of sale applies.
This agreement takes effect on your acceptance and lasts as long as your subscription, plus the periods of article 10. We may amend it; any change affecting your rights is announced to you by email at least one month before it comes into force, and you may cancel free of charge before that date. This document always states its version and its date, at the top of the page.
French law. In the event of disagreement, write to us first: contact@arkiasuite.fr or +33 9 51 56 59 54.
The detail, module by module
What each part of the service actually processes. The retention periods are those of our privacy policy, repeated here so that a single document is enough for your records.
| Module | Data processed | Retention |
|---|---|---|
| Cloud | The files you upload, their name, their date, their shares | As long as you keep them |
| Messages received and sent, attachments, correspondents’ addresses, technical headers | As long as you keep them | |
| Documents | The content of documents opened for editing, and their successive versions | As long as you keep them |
| Calendar & contacts | Appointments, participants, places, contact cards | As long as you keep them |
| Photos | Images and videos, their metadata (date, device, and the place if it is there) | As long as you keep them |
| Account | Username, contact address, phone number if you gave one | Life of the account, then 30 days |
| Authentication | Hash of the password — never the password | Life of the account |
| Connection logs | IP address, date, service used | 1 year (host obligation) |
| Technical logs | Traces of the web server running | 6 months |
| Billing | Amount, date, plan, billing details | 10 years (accounting obligation) |
Face recognition in the Photos module, if you switch it on, runs on our machines and does not leave them. The computed signatures serve only your own searches, and disappear with the photos. It can be switched off.
The security measures, and their limits
Article 32 of the GDPR. Every line says what is in place; the last two say what is not.
- In transit — every link between you and us is encrypted (TLS), without exception, including the mail protocols.
- Passwords — never stored in clear text, never sent by email, checked against known breaches at the moment you choose them.
- Two-factor authentication — available on every account.
- Administrator access — one person only, by SSH key, never by password.
- Backups — daily, automatic, and above all verified: a backup whose restore nobody has tested is not a backup. Ours is tested, and failure raises an alert.
- Two sites — Frontenex (Savoie) and Faverges (Haute-Savoie), 40 km apart: far enough that a fire, a flood or a burglary cannot take both copies.
- Off-site backups — encrypted, because they travel.
- The remote site pulls, it does not receive — our servers hold no credentials for the backup site. Ransomware at the shop therefore cannot reach the spare copy.
- Physical access — locked rack, in a private room, away from any public space.
- No tracker, no advertising cookie on our sites; even the typefaces are served from our own servers.
- At rest, the disks are not encrypted. A lock protects them, not mathematics. Decided with full knowledge of the facts: on a running server the decryption key is in memory — encryption at rest protects against stolen disks, not against an intrusion.
- We do not do end-to-end encryption. The administrator can technically read a file. No host that offers you search, previews or antivirus can claim otherwise; we prefer to write it down rather than let you believe otherwise.
The page to sign
Accepting online is legally sufficient. This page exists for organisations whose procedure requires a signed document on file — a data protection officer, a public procurement process, an auditor. Print this page (it comes out on its own, the rest of the site does not print), sign it, and send it back to contact@arkiasuite.fr: we return it to you countersigned.
Data processing agreement within the meaning of article 28 of the GDPR
The undersigned controller and GS Informatique, EURL, SIREN 925 179 079, 26 bis rue de la Mairie, 73460 Frontenex, France, agree that the processing of personal data entrusted within the ArkiaSuite service is governed by articles 1 to 12 of the document above, which the parties acknowledge having read and accept without reservation.
Organisation
Address
Company number
Represented by
Capacity
ArkiaSuite account
Data protection officer
For the controller
For GS Informatique
One document to send back, one signature, and it is settled. If your organisation has its own data processing agreement template, send it over: we study it and we sign it if it does not make us promise what we cannot keep.