DPA contents

Our Data Processing Agreement covers the following sections:

  1. 1 Subject matter and duration of processing
  2. 2 Nature and purpose of processing
  3. 3 Types of personal data processed
  4. 4 Categories of data subjects
  5. 5 Obligations of the processor (Bunker)
  6. 6 Obligations of the controller (the client)
  7. 7 Sub-processors
  8. 8 Transfers outside the EU
  9. 9 Technical and organizational security measures
  10. 10 Data breach notification
  11. 11 Assistance with data subject rights
  12. 12 Data return and deletion
  13. 13 Audit and control

Key commitments of Bunker

Process data only on documented instructions from the client.
Confidentiality of all personnel authorized to process data.
State-of-the-art technical and organizational security measures.
Notification of any data breach within 48 hours.
Assistance to the client in responding to data subject rights requests.
Deletion or return of data at the client's choice (30-day retention).
Prior notice before adding any new sub-processor.

Full text of the DPA

Effective date : July 1, 2026

This Data Processing Agreement (hereinafter the « DPA ») forms an integral part of the Terms of Service (hereinafter the « Agreement ») concluded between France Nuage SAS (hereinafter « Bunker », the « Processor ») and the Client (hereinafter the « Controller ») and sets out the conditions under which Bunker processes personal data on behalf of the Client in the context of providing the Services.

Capitalized terms not defined in this DPA have the meaning given to them in the Agreement or in the applicable data protection regulations.

Article 1 — Definitions

« Applicable Regulations » means all laws and regulations applicable to the protection of personal data, in particular Regulation (EU) 2016/679 of 27 April 2016 (hereinafter the « GDPR »), French Law No. 78-17 of 6 January 1978 known as « Informatique et Libertés » as amended, as well as any national transposition or implementation legislation.
« Personal Data » means any information relating to an identified or identifiable natural person, within the meaning of Article 4(1) of the GDPR, processed by Bunker on behalf of the Controller under the Agreement.
« Processing » means any operation or set of operations performed on Personal Data, within the meaning of Article 4(2) of the GDPR.
« Sub-processor » means any third party engaged by Bunker to carry out specific processing activities on behalf of the Controller.
« Special Categories of Data » means the data referred to in Article 9 of the GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic, biometric or health data, or data concerning sex life or sexual orientation).
« Data Breach » means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

Article 2 — Scope and duration of processing

2.1. This DPA applies to all processing of Personal Data carried out by Bunker on behalf of the Controller in the context of providing the Services defined in the Agreement.
2.2. Processing begins on the effective date of the Agreement and continues for the entire duration of the Agreement, plus the retention period provided for in Article 13.
2.3. A detailed description of the processing operations is set out in Annex 1 to this DPA.

Article 3 — Nature and purpose of processing

3.1. Bunker processes Personal Data in the context of providing cloud infrastructure, hosting, storage, compute and related services, as described in the Agreement.
3.2. Processing includes, in particular: hosting, storage, compute, transmission, backup, monitoring and technical administration of the data submitted by the Controller to the platform.
3.3. The platform does not process Special Categories of Data by default. If the Controller wishes to process such data via the Services, it must make an express written request and a specific amendment must be concluded between the parties prior to any processing.

Article 4 — Types of personal data processed

The categories of Personal Data processed are described in Annex 1 and include, in particular:
  • Email addresses, first and last names of authorized users;
  • IP addresses and connection logs;
  • Authentication tokens;
  • Application data hosted by the Controller;
  • Billing information;
  • Any other Personal Data that the Controller chooses to submit to the platform.
Note: The Controller determines the actual categories of Personal Data processed through its use of the Services. Bunker processes the data as submitted by the Controller and does not control the content of the hosted data.

Article 5 — Categories of data subjects

The data subjects concerned by the processing are described in Annex 1 and include, in particular:
  • The Controller's end users whose data is hosted on the platform;
  • The Controller's employees, contractors and collaborators;
  • The authorized users of the Controller's Bunker account;
  • Any natural person whose data is submitted by the Controller.

