Version: 2.1 – Last updated: June 18, 2026.
These legal notices are written in French. Any translation, particularly into English, is provided for informational purposes only. In case of any discrepancy, ambiguity, or difficulty in interpretation between the French version and a translated version, the French version alone shall prevail.

Data Processing Agreement

Purpose and Scope of the Agreement

This Data Processing Agreement (« Agreement » or DPA) sets out the terms under which Ask Technologies SAS (hereinafter « Ask Technologies » or the Processor), in its capacity as a provider of generative AI chatbot solutions, processes personal data on behalf of its client (hereinafter the Client or Controller) in connection with the services provided by Ask Technologies. This Agreement forms an integral part of the service contract between Ask Technologies and the Client and aims to ensure compliance with Regulation (EU) 2016/679, known as the General Data Protection Regulation (GDPR). It complies with the requirements of Article 28(3) of the GDPR, by specifying, in particular, the subject matter, duration, nature, and purpose of the processing operations, the types of personal data concerned, the categories of data subjects, as well as the obligations and rights of each party​.

By default, Ask Technologies' services do not require any personal data collection: no personal data is recorded or processed without the end-users' knowledge when the Ask Technologies chatbot is used without specific Client configuration. The chatbot can therefore be deployed without personal data by default. However, depending on the use and configurations made by the Client, personal data may potentially be processed via the Ask Technologies platform. This DPA applies exclusively to the processing of personal data carried out by Ask Technologies as the Client's data processor. Data processing for which Ask Technologies determines the purposes and means (e.g., Client registration data for the administration platform) does not fall under this Agreement and is covered by Ask Technologies' privacy policy, where applicable.

Ask Technologies SAS is a simplified joint-stock company under French law, registered with the Paris Trade and Companies Register under number 879 858 876, with a share capital of €1,759.28, and its registered office located at 4 PLACE ALBERT EINSTEIN 56000 VANNES FRANCE. Ask Technologies operates primarily in France and plans to expand its activities within the European Union, in compliance with applicable data protection legislation. The  refers to the entity (company, administration, or other organization) that has subscribed to Ask Technologies' services and acts as the data controller for the data it chooses to process via these services.

The Client and Ask Technologies are hereinafter collectively referred to as « the Parties ».

Definitions

For the purposes of this Agreement, the following terms shall have the meanings set forth below, whether used in the singular or plural:

Personal Data (or Personal Data): any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.

Processing (or Process/Processed): any operation or set of operations performed on Personal Data (collection, storage, consultation, use, transmission, erasure, etc.), whether or not by automated means, as defined in Article 4(2) of the GDPR.

Data Controller: the natural or legal person, public authority, agency, or any other body which, alone or jointly, determines the purposes and means of the Processing. Under this Agreement, the Client is the Data Controller of the Personal Data it decides to process via Ask Technologies' services.

Data Processor : the natural or legal person who Processes Personal Data on behalf of the Data Controller. In this instance, Ask Technologies acts as the Data Processor for the services covered by this DPA.

Sub-processor (or Subsequent Processor or Secondary Processor): any third-party entity engaged by the Processor (Ask Technologies) to perform specific processing activities on behalf of the Data Controller. Authorized Sub-processors under this Agreement are listed in the Authorized Sub-processors section below.

Services: the SaaS platform, generative AI chatbots, and, more generally, the software solutions provided by Ask Technologies to the Client, as described in the main agreement binding the Parties (general terms of service, commercial contract, or any equivalent document).

Applicable Data Protection Regulations: GDPR, as well as any applicable national law or regulation (such as the amended French Data Protection Act no. 78-17) and any other current text governing the protection of Personal Data applicable to the Processing operations covered by this Agreement.

Term of Agreement

This DPA enters into force on the effective date of the main agreement between Ask Technologies and the Client or on the date of the Client's acceptance of this DPA (whichever is later). It shall remain in effect for the entire duration of the contractual relationship during which Ask Technologies processes Personal Data on behalf of the Client. In practice, the Agreement covers any period during which Ask Technologies holds or processes the Client's Personal Data, including potentially after the termination of the main agreement, until the complete return or deletion of the data in accordance with the Client's instructions and the provisions of this DPA.

The obligations set forth in this Agreement (particularly regarding confidentiality and security) survive its expiration or termination as long as Ask Technologies retains Client Personal Data in accordance with the "Data Disposition" section below, or as long as required by law.

