DPA contents
Our Data Processing Agreement covers the following sections:
- 1 Subject matter and duration of processing
- 2 Nature and purpose of processing
- 3 Types of personal data processed
- 4 Categories of data subjects
- 5 Obligations of the processor (Bunker)
- 6 Obligations of the controller (the client)
- 7 Sub-processors
- 8 Transfers outside the EU
- 9 Technical and organizational security measures
- 10 Data breach notification
- 11 Assistance with data subject rights
- 12 Data return and deletion
- 13 Audit and control
Key commitments of Bunker
Full text of the DPA
Version 2 Effective date: 23 December 2025 Version history
Effective date : 23 December 2025
This Data Processing Agreement (hereinafter the « DPA ») forms an integral part of the agreement governed by the General Terms and Conditions of Service (hereinafter the « Agreement ») concluded between France Nuage SAS (hereinafter « Bunker », the « Processor ») and the Client (hereinafter the « Controller »). In the event of a conflict between the documents of the Agreement, the order of precedence of article 3 of the General Terms and Conditions of Service applies. The DPA sets out the conditions under which Bunker processes personal data on behalf of the Client in the context of providing the Services.
Capitalized terms not defined in this DPA have the meaning given to them in the Agreement or in the applicable data protection regulations.
Article 1 — Definitions
Article 2 — Scope and duration of processing
Article 3 — Nature and purpose of processing
Article 4 — Types of personal data processed
- Email addresses, first and last names of authorized users;
- IP addresses and connection logs;
- Authentication tokens;
- Application data hosted by the Controller;
- Billing information;
- Any other Personal Data that the Controller chooses to submit to the platform.
Article 5 — Categories of data subjects
- The Controller's end users whose data is hosted on the platform;
- The Controller's employees, contractors and collaborators;
- The authorized users of the Controller's Bunker account;
- Any natural person whose data is submitted by the Controller.
Article 6 — Obligations of the Processor
Article 7 — Obligations of the Controller
Article 8 — Sub-processing
Article 9 — International data transfers
- (a) an adequacy decision by the European Commission under Article 45 of the GDPR;
- (b) the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with the appropriate module;
- (c) appropriate supplementary safeguards and, where applicable, a Transfer Impact Assessment.
Article 10 — Security measures
- (a) implement measures to protect against the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data;
- (b) restrict access to Personal Data to authorized persons only, on a need-to-know basis;
- (c) ensure that all personnel and Sub-processors with access to Personal Data are subject to appropriate confidentiality obligations;
- (d) regularly test, analyze and evaluate the effectiveness of the technical and organizational measures implemented.
Article 11 — Data breach notification
- (a) a description of the nature of the Data Breach, including the categories and approximate number of data subjects and Personal Data records concerned;
- (b) the name and contact details of Bunker's data protection point of contact;
- (c) a description of the likely consequences of the Data Breach;
- (d) a description of the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects.
Article 12 — Assistance with data subject rights
Article 13 — Data deletion and return
- (a) returns all Personal Data in a structured, commonly used and machine-readable format; or
- (b) deletes all Personal Data using secure deletion methods compliant with industry standards.
Article 14 — Audit and control
- (a) the Controller notifies Bunker with at least 30 business days' written notice;
- (b) audits are limited to once per year, except in the event of a confirmed Data Breach or a requirement from a supervisory authority;
- (c) the auditor is subject to appropriate confidentiality obligations;
- (d) the audit does not unreasonably disrupt Bunker's operations and does not compromise the security or confidentiality of other clients' data;
- (e) audit costs are borne by the Controller;
- (f) the Controller may accept an audit or certification report issued by an independent third-party auditor in lieu of an on-site audit.
Article 15 — Liability
Article 16 — Term and termination
Article 17 — Governing law and jurisdiction
Article 18 — Contact
Email: [email protected]
Annexes
Annex 1 — Description of processing operations
| Item | Description |
|---|---|
| Subject matter of processing | Provision of cloud infrastructure, hosting, storage, compute and related services by Bunker to the Controller in accordance with the Agreement. |
| Duration of processing | Duration of the Agreement, plus 30 days for data cleanup operations after account deletion. |
| Nature of processing | Hosting, storage, compute, transmission, backup, monitoring and technical administration of the data submitted by the Controller to the platform. |
| Purpose of processing | To provide the cloud infrastructure services described in the Agreement, including deployment, scaling, monitoring, support and billing. |
| Categories of personal data | Email addresses, first and last names, IP addresses, authentication tokens, application data hosted by the Controller, billing information, usage logs, and any other personal data that the Controller chooses to submit to the platform. |
| Categories of data subjects | The Controller's end users; the Controller's employees, contractors and collaborators; the authorized users of the Bunker account. |
| Location of processing | France for hosting and the main processing of the data. Some sub-processors, which are not hosting providers, operate from within the European Union or, under Standard Contractual Clauses (EU 2021/914) safeguards, from the United States — see Annex 3 for details per provider. |
| Frequency | Continuous and automated processing for the duration of the Agreement. |
Annex 2 — Technical and organizational security measures
Self-assessed security measures, not certified by a third party to date. Our certification roadmap is published on the Security & Compliance page.
