Data Processing Agreement | contrast Help Center

Data Processing Agreement

Contrast's DPA and how to contact DPO

Written by Luuk de Jonge
October 17, 2025

The company AirfairCTWW, SAS operating as Contrast with a capital of 214.22 euros, registered in the Commercial Register of Bobigny under the number 889006706 whose registered office is located at 9 rue des colonnes 75002 Paris, represented by Salim Semaoune in his capacity as data protection officer;

(hereinafter, the “Data Processor”) on the other hand,

The Data Processor and the Data Controller are individually referred to as a “Party” and jointly as the “Parties”.

IT HAS BEEN PREVIOUSLY SET FORTH, AS FOLLOWS:

The Parties declare and acknowledge that the negotiations that preceded the conclusion of this agreement were conducted in good faith...

THIS BEING EXPOSED, THE PARTIES HAVE AGREED AS FOLLOWS:

Purpose

The purpose of this agreement is to define the conditions in which the Data Processor undertakes to carry out, on the Data Controller's behalf, the personal data processing operations defined below.

As part of their contractual relations, the Parties shall undertake to comply with the applicable regulations on personal data processing and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter “the General Data Protection Regulation”).

Definitions

For the purposes of this agreement, the following terms shall have the meanings set out below or set forth in the General Data Protection Regulation:

Description of the Processing being subcontracted out

The Processor is authorised to process, on behalf of the Controller, the necessary Personal Data for providing the following services:

To perform the service covered herein, the Controller shall provide the Processor with the necessary information, including a detailed description of the processing set out in Appendix 1.

Duration of the agreement

This DPA is effective as of the date of the signature of the MSA agreement by the Parties for the duration of the engagement between the data controller and data processor or as long as personal data is being processed.

Data Controller’s obligations

The Data Controller acknowledges and ensures:

  1. that the Processing is carried out in accordance with the General Data Protection Regulation...
  2. That in the event the Data Controller processes “sensitive Data”...
  3. that the Data Controller will respond, without undue delay, to requests for information from the data protection authority...
  4. that the Data Controller will respond, without undue delay, to requests from Data Subjects and will give appropriate instructions to the Data Processor, in due time.

The Controller undertakes to:

  1. provide the Processor with the Personal Data mentioned in Appendix 1 hereof;
  2. document, in writing, any instruction regarding the Processing of Personal Data by the Processor;
  3. ensure, before and throughout the Processing, compliance with the obligations set out in the General Data Protection Regulation.

Data Processor's obligations

The Data Processor shall undertake to:

  1. process the Personal Data solely for the purposes subject to the agreement signed between the Parties...
  2. where the Processor considers that an instruction infringes the General Data Protection Regulation...
  3. guarantee the confidentiality of Personal Data processed hereunder;
  4. ensure that the persons authorised to process the Personal Data hereunder:
  5. have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  6. receive the appropriate Personal Data protection training;
  7. take into consideration, in terms of tools, products, applications or services, the principles of Data protection by design and by default;
  8. set up and maintain a specific documentation of Personal Data protection legislation and practice;
  9. inform its employees of their responsibility regarding Data protection, including confidentiality of the Personal Data;
  10. in the event of a legal, administrative or judicial prohibition of the Data Processor’s right to process Personal Data, the Data Processor will inform the Data Controller...

Sub-processing

The Data Processor may use another sub-processor...

The Data Controller has a minimum of 30 (thirty) days from the date of receipt of this information to present its objections...

Data Subjects’ information

It is the Data Controller's responsibility to inform the Data Subjects concerned by the Processing activities...

Exercise of Data Subjects’ rights

It is the Data Controller's responsibility to fulfill its obligation to respond to requests of the Data Subjects to exercise their rights...

Notification of Personal Data Breach

The Data Processor shall notify the Data Controller of any Personal Data Breach without undue delay...

Assistance

The Data Processor assists the Data Controller in carrying out data protection impact assessments...

Security measures

The Data Processor undertakes to implement the technical and organisational measures to ensure a level of security appropriate to the risk...

End of services

At the end of the service regarding the Processing of such Personal Data, the Data Processor undertakes to destroy or anonymize all Personal Data provided by the Data Controller.

Records of the Processing activities

The Data Processor acknowledges and ensures that it maintains a written record of all categories of Processing activities...

Documentation

The Data Processor provides the Data Controller with the necessary documentation for demonstrating compliance with all of its obligations...

Ex-EEA Transfers

Any transfer of Personal Data outside the European Economic Area (EEA) must be carried out by the applicable regulations...

Data protection officer

The Data Controller has appointed the following Data protection officer (“DPO”):
Salim Semaoune
113 avenue du général Michel Bizot, 75012 Paris
(+33) 6.63.68.60.87
dpo@getcontrast.io

Termination of the Agreement

The Parties acknowledge that the termination of the Agreement does not relieve them of their obligations under the General Data Protection Regulation...

Liability

With regard to the Data Processor’s liability for the Processing of Personal Data...

Governing Law – Agreement Language

By express agreement between the Parties, this Agreement is governed by French law...

Resolution of disputes

For any dispute arising from the execution of this Agreement, the most diligent Party shall take action before the competent courts.

APPENDIX 1 – DETAILS OF THE PROCESSING SUBJECT TO PROCESSING

* File available upon request

APPENDIX 2 – SECURITY MEASURES

Our duty to keep your data secure

Contrast is a platform that helps businesses create videos and hosts webinars...

Security at the organizational level

At Contrast, the security initiative and program are managed and supervised by co-founder and Chief Technical Officer (CTO)...

Customer Data Protection Program (CDPP)

The goal of this program is to prevent unauthorized access to our customer's data...

Embedded security in product development process

Together, the product and tech team mitigate risk by making security a priority...

TLS

Transport Layer Security ( TLS) is a cryptographic protocol designed to provide communications security...

Video conference security

Contrast uses the WebRTC protocol to exchange audio and video packages within a browser...

Video streaming security

Contrast employs the HTTP Live Streaming (HLS) protocol to stream the videos on the Internet...

Data in transit

Data at rest

Payments

Payment processing is done through our payment provider Stripe...

Provisioning

To minimize the risk of data exposure, we limit access to data...

Authentication

To minimize further risk, we employ multi-factor authentication...

Password Management

Contrast requires employees to use an approved password manager...

System Monitoring, Logging, and Alerting

Contrast is using the AWS WAF to mitigate DDOS attacks and prevent several other threats...

Data retention and disposal

Customer data is hard deleted upon request to our customer service or DPO...

Responding to Security Incidents

Contrast has an incident escalation policy and tools in place to organize and decrease the time to remediation...

Disaster Recovery and Business Continuity Plan

You can find a link to our plan here

Vendors and third-party-services

Our operations require the use of vendors and third-party-services...

Contrast Application

The Contrast application exists out of multiple components that are accessible depending on somebody's role.

Admin application

This application is used to create and manage webinars...

Registration pages and channels

Registration pages and channels are publicly available on the internet...

Contrast Studio

Contrast Studio is a live streaming solution that broadcasts the webinar or records content...

Questions or remarks

If you have questions or remarks regarding security or privacy at Contrast, do not hesitate to reach out to

Did this answer your question?
😞😐😃