Description of the relevant processing

This DPA applies solely to the Processing of Personal Data carried out by Ask Technologies in connection with the Services provided to the Client. The characteristics of this Processing are as follows:

Purpose of Processing – Objective: Ask Technologies provides a generative artificial intelligence chatbot platform and associated services, enabling the Client to configure and deploy conversational agents (chatbots) that answer end-user questions. The sole purpose of the processing is to ensure the proper execution of the Services requested by the Client (e.g., responding to user queries via the chatbot, accessing a knowledge base configured by the Client, providing technical support, etc.), in accordance with the Client's instructions and the terms of the main contract. No other use of Personal Data by Ask Technologies is made without the Client's instruction or authorization.

Nature of Processing Operations: Ask Technologies performs data storage, organization, algorithmic analysis (AI engine response generation), transmission, and deletion operations, as required by the Service. By default, user interactions with the chatbot are not retained by Ask Technologies. Therefore, Ask Technologies does not permanently store conversation content, unless the Client explicitly enables a logging or recording feature. In the latter case, data retention is carried out according to the terms determined by the Client (for example, a configurable retention period via the administration interface or specific instructions).

Types of Personal Data Processed: By design, the Service can be used without processing identifiable Personal Data. However, depending on its use, the Data processed may include any type of data that the Client chooses to integrate into the chatbot or the underlying knowledge base. This may include identification data (e.g., name, surname, end-user pseudonym), contact details (email address, phone number), professional data (position, department), data provided through questions asked to the chatbot (which could contain personal information inserted by the end-user), or any other category of data that the Client decides to use via the Service. By default, none of this data is required to use the Service, and any inclusion of Personal Data is solely at the Client's discretion. The Client is advised to avoid submitting special categories of data (sensitive data as defined by Article 9 of the GDPR, such as health data, biometric data, etc.) to the Service, unless necessary and with appropriate additional safeguards.

Categories of Data Subjects : The individuals whose data may be processed as part of the Service are determined by the Client. These may primarily include (i) the end-users of the chatbot deployed by the Client (e.g., customers, citizens, or employees asking questions to the chatbot and potentially providing their information in their queries), (ii) the Client's employees, collaborators, or agents whose data might appear in the knowledge base or in the content used by the chatbot to formulate responses, and (iii) more generally, any individual whose data would be integrated by the Client into the content utilized via the Service. As Ask Technologies has no direct contact with the data subjects (chatbot end-users or other third parties whose data is processed), it is the Client's responsibility to provide the required legal information to these individuals and, where applicable, to obtain the appropriate legal bases (e.g., consent) for the Processing carried out via the Service.

Processing Duration – Retention: Ask Technologies processes the Client's Personal Data only for the duration necessary to provide the Services and in accordance with the Client's instructions and this DPA. Unless otherwise instructed, Personal Data processed on an ad-hoc basis via the chatbot (e.g., the content of a question asked) is not persistently stored (no permanent storage by Ask Technologies, excluding anonymized technical logs), unless the Client activates retention options (such as conversation recording or data archiving). In any event, data will not be retained by Ask Technologies beyond the term of the service contract, subject to applicable legal retention obligations. The terms for returning or deleting data upon termination of the Services are specified in the section Data Disposition of this Agreement.

Ask Technologies' Obligations as a Processor

In accordance with the GDPR, Ask Technologies is committed to complying with the following obligations when processing Personal Data on behalf of the Client:

Processing on Documented Instructions : Ask Technologies will only process the Client's Personal Data based on the Client's documented instructions, including with regard to data transfers to a third country. The Client's use of the Services, in accordance with the main agreement and Ask Technologies' documentation, constitutes the Client's instruction to Ask Technologies to process the data for the specified purposes. Ask Technologies will refrain from any use, access, or processing of the Client's Personal Data for other purposes (including its own, commercial, or marketing purposes) without the Client's prior authorization. If Ask Technologies believes that a Client instruction infringes the GDPR or other applicable data protection provisions, it will inform the Client without undue delay (unless legally prohibited).

Employee Confidentiality : Ask Technologies guarantees that individuals authorized to process the Customer’s Personal Data (employees, contractors, and subsequent subcontractors) are bound by the strictest confidentiality. All individuals with access to the data are subject to an appropriate legal or contractual confidentiality obligation. Ask Technologies ensures that access to Personal Data is limited solely to employees and agents who need it to perform the Service, and that such access is regularly reviewed. Ask Technologies’ Data Protection Officer (DPO) can be reached at dpo@polaria.ai for any questions regarding data protection under this Agreement.

