Klepsi data processing agreement
Version 0.1, September 2026. Annex to the subscription terms.
This is a translation: the French version prevails.
1. Purpose and parties
This agreement governs the processing of personal data carried out by ALEOP SAS ("Aleop", processor) on behalf of the customer subscribed to Klepsi ("the Customer", controller), in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR).
It is attached to the Klepsi subscription terms and forms part of them. It is accepted together with them. In case of conflict on data protection, this agreement prevails.
2. Description of the processing
Aleop hosts, backs up, monitors, maintains and updates the Customer's Klepsi Instance, and handles support requests. The nature and purpose of the processing, the categories of data and data subjects and the duration are described in Annex 1.
3. Customer instructions
Aleop processes the data only on documented instructions from the Customer. The subscription terms, this agreement, the Instance settings and the Customer's written requests constitute these instructions.
If Aleop considers that an instruction infringes data protection law, it informs the Customer without delay. If Union or Member State law requires Aleop to carry out a processing, Aleop informs the Customer before doing so, unless the law prohibits it.
4. Confidentiality
Persons authorised by Aleop to access the data are bound by a contractual or statutory duty of confidentiality. Access is limited to what operations and support require.
5. Security
Aleop implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk. Aleop may change them, without ever lowering the level of protection.
The Customer remains responsible for the security of what it controls: management of its users and their rights, choice of its sign-in methods, confidentiality of credentials, connectors it enables to third-party services.
6. Sub-processors
The Customer authorises Aleop to use the sub-processors listed in Annex 3. Aleop imposes on them by contract data protection obligations equivalent to those of this agreement and remains liable for their performance.
Aleop informs the Customer by email at least thirty (30) days before adding or replacing a sub-processor. The Customer may object on data protection grounds. Failing agreement, it may terminate its subscription at no cost before the new sub-processor starts.
Third-party services that the Customer itself connects to its Instance (accounting tool, email, identity provider, instant messaging) are not Aleop's sub-processors. The Customer chooses them and contracts with them directly.
7. Location and transfers
Instance data and its backups are hosted in France. No data is transferred outside the European Union without the Customer's written consent, except in the cases stated in Annex 3. Any transfer is then covered by an adequacy decision or by the European Commission's standard contractual clauses.
8. Data subject rights
The Instance lets the Customer answer requests for access, rectification, erasure, restriction and portability itself: viewing and editing records, full export, deletion and purge of a person's data.
If a data subject contacts Aleop directly, Aleop forwards the request to the Customer without answering it, unless instructed otherwise. Aleop assists the Customer where the Instance is not enough.
9. Personal data breach
Aleop notifies the Customer of any personal data breach affecting the Instance within forty-eight (48) hours of becoming aware of it. The notification describes, as far as possible, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and the contact at Aleop.
The Customer, as controller, notifies the supervisory authority and, where required, the data subjects. Aleop assists it in doing so.
10. Assistance to the Customer
Aleop provides the Customer with the information it reasonably needs to carry out a data protection impact assessment or to consult the supervisory authority, as far as Klepsi is concerned.
11. Return and deletion of data
At the end of the subscription, the Instance remains available in read-only mode for sixty (60) days so that the Customer can export its data, in the formats offered by the Instance. After this period, Aleop deletes the Instance and its database. Backup copies are erased at the end of their rotation cycle, no later than thirty-five (35) days after deletion. Until then, they are not used for any restore specific to the Customer. If a full restore of the host takes place during this period, the deleted Instance is deleted again straight away.
Aleop provides a deletion certificate on request. Aleop keeps no copy, except where required by law, in which case it informs the Customer.
12. Documentation and audit
Aleop makes available to the Customer the information needed to demonstrate compliance with this agreement, in particular the current description of security measures and the list of sub-processors.
The Customer may have an audit carried out, by itself or by an independent auditor bound by confidentiality and not a competitor of Aleop, at most once a year, with thirty (30) days' written notice. The audit covers Klepsi and is carried out without disrupting the service or giving access to other customers' data. Its costs are borne by the Customer, unless it reveals a significant breach by Aleop.
13. Records
Aleop keeps the record of categories of processing activities carried out on behalf of its customers, as provided for in Article 30(2) GDPR.
14. Term and liability
This agreement applies for the whole term of the subscription and until the data has been fully deleted. Each party's liability follows the subscription terms, without prejudice to the mandatory provisions of the GDPR.
Annex 1. Description of the processing
- Nature of the operations
- Hosting, storage, backup and restore, monitoring, maintenance and updates, support at the Customer's request.
- Purpose
- Providing the Customer with the Klepsi service: tracking time, projects and orders, activity reports, invoicing.
- Data subjects
- Employees, consultants, temporary staff and subcontractors of the Customer who use the Instance. Contacts at the Customer's own clients, recorded in the Instance.
- Data processed
- Identity and business contact details, sign-in credentials and second factor, role, team and assignments, time entries and comments, projects and orders, rates and costs, invoices and activity reports, technical logs (sign-in dates, IP address).
- Sensitive data
- None expected. The Customer undertakes not to enter any. If it enables absence tracking, it sets up reasons without medical detail.
- Duration
- Term of the subscription, then sixty (60) days of read-only mode, then erasure of backups at the end of their rotation, thirty-five (35) days at most.
- Location
- France (hosting and backups).
Annex 2. Security measures
- Isolation
- One Instance per customer, with its own database, its own containers and its own address. No database shared between customers.
- Encryption
- Traffic encrypted with TLS. Backups encrypted (AES-256) on the host before they are sent to the backup server, which cannot read them. The key is kept by Aleop outside that server.
- Authentication
- Local accounts protected by a second factor (TOTP), or single sign-on through the Customer's identity provider. Passwords stored hashed.
- Operations access
- Administrative access restricted to authorised operations staff, through named accounts, over a VPN and with a second factor. Access is logged.
- Backups
- Daily encrypted backup of the Instance, kept on another site: seven (7) daily and four (4) weekly copies, thirty-five (35) days at most. Restore test once a quarter.
- Monitoring
- Continuous monitoring of each Instance's availability and of host capacity, with alerting.
- Updates
- Security updates of the system and the software applied regularly, backup before each version upgrade.
- Logging
- Access logs (including IP addresses) kept for one hundred and eighty (180) days, then deleted. Application logs capped in size and renewed automatically.
- Organisation
- Aleop information security policy, staff confidentiality, incident management procedure.
Annex 3. Sub-processors
- OVHcloud (France)
- Hosting of Instances and backups, in data centres located in France.
- Brevo (France)
- Sending of service emails (sign-up, invitations, password resets, notifications) from the klepsi.app domain. Processes the recipient's address, name and the message content. Brevo rewrites the links in these messages and records clicks; anonymous tracking is enabled on the account, so a click is not tied to the recipient. Data hosted in the European Union.
- Atlassian (Jira Service Management)
- Support portal. Contains requests and whatever the Customer attaches to them. Data hosted in the European Union (EU data residency). Company subject to US law: any access from outside the Union is covered by the European Commission's standard contractual clauses.
ALEOP SAS, 99 vieille route de la Gavotte, Les Bastides du Cèdre, 13170 Les Pennes Mirabeau, France. Trade register Aix-en-Provence 883 057 424. Data protection contact: contact@aleop.eu.