ICT Provider & Data Processing Addendum
Version 1.0 — 31 August 2026
This addendum applies to customers who are data controllers for the content of their register, and to financial entities subject to Regulation (EU) 2022/2554 (DORA). It covers the terms Article 28(3) of the GDPR and Article 30 of DORA require. Where it conflicts with the Terms of Service, this addendum prevails.
Preamble — two roles, not one
Obligia acts in two distinct capacities, and the difference decides who notifies whom.
- Controller for user accounts, authentication logs and audience measurement. Obligia determines the purposes and notifies the supervisory authority directly.
- Processor for the content of your register — providers, contracts, functions, identifiers. You determine the purposes; Obligia acts on your instructions and alerts you rather than notifying the authority in your place.
Register content contains personal data: the ITS data model provides for person_type in B_05.01, which explicitly distinguishes a legal person from a natural person. An ICT provider may be a sole trader.
Part I — Processing of personal data (GDPR art. 28)
1. Subject matter, duration, nature and purpose
Obligia processes, on your behalf, the personal data contained in your register of information, for the sole purpose of allowing that register to be entered, validated, retained and exported in the format required by ITS (EU) 2024/2956. Processing lasts for the subscription, plus the 30 days of export availability in section 8.
Data types: names and identifiers of ICT providers (LEI, EUID, national codes), including where applicable the name of a natural person trading in their own name; professional contact details entered in free-text fields.
Categories of data subjects: ICT providers who are natural persons, and people named as a contact in a register.
No data falling under Articles 9 or 10 of the GDPR is processed. You undertake not to enter any.
2. Documented instructions art. 28(3)(a)
Obligia processes the data only on your documented instructions. These terms, your use of the service and the published documentation constitute those instructions. No transfer outside the European Union takes place. Were Union or Member State law to require processing beyond these instructions, you would be informed before the processing unless that information is legally prohibited.
3. Confidentiality art. 28(3)(b)
People authorised to process the data are bound by confidentiality. One person currently holds administrative access; any recruitment will be preceded by a written confidentiality undertaking before access is granted.
4. Security measures art. 28(3)(c), art. 32
- Two-layer tenant isolation: application filtering on every request and PostgreSQL row-level security policies, failing closed;
- Encryption in transit (TLS) and at rest; second-factor secrets encrypted under a key separate from the signing key;
- Passwords hashed with argon2id; second factor mandatory for all platform administration;
- Audit log of sensitive actions, retained 36 months;
- Daily encrypted backup (AES-256), with restoration rehearsed and verified;
- Automatic purge of data at the end of the published retention periods;
- Refusal to start under an unsafe production configuration.
The operator back-office gives access to neither the content of registers nor the data they contain: it exposes aggregates and metadata only. This property is enforced by automated tests.
5. Sub-processors art. 28(2), art. 28(3)(d)
| Sub-processor | Purpose | Location |
|---|---|---|
| IONOS SARL | Hosting | European Union (Spain) |
| Sendinblue SAS (Brevo) | Transactional email | European Union (France) |
| Stripe Payments Europe, Ltd. | Payment processing | European Union (Ireland) |
Each sub-processor is bound by at least equivalent obligations. Any addition or replacement is notified to you 30 days in advance, during which you may object and, failing agreement, terminate without penalty.
6. Assisting with data subject rights art. 28(3)(e)
The service lets you respond yourself, without delay and without contacting Obligia: access and portability through the full register export in the regulatory format and a structured JSON export of the account record; erasure through immediate cascading account deletion; rectification through direct editing. For any request these functions do not cover, Obligia assists you within 5 working days.
7. Assisting with articles 32 to 36 art. 28(3)(f)
Obligia makes available, on request, its record of processing activities, its risk assessment, its incident notification procedure, and the material needed for a data protection impact assessment.
In the event of a breach affecting your register, Obligia — as processor — alerts you without undue delay, providing the six elements of Article 33(3). Obligia does not notify the supervisory authority on your behalf: that obligation belongs to the controller.
