Data Processing Agreement (DPA)

Last updated July 30, 2026 · v1.0

This translation is provided for your convenience. In the event of any discrepancy, the French version prevails.

1. Purpose, definitions and scope

This Data Processing Agreement (hereinafter the "Agreement" or "DPA") governs the processing of personal data that KAWLET EURL, publisher of the TITU service, carries out **on behalf of a professional partner, in the cases and on the terms described in Annex 1**.

It is entered into pursuant to Article 28 of Regulation (EU) 2016/679 (hereinafter the "GDPR") and forms an indivisible whole with the services contract, the listing agreement or the integration agreement entered into between the Parties (hereinafter the "Main Agreement").

1.1. The Parties

  • The "Processor" means KAWLET EURL, société à responsabilité limitée à associé unique, whose registered office is at 15 Square Rameau, 59000 Lille (France), registered with the RCS of Lille Métropole under number 993 159 250, publisher of the TITU service.
  • The "Partner" means the professional legal entity signing the Main Agreement, acting as controller: sports facility operator, club, association, federation, league, district, or technical integration partner.

1.2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given to them by Article 4 GDPR.

"Entrusted Data" means only the personal data that the Partner transmits to the Processor, or gives it access to, for the purposes of performing the Main Agreement.

1.3. What this Agreement does not cover

This Agreement does not apply to the processing for which KAWLET acts as controller, which is described in paragraph 2.2 and governed by the TITU privacy policy, to the exclusion of this Agreement.

It likewise does not apply to individual users of the TITU service. No player, no member of a group and no group admin is a party to this Agreement, signs it, or is intended to sign it.

2. Capacity of the Parties

The capacity of a party follows neither from its contractual title nor from the Parties' intention, but from who actually determines the purposes and means of the processing (Article 4(7) GDPR). The Parties expressly agree on the following allocation.

2.1. Processing covered by this Agreement

For the processing described in Annex 1 only, carried out on the Partner's documented instructions and in its interest:

  • the Partner is the controller;
  • KAWLET is the processor.

2.2. Excluded processing: KAWLET as controller

For the whole of the TITU user-facing service, KAWLET acts as controller and not as processor. This covers in particular:

  • creating and managing a player account, authentication by one-time code received by SMS, the account profile and language;
  • the life of a group: recurring sessions, attendance, the queue, substitutes, guests, scores, standings and votes;
  • notifications sent to players;
  • product usage measurement;
  • the optional matching of a player account with the public results of competitions, where the player asks for it and confirms it.

It is expressly agreed that:

  1. A data subject's consent transfers no responsibility. A player who declares their club and then confirms a proposed match provides a legal basis for the processing within the meaning of Article 6(1)(a) GDPR. They remain the data subject and in no way become a controller.
  2. KAWLET alone determines the purposes and means of that processing: which public sources are consulted and when, the anonymisation of people who are not concerned, how long items are made available, the abuse-limiting counters, and the dispute and withdrawal procedure.
  3. A group admin or manager is not a controller of their group members' data. The administration roles provided by the service (admin, co-admin) are application-level functions for governing an amateur group. They confer no capacity within the meaning of the GDPR, no obligation under Article 28, and no personal liability on the admin in respect of the processing.

2.3. Processing for which each Party is an independent controller

Where the Partner and KAWLET each pursue their own purposes on distinct data — for example, the Partner for its customer relationship, KAWLET for the operation of its directory — each Party acts as an independent controller and bears its own obligations alone. This Agreement does not apply to such processing.

3. Description of the processing

The characteristics of the processing carried out by KAWLET on behalf of the Partner — subject matter, nature, purpose, duration, categories of data and categories of data subjects — are described in Annex 1 to this Agreement, in accordance with Article 28(3) GDPR.

Annex 1 is exhaustive. **Any processing not described in Annex 1 is deemed to fall outside the scope of this Agreement** and may be carried out only after that annex has been amended in writing and signed by both Parties.

The Parties acknowledge that, in several of the use cases described in Annex 1, **no personal data is transmitted to KAWLET**: listing a facility, a booking offer or a club rests on organisational data (name, address, opening hours, prices, capacities) which does not relate to an identified or identifiable natural person. In those cases this Agreement remains without object for the service concerned, without the Parties having to terminate it.

