Data processing agreement
This data processing agreement (the “Agreement” or the “DPA”) governs the processing of personal data carried out by Quilium on behalf of the User in the context of the provision of the Quilium Services. It forms an integral part of the Terms of Use and is accepted when creating a User Account. It applies between Quilium and the organisation that owns each User Site, represented by its owner and administrators (the “User” below); members invited into an organisation without administrative rights are not parties to it. In the event of a conflict regarding the processing of personal data, this Agreement prevails over the Terms of Use.
It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (the “GDPR”), between:
Quilium S.A., a public limited company under Luxembourg law, registered office 67, rue de Hollerich, L-1741 Luxembourg, RCS Luxembourg B 201627 (the “Processor” or “Quilium”),
and the User, as identified in their User Account, acting as controller for the data they process through the Quilium Services (the “Controller”).
1. Definitions
The terms “personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meaning given to them by Article 4 of the GDPR. The terms defined in the Terms of Use (in particular “User”, “User's Customer”, “User Site”, “Quilium Services”) keep their meaning here.
2. Roles of the parties
In the context of the Quilium Services, the User determines the purposes and means of the processing of the personal data present in their User Sites (content, data of User's Customers, data of the visitors and users of those sites). As such, the User acts as controller and Quilium as processor.
Where the User operates a User Site on behalf of a User's Customer, the User warrants that this User's Customer, where it is itself the controller, has consented to the terms of this Agreement, and indemnifies Quilium against any claim in this respect.
This Agreement does not apply to data for which Quilium acts as controller (management of the User Account, invoicing, security and improvement of the Services), which is governed by the privacy policy.
3. Subject matter, duration, nature and purpose of the processing
Subject matter: the provision of the Quilium Services (SaaS CMS, hosting, backups, monitoring, AI assistant) subscribed to by the User.
Nature and purpose: the hosting, storage, duplication for backup purposes, display, provision, structuring and processing by the AI assistant of the content and data that the User or their visitors enter into the Services, for the sole purpose of performing those Services and in accordance with the User's instructions.
Duration: the processing is carried out for the entire duration of the User's subscription, until the data is deleted under the conditions of section 10.
4. Categories of data and data subjects
Categories of data subjects: User's Customers, as well as the visitors and users of User Sites, and any person whose data appears in the content entered by the User.
Categories of data: identification and contact data, the content of forms and communications, technical browsing data, and any other data the User chooses to process through their User Site. Special categories of data (Article 9 of the GDPR: health, biometric or genetic data, political opinions, religious beliefs, sexual orientation, trade union membership, racial or ethnic origin) and data relating to criminal convictions are expressly excluded from the Services. The User undertakes not to process such data through their User Site.
5. Obligations of Quilium as processor
In accordance with Article 28(3) of the GDPR, Quilium undertakes to:
a. Documented instructions: process personal data only on documented instructions from the User, including with regard to transfers to a third country, unless required to do so by a legal obligation to which Quilium is subject; in that case, Quilium informs the User before processing, unless prohibited by law. The Terms of Use, this Agreement and the User's use of the features of the Services constitute their documented instructions. Quilium informs the User if, in its opinion, an instruction infringes the GDPR.
b. Confidentiality: ensure that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
c. Security: implement the appropriate technical and organisational measures provided for in Article 32 of the GDPR, described in Annex 2.
d. Sub-processing: engage another processor only under the conditions of section 6 below.
e. Assistance with data subject rights: assist the User, insofar as possible and by appropriate technical and organisational measures, in responding to requests for the exercise of data subject rights (access, rectification, erasure, restriction, portability, objection). Where a data subject sends such a request relating to a User Site directly to Quilium, Quilium forwards it to the User and does not respond directly, unless instructed otherwise.
f. Security and compliance assistance: assist the User in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR (security, breach notification, impact assessment, prior consultation), taking into account the nature of the processing and the information available to Quilium.
g. Fate of the data at the end of processing: at the User's choice, delete or return the personal data at the end of the provision of the Services, and destroy existing copies, unless retention is required by law. See section 9.
h. Audit: make available to the User the information necessary to demonstrate compliance with the obligations of Article 28, and allow for audits under the conditions of section 8.
