Data processing agreement (DPA)

Version of July 19, 2026. This agreement is an integral part of theterms for any customer acting as controller. It is the written agreement required by article 28 GDPR. The French version prevails.

1. Parties and roles

The customer (you, holder of the organization in Menestrel) is the controller of the data entrusted to the service: the content of their sites and the data of the people they invite as editors. Agoraios Application (SAS), enseigne Agora Studio, SIREN 908 978 653, 6 impasse de l'Église, 42580 L'Étrat, France, is the processor.

2. Subject matter, nature and duration

Hosting, storage, technical transformation (image processing, publication snapshots), delivery of content to the customer's sites, and management of the organization's editor accounts. Processing lasts as long as the customer's account exists, plus the 30 day purge window.

3. Categories of data and data subjects

Data subjects: the editors invited by the customer, and any person whose data appears in the content the customer publishes. Categories: editor identity and contact details (email, name), editorial content and media. The customer undertakes not to entrust special categories of data (article 9 GDPR) to the service without prior written agreement.

4. Instructions

We process this data only on the customer's documented instructions, materialized by the use of the service (create, publish, delete, export) and this agreement. We inform the customer if an instruction appears to infringe the GDPR, or if Union or member state law requires a specific processing.

5. Confidentiality and security

Persons authorized to process the data are bound by confidentiality. Technical and organizational measures: TLS in transit, sensitive secrets encrypted at rest (AES-256-GCM), hashed passwords (scrypt), strict isolation between organizations verified by an automated test suite run on every code change, per-organization activity log, encrypted backups with tested restoration, two-factor authentication available, hosting in the European Union (Paris region).

6. Sub-processors

The customer authorizes the following sub-processors:

Any addition or replacement is announced by email at least 30 days in advance; the customer may object in writing, and an unresolved objection opens a right to terminate without penalty. Each sub-processor is bound by obligations equivalent to this agreement. Stripe is not a sub-processor under this agreement: it processes the customer's billing data on our own behalf.

7. Transfers outside the European Union

The processing covered by this agreement takes place in the European Union. No transfer outside the EU occurs for the entrusted data, unless instructed otherwise by the customer (for example a deploy target they choose outside the EU, under their responsibility).

8. Assistance

We assist the customer, taking the nature of the processing into account: answering data subject requests (export and deletion are directly available in the service), security, impact assessments where relevant. Any personal data breach likely to result in a risk is notified to the customer without undue delay and at the latest 72 hours after we become aware of it, with the information listed in article 33 GDPR.

9. End of processing

At the end of the contract, the customer retrieves all their data through the export command (markdown, JSON, media). Data is then deleted within 30 days, backups purged along their rotation, save for legal retention obligations.

10. Audit

We make available the information necessary to demonstrate compliance with this agreement. The customer may conduct, at their own expense, one audit per 12 month period, with 30 days written notice, during business hours, without access to other customers' data; a written questionnaire is the first audit level.

Data contact: bonjour@menestrel.dev.

Back to the homepage