— Aperçu de CONTENU (structure & densité). Le design final = blocks shadcnblocks. Le texte contractuel exact du DPA signé = à finaliser juridiquement. — ← toutes les pages
When you use Reprtoir to manage other people's personal data, we process it on your behalf. This page explains how — and how to put our DPA in place.
Under the GDPR, when you put personal data into Reprtoir — details of artists, rights-holders, contacts — you decide why and how it's used, and we act on your instructions.
You own the relationship with the people whose data you upload, and you determine the purposes of the processing.
We process that data only to provide the service to you, on your documented instructions — nothing more.
Separately, for data we collect as a business (your account, website visitors), Reprtoir is the controller — see our Privacy Policy.
We do not use your data for our own purposes, and we never use your audio to train AI models.
We use a small set of vetted providers to deliver the service. Each is bound by a written agreement with data-protection obligations no less protective than this DPA. We'll give notice before adding or replacing a sub-processor, so you can object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting & data processing | 🇪🇺 EU — Ireland (prod), Paris (backups) |
| Cyanite (elceedee UG) | Audio analysis / tagging | 🇪🇺 EU — Germany |
| PostHog | Product analytics | 🇪🇺 EU |
| Front | Customer support & communication | 🇪🇺 EU — Ireland |
| Stripe | Payment processing | EU (Ireland) + US — SCC/DPF |
| Cloudinary | Media & image delivery | US — SCC/DPF |
| Postmark | Transactional email | US — SCC/DPF |
| Bugsnag | Error & stability monitoring | US — SCC/DPF |
We apply appropriate technical and organisational measures: encryption in transit and at rest, EU-hosted infrastructure, least-privilege and role-based access, two-factor authentication, continuous monitoring and automated security testing. The full picture is on our Security page, which forms part of the measures under this DPA.
If someone in your catalog exercises their GDPR rights (access, correction, deletion, portability), the tools in Reprtoir let you act on it directly — you can find, edit, export and delete records yourself. Where you need more, we'll assist you, taking into account the nature of the processing.
If we become aware of a personal-data breach affecting your data, we'll notify you without undue delay, with the information you need to meet your own notification duties. Live platform status is always at status.reprtoir.com.
Your catalog data is hosted in the EU. Where a sub-processor processes data outside the EU (see the table above), we rely on appropriate safeguards — EU Standard Contractual Clauses (SCC) and, where applicable, the EU–US Data Privacy Framework (DPF). [safeguards to confirm per vendor]
When your subscription ends, you can export everything (CSV/Excel or API). After that, we delete or anonymise the personal data we processed on your behalf within 45 days of the final deletion notice, subject to limited backup cycles and any retention the law requires of us. No penalty to leave, no data held hostage.
We countersign our standard DPA, including the EU Standard Contractual Clauses where relevant. Send it our way and our team will handle it for your procurement and legal review.