Data Processing Agreement

This Data Processing Agreement ("DPA") describes the standard framework that applies when a customer organization ("Customer") uses Harmate to process personal

Published version: August 15, 2026.

This Data Processing Agreement ("DPA") describes the standard framework that applies when a customer organization ("Customer") uses Harmate to process personal data in its questionnaires, contacts or results. It supplements the applicable contractual terms. If a signed customer agreement conflicts with this document, the customer agreement prevails. This document is not legal advice.

Harmate is operated by Enzo MARTIN, an active sole proprietor (SIREN 108 698 242, SIRET 108 698 242 00014), under the ALL activity. The business locality is Saint-Martin-d'Hères, France; the detailed business address is [NOT PUBLICLY DISCLOSED] in this public version. He is designated as the "Provider" and is the party to this DPA.

1. Parties And Roles

For data entered or collected by the Customer in its workspace:

  • the Customer determines the purposes and essential means of processing and acts as the controller;
  • the Provider acts as the processor and processes the data only to provide the service and on the Customer's documented instructions.

The Provider remains controller for its own account, security and operational data. Those processing activities are described in the Privacy Policy (PC_EN.md).

The privacy contact is contact@harmate.com.

2. Instructions And Scope

The Customer's instructions consist of its workspace configuration, actions performed in Harmate and documented requests sent to the Provider. The Provider's documented purposes do not include selling Customer data, using it for its own advertising, or training a general-purpose model. Any guarantees specific to an external provider must be checked in the subprocessor register before data is transmitted.

Any new purpose or purpose incompatible with the service requires prior instruction and qualification. This DPA alone does not authorize optional real-persona enrichment or the transmission of contact data to an external LLM provider.

For the audience and sourced-memory contract, the instruction is disabled by default and persona processing is local-only. Explicit sharing copies only first name, last name, email and phone; the personal note remains in the source address book. An external LLM provider, territory, safeguards and separate instruction must be documented in the subprocessor register before any change outside this mode is activated.

3. Data And Data Subject Categories

Depending on the Customer's configuration, the service may process:

  • identifiers and contact details: first name, last name, email address, phone number, technical identifiers and a contact's free-text note;
  • questionnaire metadata, questions, answers, attachments, exports and grouping or analysis results;
  • respondent data required to distribute and verify a questionnaire;
  • a persona linked to a contact record. That persona is personal data and follows the same regime as the contact record;
  • an organization-contact projection, audience, identity link, immutable final submission snapshot, evidence and related idempotent receipts;
  • minimized technical and security logs, as necessary to operate and secure the service.

The Customer must collect only data necessary for its purpose and inform the data subjects. Special categories of data are not required by the Provider; if the Customer enters them, it remains responsible for the legal basis and related instructions.

Personas generated from public statistical data are synthetic and outside the personal-data scope while they are not linked to a real contact. A persona linked to a real contact is, by contrast, personal data in full.

4. Authorized Purposes

On the Customer's instructions, the Provider may:

  1. host and administer questionnaires, contacts and answers;
  2. distribute questionnaires and collect answers;
  3. calculate groupings, results and reports requested by the Customer;
  4. provide exports, support, security, abuse prevention and technical service continuity; and
  5. comply with legal obligations applicable to the processor.

For organization audiences, the Provider performs deterministic application to a draft questionnaire and memory of only final responses connected by a persisted identity link. These operations trigger no email, analysis, grouping or LLM credit.

Persona enrichment based on answers linked to a real contact is a separate processing activity. It may run only when the Customer has authorized it through documented instructions and the relevant flow and provider are listed in the current subprocessor register. The availability and exact scope of this setting remain to be confirmed; no authorization should be inferred from the subscription alone or from this DPA alone.

5. Retention, Return And Deletion

The Customer, as controller, determines how long contact data is retained. The Provider does not impose an expiry period for contacts and does not automatically delete business data because of inactivity. The Customer may request deletion or anonymization of a contact record; its linked persona follows that operation.

The applicable principles are:

  • account data and derivatives: for the life of the account, then deletion according to an account-deletion request;
  • questionnaire answers and data: for the life of the questionnaire or as instructed by the Customer;
  • contact record and linked persona: for the life of the owning account, without automatic expiry, then deletion or anonymization on the Customer's instruction or account deletion; and
  • purely synthetic personas: unlimited retention outside this DPA, unless they are linked to a real contact.

