Data Processing Agreement
Data Processing Agreement (DPA)
Last updated: April 2026
1. Roles of the Parties
In connection with the use of the Flunter solution:
Raliance (publisher of Flunter)
Acts as a processor within the meaning of the GDPR for the Personal Data processed on behalf of the Customer.
The Customer
Acts as the controller.
Raliance also acts as a controller for its own internal processing activities:
Account management
Billing
Customer support
2. Nature and purposes of processing
Raliance processes Personal Data in connection with the provision of the Flunter product.
Nature of processing
collection, storage, organization, consultation, transmission, recording, deletion.
Main purposes
Management of user accounts
Management of prospecting campaigns
Management of calls and sales activity
Analytics and reporting features
Customer support
Product improvement
3. Categories of data processed
The data processed may include in particular:
Professional identification data
Business phone numbers
Activity data (calls, statuses)
Call transcripts and summaries
Technical data (logs, usage)
Campaign information
Important note: The Flunter solution is designed for B2B use and is not intended to process special categories of data within the meaning of Article 9 of the GDPR.
4. Raliance's obligations
Raliance undertakes to:
Process Personal Data only on documented instructions from the Customer
Ensure the confidentiality of the data processed
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk
Notify any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it
Assist the Customer, to a reasonable extent, in complying with its GDPR obligations (data subject rights, security, impact assessments)
Maintain a record of the processing activities carried out in its capacity as processor
5. Sub-processors
In connection with the provision of the Flunter service, Raliance uses the following sub-processors:
OVHcloud: primary hosting, European Union
Scaleway: storage (backups, emails), European Union
Cloudflare: security and traffic distribution, Global
Twilio: telephony and call recordings, Global
OpenAI: AI processing (transcription and generation), USA
PostHog: product analytics, USA
Stripe: payment processing, USA
Raliance undertakes to impose on its sub-processors obligations equivalent to those of this DPA.
Any addition or replacement of a sub-processor will be notified to the Customer with reasonable prior notice.
6. International transfers
Some sub-processors may be located outside the European Union.
In such cases, Raliance implements appropriate safeguards, including in particular:
The use of Standard Contractual Clauses (SCCs) approved by the European Commission
Or any other mechanism recognized as compliant under applicable regulations
7. Data security
Raliance implements appropriate security measures, including in particular:
Encryption of data in transit (TLS)
Access control to production environments
System logging and monitoring
Regular data backups
Logical isolation of data between customers
Documentation available: A more detailed description of the security measures is available in Flunter's Security Assurance Plan (PAS).
8. Retention period
Data is retained for as long as necessary for the purposes of the processing, in accordance with the Customer's instructions and applicable legal obligations.
Certain data may be retained longer in order to comply with legal obligations (in particular accounting obligations).
9. End of contract
At the end of the contract, and on the Customer's instructions, Raliance undertakes to:
Option 1: Return the data to the Customer
Option 2: Delete or anonymize the data within a reasonable period
Timeframe: Unless otherwise required by law, deletion takes place within a maximum of 30 days.
10. Data subject rights
Raliance assists the Customer, insofar as possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, objection).
11. Audit and inspection
Once a year, the Customer may audit Raliance's compliance measures, subject to:
30 days' prior written notice
The audit not affecting the security or confidentiality of other customers
And the audit remaining reasonable in scope and frequency
Compliance documents (including the PAS) may be provided in advance to limit the need for on-site audits.
12. Changes to the DPA
This DPA may be updated to reflect regulatory, technical or organizational changes.
Version in force: The version in force is the one available on Flunter's official website.