Legal information
Data Processing Agreement (DPA)
Effective date: June 14, 2026 — v1.1
Language note: The legally binding version of this DPA is the French version (available here). This English translation is provided for information purposes only and is not legally binding in the event of a dispute.
Preamble
This Data Processing Agreement (hereinafter the "DPA") is entered into pursuant to Article 28 of Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (hereinafter the "GDPR"). It governs the processing of personal data carried out by the Processor on behalf of the Controller in connection with the provision of the Scell.io services.
This DPA is incorporated by reference into the General Terms and Conditions of Sale and takes effect on the date the Client account is activated. It may be signed electronically from your Scell.io dashboard. In the event of any conflict between this DPA and the General Terms and Conditions of Sale regarding the protection of personal data, this DPA shall prevail.
The Processor
QR Communication SAS Simplified joint-stock company (SAS) with a share capital of EUR 5,000 Paris Trade and Companies Register 940 163 496 — VAT: FR43940163496 23 rue de Richelieu, 75001 Paris, France Legal representative: Joëlle Azogui, President DPA contact: dpa@scell.io
Hereinafter the "Processor" or "Scell.io".
The Controller
The Client, whether a legal entity or natural person, as identified in its Scell.io account (company name, business registration number, address, billing email), who determines the purposes and means of the processing entrusted to Scell.io.
Hereinafter the "Controller" or the "Client".
Article 1 — Definitions
The terms used in this DPA have the meaning assigned to them by the GDPR, in particular Article 4 thereof.
| Term | Definition |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person (Art. 4.1) |
| Processing | Any operation or set of operations performed on personal data (Art. 4.2) |
| Controller | The Client — determines the purposes and means of the processing (Art. 4.7) |
| Processor | Scell.io — processes personal data on behalf of the Controller (Art. 4.8) |
| Sub-processor | Any service provider engaged by Scell.io to carry out specific processing activities (Art. 28.2 and 28.4) |
| Data subject | The natural person to whom the personal data relates |
| Personal data breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data (Art. 4.12) |
| Supervisory authority | The French Data Protection Authority (CNIL), the competent authority in France (Art. 4.21) |
Article 2 — Subject matter, nature and purpose of the processing
2.1 Purposes and legal bases
The Processor processes personal data solely for the purpose of providing the following services to the Controller.
| Service | Purpose | Legal basis |
|---|---|---|
| Electronic invoicing (Factur-X / UBL / CII) | Generation, validation, transmission and archiving of invoices and credit notes | Performance of the contract (Art. 6.1.b) + Legal obligation (Art. 6.1.c) |
| Electronic signature EU-SES (eIDAS) | Creation of signature requests and compilation of evidence files | Performance of the contract (Art. 6.1.b) |
| Buyers registry | Retention and reuse of buyer data | Performance of the contract (Art. 6.1.b) |
| Fiscal audit and integrity (ISCA) | Immutable SHA-256 chain, integrity logs | Legal obligation (Art. 6.1.c) + Legitimate interest (Art. 6.1.f) |
| Transactional communications | Sending of emails and OTP SMS related to the service | Performance of the contract (Art. 6.1.b) |
2.2 Nature of the processing operations
The processing operations carried out by the Processor include, in particular: collection, recording, organisation, structuring, storage, encryption, consultation, use, transmission to recipient bodies (partner dematerialisation platform, signature provider), evidential archiving, extraction (export), restriction, erasure and destruction of personal data, strictly to the extent necessary for the provision of the services.
2.3 Categories of data processed
- Issuer identification data (company name, business registration number, VAT number, address, contact details, account identifiers);
- Buyer identification data (name, company name, business registration number, VAT number, billing and shipping address, email, telephone);
- Data contained in invoices and credit notes (amounts, descriptions, references, legal mentions);
- Electronic signature data (signatory identity, email, telephone number, timestamp, evidence file);
- Technical and connection data (IP addresses, access logs, technical identifiers);
- Payment references (excluding full bank card numbers, which are processed directly by the payment provider).
The Processor does not process any special category of data within the meaning of Article 9 of the GDPR.
2.4 Categories of data subjects
- The legal representatives and staff of the Client (account users);
- Natural-person buyers and the contacts of the Client's legal-entity buyers;
- Signatories of documents submitted for electronic signature;
- Any natural person mentioned in the invoices, credit notes or documents processed by the Client through the services.
Article 3 — Duration of the processing
This DPA takes effect on the date the Client account is activated and remains in force for the entire term of performance of the contract for the provision of the Scell.io services. The processing continues until the actual termination of the contract, subject to the statutory retention periods set out in Article 12 and the end-of-contract effects provided for in Article 13.
Article 4 — Obligations of the Processor (Article 28.3)
The Processor undertakes to comply with all obligations incumbent upon it under Article 28.3 of the GDPR.
4.a) Processing on documented instructions
The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which it is subject; in such a case, the Processor informs the Controller of that legal requirement before processing, unless that law prohibits such information. This DPA, the General Terms and Conditions of Sale and the settings configured by the Client in the dashboard constitute these documented instructions. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or any other data protection provision.
