Data Processing Agreement (DPA)

Version 1.1 — 24 August 2026

To save a PDF copy: use your browser’s Print dialog and choose “Save as PDF”.

1. Purpose

This Data Processing Agreement (“DPA”) forms part of the contractual relationship between Body Graph Studio (operated by Nicolas Teysseyre, SIRET 888 766 797 00011) (“Processor”) and the customer using Body Graph Studio (“Controller”), pursuant to Article 28 of the GDPR. It applies when the Controller uses features that process personal data of end users on the Controller’s behalf, in particular the website embed widget and related lead storage.

2. Roles

For visitors who submit data through the embed widget on the Controller’s website: the Controller is the data controller; Body Graph Studio is the processor. For the Controller’s own practitioner account (login, billing, settings), Body Graph Studio acts as an independent controller as described in the Privacy Policy.

3. Subject matter and duration

The Processor provides Human Design chart calculation, hosting of submitted lead records in the Controller’s dashboard, and related technical operations for the embed widget. Processing lasts for the duration of the Controller’s active Body Graph Studio account and until deletion as set out below.

4. Nature and purpose of processing

Processing is limited to: receiving form submissions from the embed; calculating a Human Design chart; storing lead records for the Controller; displaying them in the Controller’s dashboard; rate limiting and security; and assisting the Controller with deletion or support requests. The Processor does not use embed visitor data for its own marketing.

5. Types of personal data

Depending on the Controller’s embed settings, processing may include:

  • Identity and contact data: name (optional), email (optional)
  • Birth data required for calculation: date, time, place, and derived coordinates/timezone
  • Consent metadata: timestamp, accepted wording, consent version
  • Chart summary stored with the lead: type, authority, profile, strategy
  • Technical signals used for abuse protection (e.g. IP at request time for rate limiting), not stored as lead fields

6. Categories of data subjects

Visitors and end users of the Controller’s website who use the Body Graph Studio embed widget.

7. Documented instructions

The Processor processes personal data only on documented instructions from the Controller, which include: (i) configuration of the embed (fields collected, language, branding); (ii) use of the dashboard to view/export/delete leads; and (iii) this DPA, the Terms, and the Privacy Policy. The Processor shall inform the Controller if an instruction appears to infringe GDPR.

8. Confidentiality

Persons authorised to process personal data are bound by confidentiality obligations and access is limited to what is necessary to operate and support the service.

9. Security measures

Taking into account the nature, scope and purposes of processing (Human Design chart calculation and lead storage for practitioners), the Processor implements the following technical and organisational measures:

  • Encryption in transit: HTTPS/TLS for the website, dashboard API and embed API
  • Access control: practitioner dashboard behind authenticated session; embed generate API requires a valid API key tied to an active subscription
  • Passwords stored as secure hashes (not in clear text)
  • Abuse protection: rate limiting by IP and by API key on embed generation and geocoding endpoints
  • Database hosted by Neon in the EU (AWS eu-central-1) with provider-side encryption at rest
  • Embed consent: when lead capture fields are enabled, generation requires an explicit consent checkbox; consent wording, version and timestamp are stored with the lead
  • No advertising networks and no analytics cookies inside the embed widget script itself

10. Sub-processors

The Controller authorises the Processor to use the following sub-processors necessary to operate the service:

  • Vercel — application hosting and infrastructure
  • Neon (AWS eu-central-1, Frankfurt) — database hosting for accounts, charts, and embed leads
  • Paddle — payment and subscription processing as Merchant of Record (Controller billing data; not embed visitor leads)
  • Open-Meteo — birth-place geocoding used for chart calculation

The Processor may update this list when reasonably necessary. Material changes will be reflected in the Privacy Policy and/or this DPA. Continued use of the service after notice constitutes acceptance of the updated list, without prejudice to the Controller’s right to object on legitimate grounds and terminate the relevant processing features.

11. International transfers

Transfers are limited to what is required to operate the service:

  • Neon database (including embed leads and birth data): stored in the EU (AWS eu-central-1, Frankfurt) — no intended transfer of this primary dataset outside the EEA
  • Vercel (application hosting): request processing may occur on infrastructure in the EEA and/or other regions depending on routing; where personal data is transferred outside the EEA, Vercel’s contractual safeguards apply (including Standard Contractual Clauses / other lawful transfer tools as offered by Vercel)
  • Paddle (payments): processes the Controller’s billing/subscription data as Merchant of Record and may involve transfers outside the EEA under Paddle’s own GDPR documentation; Paddle does not process embed visitor leads for the Processor
  • Open-Meteo (geocoding): receives the birth-place search string (and related lookup parameters) to return coordinates/timezone for chart calculation

12. Assistance to the Controller

Taking into account the nature of processing, the Processor assists the Controller in responding to data-subject requests (access, rectification, erasure, portability, objection) related to embed leads, via dashboard tools (view, CSV export, delete) and support at crssoweb@gmail.com. The Controller remains responsible for informing visitors and handling requests addressed to the Controller.

13. Personal data breach

The Processor will notify the Controller of a personal data breach affecting data processed under this DPA without undue delay and at the latest within 48 hours after becoming aware of it, and will provide information reasonably available to help the Controller meet its GDPR obligations (including the Controller’s possible 72-hour notification duty to a supervisory authority).

14. Deletion and return of data

Return (portability/restitution): the Controller can export embed leads at any time from the Integration dashboard as a CSV file (name, email, birth data, chart summary fields, collection timestamp). Deletion: the Controller can delete individual leads from the dashboard. At the end of the service (account deletion or written request), after the Controller has exported any data they wish to keep, personal data related to the account (including remaining embed leads) is permanently erased within a maximum of 48 hours, unless Union or Member State law requires longer retention of limited records. On written request to crssoweb@gmail.com, the Processor will confirm in writing that deletion has been completed. The Processor does not keep a separate offline archive of embed leads for its own purposes.

15. Information and audits

The Processor makes available information necessary to demonstrate compliance with this DPA (including this document, the Privacy Policy, the public sub-processor description, and reasonable written answers). On-site audits are not offered by default for this lightweight SaaS; remote information requests are the standard mechanism. Any audit shall be limited to data processed under this DPA, confidential, and shall not disrupt security or other customers.

16. Liability and precedence

This DPA is governed by French law. It prevails over conflicting terms solely on GDPR processor matters for embed visitor data. Nothing in this DPA reduces mandatory GDPR obligations. Liability otherwise follows the Terms of Service.

17. Acceptance

By enabling or using the Body Graph Studio embed widget (or by expressly accepting this DPA in the product), the Controller agrees to this DPA. A signed copy can be requested by email if required by the Controller’s internal policy.

18. Contact

Questions about this DPA: crssoweb@gmail.com

See also our Privacy Policy.