Data Security : Ask Technologies implements appropriate technical and organizational measures to protect Personal Data against destruction, loss, alteration, unauthorized disclosure, or unauthorized access, commensurate with the risk. Specifically, Ask Technologies applies industry best security practices: encryption of data in transit (secure communications via SSL/TLS) and, where applicable, encryption of data at rest on servers or databases. Data access is strictly controlled and logged, so that only duly authorized Ask Technologies personnel (or the Client, in the case of dedicated environments) can access necessary information, in compliance with confidentiality commitments. Ask Technologies has also implemented perimeter protection and proactive monitoring systems to prevent intrusions and malware (firewalls, intrusion detection/prevention systems, etc.), and regularly updates its systems to promptly address any known vulnerabilities. Overall, Ask Technologies ensures that the infrastructure used for the Service is secure and compliant with the state of the art in data protection (including by utilizing certified and reliable data centers, see Authorized Sub-processors section).

Privacy by Design: Ask Technologies adheres to the principles of Privacy by Design and by Default. The Services are designed to minimize the collection of Personal Data (no personally identifiable data is required by default to use the chatbot). Ask Technologies integrates data protection from the design phase and throughout the product and service lifecycle.

Sub-processors: Ask Technologies only engages Sub-processors (secondary sub-contractors) for processing activities with the Client's authorization. The Client hereby grants Ask Technologies general authorization to engage the Sub-processors listed in the Authorized Sub-processors section below, provided that Ask Technologies ensures each of these sub-processors complies with data protection obligations equivalent to its own (via a sub-processing agreement compliant with Article 28 of the GDPR). Ask Technologies will inform the Client of any planned changes regarding the addition or replacement of sub-processors within a reasonable timeframe, so that the Client has the opportunity to raise objections for legitimate reasons. In the absence of an objection raised within the specified timeframe, the new sub-processor will be deemed accepted.

Assistance with Client's Obligations: Ask Technologies provides assistance to the Client to enable it to comply with its own obligations under the Applicable Regulations. Specifically, Ask Technologies assists the Client, through appropriate technical and organizational measures, in fulfilling requests from data subjects exercising their rights (access, rectification, erasure, objection, etc.) received by the Client, where the Client cannot address them itself through the provided functionalities. Similarly, Ask Technologies will provide the Client with the necessary assistance to conduct, where applicable, Data Protection Impact Assessments (DPIAs) related to the Processing carried out within the scope of the Service, and to carry out any necessary prior consultations with the competent supervisory authority, insofar as such information is in Ask Technologies' possession. This assistance is provided upon the Client's written request and may include providing documentation on security measures, the technical organization of processing operations, and, more generally, any information useful to the Client for demonstrating the processing's compliance with legal obligations.

Data Breach Notification: Ask Technologies shall notify the Client of any security breach affecting the Personal Data processed (personal data breach as defined in Article 4(12) of the GDPR) as soon as it becomes aware of it. This notification shall be made without undue delay (and if possible within 48 hours of incident detection), accompanied by all necessary documentation to enable the Client, if necessary, to notify this breach to the data protection authority and/or the data subjects concerned, in accordance with Articles 33 and 34 of the GDPR. Ask Technologies shall communicate to the Client the available information on the nature of the breach, the categories and volume of data potentially affected, the probable consequences, as well as the corrective measures already taken or envisaged to remedy the breach and mitigate its effects. Ask Technologies undertakes to promptly investigate any breach and to take appropriate measures to restore the integrity, security, and confidentiality of the data. It shall cooperate in good faith with the Client to facilitate compliance with legal obligations resulting from the breach.

Data Disposition upon Contract Termination: Upon expiration or early termination of the service contract, Ask Technologies, at the Client's discretion and upon their instruction, will completely delete all Personal Data processed on behalf of the Client, or return all such data to the Client in a structured and commonly used format, and then delete all existing copies from its systems (unless legally required otherwise). Unless the Client provides specific contrary instructions before the contract ends, Ask Technologies will, by default, securely delete any residual data still in its possession after a reasonable period following contract termination. Ask Technologies may retain a copy of the data if required by Union or Member State law (for example, for evidentiary purposes or to comply with accounting obligations); in which case, Ask Technologies guarantees that such data will remain subject to appropriate protection measures and will no longer be actively processed except to fulfill the relevant legal requirements.