At the end of the service, the Provider returns or deletes the data according to the Customer's instruction, subject to applicable legal obligations. Technical backup copies may remain during the applicable operational backup window; its exact duration is to be confirmed in the relevant contract or operations register.

6. Confidentiality And Security Measures

The Provider imposes confidentiality duties on people authorized to access the data and limits access to a need-to-know basis. Technical and organizational measures include authentication and access control, minimization of data in logs, secure transport, and backup and restore procedures. Measures may evolve to maintain appropriate security; their detailed configuration is not a guarantee of a particular mechanism not described here.

The Provider does not transmit personal data to a new subprocessor without appropriate instruction and qualification. If a security incident affects Customer data, the Provider informs the Customer without undue delay after confirming the incident and cooperates to document the facts, measures taken and corrective actions.

7. Subprocessors

The Customer authorizes only the following categories, subject to their entry in the applicable subprocessor register:

CategoryServiceStatus known at publication
Primary hostingHarmate service infrastructureInfomaniak Network SA, in Europe, is identified in the Legal Notice
Identity and technical servicesauthentication, storage or operations required for the servicelegal identity and exact territory to be confirmed in the current register
External LLMa specifically authorized use case, including real-persona enrichmentthe general configuration exposes Google (Gemini API) as the current production primary and Ollama Cloud as an option; legal identity, territory, non-reuse safeguards and transfer mechanism to be confirmed before any transmission. The P1-67 scope remains local_only and disabled by default: no contact data is sent.
Optional analytics measurementGA4 after the applicable consent; PostHog remains disabledGA4: Google Ireland Limited, global processing, DPA accepted on April 4, 2025, referenced Google subprocessors, 2-month event and 14-month user retention, with transfers covered by the EU–US DPF and Standard Contractual Clauses as fallback; PostHog remains disabled_legal_readiness, with no fallback provider

The runtime may be configured with internal or external providers. Technical provider labels (for example google, ollama_cloud or ollama_local) do not, by themselves, constitute the contractual designation of a subprocessor. ollama_local denotes local processing and not an external subprocessor.

The Provider maintains the actually authorized list and informs the Customer of changes under the applicable contractual mechanism. No uniform advance-notice period is stated here until one is fixed in that contract.

8. International Transfers

Any transfer outside the European Economic Area must rely on an applicable legal mechanism and be documented for the relevant subprocessor. The primary hosting identified in the Legal Notice is operated by Infomaniak Network SA in Switzerland/Europe. For an LLM provider or another external service, the country of processing, safeguards and transfer mechanism remain to be confirmed before activation and must be recorded in the subprocessor register.

The same fail-closed gate applies to analytics providers: consent alone does not authorize a transfer whose contractual facts are missing, expired or incompatible with the runtime host.

9. Assistance And Data Subject Rights

The Customer responds to data-subject requests and informs people of its role as controller. On instruction, the Provider provides proportionate assistance to search for a record by email address, export one contact record and its linked persona, delete or anonymize the record, and retain a time-stamped operation trace. Versioned analytics pseudonyms, when present, are recalculated for every retained key version during export or erasure and sent to the configured processor-rights endpoint. Receipts retain neither a secret key nor a clear Account UUID and distinguish completed provider operations from missing, invalid, unavailable, non-terminal or rejected provider configuration. A local receipt or asynchronous acknowledgement is not treated as completed erasure.

For a request concerning questionnaire answers, the Customer remains the first contact. The Provider can be reached at contact@harmate.com when technical action is needed. Detailed assistance times and procedures are to be confirmed in the applicable service agreement.

10. Documentation And Audit

The Provider makes available information reasonably necessary to demonstrate compliance with its processor obligations and cooperates with a proportionate, confidential audit limited to the Customer-data scope. Audit procedures, any costs and frequency are to be confirmed in the individual agreement.

11. Customer Obligations

The Customer represents that it has a legal basis, provides the required notices to data subjects, limits collection, documents its instructions and does not use Harmate for an unlawful purpose. It selects the retention periods applicable to its contacts and initiates the required deletion or anonymization operations.

12. Updates And Contact

This DPA may be updated to reflect service or legal changes. The version in force is the one published with its version date. For questions about data processing, contact contact@harmate.com.

Follow-up action dated August 8, 2026: complete the subprocessor register with legal identity, territory, transfer safeguards, backup window and assistance terms before making a more specific contractual promise or sending contact data to an external LLM.


Internal references: docs/backend/PERSONAL_DATA_CLASSIFICATION_RULE_2026-08-06.md and docs/archive/todo/P0-42-legal-pages-reachable.md.