Squadra PlanningSquadra
NoticeThis document is legally binding only in its French version. A courtesy translation is not provided; please refer to the French text below or contact us for clarification.

Document légal

Data Processing Agreement (DPA)

Version 1.1 · in force since April 18, 2026

Annex to the Terms of Service, entered into under article 28 of Regulation (EU) 2016/679 (GDPR).

This is an English translation provided for convenience. The French version remains the legally binding one, and prevails in the event of any discrepancy. You can read it at squadraplanning.com/fr/legal/dpa.

1. Purpose

This Data Processing Agreement (the « DPA ») governs the processing of personal data carried out by LE PETIT LUNETIER (the « Processor »), publisher of the Squadra Planning service, on behalf of the Customer (the « Controller ») in performing the Terms of Service.

In the event of a conflict between this DPA and the Terms on data protection matters only, this DPA prevails.

2. Roles of the parties

The Customer acts as controller within the meaning of article 4(7) of the GDPR. It alone determines the purposes and means of processing the personal data handled through the Service, in particular the data of its employees and users.

Squadra Planning acts as processor within the meaning of article 4(8) of the GDPR. It processes data solely on behalf of, and on the documented instructions of, the Controller.

3. Nature, purposes and duration of processing

Purposes: providing the features of the Service (scheduling, time tracking, working time management, payroll calculation, accounting export, absence management, meal vouchers, third-party integrations).

Nature of the operations: collection, recording, organisation, structuring, storage, consultation, alteration, retrieval, disclosure by transmission, erasure.

Duration: for the entire term of the contract, and in accordance with article 10 of this DPA.

4. Categories of data and of data subjects

Categories of data subjects: the Customer's employees, directors, managers and users, and anyone recorded in the time tracking or scheduling tools.

Categories of data processed:

  • Identification data: last name, first name, work email, PIN code, photograph where applicable.
  • Employment data: job title, contract (weekly hours, type), assigned location, application role.
  • Time tracking data: clock-in and clock-out times, geolocation at clock-in (if enabled), verification photo (if enabled).
  • Scheduling data: schedules, leave, absences, reasons.
  • Technical data: connection logs, IP addresses, session identifier, user agent (for security and audit purposes).

The Service is not designed to process special categories of data within the meaning of article 9 of the GDPR (health data, racial or ethnic origin, political opinions, and so on). The Customer undertakes not to enter any.

5. Processor obligations

In accordance with article 28 of the GDPR, the Processor undertakes to:

  • process the data solely on the Controller's documented instructions, unless required otherwise by law;
  • ensure that persons authorised to process the data are bound by an obligation of confidentiality;
  • implement the technical and organisational measures described in article 8;
  • assist the Controller in responding to requests from data subjects exercising their rights (articles 12 to 23 of the GDPR);
  • help the Controller comply with its obligations on security, breach notification and impact assessment (articles 32 to 36 of the GDPR);
  • notify any personal data breach as soon as possible and at the latest 72 hours after becoming aware of it;
  • make available all information necessary to demonstrate compliance and, where applicable, allow audits to be carried out.

6. Controller obligations

The Customer undertakes to:

  • transmit to the Processor only the data necessary to perform the Service (data minimisation);
  • have a valid legal basis for the processing (performance of the employment contract, legitimate interest, consent, and so on);
  • inform its Users, in particular its employees, that their data is processed through the Service, in accordance with articles 13 and 14 of the GDPR;
  • consult its employee representative bodies where applicable (in France, the comité social et économique) before introducing biometric or geolocated time tracking;
  • enter no special category of data within the meaning of article 9 of the GDPR.

7. Sub-processors

The Customer authorises the Processor to use the following sub-processors:

  • Supabase Inc. (database hosting and authentication), EU servers.
  • Vercel Inc. (application hosting and CDN), EU regions (fra1) preferred.
  • Stripe Payments Europe Ltd. (subscription payments), registered office in Dublin, Ireland.
  • Resend (Drift.com, Inc.) (transactional email delivery).
  • Google LLC (anonymised audience measurement, Google Analytics 4), IP addresses anonymised.

Any change to this list is notified to the Customer, who then has 30 days to object. If the Customer objects and no alternative is offered, it may terminate the contract at no cost.

The Processor imposes on its sub-processors the same data protection obligations as those set out in this DPA.

8. Technical and organisational measures

The Processor implements in particular:

  • encryption of data in transit (TLS 1.2+) and at rest (AES-256);
  • multi-tenant separation at database level (PostgreSQL row level security plus an org_id filter);
  • strong authentication (password of at least 8 characters, hashed with bcrypt);
  • granular role management (ADMIN, HR, MANAGER, EMPLOYEE, and others);
  • logging of sensitive events (audit_logs);
  • automatic daily database backups;
  • a password policy and administrative access managed through MFA;
  • a documented procedure for handling data breaches.

9. Transfers outside the EU

Data is hosted principally within the European Union. Some sub-processors (Stripe, Google, Resend, Vercel) may, in limited cases, transfer data to the United States; where they do, those transfers are governed by the European Commission's Standard Contractual Clauses (decision 2021/914) and/or the Data Privacy Framework.

10. Return and deletion of data

On expiry of the contract, whatever the cause, the Processor makes an export of the data available to the Controller for 30 days. After that period, the data is permanently erased from production systems within a maximum of 30 days, then from backups within a maximum of 90 days, unless a legal retention obligation applies.

11. Audit

The Controller may request, at its own expense and with 30 working days' written notice, the documents evidencing the Processor's compliance (security policies, audit reports). A confidentiality undertaking may be required beforehand. On-site audits are excluded unless a compelling regulatory obligation applies.

12. Liability

The Processor's liability under this DPA is subject to the same caps as those set out in article 14 of the Terms, excluding indirect damage.

13. Contact

For any question about data processing: contact@squadraplanning.com.

This DPA forms an inseparable annex to the Terms of Service. Signing it, or accepting it electronically, constitutes acceptance by the Customer within the meaning of article 28 of the GDPR.