HygiControl
Data processing agreement
Processing of personal data — Article 28 of Regulation (EU) 2016/679
Updated: 6 August 2026·DPA-HC-2026-001 · V1.0
This agreement is concluded between the Client, acting as data controller, and the company EASYTECH SOLUTIONS, acting as subcontractor, for the use of the HygiControl service. It constitutes an inseparable annex from the General Subscription Conditions and is accepted under the same terms. It defines the conditions under which the subcontractor processes personal data on behalf of the data controller. If language versions diverge, the French version prevails.
Article 1 — Games and qualification
- Part
- The Customer
- Identify
- The legal entity or professional holding the subscription, identified in the order summary.
- Quality
- Data controller. It determines the purposes and means of processing: it decides to deploy the service, chooses the activated modules, configures the thresholds and durations, and designates the people with access.
- Part
- The Subcontractor
- Identify
- EASYTECH SOLUTIONS, SAS au capital de 1 000 euros, SIREN 108 197 278, 8 avenue Émile Dambel, 93420 Villepinte, France.
- Quality
- Subcontractor within the meaning of article 4.8 of the regulation. It processes the data on behalf of the Client and only on the Client's documented instructions.
The Subcontractor also processes, as an independent data controller, data relating to the management of the commercial relationship (contacts, invoicing, support). These treatments do not fall under this agreement and are described in the Privacy Policy.
Article 2 — Purpose, duration and description of the processing
The Subcontractor is authorized to process the personal data necessary for the provision of the HygiControl service, for the sole execution of the purposes described below.
- Nature of operations
- Collection, recording, organization, structuring, conservation, consultation, use, extraction, communication by transmission, erasure and destruction, carried out by means of automated processes.
- Purposes
- Allow the Customer to organize, record and keep their health self-checks; attribute each recording to its author in order to ensure its probative value; send alerts and reminders; produce reports and exports; where applicable, monitor working time when the corresponding module is activated by the Client.
- Duration of treatment
- For the duration of the subscription, increased by the return and retention periods provided for in article 10.
- Territory
- European Union. The main accommodation is located in France. No transfer outside the European Union is carried out other than in the cases covered by Article 7.
Article 3 — Categories of people and data
- Categories of people
- Employees and collaborators of the Client using the service (employees, establishment managers)
- Data categories
- Identity (surname, first name), professional email address, role and establishment, connection identifier and password in condensed form, profile photograph provided at registration, connection logs.
- Comments
- The profile photograph is an element of internal identification. No biometric processing is implemented under this agreement.
- Categories of people
- Employees, in respect of their activity
- Data categories
- Sanitary records time-stamped and attributed to their author: temperature readings, receipt checks, batch traceability, cleaning tasks, non-conformities; photographs taken in a professional setting.
- Comments
- This data concerns professional activity and not private life.
- Categories of people
- Employees, if the time tracking module is activated by the Client
- Data categories
- Timestamp of arrivals and exits, establishment concerned, and result of on-site presence verification.
- Comments
- The Client activates this module on his own initiative and is responsible for assessing its proportionality, informing people and consulting staff representatives.
- Categories of people
- Customer contacts (suppliers, service providers, stakeholders)
- Data categories
- Name of the organization, name of the contact, professional contact details entered by the Client.
- Comments
- Entries at the initiative of the Customer in the repositories.
Article 4 — Obligations of the Subcontractor
The Subcontractor undertakes to:
- Process data only on documented instructions from the Customer, including in matters of transfer outside the European Union. These constitute the initial instruction; the settings made by the Customer in the service and their written requests constitute the complement. If the Subcontractor considers that an instruction constitutes a violation of the regulations, it immediately informs the Client.
- Guarantee the confidentiality of data and ensure that the people authorized to process them are subject to an obligation of confidentiality and receive the necessary training.
- Implement the technical and organizational measures described in Article 6.
- Comply with the conditions for using a subcontractor defined in Article 5.
- Help the Client, through appropriate technical and organizational measures, to respond to requests to exercise rights (article 8).
- Help the Client ensure compliance with its security, breach notification and, where applicable, impact analysis obligations, taking into account the information available to it.
