Data Processing Agreement (DPA)
Version: v1.0 — Last updated: May 1, 2026
This Data Processing Agreement (the “DPA”) is entered into under Article 28 of Regulation (EU) 2016/679 (the “GDPR”) between DECALAB, a French single-member limited liability company (EURL) operating the Elron service on the
elron.aidomain (“DECALAB,” “Decalab,” or the “Processor”), and the Customer (the “Customer” or the “Controller”) that has subscribed to the Elron Service. It forms an integral part of the agreement between the parties established through acceptance of the Terms of Use and Terms of Sale.If this DPA conflicts with the Terms of Use or Terms of Sale, this DPA controls with respect to personal data protection matters.
1. Definitions
Capitalized terms not defined below have the meaning given to them in the GDPR and/or the Terms of Use.
- “Data” means personal data processed by Decalab on the Customer’s behalf through the Service.
- “Subprocessor” means any processor engaged by Decalab to perform all or part of the processing of Data on the Customer’s behalf.
- “Data Subject” means any identified or identifiable individual whose Data is processed, including tenants, owners, vendors, and Customer contacts.
2. Subject matter, nature, and purpose of processing
Decalab processes Data on the Customer’s behalf to provide the Elron Service under the conditions described in the Terms of Use, including:
- Receiving, classifying, and indexing incoming email;
- Assisted generation of replies, drafts, summaries, overviews, and action plans;
- Tracking tickets, contacts, properties, and relationship history;
- Sending outgoing email after approval by a Customer user;
- Semantic search across the Customer’s knowledge base.
3. Categories of Data and Data Subjects
| Category of Data | Categories of Data Subjects |
|---|---|
| Identity data (first and last name) | Tenants, owners, vendors, and the Customer’s business contacts |
| Contact details (email, phone, postal address) | Same as above |
| Contractual and property-related data (lease reference, unit number, rent amounts, tenancy status) | Tenants and owners |
| Communications (incoming and outgoing email, attachments, communication logs) | Same as above |
| Operational data (tickets, action plans, intervention status, notes) | Same as above |
| Technical data (OAuth identifiers, Gmail metadata, conversation identifiers) | Customer Users |
Sensitive data: Decalab does not request special categories of personal data within the meaning of Article 9 GDPR, such as health, opinions, or sexual orientation. If such data appears incidentally, for example in the body of an incoming email, it is protected by the same security measures as other Data. The Customer will limit processing of such data to what is strictly necessary and lawful.
4. Duration of processing
Processing continues throughout the agreement between the Customer and Decalab and during the deletion or return period set out in Section 11.
5. Customer obligations (Controller)
The Customer represents that it:
- Has an appropriate legal basis to collect and process the Data it provides to Decalab;
- Has informed Data Subjects that Decalab acts as a processor and, where required, obtained their consent;
- Maintains an up-to-date record of processing activities;
- Issues documented instructions, beyond standard use of the Service, where necessary;
- Ensures that Data provided to Decalab is relevant and lawfully processed.
6. Decalab obligations (Processor)
Decalab agrees to:
6.1 Process according to instructions
Process Data only on the Customer’s documented instructions, including with respect to transfers outside the EU, unless Decalab is required to do otherwise by law. In that case, Decalab will inform the Customer before processing unless the law prohibits notice.
The Customer’s standard use of Service features constitutes a documented instruction.
If Decalab believes an instruction violates the GDPR or other applicable data protection law, it will inform the Customer without undue delay.
6.2 Confidentiality
Ensure that persons authorized to process Data have committed themselves to confidentiality or are under an appropriate statutory duty of confidentiality.
6.3 Security (Article 32 GDPR)
Implement the appropriate technical and organizational measures described in Appendix 2.
6.4 Subprocessing
Engage Subprocessors under the conditions set out in Section 9.
6.5 Assistance
Taking into account the nature of processing, assist the Customer through appropriate technical and organizational measures, where possible, so that the Customer can:
- Respond to Data Subject requests under Articles 15 through 22 GDPR;
- Comply with security, breach notification, data protection impact assessment, and prior consultation obligations under Articles 32 through 36 GDPR.
6.6 Data breach notification
Notify the Customer of a Data breach within no more than 72 hours after discovery and provide all reasonably available information needed for the Customer to make any required notification to the supervisory authority under Article 33 GDPR.
6.7 Deletion or return
At the end of the agreement, delete or return Data under Section 11.
6.8 Audit
Make available to the Customer all information necessary to demonstrate compliance with this DPA and permit audits requested by the Customer under Section 10.
7. Data Subject requests
When a Data Subject contacts Decalab directly to exercise rights relating to Data processed on the Customer’s behalf, Decalab will promptly forward the request to the Customer and will not respond directly unless instructed by the Customer.
For request-management tools under the Customer’s own control, such as deleting a Customer user account or exporting the Customer’s own data, Decalab provides self-service functionality or dedicated assistance.
8. International transfers
When a transfer outside the European Union is necessary, Decalab will implement appropriate safeguards under Articles 44 through 49 GDPR, including:
- The European Commission’s Standard Contractual Clauses (SCCs) adopted on June 4, 2021;
- Where applicable, the EU-US Data Privacy Framework (DPF) for certified organizations;
- Supplementary technical and organizational measures such as encryption, pseudonymization, and personal-data redaction.
By entering into this DPA, the Customer authorizes Decalab to make transfers necessary to provide the Service to the Subprocessors identified in Appendix 3 or at https://elron.ai/sous-traitants.
9. Subprocessors
9.1 General authorization
By entering into this DPA, the Customer generally authorizes Decalab to use the Subprocessors listed in Appendix 3 or at https://elron.ai/sous-traitants.