Article 6 — Obligations of the Processor

Bunker undertakes to:
6.1. Process Personal Data only on documented instructions from the Controller, including with regard to transfers of data to a third country, unless Bunker is required to do so under Union or Member State law to which it is subject, in which case it informs the Controller of that requirement before processing, unless legally prohibited (Article 28(3)(a) of the GDPR).
6.2. Ensure confidentiality: ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Article 28(3)(b) of the GDPR).
6.3. Implement security measures — appropriate technical and organizational measures in accordance with Article 32 of the GDPR, as described in Annex 2 (Article 28(3)(c) of the GDPR).
6.4. Comply with the conditions for engaging a Sub-processor in accordance with Article 8 of this DPA (Article 28(3)(d) of the GDPR).
6.5. Assist the Controller in fulfilling data subject rights requests, in accordance with Article 12 of this DPA (Article 28(3)(e) of the GDPR).
6.6. Assist the Controller in ensuring compliance with the obligations set out in Articles 32 to 36 of the GDPR, taking into account the nature of the processing and the information available to Bunker (Article 28(3)(f) of the GDPR).
6.7. At the Controller's choice, delete or return all Personal Data at the end of the service, in accordance with Article 13 of this DPA (Article 28(3)(g) of the GDPR).
6.8. Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for audits, in accordance with Article 14 of this DPA (Article 28(3)(h) of the GDPR).
6.9. Immediately inform the Controller if, in Bunker's opinion, an instruction from the Controller infringes the GDPR or other provisions of the Applicable Regulations.
6.10. Not use the Personal Data for personal, own commercial, fraudulent purposes or purposes diverted from those provided for in the Agreement.
6.11. Maintain a record of the categories of processing activities carried out on behalf of the Controller, in accordance with Article 30(2) of the GDPR, and make it available to the Controller upon request.

Article 7 — Obligations of the Controller

7.1. The Controller determines the purposes and means of processing the Personal Data. It warrants that the processing is based on a lawful legal basis within the meaning of Article 6 of the GDPR.
7.2. The Controller warrants that it holds all the rights and authorizations necessary to transfer the Personal Data to Bunker and to its Sub-processors in accordance with the Applicable Regulations.
7.3. The Controller is responsible for the lawfulness of the content of the data hosted on the platform and ensures that no Special Category of Data is processed via the Services without Bunker's prior written consent.
7.4. The Controller undertakes to document its instructions relating to the processing of Personal Data.

Article 8 — Sub-processing

8.1. The Controller grants Bunker a general authorization to engage Sub-processors to carry out specific processing activities, under the conditions set out in Article 28(2) of the GDPR.
8.2. Bunker maintains an up-to-date list of its Sub-processors on the Sub-processors page. The list in force at the date of this DPA is set out in Annex 3.
8.3. Bunker notifies the Controller by email at least 30 days before adding or replacing a Sub-processor, in order to allow the Controller to raise objections.
8.4. The Controller has thirty (30) calendar days from the notification to object to the addition or replacement of a Sub-processor. If the Controller raises a reasonable objection on legitimate data protection grounds, Bunker will use commercially reasonable efforts to propose an alternative solution. In the absence of a reasonable solution, the Controller may terminate the affected Services without penalty.
8.5. Bunker imposes on each Sub-processor, by written agreement, data protection obligations equivalent to those set out in this DPA, in accordance with Article 28(4) of the GDPR.
8.6. Bunker remains fully liable to the Controller for the performance by its Sub-processors of their obligations relating to the processing of Personal Data.

Article 9 — International data transfers

9.1. The Controller's Personal Data is hosted and processed in France, in certified data centers located on French territory, and is subject exclusively to French law and the law of the European Union.
9.2. Bunker undertakes not to transfer Personal Data outside the European Economic Area (« EEA ») without the Controller's prior written consent.
9.3. Where a transfer of Personal Data to a third country is necessary (including through the use of Sub-processors), Bunker ensures that such transfer is carried out in accordance with Chapter V of the GDPR, relying on one of the following mechanisms:
  • (a) an adequacy decision by the European Commission under Article 45 of the GDPR;
  • (b) the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with the appropriate module;
  • (c) appropriate supplementary safeguards and, where applicable, a Transfer Impact Assessment.
9.4. The Controller mandates Bunker to conclude, on its behalf, the Standard Contractual Clauses with Sub-processors located in third countries, where applicable.

