GDPR data processing agreement (Article 28) — pseudonymized architecture, security measures, framed transfers.
Agreement on the Processing of Personal Data
| Version | 1.0 |
| Last updated | May 18, 2026 |
| Canonical URL | https://www.titane-intelligence.com/en/legal/dpa |
| Principal document | Incorporated by reference into the Subscription Agreement (MSA) |
Preliminary note. This Data Processing Agreement (the "DPA") is incorporated by reference into the Subscription Agreement (MSA) entered into between Titane Intelligence and the Customer. It is accepted at the same time as the MSA under the conditions of Article 17 of the MSA. A PDF version signed by Titane may be made available upon request sent to
contact@titane-intelligence.com.
In the course of performing the Subscription Agreement, Titane Intelligence may process personal data on behalf of the Customer. The Parties wish to govern such processing in accordance with the requirements of:
The terms used in this DPA have the meaning given by Article 4 of the GDPR. In particular, the following apply:
"Controller" or "Controller" means the entity that determines the purposes and means of the processing (Article 4(7) GDPR).
"Processor" or "Processor" means the entity that processes personal data on behalf of the Controller (Article 4(8) GDPR).
"Subprocessor" or "Sub-processor" means any processor engaged by Titane to process the data on behalf of the Customer.
"Personal Data" means any information relating to an identified or identifiable natural person (Article 4(1) GDPR), processed by Titane on behalf of the Customer under the Agreement. In Titane's specific context, such data takes the form of Pseudonymized Identifiers as defined below.
"Pseudonymization" has the meaning given by Article 4(5) of the GDPR: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Pseudonymized Identifiers" means the opaque tokens generated by the Customer's encryption of its customer identifiers (in particular customer_id, hashed or tokenized email), in accordance with the architecture described in Article 6 below.
"Data Subject" means the natural person to whom the Personal Data relate (Article 4(1) GDPR).
"Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of Personal Data, or unauthorized access to such data (Article 4(12) GDPR).
"SCCs" means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914.
Other capitalized terms not defined herein have the meaning given to them in the MSA.
2.1 The purpose of this DPA is to define the conditions under which Titane processes Personal Data on behalf of the Customer in the course of performing the Subscription Agreement.
2.2 The DPA takes effect on the date of acceptance of the MSA and remains in force for as long as Titane processes Personal Data on behalf of the Customer. Obligations that by their nature are intended to survive (Article 11, Article 14) survive the termination of the DPA.
2.3 The details of the processing (purposes, nature, duration, categories of data, categories of data subjects) are set out in Annex 1 to this DPA.
3.1 For the purposes of the GDPR, the Customer acts as Controller of the Personal Data it transmits to Titane, and Titane acts as Processor within the meaning of Article 28 of the GDPR.
3.2 In certain cases, the Customer may itself act as Processor on behalf of its own clients (for example, where the Customer is an agency or an integrator). In that case, Titane acts as Subprocessor within the meaning of Article 28(2) and (4) of the GDPR. The obligations of this DPA then apply mutatis mutandis.
3.3 Each Party complies with its own obligations under the GDPR. The Customer is solely responsible for:
4.1 Titane processes Personal Data only on documented instructions from the Customer. This DPA, the MSA and the configuration of the Customer's Account constitute the Customer's initial documented instructions. Any additional instruction must be notified in writing to privacy@titane-intelligence.com.
4.2 The principal purposes of the processing are:
4.3 Titane informs the Customer if it considers that an instruction constitutes a breach of the GDPR or of any other Union or Member State data protection provision (Article 28(3), in fine, GDPR).
5.1 Anti-cross-training commitment. Titane expressly undertakes not to use the Personal Data transmitted by the Customer, nor the Specific Artifacts produced from such data, to train, retrain, fine-tune or improve the Generic Models intended for other customers. The Customer Data and the Specific Artifacts are strictly isolated to the Customer concerned.
5.2 Contractual use exclusions. In accordance with Titane's algorithmic compliance commitment, the Personal Data and the Recommendations produced are under no circumstances used for:
5.3 Any use of the Personal Data for a purpose not provided for in this DPA or in the Customer's instructions is expressly prohibited.
6.1 Titane's architecture is based on the pseudonymization at the source of the Customer's customer identifiers, in accordance with Article 4(5) of the GDPR and the EDPB guidelines of January 2025.
6.2 The Customer encrypts its customer identifiers (customer_id, hashed or tokenized email) before any transmission to Titane, using a cryptographic key over which it retains exclusivity.
6.3 Titane does not hold the decryption key and does not have the technical capability to re-identify the data subjects. The resulting opaque tokens (Pseudonymized Identifiers) are the only identifiers processed by Titane.