4. Obligations of the Partner (controller)

As controller, the Partner undertakes to:

  • Lawfulness. Transmit to KAWLET only data collected and processed lawfully, on a valid legal basis within the meaning of Article 6 GDPR, and to have the right to entrust it to a processor for the purposes described in Annex 1.
  • Informing data subjects. Ensure that data subjects are informed as required by Articles 13 and 14 GDPR, including about the use of KAWLET as a processor, and obtain their consent where applicable.
  • Documented instructions. Give its instructions in writing, including by electronic means. The Main Agreement and this Agreement, including Annex 1, constitute the Partner's initial instructions. Any subsequent instruction must be sent to the contact given in Article 8.
  • Minimisation. Transmit only the data strictly necessary for the services. In particular, the Partner shall not transmit to KAWLET, through any channel whatsoever, data falling within the special categories of Article 9 GDPR (in particular health data, opinions, trade union membership, biometric data), data relating to criminal convictions (Article 10), or the contact details of registered players, club officials, referees or minors, for which the TITU service has neither a use nor a structure to hold them.
  • Accuracy. Ensure that the entrusted data is accurate and up to date, and notify KAWLET without delay of any rectification, objection or deletion that must be passed on.
  • Data subject rights. Answer requests from data subjects to exercise their rights itself, with the assistance from KAWLET provided for in Article 5.5.
  • Security of its own environment. Keep the access credentials issued to its staff confidential and notify any suspected compromise without delay.
  • Documentation. Keep its own record of processing activities and, where applicable, carry out the data protection impact assessment provided for in Article 35 GDPR.

The Partner shall indemnify KAWLET against any claim, action or penalty resulting from a failure to comply with the obligations incumbent on it under this Article.

5. Obligations of KAWLET (processor)

In accordance with Article 28(3) GDPR, KAWLET undertakes as follows.

5.1. Processing on documented instructions

KAWLET processes the Entrusted Data only on the Partner's documented instructions, including as regards transfers to a third country, unless required to do so by a legal obligation to which KAWLET is subject. In that case, KAWLET informs the Partner of that legal requirement before processing, unless the applicable law prohibits such information on important grounds of public interest.

KAWLET immediately informs the Partner if, in its opinion, an instruction received infringes the GDPR or another applicable data protection provision. In that case it may suspend performance of the disputed instruction until the Partner confirms or amends it in writing.

KAWLET shall not use the Entrusted Data for its own purposes, in particular for marketing, for enriching its directory, for building commercially exploitable statistics or for training machine learning models.

5.2. Confidentiality

KAWLET guarantees that the Entrusted Data remains strictly confidential. Accordingly:

  • access to the data is limited to the people who need it to perform the services, on a least-privilege basis;
  • the people authorised to process the data are bound by a contractual or statutory duty of confidentiality, including after their assignment ends;
  • KAWLET discloses no data to any third party, other than the sub-processors listed in Annex 2 and other than on the order of a competent authority;
  • in the event of a judicial or administrative order concerning the Entrusted Data, KAWLET informs the Partner as soon as possible, unless legally prohibited from doing so.

5.3. Security of processing

KAWLET implements appropriate technical and organisational measures within the meaning of Article 32 GDPR, described in Annex 3. Those measures are stated as they are **actually implemented at the date of this Agreement; KAWLET claims no certification** of security or compliance.

KAWLET may change those measures to take account of the state of the art, provided that the overall level of security is not reduced. Annex 3 is then updated.

5.4. Sub-processing

The Partner gives the Processor general written authorisation to engage sub-processors, on the terms of Articles 28(2) and 28(4) GDPR.

The list of sub-processors in force at the date of this Agreement is set out in Annex 2. That list is drawn up as an exhaustive inventory of the third-party services actually called by the TITU service, including those that process no personal data, so that the Partner has a complete view of the flows.

