Saltar al contenido

Data Processing Agreement

Version 1.0 — 7 August 2026

This Data Processing Agreement ("DPA") forms part of the ReefOffice Terms of Service and applies whenever ReefOffice processes personal data on your behalf. It gives effect to Article 28(3) of Regulation (EU) 2016/679 (GDPR). No signature is required: it applies automatically to every ReefOffice customer. If your organisation needs a countersigned copy, write to contact@reefoffice.com and we will sign yours.

1. Roles

You are the data controller for the personal data you place on your ReefOffice server — your employees, your clients, your suppliers, your records. You decide what is collected and why.

ReefOffice (Robin Angelé EI, trading as Robin4consulting, entrepreneur individuel, SIRET 99906226800019) is the data processor. We host, maintain, back up and support the server on which that data lives. We do not decide what you store or why.

Where ReefOffice processes data about you as our own customer — your billing details, your support tickets, your account — we are the controller, and the Privacy Policy governs that instead.

2. Scope and duration

Subject matter: hosting and operation of a managed private server and the applications running on it. Duration: for as long as your subscription is active, plus the retention window in section 8. Nature and purpose: storage, backup, transmission, and technical support of the data you place on the server.

Categories of data subject and of personal data are determined entirely by you, because you choose what to put on the server. Typically this includes your staff, your customers and your suppliers, and data such as names, contact details, documents, invoices and messages.

3. Processing only on your instructions

We process personal data only on your documented instructions, including the instructions implied by your use of the service. Your configuration of the server, and any written request you send us, are documented instructions for this purpose.

We do not read, mine, sell or use your data for our own purposes, and we never use it to train AI models. If we are ever required by EU or French law to process your data otherwise, we will tell you before doing so unless that law forbids it.

If in our opinion an instruction from you would infringe the GDPR, we will tell you.

4. Confidentiality

Every person authorised to process your personal data is bound by a duty of confidentiality that survives the end of their engagement. ReefOffice is operated by a single named individual; administrative access is not shared, delegated or subcontracted to staff.

5. Security (Article 32)

We implement appropriate technical and organisational measures, described in detail and kept current on our Security page. In summary: full-disk encryption at rest (LUKS2), encryption in transit (TLS), single-tenant servers with no shared application layer, single sign-on with enforced multi-factor authentication, hourly encrypted off-site backups with a weekly restore drill, automated vulnerability scanning, and a tamper-evident audit log.

You control two things that materially affect security and we will not override them: which optional services are enabled, and whether backups use zero-knowledge encryption with a key only you hold.

6. Sub-processors

You give general authorisation for the sub-processors listed on our Providers page, which records each one's role and legal jurisdiction. We will give you at least 30 days' notice by email before adding or replacing a sub-processor, and you may object; if we cannot resolve your objection you may terminate without penalty and take your data with you.

Every sub-processor is bound by data protection obligations no less protective than those in this DPA. We remain fully liable to you for their performance.

7. Assisting you

Data subject rights: because you hold administrative access to your own server, you can usually satisfy access, rectification, erasure and portability requests yourself. Where you cannot, we will assist you at no charge, taking into account the nature of the processing.

We will also assist you, on request, with data protection impact assessments and prior consultation with a supervisory authority, and we will make available the information you need to demonstrate compliance with Article 28.

8. Personal data breaches

We will notify you without undue delay, and in any case within 48 hours, of becoming aware of a personal data breach affecting your data. The notification will describe what happened, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed.

It is your responsibility as controller to notify your supervisory authority and, where required, the affected individuals. We will give you what you need to do so.

9. Deletion and return

On termination you choose: we return your data in open, portable formats, or we delete it. Your ReefOffice server can be exported in full at any time without our involvement — that is a design goal, not a favour.

Unless you ask us to delete immediately, we keep the server and its backups for 30 days after termination so you can recover anything missed, then destroy them. Backup copies age out of the retention schedule within a further 12 months. We do not keep archival copies beyond this.

10. Audits

We will make available all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. In practice most questions are answered by the Security page, the open-source stack, and the per-server security posture panel in your dashboard, which reports what your server actually measures rather than what we claim.

We ask for reasonable notice and that audits do not compromise the security or privacy of other customers.

11. International transfers

Your server, its backups and its AI processing stay within the European Union. Our sub-processors are EU-established, and their jurisdictions are listed on the Providers page. Where any transfer outside the EEA would ever be necessary, we will not make it without first telling you and putting an appropriate Article 46 safeguard in place.

12. Contact

Data protection questions, audit requests and breach enquiries: contact@reefoffice.com. ReefOffice has not appointed a Data Protection Officer, because it does not meet the Article 37 criteria requiring one; the named individual above answers these questions directly.

Need this countersigned?

Send us your own DPA or ask for a signed copy of this one. Either is fine, and neither costs anything.

Contact us