MazylonPulse
Data Processing Agreement

Data Processing Agreement.

Legal document compliant with GDPR article 28. This DPA applies automatically to all Mazylon Pulse customers. A tailored signable version is available on request for Enterprise contracts.

1. Parties

**Processor:** Mazylon SAS —

**Controller:** the Customer, legal entity bound to Mazylon by a Service use contract.

This DPA governs the processing carried out by Mazylon on behalf of the Customer as part of the provision of the Mazylon Pulse Service.

2. Subject matter and scope of processing

Purpose
Delivery governance analysis: blocker detection, quality coaching, digest, process answers, agile ceremony prep packs.
Duration
Duration of the main contract + 90 days of post-termination purge.
Nature
Collection, storage, correlation, indexing, analysis, delivery.
Categories of data processed
Professional identifiers (email, name, role), ticket/PR/message/Confluence page metadata, technical logs.
Categories of persons concerned
Employees and contractors of the Customer with access to connected tools (Jira, GitHub/GitLab/Bitbucket, Teams, Confluence).

3. Mazylon's obligations

  1. Process personal data only on the Customer's documented instructions (these Terms and the subscribed contract)
  2. Ensure confidentiality by contract for any person accessing the data
  3. Implement the technical and organizational measures described in Annex 1
  4. Assist the Customer in satisfying the rights of the persons concerned (access, rectification, erasure, portability)
  5. Notify the Customer within 72h in the event of a data breach
  6. Delete or return the data at the end of the contract, at the Customer's choice
  7. Make available all information necessary to demonstrate compliance, and submit to audits on reasonable request

4. Sub-processors

The Customer authorizes Mazylon to use the sub-processors listed on our Security page. This list is public and kept up to date.

Mazylon informs the Customer by email 30 days before any substantial change to this list. The Customer may object to an addition via a reasoned objection; failing a shared solution, the Customer may terminate their contract without penalty.

5. Transfers outside the EU

By default, no transfer outside the EU. The only potential transfer concerns Claude API calls (Anthropic, United States), governed by the Standard Contractual Clauses of the European Commission (Decision 2021/914). For Enterprise contracts, EU residency can be activated or an EU-hosted LLM can be used.

6. Technical and organizational measures (Annex 1)

  • TLS 1.3 encryption in transit and AES-256 at rest
  • OAuth tokens encrypted column-by-column via pgcrypto
  • Multi-tenant isolation enforced by PostgreSQL Row-Level Security + Hibernate application filter
  • Append-only audit log + S3 WORM copy
  • MFA required for Mazylon administrators
  • Automatic secret rotation, dedicated vault management
  • Automatic nightly data purge according to retention policy (see Privacy policy)
  • Annual penetration testing (report available on Enterprise request)

7. Data breach

In the event of a personal data breach concerning the Customer, Mazylon notifies the Customer without undue delay and no later than 72 hours after becoming aware of it, to the contact email designated in the contract. The notification includes: nature of the breach, categories and approximate volume of persons and data concerned, likely consequences, measures taken to remedy it.

8. Right to audit

The Customer may request an audit once a year, with 30 days' notice, on the measures implemented by Mazylon. The audit may take the form of a questionnaire, documentary review, or for Enterprise contracts, on-site inspection at the Customer's expense, subject to mutual confidentiality.

9. End of processing

At the end of the contract, Mazylon returns the data to the Customer (JSON/CSV export) then deletes it within a maximum of 90 days, except for those retained under a legal obligation (accounting traceability, judicial requests). A destruction certificate may be provided on request.

10. Applicable law

This DPA is governed by French law and interpreted in light of Regulation (EU) 2016/679 (GDPR) and French law n° 78-17 of 6 January 1978 as amended.

Contact

For any question about this DPA or to request a tailored signed version: privacy@mazylon.com

Last update: 22 July 2026.