The data-processing agreement governing rights and obligations between you (Controller) and Illizeo (Processor), pursuant to GDPR article 28.
Version May 2026 GDPR art. 28 & FADP compliant
Art. 28GDPR applicable
EU / EEAHosting
14dAudit notice
30dPost-contract delay
1. Introduction, scope & definitions
These provisions govern the rights and obligations of the Customer (“Controller”) and Illizeo (“Processor”) in the processing of personal data carried out on behalf of the Controller, in connection with the use of Illizeo software and services.
Hierarchy: in case of conflict with the main contract, the DPA terms prevail. Capitalised terms have the meaning given in the main contract or the GDPR.
The Controller accepts these provisions on its own behalf and on behalf of any affiliated entity concerned by processing under this DPA.
2. Scope of processing, data categories & data subjects
2.1Types of data
Identity (last name, first name, address, date of birth, phone, business email)
HR contractual data (degrees, training, contracts, certificates)
Employees, external providers, freelancers, volunteers in post
Former employees
Candidates, future volunteers or employees
2.3Location of processing
Exclusively EU / EEA / adequate countries (GDPR art. 45)
Any transfer outside the EEA: art. 46+ safeguards (SCCs, etc.)
Duration: throughout service provision unless otherwise agreed in writing
3. Confidentiality
Illizeo undertakes to ensure the confidentiality of personal data, in accordance with articles 28(3)(b), 29 and 32(4) GDPR.
Any person authorised to process personal data is bound by an obligation of confidentiality, whether arising from an employment contract, a specific agreement or a legal duty.
4. Controller obligations
The Customer remains solely responsible for compliance with GDPR in its use of the services
Immediate information of Illizeo of any anomaly or non-compliance detected
Designation of a data-protection contact if needed
5. Customer instructions
Illizeo only processes data on documented instructions from the Customer (except legal obligation under GDPR)
If an instruction appears to breach GDPR, Illizeo informs the Customer and may suspend execution
Persons authorised to issue instructions are designated in the software; failing this, only the Customer’s legal representatives
Illizeo may suspend any instruction until the issuer’s authority is proven
6. Processor obligations
6.1General obligations
Designated DPO, contact details available on Illizeo’s website
Reasonable assistance to the Customer for DPIAs and prior authority consultations
Immediate notice to the Customer of any data-protection authority action concerning the DPA
6.2Audits
Verification of DPA, TOM and GDPR compliance during business hours, 14-day notice
External auditor allowed, prior NDA
“Event-triggered audit” in case of incident: shorter reasonable notice, no limitations
Outside events: max 1 on-site audit per year, 1 day max
Illizeo may decline a non-event audit if it provides sufficient evidence (ISO 27001, art. 40 codes of conduct, art. 42 certifications)
Illizeo may refuse a competing auditor or for other legitimate reasons
6.3Technical & Organisational Measures (TOM)
Implementation pursuant to GDPR article 32
Adapted to state of the art, costs, nature and risks
Latest version on the TOM page or via Settings > Support > Subscription & Billing
Updates possible without reducing overall security level
Afin de vous offrir la meilleure expérience possible, nous utilisons des technologies telles que les cookies pour stocker et/ou accéder aux informations relatives à votre appareil. En acceptant ces technologies, vous nous autorisez à traiter des données telles que votre comportement de navigation ou vos identifiants uniques sur ce site. Le refus ou le retrait de votre consentement peut avoir un impact négatif sur certaines fonctionnalités et fonctions.
Fonctionnel
Always active
Le stockage technique ou l'accès est strictement nécessaire à des fins légitimes afin de permettre l'utilisation d'un service spécifique explicitement demandé par l'abonné ou l'utilisateur, ou dans le seul but d'effectuer la transmission d'une communication sur un réseau de communications électroniques.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistiques
Le stockage technique ou l'accès utilisé exclusivement à des fins statistiques.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
Le stockage technique ou l'accès est nécessaire pour créer des profils d'utilisateurs afin d'envoyer des publicités ou de suivre l'utilisateur sur un site web ou sur plusieurs sites web à des fins marketing similaires.