Data Processing Agreement
The Article 28 GDPR agreement governing Provider’s processing of personal data on Customer’s behalf.
This Data Processing Agreement (the « DPA ») forms an integral part of, and is incorporated by reference into, the Balt General Terms of Service. It is entered into between Customer, as controller, and SKILLFORGE APP, a French simplified joint stock company (société par actions simplifiée) with a share capital of EUR 1,000, identified under SIREN 993 554 203, with registered office at 2 Rue des Commères, 78310 Coignières, France, as processor.
It takes effect on the date Customer accepts the General Terms and remains in force for as long as Provider processes personal data on Customer’s behalf. No signature is required for it to apply: a Customer that nevertheless wishes to hold a counter-signed copy may request one at legal@cobalt-ia.com, and that copy reproduces this text without modifying it.
Capitalized terms not defined here have the meanings given in the Definitions.
1. Definitions
- Standard Contractual Clauses or SCC: the standard data protection clauses adopted by Commission Implementing Decision (EU) 2021/914 of June 4, 2021 for the transfer of personal data to third countries.
- Personal Data: personal data within the meaning of Article 4(1) GDPR, comprised in Customer Data and processed by Provider on Customer’s behalf.
- Data Protection Law: the GDPR, French law no. 78-17 of January 6, 1978 as amended, Directive 2002/58/EC as transposed, the UK GDPR, and any other law applicable to the processing of Personal Data.
- Data Subject: the individual to whom the Personal Data relates.
- Controller, Processor, Processing, Personal Data Breach: as defined in Article 4 GDPR.
- Subprocessor: any processor engaged by Provider to carry out specific processing activities on Customer’s behalf.
- UK Addendum: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office.
2. Purpose and relationship with the Agreement
2.1 Purpose
This DPA sets out the terms on which Provider processes Personal Data on Customer’s behalf in the course of providing the Service, in accordance with Article 28 GDPR.
2.2 Order of precedence
In the event of conflict, the order of precedence is: (i) the Standard Contractual Clauses for matters relating to international transfers; (ii) the UK Addendum for transfers from the United Kingdom; (iii) this DPA; (iv) the General Terms and the other documents of the Agreement.
2.3 Description of the processing
The subject matter, duration, nature, and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I, which constitutes the description of the processing within the meaning of Article 28(3) GDPR.
3. Roles of the Parties
Customer is the controller of the Personal Data processed through the Service. Where Customer itself acts as a processor for a third party, Provider is a subprocessor and this DPA applies accordingly: Customer then warrants that it holds the necessary authorizations from its own controller.
Provider acts as controller for its own processing relating to customer relationship management, billing, security, and improvement of the Service, described in Section 2.2 of the Privacy Policy. This DPA does not apply to that processing.
4. Documented instructions
4.1 Scope of instructions
Provider processes Personal Data only on Customer’s documented instructions. Customer’s complete documented instructions as at the date of this DPA are: the Agreement, this DPA, the use of the Service by Authorized Users and the configuration Customer adopts, and any further instruction agreed between the Parties in writing.
4.2 Permitted processing
On that basis, Provider is authorized to:
- (a) provide, maintain, and secure the Service, including hosting, storing, indexing, and returning Personal Data;
- (b) execute the AI-driven tasks and workflows requested by Customer, including by transmitting the relevant content to AI Subprocessors for the sole purpose of producing Outputs;
- (c) exchange data with the Connected Platforms Customer has connected, within the permissions Customer has granted;
- (d) provide technical support and diagnose incidents;
- (e) carry out security monitoring, abuse detection, and business continuity;
- (f) comply with its legal obligations, on the terms of Section 4.4.
4.3 Prohibited processing
Provider shall not process Personal Data for any other purpose, and in particular shall not sell it, rent it, use it for targeted advertising, or use it to train general-purpose AI models. The arrangements entered into in that respect with each AI Subprocessor are described in Section 6 of the Privacy Policy.
4.4 Processing required by law
Where Union or Member State law to which Provider is subject requires processing, Provider informs Customer before processing, unless that law prohibits such information on important grounds of public interest.
4.5 Unlawful instruction
Provider immediately informs Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until Customer confirms, amends, or withdraws it.
