Data processing agreement
Read this first
This document is not legal advice. It was written by the team that writes the product, from what the code actually does, and it must be reviewed by a lawyer before any payment is taken.
It is published anyway because a verified, provisional text is worth more than a contract template describing some other product.
Last updated: 25 September 2026.
Who is bound, and by what
This agreement is entered into between the organisation that puts data into Jalon, as controller, and Joffrey Herard, Sole proprietor (French “micro-entreprise”), publisher of the service and processor. The registration number, registered address and contact address appear in the legal notice.
It is not signed case by case: it is formed by the reference the terms of use make to it, and it is accepted together with them, at the moment an account is created. Whoever creates the organisation accepts it on the organisation’s behalf and states that they have authority to bind it. The text is published at /en/data-processing.
Proof of that acceptance is the version of the terms recorded with the account, and the date on which it was recorded. This agreement carries the same version number as those terms: an acceptance therefore cannot point to one without the other.
If your organisation requires a signed document
Article 28.9 of the GDPR allows electronic form, and that is the form used here: this text is a written contract. An organisation whose internal compliance nonetheless requires a signature may ask for one at the contact address in the legal notice.
Accounts created before 18 September 2026
They accepted a version of the terms of use that did not refer to this agreement: it is therefore not enforceable against them until they have accepted the version in force. A re-acceptance flow remains to be built, and is tracked as such.
An acceptance carried by the organisation itself, distinct from the person’s, also remains to be built: the terms of use bind the person, this agreement binds the organisation, and those are two distinct bearers.
Subject matter, nature, purpose and duration
Subject matter: hosting and running Jalon, a browser-based roadmap tool, on behalf of the organisation. Nature of the operations: collection, recording, organisation, storage, consultation, alteration, retrieval and erasure — the ones a project tracking tool performs in order to display and keep what is written in it.
Purpose: to let the organisation and its members plan and track their work. The publisher does not use the entrusted data for its own account, for commercial or advertising purposes, or to train a model of any kind.
Duration
The agreement takes effect when the organisation is created and lasts as long as the organisation exists. It ends with it, whether the organisation is deleted from the Organisation page or carried away by the deletion of the account that solely owns it.
The data entrusted and the people concerned
Categories of data
The organisation’s working data: lanes, milestones, tasks and their descriptions, due dates, labels, board columns, links between tasks, snapshots. People records, which carry a name and, where applicable, an email address. The members of the organisation and their role. And, if the organisation connects a forge, what Jalon copies from it: projects, issues and their labels, merge requests, deployments and environments.
Categories of people concerned
Members of the organisation, who have an account here and know what they are doing with it. And people described by a record without having an account: someone may be named there by a colleague without ever knowing, and without the publisher having any way to reach them.
Jalon is not built for special category data within the meaning of article 9 of the GDPR, nor for data on criminal convictions and offences. The terms of use forbid putting any there, and no measure specific to those categories is in place: the prohibition is the measure.
The organisation’s instructions
The publisher processes the entrusted data only on documented instructions from the organisation. Those instructions are first of all the acts the organisation performs in the tool itself: what it writes there, what it deletes, the members it invites and the roles it gives them, the forge it connects, the export it asks for. Any other instruction is sent in writing to the contact address in the legal notice.
The publisher informs the organisation if it considers an instruction to infringe the GDPR, and may refuse to carry it out.
The publisher accesses the entrusted data to operate and troubleshoot the service, and for nothing else. That access is not logged for the organisation’s benefit: the audit log records the acts of members, not those of the publisher. The point is written down rather than left unsaid.
Outside the European Union
The core of the service does not leave the Union: the application, the database and the backups sit on a server located in France and administered by the publisher, and outgoing mail leaves through OVH, a company established in the Union.
Two acts by the organisation, and only two, can take data outside the Union: connecting an account on gitlab.com or github.com, both run by American companies — an instance the organisation hosts itself sends nothing anywhere but to itself —, and subscribing to the paid plan, which passes Stripe the data described below. An organisation that does neither sees no data leave the Union.
The safeguards covering those transfers
Transfers to GitLab Inc., GitHub, Inc. and Stripe, LLC rely first on the EU–US Data Privacy Framework, an adequacy decision under article 45 of the GDPR to which all three companies state that they adhere, and, for anything it would not cover, on the European Commission’s standard contractual clauses provided for in their documents, a safeguard under article 46. The entities, locations, clauses and official evidence were reviewed by the publisher on 20 September 2026; the organisation obtains a copy on simple request to the contact address in the legal notice.
Confidentiality of authorised persons
The persons authorised to process the entrusted data undertake to keep it confidential, and remain bound by that undertaking after the agreement ends.
Precision matters here more than reassurance: the publisher is a sole proprietorship, and that authorised person is one and the same person, named in the legal notice. There is no operations team, no managed-services provider, no on-call duty handed to a third party. The undertaking is therefore theirs, and there is no one else to extend it to.
The security measures
The measures below answer article 32 of the GDPR. They are the ones actually in place, read back in the code that applies them, and not a list of intentions.
What is in place
Passwords are never kept in clear text: only an Argon2 hash is, and it does not allow them to be recovered. The connected forge’s token is encrypted at rest with ChaCha20Poly1305, the key being held outside the database; only its last four characters are kept in clear, so the screen can say which one is set without ever showing it in full again.
Exchanges with the service go over HTTPS. The session cookie carries nothing but a session identifier, it is HttpOnly — the page’s JavaScript cannot read it —, SameSite=Lax and Secure, and it expires after thirty days. The public authentication and invitation routes are rate-limited per address; the counter is kept in the database and erased at the latest three hours after the last counted call.
Isolation between organisations is checked on every request, and the four roles bound what a member may read and write. Neither the public pages nor the signed-in application load any resource from another domain: nothing on screen calls out to a third party.
