Legal
Data processing agreement (DPA)
Frame applying when a business customer entrusts VERiXiS with personal data processing for the proof service.
Last updated: 31 July 2026
Contents
1. Roles
The customer is the controller for data it collects via VERiXiS (proofs, users in its organisation). VERiXiS acts as a processor under the GDPR for storage, sealing, verification and support.
Processor: MODULO44 (brand VERiXiS), 32 rue de Paris, 92100 Boulogne-Billancourt, France.
2. Subject of processing
- Categories: user accounts, captured media, session metadata, technical logs, billing data linked to the account.
- Purpose: provide real capture proof, the library, dossier sealing and public verification.
- Duration: contract term, then 6-year product retention for proofs and related data (earlier deletion available at the user's request), subject to legal obligations.
3. Instructions
VERiXiS processes data on documented customer instructions, except where required by law. Capture intended for proof happens exclusively at the time of the shot. No imported file becomes a VERiXiS proof.
4. Security
Encryption in transit and at rest, access control, logging, hosting in the European Union, environment separation. Measures described on the site Security page (encryption in transit and at rest, access control, EU hosting, refusal when in doubt). Enterprise operational detail on request. See also /en/securite.
5. Sub-processors
List of authorised sub-processors:
- SCALEWAY SAS: cloud hosting, object storage, databases, transactional email (TEM) (European Union (FR / NL)).
- Stripe: payments, subscriptions and invoicing (EU, with possible transfers outside the EU under Stripe safeguards).
- Twilio: SMS OTP delivery (phone verification and MFA) (EU / outside the EU depending on Twilio configuration, under contractual safeguards).
- Certigna: qualified eIDAS electronic timestamping (TSA) (European Union (France)).
- MaxMind: GeoIP enrichment / network classification (abuse prevention) (outside the EU, under appropriate contractual safeguards).
- Google LLC: Android integrity attestation (Play Integrity) (possible outside the EU, limited to device attestation tokens).
- Apple Inc.: iOS device attestation (App Attest / DeviceCheck) (possible outside the EU, limited to device attestation tokens).
Notice of addition or replacement of a sub-processor: 30 days before it takes effect, except for a security emergency. The customer may object on legitimate grounds; failing agreement, termination is possible under the Terms of sale.
6. Assistance with data subject rights
VERiXiS assists the customer in responding to rights requests. DPO contact: contact@verixis.app.
7. Exit and return
At contract end, return or deletion of data according to product options. Grace period: 30 days after platform hosting stops, unless otherwise agreed. Sealed dossiers remain exportable; the seal remains verifiable within applicable retention limits.