legal_

Data processing agreement

Version 1.0 — effective August 18, 2026

This Data Processing Agreement (the “DPA”) forms part of the Airdun Terms of Service or other written agreement between Airdun and Customer governing Customer's use of the Service (the “Agreement”).

Parties: AIRDUN, a French société par actions simplifiée with share capital of €1,000, registered with the Trade and Companies Register of Haute-Garonne under number 108 601 741, registered office 63 route de Laoureaux, 31590 Lavalette, France (“Airdun”), and the entity identified as the customer in the Agreement (“Customer”).

1. Definitions

“Applicable Data Protection Law” means all laws relating to the processing of Personal Data that apply to a party, including Regulation (EU) 2016/679 (“GDPR”), the French Loi Informatique et Libertés, the UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended (“CCPA”).

“Customer Personal Data” means Personal Data contained in Customer Data that Airdun processes on behalf of Customer under the Agreement. “End Customer” means a natural person who is a customer, subscriber or payer of Customer, and whose payment has failed. “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.

“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Sub-processor” and “processing” have the meanings given in the GDPR.

2. Roles of the parties

2.1 With respect to Customer Personal Data, Customer is the Controller and Airdun is the Processor. Where Customer acts as a processor on behalf of a third-party controller, Airdun acts as a sub-processor, and Customer warrants that it has the authority required to appoint Airdun.

2.2 Airdun is an independent Controller with respect to Personal Data it processes for its own purposes, including account administration, billing, security, service improvement, and communications with Customer's personnel. Such processing is governed by the Airdun Privacy Policy and not by this DPA.

2.3 The parties do not intend to act as joint controllers.

3. Scope and instructions

3.1 Airdun shall process Customer Personal Data only on documented instructions from Customer, including with regard to transfers, unless required to do so by Union or Member State law to which Airdun is subject, in which case Airdun shall inform Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.2 Customer's documented instructions comprise, and are limited to: (a) the Agreement and this DPA; (b) the configuration Customer establishes in the Service, including enabled channels, sending windows, message volume limits, tone and content settings, and any suppression lists; and (c) any further written instruction agreed by the parties.

3.3 The parties acknowledge that the Service operates autonomously within the parameters set by Customer. Airdun's automated systems determine, for each failed payment, whether to communicate with the relevant End Customer, through which enabled channel, at what time, and with what content, in each case within the constraints configured by Customer under clause 3.2(b). Customer acknowledges that this autonomous operation is the purpose of the Service and constitutes processing on Customer's instructions.

3.4 Airdun shall inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

3.5 Airdun shall not sell or share Customer Personal Data, shall not retain, use or disclose it for any purpose other than performing the Service, and shall not combine it with Personal Data received from other sources, except as permitted by Applicable Data Protection Law. For CCPA purposes, Airdun is a “service provider” and this clause constitutes the required contractual terms.

3.6 Customer Personal Data shall not be used to train, fine-tune or otherwise improve any machine-learning model made available outside the Service, whether by Airdun or by any Sub-processor. Airdun has disabled data sharing for model training with its model provider, which deletes inputs and outputs from its systems within thirty (30) days.

4. Duration and confidentiality

4.1 This DPA takes effect on the effective date of the Agreement and continues until Airdun has deleted or returned all Customer Personal Data in accordance with clause 9.

4.2 Airdun shall ensure that persons authorized to process Customer Personal Data are subject to an appropriate obligation of confidentiality, and shall limit access to those personnel who require it to perform the Service.

5. Security

5.1 Airdun shall implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects.

5.2 Airdun may update those measures provided the level of protection is not degraded.

5.3 Airdun does not access, receive or store full payment card numbers. All card data remains within Stripe's environment. Airdun processes only card metadata (last four digits, brand, expiry, issuer decline codes).

6. Sub-processors

6.1 Customer grants Airdun general written authorization to engage Sub-processors. The current list is set out in Annex III.

6.2 Airdun shall give Customer at least thirty (30) days' notice before adding or replacing a Sub-processor, by email to the notification address designated by Customer and by updating the published list.

6.3 Customer may object on reasonable data-protection grounds within that period. The parties shall discuss in good faith. If no resolution is reached, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees.

6.4 Airdun shall impose on each Sub-processor the same data-protection obligations as those set out in this DPA, and remains fully liable to Customer for the performance of each Sub-processor's obligations.

7. International transfers

7.1 Airdun shall not transfer Customer Personal Data outside the European Economic Area except where an adequacy decision applies, or subject to appropriate safeguards under Article 46 GDPR.

