Legal information
Data Processing Agreement (DPA)
Last updated: 25 July 2026
Preamble and parties
This data processing agreement (the “DPA”) forms part of the contract concluded between: (i) the establishment, body, company, association or professional that determines the purposes and means of processing pupil or learner data by means of Tralo (the Controller); and (ii) DigitConsult, SASU, Versailles Trade and Companies Register 953 671 591, publisher of Tralo (the Processor).
It supplements the terms of use, the terms and conditions of sale and the privacy policy. For processing carried out on behalf of the Controller, the DPA prevails in the event of conflict. It takes effect when the Controller enables or uses a feature processing learner data. A signed version may be requested at contact@tralo.fr.
1. Purpose, duration and classification
DigitConsult processes the data defined in Annex 1 solely for the purpose of hosting and providing the educational functions configured by the Controller. The processing continues for the duration of Tralo’s use, and subsequently during the restoration, deletion and limited retention operations provided for in Article 11.
DigitConsult acts as a data controller for its own purposes (Author’s account, general security, subscription, billing, support and legal obligations), which are covered by the privacy policy and not by this DPA.
2. Documented instructions
DigitConsult shall process data only on the basis of documented instructions from the Controller, including in the case of an international transfer, unless required by Union or Member State law; in such cases, it shall inform the Controller in advance, unless prohibited by law. The following constitute instructions: this DPA, the main contract, the configuration selected in Tralo, actions carried out by authorised persons, and any compatible written instructions sent tocontact@tralo.fr .
If DigitConsult considers that an instruction breaches the GDPR or any applicable rule, it shall immediately inform the Data Controller and may suspend its execution until a lawful instruction is received.
3. Obligations of the Processor
DigitConsult undertakes to:
• process the data solely in order to provide Tralo and in accordance with instructions;
• ensure that authorised persons are bound by a duty of confidentiality and access only the data they need;
• implement the security measures set out in Annex 3;
• make available the information necessary to demonstrate compliance with Article 28 GDPR;
• assist the Controller with data subject rights, security, breaches, impact assessments and prior consultations;
• not sell the data, not use it for advertising and not use it to train an artificial-intelligence model on its own account.
4. Confidentiality and Authorisations
DigitConsult staff authorised to access the systems are selected on the basis of their roles, informed of their obligations and bound by confidentiality. Administrative access is restricted to the support requested, maintenance, security or compliance with a legal obligation. Access rights are withdrawn when they are no longer required.
5. Security: Article 32 of the GDPR
Taking into account the state of the art, costs, the nature of the data, the context and the risks, in particular the fact that data subjects may be minors, DigitConsult applies the measures set out in Annex 3. The level of these measures may be adjusted to maintain or improve security without substantially reducing the overall level of protection.
The measures include, in particular, the encryption of communications, regular backups of the database, authentication of Authors with optional two-factor verification, sessions using httpOnly cookies, segregation of lines of business via database access policies, separation of privileged keys, rate limiting of certain operations, random Reader session tokens and incident management procedures. No Author passwords are stored in plain text by DigitConsult.
6. Sub-contractors
The Data Controller grants general authorisation for the use of the sub-processors listed in Annex 2. DigitConsult imposes, by contract, data protection obligations on them that are substantially equivalent to those required by Article 28 and remains liable to the Controller for the fulfilment of their obligations under the terms of the GDPR.
DigitConsult shall inform the Controller of any proposed addition or replacement at least 30 days in advance by email, notification within the Service or a highlighted update to the list. The Controller may, within this period, raise a documented objection on data protection grounds. The parties shall seek a solution in good faith; failing that, the Controller may suspend the assigned function or terminate the relevant service prior to the change.
7. International transfers
The main storage of the Tralo project database and files is located in France, on a dedicated server operated by DigitConsult and hosted by OVH SAS in its Strasbourg data centre. Certain peripheral services, in particular payment, email sending and support, may however involve technical, security or assistance processing outside the European Economic Area. It should not therefore be understood that every ancillary operation remains exclusively within the European Union.
Where a transfer to a country without an adequacy decision is necessary, DigitConsult requires a mechanism compliant with Chapter V of the GDPR, in particular the European Commission’s standard contractual clauses, supplemented, where the risk so requires, by additional measures. Information on these safeguards is provided on request, subject to security secrets and confidentiality obligations.
8. Exercising rights
The Data Controller is the first point of contact for pupils, learners and legal representatives. Given the nature of the processing, DigitConsult assists the Data Controller by providing functions for consultation, data export and reset, as well as, where necessary, by taking reasonable action upon written request.
If DigitConsult receives a request directly concerning data processed on behalf of the Data Controller, it shall forward it without delay and shall not respond to the substance of the request, unless instructed to do so or required by law. The Data Controller shall provide the information necessary to identify the data without disclosing more personal data than is necessary.
9. Data breaches
DigitConsult shall notify the Controller of any data breach falling within the scope of this DPA as soon as possible after becoming aware of it. The notification shall describe, as and when the information becomes available: the nature of the incident, the categories and approximate number of data subjects and data concerned, the likely consequences, the measures taken or proposed, and a point of contact.
DigitConsult shall cooperate to enable the Controller to assess and fulfil its obligations to notify the supervisory authority and, where applicable, the data subjects. Notification by DigitConsult shall not constitute an admission of fault or liability.
