Data Processing Agreement (DPA) - Ultimate Cart Recovery
⚠️ Draft document - to be reviewed by a lawyer before signature. Compliant with Article 28 of the GDPR. Company information completed (Pappers / RCS). Version: 1.0 - Last updated: 24 June 2026
This Data Processing Agreement ("DPA") forms an integral part of the Terms and Conditions of Sale entered into between VISICREA (SASU, 180 Lotissement du Stade, 42140 Grammond, 902 306 133 R.C.S. Saint-Étienne) ("Visicrea", processor) and the merchant customer ("the Controller") using the "Ultimate Cart Recovery" module.
1. Roles of the Parties
- For the data of the merchant's end customers processed via the module and the licence server (emails, phone numbers, cart contents, tracking events), the merchant is the controller and Visicrea is the processor within the meaning of Article 28 of the GDPR.
- The merchant warrants that it has a valid legal basis (consent or legitimate interest depending on the channel and jurisdiction) for the prospecting and processing of its end customers' data.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: processing of the data required to detect abandoned carts and to send multichannel follow-up messages.
- Duration: the term of the active licence, plus the legal/technical retention periods described in § 6.
- Nature and purpose: collection, storage, formatting, transmission to the channel providers configured by the merchant, deletion.
3. Categories of Data Subjects and Data
- Data subjects: the merchant's end customers and prospects who have started a cart.
- Data: identity (name, first name if provided), contact details (email, phone number), cart/order identifier, cart contents, amounts, events (open, click, conversion), opt-out status.
- No sensitive data within the meaning of Article 9 is processed.
4. Obligations of Visicrea (Processor)
- Process the data only on the merchant's documented instructions (the configuration of the module constituting an instruction);
- Ensure confidentiality (staff bound by confidentiality);
- Implement the security measures of Article 32 (encryption of secrets via a dedicated mechanism, HTTPS, access control, logging, minimisation - "GDPR by default");
- Comply with the dry-run mode and the opt-out lists (never purged) provided by the module;
- Assist the merchant in responding to requests to exercise rights (export, erasure, anonymisation via the module's dedicated CLI commands);
- Notify the merchant without undue delay in the event of a data breach;
- Delete or return the data at the end of the contract, at the merchant's choice, unless there is a legal obligation to retain it.
5. Sub-processors
The merchant authorises the use of the sub-processors that it configures itself in the module:
| Provider | Role | Location |
|---|---|---|
| Twilio | SMS / WhatsApp | US (DPF + SCC) |
| Brevo | SMS / email | EU (FR) |
| Mailgun | email + bounce webhooks | US/EU depending on region |
The merchant is responsible for entering into the required agreements with the providers it activates. Visicrea does not engage any other sub-processor for these processing activities without prior information allowing objection.
6. Retention and Deletion
- Send log: 12 months by default (configurable by the merchant);
- Opt-out list: retained without time limit (obligation to honour objections);
- Deletion/anonymisation on request via the module's GDPR tools (
ucr:export:gdpr,ucr:delete:gdpr).
7. Transfers outside the EU
Any transfers (Twilio, Mailgun US) are governed by the Data Privacy Framework and/or the standard contractual clauses. The merchant may restrict its channels to EU providers (Brevo) if it wishes to avoid any transfer.
8. Audit
Visicrea makes available the information necessary to demonstrate compliance with Article 28 and submits, under reasonable conditions, to audits conducted by the merchant or an appointed auditor.
9. Governing Law
This DPA is governed by French law and supplements the Terms and Conditions of Sale. In the event of a conflict concerning data protection, this DPA shall prevail.