7.2 Where required, the parties enter into the SCCs, which are incorporated by reference: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. Annexes I, II and III of this DPA populate Annexes I, II and III of the SCCs. Clause 7 (docking) applies; under clause 9, Option 2 (general written authorization) applies with the notice period in clause 6.2; under clause 17, the governing law is French law; under clause 18, the forum is the courts of France.

7.3 For transfers subject to UK Data Protection Law, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs.

7.4 Current transfers. Application hosting and observability are located within the European Union. Database storage is located in the United Kingdom, which benefits from an adequacy decision of the European Commission; no additional safeguard is required. Model inference (Anthropic), email delivery (Postmark) and SMS and WhatsApp delivery (Twilio) are performed by providers established in the United States, for which the SCCs apply — including where the recipient is located in the European Economic Area.

8. Customer's obligations and warranties

Customer represents, warrants and undertakes that:

  • 8.1 Lawfulnessit has established and shall maintain a valid legal basis for the processing of Customer Personal Data by Airdun, including for the sending of communications to End Customers through each channel Customer enables.
  • 8.2 Transparencyit has provided End Customers with all information required by Articles 13 and 14 GDPR, including the fact that a third-party processor may contact them regarding failed payments, and the categories of recipients of their Personal Data.
  • 8.3 Communication channelsfor each channel it enables, it holds all consents, opt-ins and authorizations required by applicable law and by the relevant channel provider's policies, including prior express consent where required for SMS, opt-in and approved message templates where required by the WhatsApp Business Messaging Policy, and any consent required under Directive 2002/58/EC and its national transpositions.
  • 8.4 Geographic scope of channelsSMS delivery is technically restricted to recipients located in the European Economic Area. Airdun does not deliver SMS outside that area, and Customer may not circumvent this restriction. Any extension of SMS delivery to other jurisdictions requires a prior written amendment and Customer's express confirmation of compliance with clause 8.3.
  • 8.5 Accuracy of contact datathe contact details it makes available are those of the relevant End Customer, and are accurate and current. Customer acknowledges that sending a message to an incorrect address or number may constitute a Personal Data Breach for which Customer is responsible where it results from inaccurate data supplied by Customer.
  • 8.6 Sender identitywhere Customer delegates a subdomain or sending identity to Airdun, Customer remains the sender of record and the creditor of the underlying amount. Airdun acts solely as a technical intermediary and does not act as a debt collection agent.
  • 8.7 Contentit has reviewed and is responsible for the configuration, tone and content parameters it sets, and for the Acceptable Use provisions of the Agreement.
  • 8.8 IndemnityCustomer shall indemnify Airdun against all claims, fines and costs arising from a breach of this clause 8.

9. Data subject rights, breach, deletion

9.1 Airdun shall, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR.

9.2 If Airdun receives a request directly from a Data Subject, it shall not respond to the substance of the request, shall promptly forward it to Customer, and shall inform the Data Subject that the request has been forwarded to the responsible party.

9.3 Airdun shall, upon Customer's written request, access, correct, export or delete Customer Personal Data relating to an individual End Customer within the time limits of Article 12(3) GDPR.

9.4 Airdun shall provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the information available to it.

9.5 Personal Data Breach. Airdun shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Airdun shall not notify any supervisory authority or Data Subject on Customer's behalf unless instructed to do so in writing. Airdun's notification is not an acknowledgement of fault or liability.

9.6 Deletion and return. On termination of the Agreement, Airdun shall, at Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless retention is required by Union or Member State law. Customer may request export in a structured, commonly used, machine-readable format within thirty (30) days of termination.

9.7 Retention criteria. Airdun retains Customer Personal Data for as long as Customer's Stripe account remains connected to the Service. Airdun retains decision records for as long as necessary to audit the reliability of the Service and to investigate incidents.

9.8 Requests during and after the term. Airdun shall act on Customer's request to delete or return Customer Personal Data within one month of the request, except where retention is required by Union or Member State law.

10. Audit

10.1 Airdun shall make available all information necessary to demonstrate compliance with Article 28 GDPR.

10.2 Airdun shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Such audits shall: take place no more than once per twelve-month period (unless required by a supervisory authority or following a Personal Data Breach); be requested with at least thirty (30) days' written notice; occur during business hours; be subject to confidentiality; and not unreasonably interfere with Airdun's operations.

10.3 Airdun may satisfy an audit request by providing an up-to-date third-party certification or audit report, where one is available.

10.4 Customer shall bear the costs of any audit it initiates.

11. Liability and general

11.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

11.2 Order of precedence. In the event of conflict, this DPA prevails over the Agreement in respect of the processing of Customer Personal Data. The SCCs prevail over this DPA.

