Data Processing Agreement (DPA)
Last updated: October 2026
1. Subject matter, nature and duration of processing
This Data Processing Agreement (DPA) is entered into pursuant to Article 28 of the GDPR between the Client (controller) and OmniRealm SASU (processor), which operates the WarDek service.
WarDek processes personal data on behalf of the Client solely for the purpose of providing the security and compliance audit service, and only on the Client's documented instructions. Creating an account and agreeing to the Terms of Service constitute the initial instruction.
Purposes
Running security scans, generating audit reports, managing accounts and billing
Nature of operations
Collection, recording, automated analysis, storage, disclosure to the Client and erasure
Duration
The entire subscription term, extended by the return and deletion periods (section 9)
Roles
Client = controller · OmniRealm SASU = processor
OmniRealm SASU does not process Client data for its own purposes. Data is never sold, nor used to train any artificial intelligence model.
2. Categories of data and data subjects
The categories of personal data processed are:
Scanned domains
URLs and domain names submitted for audit, at the Client's initiative
Scan results
Detected vulnerabilities, scores, reports and supporting evidence
User accounts
Email address, name, authentication credentials
Technical data
IP address, access logs, error diagnostic data
Support exchanges
Messages sent to support or to the conversation assistant
Billing data
Handled by Stripe — WarDek never stores card data
Data subjects: users of the WarDek service (the Client's staff) and, incidentally, individuals whose data appears publicly on a domain scanned at the Client's request.
No special categories of data (health, opinions, biometrics) are processed intentionally. The Client undertakes to submit for audit only domains it owns or for which it holds authorisation.
3. Retention periods
Data is retained for the following periods:
Scan results and audit reports
User profile data
Post-termination data (export available during this period)
Invoices and accounting records (statutory retention obligation)
Once these periods expire, data is irreversibly deleted or anonymised.
4. Confidentiality and authorised personnel
In accordance with Article 28(3)(b) of the GDPR, OmniRealm SASU ensures that persons authorised to process the Client's data are bound by a duty of confidentiality.
Who has access
Access is restricted to personnel authorised by OmniRealm SASU's management. Given the size of the company, authorised personnel is currently limited to the company director, who also acts as system administrator and therefore holds direct technical access to the production database — including scanned domains and audit results.
This disclosure is deliberate: administrator access necessarily exists in any hosted service. Clients are entitled to know who holds it.
Purposes for which that access may be exercised
- Support and incidents - diagnosing and fixing a reported or detected malfunction
- Client request - carrying out an export, a deletion or the exercise of a data subject right
- Maintenance - migration, backup and restore operations
- Legal obligation - responding to a lawful request from a competent authority
Any access outside these purposes is excluded. Client data is never accessed for commercial or marketing purposes, nor used to train an artificial intelligence model.
Under what commitment
- Duty of confidentiality arising from corporate office for the director, and a written contractual confidentiality clause for any future employee, intern or contractor granted access
- The commitment survives the end of the employment relationship or contract
- Authorisation is granted case by case, limited to what is strictly necessary, and revocable
On the Client's request, OmniRealm SASU will provide the names of authorised persons and the nature of their access. Any lasting extension of authorised personnel will be reflected in an update to this section.
5. Technical and organisational security measures
OmniRealm SASU implements the following technical and organisational measures, in accordance with Article 32 of the GDPR:
These measures are reviewed periodically and may evolve towards an equivalent or higher level of protection. Details of the measures in force are available on request under section 10.
6. Sub-processors
The Client authorises OmniRealm SASU to engage the following sub-processors. Each is bound by data protection commitments at least equivalent to this agreement.
Hostinger International Limited (France datacenter)
Hosting of the application infrastructure and the PostgreSQL database
Data shared: All service data
Stripe (Ireland (EU))
Payment processing, PCI-DSS Level 1 certified
Data shared: Email, billing data
Resend (EU)
Transactional email delivery (verification, reset, notifications)
Data shared: Email, message content
Upstash (EU)
Rate limiting and usage counters (abuse protection)
Data shared: Session identifier, IP address
Sentry (EU)
Application error collection for debugging
Data shared: Technical diagnostic data, user identifier
Mistral AI (France (EU))
Conversation assistant on the public website (visitor answers)
Data shared: Content of messages exchanged with the assistant
Telegram (Outside the EU)
Internal notification of a signup or a contact request
Data shared: Email domain, contact message
The audience analytics platform and internal monitoring services are self-hosted on OmniRealm's own infrastructure and are therefore not third-party sub-processors.
