GDPR Art. 28 Framework

Data Processing Agreement (DPA)

Last updated: October 2026

1. Subject matter, nature and duration of processing

This Data Processing Agreement (DPA) is entered into pursuant to Article 28 of the GDPR between the Client (controller) and OmniRealm SASU (processor), which operates the WarDek service.

WarDek processes personal data on behalf of the Client solely for the purpose of providing the security and compliance audit service, and only on the Client's documented instructions. Creating an account and agreeing to the Terms of Service constitute the initial instruction.

Purposes

Running security scans, generating audit reports, managing accounts and billing

Nature of operations

Collection, recording, automated analysis, storage, disclosure to the Client and erasure

Duration

The entire subscription term, extended by the return and deletion periods (section 9)

Roles

Client = controller · OmniRealm SASU = processor

OmniRealm SASU does not process Client data for its own purposes. Data is never sold, nor used to train any artificial intelligence model.

2. Categories of data and data subjects

The categories of personal data processed are:

Scanned domains

URLs and domain names submitted for audit, at the Client's initiative

Scan results

Detected vulnerabilities, scores, reports and supporting evidence

User accounts

Email address, name, authentication credentials

Technical data

IP address, access logs, error diagnostic data

Support exchanges

Messages sent to support or to the conversation assistant

Billing data

Handled by Stripe — WarDek never stores card data

Data subjects: users of the WarDek service (the Client's staff) and, incidentally, individuals whose data appears publicly on a domain scanned at the Client's request.

No special categories of data (health, opinions, biometrics) are processed intentionally. The Client undertakes to submit for audit only domains it owns or for which it holds authorisation.

3. Retention periods

Data is retained for the following periods:

12 months

Scan results and audit reports

Account lifetime

User profile data

30 days after deletion

Post-termination data (export available during this period)

6 years

Invoices and accounting records (statutory retention obligation)

Once these periods expire, data is irreversibly deleted or anonymised.

4. Confidentiality and authorised personnel

In accordance with Article 28(3)(b) of the GDPR, OmniRealm SASU ensures that persons authorised to process the Client's data are bound by a duty of confidentiality.

Who has access

Access is restricted to personnel authorised by OmniRealm SASU's management. Given the size of the company, authorised personnel is currently limited to the company director, who also acts as system administrator and therefore holds direct technical access to the production database — including scanned domains and audit results.

This disclosure is deliberate: administrator access necessarily exists in any hosted service. Clients are entitled to know who holds it.

Purposes for which that access may be exercised

  • Support and incidents - diagnosing and fixing a reported or detected malfunction
  • Client request - carrying out an export, a deletion or the exercise of a data subject right
  • Maintenance - migration, backup and restore operations
  • Legal obligation - responding to a lawful request from a competent authority

Any access outside these purposes is excluded. Client data is never accessed for commercial or marketing purposes, nor used to train an artificial intelligence model.

Under what commitment

  • Duty of confidentiality arising from corporate office for the director, and a written contractual confidentiality clause for any future employee, intern or contractor granted access
  • The commitment survives the end of the employment relationship or contract
  • Authorisation is granted case by case, limited to what is strictly necessary, and revocable

On the Client's request, OmniRealm SASU will provide the names of authorised persons and the nature of their access. Any lasting extension of authorised personnel will be reflected in an update to this section.

5. Technical and organisational security measures

OmniRealm SASU implements the following technical and organisational measures, in accordance with Article 32 of the GDPR:

AES-256 encryption at rest
TLS 1.3 in transit
Daily encrypted off-site backups
Application access logging
Data segregation per organisation
Encryption of Client-supplied API keys
Cryptographic signing of exported reports
Regular penetration tests and code reviews

These measures are reviewed periodically and may evolve towards an equivalent or higher level of protection. Details of the measures in force are available on request under section 10.

6. Sub-processors

The Client authorises OmniRealm SASU to engage the following sub-processors. Each is bound by data protection commitments at least equivalent to this agreement.

Hostinger International Limited (France datacenter)

Hosting of the application infrastructure and the PostgreSQL database

Data shared: All service data

Stripe (Ireland (EU))

Payment processing, PCI-DSS Level 1 certified

Data shared: Email, billing data

Resend (EU)

Transactional email delivery (verification, reset, notifications)

Data shared: Email, message content

Upstash (EU)

Rate limiting and usage counters (abuse protection)

Data shared: Session identifier, IP address

Sentry (EU)

Application error collection for debugging

Data shared: Technical diagnostic data, user identifier

Mistral AI (France (EU))

Conversation assistant on the public website (visitor answers)

Data shared: Content of messages exchanged with the assistant

Telegram (Outside the EU)

Internal notification of a signup or a contact request

Data shared: Email domain, contact message

The audience analytics platform and internal monitoring services are self-hosted on OmniRealm's own infrastructure and are therefore not third-party sub-processors.