Documentation and Audit Rights: Ask Technologies will provide the Client with all reasonable information necessary to demonstrate compliance with the obligations set forth in this DPA and to enable compliance audits. In practice, Ask Technologies may provide the Client, upon request, with its security and confidentiality documentation, including internal policies, and third-party certifications or audits, where applicable, attesting to the level of protection implemented. The Client is entitled to conduct or have conducted, a maximum of once per year (unless otherwise required by law or in the event of a proven incident), an audit of Ask Technologies' activities related to the Processing performed on its behalf. This audit must be conducted by the Client or an independent third party mandated by the Client, with at least 15 business days' prior notice, and must not significantly disrupt Ask Technologies' operations. The scope of the audit will be limited to facilities, systems, and documents relevant to the Client's data. Ask Technologies will cooperate in good faith with the audit by providing access to the requested information, subject to appropriate confidentiality measures. The costs of the audit shall be borne by the Client, unless the audit reveals a serious breach by Ask Technologies of its obligations under this Agreement.

Client's Obligations as Data Controller

The Client, in its capacity as Data Controller, undertakes to comply with the following obligations in connection with the use of Ask Technologies' Services:

Compliance and Legal Basis : The Client warrants that the Processing of Personal Data entrusted to Ask Technologies is carried out in compliance with the Applicable Regulations. It is notably the Client's responsibility to determine and document a valid legal basis for each item of Personal Data processed through the Service (e.g., consent of the data subject, legitimate interest, legal obligation, or performance of a contract) and to ensure that the purposes pursued are authorized by law. The Client declares and warrants that it is duly authorized to process and have processed the Personal Data concerned and that it has completed all necessary formalities (including, where necessary, obtaining the consent of the data subjects for the use of their data within the scope of the Service).

Data Subject Information: The Client is responsible for providing data subjects with the information required by Articles 13 and 14 of the GDPR concerning the Processing of their data via Ask Technologies' services. The Client must ensure that end-users are clearly informed of the chatbot's presence and that their interactions may be processed automatically, as well as, where applicable, any collection of personal data concerning them. For example, if the Client enables logging of chatbot conversations that include personal information, they must notify users in advance and, if necessary, obtain their consent.

Data Quality and Proportionality: The Client is responsible for the data they integrate into the Service. They undertake to provide Ask Technologies only with Personal Data that is accurate, up-to-date, and strictly necessary for the purposes of using the Service. The Client is prohibited from misusing Ask Technologies' Service to massively collect or process data unrelated to the chatbot's purposes, and undertakes not to store illicit or sensitive data disproportionately via Ask Technologies' platform without appropriate measures.
Service Configuration: Insofar as the Service offers configuration options impacting data protection (e.g., setting a conversation retention period, etc.), the Client is responsible for the configuration choices made via the administration interface. It is the Client's responsibility to configure the Service in accordance with data minimization principles and to limit the retention of personal data to what is strictly necessary. Ask Technologies provides tools and settings that allow the Client to maintain control over the data (content deletion, knowledge export, etc.), which the Client must use to comply with their regulatory obligations.

Client-Side Security: The Client undertakes to use Ask Technologies' Service in a secure technical environment. Specifically, the Client must maintain the confidentiality of login credentials for the Ask Technologies platform and ensure that access to their instance is secure. The Client shall promptly notify Ask Technologies in the event of suspected unauthorized access or compromise of their credentials, to enable Ask Technologies to take appropriate measures. Furthermore, if the Client collects data directly from users to input into the Service (e.g., via forms connected to the chatbot), it is their responsibility to ensure the security of this collection and to transmit the data to Ask Technologies using encrypted and secure communication methods.

Cooperation: The Client will cooperate in good faith with Ask Technologies to facilitate compliance with this DPA. Specifically, the Client will provide Ask Technologies with information regarding the processing activities it intends to carry out via the Service if necessary for Ask Technologies to fulfill its own obligations (e.g., if a data protection impact assessment is conducted, the Client will share the relevant sections with Ask Technologies). Similarly, in the event of a request or inquiry from a data protection authority concerning the Service, the Client will involve Ask Technologies as appropriate to obtain the technical information relevant to Ask Technologies.

