⚠ Version bêta — non validée par un conseil juridique

Ce document est publié sans revue préalable par un avocat ou un DPO externe. Il décrit la situation réelle du traitement de vos données aussi précisément que possible et sera mis à jour dès qu'une revue juridique aura été réalisée. Aucune clause ne doit être présentée comme définitivement opposable sans cette revue.

Dernière mise à jour : 2026-08-16 · Contact : direction@helix-core.io

Data Processing Agreement (DPA)

Helix-Core SAS · GDPR Art. 28 · v1.0 · 2026-05-08

1. Parties

This Data Processing Agreement ("DPA") is entered into between :

2. Subject matter and duration

Helix-Core processes Customer's data solely to provide AaaS (Agents-as-a-Service) cascade functionality. Duration : term of the Service Agreement.

3. Categories of data subjects

4. Categories of personal data

5. Sub-processors

Helix-Core uses the following sub-processors :

Les garanties contractuelles (clauses contractuelles types / Data Privacy Framework) avec chacun de ces sous-traitants sont en cours de confirmation. Nous préférons vous l'indiquer plutôt que d'affirmer une conformité que nous n'avons pas vérifiée pour chacun.

Sub-processor certifications beyond the contractual SCC (including Data Privacy Framework participation) are verified individually against each provider's own published documentation and the official DPF list. This page states only what those documents state.

6. Technical and organizational measures (Art. 32)

7. Data subject rights

Helix-Core supports Customer in fulfilling :

8. Breach notification (Art. 33-34)

Helix-Core notifies Customer of any personal data breach within 72 hours via email + audit_log entry severity=critical.

9. International transfers

For data residing in non-EU regions, Helix-Core relies on EU Standard Contractual Clauses (SCC) 2021/914. Where a given sub-processor additionally participates in the EU-U.S. Data Privacy Framework, that participation supplements — and does not replace — the contractual clauses, and is verified against that provider's own documentation.

10. Audits

Customer may audit Helix-Core compliance once per year (or upon material breach) with 30 days notice.

Signature

Pour signature électronique : legal@helix-core.io
Helix-Core retournera la version signée sous 5 jours ouvrés.

Helix-Core SAS · 2026-05-08 · DPA v1.0 · GDPR Art. 28 compliant