Skip to content
  • Home
  • Features
  • Partners
  • About
  • Blog
FR / EN
Contact

Data Processing Agreement (DPA)

Last updated : 16 July 2026

Applicable to professional customers who, by using OpenVisio, process personal data for which they are the controller. It implements Article 28 GDPR, supplements the Terms of Use, and prevails, on data-protection matters only, in the event of conflict.

1. Parties

  • The Controller: the professional customer using the Service (the “Customer”).
  • The Processor: Vopenia (“Vopenia”), publisher of the OpenVisio service.

2. Definitions

The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given by Article 4 GDPR.

3. Subject matter and roles

In providing the Service, Vopenia processes personal data on behalf of and on the documented instructions of the Customer, as a processor within the meaning of Article 28 GDPR. The Customer remains the controller and warrants that it has a legal basis for the processing it carries out via the Service.

4. Description of processing

  • Nature and purpose: provision of a video-conferencing service (real-time video/audio meetings, participant management, notifications, related features).
  • Duration: the term of the contract between the Customer and Vopenia.
  • Categories of data subjects: the Customer’s users, staff, guests and meeting participants.
  • Categories of data: identification and account data, meeting metadata, technical and connection data, content exchanged during meetings (audio/video streams are not recorded by default), diagnostic data.
  • Operations: collection, hosting, real-time transmission, logging, security, deletion.

5. Vopenia’s obligations (processor)

Under Article 28.3 GDPR, Vopenia undertakes to:

  1. process data only on the Customer’s documented instructions, including for transfers outside the EU, unless required by law (in which case Vopenia informs the Customer unless legally prohibited);
  2. ensure persons authorised to process the data are bound by confidentiality;
  3. implement the appropriate technical and organisational measures under Article 32 GDPR (see section 8);
  4. comply with the conditions for engaging another processor (section 6);
  5. assist the Customer, by appropriate measures, in responding to data-subject requests (Articles 15–22 GDPR);
  6. assist the Customer in ensuring compliance with Articles 32–36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of processing and available information;
  7. delete or return the data at the end of the contract (section 9);
  8. make available to the Customer all information necessary to demonstrate compliance with Article 28 and allow audits (section 7).

6. Sub-processing

The Customer authorises Vopenia to engage sub-processors to provide the Service, notably: OVHcloud (SAS OVH, France) (hosting), Bugsnag (SmartBear) (crash reporting). Vopenia contractually imposes on these sub-processors data-protection obligations equivalent to those of this agreement. Vopenia informs the Customer of any change regarding the addition or replacement of a sub-processor, allowing the Customer to raise legitimate objections within a reasonable time.

7. Audit

Vopenia makes available the information necessary to demonstrate compliance and allows audits, including inspections, by the Customer or a mandated auditor, under conditions preserving confidentiality and security, with reasonable notice and proportionate frequency. Vopenia may satisfy this obligation by providing existing reports or certifications.

8. Security

Vopenia implements appropriate technical and organisational measures, including: encryption of streams in transit (WebRTC/DTLS-SRTP, TLS), access control and logging, segregation, authorisation management, backups, testing and continuity procedures, ensuring the confidentiality, integrity, availability and resilience of systems.

9. Personal data breach

Vopenia notifies the Customer of any personal-data breach without undue delay after becoming aware of it, providing the useful information (nature, approximate categories and volume, likely consequences, measures taken) to enable the Customer to meet its notification obligations (Articles 33 and 34 GDPR).

10. Transfers outside the European Union

Any transfer outside the EU is governed by appropriate safeguards (Articles 44 et seq. GDPR): the European Commission’s Standard Contractual Clauses, adherence to the EU-U.S. Data Privacy Framework where applicable, and additional measures. The sub-processors concerned are listed in section 6.

11. Fate of data at the end of the contract

At the end of the services, Vopenia, at the Customer’s choice, returns and then deletes the personal data and existing copies, within 30 days, unless legally required to retain them.

12. Liability

Each party’s liability is assessed under Article 82 GDPR and the provisions of the main contract. Each party is liable for damage caused by processing carried out in breach of its own obligations.

13. Term

This agreement enters into force upon the Customer’s acceptance of the Service and applies throughout the processing of data on the Customer’s behalf.

OpenVisio extends Visio, the sovereign video-conferencing app of La Suite numérique, to native mobile apps and meeting rooms — without giving up sovereignty or open source.

Hosted in France · Open-source technologies

Navigation

  • Features
  • Partners
  • About
  • Blog
  • Contact

Legal

  • Legal notice
  • Privacy
  • Terms
  • Cookies
  • DPA

© 2026 OpenVisio · Published by Vopenia. All rights reserved.

Sovereign video conferencing, everywhere.