Data processing agreement (GDPR, article 28)
Version 1.0 – effective 1 October 2026
This agreement supplements the terms and conditions of sale and subscription. It binds the Client, as controller, and Tonappli (Marco Midrouillet, micro-entrepreneur, SIRET [SIRET], [ADRESSE]), as processor.
1. Purpose
Tonappli hosts and runs the Client's application. In this capacity, it processes the personal data of the Client's end customers on the Client's behalf, solely on documented instructions. The terms and conditions and the use of the application constitute instructions. If an instruction appears to infringe the GDPR, Tonappli informs the Client.
2. Term
This agreement applies for the entire duration of the subscription, and then until the data is returned and deleted as set out in section 9.
3. Description of processing
- Purposes: appointment booking, customer relationship management, confirmations and reminders, features specific to the Client's business.
- Data subjects: the Client's customers and prospects, users of the application.
- Categories of data: identity (first and last name), contact details (email, phone), appointments and service history, messages exchanged, preferences, and where applicable photos or notes entered by the Client.
- Sensitive data: the application is not designed for health data or other special categories (art. 9 GDPR). The Client undertakes not to enter such data without prior written agreement.
- Operations: collection, storage, consultation, modification, sending emails, export, deletion.
4. Tonappli's obligations
- Process the data solely for the purposes above.
- Ensure its confidentiality: only Marco Midrouillet has access, and only for support or maintenance.
- Never sell, rent or use the data for any other purpose.
- Keep a record of processing carried out on behalf of the Client.
5. Sub-processors
The Client authorises Tonappli to use the following sub-processors:
- Cloudflare (hosting, database, storage, security): data stored in the European Union.
- Resend (transactional email delivery): email address and content of messages sent.
Where data may be accessible from a country outside the European Union, the transfer is governed by the EU–US Data Privacy Framework or by the European Commission's standard contractual clauses. Tonappli imposes on its sub-processors obligations equivalent to those of this agreement. It informs the Client of any addition or replacement at least 30 days in advance; the Client may object and, failing agreement, cancel at no cost.
6. Security
- Encryption of data in transit (HTTPS) and at rest with the host.
- Admin access protected by strong authentication.
- Isolation of each Client's data.
- Regular backups.
- Security updates and data minimisation.
7. Data breach
Tonappli notifies the Client of any personal data breach without undue delay, and no later than 72 hours after becoming aware of it. The notification describes, as far as possible, the nature of the breach, the data and individuals concerned, the likely consequences and the measures taken. Tonappli helps the Client notify the CNIL (French data protection authority) and, where necessary, the individuals concerned.
8. Data subject rights and assistance
From their account, the Client can view, correct, export and delete data, enabling them to respond to requests for access, rectification, erasure, objection and portability. If an individual contacts Tonappli directly, the request is forwarded to the Client without delay. Tonappli also assists the Client, within reason, with any data protection impact assessment.
9. End of agreement: return and deletion
At the end of the subscription, the Client can export all their data for 30 days. Tonappli then deletes it, including copies, unless retention is required by law; backups are erased as they rotate, within a further 30 days at most. Tonappli confirms deletion on request.
10. Audit
Tonappli provides the Client with the information needed to demonstrate compliance with this agreement. An audit may be requested once a year, with 30 days' notice, at the Client's expense.
11. Client's obligations
The Client informs their own customers about the processing (privacy policy), has a legal basis for each processing activity and gives instructions that comply with the GDPR.