Hotlink

Data processing agreement

The terms on which we process, on your behalf, the data of people who leave their details through your menu.

In force since September 13, 2026


1. Parties and subject matter

This agreement is made between you, as controller, and 3m Spotsy, as processor, and forms part of the Terms and Conditions of the service.

It applies only to personal data we process on your behalf — principally the details left by visitors through the capture form in your menu. For your account data we are the controller, and that processing is described in the Privacy Policy.

The agreement is entered into when you accept the Terms and lasts as long as you have an active account.

2. Nature, purpose and categories

ElementContent
Subject matterStoring and making available the data collected through your menu
Nature of operationsCollection, storage, consultation, export, erasure
PurposeSolely to provide you the service, on your instructions
Categories of data subjectsVisitors to your public page who complete the form
Categories of dataEmail address and, if you ask for them, name and phone number
DurationWhile your account is active, plus 90 days

We do not process special categories of data on your behalf. The service is not built for it and we ask you not to use it that way.

3. Your instructions

We process the data only on your documented instructions. Using the features of the service constitutes such an instruction; any other instruction should be given to us in writing.

If an instruction appears to us to breach the regulation or another data protection rule, we tell you and may suspend acting on it until the matter is settled.

If the law requires us to process the data otherwise than instructed, we inform you beforehand unless the law forbids it.

4. Confidentiality and personnel

Only those who need it have access to data processed for you. All of them are bound by a duty of confidentiality.

Our internal administration console does not display the contents of contact lists, only the number of records. Every intervention by our staff on a customer account is recorded automatically, with its author and its timestamp.

5. Security measures

We apply the technical and organisational measures required by Article 32 of the regulation, including:

  • encryption of traffic in transit;
  • storage of passwords and session tokens only as hashes;
  • strict separation of data between customers, verified on every read;
  • limits on the number of sign-in attempts per IP address;
  • regular backups;
  • logging of administrative interventions.

6. Sub-processors

You give us general authorisation to use sub-processors for hosting, email delivery and payment processing. The current list is in section 5 of the Privacy Policy.

Each sub-processor is bound by contract to obligations at least as strict as our own. We remain liable to you for their activity as for our own.

Where we intend to add or replace a sub-processor, we notify you at least 30 days in advance. You may raise a reasoned objection within that period; if we cannot resolve it, you may terminate the subscription without penalty.

7. The assistance we give you

  • Data subject requests: we give you export and erasure directly in the app so you can answer them yourself. If a request reaches us, we pass it on to you without delay and do not answer it in your place.
  • Security breaches: we notify you without undue delay after becoming aware of a breach affecting data processed for you, with the information available to us, so that you can meet your own 72-hour notification duty.
  • Impact assessments: we provide the information we hold about the processing and about our security measures.

8. Erasure and return of data

You can export the data you have collected at any time from the app, in CSV format.

On termination we erase the data processed for you within 90 days, including from backups still in rotation, except where the law requires us to keep it longer. In that case it remains stored without being processed for any other purpose.

9. Audit

On request we provide the information necessary to demonstrate compliance with this agreement.

You may request an audit no more than once a year, on reasonable notice, during working hours, and without disrupting the service or the confidentiality of other customers. You bear the cost of an audit carried out by a third party, unless it reveals a material non-compliance.

10. International transfers

Data processed for you is stored in the European Union. Certain sub-processors may also process it in the United States, in which case the transfer relies on the Standard Contractual Clauses or on an adequacy decision.

Version in force since 13 September 2026.