Data processing agreement

Version of October 2, 2026

In short. When you store your clients' data in ElectriCAD (name, site address, phone…), you are responsible for it and we process it for you, only to run the Service. This agreement, required by Article 28 of the GDPR, is part of the terms. It applies automatically, without signing anything.

1. Parties and purpose

1.1. You (ElectriCAD's customer) are the controller of the personal data about third parties that you store in the Service. ElectriCAD, BE 0606.959.880, is your processor for that data.

1.2. This agreement sets out our obligations when we process that data for you. It applies for as long as we process it.

2. What we process

ItemDescription
Data subjectsYour clients and their contacts; your staff and the people you share documents with
DataName, site address, phone, email, information about the installation, signatures and images you import
Sensitive dataNone is expected; do not store any
OperationsHosting, storage, display, sharing according to your settings, backup, export, deletion
PurposeProviding the Service described in the terms, and nothing else
DurationAs long as the data is in your documents, then as set out in section 9

3. Our commitments

We undertake to:

4. Sub-processors

4.1. You authorise us to use the following providers to process that data: Supabase (database and files, European Union), Vercel (application hosting), Google (sending sharing and invitation emails), Geoapify and the public Belgian and French address registers (suggesting and checking the addresses you type).

4.2. We impose on them data protection obligations equivalent to those of this agreement. We remain responsible to you for their compliance.

4.3. We inform you of any addition or replacement by updating this page, at least 30 days in advance for a new provider. You may object for a reasonable reason related to data protection; if we cannot find a solution, you may cancel the subscription and get a refund for the unused part.

5. Security

Among other things, we apply: encryption of exchanges (HTTPS); access control per workspace and per role, enforced down to the database; encrypted storage of passwords; regular backups; internal access limited to what is necessary; logging of sensitive operations at our hosting providers.

6. Data breach

If we become aware of a data breach affecting your data, we notify you without undue delay, and no later than 48 hours after becoming aware of it, with the information we have, so that you can meet your own obligations.

7. Transfers outside the European Union

This data is stored in the European Union. If a provider needs to access it from a third country, the transfer relies on an adequacy decision (including the EU–US Data Privacy Framework) or on the standard contractual clauses of the European Commission.

8. Audits

On written request, we provide you with the information needed to show that we comply with this agreement. If that information is not enough, you may have an audit carried out, at your own cost, by an auditor bound by confidentiality, with 30 days' notice, at most once a year, without disrupting the Service or accessing other customers' data.

9. End of processing

Throughout the contract, you can export your documents as PDF and delete your data. When your account is closed, we delete that data within 30 days; backups are erased as they rotate, at the latest 90 days later. We only keep what the law requires us to keep.

10. Liability and order of documents

The liability limits of the terms apply to this agreement, except where the law forbids them. In case of conflict on data protection, this agreement prevails over the terms.

The French version of this text prevails over this translation in case of any difference.