1. Parties and scope
This Data Processing Agreement ("DPA") is part of the Rokn Terms of Service. It applies between the customer who holds a Rokn workspace (the "Customer", acting as controller) and [FULL NAME], individual entrepreneur registered in France, SIREN [SIREN], [ADDRESS], operating Rokn ("Rokn", acting as processor). It meets the requirements of Article 28 of the GDPR and takes effect when the Customer accepts the Terms of Service.
2. Details of the processing
- Subject matter: hosting and processing the data the Customer puts into its Rokn workspace, to provide the Service.
- Duration: for as long as the Customer uses the Service, and then until deletion as described in section 9.
- Nature and purpose: storage, organisation, retrieval, display, transmission and deletion of data, to provide the features the Customer uses: client and project management, time tracking, invoicing, quotes, payments through the Customer's own gateway, documents and contracts with e-signature, support tickets and inbound email, email sending, campaigns, file storage, the API and the AI assistant.
- Categories of data subjects: the Customer's clients and their contacts, prospects (leads), the Customer's team members, recipients of the Customer's emails and campaigns, and people who sign documents or contact the Customer's support.
- Categories of personal data: identification and contact data (names, email addresses, phone numbers, postal addresses), professional data (company, role, VAT number), financial and transaction data (invoices, quotes, payments, rates), communication content (emails, tickets, messages, documents and files), e-signature evidence (name, email, timestamp, an IP address shortened to a network prefix), and any other data the Customer chooses to store.
- Special categories: the Service is not designed for special categories of data (Article 9 GDPR). The Customer should not store them in Rokn.
3. Customer's instructions
Rokn processes the personal data only on the Customer's documented instructions. These consist of the Terms of Service, this DPA, and the Customer's use and configuration of the Service. Rokn does not process it for any other purpose, unless EU or French law requires it; in that case Rokn informs the Customer first, unless that law forbids it. Rokn tells the Customer if it believes an instruction infringes data-protection law.
The Customer is responsible for having a lawful basis for the data it puts in the Service, and for informing its own data subjects.
4. Confidentiality
Anyone authorised by Rokn to process the personal data is bound by confidentiality, and has access only to the extent needed to provide, secure or support the Service.
5. Security
Rokn implements the technical and organisational measures in the annex, which are appropriate to the risk (Article 32 GDPR). Rokn may improve these measures over time, but will not reduce the overall level of protection.
6. Sub-processors
The Customer gives Rokn general authorisation to use the sub-processors listed in the annex. Rokn will inform workspace owners at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data-protection grounds. If no solution is found, the Customer may terminate the Service with a pro-rata refund of any prepaid period. Rokn imposes data-protection obligations on each sub-processor that are equivalent to this DPA, and remains responsible for its sub-processors.
Services the Customer connects itself (its own payment gateway, email provider, calendar, webhook destinations or API clients) are not Rokn's sub-processors. The Customer engages them directly.
7. International transfers
Where a sub-processor processes personal data outside the European Economic Area, the transfer is covered by the EU-US Data Privacy Framework where the recipient is certified, and otherwise by the European Commission's Standard Contractual Clauses.
8. Assistance
Taking into account the nature of the processing, Rokn assists the Customer:
- in answering data subjects' requests to exercise their rights. The Service lets the Customer view, edit, export and delete the data itself, and Rokn helps with anything the features do not cover;
- with security, personal data breach notification, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR), using the information available to Rokn.
Personal data breaches: Rokn notifies the Customer without undue delay, and at the latest within 48 hours of becoming aware of a breach affecting the Customer's data. The notice includes the information available to Rokn that the Customer needs to meet its own obligations.
9. Return and deletion
The Customer can export its workspace data at any time. When the Customer closes its workspace, the data remains recoverable for 30 days and is then permanently deleted, and it expires from backups within a further 30 days. The exception is data Rokn must keep by law, which is kept for the legally required period only.
10. Information and audits
Rokn makes available to the Customer the information needed to demonstrate compliance with this DPA, in the form of written answers to reasonable questions sent to privacy@rokn.dev. Where that is not sufficient, or a supervisory authority requires it, the Customer may carry out an audit at its own cost. It must give 30 days' notice, the audit happens at most once a year, and it must be conducted in a way that does not disrupt the Service or expose other customers' data.
11. Liability and precedence
The liability terms of the Terms of Service apply to this DPA, except where the GDPR provides otherwise. If this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.
Annex 1: Sub-processors
- Hetzner Online GmbH (Germany): servers and database, EU data centres.
- Cloudflare, Inc. (USA): network protection, content delivery, file storage (R2) and encrypted backups.
- Resend (USA): email delivery.
- Sentry (EU region): error monitoring, with personal data minimised.
- Anthropic PBC (USA) and OpenAI (USA): the AI assistant, only for conversations where it is used and the selected provider. Data is not used for model training.
- Google LLC (USA): only when a user connects Google Calendar or signs in with Google.
- GitHub, Inc. (USA): only when a user signs in with GitHub.
Annex 2: Security measures
- Encryption in transit (HTTPS/TLS) on every connection.
- Workspace isolation enforced in the database through row-level security. The application connects with a role that cannot bypass it.
- Secrets stored by the Customer, such as saved credentials and payment and email keys, are encrypted with AES-256-GCM under a per-workspace key.
- Role-based access control inside each workspace, and two-factor authentication available for every user.
- An audit log of security-relevant actions, retained according to the plan.
- Malware scanning of inbound email attachments before storage.
- Rate limiting and bot protection on public endpoints.
- Hourly database backups, stored encrypted and kept for up to 30 days, with restore tests.
- Access to production systems restricted to Rokn's operator, with strong authentication.