5. Customer’s obligations
Customer:
- (a) warrants that it has an appropriate legal basis for each processing operation it entrusts to Provider, and that it has discharged its information obligations towards Data Subjects, including as regards the use of artificial intelligence systems and, where applicable, meeting recording;
- (b) submits to the Service no Regulated Data within the meaning of Section 3 of the Acceptable Use Policy, and in particular no data falling under Articles 9 and 10 GDPR, absent a prior written addendum;
- (c) configures permission scopes, approval policies, and the access of its Authorized Users proportionately to the data concerned;
- (d) is responsible for the instructions it gives and for Data Subject requests;
- (e) promptly informs Provider of anything liable to affect the lawfulness of the processing.
6. Confidentiality of personnel
Provider ensures that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, receive data protection training, and access only the data strictly necessary for their duties. Access is logged and reviewed periodically.
7. Security of processing
Provider implements the appropriate technical and organizational measures required by Article 32 GDPR, described in Annex II and in Section 6 of the Product Terms. Those measures may evolve with the state of the art, provided the overall level of security is not diminished.
8. Subprocessors
8.1 General authorization
Customer grants Provider a general authorization to engage Subprocessors, on the terms of this Section. The list of Subprocessors authorized as at the date of this DPA is set out in Section 7 of the Privacy Policy, which holds it for the whole of the contractual documents.
8.2 Obligations imposed
Provider enters into a contract with each Subprocessor imposing data protection obligations at least equivalent to those of this DPA. Provider remains fully liable to Customer for the performance by the Subprocessor of its obligations.
8.3 Notice and objection
Provider informs Customer of any intended addition or replacement of a Subprocessor at least thirty (30) days before it begins processing Personal Data. That information is given by publishing the amended list in Section 7 of the Privacy Policy, together with a dated entry in the version history; the period runs from that publication. A Customer that also wishes to receive notice by email may request it at legal@cobalt-ia.com. Customer may object within that period, in writing and on reasonable data protection grounds. The Parties will then seek an alternative solution in good faith; failing a solution within thirty (30) days, Customer may terminate without penalty the portion of the Service that cannot be provided without that Subprocessor, and obtain a pro-rata refund of prepaid fees for the unused period.
8.4 Connected Platforms
The Connected Platforms Customer chooses to connect are not Provider’s Subprocessors. They process data on Customer’s behalf under the separate contractual relationship between Customer and them.
9. Assistance to Customer
9.1 Data Subject rights
Provider forwards to Customer, within five (5) business days of receipt, any rights request a Data Subject addresses directly to it, without responding itself unless instructed by Customer. Provider assists Customer, by appropriate technical and organizational measures and taking into account the nature of the processing, in responding to such requests. The Service makes available to Customer the access, rectification, export, and deletion functions required; where the assistance requested exceeds those functions and requires substantial work, it may be charged on a time-spent basis, after prior notice to Customer.
9.2 Articles 32 to 36 GDPR
Provider assists Customer, taking into account the nature of the processing and the information available to it, with security of processing, breach notification, data protection impact assessments, and prior consultation of the supervisory authority.
9.3 Documentation
Provider makes available to Customer the information necessary to demonstrate compliance with the obligations of Article 28 GDPR.
10. Personal data breaches
Provider notifies Customer of any Personal Data Breach affecting Personal Data without undue delay after becoming aware of it, and in any event within seventy-two (72) hours. Notice is given to the administrative contacts declared by Customer.
It describes, so far as the information is available:
- (a) the nature of the breach and, where possible, the categories and approximate number of Data Subjects and records concerned;
- (b) the likely consequences of the breach;
- (c) the measures taken or proposed to address it and mitigate its effects;
- (d) the contact point from which more information can be obtained.
Missing information is provided as it becomes available. Notification of a breach to the supervisory authority and to Data Subjects is Customer’s responsibility; Provider makes no notification on Customer’s behalf without its prior agreement, save where it is under its own legal obligation.
11. International transfers
11.1 Location
The Service’s primary data is hosted in France and in the European Union. Some Subprocessors are established outside the European Union, principally in the United States.
11.2 Standard Contractual Clauses
Where a transfer of Personal Data outside the European Economic Area is not covered by an adequacy decision, the Standard Contractual Clauses are incorporated into this DPA by reference and deemed executed between the Parties, as follows: module two (controller to processor) where Customer acts as controller, or module three (processor to processor) where it acts as processor; clause 7 (docking clause) applies; clause 9, option 2 applies with the thirty (30) day period set out in Section 8.3; clause 11 is adopted without an independent dispute resolution body; clause 17 designates French law; clause 18 designates the French courts. Annexes I and II to this DPA serve as Annexes I and II to the Standard Contractual Clauses.
