DRAFT: to be validated by qualified legal counsel: DRAFT: to be validated by qualified legal counselVersion 1.0 · Last updated 2026-08-10

Data processing agreement (business customers)

Applies where you use the software in a professional capacity and remain the controller of the data you process through it. We then act as processor, on your documented instructions.

Entry into force on the first paid subscription opened to the public. This draft binds no one before that date, and qualified legal counsel will review it before we get there.

Who contracts with you

The service is provided by the company identified below, which is your contracting party, the owner of the intellectual property, the controller of your data and the merchant of record that issues your invoices.

Delta-One Capital Sàrl · The company is identified below by its commercial-register number, verified against the official register: that number gives access to its public record and statutory data. The VAT number will be added as soon as the tax regime has been settled.

1. Who is who, and when this document applies

This agreement supplements the terms of service where you act in a professional capacity and process, through the software, personal data for which you are yourself the controller. In that case Delta-One Capital Sàrl acts as processor and you as controller.

Outside that case, that is, for a consumer customer, or for the data we process for our own needs (account, billing, security, evidence of your acceptances), Delta-One Capital Sàrl remains the controller and the privacy policy applies, not this agreement. The two capacities never overlap on the same processing operation.

2. Subject matter, duration, nature and purpose

  • Subject matter: the supply of the analysis software described in the terms of service.
  • Duration: the term of your subscription, extended by the export window in article 8.
  • Nature of the operations: collection, consultation, structuring, storage, making available and erasure.
  • Purpose: producing the analyses you request, and only those.
  • Categories of data and of data subjects: those described in the privacy policy, to which this agreement refers rather than copying them.

3. Documented instructions

We process your data only on your documented instructions, of which this agreement and your configuration of the software form part. If an instruction appears to us to breach applicable law, we tell you and may suspend its execution.

We never process your data for our own commercial purposes, and we train no model on identifiable customer data.

4. Confidentiality and security

  • The people authorised to access the data are individually identified and bound by a duty of confidentiality.
  • The technical and organisational measures are described in the security annex, versioned at the same pace as this agreement.
  • No recovery phrase and no private key can be received by the software: no field in the application is able to accept one.
  • Administrative access is logged tamper-evidently.

5. Sub-processors

The named list of our processors, the actual location of each processing operation and the applicable transfer mechanism are published in the versioned annex to the privacy policy. That list is referenced here and never copied: a duplicated list always ends up existing in two different versions.

Any addition or replacement of a processor is notified in advance. You may object on reasonable data-protection grounds; failing agreement, you may cancel the affected part of the service at no cost, with a refund of the unused balance of the period.

6. Assistance

  • We help you answer the rights requests you receive, to the extent the software holds the means.
  • We provide the information needed for an impact assessment and, where applicable, for consulting the authority.
  • We notify you of any breach concerning us as soon as possible, stating what is established, without waiting for the investigation to end before informing you.

7. International transfers

The transfer mechanism is declared provider by provider in the annex to the privacy policy: an adequacy decision or standard contractual clauses as the case may be. No general clause stands in for a mechanism; an undocumented transfer is an unauthorised transfer.

8. Return and deletion

  • At the end of the contract you have a ninety-day window to export all the data, in an open format.
  • After that, the data is deleted following the chain described in the privacy policy, backups included.
  • Accounting records and tamper-evident logs are the exception: they are kept for the statutory period, and their link with an identifiable person is severed.

9. Audit

You have a documentary audit right: on request, we provide the material evidencing compliance with this agreement. An on-site audit is possible with reasonable notice, within agreed frequency limits and at your cost.

That limit is written rather than left unsaid: a small organisation that accepted unlimited on-site audits would be promising something it could not deliver.

Sources

Every legal text cited in this document is listed below, with a link to its official version and the date we read it. A clause whose basis you cannot check is a clause you would have to take on faith.