Infrastructure security
- Hosting: data centers located exclusively in France, operated in-house by France Nuage (physical security self-assessed, not certified by a third party to date).
- Encryption at rest: volumes and object storage are encrypted at the storage layer. This encryption does not on its own cover the secrets that a managed application keeps in its own database, such as source connection credentials: their application-level encryption is configured application by application and is not yet enabled on every managed service.
- Encryption in transit: TLS 1.2 minimum for all data in transit.
- Backups: automated and encrypted backups; managed service database backups are kept for 30 days.
- DDoS protection: DDoS mitigation via Cloudflare (with Standard Contractual Clauses in place).
- Isolation: each managed service runs in a dedicated Kubernetes namespace. Network filtering rules between namespaces are being rolled out and do not yet cover every managed service.
- Ingress filtering: reputation-based address filtering and a signature-based application firewall (CrowdSec) on the shared public entry point; their extension to every exposed service is in progress.
Application security
- Authentication: centralized identity management via Keycloak (self-hosted).
- Access control: role-based access control (RBAC) following the principle of least privilege.
- Sessions: session and token lifetimes follow the configuration of each managed application. After fixing a vulnerability that allows unauthorised access, France Nuage invalidates the active sessions of the service concerned (General Terms and Conditions of Service, article 9.3).
- Operational access: access to the infrastructure through a WireGuard VPN (Headscale) and a central identity provider.
Development security
- Changes: every change goes through a merge request validated by continuous integration before reaching production.
- Automated analysis: secret detection in continuous integration and automated dependency updates; automated dependency vulnerability scanning is being rolled out.
- Open-source stack: platform built on open-source technologies (Kubernetes, PostgreSQL, Redis, Prometheus, Grafana), enabling a full audit of the code.
Monitoring and incident response
- Monitoring: automated monitoring of availability, resource saturation and backup freshness, with alerts handled by the operations team. France Nuage does not run a security operations center, and detection of abnormal activity within managed applications is not covered to date.
- Observability: centralized logging and distributed tracing (Grafana, Loki, Tempo, Mimir, self-hosted).
- Availability monitoring: external probes via Better Stack (EU-based).
- Incident response: incident response procedure and post-incident reviews; the data breach notification procedure is being formalised.
- Address reputation: CrowdSec (self-hosted) shares reports of malicious addresses with its community.
Organizational measures
- Confidentiality: all personnel are subject to confidentiality obligations.
- Access management: need-to-know principle applied.
- Awareness: security awareness for the team; a formal training programme is being written.
- Vendor assessment: security of Sub-processors assessed prior to their engagement.
Data retention
- Application data: according to the retention settings defined by the Controller.
- Account data: duration of the Agreement plus 30 days.
- Billing data: 10 years (French tax obligation — Article L123-22 of the French Commercial Code).
- Logs: access, administration and network logs kept for 90 days; in the event of an incident, the relevant items are kept until the investigation is closed.
Annex 3 — List of sub-processors
List in force on the effective date of this version. It reproduces the Sub-processors page, updated in February 2026.
| Sub-processor | Location | Purpose | Data processed | Transfer mechanism |
|---|---|---|---|---|
| Stripe, Inc. | United States | Payment processing and billing | Billing data, payment tokens | Standard Contractual Clauses (EU 2021/914) |
| Cloudflare, Inc. | United States | DNS management and DDoS protection | Visitor IP addresses, HTTP request metadata | Standard Contractual Clauses (EU 2021/914) |
| Better Stack Ltd | Lithuania (EU) | Availability monitoring | Public URLs, response times | N/A (intra-EEA) |
Self-hosted services (France — no third-party sub-processor): Keycloak, PostgreSQL, Redis, Matomo, GitLab, Grafana/Loki/Tempo/Mimir, Ceph S3, DocuSeal, N8N, CrowdSec, Headscale.
The up-to-date list of Sub-processors is available on the Sub-processors page.
Version 2 of the Data Processing Agreement, applicable from 23 December 2025. Version 1 remains available in the version history.
Printable version
This standard DPA applies to all Bunker clients. Print it or save it as a PDF from your browser to archive it or attach it to your compliance file.
For a custom DPA or a signed version, contact our DPO.
Questions about the DPA?
Contact our DPO at [email protected]