Data Processing Agreement (DPA)

Framework for processing personal data on behalf of PartnAir's distributor customers.

Zuletzt aktualisiert · 16. Juli 2026

Dieses Dokument wird auf Englisch bereitgestellt. Die französische Fassung ist maßgeblich.

This Data Processing Agreement ("DPA") supplements the Terms of Sale and governs, in accordance with Article 28 GDPR, the processing of personal data carried out by TBF (the "Processor") on behalf of the contracting Customer, exclusively an automotive parts distributor, wholesaler, distribution group or aftermarket buying centre (the "Controller"). Partner Workshops are beneficiary Users equipped by that Customer and are not parties to this DPA. In the event of conflict, this DPA prevails over the ToS on data protection matters.

1. Purpose and duration

The Processor processes personal data on behalf of the Controller solely to provide the PartnAir Service to the Customer and Users at its Partner Workshops. Processing lasts for the duration of the subscription contract entered into with the Customer, until deletion or return of the data.

2. Nature, purpose and categories

ItemDescription
PurposeProvision of the Service: request capture, parts identification, quotes, orders, messaging, tracking
Nature of processingCollection, recording, hosting, structuring, consultation, transmission to the distributor Customer and authorised Users at its Partner Workshops, deletion
Categories of individualsEnd customers of Partner Workshops equipped by the Customer, staff of the Customer and those workshops, contacts
Categories of dataIdentity and contact details, vehicle and registration data, requests and messages, parts photos, exchange history
Sensitive dataNo sensitive data is required by the Service

3. Processor obligations

  • Process data only on documented instructions from the Controller, including for transfers outside the EU, unless legally required.
  • Ensure the confidentiality of the data and that authorised persons commit to confidentiality.
  • Implement appropriate technical and organisational measures (Article 32 GDPR) described in §6.
  • Assist the Controller in responding to data subjects' rights requests.
  • Assist the Controller with its security, breach notification and impact assessment obligations (Articles 32 to 36).
  • Not train any third-party AI model on the Controller's data: processing is limited to the inference necessary for the Service.

4. Sub-processors

The Controller authorises the use of the sub-processors listed below. The Processor imposes on them, by contract, obligations equivalent to this DPA and remains responsible for their performance. Any change to the list is subject to prior information, allowing the Controller to raise legitimate objections.

Sub-processorPurposeLocationSafeguard
Vercel Inc.Website and web application hostingUnited States / EU (edge)EU Standard Contractual Clauses
Supabase Inc.Database, authentication, file storageEuropean Union (Frankfurt)Hosted within the European Union
OpenRouter, Inc.Routing of requests to AI models (inference)United StatesEU Standard Contractual Clauses
Google (Gemini API)Generative and vision AI models (parts photo analysis)European Union / United StatesEU Standard Contractual Clauses
Resend, Inc.Transactional email deliveryUnited StatesEU Standard Contractual Clauses
Stripe Payments Europe, Ltd.Subscription payment processingEuropean Union (Ireland)Hosted within the European Union

5. Transfers outside the European Union

Where processing involves a transfer of data outside the European Union, it is governed by appropriate safeguards, in particular the Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional measures.

6. Security measures

  • Encryption of data in transit (TLS) and at rest.
  • Logical isolation of data per distributor Customer (PostgreSQL Row Level Security), with limited rights for Partner Workshop Users.
  • Named access control, authentication, least-privilege principle.
  • Logging of access and security events, monitoring.
  • Regular backups and a restoration plan.
  • Vulnerability and patch management.

7. Breach notification

The Processor notifies the Controller of any personal data breach without undue delay after becoming aware of it, with the information needed to enable notification to the CNIL within 72 hours where applicable. Contact: security@partn-air.com.

8. Fate of data at end of contract

At the end of the contract, the Processor returns the data in a structured format then deletes or anonymises it within 30 days, subject to legal retention obligations, and deletes existing copies.

9. Audit

The Processor makes available to the Controller the information needed to demonstrate compliance and allows for audits, under reasonable conditions agreed between the parties (notice, confidentiality, frequency).