DPA contents
Our Data Processing Agreement covers the following sections:
- 1 Subject matter and duration of processing
- 2 Nature and purpose of processing
- 3 Types of personal data processed
- 4 Categories of data subjects
- 5 Obligations of the processor (Bunker)
- 6 Obligations of the controller (the client)
- 7 Sub-processors
- 8 Transfers outside the EU
- 9 Technical and organizational security measures
- 10 Data breach notification
- 11 Assistance with data subject rights
- 12 Data return and deletion
- 13 Audit and control
Key commitments of Bunker
Full text of the DPA
Effective date : July 1, 2026
This Data Processing Agreement (hereinafter the « DPA ») forms an integral part of the Terms of Service (hereinafter the « Agreement ») concluded between France Nuage SAS (hereinafter « Bunker », the « Processor ») and the Client (hereinafter the « Controller ») and sets out the conditions under which Bunker processes personal data on behalf of the Client in the context of providing the Services.
Capitalized terms not defined in this DPA have the meaning given to them in the Agreement or in the applicable data protection regulations.
Article 1 — Definitions
Article 2 — Scope and duration of processing
Article 3 — Nature and purpose of processing
Article 4 — Types of personal data processed
- Email addresses, first and last names of authorized users;
- IP addresses and connection logs;
- Authentication tokens;
- Application data hosted by the Controller;
- Billing information;
- Any other Personal Data that the Controller chooses to submit to the platform.
Article 5 — Categories of data subjects
- The Controller's end users whose data is hosted on the platform;
- The Controller's employees, contractors and collaborators;
- The authorized users of the Controller's Bunker account;
- Any natural person whose data is submitted by the Controller.
Article 6 — Obligations of the Processor
Article 7 — Obligations of the Controller
Article 8 — Sub-processing
Article 9 — International data transfers
- (a) an adequacy decision by the European Commission under Article 45 of the GDPR;
- (b) the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), with the appropriate module;
- (c) appropriate supplementary safeguards and, where applicable, a Transfer Impact Assessment.
Article 10 — Security measures
- (a) implement measures to protect against the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data;
- (b) restrict access to Personal Data to authorized persons only, on a need-to-know basis;
- (c) ensure that all personnel and Sub-processors with access to Personal Data are subject to appropriate confidentiality obligations;
- (d) regularly test, analyze and evaluate the effectiveness of the technical and organizational measures implemented.
Article 11 — Data breach notification
- (a) a description of the nature of the Data Breach, including the categories and approximate number of data subjects and Personal Data records concerned;
- (b) the name and contact details of Bunker's data protection point of contact;
- (c) a description of the likely consequences of the Data Breach;
- (d) a description of the measures taken or proposed to address the Data Breach, including measures to mitigate its possible adverse effects.
Article 12 — Assistance with data subject rights
Article 13 — Data deletion and return
- (a) returns all Personal Data in a structured, commonly used and machine-readable format; or
- (b) deletes all Personal Data using secure deletion methods compliant with industry standards.
Article 14 — Audit and control
- (a) the Controller notifies Bunker with at least 30 business days' written notice;
- (b) audits are limited to once per year, except in the event of a confirmed Data Breach or a requirement from a supervisory authority;
- (c) the auditor is subject to appropriate confidentiality obligations;
- (d) the audit does not unreasonably disrupt Bunker's operations and does not compromise the security or confidentiality of other clients' data;
- (e) audit costs are borne by the Controller;
- (f) the Controller may accept an audit or certification report issued by an independent third-party auditor in lieu of an on-site audit.
