Data processing agreement
This page describes matters to cover in a data processing agreement under Article 28 GDPR. It is not a signed DPA. The applicable agreement must identify the parties, processing, safeguards and providers before customer personal data is used.
Last updated · September 12, 2026
1. Request and formalisation
Contact contact@prosio.be with the company name, registration number, signatory and features to enable. The DPA and its schedules must be agreed with the customer. This page does not attest to a signature deadline or an already signed document.
2. Parties
Intended processor: Salama Forever SRL (Prosio brand), rue du Bon Pasteur 54/1, 1140 Evere, company number BE 0711.688.802. The customer controller and its signatory must be identified in the agreement. The DPA only forms part of the contract once agreed by the parties.
3. Definitions
The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" are understood within the meaning of Article 4 of the GDPR.
4. Scope
The DPA covers processing by Prosio for the Customer within enabled functions: storing business data, following up actions and appointments, logging and, where the relevant services are configured, assisted message preparation and delivery through the business workflow. Linking Microsoft OAuth does not by itself connect CRM delivery to Microsoft Graph.
The categories of processed data and data subjects are described in the DPA annex.
5. Duration
The DPA takes effect on the date of signature and remains in force for the entire duration of execution of the main contract. The obligations relating to confidentiality and to the return / deletion of data survive the end of the contract to the extent necessary for their performance.
6. Processor's obligations
Prosio undertakes in particular:
— to process the data only for the purposes provided for in the DPA and in accordance with the Customer's documented instructions ; — to inform the Customer without delay if an instruction appears to it to constitute a violation of the GDPR or applicable law ; — to impose confidentiality on any person having access to the data ; — to implement the technical and organisational measures described on the Security page ; — to assist the Customer in responding to requests by data subjects to exercise their rights ; — to assist the Customer in conducting data protection impact assessments (DPIAs) where required.
7. Controller's obligations
The Customer warrants that it has a valid legal basis within the meaning of Article 6 of the GDPR for the processing entrusted to Prosio, that it has fulfilled its information obligations to the data subjects, and that it transmits to Prosio documented instructions compliant with the GDPR.
8. Documented instructions
The Customer's instructions are constituted by: the main contract, the DPA and its annexes, the parameters defined in the application by the Customer's administrators, and any subsequent written instruction addressed to contact@prosio.be.
Prosio does not carry out any processing beyond these documented instructions.
9. Confidentiality
The DPA must address confidentiality, restricted access and instructions for authorized personnel. Organizational measures actually applied must be documented with the service operator.
10. Security measures (Article 32 GDPR)
Application protections include AES-256-GCM encryption of OAuth tokens and access controls by role and scope, alongside database rules. The Security page distinguishes protections provided by the code from those depending on configured providers.
The operational measures actually applicable — backups, stronger authentication, logging and security checks — must be documented in the DPA annexes. This technical description does not attest to a retention period, audit frequency or service level.
11. Subsequent sub-processors
The DPA must identify enabled providers, their role, processing regions and transfer safeguards. It must specify authorization of subprocessors, advance information about changes and an opportunity to object. An integration in the code does not prove that a provider is already enabled for the customer.
12. Data subjects' rights
Prosio assists the Customer, insofar as possible and taking into account the nature of the processing, in responding to requests to exercise the rights referred to in Articles 15 to 22 of the GDPR.
When a data subject addresses Prosio directly, their request is transmitted to the Customer without delay, except in case of contrary written instruction from the Customer.
13. Notification of data breaches
The processor must notify the controller of a personal data breach without undue delay after becoming aware of it. The 72-hour period in Article 33 concerns the controller’s notification to the authority where required; it is not a waiting period for the processor. Alert channels, contacts and assistance must be defined in the DPA.
14. Audit rights
The DPA must provide access to information needed to verify processor obligations and permit required audits, with proportionate practical arrangements. This page does not claim that an ISO 27001, SOC 2 or independent Prosio audit report is available.
15. Return and deletion
The DPA must provide for return or deletion at the customer’s choice at the end of the service, subject to legal obligations. Scope, format, achievable deadlines and copies held by providers and in backups must be documented. This page does not attest to automatic deletion after 30 or 90 days.
16. International transfers
Prosio undertakes not to carry out any transfer of data to a third country outside the European Economic Area without an appropriate safeguard within the meaning of Chapter V of the GDPR (adequacy decision, standard contractual clauses signed with the subsequent sub-processor, additional technical measures where necessary).
The mapping of transfers is kept up to date and communicated to the Customer upon reasoned request.