4.b) Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This confidentiality undertaking by staff survives the termination of their duties or employment contract.
4.c) Security of processing
The Processor implements the appropriate technical and organisational measures provided for in Article 32 of the GDPR to ensure a level of security appropriate to the risk. These measures are detailed in Annex 2.
4.d) Engagement of sub-processors
The Controller grants the Processor general authorisation to engage the Sub-processors listed in Annex 3. The Processor imposes on each Sub-processor, by contract, the same data protection obligations as those set out in this DPA. Any change (addition or replacement) is subject to 30 days' prior notice, in accordance with Article 6.
4.e) Assistance with data subjects' rights requests
Taking into account the nature of the processing, the Processor assists the Controller, by appropriate technical and organisational measures, in fulfilling its obligation to respond to requests for the exercise of the data subjects' rights (right of access, rectification, erasure, restriction, portability and objection) provided for in Articles 12 to 23 of the GDPR. The Processor makes export and deletion functionalities available to the Client from the dashboard.
4.f) Assistance with the Controller's compliance
Taking into account the nature of the processing and the information available to it, the Processor assists the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR, namely: the security of processing, the notification of personal data breaches to the supervisory authority and to data subjects, the carrying out of data protection impact assessments (DPIA, Art. 35) and prior consultation of the supervisory authority (Art. 36).
4.g) Fate of the data at the end of the service
At the Controller's choice, the Processor deletes or returns all personal data to the Controller at the end of the provision of the services, and deletes existing copies, unless storage is required by Union or applicable national law (Art. 28.3.g). The terms are specified in Article 13.
4.h) Provision of information and audits
The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28, and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor mandated by it (Art. 28.3.h). The terms are specified in Article 10.
Article 5 — Obligations of the Controller
The Controller undertakes to:
- Ensure that it has a valid legal basis for each processing operation entrusted to the Processor;
- Inform its own users, buyers and signatories of the engagement of Scell.io and of the processing carried out;
- Provide the Processor with lawful, documented instructions compliant with the GDPR;
- Where applicable, obtain the consent of data subjects and ensure compliance with their rights;
- Maintain its own record of processing activities in accordance with Article 30 of the GDPR;
- Notify personal data breaches to the supervisory authority and, where applicable, to the data subjects, within the statutory deadlines.
Article 6 — Sub-processing
The Controller consents to the Processor's engagement of the Sub-processors listed in Annex 3 (general authorisation within the meaning of Articles 28.2 and 28.4 of the GDPR).
Before engaging a new Sub-processor or replacing an existing Sub-processor, the Processor notifies the Client 30 days in advance. The Client has this period to raise a reasoned written objection. In the absence of a response upon expiry of the period, silence shall constitute tacit acceptance. In the event of an unresolved reasoned objection, the Client may terminate the affected portion of the services.
The Processor remains fully liable to the Controller for the Sub-processor's performance of its data protection obligations.
Article 7 — Transfers outside the European Union
✓ No transfer of personal data outside the European Union — all processing and hosting take place within the European Union.
| Infrastructure | Location | Qualification |
|---|---|---|
| Scaleway | fr-par (Paris, France) | EU ✓ |
| Stripe Payments Europe | EU servers | EU ✓ |
| SuperPDP | France | EU ✓ |
| OpenAPI.com | European Union | EU ✓ |
| Mistral AI | France | EU ✓ |
| BulkGate | Czech Republic | EU ✓ |
| Sentry EU | Frankfurt, Germany | EU ✓ |
| Resend | European Union | EU ✓ |
Consequently, no appropriate safeguards within the meaning of Chapter V of the GDPR (standard contractual clauses, adequacy decision) are required. Should a transfer outside the EU be envisaged in the future, it would be subject to prior notification under Article 6 and to the implementation of the required appropriate safeguards.
Article 8 — Personal data breach
In the event of a personal data breach affecting the Client's data, the Processor notifies the Controller without undue delay and at the latest within 24 hours after becoming aware of it, in order to enable the Controller to notify the supervisory authority (CNIL) within the statutory 72-hour deadline provided for in Article 33 of the GDPR.
The Processor's notification to the Client includes, where possible:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records concerned;
- The contact details of the point of contact from which further information can be obtained;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to address the breach and, where appropriate, to mitigate its consequences.
Where this information cannot be provided at the same time, it shall be provided in phases without undue further delay.
Article 9 — Impact assessment and prior consultation
Taking into account the nature of the processing and the information available to it, the Processor provides the Controller with the reasonable assistance necessary to carry out the data protection impact assessments (DPIA) provided for in Article 35 of the GDPR, as well as the prior consultation of the supervisory authority provided for in Article 36 where a DPIA indicates a high residual risk. To this end, the Processor communicates to the Controller the relevant information relating to the security measures and the architecture of the processing.
Article 10 — Audit and verification of compliance
The Controller may audit the Processor's processing activities once per year, upon 30 calendar days' prior written notice and at its own expense. The audit is conducted under conditions that do not compromise the security of other clients or the continuity of the service.