6.4 The final linking between a Recommendation produced by Titane and a civil identity is carried out exclusively on the Customer's side, under the Customer's control, within its own information system (CRM, marketing automation tool, e-commerce platform).
6.5 Titane undertakes not to transmit to Data Subjects any directly identifying Personal Data (surname, first name, email address, telephone number, postal address, banking data), in accordance with the Customer's reciprocal commitment in Article 4.2 of the MSA.
6.6 The Customer is solely responsible for the security of the encryption key and for the quality of the pseudonymization carried out at the source. The compromise of this key by the Customer shall not give rise to any liability on the part of Titane.
Titane, in its capacity as Processor, undertakes to:
8.1 Titane implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR.
8.2 The details of the technical and organizational measures are set out in Annex 2 to this DPA. These measures are aligned with the public commitments set out at https://www.titane-intelligence.com/en/security and are regularly reviewed by Titane.
8.3 Titane reserves the right to update these measures in line with the state of the art, provided that the overall level of security is not reduced.
9.1 General authorization. The Customer authorizes Titane to engage Subprocessors for the provision of the Services. The exhaustive list of Subprocessors is published and kept up to date at https://www.titane-intelligence.com/en/legal/subprocessors.
9.2 Conditions for sub-processing. Titane imposes on the Subprocessors, by contract, data protection obligations equivalent to those of this DPA, in accordance with Article 28(4) of the GDPR. Titane remains fully liable to the Customer for the performance by the Subprocessors of their obligations.
9.3 Notification of addition or replacement. Titane notifies the Customer by email of any intended addition or replacement of a Subprocessor, at least thirty (30) days before the change takes effect.
9.4 Right of reasoned objection. The Customer has a period of fifteen (15) days from the notification to object on reasonable and documented grounds relating to data protection. The Parties shall confer in good faith to find a solution. Failing that, the Customer may terminate the Agreement without penalty.
9.5 Urgent changes. In the event of an urgent need relating to the security or continuity of the Service, Titane may replace a Subprocessor without observing the 30-day notice period, provided that it informs the Customer without delay and justifies the urgency.
10.1 Titane assists the Customer, insofar as possible and taking into account the nature of the processing, in responding to requests by data subjects to exercise their rights (rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to an automated individual decision — Articles 15 to 22 of the GDPR).
10.2 Given the pseudonymized architecture described in Article 6, Titane does not hold the information enabling the direct identification of data subjects. The exercise of rights by data subjects must therefore be addressed in the first instance to the Customer, which holds the reversibility key.
10.3 On the Customer's instructions, Titane carries out the necessary operations (deletion of the relevant Pseudonymized Identifiers, rectification, blocking) within a timeframe compatible with the Customer's statutory response deadlines.
10.4 Titane redirects to the Customer any request to exercise rights that may be addressed to it directly by a data subject, within a reasonable time and without acting on it, unless the request is manifestly unfounded or excessive.
11.1 Notification deadline. In the event of a Personal Data Breach affecting the data processed on behalf of the Customer, Titane notifies the Customer of the breach as soon as possible and no later than within twelve (12) hours of becoming aware of the breach.
This deadline constitutes a stricter commitment than the statutory deadline of seventy-two (72) hours provided for in Article 33 of the GDPR for the notification of Data Breaches by the Controller to the supervisory authority.
11.2 Content of the notification. The notification includes, to the extent that such information is available:
11.3 Cooperation. Titane cooperates with the Customer to assist it in complying with its own obligations to notify the supervisory authority (Article 33 GDPR) and, where applicable, the data subjects (Article 34 GDPR).
11.4 Notification channel. The notification is sent by email to the primary address of the Customer's Account. The Customer may, at any time, designate an alternative address at privacy@titane-intelligence.com.
12.1 Titane processes Personal Data within the European Union (AWS region eu-west-3, Paris).
12.2 Certain Subprocessors may process Personal Data outside the European Economic Area, in particular in the United States. The list of these Subprocessors and their location are set out at https://www.titane-intelligence.com/en/legal/subprocessors.
12.3 Transfer mechanism. Any transfer outside the EU is governed by one of the mechanisms provided for in Articles 44 to 49 of the GDPR, and in particular:
12.4 UK Addendum. For transfers subject to UK regulation, the SCCs are supplemented by the UK International Data Transfer Addendum published by the Information Commissioner's Office.
12.5 Swiss modifications. For transfers subject to the Swiss Federal Act on Data Protection, the SCCs are adapted in accordance with the modifications published by the Federal Data Protection and Information Commissioner.
12.6 Transfer Impact Assessment (TIA). Titane carries out transfer impact assessments in accordance with EDPB Recommendations 01/2020. Titane makes available to the Customer, upon reasonable request, the relevant materials to demonstrate the compliance of the transfers.
