Legal Information
Data Processing Agreement (DPA)
Last updated: July 25, 2026
Preamble and Parties
This data processing agreement (the “DPA”) forms part of the contract concluded between: (i) the school, body, company, association, or professional that determines the purposes and means of processing student or learner data by means of Tralo (the Controller); and (ii) DigitConsult, SASU, Versailles Trade and Companies Register 953 671 591, publisher of Tralo (the Processor).
It supplements the terms of use, the terms and conditions of sale, and the privacy policy. For processing carried out on behalf of the Controller, the DPA prevails in the event of conflict. It takes effect when the Controller enables or uses a feature processing learner data. A signed version may be requested at contact@tralo.fr.
1. Purpose, Term, and Classification
DigitConsult processes the data defined in Appendix 1 solely for the purpose of hosting and providing the educational features configured by the Controller. The processing continues for the duration of Tralo’s use, followed by the restoration, deletion, and limited retention operations provided for in Article 11.
DigitConsult acts as the data controller for its own purposes (Author account, general security, subscription, billing, support, and legal obligations), which are governed by the Privacy Policy and not by this DPA.
2. Documented Instructions
DigitConsult processes data only upon documented instructions from the Controller, including for international transfers, unless required by Union law or the law of a Member State; in such cases, it shall inform the Controller in advance, unless prohibited by law. The following constitute instructions: this DPA, the main contract, the configuration selected in Tralo, actions performed by authorized persons, and any compatible written instructions sent tocontact@tralo.fr .
If DigitConsult believes that an instruction violates the GDPR or any applicable rule, it shall immediately notify the Data Controller and may suspend its execution until a lawful instruction is received.
3. Obligations of the Processor
DigitConsult undertakes to:
• process the data solely in order to provide Tralo and in accordance with instructions;
• ensure that authorized persons are bound by a duty of confidentiality and access only the data they need;
• implement the security measures set out in Annex 3;
• make available the information necessary to demonstrate compliance with Article 28 GDPR;
• assist the Controller with data subject rights, security, breaches, impact assessments, and prior consultations;
• not sell the data, not use it for advertising, and not use it to train an artificial-intelligence model on its own account.
4. Confidentiality and Authorizations
DigitConsult personnel authorized to access the systems are selected based on their assigned tasks, informed of their obligations, and bound by confidentiality. Administrative access is limited to requested support, maintenance, security, or compliance with a legal obligation. Access privileges are revoked when they are no longer necessary.
5. Security: Article 32 of the GDPR
Taking into account the state of the art, costs, the nature of the data, the context, and the risks, particularly the fact that data subjects may be minors, DigitConsult applies the measures set forth in Annex 3. The level of these measures may be adjusted to maintain or improve security without substantially reducing the overall level of protection.
The measures include, in particular, encryption of communications, regular database backups, authentication of Authors with optional two-factor verification, sessions using httpOnly cookies, isolation of user groups via database access policies, segregation of privileged keys, rate limiting of certain operations, random Reader session tokens, and incident management procedures. DigitConsult does not store any Author passwords in plain text.
6. Subcontractors of Subcontractors
The Data Controller grants general authorization for the use of the sub-processors listed in Appendix 2. DigitConsult imposes, by contract, data protection obligations on them that are substantially equivalent to those required by Article 28 and remains liable to the Controller for the fulfillment of their obligations under the terms of the GDPR.
DigitConsult shall notify the Controller of any proposed addition or replacement at least 30 days in advance via email, a notification within the Service, or a flagged update to the list. The Controller may, within this period, raise a documented objection based on data protection grounds. The parties shall seek a solution in good faith; failing that, the Controller may suspend the assigned function or terminate the relevant service prior to the change.
7. International Transfers
The main storage of the Tralo project database and files is located in France, on a dedicated server operated by DigitConsult and hosted by OVH SAS in its Strasbourg data center. Certain peripheral services, in particular payment, email sending, and support, may however involve technical, security, or assistance processing outside the European Economic Area. It should not therefore be understood that every ancillary operation remains exclusively within the European Union.
When a transfer to a country without an adequacy decision is necessary, DigitConsult requires a mechanism compliant with Chapter V of the GDPR, specifically the European Commission’s standard contractual clauses, supplemented, where the risk so requires, by additional measures. Information regarding these safeguards is provided upon request, subject to security secrets and confidentiality obligations.
8. Exercising Rights
The Data Controller is the primary point of contact for students, learners, and legal representatives. Given the nature of the processing, DigitConsult assists the Data Controller by providing access, export, and reset functions, as well as, when necessary, by taking reasonable action upon written request.
If DigitConsult receives a request directly regarding data processed on behalf of the Data Controller, it shall forward the request without delay and shall not respond to the substance of the request, unless instructed to do so or required by law. The Data Controller shall provide the information necessary to identify the data without disclosing more personal data than is necessary.
9. Data Breach
DigitConsult shall notify the Controller of any data breach covered by this DPA as soon as possible after becoming aware of it. The notification shall describe, as information becomes available: the nature of the incident, the categories and approximate number of data subjects and data involved, the likely consequences, the measures taken or proposed, and a point of contact.
DigitConsult shall cooperate to enable the Controller to assess and fulfill its obligations to notify the supervisory authority and, where applicable, the data subjects. Notification by DigitConsult shall not constitute an admission of fault or liability.