Any addition or replacement of a sub-processor is notified to the Client with 30 days' prior notice. The Client may object within that period on legitimate data protection grounds; failing agreement, the Client may terminate the affected part of the service without penalty.
7. Assistance with data subject rights
Requests from data subjects are the responsibility of the Client as controller. OmniRealm SASU assists as follows:
- Access and portability - export of the data associated with an account in a structured, machine-readable format (JSON or CSV)
- Rectification - correction from the service interface, or on request where the data is not editable there
- Erasure - deletion of the account and associated data, under the conditions of section 9
- Restriction and objection - suspension of processing on the Client's written instruction
If a data subject contacts OmniRealm SASU directly, the request will not be acted upon without instructions: it is forwarded to the Client without undue delay and without any substantive reply.
OmniRealm SASU responds to the Client's assistance requests within 5 business days, so the Client can meet its own response deadline towards the data subject. This assistance is provided at no extra cost for requests of reasonable volume.
8. Personal data breach notification
In the event of a personal data breach affecting data processed on behalf of the Client, OmniRealm SASU will:
- notify the Client without undue delay and no later than 48 hours after becoming aware of it
- describe the nature of the breach, the categories and approximate volume of data and data subjects concerned
- state the likely consequences and the measures taken or proposed to address it
- provide a point of contact for further information
Where all information is not immediately available, it is provided in phases as the investigation progresses.
Notification to the supervisory authority and, where applicable, to data subjects, is the Client's responsibility as controller. OmniRealm SASU provides all information needed for that purpose and keeps internal documentation of the incident.
9. Return and deletion of data at the end of the contract
At the end of the service, the Client chooses between the return and the deletion of its data.
Data remains exportable by the Client from the account, or on request in JSON/CSV format
Deletion of production data, unless the Client instructs otherwise in writing
Data is purged from encrypted backups at the end of the backup retention cycle
Only invoices and accounting records are kept, under the statutory obligation (section 3)
A deletion certificate is issued to the Client on request. Deletion also applies to copies held by sub-processors, according to their own purge schedules.
10. Audit rights and availability of information
OmniRealm SASU makes available to the Client the information necessary to demonstrate compliance with this agreement, and submits to the following reviews:
- Documentation on request - description of the security measures in force, list of sub-processors and authorised persons, security test reports (subject to redaction of items that could compromise the security of other clients)
- Security questionnaire - written response within 15 business days
- On-site or remote audit - once a year, on 30 days' written notice, at the Client's expense, by the Client or an independent auditor bound by confidentiality and not a competitor of OmniRealm
- Additional audit - available following a confirmed data breach affecting the Client
Audits must not disrupt operation of the service or give access to other clients' data. OmniRealm SASU will inform the Client if it considers that an instruction received infringes the GDPR or other applicable data protection provisions.
11. Transfers outside the European Union
Service hosting, the database and backups are located within the European Union. The sub-processors listed in section 6 are established in the EU, with one exception, disclosed below.
Exception — internal notifications: the messaging service used to alert the team of a new signup or a contact request is operated outside the European Union. The items transmitted are limited to the email domain and, for a contact request, the message written by its author. No scan results, no billing data and no full user email address pass through this channel.
Any transfer outside the EU is governed by the European Commission's Standard Contractual Clauses or an applicable adequacy decision, supplemented where necessary by additional measures. The Client may request details of the transfer mechanism applicable to each recipient.
Legal basis for processing on behalf of a controller: Article 28 of the GDPR. Framework for transfers: Chapter V of the GDPR.
12. Contact and acceptance
This agreement supplements the Terms of Service and applies from the moment the service is subscribed to. For any question, audit request or exercise of a right:
A signed copy of this agreement can be provided on request to Clients who need one for their own record of processing activities. In the event of a conflict between this document and the Terms of Service on a data protection matter, this agreement prevails.
Other legal documents