Article 10 — Security measures

10.1. Bunker implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, thereby supporting the Controller's compliance with data protection by design and by default (Article 25 of the GDPR).
10.2. Bunker undertakes in particular to:
  • (a) implement measures to protect against the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data;
  • (b) restrict access to Personal Data to authorized persons only, on a need-to-know basis;
  • (c) ensure that all personnel and Sub-processors with access to Personal Data are subject to appropriate confidentiality obligations;
  • (d) regularly test, analyze and evaluate the effectiveness of the technical and organizational measures implemented.
10.3. The specific technical and organizational measures are described in Annex 2 to this DPA.

Article 11 — Data breach notification

11.1. Bunker notifies the Controller of any Data Breach without undue delay and no later than within 48 hours of becoming aware of the breach.
11.2. This notification includes, to the extent the information is available at the time of notification:
  • (a) a description of the nature of the Data Breach, including the categories and approximate number of data subjects and Personal Data records concerned;
  • (b) the name and contact details of Bunker's data protection point of contact;
  • (c) a description of the likely consequences of the Data Breach;
  • (d) a description of the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects.
11.3. Where it is not possible to provide all the information at the same time, Bunker provides it in phases without undue delay.
11.4. Bunker provides reasonable cooperation and assistance to the Controller to enable it to meet its notification obligations to the competent supervisory authority (Article 33 of the GDPR) and to data subjects (Article 34 of the GDPR).

Article 12 — Assistance with data subject rights

12.1. Bunker promptly notifies the Controller of any request or complaint received directly from a data subject exercising their rights under the Applicable Regulations (access, rectification, erasure, restriction, portability, objection).
12.2. Bunker provides reasonable technical and organizational cooperation and assistance to enable the Controller to respond to such requests within the time limits set by applicable law.
12.3. Bunker does not respond directly to a data subject request, unless otherwise instructed by the Controller or required by law.

Article 13 — Data deletion and return

13.1. The Controller is solely responsible for defining and implementing appropriate retention periods.
13.2. Upon termination or expiry of the Agreement, Bunker, at the Controller's written choice:
  • (a) returns all Personal Data in a structured, commonly used and machine-readable format; or
  • (b) deletes all Personal Data using secure deletion methods compliant with industry standards.
13.3. Bunker carries out the return or deletion within 30 days of the end of the Agreement, unless a legal retention obligation applies.
13.4. Bunker deletes all existing copies of the Personal Data, unless Union or Member State law requires retention. Upon request, Bunker provides a written certificate of deletion.

Article 14 — Audit and control

14.1. Bunker makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and in this DPA.
14.2. Bunker allows for and contributes to audits, including inspections, carried out by the Controller or an independent auditor mandated by the Controller, subject to the following conditions:
  • (a) the Controller notifies Bunker with at least 30 business days' written notice;
  • (b) audits are limited to once per year, except in the event of a confirmed Data Breach or a requirement from a supervisory authority;
  • (c) the auditor is subject to appropriate confidentiality obligations;
  • (d) the audit does not unreasonably disrupt Bunker's operations and does not compromise the security or confidentiality of other clients' data;
  • (e) audit costs are borne by the Controller;
  • (f) the Controller may accept an audit or certification report issued by an independent third-party auditor in lieu of an on-site audit.
14.3. Bunker cooperates with any investigation or audit carried out by a competent data protection supervisory authority.
14.4. The Controller shares audit reports with Bunker and grants it a reasonable period to respond to any findings.

Article 15 — Liability

15.1. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
15.2. The parties acknowledge that, in accordance with Article 82 of the GDPR, each party is liable for the damage caused by processing that infringes the GDPR, under the conditions provided for therein.
15.3. The limitations and exclusions of liability set out in the Agreement apply exclusively to the relationship between the parties. They affect neither the right to compensation of data subjects under Article 82 of the GDPR, nor administrative fines imposed by a supervisory authority under Article 83 of the GDPR.

Article 16 — Term and termination

16.1. This DPA takes effect on the date the Controller accepts the Agreement and remains in force for the entire duration of the Agreement.
16.2. Bunker's obligations under this DPA relating to the security and deletion of Personal Data survive the termination or expiry of the Agreement. The confidentiality obligation continues for a period of five (5) years after the end of the Agreement.

Article 17 — Governing law and jurisdiction

17.1. This DPA is governed by French law.
17.2. Any dispute relating to this DPA shall be subject to the exclusive jurisdiction of the courts of La Roche-sur-Yon, France.

