HygiControl logo
Start free trial

HygiControl

Data processing agreement

Processing of personal data — Article 28 of Regulation (EU) 2016/679

Updated: 6 August 2026·DPA-HC-2026-001 · V1.0

This agreement is concluded between the Client, acting as data controller, and the company EASYTECH SOLUTIONS, acting as subcontractor, for the use of the HygiControl service. It constitutes an inseparable annex from the General Subscription Conditions and is accepted under the same terms. It defines the conditions under which the subcontractor processes personal data on behalf of the data controller. If language versions diverge, the French version prevails.

Article 1 — Games and qualification

Part
The Customer
Identify
The legal entity or professional holding the subscription, identified in the order summary.
Quality
Data controller. It determines the purposes and means of processing: it decides to deploy the service, chooses the activated modules, configures the thresholds and durations, and designates the people with access.
Part
The Subcontractor
Identify
EASYTECH SOLUTIONS, SAS au capital de 1 000 euros, SIREN 108 197 278, 8 avenue Émile Dambel, 93420 Villepinte, France.
Quality
Subcontractor within the meaning of article 4.8 of the regulation. It processes the data on behalf of the Client and only on the Client's documented instructions.
This distribution is essential: it is the Client who is responsible, with regard to his employees and the authorities, for the lawfulness of the processing, the information of people and the formalities incumbent on him. The Subcontractor is responsible for the security and compliance of the operations it carries out on its behalf.

The Subcontractor also processes, as an independent data controller, data relating to the management of the commercial relationship (contacts, invoicing, support). These treatments do not fall under this agreement and are described in the Privacy Policy.

Article 2 — Purpose, duration and description of the processing

The Subcontractor is authorized to process the personal data necessary for the provision of the HygiControl service, for the sole execution of the purposes described below.

Nature of operations
Collection, recording, organization, structuring, conservation, consultation, use, extraction, communication by transmission, erasure and destruction, carried out by means of automated processes.
Purposes
Allow the Customer to organize, record and keep their health self-checks; attribute each recording to its author in order to ensure its probative value; send alerts and reminders; produce reports and exports; where applicable, monitor working time when the corresponding module is activated by the Client.
Duration of treatment
For the duration of the subscription, increased by the return and retention periods provided for in article 10.
Territory
European Union. The main accommodation is located in France. No transfer outside the European Union is carried out other than in the cases covered by Article 7.

Article 3 — Categories of people and data

Categories of people
Employees and collaborators of the Client using the service (employees, establishment managers)
Data categories
Identity (surname, first name), professional email address, role and establishment, connection identifier and password in condensed form, profile photograph provided at registration, connection logs.
Comments
The profile photograph is an element of internal identification. No biometric processing is implemented under this agreement.
Categories of people
Employees, in respect of their activity
Data categories
Sanitary records time-stamped and attributed to their author: temperature readings, receipt checks, batch traceability, cleaning tasks, non-conformities; photographs taken in a professional setting.
Comments
This data concerns professional activity and not private life.
Categories of people
Employees, if the time tracking module is activated by the Client
Data categories
Timestamp of arrivals and exits, establishment concerned, and result of on-site presence verification.
Comments
The Client activates this module on his own initiative and is responsible for assessing its proportionality, informing people and consulting staff representatives.
Categories of people
Customer contacts (suppliers, service providers, stakeholders)
Data categories
Name of the organization, name of the contact, professional contact details entered by the Client.
Comments
Entries at the initiative of the Customer in the repositories.
Data excluded. The service is not intended to receive data falling under Article 9 of the regulation (health data, opinions, trade union membership, biometric or genetic data), nor data relating to convictions. The Customer is prohibited from recording any, particularly in free fields and comments, and alone bears the consequences of such recording.