6. Sub-processors
The User gives Quilium general authorisation to engage sub-processors for the performance of the Services. The list of current sub-processors is set out in Annex 1.
Quilium imposes on each sub-processor, by contract, data protection obligations equivalent to those of this Agreement, and remains fully liable to the User for the performance of that sub-processor's obligations.
Quilium keeps the list of sub-processors in Annex 1 up to date and notifies the account owners by e-mail of any intended addition or replacement of a sub-processor at least fifteen (15) days before the sub-processor starts processing the User's data. The User may object within that period on reasonable grounds relating to data protection. If the parties cannot find a solution in good faith, the User may terminate the subscription of the affected User Site before the change takes effect, without penalty.
Where a replacement is required urgently to maintain the security or continuity of the Services, Quilium may proceed without prior notice and informs the User as soon as possible; the objection period then runs from that notification.
7. Transfers outside the European Union
Production data is primarily hosted and stored in the European Union (see Annex 1). Quilium does not transfer personal data to a third country without appropriate safeguards within the meaning of Chapter V of the GDPR (adequacy decision, standard contractual clauses, or an equivalent mechanism).
In the context of the AI features, certain strictly limited data may be processed by Anthropic, PBC (built-in assistant and AI features of the CMS: messages exchanged with the assistant and the content submitted for processing) and by OpenAI, L.L.C. (image generation: the prompts only), both established in the United States, on the basis of the European Commission's standard contractual clauses included in each provider's data processing addendum. Both providers retain the data submitted through their API for a maximum of thirty (30) days for abuse detection and do not use it to train their models.
In addition, certain security and anti-spam tools (Cloudflare, OOPSpam, CleanTalk, Google reCAPTCHA) and the error monitoring tool (Sentry) may process visitors' traffic, browsing, form or technical data outside the European Union, on the basis of the safeguards stated for each of them in Annex 1 (EU-US Data Privacy Framework or standard contractual clauses).
8. Audit
Quilium makes available to the User, on reasonable written request and at most once a year, the information and documentation demonstrating compliance with this Agreement. Any on-site audits are carried out with reasonable notice, during business hours, without disrupting the Services, with due regard for confidentiality and for Quilium's other customers, and at the User's expense. Such audits are limited to once a year, with at least thirty (30) days' written notice, unless required by a supervisory authority or following a personal data breach.
9. Personal data breach
Quilium notifies the User of any personal data breach concerning them as soon as possible after becoming aware of it, and provides them with the reasonably available information enabling them to fulfil their own notification obligations under Articles 33 and 34 of the GDPR. The notification is sent by e-mail to the account owners without undue delay and no later than seventy-two (72) hours after Quilium becomes aware of the breach, and is supplemented as further information becomes available. It is the User's responsibility, as controller, to notify the supervisory authority and the data subjects where applicable.
10. End of processing and fate of the data
Upon closure of a User Site or termination or expiry of its subscription, the User may retrieve their data for thirty (30) days, through the export features of the Services or on request. At the end of that period, Quilium deletes the personal data processed on behalf of the User from the production systems, and from backups within ninety (90) days according to their rotation cycle, unless retention is required by law.
User Sites in preparation that remain inactive for a prolonged period may be deleted under the conditions set out in the Terms of Use, after prior notification to the User; the same retrieval and deletion periods then apply from the date announced in that notification.
11. Liability
Each party's liability under this Agreement is governed by the limitations provided for in the Terms of Use, within the limits permitted by the applicable data protection regulations. The User warrants that the data they process through the Services, and the instructions they give, comply with the applicable regulations.
12. Term, amendments and applicable law
This Agreement takes effect upon acceptance of the Terms of Use and remains in force for as long as Quilium processes personal data on behalf of the User. Quilium may amend it to reflect legal, regulatory or Service developments; material changes are brought to the User's attention. The Agreement is governed by Luxembourg law and falls under the jurisdiction of the Luxembourg courts, subject to applicable mandatory provisions.
