Translation for information purposes only. This English version has no contractual value. Only the French version, available at https://arrmesh.ai/fr/legal/dpa, is legally binding and prevails before the courts, which have jurisdiction under French law.
Data Processing Agreement
Controller: the Customer, as identified at subscription or in the Order Form. Processor: Atyos SAS, 18a Route de Paris, 67117 Ittenheim, France (“Atyos”).
Preamble
This agreement (the “DPA”) is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”) and French Law No. 78-17 of 6 January 1978, as amended. It forms an integral part of the subscription contract for the ArrMesh service (the “Service”) governed by the Terms of Subscription. It is accepted together with them, online or by signing an Order Form. In the event of any conflict, the DPA prevails over the Terms of Subscription for all matters relating to personal data.
Where the Customer is subject to the Swiss Federal Act on Data Protection (FADP), references to the GDPR also refer to the corresponding provisions of the FADP.
1. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given to them in Article 4 GDPR. Other capitalised terms have the meaning defined in the Terms of Subscription.
2. Description of the processing
| Subject matter | Provision of the Service: hosting, management of organisations, identities and access rights, usage metering, billing, notifications, logging and support. |
| Duration | Term of the contract, plus the export and deletion period set out in Section 10. |
| Nature of operations | Collection, recording, organisation, storage, consultation, use, disclosure by transmission, matching, erasure. |
| Purposes | Authentication and access management; management of organisations, applications and licences; usage metering and billing calculation; sending of transactional notifications; audit and traceability; security; support. |
| Data subjects | The Customer's Users (employees, administrators); the Customer's End Customers and their users, whose identities and usage are managed through the Service. |
| Categories of data | Identification data (first name, last name, email address, technical identifiers); authentication data (login identifiers, tokens, MFA factors — passwords are managed by Amazon Cognito and are never accessible in clear text); roles and rights; connection and log data (IP address, timestamp, actions performed); usage and billing data linked to an organisation or a user; any other data the Customer chooses to send to the Service. |
| Sensitive data | None. The Customer undertakes not to send to the Service any data falling under Article 9 or Article 10 GDPR. |
3. Customer instructions
3.1. Atyos processes personal data only on documented instructions from the Customer. The Contractual Documents and the Customer's configuration and use of the Service constitute its instructions.
3.2. Atyos immediately informs the Customer if, in its opinion, an instruction infringes applicable law. If a legal obligation requires Atyos to carry out processing not covered by the instructions, it informs the Customer before the processing, unless the law prohibits it.
4. Confidentiality
Atyos ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and process the data only to the extent necessary to provide the Service.
5. Security
5.1. Atyos implements the technical and organisational measures described in Annex 1, which ensure a level of security appropriate to the risk. Atyos may update them, provided that the overall level of security is not reduced.
5.2. The Customer is responsible for the security of its own systems, the management of its Users' access and the configuration of the security features made available to it (MFA, SSO, API key management).
6. Sub-processors
6.1. The Customer grants Atyos a general authorisation to engage sub-processors. The up-to-date list is published at https://arrmesh.ai/fr/legal/subprocessors.
6.2. Atyos informs the Customer, by email and at least thirty (30) days in advance, of any addition or replacement of a sub-processor. The Customer may object in writing, with reasons, within that period. The Parties shall then seek a solution in good faith; failing that, the Customer may terminate the affected part of the Service at no cost before the change takes effect.
6.3. Atyos contractually imposes on each sub-processor data protection obligations at least equivalent to those of this DPA, and remains fully liable to the Customer for the performance of their obligations.
7. Data location and transfers
7.1. Personal data is hosted and processed within the European Union:
- eu-west-3 (Paris, France): primary region, hosting all application services;
- eu-central-1 (Frankfurt, Germany): disaster recovery region, to which persistent data is replicated for continuity and disaster recovery purposes. No application processing takes place there under normal operation; it is activated only in the event of a major incident affecting the primary region.
AWS services used in the us-east-1 region (North Virginia) are limited to TLS certificate management and do not involve any personal data of data subjects.
7.2. Only the hosting of personal data within the European Union is a contractual commitment. The AWS regions mentioned in this Section and in the other Contractual Documents are given for information purposes only. Atyos may change them at any time, in particular for technical, security, performance or service continuity reasons, provided that the data remains hosted within the European Union. Such a change does not constitute a change of sub-processor within the meaning of Section 6; the regions in use are kept up to date on the sub-processors page.
7.3. Atyos does not transfer personal data to a country outside the European Economic Area, except on the Customer's instructions or through a sub-processor notified in accordance with Section 6. Any such transfer is then covered by one of the mechanisms provided for in Chapter V GDPR (adequacy decision, including the EU–US Data Privacy Framework, or standard contractual clauses).
