Data Processing Agreement (DPA)

Effective from 2026-08-10v1

Between the Parties

  • Data Controller: the Customer (the “Garage”), identified by the information provided when creating its account and subscribing online (company name, SIRET registration number, address, representative — as shown in its customer portal and order summary).
  • Data Processor: Prospectrum (Benjamin Bengler, sole trader), 173 rue de Courcelles, 75017 Paris, France — benjamin.bengler@prospectrum.ai — SIRET 106 886 088 00017.
Contract formation. This DPA is an inseparable annex to the T&Cs, accepted electronically by the Customer upon self-service online subscription (checkbox + double-click, Art. 1127-2 of the French Civil Code). No handwritten signature is required: Article 28.9 of the GDPR expressly permits electronic written form for this contract. Proof of acceptance (timestamp, IP address) is retained with the contractual file.

01. Purpose

The Processor processes, on behalf of and on the documented instructions of the Controller, the data necessary for the Prospectrum service (AI telephone assistant). A description of this processing is set out in Annex 1.

02. Definitions

Terms used in this contract have the meaning given to them in Article 4 of the GDPR.

03. Duration

This contract applies for the entire duration of the service contract and for as long as the Processor processes data on behalf of the Controller.

04. Documented instructions (Art. 28.3.a)

  • The Processor processes data only on the Controller’s documented instructions, including for transfers outside the EU, except where required by law (in which case the Processor informs the Controller beforehand, unless prohibited from doing so by law). This contract and its annexes — which set out, in particular, the categories of data, how the AI assistant operates, and the retention periods, as fixed by the Processor as part of its service — together with the Garage’s own configuration (calendar, service catalogue), constitute these instructions, which the Controller adopts by accepting this contract. The Processor alerts the Controller if it considers that an instruction would infringe the GDPR.
  • Purposes authorised by the Controller include the short-term retention of recordings and transcripts for security, debugging and quality purposes (retention periods set out in Annex 1). Without this authorisation, debugging carried out on audio data would cause the Processor to become a controller in its own right (Art. 28.10 of the GDPR).

05. Confidentiality (Art. 28.3.b)

Persons authorised to process the data undertake to keep it confidential. As the Processor is currently a sole proprietorship, this undertaking is personal; any person authorised in the future will be bound by an equivalent confidentiality undertaking.

06. Security (Art. 28.3.c, Art. 32)

The technical and organisational measures implemented by the Processor are described in Annex 3.

07. Sub-processing (Art. 28.2 and 28.4)

  • General authorisation: the up-to-date list of sub-processors is published at https://prospectrum.ai/sous-traitants (see Annex 2).
  • The Controller is informed of any addition or replacement of a sub-processor with 15 days’ notice and may, within that period, raise a legitimate objection. That notice is sent by email to the contact address on the Controller’s account, and the version in force of the list is published at the address referred to above. Where the Processor cannot accommodate a legitimate objection, the Controller may terminate the affected service without penalty — the sole effect of the objection.
  • Alternative voice-technology providers (voice-stack bench, Annex 2) are deemed pre-authorised, being known at the time of subscription: their activation does not trigger a new notification.
  • The same obligations set out in this contract are imposed on each sub-processor (Art. 28.4 of the GDPR); the Processor remains fully liable to the Controller for the performance of those obligations.

08. Transfers outside the EU

  • Transfers of data outside the European Union are governed in accordance with Article 46 of the GDPR.
  • Twilio (Twilio Inc., United States): the transfer is covered by the EU-US Data Privacy Framework, with Standard Contractual Clauses applying as a fallback.
  • OpenAI (EU contracting entity: OpenAI Ireland Ltd): this provider is not Data Privacy Framework-certified; the transfer is therefore covered by Standard Contractual Clauses (Art. 46.2.c of the GDPR), accompanied by a transfer impact assessment (following the Schrems II ruling, CJEU, C-311/18).
  • Scaleway (France): hosted in France, no transfer outside the EU.
  • Gladia (Gladia SAS, France): speech recognition, with data localised in Europe under its own data processing agreement — no transfer outside the EU under that service.
  • ElevenLabs (ElevenLabs Ltd., United States): speech synthesis — the transfer is covered by the EU-US Data Privacy Framework, with the Standard Contractual Clauses of its data processing agreement applying as a fallback.
  • Details by provider are set out in Annex 2.

09. Data subject rights (Art. 28.3.e)

The Processor assists the Controller in responding to requests to exercise data subject rights (Art. 15 to 22 of the GDPR). Any request addressed directly to the Processor is forwarded to the Controller without delay.

10. Security assistance, breaches, DPIA (Art. 28.3.f; Art. 33-36)

  • Assistance to the Controller with respect to the security measures required under Article 32 of the GDPR.
  • Personal data breach: the Processor notifies the Controller without undue delay after becoming aware of it (Art. 33.2 of the GDPR), communicating the information available to it within the meaning of Art. 33.3, and in such a way as to enable the Controller to make its own notification to the CNIL within the 72-hour period set out in Art. 33.1 of the GDPR. The Processor supplements that information as it becomes available, without waiting until it has fully characterised the incident.
  • Assistance to the Controller in carrying out data protection impact assessments (DPIAs, Art. 35 of the GDPR) and with prior consultation of the CNIL where required (Art. 36 of the GDPR).

11. End of contract (Art. 28.3.g)

At the Controller’s choice, expressed at the end of the service contract, the Processor returns (exports) the personal data and then erases it, or erases it directly, unless required by law to retain it. Erasure has the meaning given in Annex 1: personal data is deleted or irreversibly anonymised in production systems; encrypted backups already taken retain it until they expire under the rotation cycle in force, and are not otherwise used. Absent instructions from the Controller, the Processor carries out that erasure in accordance with the retention periods set out in Annex 1.

