DIFFUSONS
DIFFUSONS · LEGAL

Data Processing Agreement

Operational GDPR clauses applicable to data processed on behalf of customers.

Last updated: 17 July 2026

1. Roles

For the CRM data, content, subscribers, messages and campaigns managed by a customer, the customer is the data controller and IXYS acts as processor. IXYS remains the data controller for the management of the service, billing, security, support and its own legal obligations.

2. Documented instructions

IXYS processes the data solely to provide Diffusons, to carry out the actions requested by the customer, to ensure security, to produce exports, to handle deletions and to comply with legal obligations. Any unlawful or manifestly disproportionate instruction may be refused and documented.

3. Sub-processors (« sous-traitants ultérieurs »)

IXYS may use providers that are necessary to the service: hosting, storage, payment, SMS, email, AI and the platforms connected by the customer. The list is kept in the application's compliance register. IXYS imposes confidentiality and security obligations appropriate to each provider.

4. Security

IXYS implements technical and organisational measures: multi-tenant isolation, access control, private storage, encryption of sensitive fields, logging, operator MFA, backups, restriction of exports and scheduled purging of data that no longer serves a purpose.

5. Assistance to the customer

IXYS assists the customer with requests to exercise rights, exports, deletion, restriction, incidents, data protection impact assessments (DPIA — « AIPD ») and reasonable audits. Requests are tracked with their date of receipt, deadline and closure.

6. Data breaches

IXYS documents every breach in an internal register, assesses the risk, prepares the notification material and informs the customer without undue delay where the breach concerns its data.

7. Return, destruction and audit

At the end of the contract, IXYS allows the data to be exported, then purges or anonymises the operational data. Legally required records are kept in a minimised archive for the required period. Customers may request reasonable audit material evidencing the performance of the return and destruction measures, excluding security secrets or other customers' data.