Article 4 — Obligations of the Subcontractor

The Subcontractor undertakes to:

  • Process data only on documented instructions from the Customer, including in matters of transfer outside the European Union. These constitute the initial instruction; the settings made by the Customer in the service and their written requests constitute the complement. If the Subcontractor considers that an instruction constitutes a violation of the regulations, it immediately informs the Client.
  • Guarantee the confidentiality of data and ensure that the people authorized to process them are subject to an obligation of confidentiality and receive the necessary training.
  • Implement the technical and organizational measures described in Article 6.
  • Comply with the conditions for using a subcontractor defined in Article 5.
  • Help the Client, through appropriate technical and organizational measures, to respond to requests to exercise rights (article 8).
  • Help the Client ensure compliance with its security, breach notification and, where applicable, impact analysis obligations, taking into account the information available to it.
  • Notify the Customer of any data breach under the conditions of article 9.
  • Delete or return the data at the end of the contract, under the conditions of article 10.
  • Make available to the Client all information necessary to demonstrate compliance with this agreement and allow audits to be carried out under the conditions of article 11.
  • Maintain a record of the categories of processing activities carried out on behalf of the Client, in accordance with Article 30.2 of the Regulation.

Article 5 — Sub-processors

The Client authorizes the Subcontractor to use the service providers listed below, whose intervention is necessary for the provision of the service. This authorization constitutes a general written authorization within the meaning of article 28.2 of the regulation.

Sub-processor
Hostinger International Limited
Benefit
Hosting of application servers and interfaces
Data localization
France (Paris) — European Union
Sub-processor
Supabase
Benefit
Database hosting
Data localization
European Union
Sub-processor
Amazon Web Services
Benefit
Storage of photographs and documents; sending transactional emails
Data localization
European Union
Sub-processor
Stripe
Benefit
Payment processing and invoicing
Data localization
European Union, with contractual guarantees for treatments carried out outside the Union
Sub-processor
Google Ireland Limited
Benefit
Delivery of notifications to mobile terminals; geocoding of establishment addresses
Data localization
European Union, with contractual guarantees for treatments carried out outside the Union
Sub-processor
Sentry
Benefit
Detection and diagnosis of technical errors
Data localization
European Union (Germany)

The Processor imposes on each sub-processor data protection obligations equivalent to those in this agreement. He remains fully responsible towards the Client for their execution of their obligations.

Subsequent change of subcontractor. The Subcontractor informs the Client of any addition or replacement project, by email and by publication of the updated list, at least thirty days before its implementation. The Customer has this period to submit a reasoned objection relating to data protection. In the event of an objection that the parties are unable to resolve, the Customer may terminate the subscription without cost or compensation, for the part of the service concerned.

Article 6 — Security

Taking into account the state of knowledge, the implementation costs, the nature and the risks of the processing, the Subcontractor implements the following measures:

Encryption
Systematic encryption of communications between applications and servers (TLS protocol). Data encryption at rest provided by hosting infrastructures.
Authentication
Passwords kept in the form of condensates and never in plain text. Minimum complexity requirements (twelve characters, combination of character types, refusal of common passwords). Temporary account blocking after five unsuccessful attempts. Limiting the number of simultaneous sessions.
Access control
Management by role: each user only accesses the data of their establishment and their functional scope. Strict partitioning of data between client organizations. Limited authorization of Subcontractor personnel, according to the principle of least privilege.
Traceability
Logging of connections and administrative actions. Any support intervention on a client organization is recorded. The Subcontractor's personnel do not log in under the identity of a user.
Availability and backups
Backups provided by the hosting and infrastructure providers mentioned in Article 5, as part of their service systems and guarantees.
Application security
Limiting the number of calls to the service to prevent mass mining and automated attacks. Regular security updates and software dependency monitoring.
Mobile terminals
Authentication tokens are stored in the operating system's secure vault. Data stored locally is erased upon disconnection.

These measures may evolve, without the overall level of security being reduced. The Client acknowledges that it is up to him to implement measures within his own scope: management of his users' authorizations, security of his terminals, removal of access to people who have left the company.

Article 7 — Transfers outside the European Union

The data is hosted and processed within the European Union. When a subcontractor is likely to carry out processing outside the Union, in particular for the purposes of technical support, this transfer is governed by the standard contractual clauses adopted by the European Commission, supplemented where appropriate by additional technical measures such as encryption and minimization of the data transmitted.

The Subcontractor prohibits any unsupervised transfer and informs the Client of any developments in this matter.

Article 8 — Rights of data subjects

It is up to the Client, as data controller, to inform the persons concerned and respond to requests to exercise their rights.

The Subcontractor assists the Client in this obligation. This assistance is included in the subscription and includes in particular: the search and extraction of data relating to a specific person, the production of a readable export, the rectification of inaccurate data, the anonymization or deletion of elements when regulations permit, and information on the retention periods applied.