Any addition or replacement of a sub-processor is notified to the Client with 30 days' prior notice. The Client may object within that period on legitimate data protection grounds; failing agreement, the Client may terminate the affected part of the service without penalty.

7. Assistance with data subject rights

Requests from data subjects are the responsibility of the Client as controller. OmniRealm SASU assists as follows:

  • Access and portability - export of the data associated with an account in a structured, machine-readable format (JSON or CSV)
  • Rectification - correction from the service interface, or on request where the data is not editable there
  • Erasure - deletion of the account and associated data, under the conditions of section 9
  • Restriction and objection - suspension of processing on the Client's written instruction

If a data subject contacts OmniRealm SASU directly, the request will not be acted upon without instructions: it is forwarded to the Client without undue delay and without any substantive reply.

OmniRealm SASU responds to the Client's assistance requests within 5 business days, so the Client can meet its own response deadline towards the data subject. This assistance is provided at no extra cost for requests of reasonable volume.

8. Personal data breach notification

In the event of a personal data breach affecting data processed on behalf of the Client, OmniRealm SASU will:

  • notify the Client without undue delay and no later than 48 hours after becoming aware of it
  • describe the nature of the breach, the categories and approximate volume of data and data subjects concerned
  • state the likely consequences and the measures taken or proposed to address it
  • provide a point of contact for further information

Where all information is not immediately available, it is provided in phases as the investigation progresses.

Notification to the supervisory authority and, where applicable, to data subjects, is the Client's responsibility as controller. OmniRealm SASU provides all information needed for that purpose and keeps internal documentation of the incident.

9. Return and deletion of data at the end of the contract

At the end of the service, the Client chooses between the return and the deletion of its data.

For 30 days

Data remains exportable by the Client from the account, or on request in JSON/CSV format

After that period

Deletion of production data, unless the Client instructs otherwise in writing

Backups

Data is purged from encrypted backups at the end of the backup retention cycle

Mandatory retention

Only invoices and accounting records are kept, under the statutory obligation (section 3)

A deletion certificate is issued to the Client on request. Deletion also applies to copies held by sub-processors, according to their own purge schedules.

10. Audit rights and availability of information

OmniRealm SASU makes available to the Client the information necessary to demonstrate compliance with this agreement, and submits to the following reviews:

  • Documentation on request - description of the security measures in force, list of sub-processors and authorised persons, security test reports (subject to redaction of items that could compromise the security of other clients)
  • Security questionnaire - written response within 15 business days
  • On-site or remote audit - once a year, on 30 days' written notice, at the Client's expense, by the Client or an independent auditor bound by confidentiality and not a competitor of OmniRealm
  • Additional audit - available following a confirmed data breach affecting the Client

Audits must not disrupt operation of the service or give access to other clients' data. OmniRealm SASU will inform the Client if it considers that an instruction received infringes the GDPR or other applicable data protection provisions.

11. Transfers outside the European Union

Service hosting, the database and backups are located within the European Union. The sub-processors listed in section 6 are established in the EU, with one exception, disclosed below.

Exception — internal notifications: the messaging service used to alert the team of a new signup or a contact request is operated outside the European Union. The items transmitted are limited to the email domain and, for a contact request, the message written by its author. No scan results, no billing data and no full user email address pass through this channel.

Any transfer outside the EU is governed by the European Commission's Standard Contractual Clauses or an applicable adequacy decision, supplemented where necessary by additional measures. The Client may request details of the transfer mechanism applicable to each recipient.

Legal basis for processing on behalf of a controller: Article 28 of the GDPR. Framework for transfers: Chapter V of the GDPR.

12. Contact and acceptance

This agreement supplements the Terms of Service and applies from the moment the service is subscribed to. For any question, audit request or exercise of a right:

Data Protection — OmniRealm SASU

[email protected]

OmniRealm SASU — Les Sables d'Olonne, France

A signed copy of this agreement can be provided on request to Clients who need one for their own record of processing activities. In the event of a conflict between this document and the Terms of Service on a data protection matter, this agreement prevails.

Other legal documents