KAWLET undertakes to:

  • inform the Partner of any addition or replacement of a sub-processor with reasonable notice, and in any event before the new sub-processor processes any Entrusted Data;
  • allow the Partner thirty (30) days to raise a reasoned objection. Where an objection cannot be resolved between the Parties, the Partner may terminate the service concerned without compensation;
  • impose on each sub-processor, by contract, data protection obligations substantially equivalent to those of this Agreement;
  • remain fully liable to the Partner for its sub-processors' performance of their obligations.

5.5. Assistance to the Partner

Taking into account the nature of the processing and the information available to it, KAWLET assists the Partner:

  • Data subject rights. By implementing appropriate technical and organisational measures to enable the Partner to respond to requests for access, rectification, erasure, restriction, objection and portability. Any request received directly by KAWLET is passed on to the Partner without delay and is not handled by KAWLET, unless instructed otherwise.
  • Security, breaches, impact assessments. By providing the information needed for the Partner to comply with the obligations laid down in Articles 32 to 36 GDPR, including the impact assessment and prior consultation of the supervisory authority.

5.6. Personal data breach

KAWLET notifies the Partner of any personal data breach affecting the Entrusted Data **without undue delay after becoming aware of it, in accordance with Article 33(2) GDPR**, so as to enable the Partner to comply, where applicable, with its obligation to notify the supervisory authority **within 72 hours** under Article 33(1).

The notification includes, so far as the information is available when it is issued: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Missing information is provided as it becomes available, without further undue delay.

Nothing in this Article makes KAWLET responsible for notifying the supervisory authority or the data subjects, which is a matter for the Partner in its capacity as controller.

5.7. Documentation and audits

KAWLET makes available to the Partner all the information necessary to demonstrate compliance with the obligations of Article 28 GDPR.

KAWLET allows audits, including inspections, by the Partner or an auditor it mandates, provided that:

  • the audit is notified in writing with at least thirty (30) days' notice, save in an emergency justified by a proven security incident;
  • it takes place during business hours, without disproportionate disruption to operations;
  • it does not undermine the confidentiality of the data of KAWLET's other clients or users, or trade secrets;
  • the auditor is bound by a confidentiality undertaking;
  • its frequency does not exceed once per calendar year, apart from a proven security incident or a request from a supervisory authority.

KAWLET may satisfy this obligation by providing the relevant documentation, including, where they exist, the audit reports or attestations of its own sub-processors.

5.8. Record of processing

KAWLET keeps, in accordance with Article 30(2) GDPR, a record of the categories of processing activities carried out on behalf of the Partner, and makes it available on request to the supervisory authority.

5.9. Transfers outside the European Union

KAWLET hosts the Entrusted Data within the European Union. Transfers to a third country resulting from the use of the sub-processors listed in Annex 2 are covered by the appropriate safeguards mentioned in that annex, in particular the standard contractual clauses adopted by the European Commission.

KAWLET carries out no other transfer outside the European Union without documented instructions from the Partner.

6. Fate of the data at the end of the services

6.1. Return

At any time during the term of the Main Agreement, and for thirty (30) days from its end, the Partner may request the return of the Entrusted Data. KAWLET provides it in a **structured, commonly used, machine-readable format**.

6.2. Deletion

At the end of that thirty (30) day period, or immediately on the Partner's written instruction, KAWLET deletes the Entrusted Data and any existing copies, unless legally required to keep it. KAWLET certifies that deletion in writing at the Partner's request.

6.3. What is not deleted

The deletion provided for in 6.2 does not concern:

  • the data that KAWLET processes as controller under paragraph 2.2, which follows its own lifecycle;
  • non-personal organisational facts (the name of a facility or a club, address, characteristics of a pitch, fixture list) taken from public sources or from the listing, which do not constitute personal data and remain governed by the Main Agreement and not by this Agreement;
  • technical logs and backups, which are deleted according to their own rotation cycle.

7. Liability

Each Party bears the liability incumbent on it under Articles 82 and 83 GDPR, in respect of its own obligations.

KAWLET is liable for damage caused by processing only where it has not complied with the obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the Partner's lawful instructions (Article 82(2) GDPR).

The liability caps and exclusions stipulated in the Main Agreement apply to this Agreement, within the limits allowed by the applicable rules.