Compliant Use : The Client shall ensure that its use of Ask Technologies' Services remains compliant with the terms and purposes stipulated in the contract. The Client undertakes not to request Ask Technologies to process Personal Data in a manner that would violate Applicable Regulations. If the Client issues a Processing instruction to Ask Technologies, it must be lawful and necessary for the performance of the Services. Should there be any doubt regarding the legality of an instruction or a particular use of the Service, the Client agrees to consult Ask Technologies and, if necessary, the competent data protection authority before proceeding.

Authorized Sub-processors (List of Subsequent Sub-processors)

Ask Technologies engages carefully selected sub-processors to assist in the provision of its Services. These sub-processors act solely on Ask Technologies' instructions and provide sufficient guarantees regarding the implementation of GDPR-compliant data protection measures. The Client expressly authorizes Ask Technologies to engage the following Sub-processors for the processing carried out on its behalf:

OVHcloud (OVH SAS, France) – Main cloud host. OVHcloud provides the hosting infrastructure on which Ask Technologies' applications and data are deployed. The servers are located in France. Ask Technologies notably hosts its software suite on OVH's secure infrastructure, with a focus on sovereignty and security.

Dassault Systèmes (Outscale) (France) – Alternative cloud provider. Ask Technologies also leverages 3DS Outscale (Dassault Systèmes' cloud subsidiary) for hosting certain dedicated instances or environments, particularly for clients requiring a certified level of  (Outscale notably holds the SecNumCloud qualification issued by ANSSI). Outscale's data centers used by Ask Technologies are located in France. This subcontractor is subject to the same security and compliance requirements as OVH.

Sarbacane Software (France) – Transactional email sending solution. Ask Technologies uses the Sarbacane platform (also known as Mailify) to send emails related to the Services, particularly emails sent by the app.polaria.ai application (e.g., confirmation emails, user notifications, password resets, etc.). In this context, the email addresses of the Client's end-users or administrators, as well as the necessary message content (email text, links), are transmitted to Sarbacane's servers for dispatch. Sarbacane Software SAS is a French company, and the email data processed is hosted on servers located in France. This sub-processor is committed to complying with GDPR regulations (Sarbacane has an internal DPO and an active data protection policy compliant with GDPR). No data is transmitted by Sarbacane to third parties, except for technical routing necessities via messaging operators.

Mistral AI SAS (France) – Large Language Model (LLM) provider. Ask Technologies uses Mistral AI models to power the chatbot's response generation engine. Mistral AI SAS is a French company headquartered at 15 rue des Halles, 75001 Paris. Processing is carried out in France, in compliance with GDPR. Mistral AI does not store data transmitted during inferences and does not use customer data to train its models.

Ask Technologies commits not to add or replace any sub-processor without prior notification to the Client. In the event of a subsequent sub-processor change, Ask Technologies will notify the Client through any agreed contact method (e.g., email or publication on the corporate website) at least 15 days before the effective change. The Client has the right to raise a reasoned objection if, in its opinion, the proposed new sub-processor poses a substantial risk to the protection of its data. In the event of a legitimate and unresolved objection, the Client may terminate the affected service in accordance with the terms of the main contract. In all cases, Ask Technologies remains fully responsible to the Client for its sub-processors' proper fulfillment of their data protection obligations. Each subsequent sub-processor is bound to Ask Technologies by a data processing agreement compliant with Article 28 of the GDPR, including security, confidentiality, and instruction compliance obligations equivalent to those in this DPA.

Data Localization and International Transfers

Ask Technologies prioritizes an infrastructure entirely located in France for the processing and storage of Client Personal Data. By default, data is hosted in France, including via OVHcloud or Dassault Systèmes Outscale. As a result, Personal Data entrusted to Ask Technologies remains in France.

Ask Technologies confirms that as of the date of signature of this DPA, no massive or systematic transfer of Client Personal Data to non-EU countries is performed other than for the specific uses mentioned. If the Client wishes for a different data localization, they may request it from Ask Technologies, which will endeavor to propose a suitable solution (potentially via an optional offering). Ask Technologies undertakes to inform the Client if, during the performance of the contract, it were to consider transferring Client Personal Data outside the EU under conditions not provided for in this Agreement.

Data Subject Rights and Processor Assistance

Given the nature of the Processing, Ask Technologies will assist the Client in fulfilling its obligation to respond to requests for exercising data subject rights (right of access, rectification, erasure, objection, restriction, data portability, etc.).

