ArkiaSuite Back to the site FR

Version 1.0 · updated 8 September 2026

Data processing agreement

Article 28 of the GDPR. What we are allowed to do with the data you entrust to us — your customers’, your residents’, your members’, your staff’s — and what we forbid ourselves.

This agreement concerns you if you use ArkiaSuite for your activity: a company, a self-employed professional, an association, a local authority or any other public body. In that case the law calls you the controller — you are the one who decides what becomes of the data of the people you serve — and it calls us the processor: all we do is keep the machines running.

It does not concern you if you are a private individual filing your own photos and your own emails. The GDPR does not apply to purely personal matters (article 2). What protects you is our privacy policy.

How this agreement is concluded. You accept it online, by ticking « read and approved » when you create your account or place an order. That acceptance is dated and kept: it is what allows us to prove, to you and to the French data protection authority, that the agreement exists.

If your organisation requires a signed document for its records — which is the case for most public bodies — annex 3 is made to be printed and signed. The text is the same, word for word. Go to the page to sign →

Courtesy translation. This page is provided in English so that you can read it. Only the French version is legally binding: it is the one the contract is made in, and the one a French court would read. Where the two differ, the French text prevails.

1. Between whom, and about what

On one side GS Informatique, EURL, SIREN 925 179 079, 26 bis rue de la Mairie, 73460 Frontenex, France, represented by Gerald Sonzogni — the processor. On the other you, holder of the ArkiaSuite account — the controller.

This agreement governs the processing we carry out for you as part of the ArkiaSuite service. It supplements our terms and conditions of sale and our privacy policy, of which it forms an integral part. Where the three contradict one another on a data protection point, this agreement prevails.

It does not cover the data for which we are ourselves the controller: your name, your billing address, your invoices, our support exchanges. Those come under our privacy policy.

2. What we process, and why

Article 28.3 of the GDPR requires this to be written down in black and white. Here it is.

Subject matter To host and make available a file space, a mail service, documents, a calendar, contacts and photos.
Nature of the operations Storage, transmission, backup, restoration, indexing for your own searches, deletion. Nothing else.
Purpose To provide you with the service you subscribed to, and only that.
Duration The whole term of your subscription, then the return and erasure periods of article 10.
Data concerned Whatever you upload: we do not choose it and we do not know it. The detail per module is in annex 1.
Data subjects The people whose data you process: your customers, residents, members, staff, suppliers, correspondents.

One consequence, better said straight away: if you upload sensitive data within the meaning of article 9 — health, opinions, trade union membership, biometric data — you do so under your own responsibility. We cannot know what a file we do not read contains. It is for you to judge whether our level of security, described in annex 2 with nothing dressed up, suits what you entrust to us.

3. We act only on your instructions

We process your data only on your documented instruction. Your instruction is the agreement itself and the use you make of the service: what you upload, what you share, what you erase.

We touch it outside of that in three cases only, and no others:

If one of your instructions seems to us contrary to the GDPR, we say so and we may suspend carrying it out.

4. Who can see your data

One person only: Gerald Sonzogni, manager and only employee of GS Informatique. There is no support team, no outsourced on-call rota, no managed services provider. That is at once our best guarantee and our limit, and we prefer to write it down.

Administrator access technically makes it possible to read your files — which is true of every host that does not do end-to-end encryption, and we do not claim to. It is used only in the three cases of article 3. Anyone who came to hold that access would be bound by a written confidentiality undertaking, surviving the end of their assignment.

5. How we protect what you upload

The technical and organisational measures of article 32 of the GDPR are set out in annex 2, with their limits. In short: every link encrypted, passwords never stored in clear text, two-factor authentication available, daily verified backups on two sites 40 km apart, and encrypted as soon as they leave our premises.

The limit, written here rather than elsewhere: at rest, on site, the disks are not encrypted. They are in a locked rack, in a private room. Encryption whose key sleeps next to the disk would have protected nothing more — but it is a lock that protects them, not mathematics, and you need to know that in order to decide.

We review these measures at least once a year, and at every change to the service.

6. Our own subprocessors

No third party touches your content. None.

No hosting company, no rented data centre, no backup at a storage operator, no antivirus service in the cloud, no analytics tool. Your files and your emails are readable only by our own machines, in Frontenex and in Faverges. That is what sets us apart most sharply from the offers you compare us with, and it is also what costs us most.

Three third parties do intervene, on something other than your content. Here they all are:

WhoWhat forWhat they see
Stripe Payments Europe
Ireland
To take card payments Your card and your billing address, never your content. We never have your card number.
Have I Been Pwned
k-anonymity
To check that a chosen password does not appear in a known breach Five characters of a hash. Neither the password, nor the address, nor the username leaves.
Let’s Encrypt
Certificate authority
To issue the certificates that encrypt your connections The domain names, nothing else.

You authorise us to use these three. If we had to add a fourth, we would tell you at least one month beforehand. You could then object, and cancel with no charge and no penalty if we kept to our choice.

7. No transfer outside Europe

Your data does not leave the European Union. It does not in fact leave Savoie and Haute-Savoie, apart from the journey to your screen.

We are subject to no extraterritorial data disclosure law. GS Informatique is a French company, owned by a French person, whose machines are all in France: the American CLOUD Act, which lets a United States authority demand data from a company under American law wherever it is stored, cannot apply to us. That is a difference in kind, not in degree, from hosting at Microsoft, Google or Amazon — including when they announce servers in France.

