Data Processing Agreement
Last updated: 28 August 2026
This agreement is annexed to the subscription terms and supplements them for everything concerning personal data. Courtesy translation — the French text prevails. It is entered into between the client shop, the "Controller", and Paul Hilmarcher — Echo Studio Agency, the "Processor":
- Registered office: 29 Route du Revoireau, 38790 Saint-Georges-d'Espéranche, France
- Company number: 883 750 143 00033
- Registration: RCS Vienne 883 750 143
- Email: contact@echotcg.fr
1. Roles
The shop decides why and how its customers' data is processed: it is the controller. The publisher merely operates the Service on its behalf: it is the processor within the meaning of Article 28 GDPR.
One exception, and it matters: for the shop's own data — manager identity, billing, service emails — the publisher is the controller. That processing falls under its privacy policy, not this agreement.
2. Subject matter, duration, nature and purpose
Subject matter: the processing required to provide the Echo TCG point-of-sale and management software.
Duration: the term of the subscription, extended by the statutory retention periods binding on the shop (notably ten years for accounting records and five years for the second-hand register).
Nature and purpose: recording, storing, consulting, backing up and deleting the data entered by the shop, solely to provide it with the till, stock, buy-back, loyalty, accounting and sales-channel features.
3. Categories of persons and data
- Shop customers: name, email, phone, purchase history, loyalty points and vouchers.
- Second-hand sellers (police register): name, address, date and place of birth, identity document type and number, issuing authority and date. These entries are required by Article 321-7 of the French Criminal Code.
- Shop employees: name, email, role, till-code hash.
- No Article 9 data is collected by the Service. Police-register data, while not a special category, is sensitive by nature and handled with the same care.
4. Instructions
The publisher processes the data only on the shop's documented instructions. Use of the Service constitutes instruction for everything it performs. Any other instruction must be given in writing.
The publisher informs the shop if it considers an instruction to infringe the GDPR, and may suspend it until the matter is settled.
5. Confidentiality
Persons authorised to process this data at the publisher are bound by a confidentiality obligation that survives the end of their involvement. Access to a shop's data is limited to cases where it is indispensable — requested support, incident, legal obligation — and is logged.
6. Security (Article 32)
- Per-shop isolation enforced in the database itself, on every table, not only in the application.
- Encryption in transit (TLS) and at rest with the hosting provider.
- Named authentication, role-based rights, till codes stored as non-reversible hashes.
- Accounting and tax records are immutable: sales, buy-backs, sessions and closures are SHA-256 hash-chained and cannot be altered or deleted, including by the publisher.
- Daily encrypted backups kept outside the main database, in addition to the host's own backups.
- Audit log of access and sensitive operations.
7. Sub-processors
The shop authorises the publisher to use the sub-processors listed below. The publisher will give reasonable notice of any addition or replacement, and the shop may object on legitimate data-protection grounds.
- Supabase Inc. — database and authentication. Data hosted in France (AWS eu-west-3, Paris).
- Vercel Inc. — application hosting and execution.
- Resend Inc. — transactional email.
- Stripe Payments Europe Ltd. is absent from this list: it processes the SHOP's data for the subscription, for which the publisher is the controller — not the shop's customers' data.
8. Transfers outside the European Union
Service data is hosted in France. Some sub-processors are established in the United States and may access it for operation and support. Such access is covered by the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
9. Data subject rights
Data subjects exercise their rights with the shop, which is responsible for them. The publisher provides the means to respond — consultation, export, rectification, deletion — and assists where a request exceeds what the software allows.
A request addressed directly to the publisher is forwarded without delay, and not answered by it.
10. Personal data breach
The publisher notifies the shop without undue delay, and at the latest within forty-eight hours of becoming aware, of any breach affecting it. The notification describes the nature of the breach, the categories and approximate volume of data affected, the likely consequences and the measures taken.
Notification to the CNIL within seventy-two hours is the shop's responsibility as controller. The publisher provides the necessary information.
11. Data protection impact assessment
The publisher assists the shop, within the limits of the information available to it, in carrying out an impact assessment and any prior consultation of the CNIL.
12. Fate of the data at the end
At the end of the subscription, the shop has thirty days to export its data from the Service. After that period and upon request, the publisher deletes it.
Absent a request, it is kept only for as long as the shop's legal obligations require, then deleted. Encrypted backups expire on their own rotation cycle.
One reservation, said plainly: tax records are immutable by design — that is what makes the software compliant. They can only be removed by deleting the shop's data as a whole.
13. Audit
The publisher makes available the information needed to demonstrate compliance with this agreement. The shop may request an audit, at most once a year, with thirty days' notice, at its own expense, during business hours and without disrupting the Service.
14. Precedence
This agreement prevails over the subscription terms for everything concerning personal data. It takes effect on subscription and ends with the last retention obligation.