Data Processing Agreement (DPA)

Last updated: April 2026


1. Roles of the Parties

In connection with the use of the Flunter solution:

Raliance (publisher of Flunter)

Acts as a processor within the meaning of the GDPR for the Personal Data processed on behalf of the Customer.

The Customer

Acts as the controller.

Raliance also acts as a controller for its own internal processing activities:

  • Account management

  • Billing

  • Customer support


2. Nature and purposes of processing

Raliance processes Personal Data in connection with the provision of the Flunter product.

Nature of processing

collection, storage, organization, consultation, transmission, recording, deletion.

Main purposes

  • Management of user accounts

  • Management of prospecting campaigns

  • Management of calls and sales activity

  • Analytics and reporting features

  • Customer support

  • Product improvement


3. Categories of data processed

The data processed may include in particular:

  • Professional identification data

  • Business phone numbers

  • Activity data (calls, statuses)

  • Call transcripts and summaries

  • Technical data (logs, usage)

  • Campaign information

Important note: The Flunter solution is designed for B2B use and is not intended to process special categories of data within the meaning of Article 9 of the GDPR.


4. Raliance's obligations

Raliance undertakes to:

  1. Process Personal Data only on documented instructions from the Customer

  2. Ensure the confidentiality of the data processed

  3. Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk

  4. Notify any personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it

  5. Assist the Customer, to a reasonable extent, in complying with its GDPR obligations (data subject rights, security, impact assessments)

  6. Maintain a record of the processing activities carried out in its capacity as processor


5. Sub-processors

In connection with the provision of the Flunter service, Raliance uses the following sub-processors:

  • OVHcloud: primary hosting, European Union

  • Scaleway: storage (backups, emails), European Union

  • Cloudflare: security and traffic distribution, Global

  • Twilio: telephony and call recordings, Global

  • OpenAI: AI processing (transcription and generation), USA

  • PostHog: product analytics, USA

  • Stripe: payment processing, USA

Raliance undertakes to impose on its sub-processors obligations equivalent to those of this DPA.

Any addition or replacement of a sub-processor will be notified to the Customer with reasonable prior notice.


6. International transfers

Some sub-processors may be located outside the European Union.

In such cases, Raliance implements appropriate safeguards, including in particular:

  • The use of Standard Contractual Clauses (SCCs) approved by the European Commission

  • Or any other mechanism recognized as compliant under applicable regulations


7. Data security

Raliance implements appropriate security measures, including in particular:

  • Encryption of data in transit (TLS)

  • Access control to production environments

  • System logging and monitoring

  • Regular data backups

  • Logical isolation of data between customers

Documentation available: A more detailed description of the security measures is available in Flunter's Security Assurance Plan (PAS).


8. Retention period

Data is retained for as long as necessary for the purposes of the processing, in accordance with the Customer's instructions and applicable legal obligations.

Certain data may be retained longer in order to comply with legal obligations (in particular accounting obligations).


9. End of contract

At the end of the contract, and on the Customer's instructions, Raliance undertakes to:

  • Option 1: Return the data to the Customer

  • Option 2: Delete or anonymize the data within a reasonable period

Timeframe: Unless otherwise required by law, deletion takes place within a maximum of 30 days.


10. Data subject rights

Raliance assists the Customer, insofar as possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, objection).


11. Audit and inspection

Once a year, the Customer may audit Raliance's compliance measures, subject to:

  1. 30 days' prior written notice

  2. The audit not affecting the security or confidentiality of other customers

  3. And the audit remaining reasonable in scope and frequency

Compliance documents (including the PAS) may be provided in advance to limit the need for on-site audits.


12. Changes to the DPA

This DPA may be updated to reflect regulatory, technical or organizational changes.

Version in force: The version in force is the one available on Flunter's official website.