- Notify the Customer of any data breach under the conditions of article 9.
- Delete or return the data at the end of the contract, under the conditions of article 10.
- Make available to the Client all information necessary to demonstrate compliance with this agreement and allow audits to be carried out under the conditions of article 11.
- Maintain a record of the categories of processing activities carried out on behalf of the Client, in accordance with Article 30.2 of the Regulation.
Article 5 — Sub-processors
The Client authorizes the Subcontractor to use the service providers listed below, whose intervention is necessary for the provision of the service. This authorization constitutes a general written authorization within the meaning of article 28.2 of the regulation.
- Sub-processor
- Hostinger International Limited
- Benefit
- Hosting of application servers and interfaces
- Data localization
- France (Paris) — European Union
- Sub-processor
- Supabase
- Benefit
- Database hosting
- Data localization
- European Union
- Sub-processor
- Amazon Web Services
- Benefit
- Storage of photographs and documents; sending transactional emails
- Data localization
- European Union
- Sub-processor
- Stripe
- Benefit
- Payment processing and invoicing
- Data localization
- European Union, with contractual guarantees for treatments carried out outside the Union
- Sub-processor
- Google Ireland Limited
- Benefit
- Delivery of notifications to mobile terminals; geocoding of establishment addresses
- Data localization
- European Union, with contractual guarantees for treatments carried out outside the Union
- Sub-processor
- Sentry
- Benefit
- Detection and diagnosis of technical errors
- Data localization
- European Union (Germany)
The Processor imposes on each sub-processor data protection obligations equivalent to those in this agreement. He remains fully responsible towards the Client for their execution of their obligations.
Subsequent change of subcontractor. The Subcontractor informs the Client of any addition or replacement project, by email and by publication of the updated list, at least thirty days before its implementation. The Customer has this period to submit a reasoned objection relating to data protection. In the event of an objection that the parties are unable to resolve, the Customer may terminate the subscription without cost or compensation, for the part of the service concerned.
Article 6 — Security
Taking into account the state of knowledge, the implementation costs, the nature and the risks of the processing, the Subcontractor implements the following measures:
- Encryption
- Systematic encryption of communications between applications and servers (TLS protocol). Data encryption at rest provided by hosting infrastructures.
- Authentication
- Passwords kept in the form of condensates and never in plain text. Minimum complexity requirements (twelve characters, combination of character types, refusal of common passwords). Temporary account blocking after five unsuccessful attempts. Limiting the number of simultaneous sessions.
- Access control
- Management by role: each user only accesses the data of their establishment and their functional scope. Strict partitioning of data between client organizations. Limited authorization of Subcontractor personnel, according to the principle of least privilege.
- Traceability
- Logging of connections and administrative actions. Any support intervention on a client organization is recorded. The Subcontractor's personnel do not log in under the identity of a user.
- Availability and backups
- Backups provided by the hosting and infrastructure providers mentioned in Article 5, as part of their service systems and guarantees.
- Application security
- Limiting the number of calls to the service to prevent mass mining and automated attacks. Regular security updates and software dependency monitoring.
- Mobile terminals
- Authentication tokens are stored in the operating system's secure vault. Data stored locally is erased upon disconnection.
These measures may evolve, without the overall level of security being reduced. The Client acknowledges that it is up to him to implement measures within his own scope: management of his users' authorizations, security of his terminals, removal of access to people who have left the company.
Article 7 — Transfers outside the European Union
The data is hosted and processed within the European Union. When a subcontractor is likely to carry out processing outside the Union, in particular for the purposes of technical support, this transfer is governed by the standard contractual clauses adopted by the European Commission, supplemented where appropriate by additional technical measures such as encryption and minimization of the data transmitted.
The Subcontractor prohibits any unsupervised transfer and informs the Client of any developments in this matter.
Article 8 — Rights of data subjects
It is up to the Client, as data controller, to inform the persons concerned and respond to requests to exercise their rights.
The Subcontractor assists the Client in this obligation. This assistance is included in the subscription and includes in particular: the search and extraction of data relating to a specific person, the production of a readable export, the rectification of inaccurate data, the anonymization or deletion of elements when regulations permit, and information on the retention periods applied.