11.3 United Kingdom and Switzerland
For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and supplements the Standard Contractual Clauses. For transfers subject to the Swiss Federal Act on Data Protection, references to the GDPR are read as references to that Act, the competent supervisory authority is the Federal Data Protection and Information Commissioner, and the term « Member State » does not exclude Switzerland.
11.4 Supplementary measures
Provider carries out a transfer impact assessment, implements supplementary measures where these are necessary, and informs Customer if it considers that it can no longer meet its obligations under the Standard Contractual Clauses.
12. Audit
12.1 Documentation
Provider makes available to Customer, on written request, documentation relating to its security measures, its certifications, and any independent audit reports, and responds to Customer’s security and compliance questionnaires within a reasonable period not exceeding thirty (30) days. Customer reviews that documentation first, before requesting any on-site audit.
12.2 On-site audit
Where that documentation is not sufficient to demonstrate compliance with this DPA, Customer may carry out an audit, itself or through an independent auditor bound by confidentiality and not a competitor of Provider. The audit is notified at least thirty (30) days in advance, takes place during business hours, does not disrupt Provider’s operations, does not extend to other customers’ data, and is limited to once in any twelve (12) month period. That limit does not apply where an audit is required by a supervisory authority or follows a confirmed Personal Data Breach.
12.3 Costs
The costs of the audit are borne by Customer, save for those incurred by Provider in remedying a material breach revealed by the audit.
13. Term, return, and deletion
13.1 Term
This DPA remains in force for as long as Provider processes Personal Data on Customer’s behalf, notwithstanding any provision of the Agreement to the contrary.
13.2 Return
Customer may, during the Subscription Term and for thirty (30) days after its end, export Personal Data using the functions of the Service, under Section 11.10 of the General Terms.
13.3 Deletion
After that period, or at any time on Customer’s written request, Provider deletes Personal Data from active systems within thirty (30) days. Encrypted backups are purged in accordance with their rotation cycle and in any event within ninety (90) days; until purged, they remain protected by the measures set out in Annex II and are restored only in the event of an incident.
13.4 Order of deletion
Deletion of raw data precedes deletion of the content the Service derived from it, for the reason set out in Section 10.3 of the Privacy Policy: deleting the derived content first would leave the next run free to write it back.
13.5 Retention required by law
Provider may retain Personal Data to the extent required by Union or Member State law, or for the establishment, exercise, or defense of legal claims; it then retains it solely within the limits of that purpose and applies to it the security measures of this DPA.
14. Liability
Each Party’s liability under this DPA is subject to the exclusions and liability caps of Section 6 of the General Terms, to the extent permitted by Data Protection Law. Nothing in this Section limits a Party’s liability to a Data Subject under Article 82 GDPR.
Customer shall indemnify Provider against the consequences of any claim arising from an instruction that does not comply with Data Protection Law, from the absence of a legal basis or of information to Data Subjects, or from the submission of Regulated Data to the Service.
15. Acceptance and contact
Acceptance of the General Terms constitutes acceptance of this DPA, with no further formality. A Customer that wishes to hold a counter-signed copy, or that must produce a signed DPA to its own controller, may request one at legal@cobalt-ia.com, stating its corporate name and the name of the signatory.
Any question about this DPA, about the exercise of Data Subject rights, or about the security of the processing may be addressed to legal@cobalt-ia.com, or by post to SKILLFORGE APP, Legal Department, 2 Rue des Commères, 78310 Coignières, France.
Annex I — Description of the processing
A. Parties
Data exporter: Customer, acting as controller or, where applicable, as processor, whose identity and contact details are set out in the Order Form. Contact: the administrator declared in the Service.
Data importer: SKILLFORGE APP, 2 Rue des Commères, 78310 Coignières, France, acting as processor or subprocessor. Contact: legal@cobalt-ia.com.
B. Categories of Data Subjects
- Customer’s Authorized Users;
- employees, contractors, and other participants in the conversations of connected workspaces, including people who do not themselves use the Service;
- participants in the meetings Customer has Balt join;
- people whose data is held in the Connected Platforms Customer gives the Service access to, including its candidates, prospects, customers, and suppliers;
- any other person whose data is submitted to the Service by or on behalf of Customer.
