This Data Processing Agreement (“DPA”) forms part of the Terms of Service
between Reqme SAS (“Reqme”, “Processor”) and the Customer (“Controller”). It
applies where Reqme processes personal data on the Controller’s behalf in
providing the service, in accordance with Article 28 GDPR. Reqme additionally acts
as an independent controller for platform security, abuse
prevention, and service improvement, as described in our Privacy Policy; that
processing is outside the scope of this DPA.
Subject-matter: provision of the Reqme service.
Duration: the term of the Terms of Service.
Nature and purpose: hosting, processing and transmitting
Customer content to manage service requests, proposals, contracts, invoices,
communications and related workflows.
Data subjects: the Controller’s clients, prospects and contacts.
Categories: identification and contact data, request/deal content, documents,
communications, and payment-related identifiers as submitted by the Controller.
The Controller provides general authorisation for Reqme to engage the
sub-processors listed at
reqme.co/subprocessors. Reqme will
inform the Controller of intended additions or replacements and the Controller
may object on reasonable data-protection grounds. Reqme imposes
Article 28 obligations on each sub-processor and remains fully liable to
the Controller for each sub-processor’s performance.
Where personal data is transferred outside the EEA, transfers are governed by
EU Standard Contractual Clauses, the EU-US Data Privacy Framework (where the
recipient is certified), or another lawful mechanism. The applicable Standard Contractual Clauses are made available to the Controller on request.
Reqme maintains the measures summarised at
reqme.co/security.
Reqme will make available compliance information and, on reasonable notice and
subject to confidentiality, support audits on reasonable prior notice, subject to confidentiality, at a scope and frequency proportionate to the processing.
Reqme will notify the Controller without undue delay after becoming aware of a
personal-data breach affecting the Controller’s data, consistent with the
breach-notification timing in our Terms of Service.