13.1 Titane makes available to the Customer, upon reasonable request sent to dpo@titane-intelligence.com, all information necessary to demonstrate compliance with this DPA and with the obligations set out in Article 28 of the GDPR.
13.2 Right of audit. The Customer (or an independent third party mandated by it and subject to an equivalent obligation of confidentiality) may conduct an audit of compliance with the obligations of this DPA, limited to one audit per calendar year, subject to reasonable written notice of sixty (60) days.
13.3 Procedures. The audit takes place during business hours, without disrupting Titane's activity, and concerns only the elements necessary to verify compliance with the DPA. Any information obtained in the course of the audit is covered by the confidentiality obligation set out in Article 5 of the MSA.
13.4 Costs. The costs of the audit are borne by the Customer. If the audit reveals a material failure by Titane to meet its obligations, Titane bears the reasonable and documented costs of the audit.
13.5 Alternative. Titane may satisfy the audit obligation by making available to the Customer audit reports, certifications or equivalent independent attestations (where applicable, ISO 27001, SOC 2, or pentest reports under NDA).
14.1 At the end of the Subscription Agreement, and on the Customer's express instruction given within a period of thirty (30) days following the effective date of termination, Titane carries out:
14.2 Deletion deadline. Deletion is carried out within a maximum period of thirty (30) days from the effective date of termination, subject to the legal retention obligations imposed on Titane.
14.3 Certificate of destruction. Upon the Customer's request, Titane issues a certificate of destruction attesting to the effective deletion of the Personal Data and of the Specific Artifacts, signed by Titane's Legal Representative or by the DPO.
14.4 Backups. Backups that may contain residual Personal Data are overwritten in the normal backup rotation cycles (at the latest within ninety (90) days). During this period, the residual Data remain subject to the security measures of this DPA and are accessible only for restoration purposes.
| Controller | The Customer as identified upon acceptance of the MSA |
| Processor | SAS TITANE INTELLIGENCE, SIREN 105 840 060 |
Provision of the Titane Intelligence Services: recommendation, segmentation, forecasting and trend detection models applied to the Customer Data.
For the entire duration of the Subscription Agreement, extended where applicable by the deletion deadlines provided for in Article 14.
Collection, structuring, organization, storage, consultation, use for training and inference purposes, communication (to the Customer only), erasure.
In accordance with Article 6 of this DPA, no directly identifying data is transmitted to Titane, in particular:
Public list kept up to date at https://www.titane-intelligence.com/en/legal/subprocessors. As of the last update of this DPA, the Subprocessors are:
| Processor | Service | Location | Transfer outside the EU |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Infrastructure hosting | Paris (eu-west-3), EU | — |
| Anthropic PBC | Language model services | United States | SCCs Module 3 |
| OpenAI OpCo LLC | Language model services | United States | SCCs Module 3 |
| Neon Inc. | Managed database | EU region (to be confirmed) | SCCs Module 3 if non-EU |
| Vercel Inc. | Frontend hosting | United States | SCCs Module 3 |
aws:sourceVpce).https://www.titane-intelligence.com/en/legal/vdp).The commitments in this Annex 2 are aligned with the public commitments set out at https://www.titane-intelligence.com/en/security. In the event of any discrepancy, this DPA prevails with respect to the contractual obligations toward the Customer.
The standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of June 4, 2021 are incorporated into this DPA by reference, in their official version published in the Official Journal of the European Union and accessible at:
https://eur-lex.europa.eu/eli/dec_impl/2021/914
Unless otherwise agreed in writing between the Parties:
Annexes I (list of the Parties, description of the transfer, competent supervisory authority) and II (technical and organizational measures) of the SCCs are completed by reference to Annexes 1 and 2 of this DPA. Annex III (list of Subprocessors) is completed by reference to the public list https://www.titane-intelligence.com/en/legal/subprocessors.
For any transfer subject to UK regulation, the Parties subscribe to the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, published by the ICO and accessible at https://ico.org.uk/.
For any transfer subject to the Swiss Federal Act on Data Protection (FADP), the SCCs are adapted in accordance with the guidance of the Federal Data Protection and Information Commissioner (FDPIC), in particular by reference to the FADP in place of the GDPR and to the competent Swiss authority.
The full text of the SCCs is available upon request from the Titane DPO at dpo@titane-intelligence.com or directly at the official URL indicated in Article 3.1 of this Annex.
Dedicated contacts
dpo@titane-intelligence.comprivacy@titane-intelligence.comsecurity@titane-intelligence.comcontact@titane-intelligence.comVersion 1.0 — Last updated: May 18, 2026
For a PDF copy signed by Titane or any clarification, write to us.
contact@titane-intelligence.com