C. Categories of Personal Data
- identification and contact data: name, email address, platform identifier, display name, job title, organization;
- conversation content: message text, files and documents submitted, timestamps, and threads;
- derived content: workspace memory, skill documents, and private notes produced by the Service;
- meeting recordings and transcripts, where that feature is used;
- content retrieved from Connected Platforms, according to the permissions granted;
- technical data: event log, access and execution logs, IP addresses, timestamps.
D. Sensitive data
The Service is not intended for the processing of special categories of data within the meaning of Articles 9 and 10 GDPR, whose submission is prohibited by Section 3 of the Acceptable Use Policy. Such data may nevertheless appear incidentally in conversation content, which is not filtered at ingestion; it then benefits from the measures of Annex II, without the Service applying any specific safeguard to it.
E. Frequency of the transfer
Continuous, throughout the provision of the Service.
F. Nature and purpose of the processing
Collection, recording, organization, structuring, storage, consultation, use, disclosure by transmission, alignment, restriction, erasure, and destruction, for the purpose of providing the Service described in Section 4.2: execution of AI-driven tasks and workflows, generation of Outputs, exchanges with Connected Platforms, support, security, and continuity.
G. Retention period
For the duration of the workspace connection and of the Subscription Term, then in accordance with Section 13 and the periods set out in Section 9 of the Privacy Policy.
H. Subprocessors
Subject matter, nature, and duration of the processing as described in Annex III.
I. Competent supervisory authority
The Commission nationale de l’informatique et des libertés (CNIL), the supervisory authority of Provider’s establishment, or the authority competent by reference to the data exporter’s establishment where the Standard Contractual Clauses so provide.
Annex II — Technical and organizational measures
The measures below supplement Section 6 of the Product Terms. They are reviewed periodically and may evolve, without diminishing the overall level of security.
- Encryption: data encrypted in transit with TLS 1.3 and encrypted at rest. Integration credentials are sealed with envelope encryption, the master key never leaving the hosting provider’s key management service;
- Access control: strong authentication, least privilege, environment separation, periodic review of entitlements, and removal of access when a staff member leaves;
- Customer separation: every request on the data plane carries the key of the workspace concerned, and the scope clause is written in one place in the code rather than repeated per entry point;
- Minimized transmission: queue messages and orchestration signals carry identifiers only; message content stays in the database and reaches neither the orchestrator nor the observability providers;
- Hosting: infrastructure located in France and in the European Union. Provider holds no ISO/IEC 27001 certification and no SOC 2 report, as stated in Section 6.1 of the Product Terms;
- Logging and monitoring: production system logging, continuous monitoring, anomaly detection, and retention of logs for investigation;
- Continuity: regular encrypted backups, operated by the hosting provider;
- Development: code review, automated testing, dependency management, and traceable, reversible deployments;
- Personnel: confidentiality undertakings, awareness, and data protection training;
- Subprocessors: prior assessment and equivalent contractual undertakings, on the terms of Section 8;
- Deletion: the by-person and by-block deletion procedures described in Section 10 of the Privacy Policy.
Annex III — Authorized subprocessors
The list of authorized Subprocessors, stating for each what it receives and for what purpose, is set out in Section 7 of the Privacy Policy.
It is not reproduced here: a second copy of a list that changes is a list that ends up contradicting the first, and it is Customer who would find the contradiction. The Privacy Policy carries a version number and an effective date, and any change to the list is notified on the terms of Section 8.3.
The other documents of the agreement
- Definitions : The defined terms used across the Balt contractual documents.
- General Terms : The core contractual terms governing access to and use of the Balt service.
- Acceptable Use Policy : The rules for acceptable and prohibited use of the Balt service, and prohibited data.
- Product Terms : Service description, AI functionality, autonomous actions, connected platforms and security.
- Usage Terms : How Credits, allocations, top-ups and accounts work.
- License Terms : The license granted to use the Balt service, and its restrictions.
- Privacy Policy : The data the Service processes, who else sees it, how long it is kept and how it is deleted.
- Legal Notice : The website publisher, its publication director and its hosting providers.
To request a counter-signed copy or ask a question, write to: legal@cobalt-ia.com