9.2 Updates to the list
Decalab will inform the Customer of a planned addition, replacement, or removal at least 15 days before it takes effect, by email to the Customer’s contact address and/or through an in-app notification.
9.3 Right to object
Within 15 days after notice, the Customer may raise a reasoned and reasonable objection to a new Subprocessor. If Decalab cannot offer a satisfactory alternative, the Customer may, as an exceptional remedy and no later than the new Subprocessor’s effective date, terminate the subscription without penalty or compensation and receive a refund of the unused portion of any prepaid period.
9.4 Contractual safeguards
Decalab ensures that each Subprocessor provides sufficient GDPR safeguards and enters into an agreement meeting Article 28 GDPR. Decalab remains fully liable to the Customer for each Subprocessor’s performance of its obligations.
10. Audit
At its own expense, the Customer may conduct one audit per year to verify Decalab’s compliance with this DPA, subject to 30 days’ written notice and execution of an appropriate confidentiality agreement.
The Customer or an independent third-party auditor approved by Decalab may conduct the audit. Decalab will not unreasonably withhold approval. The audit is limited to what is strictly necessary to verify Decalab’s obligations and must not disrupt operation of the Service or compromise other customers’ confidentiality.
As an alternative, Decalab may provide the Customer, under confidentiality, with a current audit report or certification such as SOC 2, ISO 27001, or a penetration-test attestation. If those materials answer the Customer’s questions, they satisfy the audit right for the current year.
The Customer bears audit costs. If an audit identifies a material breach attributable to Decalab, Decalab will bear the reasonable audit costs and the cost of any remediation re-audit.
11. Data at the end of the agreement
At the end of the agreement, and no later than 30 days after termination takes effect:
- Decalab will permanently delete Data processed on the Customer’s behalf, unless law requires retention or the Customer first expressly requests return;
- Upon a written request made before termination, Decalab will return a copy of the Data to the Customer in a structured, commonly used, machine-readable format;
- Backups containing Data will follow their normal rotation cycle and be permanently erased no later than 35 days after termination;
- On request, Decalab will provide a deletion certificate.
Legal retention obligations applicable to Decalab, including billing, accounting, and fraud-prevention requirements, continue to apply to the relevant data.
12. Liability
Decalab’s liability under this DPA is subject to the limits in Section 11 of the Terms of Use and Section 10 of the Terms of Sale, except where mandatory GDPR provisions provide otherwise.
Each party bears its direct liability under the GDPR and decisions of supervisory authorities. The parties may seek contribution from each other, subject to applicable liability caps.
13. Order of precedence
If this DPA conflicts with another contractual document relating to the Service, this DPA controls with respect to Data protection matters.
13 bis. Customer-connected third-party services
When the Customer enables an integration between Elron and a third-party service it uses, including customer relationship management tools, property or building management software, collaborative suites, calendars, or another integration enabled by the User, Decalab processes Data transmitted through the integration solely to provide the functionality requested by the Customer.
Those connected third-party services are not Decalab Subprocessors under this DPA. They are provided directly to the Customer by their respective providers under a separate contractual relationship between the Customer and each provider.
Accordingly:
- The Customer represents that it has the right to authorize Decalab to connect to those services and process Data obtained from them;
- The Customer is responsible for the GDPR compliance of its relationship with each third-party provider, including notice, consent, legal basis, and international transfers;
- Decalab applies the same security and confidentiality measures described in Appendix 2 to Data obtained from those integrations.
14. Governing law and jurisdiction
This DPA is governed by French law. Any dispute is subject to the exclusive jurisdiction of the Paris Commercial Court, except where mandatory law provides otherwise.
Appendix 1 — Description of processing
| Nature | Hosting, processing, indexing, transforming, and returning Data on the Customer’s behalf |
| Purpose | Provision of Elron Service features |
| Categories of Data | See Section 3 |
| Categories of Data Subjects | See Section 3 |
| Duration | See Section 4 |
Appendix 2 — Technical and organizational measures (Article 32 GDPR)
Physical and logical infrastructure security
- Hosting on Google Cloud Platform in the European Union. Data centers certified to ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, and PCI-DSS.
- PostgreSQL database with encrypted backups and point-in-time recovery.
- Private network, managed firewall, and public exposure limited to strictly necessary HTTPS endpoints.
- Gmail OAuth integration that has completed a CASA Tier 2 assessment (Cloud Application Security Assessment).
Encryption
- In transit: TLS for all communications.
- At rest: cloud-provider-managed encryption for the database, object storage, and backups.
- Application-level encryption of OAuth tokens for connected accounts.
Access control and identity
- Organization-level database isolation.
- Employee and contractor access based on least privilege, with periodic entitlement reviews.
- User authentication through Google / Microsoft OAuth or email and password credentials with robust hashing. A two-factor authentication option will be offered in the future.
Isolation and resilience
- Strictly separate development, staging, and production environments.
- Daily backups with limited retention and periodic restoration tests.
Logging and monitoring
- Centralized access and application logs.
- Error monitoring with personal-data redaction in traces.
- Automated security incident alerts.
Organization
- Confidentiality commitments signed by each employee and contractor.
- Security and data protection awareness for teams.
- A Data breach notification process with a 72-hour target.
- Regular application maintenance with prioritized security updates.
Subprocessors
- Selection based on documented GDPR safeguards, including DPAs, certifications, and transparency.
- Preference for providers offering infrastructure and processing in the European Union.
Appendix 3 — Subprocessor list
The current Subprocessor list is available at https://elron.ai/sous-traitants and is reproduced as of the signature date in Subprocessors.
Contact
Questions about this DPA:
privacy@elron.ai(GDPR requests)legal@elron.ai(legal notices)
DECALAB EURL — 149 avenue du Maine, 75014 Paris, France