If a data subject directly submits a request to Ask Technologies concerning their Personal Data processed via the Services (which would be rare, as Ask Technologies is not in direct contact with the Client's end-users), Ask Technologies will forward this request to the Client as soon as possible without responding to it directly (unless otherwise instructed by the Client or if Ask Technologies has a direct legal obligation to do so). It is the Client's responsibility, as the Data Controller, to provide the appropriate follow-up to the request. Ask Technologies will assist the Client, upon request, by providing the necessary information and tools to respond to the request (for example, by extracting relevant data or applying an erasure measure).

-Through the Service's administration interface or upon request to Ask Technologies support, the Client can access, rectify, or delete Personal Data under their control. Ask Technologies will implement the actions requested by the Client regarding the data (e.g., deletion of a set of content containing personal data, restoration of a specific record, etc.) without undue delay and in accordance with the documented instructions received.

-If the complexity of a data subject rights request requires specific technical assistance from Ask Technologies (e.g., data extraction from a backup, specific log searches), Ask Technologies will endeavor to provide this assistance. Depending on the resulting workload, Ask Technologies and the Client may agree on financial terms to cover the reasonable cost of this exceptional assistance, in accordance with Article 12(5) of the GDPR (which allows for the charging of reasonable fees for manifestly unfounded or excessive requests, or for additional requests).

In addition, Ask Technologies will assist the Client in ensuring compliance with other obligations set forth in Articles 32 to 36 of the GDPR (security of processing, breach notification, impact assessments, and prior consultation). Provisions relating to security and data breaches are set out in this Agreement. Regarding Data Protection Impact Assessments (DPIA), Ask Technologies will provide the Client, upon request, with all information related to the Services necessary for conducting the DPIA (including technical description of processing operations, security measures applied, sub-processors involved, etc.). Should the supervisory authority require a prior consultation before the use of the Service, Ask Technologies will assist the Client by providing the information required by that authority.

In summary, Ask Technologies is committed to actively cooperating with the Client to enable the Client to meet its obligations with respect to data subjects and data protection authorities. All such assistance is provided to the extent of the information available to Ask Technologies and provided that the Client does not itself have the means to meet these obligations.

Data Breach Notification

In the event of a personal data breach (accidental or unlawful) concerning the Personal Data processed on behalf of the Client, Ask Technologies will notify the Client of such breach without undue delay, and no later than within 48 hours after becoming aware of it. This notification will include, where possible, the following information:

-the nature of the breach (e.g., unauthorized access, loss, disclosure, alteration, or destruction of data) and, if available, the categories and approximate number of data subjects and data records affected;
-the probable consequences of the breach for the data subjects (potential privacy impacts, risks incurred);
-the technical and organizational measures already implemented by Ask Technologies before the breach (e.g., encryption) likely to limit its impact, as well as the immediate corrective measures taken or proposed to remedy the breach (e.g., isolation of the affected system, data restoration, security patches);
-the name and contact details of the contact person at Ask Technologies from whom further information can be obtained.

Ask Technologies will provide the Client with regular updates regarding the ongoing investigation and actions taken, as additional information about the incident becomes available. It is then the Client's responsibility, as the Data Controller, to assess whether the breach must be notified to the competent supervisory authority and/or the data subjects concerned, in accordance with Articles 33 and 34 of the GDPR. Ask Technologies will assist the Client in this process if necessary, by providing any required additional information or incident reports.

Ask Technologies will internally document any data breach, recording the facts relating to the breach, its effects, and the measures taken, in accordance with Article 33(5) of the GDPR. Upon request, Ask Technologies will make this documentation available to the Client and the supervisory authority to enable verification of compliance with legal obligations.

Data Disposition After Contract

Upon completion of the Services involving the Processing of Personal Data (including, but not limited to, in the event of termination or expiration of the contract between Ask Technologies and the Client, or if a Service functionality is discontinued), the Client's Personal Data will be handled as follows:

Data Retrieval: Upon the Client's express request, submitted no later than the contract termination date, Ask Technologies will return to the Client all Personal Data processed on its behalf. This return may take the form of one or more files extractable via the administration interface or provided by Ask Technologies (for example, export of knowledge bases, any saved conversation logs, etc.), in a structured, commonly used, and machine-readable format. Ask Technologies will also provide, upon request, the documents or materials necessary for understanding the returned data (e.g., data dictionary if applicable).

