Data Processing Agreement
1. Scope and roles
This Data Processing Agreement (“DPA”) forms part of the Terms of Service
between Reqme SAS (“Reqme”, “Processor”) and the Customer (“Controller”). It
applies where Reqme processes personal data on the Controller’s behalf in
providing the service, in accordance with Article 28 GDPR. Reqme additionally acts
as an independent controller for platform security, abuse
prevention, and service improvement, as described in our Privacy Policy; that
processing is outside the scope of this DPA.
2. Subject-matter, duration, nature and purpose
Subject-matter: provision of the Reqme service.
Duration: the term of the Terms of Service.
Nature and purpose: hosting, processing and transmitting
Customer content to manage service requests, proposals, contracts, invoices,
communications and related workflows.
3. Categories of data and data subjects
Data subjects: the Controller’s clients, prospects and contacts.
Categories: identification and contact data, request/deal content, documents,
communications, and payment-related identifiers as submitted by the Controller.
4. Processor obligations
- Process personal data only on the Controller’s documented instructions,
including for international transfers, unless required by law. - Immediately inform the Controller if, in Reqme’s opinion, an instruction
infringes the GDPR or other applicable data-protection law. - Ensure persons authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational measures (Article 32).
- Assist the Controller with data-subject requests and with Articles 32–36
obligations, taking into account the nature of processing. - At the Controller’s choice, delete or return personal data at the end of
the service, unless retention is required by law. - Make available information necessary to demonstrate compliance and allow for
audits as set out below.
5. Sub-processors
The Controller provides general authorisation for Reqme to engage the
sub-processors listed at
reqme.co/subprocessors. Reqme will
inform the Controller of intended additions or replacements and the Controller
may object on reasonable data-protection grounds. Reqme imposes
Article 28 obligations on each sub-processor and remains fully liable to
the Controller for each sub-processor’s performance.
6. International transfers
Where personal data is transferred outside the EEA, transfers are governed by
EU Standard Contractual Clauses, the EU-US Data Privacy Framework (where the
recipient is certified), or another lawful mechanism. The applicable Standard Contractual Clauses are made available to the Controller on request.
7. Security
Reqme maintains the measures summarised at
reqme.co/security.
8. Audit
Reqme will make available compliance information and, on reasonable notice and
subject to confidentiality, support audits on reasonable prior notice, subject to confidentiality, at a scope and frequency proportionate to the processing.
9. Breach notification
Reqme will notify the Controller without undue delay after becoming aware of a
personal-data breach affecting the Controller’s data, consistent with the
breach-notification timing in our Terms of Service.

