Texte de référence
Accord de traitement des données (DPA)
Cette page présente, à titre de référence, le DPA exact que les propriétaires et administrateurs d’organisation acceptent actuellement dans Klarstig. Il est publié afin que les clients, prospects et leurs conseillers puissent le lire avant de se connecter. La lecture de cette page ne vaut pas acceptation.
Commencer la lecture1.1, en vigueur depuis le 2026-09-22. Le texte anglais fait foi.
Les propriétaires et administrateurs l’acceptent dans Paramètres → Accord de traitement des données (connexion requise). Chaque acceptation enregistre la version, une empreinte du texte, la personne et l’heure.
Les acceptations de cette version ou de versions antérieures restent telles qu’enregistrées. Une nouvelle version ne s’applique qu’une fois publiée avec préavis et acceptée.
01À propos de cette copie de référence
Les sections ci-dessous reproduisent mot pour mot le texte actuel de l’accord, en anglais, y compris ses annexes. Empreinte du texte (SHA-256) : fe80135a88a438e21faf3be977ad80ea8aceee33b903e2fe81617d52af6e5633. La même empreinte est conservée avec chaque acceptation, ce qui permet de vérifier quel texte a été accepté.
L’accord n’est pas proposé en traduction ; la version acceptée est la version anglaise.
Une modification est en préparation (ajout de la protection anti-robots Cloudflare Turnstile à l’annexe III, mention du réseau périphérique de l’hébergeur lorsque Abacus.AI aura confirmé son rôle, et remplacement de la ligne de contact de l’annexe I par le formulaire de demandes relatives à la vie privée). Il s’agit d’un projet, qui n’est pas en vigueur et ne modifie aucune acceptation déjà enregistrée. Toute nouvelle version sera annoncée avec un préavis d’au moins 14 jours, conformément à la section 4.2.
D’ici là, lorsque l’annexe I indique une adresse de contact, veuillez utiliser le formulaire de contact (sujet « Confidentialité et droits sur les données ») ou écrire à Daniel Petry, exerçant sous le nom Klarstig, 11917 Laurel Ave., Forestville, CA 95436, États-Unis.
02Parties et objet
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and Daniel Petry, a sole proprietor operating as “Klarstig” (“Klarstig”, “Processor”) under which Klarstig provides the Klarstig forms, workflow and electronic-signature service (the “Service”, and that agreement, the “Principal Agreement”). It governs the processing of personal data by Klarstig on the Customer’s behalf. Where this DPA conflicts with the Principal Agreement on the subject of data protection, this DPA prevails.
031. DEFINITIONS
“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into the law of the United Kingdom. “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. “Data Protection Law” means the GDPR, the UK GDPR, and any other data-protection or privacy law applicable to the processing under this DPA. “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission (Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum.
042. ROLES AND SCOPE
2.1 As between the parties, the Customer is the controller (or a processor acting for its own controller) of the personal data it submits to or collects through the Service, and Klarstig is the processor acting on the Customer’s documented instructions.
2.2 Where the Customer acts as a processor for a third-party controller, the Customer warrants it has the authority to engage Klarstig as a sub-processor on these terms.
2.3 Klarstig processes personal data only to provide and support the Service and only on the Customer’s documented instructions, including those set out in this DPA and the Principal Agreement, unless required to act by applicable law (in which case, where legally permitted, Klarstig will inform the Customer of that legal requirement before processing).
053. PROCESSOR OBLIGATIONS
3.1 Instructions. Klarstig will process personal data only as described in Section 2 and Annex I. Klarstig will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3.2 Confidentiality. Klarstig ensures that persons authorised to process the personal data are bound by an appropriate duty of confidentiality.
3.3 Security. Klarstig implements and maintains the technical and organisational measures described in Annex II, appropriate to the risk.
3.4 Assistance. Taking into account the nature of the processing and the information available to Klarstig, Klarstig will assist the Customer by appropriate technical and organisational measures, insofar as possible, with the Customer’s obligations to respond to data-subject requests (Section 6) and with the Customer’s obligations under Articles 32 to 36 GDPR (security, breach notification, data-protection impact assessments and prior consultation).
064. SUB-PROCESSORS
4.1 General authorisation. The Customer grants Klarstig general authorisation to engage sub-processors to support the Service. The sub-processors engaged as of the effective date, and the functions they perform, are listed in Annex III and maintained in Klarstig’s subprocessor register.
4.2 Changes. Klarstig will inform the Customer of any intended addition or replacement of a sub-processor, giving the Customer a reasonable opportunity (at least fourteen (14) days) to object on reasonable data-protection grounds before the new sub-processor begins processing. If the Customer objects and the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.
4.3 Flow-down and liability. Klarstig imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible to the Customer for each sub-processor’s performance of those obligations.