12. Documentation and audits (Art. 28.3.h)

The Processor makes available to the Controller the information necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR. The Controller may request an audit no more than once per year (except in the event of a confirmed security incident justifying an additional audit), subject to reasonable notice of 30 days, during business hours, at the requesting Controller’s expense, under a confidentiality undertaking, and without disrupting the operation of the service or compromising the security of other customers’ data. The Processor may satisfy this obligation by providing existing documentation or certifications where they cover the subject of the request.

13. Register and Controller obligations

  • The Processor maintains the record of processing activities required under Article 30.2 of the GDPR.
  • The Controller has a lawful basis for its own processing and informs callers (Art. 13 and 14 of the GDPR), in particular using the turnkey information kit provided in Annex 4.
  • The Controller documents the instructions it gives to the Processor.
  • The Controller complies with the GDPR for all processing for which it is responsible.

14. Third-party recipients (separate controllers)

The following are separate data controllers, and not Prospectrum sub-processors: the licence-plate lookup API and the Google or Microsoft calendar connected by the Garage itself (via OAuth). Licence-plate lookup is disabled in production at launch of the Service: no provider is active and no plate is transmitted to any third party. It will be reactivated after launch, using a licensed re-user of the French vehicle registration system (SIV) (target: Dataneo WebSIV, licensed under Art. L. 330-5 of the French Highway Code), under a GDPR Art. 28-compliant DPA; that entity will then be recorded in the sub-processor register.

15. Liability

The Processor’s liability is governed by Article 82 of the GDPR.

16. Version and effective date

This DPA constitutes version v1, effective from 2026-08-10. No earlier version exists to date; any earlier version will be provided on request at contact@prospectrum.ai.

Annex 1 — Description of the sub-processed data processing

ItemContent
NatureCall answering and routing; recording and transcription; AI voice processing; appointment booking; SMS; data retention and return.
PurposeTo provide the Garage’s service, as well as the security, debugging and quality control of the Service.
Data subjectsThe Garage’s callers.
DataPhone number, audio recording, transcript, name, licence plate, appointment details.
Retention periods (in force)Audio: 30 days. Transcript and summary: 90 days. Structured record: 730 days (2 years). These periods are set by the Processor and accepted by the Garage under this contract. The retention period for the structured record is aligned with the actual return cycle for car repairs (the biennial French roadworthiness test), so as to recognise a returning customer (Art. 5.1.e of the GDPR; within the CNIL norm applicable to CRM, which allows up to 3 years). The three distinct periods are enforced by an automated daily purge.

Annex 2 — Authorised sub-processors

The complete, up-to-date named list of onward sub-processors — with their role, location and the safeguards governing transfers — is published and kept current at https://prospectrum.ai/sous-traitants. The sub-processors involved in processing caller data are, as at the effective date of this agreement: OpenAI (AI voice processing and response generation, United States, EU entity OpenAI Ireland Ltd), Twilio (telephony and SMS, United States / Ireland), Scaleway (hosting and storage, France), Gladia SAS (speech recognition, France, data localised in Europe) and ElevenLabs Ltd. (speech synthesis, United States, EU-US Data Privacy Framework).

Voice-technology bench — deemed pre-authorised, not activated. For speech recognition and speech synthesis the Processor may additionally use the following provider, named and therefore known to the Controller as from subscription, and deemed pre-authorised on that basis: Deepgram (speech recognition and synthesis). Activating one of these named providers does not trigger a fresh notification. Any provider not named in this Annex constitutes a new onward sub-processor, subject to the 15 days’ notice and the right of objection set out in Article 7.

Some sub-processors are established outside the European Union or transfer data there; such transfers are governed by the EU-US Data Privacy Framework or by Standard Contractual Clauses accompanied by a transfer impact assessment. Data Privacy Framework certifications are renewed annually and are rechecked before they expire.

Stripe and Brevo do not fall under this DPA: these providers process Prospectrum’s own business data (billing, emails sent to garages), not caller data. They are accordingly governed by Prospectrum’s Privacy Policy.

Annex 3 — Security measures (Art. 32)

  • Hosting within the European Union (Scaleway, France)
  • Encryption in transit (TLS)
  • Application-level encryption of calendar tokens
  • Encryption at rest: the PostgreSQL volume is encrypted at the disk level at Scaleway SAS (Paris) using recognised state-of-the-art algorithms (AES-256); the key is held by the Processor and stored in a dedicated secrets manager, separate from the volume. Backups are encrypted before export and retained within the EU. (Defence in depth: additional application-level encryption of calendar tokens.)
  • Segregation: each garage can only access its own calls
  • Automated daily purge
  • Audit log of access to recordings
  • Sub-processors are bound by the same obligations (Art. 28.4 of the GDPR).

Annex 4 — Caller information kit

  • Voice announcement at the start of the call informing callers of the processing (recording and AI) in place
  • A single caller-information page hosted by the Processor and shared by all Garages: https://prospectrum.ai/vos-donnees. It sets out the information required by Article 13 of the GDPR — categories of data, purposes, legal bases, retention periods, categories of recipients, transfers outside the EU, rights and the complaint route — and refers to the Garage, as controller, for the exercise of those rights.
  • AI usage charter, published at https://prospectrum.ai/charte-ia (transparency, Article 50 of Regulation (EU) 2024/1689 on artificial intelligence)
  • Information line and short link included in the confirmation SMS (being made available)
  • Printable poster for the reception desk (PDF) (being made available)