Data Processing Agreement (DPA)
Last updated: 25 April 2026
This data processing agreement (“DPA”) supplements the Terms of Sale (Conditions Générales de Vente) and governs the processing of personal data carried out by Corely.me (SIREN 894 108 059, the “Processor”) on behalf of the Customer (the “Controller”), pursuant to Article 28 of the General Data Protection Regulation (GDPR — EU 2016/679; RGPD in French).
1. Definitions
Capitalised terms have the meaning given to them in the GDPR. Specific terms are defined in the CGU and CGV.
2. Subject matter of the processing
The Processor processes personal data for the sole purpose of providing the Corely Service to the Customer (the “Purpose”).
3. Description of the processing
| Item | Description |
|---|---|
| Nature of the processing | Hosting, storage, consultation, modification, deletion, backup |
| Categories of data subjects | The Customer's employees, executives, prospects, customers and suppliers; freelance subcontractors; payees reported in the DAS2 return (French annual declaration of fees paid); the Customer's end users. |
| Categories of data | Identification data (last name, first name, email, telephone), professional data (position, salary, contract), financial data (invoices, accounting entries, IBAN, bank transactions), tax data (SIRET, VAT), crypto data (wallet addresses), social security data (social security number, DSN — French nominative social declaration). |
| Sensitive data | No sensitive data within the meaning of Article 9 of the GDPR is processed by the Service by default. |
| Duration of the processing | Term of the Subscription + 30-day export period + statutory retention periods |
4. Obligations of the Processor
In accordance with Article 28 of the GDPR, Corely undertakes to:
- Process the data only on documented instructions from the Customer (constituted in particular by the CGV, the CGU and this DPA).
- Ensure that persons authorised to process the data are bound by a duty of confidentiality.
- Implement the technical and organisational measures described in Article 5.
- Comply with the conditions for engaging a sub-processor (Article 6).
- Assist the Customer in responding to requests from data subjects.
- Assist the Customer in complying with its personal data breach notification obligations.
- Return or delete the data at the end of the contract (Article 8).
- Make available the information necessary to demonstrate compliance with the DPA, and allow for audits to be conducted.
5. Technical and organisational measures
5.1 Technical security
- TLS 1.3 encryption in transit, AES-256 at rest.
- Password hashing with bcrypt (12 rounds).
- Multi-factor authentication available (TOTP).
- Rotation and expiry of access tokens (short-lived JWT + refresh).
- API keys hashed (SHA-256) in the database, never stored in plain text.
- Outgoing webhooks signed with HMAC-SHA256.
- Strict multi-tenant isolation via
orgId(never accepted from the user request body).
5.2 Organisational security
- Access to production data restricted to authorised personnel and logged.
- Strong password policy for administrators.
- Ongoing security awareness and training of personnel.
- Documented procedure for managing incidents and data breaches.
5.3 Availability and resilience
- Encrypted daily backups, retained for 30 days, point-in-time recovery.
- Multi-zone replication on the OVH infrastructure.
- 24/7 monitoring (Loki, Prometheus, Grafana).
5.4 Testing
- Penetration testing, frequency: bi-annual
- Code audit and security review before each major release.
- Responsible disclosure programme: contact@corely.me.
6. Sub-processors
The Customer expressly authorises Corely to engage the sub-processors listed below for the performance of the Service. Corely will inform the Customer by email or via the platform of any change (addition, replacement) with 30 days' notice, during which the Customer may object on legitimate grounds.
| Sub-processor | Role | Location | Safeguards |
|---|---|---|---|
| OVH SAS | Infrastructure hosting and storage | France (Roubaix) | ISO 27001, HDS, GDPR-compliant |
| Bridge SA | PSD2 bank synchronisation | France | Authorised by the ACPR, PSD2-compliant |
| Coinbase, Inc. (CDP) | Crypto wallet custody | United States | Data Privacy Framework, SOC 2 |
| Stripe Payments Europe Ltd. | Subscription payments | Ireland | GDPR-compliant, PCI-DSS |
7. Transfers outside the EU
Where a transfer outside the European Economic Area is necessary, Corely ensures that it is covered by :
- An adequacy decision of the European Commission;
- The EU-U.S. Data Privacy Framework for certified U.S. sub-processors;
- Failing that, Standard Contractual Clauses adopted by the Commission.
8. Return and deletion
At the end of the contract, the Customer has 30 days to export its data using the export features (CSV, JSON, FEC, Factur-X). After that period, Corely permanently deletes the data from the production servers.
Backups containing such data are erased within a further maximum period of 30 days, subject to the statutory retention periods for accounting records (10 years, Art. L123-22 of the French Commercial Code — Code de commerce).
9. Breach notification
In the event of a personal data breach affecting the Customer, Corely notifies the Customer without undue delay, and no later than 72 hours after becoming aware of it, at the contact address provided by the Customer. The notification contains:
- A description of the nature of the breach.
- The categories and approximate number of data subjects concerned.
- The likely consequences.
- The measures taken or proposed to mitigate the consequences.
- The DPO's contact details.
10. Audit
The Customer may, subject to a limit of one audit per year and 30 days' prior notice, request an audit of the data protection arrangements implemented by Corely. The audit may take the form of a written questionnaire, an exchange of documents, or an on-site visit (at the Customer's expense).
For Enterprise Customers, Corely provides a summary compliance report annually.
11. Cooperation with authorities
Corely informs the Customer of any request from a supervisory or judicial authority concerning the Customer's data, unless prohibited by law.
12. Changes
Corely may amend this DPA to take account of legal or technical developments. Any material change will be notified to the Customer with 30 days' notice.
13. Conflict with other contractual documents
In the event of any contradiction between the CGV, the CGU and this DPA regarding the protection of personal data, the DPA shall prevail.
14. DPO contact
- Email: contact@corely.me
- Postal address: 4 rue Copernic, 59700 Marcq-en-Baroeul, France