Article 18 — Contact

For any question relating to data protection under this DPA:
France Nuage SAS
Email: [email protected]

Annexes

Annex 1 — Description of processing operations

Annex 1 — Description of processing operations
Item Description
Subject matter of processing Provision of cloud infrastructure, hosting, storage, compute and related services by Bunker to the Controller in accordance with the Agreement.
Duration of processing Duration of the Agreement, plus 30 days for data cleanup operations after account deletion.
Nature of processing Hosting, storage, compute, transmission, backup, monitoring and technical administration of the data submitted by the Controller to the platform.
Purpose of processing To provide the cloud infrastructure services described in the Agreement, including deployment, scaling, monitoring, support and billing.
Categories of personal data Email addresses, first and last names, IP addresses, authentication tokens, application data hosted by the Controller, billing information, usage logs, and any other personal data that the Controller chooses to submit to the platform.
Categories of data subjects The Controller's end users; the Controller's employees, contractors and collaborators; the authorized users of the Bunker account.
Location of processing France, except for the Sub-processors listed in Annex 3 (certified data centers located on French territory).
Frequency Continuous and automated processing for the duration of the Agreement.

Annex 2 — Technical and organizational security measures

Self-assessed security measures, not certified by a third party to date; our certification roadmap is published on the Security & Compliance page.

Infrastructure security
  • Hosting: data centers located exclusively in France, in certified facilities.
  • Encryption at rest: all stored data is encrypted at rest using state-of-the-art algorithms.
  • Encryption in transit: TLS 1.2 minimum for all data in transit.
  • Backups: automated and encrypted backups with defined retention periods.
  • DDoS protection: DDoS mitigation via Cloudflare (with Standard Contractual Clauses in place).
  • Network segmentation: isolation between client environments.
Application security
  • Authentication: centralized identity management via Keycloak (self-hosted).
  • Access control: role-based access control (RBAC) following the principle of least privilege.
  • Session management: automatic session expiry and token rotation.
  • MFA: multi-factor authentication enforced for infrastructure access.
Development security
  • Code review: mandatory peer review for any code change (self-hosted GitLab).
  • CI/CD pipeline: automated security analysis including static application security testing (SAST), container and dependency vulnerability scanning, and secret detection.
  • Open-source stack: platform built on open-source technologies (Kubernetes, PostgreSQL, Redis, Prometheus, Grafana), enabling a full audit of the code.
Monitoring and incident response
  • Monitoring: 24/7 security on-call with real-time intrusion detection.
  • Observability: centralized logging and distributed tracing (Grafana/Loki/Tempo/Mimir — self-hosted).
  • Availability monitoring: continuous monitoring via Better Stack (EU-based).
  • Incident response: defined incident response procedures with escalation paths.
  • Threat detection: CrowdSec (self-hosted) for collaborative threat intelligence.
Organizational measures
  • Confidentiality: all personnel are subject to confidentiality obligations.
  • Access management: need-to-know principle applied.
  • Awareness: regular security training for all personnel.
  • Vendor assessment: security of Sub-processors assessed prior to their engagement.
Data retention
  • Application data: according to the retention settings defined by the Controller.
  • Account data: duration of the Agreement plus 30 days.
  • Billing data: 10 years (French tax obligation — Article L123-22 of the French Commercial Code).
  • Logs: minimum 30 days, configurable according to the subscribed plan.

Annex 3 — List of sub-processors

Last updated: July 1, 2026.

Annex 3 — List of sub-processors
Sub-processor Location Purpose Data processed Transfer mechanism
Stripe, Inc. United States Payment processing and billing Billing data, payment tokens Standard Contractual Clauses (EU 2021/914)
Cloudflare, Inc. United States DNS management and DDoS protection Visitor IP addresses, HTTP request metadata Standard Contractual Clauses (EU 2021/914)
Better Stack Ltd Lithuania (EU) Availability monitoring Public URLs, response times N/A (intra-EEA)

Self-hosted services (France — no third-party sub-processor): Keycloak, PostgreSQL, Redis, Matomo, GitLab, Grafana/Loki/Tempo/Mimir, Ceph S3, DocuSeal, N8N, CrowdSec, Headscale.

The up-to-date list of Sub-processors is available on the Sub-processors page.

This Data Processing Agreement was last updated on July 1, 2026.