🆕 NOUVELLE PAGE — DPA · n'existe pas sur le site actuel  |  Reprtoir = sous-traitant (processor) des données de tes clients  |  ⚠️ à valider juridiquement (Dominique)
🎯 SEO v2  |  title : Data Processing Agreement (DPA) | Reprtoir (41 car.)  |  meta : How Reprtoir processes your data as your GDPR processor — roles, sub-processors, security, transfers, breach notification and how to sign our DPA. (151 car.)

— Aperçu de CONTENU (structure & densité). Le design final = blocks shadcnblocks. Le texte contractuel exact du DPA signé = à finaliser juridiquement. — ← toutes les pages

Legal · For our customers

Data Processing Agreement

When you use Reprtoir to manage other people's personal data, we process it on your behalf. This page explains how — and how to put our DPA in place.

Who does what

Under the GDPR, when you put personal data into Reprtoir — details of artists, rights-holders, contacts — you decide why and how it's used, and we act on your instructions.

You

Controller

You own the relationship with the people whose data you upload, and you determine the purposes of the processing.

Reprtoir SAS

Processor

We process that data only to provide the service to you, on your documented instructions — nothing more.

Separately, for data we collect as a business (your account, website visitors), Reprtoir is the controller — see our Privacy Policy.

What we process, and why

  • Subject-matter: providing the Reprtoir platform to you.
  • Duration: for as long as your subscription is active, plus limited return/deletion periods.
  • Nature & purpose: hosting, organising, analysing and delivering the catalog and business data you manage.
  • Types of data: identification and contact details, professional and rights information, and any personal data you choose to store in your catalog and contracts.
  • Data subjects: the artists, rights-holders, collaborators and contacts in your catalog.

We do not use your data for our own purposes, and we never use your audio to train AI models.

Our sub-processors

We use a small set of vetted providers to deliver the service. Each is bound by a written agreement with data-protection obligations no less protective than this DPA. We'll give notice before adding or replacing a sub-processor, so you can object.

Sub-processorPurposeLocation
Amazon Web ServicesHosting & data processing🇪🇺 EU — Ireland (prod), Paris (backups)
Cyanite (elceedee UG)Audio analysis / tagging🇪🇺 EU — Germany
PostHogProduct analytics🇪🇺 EU
FrontCustomer support & communication🇪🇺 EU — Ireland
StripePayment processingEU (Ireland) + US — SCC/DPF
CloudinaryMedia & image deliveryUS — SCC/DPF
PostmarkTransactional emailUS — SCC/DPF
BugsnagError & stability monitoringUS — SCC/DPF

Security measures

We apply appropriate technical and organisational measures: encryption in transit and at rest, EU-hosted infrastructure, least-privilege and role-based access, two-factor authentication, continuous monitoring and automated security testing. The full picture is on our Security page, which forms part of the measures under this DPA.

Helping you with data-subject requests

If someone in your catalog exercises their GDPR rights (access, correction, deletion, portability), the tools in Reprtoir let you act on it directly — you can find, edit, export and delete records yourself. Where you need more, we'll assist you, taking into account the nature of the processing.

Breach notification

If we become aware of a personal-data breach affecting your data, we'll notify you without undue delay, with the information you need to meet your own notification duties. Live platform status is always at status.reprtoir.com.

International transfers

Your catalog data is hosted in the EU. Where a sub-processor processes data outside the EU (see the table above), we rely on appropriate safeguards — EU Standard Contractual Clauses (SCC) and, where applicable, the EU–US Data Privacy Framework (DPF). [safeguards to confirm per vendor]

Return & deletion at the end

When your subscription ends, you can export everything (CSV/Excel or API). After that, we delete or anonymise the personal data we processed on your behalf within 45 days of the final deletion notice, subject to limited backup cycles and any retention the law requires of us. No penalty to leave, no data held hostage.

Need our DPA signed?

We countersign our standard DPA, including the EU Standard Contractual Clauses where relevant. Send it our way and our team will handle it for your procurement and legal review.