Annex 1: Sub-processors
Fly.io, Inc. (2045 West Grand Avenue, Chicago, IL 60612, USA): hosting of Quilium compute and application services, Frankfurt region. Machines, databases and volumes are located in the Frankfurt region only. Fly.io adheres to the EU-US Data Privacy Framework and provides a data processing agreement.
Tigris Data, Inc. (object storage offered through Fly.io, contracted through Fly.io): storage of media and files uploaded to User Sites (images, documents), which may contain personal data. Storage is restricted to a European Union region; the data is not replicated outside the European Union.
Amazon Web Services EMEA SARL (38 avenue John F. Kennedy, L-1855 Luxembourg): data backups, mirror copy of media and hosting of certain databases (Amazon RDS), in the Frankfurt region (eu-central-1). The contracting entity is established in Luxembourg and the data remains in the European Union.
Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA): content delivery network, web application firewall (WAF), TLS termination and certificate management, in front of the Quilium services and User Sites. Data processed: network traffic, IP addresses and request metadata of visitors, on Cloudflare's global network, including outside the European Union. Cloudflare, Inc. adheres to the EU-US Data Privacy Framework and provides a data processing agreement.
Brevo SAS (7 rue de Madrid, 75008 Paris, France): e-mail delivery through its SMTP relay, for account e-mails (invitations, verification, password reset, authentication codes) and the notifications sent by forms of User Sites. Data transmitted: recipient's e-mail address and message content. Brevo is established in France (European Union).
CleanTalk Inc. (111 Barclay Blvd, Suite 202, Lincolnshire, IL 60069, USA): anti-spam protection for forms of User Sites that enable it, with the User's own CleanTalk access key. Data transmitted and stored for spam detection: form content, e-mail address and IP address of the person submitting the form, for 7 or 45 days according to the account settings. Data is stored on servers in the United States and the European Union by default; the account can be restricted to European Union storage, and CleanTalk offers standard contractual clauses to its European customers. As the CleanTalk account belongs to the User, the User is responsible for that contract.
Google (reCAPTCHA): bot protection on forms of User Sites that enable it. Data transmitted to Google: IP address, browser and device information, and visitor interaction data. The contracting entity for users in the European Economic Area is Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland); data may be processed by Google LLC in the United States under the EU-US Data Privacy Framework. User Sites that enable reCAPTCHA must inform their visitors of its use.
OOPSpam LLC (1118 6th St NE, Minneapolis, MN, USA): anti-spam screening of forms, where enabled on a form. Data transmitted for spam detection: e-mail address and message content of the submission. The API is operated on Fly.io infrastructure; request logging with OOPSpam is not enabled. OOPSpam LLC is established in the United States and provides a data processing agreement governing its processing on behalf of its customers.
Google Cloud Translation (Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland): alternative machine translation engine available in the CMS. Data transmitted: the text to translate only, which ordinarily contains no personal data. Google Cloud EMEA Limited is the contracting entity for European customers under the Google Cloud terms; processing may take place on Google infrastructure outside the European Union under the standard contractual clauses included in Google Cloud's data processing terms. Google does not use Cloud Translation API content to train its models.
Sentry (Functional Software, Inc.) (45 Fremont Street, San Francisco, CA 94105, USA): error monitoring of the Quilium applications. Data transmitted: technical error reports (stack traces, request context), with the collection of personal data disabled where the tool allows it. Reports are stored in Sentry's United States region and retained for 90 days. Functional Software, Inc. adheres to the EU-US Data Privacy Framework and provides a data processing agreement.
UptimeRobot s. r. o. (Obchodná 507/2, 811 06 Bratislava, Slovak Republic, European Union): availability monitoring of User Sites. Data transmitted: the public URL and the name of the site only, which do not ordinarily contain personal data.