8. Return or deletion at the end of the service art. 28(3)(g)
You choose between return and deletion. Absent a choice expressed within 30 days of the end of the subscription, the data is deleted. Return is self-service at any time, including during those 30 days, in the regulatory xBRL-CSV format — usable without Obligia.
9. Information and audit art. 28(3)(h)
Obligia makes available all information necessary to demonstrate compliance with Article 28, and submits to the audits described in section 11.
Part II — ICT service provision under DORA (art. 30)
This part applies where you are a financial entity subject to Regulation (EU) 2022/2554.
10. Service description and location art. 30(2)(a), 30(2)(b)
Service: an online tool assisting in the construction, quality control and export of the DORA register of information. Obligia is not a regulatory advisory service; assessing function criticality and filing with the authority remain your responsibility.
Location of data and processing: European Union, exclusively. Any change of location is notified 60 days in advance and opens a right to terminate without penalty.
11. Access, inspection and audit rights art. 30(2)(e), 30(3)(e)
You, your auditor and your competent authority hold unrestricted rights of access, inspection and audit, exercisable on documents at any time — security documentation, record of processing, test reports, SBOM, your own audit trail — and on site or remotely with 30 days' notice, save for a request from a competent authority, which is exercised without notice. Obligia cooperates fully and cannot invoke trade secrecy against a competent authority.
12. Service levels art. 30(3)(a)
| Indicator | Commitment |
|---|---|
| Monthly availability | 99.0%, excluding planned maintenance |
| Planned maintenance | Announced 5 working days ahead, outside 08:00–20:00 CET on working days |
| Recovery time objective (RTO) | 8 working hours |
| Recovery point objective (RPO) | 24 hours |
| Acknowledgement of a blocking incident | 4 working hours |
| Availability report | Monthly, on request |
13. Assistance during an ICT incident art. 30(2)(f)
In the event of an ICT incident affecting the service, Obligia assists you at no additional cost: notification within 4 working hours of becoming aware, regular progress updates, and a written report within 5 working days of resolution.
14. Cooperation with authorities art. 30(2)(g)
Obligia cooperates fully with your competent authorities, including by granting the access described in section 11.
15. Termination and exit strategy art. 30(2)(h), 30(3)(f)
You may terminate in the event of: a serious breach by Obligia of its legal or contractual obligations; circumstances revealing an alteration in the performance of the service; demonstrated weakness in Obligia's ICT risk management; or a request from a competent authority.
Transition period: on termination, for whatever cause, Obligia maintains the service for 90 days to allow an orderly migration, on the pricing terms then in force.
Reversibility. You may, at any time and without any intervention from Obligia, export your entire register in the xBRL-CSV format required by ITS (EU) 2024/2956. That package is usable independently of Obligia: it is the regulatory filing format itself, not a proprietary one. No customer data is held in a format that would make leaving costly.
16. Regulatory updates
Obligia integrates European Banking Authority publications within 15 working days for a validation-rule correction, 30 for a minor DPM version, 60 for a major version, and 5 for a change notified by an authority. Registers already built are not affected: each keeps the taxonomy version it was built against.
17. Sub-outsourcing of critical functions art. 30(3)(c)
Obligia does not sub-outsource any critical or important function of the service beyond the sub-processors listed in section 5. Any new engagement is notified 60 days in advance, with rights of objection and termination.
Part III — Common provisions
18. Liability
Obligia's liability is capped at the amounts paid by you during the twelve months preceding the triggering event. This cap does not apply to damage resulting from a breach by Obligia of its obligations as a processor under the GDPR, nor to gross negligence or wilful misconduct.
19. Governing law and jurisdiction
This addendum is governed by French law. Any dispute falls under the jurisdiction of the courts of Toulouse, France, subject to mandatory rules of public policy and to the protective rules applicable to a professional customer.
20. Precedence
In the event of conflict, this addendum prevails over the Terms of Service, in particular over section 7 of those terms concerning availability.