Data Processing Agreement (DPA)
Last updated: July 2026
This agreement (GDPR, Article 28) governs how Miravela AI processes personal data on behalf of its clients. It is the contract we sign with every client. The version below is a summary; the full, signable Word version is available here:
⬇ Download the DPA (Word, EN + FR)
The parties
Controller: the client. — Processor: ECD – Estée Creative Direction (Miravela AI), 14 rue du Mail, 75002 Paris, France.
What we commit to
- Process data only on your documented instructions.
- Confidentiality for everyone who processes the data.
- Appropriate security measures (encryption, per-client isolation, restricted access, EU hosting) — see Annex 2.
- Engage sub-processors only with 30 days’ notice (list here).
- Help you respond to data-subject rights requests.
- Notify you of any data breach without undue delay (within 48h).
- Delete or return the data at the end of the services.
- Allow audits to demonstrate our compliance.
Transfers outside the EU
Your data is hosted in the European Union. Sub-processors located outside the EU are covered by Standard Contractual Clauses (SCCs).
Annexes
The Word version contains the three annexes: (1) processing details, (2) technical and organisational measures, (3) sub-processor list.
This template is provided for convenience and does not constitute legal advice — have it reviewed by your legal counsel before signing.