Data Processing Agreement
FR·EN
Last updated: 28 July 2026. Annex to the MargiPro Terms of Sale, concluded under Article 28 of Regulation (EU) 2016/679 (GDPR). This English text is an informational translation; the French version is the binding one (see Article 15).
Parties
Between: MargiPro, a French SAS registered with the R.C.S. of Romans under number 102 903 713, with its registered office at 55 Rue du Clos des Lys, 26750 Génissieux, France, hereinafter “the Processor”.
And: the business customer subscribing to the Service, as identified in the Terms of Sale, hereinafter “the Controller” or “the Customer”.
Article 1 — Purpose
This agreement sets out the conditions under which the Processor processes, on behalf of the Controller, the personal data necessary for the performance of the MargiPro Service.
It forms an integral part of the Terms of Sale. In the event of any conflict between the two documents regarding personal data protection, this agreement prevails.
It applies to the processing for which the Customer is the controller: the documents it uploads to the Service, the business data derived from them, and the data of the users it designates, insofar as that data is processed in order to deliver the Service to it.
The identification and login data of users is furthermore subject to processing for which MargiPro is the controller, for its own purposes of invoicing, security, fraud prevention, and management of the contractual relationship. That processing, together with processing relating to prospects, the content of support exchanges, and audience measurement, is governed by the Privacy policy and falls outside the scope of this agreement.
Article 2 — Description of the processing
The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex 1.
Article 3 — Documented instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country.
The Terms of Sale, this agreement, and use of the Service in accordance with its documentation constitute the Controller’s documented instructions.
The Processor immediately informs the Controller if it considers that an instruction infringes the GDPR or any other applicable data protection provision.
The Processor does not process the data for any purpose of its own. By way of exception, it may produce aggregated and anonymised statistics for the purpose of improving the Service, provided that the anonymisation is irreversible and that no re-identification is possible.
Article 4 — Confidentiality
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality, by contract or under an appropriate statutory obligation.
Access to the Customer’s data by the Processor’s staff is restricted to authorised persons and to the sole purposes of technical support, supervision of the Service, and activity monitoring.
Article 5 — Security
The Processor implements the appropriate technical and organisational measures described in Annex 2, in accordance with Article 32 of the GDPR.
These measures may evolve, provided that they do not reduce the overall level of security of the Service.
Article 6 — Sub-processors
The Controller authorises the Processor to engage the sub-processors listed in Annex 3.
The Processor informs the Controller of any addition or replacement of a sub-processor with thirty (30) days’ prior notice, by email or by notification within the Service. The Controller may object on legitimate and documented grounds within that period. Failing agreement between the parties, the Controller may terminate the contract without penalty.
The Processor imposes on each sub-processor, by contract, data protection obligations equivalent to those of this agreement. It ensures in particular that no sub-processor uses the data for a purpose of its own, including the training of artificial intelligence models.
The Processor remains fully liable to the Controller for the performance by sub-processors of their obligations.
Article 7 — Location and transfers
Application data is hosted in the European Union, in the Paris region.
Certain sub-processors may carry out transfers to third countries. Such transfers are covered by the standard contractual clauses adopted by the European Commission or by any other mechanism provided for in Chapter V of the GDPR. The arrangements applicable to each sub-processor are set out in Annex 3.
Article 8 — Data subject rights
The Controller is solely responsible for responding to requests from data subjects exercising their rights in respect of the data covered by this agreement.
The Processor assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling that obligation. It makes available the features of the Service allowing access to and rectification of the data concerned.
Users do not have the ability, within the Service, to delete their own account: that operation is carried out by the administrator. The Processor handles user account deletion requests addressed to it by the Controller within a maximum of thirty (30) days from receipt, at contact@margipro.com.
If a request is addressed directly to the Processor, the Processor refrains from responding to it and forwards it to the Controller as soon as possible.
Article 9 — Personal data breaches
The Processor notifies the Controller of any personal data breach as soon as possible and no later than forty-eight (48) hours after becoming aware of it.
The notification includes, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address it, and the contact details of the point of contact.
The Processor assists the Controller with its obligations to notify the supervisory authority and, where applicable, the data subjects.
Article 10 — Data protection impact assessment
The Processor assists the Controller, taking into account the nature of the processing and the information available to it, in carrying out a data protection impact assessment and in the prior consultation of the supervisory authority, where these are required.
