This is an English translation of the current French DPA. Until an English paid market is separately approved, the French version forms the current contractual source.
1. Scope and formation of the agreement
This Data Processing Agreement, or “DPA”, is entered into between Flying Golem SAS, 1 Keroulard Vras, 29530 Plonévez-du-Faou, France, and the customer who subscribes to or uses Plumelin for professional purposes, referred to below as the “Customer”.
It supplements the Terms where Flying Golem processes on the Customer’s behalf personal data contained in a workspace, project, manuscript, invitation, comment or other content entrusted to Plumelin. It becomes binding when the Customer accepts the Terms or an order document that incorporates it by reference. A separate signature or checkbox is not required unless the parties agree otherwise in writing.
If the Customer itself acts as a processor for a controller, this agreement applies to Flying Golem as a subprocessor. The Customer warrants that it is authorised to give the instructions set out in this agreement. If there is a conflict concerning the processing of Customer Data, this agreement prevails over the Terms.
2. Roles of the parties
Data processed for the Customer
The Customer is a controller or processor, as applicable. It determines the purposes and essential means of its use of Plumelin, chooses invited people and their permissions, and ensures the lawfulness of the data and instructions entrusted to the service. Flying Golem acts as processor for personal data contained in the Customer’s content and workspaces, referred to as “Customer Data”.
Flying Golem’s own processing
Flying Golem remains a controller for account creation and security, proof of contract acceptance, billing and the payment identifiers it receives, fraud prevention, service security, support, the defence of its rights and compliance with legal obligations. This processing is described in the privacy notice and is not performed on the Customer’s behalf under this agreement.
Processing a transaction through Stripe Managed Payments falls under the respective roles of Stripe, Link and Flying Golem described in the privacy notice and the list of subprocessors and other recipients. This DPA does not make Flying Golem a processor for Stripe and does not cover Stripe’s storage of card data.
3. Description of entrusted processing
- Subject matter
- Provide editing, local and synchronised storage, structuring, collaboration, import, export, certification and, upon express action, AI-assisted analysis.
- Duration
- For the contract term and until Customer Data is returned or deleted under section 9, subject to statutory retention obligations.
- Nature
- Collection, receipt, organisation, storage, limited technical consultation, synchronisation, transmission to authorised collaborators, transformation, export, erasure and, where requested, automated analysis.
- Purposes
- Perform the functions selected by the Customer, secure their operation, resolve incidents and provide requested support.
- Data subjects
- Users, employees, contractors, authors, co-authors, proofreaders, readers, translators, support contacts and anyone whose information appears in content supplied by the Customer.
- Data
- Identity and professional contact details, roles and invitations, manuscript and fictional-world content, comments and suggestions, collaboration history, imported or exported files, project metadata and technical data required by the service.
A manuscript may, at the Customer’s choice, contain sensitive information or information about third parties. The Customer limits such information to what is necessary, verifies that an appropriate legal basis exists and does not use Plumelin for regulated processing incompatible with the service’s published characteristics.
4. Instructions and Customer obligations
The Customer’s documented instructions arise from this agreement, the Terms, its account configuration and actions performed by its users in Plumelin. Any additional instruction must be written, lawful, compatible with the service and must not require a material modification without the parties’ agreement.
Flying Golem processes Customer Data only on those instructions, including for a transfer to a third country, unless otherwise required by European Union or Member State law. In that case Flying Golem informs the Customer of the legal requirement before processing unless the law prohibits that information. Flying Golem informs the Customer without unreasonable delay if an instruction appears to infringe applicable data-protection law.
The Customer provides required information to data subjects, handles their requests, governs its users and collaborators, maintains appropriate permissions and promptly removes access that is no longer needed.
5. Confidentiality and security
People authorised by Flying Golem to work with Customer Data are bound by confidentiality and access it only under least privilege for an operation necessary to provide, secure or support the service.