10. Assistance, data protection impact assessments and prior consultation
Taking into account the information at its disposal, DigitConsult shall provide reasonable assistance to the Controller in complying with Articles 32 to 36 of the GDPR, in particular by providing a description of the service, the categories of data, the processors, the security measures and the transfers relevant to an impact assessment. The Controller remains responsible for deciding whether a Data Protection Impact Assessment (DPIA) or prior consultation is necessary for its intended use and educational context.
11. Data handover and deletion upon completion of the service
During the term of the agreement, the Controller may use the available export functions and request a reasonable additional handover in a commonly used format. At the end of the processing, DigitConsult, in accordance with the Controller’s choice communicated prior to the expiry date, shall hand over and then delete, or simply delete, the data processed on its behalf, unless there is a legal obligation to retain it.
In the absence of specific instructions, the data shall be removed from the active database in accordance with the closure cycle notified to the Data Controller. Encrypted backups shall be overwritten in accordance with the service provider’s technical cycle and shall remain isolated from routine use. The deletion shall not apply to data that DigitConsult is required to retain in its capacity as data controller, in particular contractual, security or invoicing records.
12. Information and audit
DigitConsult shall provide the information reasonably necessary to demonstrate its compliance: this DPA, security documentation, a list of sub-processors, responses to questionnaires and, where available and shareable, reports or certificates from service providers.
If these elements are insufficient, the Data Controller may request an audit, no more than once a year, except in the event of an incident, a reasonable and documented suspicion of non-compliance, a legitimate requirement under its own contract with an educational authority, or a request from a supervisory authority, with reasonable notice unless the matter is urgent. The audit shall be carried out during working hours by an independent person bound by confidentiality, without compromising the security or data of other clients. The costs shall be borne by the Data Controller, unless there is substantial non-compliance attributable to DigitConsult or a mandatory requirement to the contrary; in such cases, DigitConsult shall bear its own reasonable costs and cooperate with the corrective action plan.
13. Obligations of the Data Controller
The Controller warrants in particular that it will:
• have a legal basis for each item of data and each purpose;
• inform the data subjects in language appropriate to their age and handle their rights;
• enable an identity only where necessary and prefer a first name or a pseudonym;
• not collect sensitive, medical or biometric data, data relating to opinions, private life or offences, or data unrelated to the activity;
• protect its accounts, links and codes, manage team permissions and train authorised users;
• give only lawful instructions and maintain its own compliance documentation;
• verify that Tralo meets its requirements, in particular those of its supervising authority or its data protection officer.
14. Liability, duration and applicable law
Each party shall be liable for any damage caused by its processing in accordance with Article 82 of the GDPR. Contractual limitations shall not apply where they are prohibited by the GDPR or mandatory law. The DPA shall remain in force for as long as DigitConsult processes data on behalf of the Controller, including during the termination of the contract.
It is governed by French law, without prejudice to the powers of the competent supervisory authority and the rights of data subjects. The parties shall first seek an amicable solution atcontact@tralo.fr .
Annex 1: description of the processing
• Subject matter and purposes: enabling Readers to play educational stories and enabling the Controller to monitor the progress it has configured.
• Operations: collection, recording, hosting, organisation, consultation, display, calculation of results, export, restriction, erasure and technical backup.
• Data subjects: pupils, learners, trainees or other Readers, who may be minors.
• Data: random session identifier; story and scenes viewed; choices, errors, score, progress and timestamps; first name, surname and class only if the Controller enables them; technical data essential to the security and operation of the request.
• Prohibited data: special categories under Article 9, criminal, medical or biometric data and any information not necessary for teaching.
• Frequency: on each reading session or relevant action during use.
• Duration: for the duration of the service and until reset, deletion of the story or an instruction to end processing, followed by a limited backup cycle.
Annex 2: authorised sub-processors
• OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France: hosting of the virtual private server on which DigitConsult operates Author authentication, the PostgreSQL database, the data API, image storage and backups; server located in the OVHcloud data centre in Strasbourg, France; involvement limited to infrastructure, governed by OVH’s DPA.
• Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Cyprus: hosting and execution of the web application that receives and returns requests; technical logs and infrastructure according to the Hostinger service subscribed to.
Stripe and Resend process Author account, payment and email data for DigitConsult’s own purposes; no student data should be sent to them during normal operation. Tchao is blocked on the Reader routes and is not part of the processing chain described in this DPA. An external image hosting provider chosen by the Controller is the Controller’s own responsibility and is not selected by DigitConsult as a sub-processor.
Annex 3: Technical and organisational measures
• TLS encryption of communications;
• Author authentication and session management by DigitConsult’s dedicated service (Better Auth), with optional two-step verification and httpOnly cookies;
• passwords stored only in hashed form, never readable in clear text;
• row-level access policies and checks on membership of accounts or teams;
• privileged keys reserved for authorised server-side processing and not exposed to the client;
• random tokens to protect writes to reading sessions;
• rate limiting and controls on sensitive functions;
• input validation, format checks and restrictions on content;
• backups and restore capabilities provided according to the infrastructure plan;
• updates, hardening, dependency monitoring and review of relevant alerts;
• incident management, notification and continuity procedures;
• limited permissions, confidentiality and withdrawal of access that is no longer needed;
• the ability to export, reset statistics and delete content.