Any legal demand reaching us would therefore come from a French or European authority, within a judicial framework you can contest. We would tell you about it, unless the law forbade it.

8. If someone exercises their rights with you

Access, rectification, erasure, portability, objection: those requests are addressed to you, and it is for you to answer them. We help you.

In practice, most of the time you will need nobody: you can export, correct and delete yourself, at any time, without asking us for anything. If a case goes beyond what the interface allows, write to contact@arkiasuite.fr: we answer within 5 working days, and we do not charge for that help.

If a data subject contacts us directly, we do not answer in your place: we refer them back to you and we let you know.

We help you in the same way with your obligations under articles 32 to 36: impact assessment, prior consultation of the supervisory authority, security. Our part is to give you the information only we hold.

9. If our data is breached

We tell you within 48 hours of the moment we become aware of it. That deadline is not chosen at random: the law gives you 72 hours to notify the supervisory authority, so you have 24 left in which to decide.

The message will tell you, at the very least:

If everything is not known after 48 hours, we send what we know and complete it afterwards. We do not notify the supervisory authority in your place — the law does not allow us to: that is your obligation, not ours.

We will also tell you if we received a court order concerning your data, so far as the law allows us to.

10. What happens to your data when you leave

You wait for nothing from us to get your files back. They are downloadable at any time, in their original format, for the whole term of the agreement and for the 30 days that follow its end. Leaving us requires no permission from anyone.

After those 30 days, we erase everything: the account, the files, the mail, the calendar, the contacts, the photos. The backup copies disappear in their turn within 30 days at the latest, the time it takes for the rotation to come round — so 60 days at most after the end of the agreement for the last trace.

We then keep only the data the law obliges us to keep: invoices for 10 years (accounting obligation) and connection logs for 1 year (host obligation). Neither of them contains your content.

On request, we send you a certificate of erasure, dated and signed. It is free, and it is often the document missing from a public body’s file.

11. Checking that we tell the truth

On simple request we provide you with all the information needed to demonstrate compliance with article 28 — including the detail of our security measures and the up-to-date list of our subprocessors.

You may have an audit carried out, once a year, by yourself or by an independent auditor you appoint, with 30 days’ notice and subject to a confidentiality undertaking. We answer it in good faith and free of charge.

And one thing almost nobody else can offer you: come and see. Our servers are in Frontenex, at an address you can type into a GPS. We welcome customers who want to see the rack, the disks and the backups with their own eyes, by appointment. A security audit that ends with a ten-minute visit is worth more than a framed certificate.

12. Records, liability, term

We keep the record of categories of processing carried out on your behalf, required by article 30.2 of the GDPR, and we send it to you on request.

Each party answers for its own breaches under articles 82 and 83 of the GDPR. For the rest — the extent and cap of our contractual liability — article 8 of the terms and conditions of sale applies.

This agreement takes effect on your acceptance and lasts as long as your subscription, plus the periods of article 10. We may amend it; any change affecting your rights is announced to you by email at least one month before it comes into force, and you may cancel free of charge before that date. This document always states its version and its date, at the top of the page.

French law. In the event of disagreement, write to us first: contact@arkiasuite.fr or +33 9 51 56 59 54.

The detail, module by module

What each part of the service actually processes. The retention periods are those of our privacy policy, repeated here so that a single document is enough for your records.

ModuleData processedRetention
Cloud The files you upload, their name, their date, their shares As long as you keep them
Mail Messages received and sent, attachments, correspondents’ addresses, technical headers As long as you keep them
Documents The content of documents opened for editing, and their successive versions As long as you keep them
Calendar & contacts Appointments, participants, places, contact cards As long as you keep them
Photos Images and videos, their metadata (date, device, and the place if it is there) As long as you keep them
Account Username, contact address, phone number if you gave one Life of the account, then 30 days
Authentication Hash of the password — never the password Life of the account
Connection logs IP address, date, service used 1 year (host obligation)
Technical logs Traces of the web server running 6 months
Billing Amount, date, plan, billing details 10 years (accounting obligation)

Face recognition in the Photos module, if you switch it on, runs on our machines and does not leave them. The computed signatures serve only your own searches, and disappear with the photos. It can be switched off.

The security measures, and their limits

Article 32 of the GDPR. Every line says what is in place; the last two say what is not.

The page to sign

Accepting online is legally sufficient. This page exists for organisations whose procedure requires a signed document on file — a data protection officer, a public procurement process, an auditor. Print this page (it comes out on its own, the rest of the site does not print), sign it, and send it back to contact@arkiasuite.fr: we return it to you countersigned.

Data processing agreement within the meaning of article 28 of the GDPR
Version 1.0 of 8 September 2026 · arkiasuite.fr/en/data-processing.html

The undersigned controller and GS Informatique, EURL, SIREN 925 179 079, 26 bis rue de la Mairie, 73460 Frontenex, France, agree that the processing of personal data entrusted within the ArkiaSuite service is governed by articles 1 to 12 of the document above, which the parties acknowledge having read and accept without reservation.

Organisation

Address

Company number

Represented by

Capacity

ArkiaSuite account

Data protection officer

For the controller

For GS Informatique

One document to send back, one signature, and it is settled. If your organisation has its own data processing agreement template, send it over: we study it and we sign it if it does not make us promise what we cannot keep.