Taking account of the service’s nature and known risks, Flying Golem maintains measures including:
- TLS encryption for network communications and restricted administration interfaces;
- passwordless authentication, session expiry and invalidation, attempt limits and separate individual accounts;
- project- and role-based access controls, express invitations and collaborator revocation;
- input validation, cryptographic verification of Stripe notifications and protection of operational secrets;
- bounded technical logs with no intentional recording of manuscript text in ordinary logs;
- encrypted independent database backups, continuous transaction log archiving, mirrored project assets, scheduled restore drills and external monitoring in Microsoft Azure; and
- scheduled deletion of trashed items and temporary export files, together with incident and erasure procedures.
The Customer remains responsible for devices, browsers, email accounts and exported copies under its control. Independent recovery protects service continuity but does not replace the Customer's own exports for offline access or records under the Customer's control.
6. Additional subprocessors
The Customer gives Flying Golem general authorisation to use the providers in the list of subprocessors and other recipients. Flying Golem contractually imposes substantially equivalent protection obligations for processing they perform on its behalf and remains responsible to the Customer for the performance of their subprocessing obligations.
Flying Golem informs the Customer, by email to the account’s administrative address or a durable notice in the application, of an intended addition or replacement of a subprocessor with access to Customer Data. Except for a security emergency or supplier-imposed necessity, notice is provided at least fifteen days before the change. During that period the Customer may raise a reasoned data-protection objection. The parties then seek a reasonable solution; if none is possible, the Customer may stop using the affected function or terminate the affected part of the service.
7. Location and international transfers
The primary service is hosted in the European Economic Area. Processing locations and transfer mechanisms for each provider are stated in the subprocessor list.
Where processing for the Customer involves a transfer outside the European Economic Area, Flying Golem uses a mechanism recognised by applicable law, such as an adequacy decision or European Commission Standard Contractual Clauses accompanied where necessary by supplementary measures. On reasonable request Flying Golem provides available information about that mechanism, subject to confidentiality obligations.
8. Rights, compliance and incidents
Taking account of the nature of processing, Flying Golem reasonably assists the Customer in responding to requests for access, rectification, erasure, restriction, objection and portability. Unless legally required to respond directly, Flying Golem forwards to the Customer any request manifestly concerning Customer Data.
Flying Golem provides reasonably available information to assist the Customer with security, breach notification, impact assessments and prior consultation obligations. It informs the Customer without undue delay after confirming a personal-data breach affecting Customer Data and progressively provides available information about its nature, likely consequences and measures taken. The Customer remains responsible for its notifications to authorities and data subjects.
9. Return and deletion
During the contract term, export functions allow the Customer to retrieve projects in the offered formats. Before account erasure, Plumelin reminds the Customer to make a final export. At the Customer’s choice expressed by that action or a written request, Flying Golem returns available data and then deletes it, or deletes it directly, when the relevant services end.
Items in Trash remain recoverable for thirty days, and export files produced on the server are deleted after twenty-four hours. Account erasure deletes active server and asset-mirror data, subject to encrypted database generations retained under the published eight-full and fourteen-differential rotation, Azure deletion and version-recovery copies retained for up to thirty additional days, and items Flying Golem must retain as controller for a legal obligation or to defend its rights. Those items are isolated from ordinary use and are not processed for other purposes.
10. Demonstration, audit and contact
Flying Golem makes reasonably necessary information available to demonstrate compliance with this agreement. The Customer first reviews the supplied documentation. If it is insufficient, no more than once per year except after an incident or serious indication of non-compliance, the Customer may request a targeted audit during business hours, on reasonable notice, by an independent person bound by confidentiality. The audit must not compromise service security or other customers’ data. The Customer bears its costs unless a material non-compliance attributable to Flying Golem is found.
The parties’ liability under this agreement follows the rules applicable to professionals in the Terms, without limiting data-subject rights or liabilities that cannot legally be excluded. Questions, instructions or objections may be sent to privacy@plumelin.com.
Flying Golem may update this agreement when the service or applicable law changes. A material change is notified before it takes effect. The version applicable to an order is the one brought to the Customer’s attention when accepted, subject to changes required by law.