8. Data protection contact

Any question, instruction, notification or request relating to this Agreement is to be sent to:

KAWLET EURL 15 Square Rameau 59000 Lille — France RCS Lille Métropole 993 159 250

Data protection contact: yo@titu.app

8.1. No data protection officer

KAWLET has not appointed a data protection officer (DPO) within the meaning of Article 37 GDPR, as it does not currently meet the conditions making such an appointment mandatory. The contact given above is the single point of entry for matters falling under this Agreement; it does not have the status or the independence guarantees attached to the role of data protection officer.

This position is reviewed whenever the business changes significantly. If an officer is appointed, this Article will be updated accordingly.

8.2. Supervisory authority

The supervisory authority competent for KAWLET is the **Commission nationale de l'informatique et des libertés (CNIL — the French data protection authority)**, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

9. Final provisions

9.1. Order of precedence

This Agreement forms an integral part of the Main Agreement. In the event of a conflict between a provision of the Main Agreement and a provision of this Agreement **concerning the processing of personal data**, this Agreement prevails. On any other question, the Main Agreement prevails.

In the event of a conflict between this Agreement and standard contractual clauses adopted by the European Commission and signed by the Parties, the latter prevail.

9.2. Term

This Agreement takes effect on the effective date of the Main Agreement and remains applicable for as long as KAWLET processes Entrusted Data on behalf of the Partner. The provisions of Articles 5.2 (confidentiality), 6 (fate of the data) and 7 (liability) survive it.

9.3. Amendment

KAWLET may amend this Agreement to take account of a change in the applicable rules, a decision of a supervisory authority or a technical change to the service. Any material amendment is notified to the Partner with reasonable notice. Failing a written and reasoned objection within thirty (30) days, the amendment is deemed accepted.

Annexes 2 and 3 may be updated on the terms provided for in Articles 5.4 and 5.3 respectively, without that update constituting a material amendment of the Agreement.

9.4. Partial invalidity

If a provision of this Agreement is held void or unenforceable, the other provisions remain in force. The Parties shall endeavour to replace the invalidated provision with a valid provision of equivalent economic and legal effect.

9.5. Applicable law and jurisdiction

This Agreement is governed by French law. Failing amicable resolution, any dispute concerning its validity, interpretation or performance falls within the exclusive jurisdiction of the **courts of Lille**, subject to any mandatory rules of jurisdiction.

Annex 1 — Description of the processing

This annex describes, in accordance with Article 28(3) GDPR, the processing carried out by KAWLET on behalf of the Partner. It is exhaustive.

A1.1. Listing in the facilities and clubs directory

ItemDescription
Subject matterListing of one or more sports facilities, or of a club, in the public TITU directory.
PurposeTo let players find a pitch or a club, and attach a session to it.
Nature of the operationsCollection, checking, structuring, correction, publication, updating, removal.
Categories of dataName, address, geographic coordinates, physical characteristics (dimensions, surface, floodlighting, changing rooms, accessibility), opening hours, public organisational identifiers.
Data subjectsNone in principle. These items are organisational data. Personal data appears only if the Partner transmits, on its own initiative, a named contact detail (for example the name and email address of a contact person).
DurationFor as long as the listing lasts, then in accordance with Article 6.

The Partner is encouraged to provide role-based contact details ("reception", "club office") rather than named ones. Where no personal data is transmitted, this Agreement remains without object for those services.

A1.2. Listing an operator's booking offer

ItemDescription
Subject matterDisplay, on a pitch or city page, of a booking offer operated by the Partner, with a link through to its own service.
PurposeTo tell the player that an offer exists and to send them to the Partner's service.
Nature of the operationsCollection of the offer's characteristics, structuring, publication, automatic expiry, redirection.
Categories of dataIdentity of the operator, site and pitch concerned, booking method, time zone, price in minor units, capacity, status, expiry date, destination link.
Data subjectsNone. The technical contract of the "offer" layer has no field able to receive a participant, a phone number, an email address, a customer account, a token or an authentication identifier.
DurationUntil the offer expires or is withdrawn by the Partner.

The booking itself is not operated by KAWLET. The player who clicks is redirected to the Partner's service, where they become that Partner's customer. The data collected from that redirection onwards is the Partner's sole responsibility, as independent controller, and falls outside the scope of this Agreement.

