DocsSign inInstall Kastel

Data Processing Agreement (DPA)

Download the PDF (v1.3, dated 28 July 2026 - French, the governing version)
01

Parties and roles

Data controllerYou, as a Kastel Cloud customer
ProcessorPHAROS, EURL with capital of €2,000, RCS Créteil 994 201 713, registered office 8 rue Jacques Kable, 94130 Nogent-sur-Marne, France - publisher of Kastel and operator of the managed mode

Pharos acts solely on the customer's documented instructions. This agreement is annexed to the terms of service and sale, not to the software license: we are a processor of your data only in managed mode, where we host and operate your instance.

Should Pharos transfer this business to a dedicated company, the processor role would transfer under the same conditions as the main contract (see “Who you contract with” in the terms of service): none of this agreement's substantive obligations would change.

02

Object, duration and purpose

Object: hosting and operating, in an isolated instance, the Kastel software and the customer's company context, on its behalf.

Duration: that of the subscription, plus the retention window for backups and exports after termination (§12).

Sole purpose: allowing the customer to use Kastel without operating the infrastructure itself. No model training on customer data, no resale of inference, no commercial use of customer data.

03

Categories of data concerned

  • The content of your Kastel: organisation, processes, entities, decisions, company memory.
  • Employee communications you choose to ingest (email, Slack, Teams): identities, content, metadata.
  • Personal data of your employees, customers and partners, including, where applicable, special categories of data (GDPR art. 9) should you choose to ingest them - you remain the sole judge and sole responsible party.
  • Your account data: the organisation owner's email, billing data.
04

Your instructions

We process your data only on documented instruction: the order form, your instance configuration, your logged support requests, the operations you trigger from the console.

05

Security measures

  • Per-instance isolation: one engine, one database, one repository and dedicated volumes per customer, never a multi-tenant engine.
  • Secrets encrypted at rest, no plaintext secret ever committed or logged.
  • Sealed audit chain using cryptographic hashing, re-verified on every read - this makes tampering detectable, it is not an absolute guarantee of impossibility.
  • BYOK: inference runs on your own provider credentials. We never process your content through our own keys and never resell inference.
  • Software integrity attestation on every deployment, verifiable offline by you.
  • Telemetry disabled by default: no content data is sent to us without your explicit choice.
  • Backups encrypted before any upload to object storage.
06

Sub-processors

Register as of 2026-07-28:

Scaleway SASHosting of instances (Kubernetes) and encrypted backups - fr-par, France (EU)
Scaleway Container RegistryPrivate registry for the engine image - European Union
Stripe (Stripe Payments Europe, Limited)Account payment and billing - contracting entity in Ireland (EU); processing transferred to Stripe, LLC (United States) and other Stripe affiliates depending on the service, under the EU-US Data Privacy Framework and/or standard contractual clauses
Brevo (Sendinblue SAS)Transactional account emails (login links, reminders) - France (EU)

Not sub-processors of Pharos: the AI providers you connect via BYOK. You choose them, contract directly with them and supply them with your own credentials; they are your sub-processors or recipients, under your sole responsibility. The provider posture registry we publish is a declarative aid, not an audit or a guarantee on our part.

07

Assistance with your rights and data subjects' rights

Erasure: each of our erasure tools seals an event in the audit chain; after erasure, a technical check confirms the data is unfindable in search indexes, vectors, cache and the working tree. A signed deletion attestation is available.

Honest limits: your Kastel's git history is not automatically rewritten (manual purge available on request); encrypted backups retain data until their rotation expires; the source system (email, Slack…) is not modified by Kastel; whatever a BYOK AI provider has already received is governed by that provider's own retention policy, outside our scope.

Access and portability: full export at any time, in open formats, requiring no assistance from us.

08

Data breach notification

We notify you without undue delay of any data breach affecting your instance, with the elements required by the GDPR. Available forensic evidence includes the sealed audit chain and the instance manifest history.

09

Your audit rights

You, or your mandated auditor, receive on request the specification set, the executable invariant test suites, and the right to conduct black-box penetration testing against your own instance.

You may at any time verify yourself the integrity attestation, the audit chain, the erasure proof and your instance's network behaviour.

Access to the engine's source code is not granted, even under a non-disclosure agreement. Continuity in the event of Pharos's failure is addressed by a separate escrow addendum.

10

International transfers

Hosting and backups for your Kastel within the European Union (Scaleway, fr-par). No transfer outside the EU on our initiative for this data. Egress to your BYOK AI providers is your own choice: your providers, your keys, your own transfer clauses.

Documented exception: your account's billing data, which we process on our own behalf and not as a sub-processor, transits through Stripe Payments Europe, Limited (Ireland) then, depending on the Stripe service involved, to Stripe, LLC (United States) and other Stripe affiliates, under the EU-US Data Privacy Framework and/or standard contractual clauses (register in section 06 above).

11

Fate of your data at contract end

A full, verified export is produced before any deletion: you can return to self-hosting the same day, with your own secrets re-provisioned by you (secrets never travel in the archive).

Containers and volumes are deleted only after the export is verified. The final export and last backup are kept for 30 days for handover to you, then deleted, including object storage copies.

12

Governing version

The French version of this agreement prevails. Any translation is provided for information only and has no contractual value.