Data processing agreement
Last updated: 23 September 2026
This data processing agreement (“DPA”) is entered into pursuant to Article 28 of the GDPR between each merchant using the RushPilot service (the “Controller”) and Louchebem Software (the “Processor”). It forms an integral part of the general terms and applies from account creation, including during the trial period.
1. Subject matter, nature and duration of processing
- Subject matter: provision of the RushPilot service (order taking, preparation, online shop, customer relations, hygiene records and statistics).
- Nature of operations: collection, recording, storage, consultation, structuring, export and erasure.
- Duration: the term of the service agreement, extended only by the data-export and deletion period (Article 8).
2. Data and data subjects
- The Controller’s end customers: identity, contact details (email, telephone), account identifiers, order contents and history, collection slots, preferences and customer-relationship indicators.
- The Controller’s staff: identity, work email, role, login credentials and links to operational records (orders prepared, hygiene checks carried out).
The service does not require any “special category” data (Article 9 of the GDPR); the Controller undertakes not to enter such data in free-text fields.
3. Instructions
The Processor processes data only on the Controller’s documented instructions, expressed through the configuration and use of the service, and for no other purpose. It does not reuse the data for its own purposes, transfer it to others or sell it. If it considers that an instruction breaches regulations, it informs the Controller without delay.
4. Confidentiality and personnel
Persons authorised to process data are subject to a duty of confidentiality. Access is limited to what is strictly necessary (the principle of least privilege); there is no permanent access to production data for development purposes.
5. Security (Article 32)
- Encryption of communications (TLS) and data at rest;
- Strict isolation of each merchant’s data, enforced at database level (Row-Level Security) and tested automatically;
- Database accessible only through a private network, with no public exposure;
- Authentication using short-lived, rotating tokens and hashed passwords;
- Daily encrypted backups, replicated off the main site, with restoration tested;
- Logging of sensitive events and continuous monitoring with alerts;
- Infrastructure hardening: administration only through a private network, with secrets kept out of the code.
6. Sub-processors
The Controller authorises the following sub-processors for data processed as part of the service, each limited to its assigned task and bound by data-protection obligations:
- Scaleway SAS (8 rue de la Ville l'Évêque, 75008 Paris, France) — hosting, databases and primary storage in France.
- Backblaze — off-site storage of backups encrypted beforehand by Louchebem Software, in a storage region in Central Europe.
- Brevo (a French company) — sending transactional emails (order confirmations, notifications) on the Controller’s behalf.
- Stripe — payment collection once online payment is activated; the Processor stores no card data.
- Sentry — technical error diagnosis, with ingestion configured in Germany and minimisation of URLs and secrets before transmission.
- Google Workspace / Gmail — email needed for support communications and, depending on configuration, sending service-related messages.
- OpenRouter — routing text- and image-generation and analysis requests to models, restricted to providers that do not retain requests or use them to train their models. The models are from Anthropic, served by their publisher or a third-party host subject to the same non-retention requirement (for example Amazon Web Services).
- Google — product-image generation via direct access.
- For these last two items: processing covers the catalogue, shop content and photographs supplied by the Controller; end customers’ personal data are excluded from these requests (Article 7).
DocuSeal (document signing) and Umami (cookieless analytics) are self-hosted on Louchebem Software’s infrastructure and therefore do not involve transmission to their publishers. NeverBounce is used by Louchebem Software for its own prospecting activities; it does not receive end customers’ personal data on the Controller’s behalf.
Any addition or replacement is notified to the Controller at least 30 days before it takes effect; the Controller may object on legitimate grounds, and inability to reach a solution gives rise to a right to terminate without charge.
7. Transfers outside the European Union
Primary hosting is in France and the backup storage region is in the European Union. However, some providers are established outside the European Economic Area or may permit limited access there. When such a transfer includes personal data, it is covered, depending on the provider concerned, by an applicable adequacy decision or by the European Commission’s standard contractual clauses, supplemented where necessary by technical measures such as minimisation and encryption.
Content-generation requests may be processed outside the European Union, but are designed to exclude end customers’ names, emails, phone numbers and addresses. Off-site backups are encrypted before transfer; the decryption key is not entrusted to the storage provider.
8. Assistance, data-subject rights and end of contract
The Processor assists the Controller in responding to requests to exercise rights (access, rectification, erasure, portability, objection and restriction): the back office allows end-customer data to be corrected, exported in a structured format and actually deleted. Requests received directly by the Processor are forwarded to the Controller without delay.
At the end of the contract, the Controller has 90 days to export its data; after that period, all the Controller’s data (database, files and application logs) are permanently deleted, with backup copies expiring no later than 60 days after that deletion.
9. Data breaches
The Processor notifies the Controller of any personal-data breach without undue delay and no later than 48 hours after becoming aware of it, with the information needed for any notification to the CNIL (nature, categories and volumes concerned, likely consequences, measures taken). An internal incident register is maintained, including events that do not require notification.
10. Audit and documentation
The Processor makes available to the Controller the documentation needed to demonstrate compliance with this DPA (this document, the privacy policy, the list of sub-processors and the description of security measures). Once a year and with 30 days’ notice, the Controller may carry out or commission an audit, at its own expense, without access to other merchants’ data.
11. Contact
Any question or notification under this DPA: bonjour@rushpilot.fr.