A1.3. Aggregated reporting of clicks on an offer

When a player activates the link of a Partner's offer, KAWLET increments an **aggregated daily counter**.

That counter — table venue_offer_click_daily — contains only the following fields:

FieldContent
offer_idIdentifier of the listed offer
dayDate (calendar day)
surfaceSurface the click came from: pitch listing, city page or map
clicksInteger counter
first_clicked_atTimestamp of the day's first click for that combination
last_clicked_atTimestamp of the day's last click for that combination

**It contains no IP address, no cookie or device identifier, no account, no player identifier, and no request header or payload. That absence is structural**: the table has no column able to hold such items, and the increment function receives only the offer identifier and the surface.

Three consequences follow, which the Parties expressly acknowledge:

  1. This counter is not processing of personal data. No natural person is identified or identifiable from these six fields.
  2. This counter is not individual audience measurement. It cannot count unique visitors, cannot reconstruct a journey, and cannot tell ten clicks by one person from one click by ten people. It must not be presented, either by KAWLET or by the Partner, as an audience measurement, as performance-based billing data, or as a fraud or abuse detection mechanism.
  3. It is provided to the Partner for information only, as a raw product signal, with no warranty of accuracy, completeness or correspondence with the conversions recorded by the Partner in its own system.

A1.4. Technical integration of a partner

ItemDescription
Subject matterSetting up a technical exchange flow between the Partner's system and the TITU service, provided for in a specific integration agreement.
PurposePerformance of the integration agreement.
Nature of the operationsReception, validation, structuring, storage, return, deletion.
Categories of dataDetermined by the integration agreement and listed exhaustively in it.
Data subjectsDetermined by the integration agreement.
DurationTerm of the integration agreement, then Article 6.

No integration may go into production without the categories of data and of data subjects having been listed in writing. The exclusions in Article 4 (special categories, convictions, contact details of club officials, referees or minors) apply in full.

A1.5. Processing excluded from Annex 1

To avoid any ambiguity, the following do not fall under this Agreement and are processed by KAWLET as controller:

  • all account, group and match data of players;
  • notifications sent to players;
  • the collection, checking and republication of organisational facts taken from public sources or from federations (club name, address, ground, level, fixtures, standings), which contain no personal data;
  • the optional matching, on request and subject to the player's confirmation, between their account and the public results of competitions.

Annex 2 — List of sub-processors

This list is drawn up as an exhaustive inventory of the third-party services actually called by the TITU service at the date of this Agreement, including those to which no personal data is transmitted. It is a superset of the sub-processors within the meaning of Article 28(4) GDPR.

A2.1. Providers liable to process personal data

ProviderRoleData locationTransfer safeguards
Supabase Inc.Database, authentication, file storage, server functions. Backbone of the service.European Union — production project hosted in the West EU (Paris) region, on AWS eu-west-3 infrastructure.Data at rest and in processing within the EU. Standard contractual clauses for any support access from a third country.
Amazon Web Services (AWS)Underlying infrastructure of the Supabase hosting (compute, file storage). KAWLET calls no AWS service directly; AWS acts as a sub-processor of Supabase.European Union — eu-west-3 (Paris) region.No transfer outside the EU for hosting. Standard contractual clauses under the AWS agreement.
Vercel Inc.Hosting and delivery of the public website (landing pages, sharing pages, directory, group join pages).United States (head office), delivery through a worldwide network of points of presence. The function execution region is not contractually pinned to date.Standard contractual clauses (Vercel data processing agreement).
Twilio Inc.Sending the authentication SMS (one-time code) only. Called by the authentication provider, never by TITU's application code. No other message is sent.United States and carrier infrastructure.Standard contractual clauses.
Google (Firebase Cloud Messaging)Push notifications only. No other Firebase service is used: no authentication, no database, no analytics, no crash reporting. The message is composed server-side and then handed to FCM.United States / Google worldwide infrastructure.Standard contractual clauses (Google data processing terms).
PostHog Inc.Product usage measurement. European instance eu.i.posthog.com. Explicitly named events; no automatic capture, no session recording, no heatmap — the corresponding libraries are not installed.European Union.Standard contractual clauses for any support access from a third country.
Google (Google Fonts)Download of typefaces by the mobile app on first launch. Transmits the device's IP address.Google worldwide infrastructure.Standard contractual clauses.
OpenFreeMapSupply of the map tiles displayed on the web and in the app. Transmits the IP address and the geographic area viewed. No key, no account, no account data transmitted.European Union (Netherlands).Not applicable — no transfer outside the EU identified.

