Data Processing Addendum
Last updated: September 2026
This Data Processing Addendum (DPA) forms part of the Terms of Service for B2B customers where DappIT processes personal data contained in customer content on behalf of the customer. For a signed copy or questions, write to privacy@dappit.fr.
1. Parties
This DPA forms part of the agreement between:
| Party | Role |
|---|---|
| Customer | Controller, or processor acting on behalf of its own controller |
| DappIT | Processor, or subprocessor where Customer is a processor |
2. Scope
This DPA applies when DappIT processes personal data contained in customer content for the purpose of providing Pragma.
It does not apply to personal data processed by DappIT as controller, such as account administration, product analytics, support, security, billing-access records, or direct communications with users. Those activities are described in the privacy policy.
3. Customer instructions
DappIT will process customer personal data only:
- to provide, secure, maintain, and support the Service;
- as documented in the Agreement, Terms, privacy policy, and this DPA;
- as otherwise instructed by Customer;
- as required by applicable law.
4. Details of processing
| Subject matter | Provision of a B2B project-management SaaS |
|---|---|
| Duration | Subscription term plus 30-day post-cancellation export window, subject to backup and legal retention |
| Nature of processing | Hosting, storage, display, indexing, backup, search, RAG embeddings, AI assistant processing, support, deletion/export |
| Purpose | Providing Pragma to Customer |
| Data subjects | Customer users, employees, contractors, clients, suppliers, project stakeholders, and other persons included in customer content |
| Data categories | Names, emails, roles, comments, project/task data, files, identifiers, logs, business metadata, and other data chosen by Customer |
| Special categories | Not intended or permitted unless expressly agreed in writing |
5. Confidentiality
DappIT will ensure that personnel authorized to process customer personal data are bound by confidentiality obligations and access customer personal data only on a need-to-know basis.
6. Security measures
DappIT will maintain appropriate technical and organizational measures, including:
- TLS encryption in transit;
- encryption at rest through managed encrypted volumes and S3 server-side encryption;
- AWS KMS for webhook secrets in cloud deployments;
- organization-scoped permissions;
- audited admin access;
- need-to-know cloud IAM access;
- managed encrypted backups;
- authentication through Ory Identity;
- optional TOTP 2FA;
- SSO for Enterprise customers.
Additional details are provided on the security page.
7. Subprocessors
Customer authorizes DappIT to use the subprocessors listed in the processors section of the privacy policy.
DappIT will maintain an up-to-date list of subprocessors and, where required by contract, provide notice of material changes.
8. International transfers
Customer personal data is primarily hosted in the EU, using AWS eu-west-1 Ireland, Couchbase Capella in Ireland, S3 in Ireland, Resend EU, and PostHog EU.
Some subprocessors may process data outside the EEA, including Sentry and Google AI / Gemini. Where required, DappIT will rely on appropriate transfer safeguards such as Standard Contractual Clauses and additional measures.
9. Assistance
Taking into account the nature of the processing, DappIT will provide reasonable assistance to Customer for:
- data subject requests;
- security obligations;
- personal-data breach notifications;
- data protection impact assessments, where applicable.
Assistance may be subject to reasonable limits or fees unless required by law or agreed in an Enterprise contract.
10. Personal-data breaches
DappIT will notify Customer without undue delay after becoming aware of a personal-data breach affecting customer personal data.
Notification will include available information about the nature of the breach, affected data, likely consequences, and measures taken or proposed.
11. Deletion and return
During the subscription, Customer may export organization data through self-serve JSON export.
After cancellation, the organization has a 30-day read-only export window. After that window, customer content may be permanently deleted, subject to backup expiry and legal obligations.
Backups are retained for 30 days on a rolling basis.
12. Audits
Upon reasonable request and subject to confidentiality, DappIT may provide information reasonably necessary to demonstrate compliance with this DPA.
On-site audits are not available for self-serve plans. Enterprise audit rights may be agreed separately.
13. Conflict
If this DPA conflicts with the Terms of Service, this DPA controls only for the processing of customer personal data as processor.