Data Processing Agreement

Version 1.0 — 2026-08-12. This DPA forms part of the service terms for every NormDrift account. A countersigned copy is available to customers on request (romain@normdrift.com).

1. Roles and scope

For the reference documents (invoices) you upload to a project, you are the data controller and NormDrift is the data processor (GDPR Art. 28). NormDrift is operated by Romain Hoareau, French sole trader, RCS Évry 888 902 954, 7 rue des Provinces, 91410 Dourdan, France (« the Processor »). This DPA covers all personal data contained in uploaded documents and processed for the sole purpose of providing the service.

2. Nature and purpose of processing

Storage (encrypted), validation against official e-invoicing rulesets, computation of per-document results and diffs, and alerting — nothing else. No advertising, no profiling, no automated decision-making, no training of models on your data. Processing lasts as long as your account exists, within the retention window you configure.

3. Categories of data and data subjects

E-invoices typically contain: business contact identities (names, e-mails, phone numbers), postal addresses, company identifiers, bank account references, and transaction amounts. Data subjects are typically your customers', suppliers' and employees' business contacts. You are responsible for having a lawful basis to submit these documents.

4. Instructions

The Processor processes data only on your documented instructions — using the service is the instruction set (upload, run, delete, configure retention). The Processor will inform you if, in its opinion, an instruction infringes the GDPR.

5. Security measures (Art. 32)

  • Documents encrypted at rest with AES-256-GCM (platform-held key), TLS 1.2+ in transit everywhere.
  • Storage in EU-jurisdiction infrastructure only (Cloudflare R2 EU jurisdiction; database in Western Europe).
  • The validation engine processes documents in memory and stores nothing on its host.
  • No invoice content, e-mail addresses or secrets in application logs (dedicated review, enforced in code).
  • Access limited to the operator; admin surface protected by secret token; single-use, expiring sign-in links.
  • Automatic nightly purge of detailed results beyond your project's retention window (30/90/180/365 days).

6. Sub-processors

You authorise the following sub-processors. The Processor will announce any change on this page at least 30 days before it takes effect; you may object by terminating the service (deletion is immediate, see §8).

Sub-processorPurposeLocation / transfer basis
Cloudflare, Inc.Hosting, storage, database, queuesData stored in EU jurisdiction; Cloudflare is US-based — EU-US Data Privacy Framework + SCCs
Contabo GmbHValidation compute (in-memory only)Germany (EU)
Brevo (Sendinblue SAS)Transactional e-mail — receives account e-mail addresses only, never invoice contentFrance (EU)
Stripe, Inc.Payments — billing data only, never invoice contentUS — EU-US Data Privacy Framework + SCCs

7. Assistance and audits

The Processor assists you, insofar as possible, in responding to data-subject requests (Arts. 12-23) and in your Art. 32-36 obligations. On request, the Processor makes available the information necessary to demonstrate compliance with Art. 28, including this document, sub-processor certifications, and a description of the measures in §5. Personnel with access are bound by confidentiality.

8. Breach notification

The Processor notifies you without undue delay after becoming aware of a personal-data breach affecting your data, with the information required by Art. 33(3) as it becomes available, to your account e-mail and configured alert channels.

9. Deletion and return

Deleting a document, a project or your account hard-deletes the corresponding data immediately (documents, results, reports, keys) — no backups of your corpus are retained beyond the platform provider's transient replication. You can export your documents at any time before deletion (you already hold the originals by construction). Free-validator submissions are processed in memory and never stored.

10. Liability and order of precedence

This DPA prevails over the general terms for personal-data matters. Liability follows the service terms. Governing law: France. Supervisory authority: CNIL.