Data Deletion: Once data restitution has been completed (or if the Client has not requested data restitution upon contract expiry), Ask Technologies will proceed with the complete and definitive deletion of the Client's Personal Data still in its possession. This deletion includes the erasure of data from active databases, as well as the purging of backup copies and logs, within reasonable operational timeframes. Ask Technologies undertakes that the Client's data will no longer be processed for any purpose whatsoever from the contract's termination, and that it will be securely removed from all its production and backup systems (unless legally mandated otherwise). If, for technical reasons, the immediate deletion of certain backup data is not possible, Ask Technologies guarantees that this residual data will be protected by appropriate security measures and will be destroyed according to the pre-established maximum retention cycles.

Proof of Destruction: At the Client's request, Ask Technologies shall provide written confirmation that the deletion of Personal Data has been successfully carried out in accordance with the terms of this Agreement. This confirmation may take the form of a certificate of destruction or an official email from Ask Technologies' technical manager or Data Protection Officer, once all erasure operations have been completed.

Legal Exception: If applicable European Union or Member State law requires Ask Technologies to retain certain Personal Data beyond the termination of the contract (e.g., legal archiving, retention of billing data, evidence for litigation purposes), Ask Technologies will inform the Client of this obligation. In such a case, Ask Technologies commits to processing this retained data solely to comply with applicable law and for no other purpose, and to delete it immediately upon the expiration of the statutory retention period.

The Client is advised to retrieve, before the end of the contract, any data they wish to retain, as Ask Technologies is not obligated to store the Client's data beyond the agreed contractual term (subject to the provisions above). In any event, after deletion or return, Ask Technologies no longer has any obligation to retain the Client's data and disclaims all liability for any permanent loss of data resulting from the termination of the contract, provided that these actions were carried out in accordance with the Client's instructions and the terms of this DPA.

Documentation and Client Audit Rights

Ask Technologies undertakes to maintain internal documentation relating to the Processing activities carried out on behalf of the Client, in accordance with Article 30(2) of the GDPR (record of processing activities by the processor). Upon request, Ask Technologies can provide the Client with the relevant elements of this record concerning the categories of activities performed for it, provided that sensitive or confidential information relating to other clients is not disclosed.Ask Technologies commits to maintaining internal documentation regarding the processing operations carried out on behalf of the Client, in accordance with Article 30(2) of the GDPR (processor's record of processing activities). Upon request, Ask Technologies can provide the Client with the relevant parts of this record concerning the categories of activities carried out for them, subject to not disclosing sensitive or confidential information pertaining to other clients.

Furthermore, Ask Technologies shall make available to the Client all information necessary to demonstrate compliance with the obligations set forth in this DPA and to allow for audits, including inspections, by the Client or another mandated auditor, and shall contribute to such audits. The terms for exercising the Client's right to auditright to audit are described above (section "Documentation and Right to Audit" of Ask Technologies' obligations).Furthermore, Ask Technologies provides the Client with all necessary information to demonstrate compliance with the obligations set forth in this DPA and to enable the performance of audits, including inspections, by the Client or another authorized auditor, and to contribute to these audits. The terms and conditions for the Client's exercise of the are described above (section "Documentation and Right to Audit" of Ask Technologies' obligations).

Ask Technologies considers that independent third-party audit reports it may obtain constitute valid proof of its compliance with the requirements of this Agreement. The Client shall in good faith agree to take such reports/certificates into account to reduce the frequency or scope of its own audits, in a spirit of collaboration.Ask Technologies considers that any independent third-party audit reports it may obtain constitute valid proof of its compliance with the requirements of this Agreement. The Client will, in good faith, agree to consider such reports/certificates to reduce the frequency or scope of its own audits, in a spirit of collaboration.

In the event of an audit initiated by a supervisory authority (e.g., CNIL) concerning Ask Technologies' activities in connection with this DPA, Ask Technologies will inform the Client if it directly concerns the Client's data (unless legally prohibited). Ask Technologies will provide the necessary access and cooperation to the authority under the conditions required by law.In the event of an audit initiated by a supervisory authority (e.g., CNIL) concerning Ask Technologies' activities in connection with this DPA, Ask Technologies will inform the Client if it directly concerns the Client's data (unless legally prohibited). Ask Technologies will provide the necessary access and cooperation to the authority as required by law.

