Data Processing Agreement

Effective: February 12, 2026

Chaman Ventures, SAS au capital de 100 €

RCS Paris 989 498 902 — TVA FR92989498902

229 Rue Saint-Honoré, 75001 Paris, France

1. Roles

You (the Customer) are the data Controller. Chaman Ventures, SAS, registered at 229 Rue Saint-Honoré, 75001 Paris, France (RCS Paris 989 498 902, TVA FR92989498902) acts as the data Processor. Where you connect third-party integrations, those providers act as sub-processors under this agreement.

2. Scope of processing

We process personal data solely to provide the ContractSpec Studio service: evidence ingestion, correlation, impact analysis, artifact generation, work item export, and stakeholder notifications. Processing is performed on documented instructions from you.

3. Data residency

Primary database resides in the EU (eu-west-1) via Supabase. Analytics data is processed in the EU via PostHog. LLM inference may route through US-based providers; EU-only inference is available via Mistral AI. Enterprise plans support single-tenant or on-premises deployment for full data sovereignty.

4. Security measures

OAuth tokens encrypted at rest (AES-256). PII automatically redacted at evidence ingestion. Role-based access control with organization-level permissions. Full audit trail on every operation. SOC 2 Type I in progress. Penetration test results available under NDA.

5. Breach notification

We will notify you of a confirmed personal data breach within 72 hours of becoming aware. Notification includes: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

6. Data retention and deletion

Retention is configurable per workspace (30 days to 12 months). Data is hard-deleted on schedule with no recovery. On-demand purge is available at any time. On contract termination, all data is deleted within the configured retention window.

7. Audit rights

You may request information necessary to demonstrate compliance with this agreement. We respond to audit and security review requests within 48 hours. SOC 2 Type I report is available under NDA. We support third-party audits at your expense with reasonable advance notice.

8. International transfers

Where data is transferred outside the EEA (e.g., to US-based LLM providers), transfers are governed by Standard Contractual Clauses (SCCs) as adopted by the European Commission. You may restrict processing to EU-only providers via workspace settings.

9. Sub-processor changes

We maintain the sub-processor list below. We will notify you at least 30 days before adding a new platform-level sub-processor. You may object to a new sub-processor by contacting us within that period.

Platform-level sub-processors

Active for all customers as part of normal operations.

ProviderPurposeData processedRegion
VercelHosting, serverless functionsHTTP requests, page viewsConfigurable
SupabaseManaged PostgreSQL databaseAll persistent application dataEU (eu-west-1)
PostHogProduct analytics, feature flagsUser behavior events, feature flag evaluationsEU
StripePayment processing, subscriptionsCustomer PII (name, email), payment methodsGlobal
OpenAILLM inference, embeddingsUser content processed through analysis pipelinesUS
AnthropicLLM inferenceUser content processed through analysis pipelinesUS
Mistral AILLM inference, embeddingsUser content processed through analysis and embeddingEU (France)
GroqFast LLM inferenceMeeting transcripts for evidence extractionUS
GoogleOAuth, Drive, Gmail, Calendar APIsUser identity, authorized file access, emailGlobal
ResendTransactional emailRecipient emails, email contentUS
ScalewayMessage queues, transactional emailApplication events, email deliveryEU (Paris)
TelnyxSMS messagingPhone numbers, message contentUS
fal.aiAI image generationText prompts derived from user contentUS
GradiumText-to-speech synthesisText scripts converted to audioEU / US
DeepLText translationText submitted for translationEU (Germany)
Jina AIWeb content extractionURLs for content retrieval (no direct PII)EU (Germany)
LinearWork item exportExported work items and task descriptionsUS

User-configurable sub-processors

Only active when explicitly connected by you through integrations settings.

ProviderPurposeData processed when connected
SlackThread import, brief postingMessages, thread content
GitHubCodebase analysis, PR ingestionRepository content, pull request data
JiraIssue exportWork items, project data
NotionDocument exportDocument content, wiki pages
ZendeskSupport ticket ingestionTicket content, customer interactions
LinkedInPost import, engagement dataOrganization posts, engagement metrics
Microsoft OneDriveFile importDocument content
Google DriveFile importDocument content
Granola / tl;dv / Fireflies.ai / FathomMeeting notes and transcript importMeeting transcripts, highlights
Twilio / PostmarkSMS and email deliveryPhone numbers, email addresses, message content
ElevenLabsVoice synthesisText scripts
QdrantVector similarity searchEmbedded content vectors
PowensOpen banking aggregationFinancial transaction data
Google CalendarCalendar event accessCalendar events, scheduling data