075. INTERNATIONAL TRANSFERS
5.1 Klarstig and its sub-processors process personal data in the United States. Where personal data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the transfer is made under an appropriate safeguard: the recipient’s certification under the EU-U.S. Data Privacy Framework (and the UK Extension and Swiss-U.S. framework, as applicable) where the recipient is certified, or otherwise the Standard Contractual Clauses, which are incorporated by reference and completed by the details in Annexes I to III.
5.2 Klarstig will make available, on request, the transfer safeguards relied on for each sub-processor, as recorded in Klarstig’s transfer register.
086. DATA-SUBJECT RIGHTS
6.1 The Service provides the Customer with controls and tooling to access, export, correct and delete personal data within the Customer’s account, so that the Customer can respond to data-subject requests.
6.2 If Klarstig receives a request directly from a data subject relating to the Customer’s data, Klarstig will not respond to the substance of the request other than to direct the data subject to the Customer, and will promptly forward the request to the Customer.
097. PERSONAL-DATA BREACH NOTIFICATION
7.1 Klarstig will notify the Customer without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a personal-data breach affecting the Customer’s personal data.
7.2 The notification will describe, to the extent known, the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point for further information, and Klarstig will provide further information as it becomes available.
108. DELETION AND RETURN
8.1 On termination or expiry of the Principal Agreement, Klarstig will, at the Customer’s choice, delete or return the personal data it processes on the Customer’s behalf, and delete existing copies, within thirty (30) days, unless applicable law requires continued storage.
8.2 Personal data held in routine backups is deleted on the ordinary backup-expiry cycle described in Klarstig’s retention documentation.
119. AUDITS
9.1 Klarstig will make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including the security documentation and any third-party reports it maintains.
9.2 Where that information is insufficient, the Customer may, on at least thirty (30) days’ prior written notice, no more than once per twelve-month period (unless required by a supervisory authority or following a breach), conduct an audit of Klarstig’s processing during business hours in a manner that does not disrupt Klarstig’s operations or compromise the confidentiality of other customers’ data. Each party bears its own costs.
1210. LIABILITY AND TERM
10.1 Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Principal Agreement.
10.2 This DPA takes effect on the Customer’s acceptance and continues for as long as Klarstig processes personal data on the Customer’s behalf.
1311. GOVERNING LAW
This DPA is governed by the law and subject to the jurisdiction stated for such matters in the Principal Agreement.
14ANNEX I — DETAILS OF PROCESSING
Data exporter (controller): the Customer identified in the Principal Agreement / account.
Data importer (processor): Daniel Petry, a sole proprietor operating as “Klarstig”, 11917 Laurel Ave., Forestville, CA 95436, United States. Contact: [email protected].
Subject matter: provision of the Klarstig forms, workflow and electronic-signature Service.
Duration: the term of the Principal Agreement plus the deletion/return period in Section 8.
Nature and purpose: hosting, processing and transmitting form submissions, workflow data, documents and electronic signatures; account administration; support.
Categories of data subjects: the Customer’s account users, and the individuals whose information the Customer collects through forms and workflows it configures.
Categories of personal data: account and contact details; authentication data; form-submission content chosen by the Customer (which may include additional personal data the Customer elects to collect); document and signature data; usage and log data. Klarstig does not require special-category data; any such data is submitted at the Customer’s discretion and under the Customer’s responsibility.
Frequency: continuous, for the duration of the Service.
Competent supervisory authority: determined by the Customer’s establishment or, for SCC transfers, as provided in the SCCs.
15ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
Klarstig maintains measures appropriate to the risk, including: encryption of data in transit (TLS 1.2+) and at rest; role-based access control and least-privilege administration; per-organisation tenant isolation; authentication controls and audit logging of security-relevant actions; secure managed hosting with backups; a documented retention and deletion schedule; and an incident-response process. These measures correspond to the control set documented in Klarstig’s security evidence (controls SEC-01 through SEC-32). Card payments are processed by Stripe within Stripe’s own PCI DSS scope; Klarstig does not store full card numbers.
16ANNEX III — SUB-PROCESSORS (as of 2026-09-22)
1. Abacus.AI, Inc. (United States) — application hosting, managed database, platform email delivery, and large-language-model processing that powers Service features.
2. Amazon Web Services, Inc. (United States) — cloud storage for uploaded files and generated documents.
3. Stripe, Inc. / Stripe, LLC (United States) — payment processing for Customer subscriptions and, where enabled, form payments.
4. Google LLC (United States) — privacy-enhanced (“no-cookie”) video playback for help content, invoked only when a user clicks to play.
The current list and the transfer safeguard relied on for each sub-processor are maintained in Klarstig’s subprocessor and transfer registers and are available on request.
