Data Processing Agreement (DPA)
Estos documentos se publican en inglés, versión que prevalece. Las traducciones están en preparación.
This Data Processing Agreement forms an integral part of the Terms of Use between REACH TECHNOLOGIES SAS ("1st Minute Lead", the "Processor") and the Client (the "Controller"). It governs the processing that 1st Minute Lead carries out on behalf of the Client pursuant to Article 28 of the GDPR. Capitalized terms have the meaning given in the Terms of Use.
1. Scope and roles
The Client is the data controller of the Lead Data and of the Advisor data it introduces or has processed on the Platform. 1st Minute Lead acts exclusively as processor for that data.
This DPA does not cover the data for which 1st Minute Lead is itself controller (the Client's account, billing, first-party product analytics), which is governed by the Privacy Policy.
2. Description of the processing
The subject matter, duration, nature and purposes of the processing, the categories of data and of data subjects are described in Annex 1. In summary: capture of the forms submitted on the Client's website with their browsing context, real-time notification and routing to the Client's Advisors, triggering and tracking of call-backs (by phone or Web Call), scheduled call-backs, statistics and exports and, where the Client keeps the Scoring module enabled, computation of an interest score by a language model.
3. Instructions
1st Minute Lead processes the data only on the Client's documented instructions, which consist of: these Terms of Use and DPA, the configuration choices made by the Client in its interface (monitored forms, routing rules, activation or deactivation of the Scoring module per site, consent mode of the Script) and any subsequent written instruction. 1st Minute Lead informs the Client if, in its opinion, an instruction infringes the GDPR.
Scoring module: activation of the module constitutes an instruction to submit the data described in Annex 1 to the language-model providers listed on the Subprocessors page. The module is enabled by default at account creation and may be disabled at any time, per site, from the interface; deactivation takes effect immediately for subsequent submissions.
1st Minute Lead does not use the data processed on behalf of the Client for its own purposes, does not enrich it, does not share it between clients and, in accordance with Article 11.4 of the Terms of Use, never uses it to train artificial intelligence models.
4. Confidentiality and security
1st Minute Lead ensures that persons authorized to process the data are bound by an appropriate confidentiality obligation, and implements the technical and organizational measures described in Annex 2. Taking into account the state of the art and the nature of the data, these measures are designed to ensure a level of security appropriate to the risk (Article 32 GDPR).
5. Subprocessors
The Client gives its general authorization to the engagement of the subprocessors listed on the Subprocessors page, which identifies for each its role, the data concerned and its location.
1st Minute Lead informs account holders by email at least thirty (30) days before adding or replacing a subprocessor processing Lead Data or Advisor data. If the Client objects on legitimate data-protection grounds and no reasonable alternative is found, the Client may terminate its Account under the conditions of the Terms of Use.
1st Minute Lead imposes on each subprocessor, by contract, data-protection obligations equivalent to those of this DPA and remains fully liable to the Client for their performance.
6. Transfers outside the EU
The Platform and its database are hosted in France. Where a subprocessor is located outside the European Union (transactional emails, push notifications, payment, language-model providers where the Scoring module is enabled), the transfer is governed by an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or by the European Commission's standard contractual clauses, together with additional measures where required. Details per provider appear on the Subprocessors page.
7. Retention, return and deletion
7.1 During the contract
The Client may consult, rectify, export (CSV export from its interface, on plans that include it) and delete Lead Data at any time.
7.2 History per plan
Each plan includes an accessible history of Leads and calls (currently 30 days, 6 months or 12 months depending on the plan — see the Terms of Sale). Data older than the included history may be archived and then deleted; the Client is invited to export before any plan downgrade.
7.3 On termination
Upon termination of the Account, for any reason: the Script stops transmitting; the Client may export its data during the thirty (30) days following termination; at the end of that period, the Lead Data and Advisor data are permanently deleted from the production systems, then from backups at the end of their rotation cycle. Upon written request received during that period, 1st Minute Lead provides the data in a structured, commonly used format instead of deleting it immediately.