A2.2. Providers processing no personal data

These services are listed for transparency: they are called by the service or by its public data pipelines, without any account, player or data subject data being transmitted to them.

ProviderRoleData locationTransfer safeguards
Open-MeteoWeather for a past session. Called from the pitch coordinates, with no API key, no account and no identifying header. No player data, and never the device's position.European Union (Germany) / Switzerland.Not applicable — no personal data transmitted.
ScrapingBeeCollection of federation sources for which authorisation has been obtained. No TITU user data is transmitted to it. Source pages containing named items are set aside before any recording: they are neither kept, nor cached, nor logged, nor republished, and the destination tables have no column able to hold a person.France (international proxies).Not applicable to the Partner's and users' data.
DataForSEOKeyword volume research for search engine optimisation. Processes generic search phrases. No account or player data.Outside the EU. No effect here: no personal data is transmitted to it.Not applicable — no personal data transfer.
Google (Gemini)Assisted extraction of technical facts about pitches. See the actual status in paragraph A2.3.United States / Google worldwide infrastructure.Standard contractual clauses.
Public sources and geocoding servicesReading public databases of sports facilities, association registers and geocoding services (Base Adresse Nationale, Nominatim/OpenStreetMap, national and municipal open data portals, portals of authorised federations). Queried with the names and addresses of facilities, never of people.Varies by source.Not applicable — no personal data transmitted.

A2.3. Actual status of the use of Google Gemini

The TITU service has two distinct uses of a language model, both limited to **facts and descriptions relating to pitches**. In both cases:

  • no player, account, group or data subject data enters a prompt; the content submitted comes exclusively from facility records and public sources;
  • no browsing tool, external search tool or access to a commercial places database is enabled;
  • no output of the model is published automatically.

Use 1 — extraction of technical facts. This pipeline is disabled by default and has never been run in production. Triggering it requires several independent conditions to be met **at the same time**: an explicit command-line flag, activation in a versioned manifest, a dedicated environment variable, a matching execution target, the exact cryptographic fingerprint of the plan, and a local database. The mere presence of an API key triggers nothing. The scope is limited to **three pre-launch validation cases**.

Use 2 — draft descriptions. A separate pipeline can produce draft descriptions of pitches. These drafts are marked not publishable and unreviewed, are never put online without an identified human review, and feed neither the public directory nor the indexable pages. This pipeline runs only if an API key is configured in the continuous integration environment.

This description reflects the actual state of the service at the date of this Agreement and anticipates no future deployment.

A2.4. Services configured but inactive

For transparency, the following services are referred to technically in the service without being called to date: Google Maps / Places (no call exists in the code; only an opaque place identifier could be kept in the future, in a separate table, without any content being reused), Mapbox and OpenCage (fallback geocoding services, not enabled). None of these services receives any data at the date of this Agreement. Enabling them would give rise to an update of this annex in accordance with Article 5.4.

Annex 3 — Technical and organisational measures

The measures below are described as they are actually implemented at the date of this Agreement. KAWLET claims no certification of security or compliance (in particular no ISO/IEC 27001, no SOC 2, no HDS and no PCI-DSS) and relies on none under this Agreement.

A3.1. Access control over the data

  • Row-level ring-fencing. PostgreSQL row level security is enabled on all application tables, including partitions. A query can return only the rows that the policy attached to the table allows for the requester.
  • Explicitly granted privileges. The anonymous role has no privilege on the tables. The authenticated role has only the strictly necessary verbs, granted table by table. Access is thus refused at privilege level before the security policies are even evaluated.
  • Service role. A trusted technical role, reserved for server-side processing, is not subject to row-level security policies — a necessary property of its use. Its credentials are never shipped in a client application, and in particular not in the public web app.