11.3 Governing law. French law, without prejudice to clause 7.2.

11.4 Changes. Airdun may update this DPA where required by Applicable Data Protection Law or to reflect a change in the Service, provided the change does not materially reduce the protection afforded to Customer Personal Data. Material changes require thirty (30) days' notice.

11.5 Language. This DPA is drafted in English. Any translation is provided for convenience; the English version prevails.

Annex I — Description of processing

Data exporter: Customer, as identified in the Agreement, acting as Controller (or processor, where applicable). Data importer: AIRDUN, 63 route de Laoureaux, 31590 Lavalette, France, acting as Processor. Activities: automated notification of failed subscription payments and restoration of payment methods. Contact: legal@airdun.com.

  • Categories of Data SubjectsEnd Customers of Customer — natural persons whose payment to Customer has failed. Personnel of Customer who use the Service.
  • Categories of Personal Dataidentity (name, email address, telephone number, country, language, time zone); billing data (subscription plan, amounts due, invoice history, currency, customer tenure, payment history); payment instrument metadata (last four digits, card brand, expiry date, issuer decline code and advice code); failure and recovery history; content of messages sent and replies received; records of automated decisions, including the composed model input.
  • Special categoriesnone. Customer shall not make special categories of Personal Data available to the Service.
  • Children's datanone. The Service is not intended to process data relating to children.
  • Frequencycontinuous, on a recurring basis, for the duration of the Agreement.
  • Nature and purposeretrieval of payment and customer records from Customer's Stripe account; automated analysis of payment failures; automated determination of whether and how to communicate with an End Customer; automated generation and delivery of messages by email, SMS and WhatsApp; measurement of outcomes; production of reporting for Customer.
  • Automated decision-makingthe Service determines autonomously, within parameters configured by Customer, whether to contact an End Customer, through which channel, at what time, and with what content. It does not determine access to any product, service or credit, does not assess creditworthiness, and does not produce legal effects concerning the End Customer.
  • RetentionCustomer Personal Data: for as long as Customer's Stripe account remains connected to the Service. Decision records: for as long as necessary to audit the reliability of the Service and investigate incidents. Deletion or return on request: within one month. See clause 9.
  • Competent supervisory authorityCommission nationale de l'informatique et des libertés (CNIL), France — Airdun being established in France.

Annex II — Technical and organizational measures

  • Encryption in transitTLS on all connections.
  • Encryption at restdatabase and backups encrypted, with an additional layer of application-level encryption for sensitive credentials.
  • Access controlauthentication delegated to a dedicated identity provider — Airdun never stores passwords. Server-side verification of workspace membership on every request, with role-based permissions.
  • Segregationeach Customer's data is logically isolated and accessible only to that Customer.
  • Least privilegeinternal access restricted to authorized personnel on a strict need-to-know basis.
  • Payment datano access to full card numbers — data remains within Stripe's environment.
  • Sub-processorsassessed before integration, and bound by equivalent data-protection obligations.
  • Incident responsedocumented procedure, with notification to Customer within seventy-two (72) hours.
  • Confidentialitypersonnel bound by confidentiality obligations.

Annex III — Sub-processors

  • Anthropic (United States)decision-making and message drafting. Identity, billing and failure history. Safeguard: SCCs.
  • Google Cloud (France, Paris)application hosting. All categories. No transfer safeguard required.
  • Firebase Hosting (Google Ireland Limited)website hosting. No Customer Personal Data.
  • Neon (United Kingdom)database storage. All categories. Safeguard: UK adequacy decision.
  • Langfuse (European Union)decision observability. All categories. No transfer safeguard required.
  • Postmark — ActiveCampaign, LLC (United States)email delivery of notifications. Identity and message content. Safeguard: SCCs.
  • Twilio (United States)SMS delivery — European Economic Area recipients only — and WhatsApp delivery. Identity and message content. Safeguard: SCCs.
  • PostHog (European Union)product analytics. Usage data of Customer personnel. No transfer safeguard required.

Stripe is not a Sub-processor under this DPA. Stripe is engaged directly by Customer, not by Airdun. Airdun accesses Customer Personal Data from Customer's Stripe account under the authorization Customer grants, and Customer's relationship with Stripe is governed by Customer's own agreement with Stripe.

Attio (CRM) and Loops (marketing email) process only Airdun's own prospect and Customer contact data, for which Airdun is a controller. They process no Customer Personal Data and are not Sub-processors under this DPA.