This data processing agreement (DPA) describes how Noaya processes personal data on behalf of the client brand, in accordance with Article 28 of the GDPR. It is part of the contract and applies to every customer, from the free trial on, whatever the plan. It complements the Terms and the privacy policy.
1. The roles
The client brand is the data controller: it decides which tools to connect and why. Noaya is the processor: it processes data only to provide the service, on the brand's instructions, and for nothing else.
2. Data processed
Noaya processes only the data needed for its 8 AI specialists to work:
- founder account data (email, first name, last name, organization);
- business metadata from read-only connected integrations (orders, products, stock, ad spend, analytics sessions);
- content of conversations with Noaya and her specialists;
- long-term memory voluntarily saved by the brand.
No data is resold, shared for advertising purposes or used to train a model. Noaya never contacts the brand's end customers.
3. Subprocessors
Noaya relies on the subprocessors below, the same ones published in the privacy policy. Every transfer outside the European Union is governed by the European Commission's Standard Contractual Clauses (SCC) and, where applicable, the EU-US Data Privacy Framework (DPF).
- Supabase (Postgres database + Storage), European Union (eu-west-1, Ireland).
- Vercel Inc. (web hosting), United States, DPF + SCC.
- Anthropic (Claude LLM for the agents), United States, DPA + SCC. 30-day retention on Anthropic's side. No data is used to train the models.
- OpenAI (Voice image generation via gpt-image-1), United States, DPA + SCC. No persistent storage on OpenAI's side, no training.
- Stripe Payments Europe (payments), European Union (Ireland).
- Resend (transactional emails), European Union, DPA in place.
This list is kept up to date in the privacy policy. If a subprocessor is added or replaced, the list is updated before it goes live, and you can object by writing to privacy@noaya.app.
4. Retention periods
The DPA applies for the entire subscription period, free trial included. After that:
- Integration data: cascading deletion within 30 days after disconnecting a tool or cancelling.
- Account data: deleted within 30 days of cancellation.
- Technical logs: 30 days.
- Accounting records: 10 years (French legal obligation).
5. Security measures
The measures in place to protect the data:
- HTTPS on all communications;
- integration tokens encrypted at rest;
- strict isolation per organization (Row-Level Security on the database);
- hashed passwords, secure sessions;
- no human read access without an explicit support request or a legal obligation; access is logged;
- everyone authorized to access the data is bound by confidentiality.
6. Assistance and incidents
Noaya helps the brand respond to GDPR requests from its own customers (access, erasure, portability) when they concern data processed through the service.
In the event of a data breach, the brand is notified without undue delay after discovery, with the information needed to meet its own obligations (GDPR Article 33).
7. Your rights and signed copy
You can exercise your rights of access, rectification, erasure, restriction, objection and portability at any time (GDPR Articles 15 to 22).
A signed copy of the DPA can be requested by any customer, whatever the plan: write to privacy@noaya.app. On the Custom plan, the DPA is negotiable and custom security annexes can be added.