Points of Contact and Data Protection OfficerContact Points and Data Protection Officer

Each Party designates a point of contact for data protection matters under this Agreement. On Ask Technologies' side, any request or question concerning this DPA or the data processed can be addressed to its Data Protection Officer (DPO)Data Protection Officer (DPO) at the following email address: dpo (at) polaria (dot) ai​dpo (at) polaria (dot) ai​. This contact can be used notably for: reporting a data breach, asking questions about security measures, requesting assistance regarding data subject rights, or any other personal data-related query.Each Party designates a point of contact for data protection-related inquiries under this Agreement. For Ask Technologies, any request or question concerning this DPA or the data processed can be addressed to its at the following email address: . This contact can be used, in particular, for: reporting a data breach, asking questions about security measures, requesting assistance regarding data subject rights, or any other inquiry related to personal data.

Ask Technologies undertakes to respond promptly to Client requests via its DPO or its data protection team. Additionally, the Client may also contact their usual commercial or technical representative at Ask Technologies, who will forward the request to the relevant internal personnel.Ask Technologies is committed to responding promptly to client requests through its DPO or its data protection team. Additionally, the Client can also contact their usual sales or technical contact at Ask Technologies, who will forward the request to the relevant internal personnel.

The Client shall, for its part, provide Ask Technologies with the contact details of its own data protection representative (e.g., the Client's DPO or Data Protection Officer, if one has been appointed). This contact will be used by Ask Technologies for sending any data-related information (breach notification, information on a new sub-processor, etc.). It is the Client's responsibility to keep this contact information up to date and to notify Ask Technologies of any changes.The Client must, for their part, provide Ask Technologies with the contact details of their own data protection point of contact (for example, the Client's DPO or equivalent data protection representative, if one has been appointed). This contact will be used by Ask Technologies for sending all data-related information (e.g., breach notifications, information about a new sub-processor, etc.). The Client is responsible for keeping these contact details up to date and for notifying Ask Technologies of any changes.

Governing Law and JurisdictionApplicable Law and Jurisdiction

This Agreement is governed by French lawFrench law, including its validity, interpretation, execution, or termination, and without prejudice to the direct application of the GDPR and any mandatory laws locally applicable to the Client. In the event of a dispute concerning the interpretation or execution of this Agreement, the Parties shall endeavor to resolve the dispute amicably in a spirit of cooperation and good faith. Failing an amicable agreement, and subject to more protective mandatory legal provisions, the competent courts within the jurisdiction of Ask Technologies' registered office (namely the courts of ) shall have sole jurisdiction over any dispute arising from this DPA, including, where applicable, summary proceedings or applications.This Agreement is governed by , including its validity, interpretation, performance, or termination, without prejudice to the direct application of the GDPR and any mandatory laws locally applicable to the Client, where applicable. In the event of a dispute relating to the interpretation or performance of this Agreement, the Parties shall endeavor to resolve the dispute amicably in a spirit of cooperation and good faith. Failing an amicable agreement, and subject to any more protective mandatory legal provisions, the competent courts having jurisdiction over Ask Technologies' registered office (namely the courts of ) shall have exclusive jurisdiction over any dispute arising from this DPA, including, if applicable, summary proceedings or ex parte applications.

This jurisdiction clause applies provided that the competent court under the main contract binding the Parties is located in a Member State of the European Union. If the main contract stipulates a different jurisdiction or applicable law, exceptions may be made to the above provisions, provided that this does not diminish the data protection safeguards set forth in this DPA and by the GDPR. In any event, the GDPR remains applicable to Processing activities falling within its territorial scope, and any clause of this Agreement shall be interpreted in light of that regulation.This jurisdiction clause applies provided that the competent court under the main contract between the Parties is located in a Member State of the European Union. If the main contract provides for a different jurisdiction or applicable law, an exception may be made to the above provisions, provided that this does not diminish the data protection safeguards set forth in this DPA and the GDPR. In any event, the GDPR remains applicable to Processing falling within its territorial scope, and any clause of this Agreement shall be interpreted in light of that regulation.

The Parties acknowledge that they have read, understood, and accepted the content of this Data Processing Agreement, which becomes effective upon its acceptance by the Client through the prescribed method (electronic signature, online validation, or tacit acceptance of the general terms and conditions including this DPA).Executed in Paris, in two digital copies, on the date of the last electronic acceptance. The Parties declare that they have read, understood, and accepted the content of this Data Processing Agreement, which comes into effect upon its acceptance by the Client through the designated process (electronic signature, online validation, or tacit acceptance of the general terms and conditions including this DPA).

Curious to learn more? Book a free 30-minute demo with our team today!

Notre produit IA
100% souverain