GDPR Addendum – Data Processing Agreement

Data Processing Agreement (DPA)

This English version is provided for information. In the event of any discrepancy, the French version prevails.

GDPR ADDENDUM

Data Processing Agreement (DPA)

Between:

The Client, user of the GDM software, acting as controller

and

GDM – Gestion Dynamique de Matériel
Published by the association Gestion Dynamique de Matériel
Represented by Marchadier Mickaël
Acting as processor

Article 1 – Purpose

The purpose of this addendum is to define the conditions under which GDM, as technical processor, undertakes to host and process the personal data required to provide the GDM – Gestion Dynamique de Matériel service.

GDM works on a multi-organisation model: each user has a single personal account that can be linked to several organisations. Each organisation pays for its own licence independently.

This addendum is entered into pursuant to Article 28 of Regulation (EU) 2016/679 of 27 April 2016 (GDPR).

Article 2 – Nature of the processing operations

GDM carries out the following processing operations on behalf of the Client:

  • Storage and management of data relating to the software’s users
  • Storage of data relating to staff, technicians and contributors entered by the Client
  • User account management (creation, modification, deletion)
  • Operational management of bookings, rentals, projects and stock movements
  • Generation of documents (dispatch notes, preparation sheets, schedules)
  • Logging and tracking of actions performed in the application
  • Automatic data backups

Article 3 – Categories of data processed

GDM distinguishes two types of data according to who they belong to:

3.1 Personal account data (belonging to the user)

This data is linked to the user’s single account:

  • Last name, first name
  • Email address
  • Password (encrypted)
  • Phone number
  • Postal address
  • Profile photo
  • Date of birth
  • Social security number (optional)
  • Congés Spectacles number (French entertainment-industry holiday fund)

3.2 Organisation-related data (belonging to the Client)

This data is specific to each organisation:

  • Role / position in the organisation
  • Team / department
  • Access rights and permissions
  • Data of non-user third parties (technicians, freelancers, contractors)

3.3 Technical data

  • Login information (timestamps, IP addresses)
  • Action logs
  • Information about the browser used

Article 4 – Data subjects

The categories of data subjects concerned by the processing are:

  • Users of the GDM software who have a personal account
  • People whose data is entered by the Client (technicians, freelancers, non-user contractors)

Note: a user may be linked to several client organisations. In that case, each organisation only has access to the data linked to its own workspace.

Article 5 – Obligations of the processor (GDM)

GDM undertakes to:

5.1 Data processing

  • Process data only on the Client’s documented instructions
  • Not use the data for any purpose other than the performance of the service
  • Not transfer, sell or transmit the data to third parties

5.2 Confidentiality

  • Guarantee the full confidentiality of the data
  • Ensure that persons authorised to process the data are bound by a confidentiality obligation

5.3 Security

Implement appropriate security measures, including in particular:

  • Password encryption (secure hashing)
  • Secure HTTPS/TLS connections
  • Access control and authentication
  • Automatic backups every 30 minutes
  • Redundant storage in 3 locations in France
  • Logging and tracking of logins and actions
  • Restricted access to servers

5.4 Data location

  • Host the data exclusively within the European Union (OVH servers in France)
  • Not transfer any data outside the EU

5.5 Breach notification

  • Notify the Client as soon as possible in the event of a security incident likely to result in a data breach
  • Provide the Client with all the information needed to notify the CNIL (the French data protection authority) if necessary

5.6 Assistance to the Client

  • Assist the Client in responding to data subjects’ requests to exercise their rights (access, rectification, erasure, portability, objection)
  • Help the Client ensure compliance with its obligations regarding security and breach notification

5.7 End of contract

  • At the end of the contract, maintain read-only access for 1 year
  • Return the data to the Client on request (Excel format)
  • Permanently delete the organisation’s data within 90 days after the end of access
  • Carry out early deletion at the Client’s request

Note: deleting an organisation’s data does not delete the users’ personal accounts, which may be linked to other organisations. Only the link between the user and the organisation is deleted, together with the data specific to that organisation.

Article 6 – Allocation of responsibilities

6.1 Responsibilities of the user

The user is responsible for the data of their personal account and undertakes to:

  • Provide accurate information when creating their profile
  • Keep their data up to date
  • Keep their login credentials confidential

6.2 Responsibilities of the Client (organisation)

The Client is responsible for the data linked to its workspace and undertakes to:

  • Determine the purposes and legal bases of the processing carried out in its workspace
  • Inform third parties (technicians, non-user freelancers) of the collection of their data
  • Ensure the lawfulness of the data entered in its workspace
  • Configure access and permissions appropriately
  • Respond to requests to exercise rights concerning the data in its workspace

Article 7 – Access to data

Only GDM’s authorised technical administrators may occasionally access the data, exclusively for the purposes of:

  • Technical maintenance
  • User support
  • Incident resolution

Such access is logged and limited to what is strictly necessary.

Article 8 – Sub-processing

As of the date of this addendum, GDM does not use any sub-processor with access to the Client’s personal data.

Should a change in the service require the use of a sub-processor, the Client would be informed in advance and could object.

Article 9 – Term

This addendum takes effect from the Client’s registration to the GDM service and remains valid for as long as the Client uses the software.

Obligations relating to the confidentiality and security of data survive the end of the contract.

Article 10 – Governing law

This addendum is governed by French law and European Union law, in particular Regulation (EU) 2016/679 (GDPR).

In the event of a dispute relating to the interpretation or performance of this addendum, the parties shall endeavour to find an amicable solution. Failing that, the courts of Paris shall have sole jurisdiction.

Acceptance

Use of the GDM software constitutes acceptance of this GDPR addendum. The Client acknowledges having read the conditions of personal data processing described above.

For any question or to request the signature of a specific addendum, contact us at [email protected].

Association Gestion Dynamique de Matériel
Registration no.: W931014617
[email protected] | +33 6 45 80 33 07
www.gdmfrance.com

Effective date: January 2025
Version: 1.0