Article 11 — Fate of the data at the end of the services
On expiry or termination of the contract, the Processor notifies the Controller in writing of the deadline for retrieving its data.
The documents uploaded by the Controller remain accessible in their original format, for retrieval purposes, for thirty (30) days from the notification. The data produced by the Service from those documents — margin calculations, price histories, production data — is accessible through the Service’s consultation features during that same period. At the end of that period, the Processor deletes all personal data covered by this agreement, including copies, unless a statutory retention obligation applies.
By way of exception, MargiPro retains, in its capacity as controller and for its own purposes referred to in Article 1 only, the identification data of user accounts for a maximum of three (3) months from the end of the contract. Uploaded documents, business data, and analysis results are deleted at the end of the thirty (30) day period.
The Controller is expressly informed that it is its responsibility to retrieve its documents within that period in order to meet its own statutory retention obligations, supplier invoices in particular having to be kept for ten (10) years by the business that receives them.
The Processor certifies the deletion in writing at the Controller’s request.
Article 12 — Documentation and audit
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations of this agreement.
The Controller may carry out an audit, including an inspection, once per twelve (12) month period, subject to thirty (30) days’ written notice, during business hours, without disproportionate disruption to the Service and while preserving the confidentiality of other customers’ data. Audit costs are borne by the Controller, unless the audit reveals a material breach by the Processor.
Article 13 — Records
Each party maintains the record of processing activities incumbent on it under Article 30 of the GDPR.
Article 14 — Duration
This agreement takes effect on the date of subscription to the Service and remains in force for the entire term of the contract, and until the complete deletion of the data in accordance with Article 11.
Article 15 — Language
This agreement is drawn up in French. Any translation, including this English version, is provided for information purposes. In the event of any divergence of interpretation, the French version prevails.
Annex 1 — Description of the processing
Subject matter: provision of the MargiPro Service for the automated analysis of purchase documents and the calculation of margins.
Nature of the processing: collection, recording, structuring, automated extraction by optical character recognition, storage, consultation, making available, and erasure.
Purposes: uploading and analysis of the Customer’s purchase documents; calculation and monitoring of margins per product; monitoring of purchase price trends; management of recipes and production; traceability of supplies.
Categories of data subjects:
- The users designated by the Customer, whether employees or collaborators.
- The Customer’s suppliers, where they are natural persons or sole traders.
Types of personal data:
- User identification data: first and last name, business email address, phone number, role, assigned site.
- Login data: date of last login, technical logs.
- Data appearing on uploaded documents: suppliers’ name, address, SIRET number, and telephone contact details.
- Raw output of the automated analysis of those documents.
No special category of data within the meaning of Article 9 of the GDPR is processed. No automated individual decision-making within the meaning of Article 22 is carried out.
Retention periods:
- User accounts: term of the contract; deleted together with the other data covered by this agreement at the end of the thirty (30) day retrieval period, subject to the three (3) month retention by MargiPro in its capacity as controller (Article 11).
- Uploaded documents and business data: term of the contract, then thirty (30) days for retrieval, then deletion.
- Raw analysis output: five (5) years from upload, capped at the term of the contract, for evidential and traceability purposes in relation to the automated processing.
- Login logs: six (6) months.
Annex 2 — Technical and organisational measures
- Encryption of communications over the HTTPS protocol.
- Encryption of data at rest provided by the hosting provider.
- Logical segregation of data by customer company and by site, applied at database engine level.
- Role-based access control, each user accessing only the sites assigned to them.
- Authentication by username and password, stored as a cryptographic hash.
- Password policy in line with the state of the art, combining minimum length and complexity requirements, together with a limit on the number of authentication attempts.
- Access to uploaded files through temporary signed links with a limited validity period.
- Hosting of data in the European Union, in the Paris region.
- Regular backups provided by the hosting provider.
- Restriction of staff access to authorised persons only, bound by a contractual confidentiality obligation.
Annex 3 — Authorised sub-processors
| Sub-processor | Service provided | Location | Safeguards |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | European Union, Paris region | Data processing agreement |
| Mistral AI SAS | Optical character recognition of uploaded documents | France; possible international transfers | Standard contractual clauses — Data processing agreement |
| Vercel Inc. | Hosting of the application, audience measurement | United States | Standard contractual clauses — Data processing agreement |