8. Assistance to the Controller
Taking into account the nature of the processing, 1st Minute Lead assists the Client:
- Rights of data subjects: the interface allows the Client to search, rectify, export and delete a Lead's record. Any request addressed directly to 1st Minute Lead by a Lead or an Advisor is forwarded to the Client without undue delay.
- Security, breach notification, DPIA: 1st Minute Lead provides the information reasonably necessary (Annex 2, Subprocessors page, processing description) for the Client's compliance with Articles 32 to 36 of the GDPR.
9. Personal data breaches
1st Minute Lead notifies the Client without undue delay after becoming aware of a personal data breach affecting the Client's data, to the email address of the Account holder, with the information required by Article 33(3) GDPR as it becomes available (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed). Notification of the supervisory authority and of data subjects remains the Controller's responsibility.
10. Audit
1st Minute Lead makes available the information necessary to demonstrate compliance with this DPA (this document, Annexes, Subprocessors page, security documentation). No more than once per twelve (12) months, the Client may conduct — at its own expense, upon thirty (30) days' notice, during business hours and without access to other clients' data — an audit of that compliance, in the form of a written questionnaire or, where an inspection is legally required, through an independent auditor bound by confidentiality.
11. Liability
The liability regime of the Terms of Use applies to this DPA. Each party remains liable for the administrative fines imposed on it under the GDPR according to its own role.
Annex 1 — Details of the processing
Subject matter: operation of the 1st Minute Lead platform (instant call-back of inbound leads) for the Client.
Duration: the duration of the Account, plus the return-and-deletion period of §7.3.
Nature and purposes: collection of the forms submitted on the Client's website with their browsing context; real-time alerting and routing to Advisors; triggering and tracking of call-backs (phone or Web Call, without recording of conversations); scheduled call-backs chosen by the visitor; qualification of the outcome by the Advisor; statistics, history and exports; where enabled, computation of an interest score (intent, engagement, score, spam probability) by a language model.
Categories of data subjects: the Leads (visitors of the Client's website who submit a form) and the Advisors (persons invited by the Client).
Categories of data:
- Leads: identity and contact details as entered in the form (name, email, phone, message and any other field of the monitored form), page and landing URL, referrer, UTM attribution parameters, date/time and fill duration, browser language, browsing journal on the Client's website (pages, scroll, clicks, on-site searches), status and history of the call-back (channel, attempts, outcome, notes and qualification entered by the Advisor), scheduled call-back slot, and — where the Scoring module is enabled — the computed score. No special categories of data are meant to be processed (Article 4.4 of the Terms of Use).
- Advisors: identity, professional email, phone number assigned by the Client, presence/availability state, call metadata and response-time statistics, push token of their device.
Automated individual decision-making: none producing legal or similarly significant effects; the score assists prioritization and every call-back decision is human (Article 9.3 of the Terms of Use).
Annex 2 — Security measures
- Hosting in a French data center (see Subprocessors); database and cache not exposed publicly.
- Encryption in transit (TLS) for all traffic, including the Script and the mobile application; Web Call streams encrypted by WebRTC (DTLS-SRTP), neither recorded nor stored.
- Authentication by individual accounts; passwords stored hashed (bcrypt); signed session tokens; site keys authenticating each installed Script; role-based access (owner, manager, advisor) and per-account data isolation enforced at the query layer.
- Mobile sign-in tokens stored in the device's secure enclave storage; QR sign-in tickets are single-use and short-lived.
- Server access restricted to authorized staff using SSH key authentication; separation of environments; secrets kept out of the code base.
- Logging of security-relevant events; IP addresses truncated in analytics; regular dependency updates.
- Backups of the database with rotation; restoration procedures tested.
This document is published by Reach Technologies SAS. For any question: contact@1stminutelead.com.
See also: Terms of Use · Terms of Sale · Privacy Policy · Subprocessors · Lead Information Notice