The Processor may offer, as an alternative to an on-site audit, available audit reports or certifications, which the Controller undertakes to accept provided that they cover the relevant scope:
- ISO 27001 — gap assessment planned for Q3 2026;
- SOC 2 Type II — planned for 2027;
- External penetration test — planned for Q3 2026;
- Response to a written compliance questionnaire within 10 business days.
Article 11 — Liability
Each party is liable for damage caused by the processing under the conditions set out in Article 82 of the GDPR. The Controller is responsible for compliance with its own obligations, in particular the lawfulness of the processing and the provision of information to data subjects. The Processor is liable for damage caused by the processing only where it has not complied with the obligations of the GDPR specifically applicable to processors (in particular Article 28) or where it has acted outside or contrary to the lawful instructions of the Controller.
Article 12 — Retention periods
| Category | Active period | Statutory archiving | Basis |
|---|---|---|---|
| Account data | Term of the contract | 5 years | Civil statute of limitations |
| Invoices and credit notes | Term of the contract | 11 years (Object Lock COMPLIANCE) | French Tax Code (CGI) Art. 54 + Art. L. 123-22 Commercial Code |
| Signed documents | Term of the contract | 10 years | eIDAS statutory limitation |
| Buyer data | Term of the contract | 5 years | Commercial statute of limitations |
| Connection logs | 12 months | — | LCEN Art. 6 II |
Article 13 — Effect at the end of the contract
At the end of the contract, at the Controller's choice:
- 30 days — Provision of an export of the personal data in a structured, commonly used format;
- 60 days — Deletion of the active data from the Processor's systems and those of its Sub-processors, followed by the issuance of a certificate of destruction;
- 11 years — Retention of the fiscal archives (invoices, credit notes and evidence files) under Object Lock COMPLIANCE.
Fiscal exception: invoices, credit notes and evidence files are retained for 11 years under Object Lock COMPLIANCE in accordance with French Tax Code (CGI) Art. 54 and Article L. 123-22 of the Commercial Code. This retention falls under the exception provided for in Article 17.3.b of the GDPR (legal retention obligation). These archives are read-only and cannot be deleted before the expiry of the statutory period, including at the request of the data subject.
Annex 1 — Description of the processing
| Category of data | Operations | Retention | Purpose |
|---|---|---|---|
| Issuer identity | Storage, reading, export, encryption | Contract + 5 years | Account management, invoicing |
| Buyer identity | Storage, reading, update, export | Contract + 5 years | Buyers registry |
| Invoice data | Generation, validation, archiving, transmission to PDP | 11 years (Object Lock) | Invoicing, fiscal compliance |
| Signature data | Collection, secure storage, evidence file | 10 years | EU-SES eIDAS |
| Technical data | Logging, storage, security analysis | 12 months | Security, ISCA audit |
| Payment references | Reference storage (excluding card numbers) | 5 years | Accounting |
Annex 2 — Technical and organisational measures (TOM)
Encryption
- AES-256 — sensitive data at rest (Eloquent encrypted cast);
- TLS 1.3 — all connections in transit;
- S3 Object Lock COMPLIANCE — fiscal archives 11 years, deletion impossible.
Access control
- Row Level Security (RLS) PostgreSQL — strict multi-tenant isolation;
- MFA TOTP — mandatory for administrator access;
- Hashed API keys — non-reversible.
Traceability and integrity
- Immutable SHA-256 chain (ISCA) — anti-mutation PostgreSQL trigger;
- OpenTimestamps — Bitcoin blockchain anchoring (best-effort).
Certifications (forthcoming)
- ISO 27001 — gap assessment planned for Q3 2026;
- SOC 2 Type II — planned for 2027;
- External penetration test — planned for Q3 2026.
Annex 3 — Authorised sub-processors
Last updated: 27 May 2026 (version 1.0)
| Provider | Service | Location | Data transferred | Safeguards |
|---|---|---|---|---|
| Scaleway SAS | Cloud hosting (compute, database, S3) | fr-par (France) | All data | Scaleway DPA |
| Stripe Payments Europe | Online payments | EU servers | Billing data | Stripe DPA |
| SuperPDP SAS | Official PDP (Factur-X) | France | Invoice content | SuperPDP DPA |
| OpenAPI.com | EU-SES signatures | European Union | Signatory data | OpenAPI.com DPA |
| Mistral AI SA | Generative AI (optional) | France | Text queries (no PII) | Mistral AI DPA |
| BulkGate s.r.o. | OTP SMS | EU (Czech Republic) | Phone number + OTP | BulkGate DPA |
| Sentry (Functional Software) | Error tracking | Sentry EU (Frankfurt) | Anonymised stacktraces | Sentry DPA |
| Resend Inc. | Transactional emails | European Union | Email + content | Resend DPA |
Contact and exercise of rights
DPA contact: dpa@scell.io
GDPR rights: privacy@scell.io or Dashboard → Settings → Personal data
Supervisory authority (France): CNIL
DPA version 1.0 — QR Communication SAS — Scell.io — 27 May 2026 This document is available for PDF download from your Scell.io dashboard (Settings → DPA).