A backup of the database is taken every night, verified by a real restore into a throwaway database — a backup that has never been restored is not a backup —, and kept thirty days on rotation on the server. It is also replicated to a second machine administered by the publisher, where it is kept ninety days: losing the server no longer takes the backups with it.
What is not, and what an organisation should know before choosing
The copies replicated to the second machine are stored there without encryption at rest: theft of that machine or of its disks would expose their contents. That is the most serious limit of the arrangement, and it is stated rather than left unsaid.
The service runs as a single instance: there is no redundancy, no automatic failover and no service level commitment, and every deployment restarts it. The terms of use already say so, and this agreement promises nothing better.
Sub-processors
The organisation authorises the publisher to use the sub-processors named below, and only those. Two of the three are called upon only if the organisation itself performs the act that brings them in. Hosting is not one of them: the publisher administers the server itself, and no cloud provider has access to the database.
The publisher imposes on each of them, through the contract binding them to it, data protection obligations equivalent to those of this agreement, and remains liable to the organisation for their failures as for its own.
OVH — outgoing mail
Transactional emails leave through an OVH mailbox, over STARTTLS. OVH therefore sees the recipient’s address and the content of the message: password reset, invitation, task assignment, daily report and weekly report. A company established in the European Union.
Stripe — payment, if the organisation subscribes
An organisation that subscribes to the paid plan passes Stripe what is needed to keep track of its subscription: its customer and subscription identifiers, its plan, its status and the end of the current period. The name, billing address and card details are entered at Stripe, on a page Stripe hosts: no card data passes through Jalon. Stripe belongs to a group whose parent company is American.
GitLab or GitHub — only if the organisation connects to one
An organisation that sets up a forge connection — to GitLab, to GitHub or to both, one connection per forge — entrusts each connected forge with an access token and the calls Jalon makes to it. If that forge is gitlab.com or github.com, it is run by an American company; if it is an instance the organisation hosts itself, nothing goes anywhere but to the organisation. Jalon reads from each connected forge and writes nothing to it.
Changing this list
Any addition or replacement of a sub-processor is published on this page and brings a new version of this agreement, and therefore of the terms of use. Like any substantial change to those terms, it is announced in the application before it takes effect, which gives an organisation that refuses it time to export its data and delete its organisation.
The assistance owed to the organisation
People’s rights
The publisher assists the organisation in responding to requests to exercise data subject rights. For the most part that assistance is already in the tool: the owner exports the working data as JSON from the Organisation page, everyone corrects their display name and language from the Account page, and a people record is edited or deleted by whoever holds the role to do it.
Anything the screens do not cover is handled on written request to the contact address in the legal notice, within a time frame that leaves the organisation enough to meet the one the GDPR imposes on it towards the person.
Informing people who have no account
A people record may describe someone who has no account and does not know the record exists. The information owed under article 14 of the GDPR falls to the organisation, and to it alone: it is the only one who knows these people and can reach them. The publisher has neither the means nor the standing to do it in its place, and does not undertake to.
Impact assessments
The publisher provides, on written request, the technical material needed for a data protection impact assessment or a prior consultation of the supervisory authority. The measures in place and their limits are described above, and this page is meant to be quoted as it stands.
In the event of a data breach
The publisher notifies the organisation of any personal data breach concerning it within forty-eight hours of becoming aware of it.
Forty-eight hours, and not the “undue delay” the GDPR leaves the processor: it is the organisation that must notify the supervisory authority within seventy-two hours, and an unquantified delay would put it at fault with nothing to hold against the publisher. The figure is here so that the organisation can rely on it.
The notification goes to the email address of the organisation’s owner. It describes the nature of the breach, the categories and approximate number of people and records concerned, the likely consequences and the measures taken or proposed. Whatever is not established at the time of notification is communicated as it comes, without waiting to know everything.
What the publisher must demonstrate
The publisher makes available to the organisation the information needed to demonstrate compliance with the obligations of this agreement, and allows for audits, including inspections, by the organisation or an auditor it mandates.
In practice: a written request to the contact address in the legal notice, reasonable notice, one audit a year absent a security incident, and an auditor bound to confidentiality. Costs incurred by the publisher are borne by the organisation, unless the audit reveals a failure on the publisher’s part.
What is already public
Part of what an audit would look for is published and need not be asked for: the security measures and their limits above, the processing operations, the recipients and the retention periods on the privacy page, the publisher’s identity and the hosting arrangements in the legal notice.
When the agreement ends
Before leaving, the owner exports the working data as JSON from the Organisation page: the organisation, its members and their role, the lanes, the milestones, the tasks, the people records, the label catalogue and the board columns. Snapshots and the organisation’s time zone are not included — better to know that before deleting than after.
Deleting the organisation erases the entrusted data, immediately and with no recycle bin. The publisher keeps no working copy of it.
One exception, stated rather than left unsaid: the backups taken before the deletion still contain that data, and disappear on rotation within thirty days. They are restored only in the event of a failure, never to reconstruct a deleted organisation.
Liability
Each party is liable for damage caused by processing where it has failed to comply with the obligations of the regulation that fall on it, under the conditions of its article 82.
No liability cap is stipulated: that is a clause to be negotiated, and the publisher would rather write none than copy one from a template. The cap set by the terms of use does not apply to this agreement, and they say so.
Changes to this agreement, and governing law
This agreement lives in the product’s repository and changes with it. It carries the same version number as the terms of use it is an annex to: changing it changes them, and a substantial change is announced in the application before it takes effect.
French law applies. This agreement governs only processing within the meaning of article 28 of the GDPR; whatever else binds the organisation and the publisher falls under the terms of use and, where applicable, the terms of sale.