A3.2. Integrity of processing

  • Business logic lives on the server. Sensitive operations run inside transactional database-side procedures, with defined privileges, which lock the row concerned before deciding. The client calls an operation; it does not determine its outcome.
  • Decisions are not delegated to the client. Critical values — in particular rank in a queue — are assigned by the database. No call signature allows a client to impose them.
  • Time-based transitions are triggered by the server, by a task scheduled in the database, not by the app. Changing the clock on a device has no effect.

A3.3. Ring-fencing of data from external sources

  • The tables making up the internal reserve of federation data are placed under row-level security with no policy at all and are subject to an explicit revocation of privileges for the anonymous and authenticated roles. No public route and no procedure accessible without authentication reads them.
  • Only a separate public projection, limited to organisational facts and with no column able to hold a person, is exposed.
  • The absence of personal data in these tables is a structural property of the schema, not a usage instruction.

A3.4. File storage

  • The storage bucket for profile photographs is private; that state is reapplied idempotently at every migration.
  • No permanent public address is generated. Access is by short-lived signed URL, limited to the file's owner or to a teammate in the same group.
  • Deleting an account triggers the purge of the file by a dedicated scheduled task, with retry on failure.

A3.5. Secrets management

  • The secrets used by the database (call addresses and tokens for server functions, encryption key for identity matching tokens) are kept in the database provider's built-in vault, and read at the point of use.
  • No production secret appears in the code repository or in its history.

A3.6. Encryption

  • In transit. Exchanges between the applications, the database and third-party services take place over HTTPS/TLS. No call in clear exists on any path handling personal data. TLS termination is handled by the hosting platforms.
  • At application level. Identity matching tokens are encrypted in the database (pgcrypto) with a key kept in the vault, and expire in ten minutes.
  • At rest. Encryption at rest of application data is provided by the hosting processor, in accordance with its own contractual commitments. KAWLET does not present it as a measure it implements itself.

A3.7. Minimisation and absence of trackers

  • Usage measurement rests on a closed list of named events, with no automatic capture and no session recording; the libraries enabling those functions are not installed.
  • The redirect to a partner's offer neither sets nor reads any cookie and keeps no IP address, no device identifier and no account identifier (see Annex 1, A1.3).
  • The data transmitted to compose a notification is limited to what is strictly necessary to display it.

A3.8. Erasure and data lifecycle

  • Erasure on request. An account erasure procedure is in place. It is triggered by the user themselves, takes no parameter designating a third party, requires an explicit confirmation, releases the spots held in upcoming sessions before closing the account, closes access to the account before attempting the purge (so that the account remains inaccessible even if the purge fails), and deletes the attached data.
  • Verification by sweep. An automated test looks for the deleted account's fingerprints in every text and structured column of the application, authentication and storage schemas, rather than in a predefined list of tables.
  • Functional durations. Several technical durations are applied by construction: expiry of matching tokens (ten minutes), the cancellation window for a drop-out, the anti-repeat delay for call-outs, expiry of reserved spots and of offers, expiry of booking slots.
  • Scope of this commitment. KAWLET does not claim to have an automatic periodic purge policy for application logs and match histories: erasure of personal data is triggered by the data subject or by the controller, and verified. Any remaining match data is anonymised.

A3.9. Organisation

  • Access to production environments limited to the people who need it.
  • Separation of development, test and production environments; development data is demonstration data.
  • Schema changes tracked through versioned and reviewed migrations.
  • Automated tests covering in particular ring-fencing, vote access reciprocity, account erasure and the private nature of file storage.
Contents
  1. 1. Purpose, definitions and scope
  2. 2. Capacity of the Parties
  3. 3. Description of the processing
  4. 4. Obligations of the Partner (controller)
  5. 5. Obligations of KAWLET (processor)
  6. 6. Fate of the data at the end of the services
  7. 7. Liability
  8. 8. Data protection contact
  9. 9. Final provisions
  10. Annex 1 — Description of the processing
  11. Annex 2 — List of sub-processors
  12. Annex 3 — Technical and organisational measures