Article 15 — Liability
Article 16 — Term and termination
Article 17 — Governing law and jurisdiction
Article 18 — Contact
Email: [email protected]
Annexes
Annex 1 — Description of processing operations
| Item | Description |
|---|---|
| Subject matter of processing | Provision of cloud infrastructure, hosting, storage, compute and related services by Bunker to the Controller in accordance with the Agreement. |
| Duration of processing | Duration of the Agreement, plus 30 days for data cleanup operations after account deletion. |
| Nature of processing | Hosting, storage, compute, transmission, backup, monitoring and technical administration of the data submitted by the Controller to the platform. |
| Purpose of processing | To provide the cloud infrastructure services described in the Agreement, including deployment, scaling, monitoring, support and billing. |
| Categories of personal data | Email addresses, first and last names, IP addresses, authentication tokens, application data hosted by the Controller, billing information, usage logs, and any other personal data that the Controller chooses to submit to the platform. |
| Categories of data subjects | The Controller's end users; the Controller's employees, contractors and collaborators; the authorized users of the Bunker account. |
| Location of processing | France, except for the Sub-processors listed in Annex 3 (certified data centers located on French territory). |
| Frequency | Continuous and automated processing for the duration of the Agreement. |
Annex 2 — Technical and organizational security measures
Self-assessed security measures, not certified by a third party to date; our certification roadmap is published on the Security & Compliance page.
Infrastructure security
- Hosting: data centers located exclusively in France, in certified facilities.
- Encryption at rest: all stored data is encrypted at rest using state-of-the-art algorithms.
- Encryption in transit: TLS 1.2 minimum for all data in transit.
- Backups: automated and encrypted backups with defined retention periods.
- DDoS protection: DDoS mitigation via Cloudflare (with Standard Contractual Clauses in place).
- Network segmentation: isolation between client environments.
Application security
- Authentication: centralized identity management via Keycloak (self-hosted).
- Access control: role-based access control (RBAC) following the principle of least privilege.
- Session management: automatic session expiry and token rotation.
- MFA: multi-factor authentication enforced for infrastructure access.
Development security
- Code review: mandatory peer review for any code change (self-hosted GitLab).
- CI/CD pipeline: automated security analysis including static application security testing (SAST), container and dependency vulnerability scanning, and secret detection.
- Open-source stack: platform built on open-source technologies (Kubernetes, PostgreSQL, Redis, Prometheus, Grafana), enabling a full audit of the code.
Monitoring and incident response
- Monitoring: 24/7 security on-call with real-time intrusion detection.
- Observability: centralized logging and distributed tracing (Grafana/Loki/Tempo/Mimir — self-hosted).
- Availability monitoring: continuous monitoring via Better Stack (EU-based).
- Incident response: defined incident response procedures with escalation paths.
- Threat detection: CrowdSec (self-hosted) for collaborative threat intelligence.
Organizational measures
- Confidentiality: all personnel are subject to confidentiality obligations.
- Access management: need-to-know principle applied.
- Awareness: regular security training for all personnel.
- Vendor assessment: security of Sub-processors assessed prior to their engagement.
Data retention
- Application data: according to the retention settings defined by the Controller.
- Account data: duration of the Agreement plus 30 days.
- Billing data: 10 years (French tax obligation — Article L123-22 of the French Commercial Code).
- Logs: minimum 30 days, configurable according to the subscribed plan.
Annex 3 — List of sub-processors
Last updated: July 1, 2026.
| Sub-processor | Location | Purpose | Data processed | Transfer mechanism |
|---|---|---|---|---|
| Stripe, Inc. | United States | Payment processing and billing | Billing data, payment tokens | Standard Contractual Clauses (EU 2021/914) |
| Cloudflare, Inc. | United States | DNS management and DDoS protection | Visitor IP addresses, HTTP request metadata | Standard Contractual Clauses (EU 2021/914) |
| Better Stack Ltd | Lithuania (EU) | Availability monitoring | Public URLs, response times | N/A (intra-EEA) |
Self-hosted services (France — no third-party sub-processor): Keycloak, PostgreSQL, Redis, Matomo, GitLab, Grafana/Loki/Tempo/Mimir, Ceph S3, DocuSeal, N8N, CrowdSec, Headscale.
The up-to-date list of Sub-processors is available on the Sub-processors page.
This Data Processing Agreement was last updated on July 1, 2026.
Printable version
This standard DPA applies to all Bunker clients. Print it or save it as a PDF from your browser to archive it or attach it to your compliance file.
For a custom DPA or a signed version, contact our DPO.
Questions about the DPA?
Contact our DPO at [email protected]