The request for assistance is made using the forms provided in the service or by email to contact@easytechsolutions.fr. It is processed within a time frame allowing the Customer to meet the one-month deadline incumbent upon them.
When a data subject contacts the Subcontractor directly, the latter does not process the request and transmits it without delay to the Client, informing the person of this transmission.
Article 9 — Data breach
The Subcontractor notifies the Client of any personal data breach as soon as possible and at the latest within forty-eight hours after becoming aware of it, in order to enable the Client to respect the seventy-two hour deadline which is incumbent upon it with regard to the supervisory authority.
The notification shall include, to the extent of available information: the nature of the violation, the categories and approximate number of persons and records concerned, the probable consequences, the measures taken or envisaged to remedy it and mitigate its effects, as well as a point of contact. Missing information is communicated gradually.
The Processor cooperates with the Customer and documents each violation. It is not the Subcontractor's responsibility to notify the supervisory authority or to inform the persons concerned: these obligations are the responsibility of the Client.
Article 10 — Fate of data at the end of the contract
- Stage
- Restitution
- Deadline
- Thirty days from the end of the contract
- Data processing
- The Client exports his data independently from the service, in spreadsheet and PDF formats, including the archive of photographs. The Subcontractor can assist in this operation.
- Stage
- Conservation
- Deadline
- Six months maximum from the end of the contract
- Data processing
- The data is kept without application access, in order to allow subscription recovery, late recovery or to meet a legal obligation. They are not subject to any other processing.
- Stage
- Deletion
- Deadline
- At the end of the six-month period, or in advance upon written request from the Client
- Data processing
- Deletion of data from production systems, then backups according to the rotation cycle of hosting providers. Written confirmation is sent to the Customer upon request.
- Stage
- Exception
- Deadline
- Applicable legal durations
- Data processing
- Documents whose retention is required by law, in particular invoices and accounting documents, are kept for the legal period. They relate to the processing carried out by the Subcontractor as an independent manager.
Article 11 — Documentation, audits and cooperation
The Subcontractor makes available to the Client the information necessary to demonstrate compliance with the obligations of this agreement, in particular the list of subcontractors, the description of security measures and information relating to data localization.
The Client may carry out an audit, at most once a year, upon thirty days' written notice, during working hours and without disrupting the Subcontractor's activity. The audit may be carried out by the Client or by an independent auditor subject to an obligation of confidentiality, and cannot infringe the confidentiality of other clients' data or business secrecy. Costs incurred by the Subcontractor beyond the provision of documentation may be invoiced with supporting documentation. An additional audit may be carried out following a proven data breach.
The parties shall cooperate with the supervisory authority in the event of any request or procedure concerning it.
Article 12 — Customer Obligations
The Client, as data controller, undertakes to:
- ensure the lawfulness of the processing and have an appropriate legal basis;
- inform the people concerned, in particular its employees, prior to the implementation of the service and each activated module;
- consult, if necessary, staff representatives, in particular when activating a functionality allowing the monitoring of employee activity;
- register the processing in its register and, where required, carry out a data protection impact analysis;
- assess the proportionality of the functionalities it activates with regard to the purposes pursued and the alternative means available;
- configure retention periods adapted to its obligations and exposure;
- manage the authorizations of its users and immediately withdraw access from people who have left the company;
- document its instructions and do not record any excluded data within the meaning of Article 3.
Article 13 — Liability, duration and final provisions
Each party is liable for damage caused by processing in violation of the regulations, under the conditions of article 82. The Subcontractor's liability is assessed within the limits provided for by the General Subscription Conditions, without these limits being able to hinder the rights of the persons concerned nor the powers of the supervisory authority.
This agreement enters into force on the date of acceptance of the General Subscription Conditions and remains applicable for the entire duration of the processing, including during the restitution and retention periods provided for in Article 10.
It may be modified to take into account regulatory developments or a decision by the supervisory authority. The Customer is informed at least thirty days before the changes come into force.
In the event of any contradiction between this agreement and the General Subscription Conditions, this agreement takes precedence for all matters relating to the processing of personal data. This agreement is subject to French law; Disputes fall under the jurisdiction of the commercial court of Bobigny.