10. Assistance, Data Protection Impact Assessment (DPIA), and Prior Consultation
Based on the information available to it, DigitConsult shall reasonably assist the Controller in complying with Articles 32 through 36 of the GDPR, in particular by providing a description of the service, data categories, processors, security measures, and transfers relevant to a data protection impact assessment. The Data Controller remains responsible for determining whether a Data Protection Impact Assessment (DPIA) or prior consultation is necessary for its intended use and educational context.
11. Data Return and Deletion Upon Completion of Services
During the term of the agreement, the Data Controller may use the available export functions and request a reasonable additional data return in a commonly used format. At the end of processing, DigitConsult, in accordance with the Data Controller’s choice communicated prior to the expiration date, shall return and then delete, or delete, the data processed on its behalf, unless there is a legal obligation to retain it.
In the absence of specific instructions, the data will be removed from the active database in accordance with the closure cycle communicated to the Client. Encrypted backups will be overwritten in accordance with the service provider’s technical cycle and will remain isolated from regular use. The deletion does not apply to data that DigitConsult is required to retain in its capacity as data controller, including contractual, security, or billing records.
12. Information and Audit
DigitConsult provides the information reasonably necessary to demonstrate its compliance: this DPA, security documentation, a list of subcontractors, responses to questionnaires, and, when available and shareable, reports or certifications from service providers.
If these elements are insufficient, the Data Controller may request an audit, no more than once a year, except in the event of an incident, a reasonable and documented suspicion of non-compliance, a legitimate requirement under its own contract with an educational authority, or a request from a supervisory authority, with reasonable notice unless the situation is urgent. The audit is conducted during business hours by an independent party bound by confidentiality, without compromising the security or data of other clients. The costs are borne by the Data Controller, unless there is substantial non-compliance attributable to DigitConsult or a mandatory requirement to the contrary; in such cases, DigitConsult bears its own reasonable costs and cooperates with the corrective plan.
13. Obligations of the Data Controller
The Controller warrants in particular that it will:
• have a legal basis for each item of data and each purpose;
• inform the data subjects in language appropriate to their age and handle their rights;
• enable an identity only where necessary and prefer a first name or a pseudonym;
• not collect sensitive, medical, or biometric data, data relating to opinions, private life, or offenses, or data unrelated to the activity;
• protect its accounts, links, and codes, manage team permissions, and train authorized users;
• give only lawful instructions and maintain its own compliance documentation;
• verify that Tralo meets its requirements, in particular those of its supervising authority or its data protection officer.
14. Liability, Term, and Governing Law
Each party is liable for damages caused by its processing in accordance with Article 82 of the GDPR. Contractual limitations do not apply where they are prohibited by the GDPR or mandatory law. This DPA remains in effect as long as DigitConsult processes data on behalf of the Controller, including during contract termination procedures.
This agreement is governed by French law, without prejudice to the powers of the competent supervisory authority and the rights of data subjects. The parties shall first seek an amicable resolution atcontact@tralo.fr .
Appendix 1: Description of the Processing
• Subject matter and purposes: enabling Readers to play educational stories and enabling the Controller to monitor the progress it has configured.
• Operations: collection, recording, hosting, organization, consultation, display, calculation of results, export, restriction, erasure, and technical backup.
• Data subjects: students, learners, trainees, or other Readers, who may be minors.
• Data: random session identifier; story and scenes viewed; choices, errors, score, progress, and timestamps; first name, last name, and class only if the Controller enables them; technical data essential to the security and operation of the request.
• Prohibited data: special categories under Article 9, criminal, medical, or biometric data and any information not necessary for teaching.
• Frequency: on each reading session or relevant action during use.
• Duration: for the duration of the service and until reset, deletion of the story, or an instruction to end processing, followed by a limited backup cycle.
Appendix 2: Authorized Sub-Processors
• OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France: hosting of the virtual private server on which DigitConsult operates Author authentication, the PostgreSQL database, the data API, image storage, and backups; server located in the OVHcloud data center in Strasbourg, France; involvement limited to infrastructure, governed by OVH’s DPA.
• Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Cyprus: hosting and execution of the web application that receives and returns requests; technical logs and infrastructure according to the Hostinger service subscribed to.
Stripe and Resend process Author account, payment, and email data for DigitConsult’s own purposes; no student data should be sent to them during normal operations. Tchao is blocked on the Reader routes and is not part of the processing chain described in this DPA. An external image hosting provider chosen by the Data Controller is under the Data Controller’s sole responsibility and is not designated by DigitConsult as a subprocessor.
Appendix 3: Technical and Organizational Measures
• TLS encryption of communications;
• Author authentication and session management by DigitConsult’s dedicated service (Better Auth), with optional two-step verification and httpOnly cookies;
• passwords stored only in hashed form, never readable in clear text;
• row-level access policies and checks on membership of accounts or teams;
• privileged keys reserved for authorized server-side processing and not exposed to the client;
• random tokens to protect writes to reading sessions;
• rate limiting and controls on sensitive functions;
• input validation, format checks, and restrictions on content;
• backups and restore capabilities provided according to the infrastructure plan;
• updates, hardening, dependency monitoring, and review of relevant alerts;
• incident management, notification, and continuity procedures;
• limited permissions, confidentiality, and withdrawal of access that is no longer needed;
• the ability to export, reset statistics, and delete content.