The request for assistance is made using the forms provided in the service or by email to contact@easytechsolutions.fr. It is processed within a time frame allowing the Customer to meet the one-month deadline incumbent upon them.

When a data subject contacts the Subcontractor directly, the latter does not process the request and transmits it without delay to the Client, informing the person of this transmission.

Article 9 — Data breach

The Subcontractor notifies the Client of any personal data breach as soon as possible and at the latest within forty-eight hours after becoming aware of it, in order to enable the Client to respect the seventy-two hour deadline which is incumbent upon it with regard to the supervisory authority.

The notification shall include, to the extent of available information: the nature of the violation, the categories and approximate number of persons and records concerned, the probable consequences, the measures taken or envisaged to remedy it and mitigate its effects, as well as a point of contact. Missing information is communicated gradually.

The Processor cooperates with the Customer and documents each violation. It is not the Subcontractor's responsibility to notify the supervisory authority or to inform the persons concerned: these obligations are the responsibility of the Client.

Article 10 — Fate of data at the end of the contract

Stage
Restitution
Deadline
Thirty days from the end of the contract
Data processing
The Client exports his data independently from the service, in spreadsheet and PDF formats, including the archive of photographs. The Subcontractor can assist in this operation.
Stage
Conservation
Deadline
Six months maximum from the end of the contract
Data processing
The data is kept without application access, in order to allow subscription recovery, late recovery or to meet a legal obligation. They are not subject to any other processing.
Stage
Deletion
Deadline
At the end of the six-month period, or in advance upon written request from the Client
Data processing
Deletion of data from production systems, then backups according to the rotation cycle of hosting providers. Written confirmation is sent to the Customer upon request.
Stage
Exception
Deadline
Applicable legal durations
Data processing
Documents whose retention is required by law, in particular invoices and accounting documents, are kept for the legal period. They relate to the processing carried out by the Subcontractor as an independent manager.

Article 11 — Documentation, audits and cooperation

The Subcontractor makes available to the Client the information necessary to demonstrate compliance with the obligations of this agreement, in particular the list of subcontractors, the description of security measures and information relating to data localization.

The Client may carry out an audit, at most once a year, upon thirty days' written notice, during working hours and without disrupting the Subcontractor's activity. The audit may be carried out by the Client or by an independent auditor subject to an obligation of confidentiality, and cannot infringe the confidentiality of other clients' data or business secrecy. Costs incurred by the Subcontractor beyond the provision of documentation may be invoiced with supporting documentation. An additional audit may be carried out following a proven data breach.

The parties shall cooperate with the supervisory authority in the event of any request or procedure concerning it.

Article 12 — Customer Obligations

The Client, as data controller, undertakes to:

  • ensure the lawfulness of the processing and have an appropriate legal basis;
  • inform the people concerned, in particular its employees, prior to the implementation of the service and each activated module;
  • consult, if necessary, staff representatives, in particular when activating a functionality allowing the monitoring of employee activity;
  • register the processing in its register and, where required, carry out a data protection impact analysis;
  • assess the proportionality of the functionalities it activates with regard to the purposes pursued and the alternative means available;
  • configure retention periods adapted to its obligations and exposure;
  • manage the authorizations of its users and immediately withdraw access from people who have left the company;
  • document its instructions and do not record any excluded data within the meaning of Article 3.
The Subcontractor provides the Client with models intended to facilitate these procedures: information note for employees, standard notice for the register and consultation framework for staff representatives.

Article 13 — Liability, duration and final provisions

Each party is liable for damage caused by processing in violation of the regulations, under the conditions of article 82. The Subcontractor's liability is assessed within the limits provided for by the General Subscription Conditions, without these limits being able to hinder the rights of the persons concerned nor the powers of the supervisory authority.

This agreement enters into force on the date of acceptance of the General Subscription Conditions and remains applicable for the entire duration of the processing, including during the restitution and retention periods provided for in Article 10.

It may be modified to take into account regulatory developments or a decision by the supervisory authority. The Customer is informed at least thirty days before the changes come into force.

In the event of any contradiction between this agreement and the General Subscription Conditions, this agreement takes precedence for all matters relating to the processing of personal data. This agreement is subject to French law; Disputes fall under the jurisdiction of the commercial court of Bobigny.

HygiControl