7.4. The Customer is informed that the parent company of Amazon Web Services is a US entity that may be subject to access requests from US authorities. AWS contractually undertakes to challenge any non-compliant access request and to notify its customers where legally permitted; these commitments and the standard contractual clauses are included in the AWS Data Processing Addendum. The Service does not rely on a sovereign cloud offering within the meaning of the French SecNumCloud qualification.
8. Data subject rights
Atyos assists the Customer, through appropriate technical and organisational measures and insofar as possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). The Service enables the Customer to view, modify, export and delete user data. Atyos forwards to the Customer, without delay, any request it receives directly from a data subject and does not respond to it without instructions.
9. Personal data breaches
9.1. Atyos notifies the Customer of any personal data breach without undue delay, and at the latest forty-eight (48) hours after becoming aware of it, at the contact address provided by the Customer.
9.2. The notification describes, where possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact point. Information not available at the time of notification is provided in phases as soon as possible.
9.3. As controller, the Customer is responsible for notifying the breach to the supervisory authority and, where applicable, to data subjects. Atyos provides it with the reasonably necessary assistance.
10. End of processing
10.1. At the end of the contract, the Customer has thirty (30) days to export its data using the Service's features or upon request to Atyos.
10.2. After that period, Atyos deletes the personal data from its production systems within thirty (30) days, and then from its backups at the end of their rotation cycle (no more than thirty-five (35) days), unless a legal retention obligation applies. Atyos provides a certificate of deletion upon request.
11. Assistance and impact assessments
Atyos provides the Customer with the information reasonably necessary to carry out data protection impact assessments and prior consultations with the supervisory authority, taking into account the nature of the processing and the information available to it.
12. Documentation and audits
12.1. Atyos makes available to the Customer the information necessary to demonstrate compliance with this DPA, including an up-to-date description of the security measures and, where applicable, available certification or audit reports, including those of its sub-processors.
12.2. If that information is not sufficient, or at the request of a supervisory authority, the Customer may have an audit carried out, by itself or by an independent auditor who is not a competitor of Atyos and is bound by confidentiality, no more than once a year except in the event of a proven breach, with thirty (30) days' notice. The scope, date and duration of the audit are agreed by mutual agreement; the audit must not disrupt the operation of the Service or compromise the security or confidentiality of other customers' data. Audit costs are borne by the Customer.
13. Customer obligations
As controller, the Customer:
- has a legal basis for each processing operation entrusted to Atyos;
- informs data subjects in accordance with Articles 13 and 14 GDPR;
- ensures that it only sends data that is adequate, relevant and limited to what is necessary;
- documents its instructions and informs Atyos of any specific requirements.
14. Liability
Each Party's liability under this DPA is governed by the Terms of Subscription, without prejudice to the rights of data subjects and the mandatory provisions of the GDPR.
15. Governing law
This DPA is governed by French law. Disputes are brought before the courts designated in the Terms of Subscription, without prejudice to the right of any person to lodge a complaint with the competent supervisory authority (in France, the CNIL).
16. Data protection contact
For any question about this DPA: privacy@arrmesh.ai.
Annex 1 — Technical and organisational measures
Hosting and architecture
- Amazon Web Services infrastructure hosted within the European Union — for information: primary region eu-west-3 (Paris, France), disaster recovery region eu-central-1 (Frankfurt, Germany) (see Section 7.2).
- Serverless managed services (API Gateway, Lambda) and managed databases (Aurora PostgreSQL, DynamoDB), deployed across multiple availability zones.
- Infrastructure as code (Terraform), reviewed and deployed through a continuous integration pipeline.
- Production and non-production environments separated in distinct AWS accounts.
Encryption
- Encryption of data in transit (TLS 1.2 minimum).
- Encryption of data at rest (AES-256 via AWS KMS), including backups.
- Application secrets and keys stored in dedicated services (AWS SSM Parameter Store, KMS); customer API keys stored in hashed form.
Access control
- Principle of least privilege; production access restricted to authorised personnel, using named identities and multi-factor authentication.
- Logical isolation of data between customers (multi-tenant), enforced on every request by the API authoriser.
- Authentication of Service users via Amazon Cognito; support for SSO (SAML, OIDC) and multi-factor authentication where enabled [MFA: verify availability in production].
Logging and monitoring
- Logging of access and sensitive actions (Amazon CloudWatch, Service audit logs).
- Automatic alerts on availability and security indicators; 24/7 on-call for critical incidents.
- AWS Security Hub enabled on infrastructure accounts.
Continuity
- Automatic encrypted backups and cross-region replication to the disaster recovery region; recovery objectives described in the SLA.
- Documented and tested failover procedure to the disaster recovery region [replication and failover test to be completed before the first customer].
Organisation
- Staff confidentiality undertakings; security awareness.
- Vulnerability management (dependency scanning, security patches) and regular security testing.
- Incident and data breach management procedure.
ArrMesh — Data Processing Agreement (DPA) — version 2026-09. Permanent URL: https://arrmesh.ai/legal/dpa/2026-09