Anthropic, PBC (artificial intelligence model provider): operation of the built-in AI assistant and of the AI features of the CMS (translations, content preparation, media descriptions, layout suggestions). Data transmitted: messages exchanged with the assistant, the content submitted for processing and the public URL of media to describe. No browsing data (IP address, device identifier, geolocation) is transmitted. Anthropic is established in the United States, provides a data processing addendum including the standard contractual clauses, retains the data submitted through its API for a maximum of thirty (30) days and does not use it to train its models.
OpenAI, L.L.C. (artificial intelligence model provider): image generation. Data transmitted: the image generation prompts only. OpenAI is established in the United States, provides a data processing addendum including the standard contractual clauses, retains the data submitted through its API for a maximum of thirty (30) days and does not use it to train its models.
Audience measurement: no sub-processor. Quilium measures the audience of its own sites with Matomo, an open-source tool hosted by Quilium on its own infrastructure in the European Union and fed server-side; no third party receives this data.
Annex 2: Technical and organisational measures (TOMs)
Quilium implements the following technical and organisational measures to ensure a level of security appropriate to the risk, within the meaning of Article 32 of the GDPR. These measures may evolve to keep up with the state of the art, without lowering the overall level of security. The “To confirm” notes flag items to be checked against the actual configuration before publication.
Hosting and data location
Compute and application services are hosted on Fly.io in the Frankfurt region (Germany). Uploaded media and files are stored through Tigris (object storage). Certain databases and the backups rely on Amazon Web Services (including Amazon RDS). All production data and backups are located in the European Union: Fly.io machines and databases in the Frankfurt region only, Tigris object storage restricted to a European Union region, Amazon Web Services in the Frankfurt region (eu-central-1). Certain third-party security tools (firewall/WAF, anti-spam, reCAPTCHA) nevertheless receive visitors' traffic, form or browsing data and may process it outside the European Union (see Annex 1).
Encryption in transit
Exchanges between users and the Quilium services are encrypted via HTTPS (TLS). TLS termination and certificate management are handled by Cloudflare, which also provides a web application firewall (WAF) in front of the services. TLS 1.2 is the minimum version accepted and every HTTP request is redirected to HTTPS.
Encryption at rest
Storage volumes of the hosting platform, object storage and backups are encrypted at rest at the infrastructure level.
Application access control
Access to the content of a User Site is governed by a system of accounts and roles: each user only accesses the sites and actions permitted by their role. Passwords are stored as bcrypt hashes. Two-factor authentication by one-time code is available on user accounts.
Infrastructure access control
Access to production environments and to the data they contain is restricted to authorised Quilium staff, following the principle of least privilege. At the date of this Agreement, two persons hold such access.
Backups and continuity
Data is backed up regularly, with backups kept in the European Union, allowing restoration in the event of an incident: database snapshots on the hosting platform and a daily copy of media and databases in a separate Amazon Web Services account, both in the Frankfurt region.
Isolation and separation of environments
Production and development environments are separated. The data of the various User Sites is logically isolated from one another: every record is bound to its site and every request is scoped to the site of the authenticated account.
Logging and monitoring
The services are monitored continuously (availability, site status). Relevant events are logged: application and access logs on the hosting platform, error reports in the monitoring tool (90 days), availability history in the monitoring service.
Vulnerability management and updates
The hosting platform applies security patches at the system level. Quilium's application dependencies are kept up to date and security advisories affecting them are reviewed as they are published.
Secrets management
Application secrets (keys, connection credentials) are managed through the platform's secrets vault and are not stored in plain text in the code. They are rotated when a person with access leaves or whenever a compromise is suspected.
Sub-processors
Quilium only uses providers offering sufficient guarantees, bound by equivalent contractual data protection commitments (see Annex 1).
Incident and breach management
Quilium has a procedure for detecting, qualifying and notifying data breaches, pursuant to section 9 of this Agreement, which names the persons alerted, the qualification steps, the containment measures and the notification channel.
Organisational measures
Quilium staff are bound by a confidentiality obligation and only access data on a need-to-know basis. Quilium keeps a record of its processing activities and carries out, where applicable, a data protection impact assessment. Every person with access to production data signs a confidentiality undertaking.