Data processing agreement

The processing agreement (Article 28 GDPR) between Maketools and its customer organisations for the data of their members and players.

Admins11 min read

Version 0.9 of 5 October 2026 (draft, under legal review).

This English version is a translation; the French version prevails.

1. Purpose and parties

This agreement (the "DPA") forms part of the contract between the Customer, a customer organisation of Maketools, and MAKETOOLS SAS, 149 avenue du Maine, 75014 Paris, RCS Paris 990 247 603 ("Maketools"), formed by the terms of sale or an Enterprise contract. It is accepted at the same time as those terms.

It governs the processing of personal data that Maketools carries out on behalf of the Customer, within the meaning of Article 28 of Regulation (EU) 2016/679 (GDPR): the Customer is the controller, Maketools is the processor.

The processing for which Maketools is the controller (user accounts, authentication, security, billing, internal statistics authorised in article 3) is described in the privacy policy and does not fall under the DPA.

2. Description of the processing

The description (subject matter, nature, purpose, categories of data and of data subjects, duration) is set out in Annex 1.

3. Customer's instructions

Maketools processes the data only on documented instructions from the Customer. These instructions consist of: the contract, the DPA, and the settings the Customer makes in the service (access to games, including the Public visibility of a game, pseudonymised or named reporting mode, SSO, SCORM or xAPI connectors, exports, deletions, and, for the Enterprise plan, inviting Maketools staff into its Organisation to customise its games). Maketools immediately informs the Customer if, in its opinion, an instruction infringes the regulations.

The Customer also authorises Maketools to derive aggregated statistics per game from the game sessions (number of active organisations, number of completed sessions) to rank the games of its public catalogue. These statistics contain no personal data, name no organisation and are never published as figures: only the order of the games and a badge ("Popular", "New") are visible.

Finally, the Customer authorises Maketools to produce, on its own behalf, aggregated and anonymous statistics on the use of the service from the data processed for the Customer, including that of its players: for example the number of game sessions and minutes played, of members and active users, of games released and deployed, or the adoption of features. These statistics are used to steer, improve and promote the service. Maketools is the controller of this processing and describes it in its privacy policy. It undertakes that:

  • these statistics contain no personal data: the finest level is the Organisation, and they are stored in a separate database that contains no name, email, account identifier or IP address;
  • the only intermediate step relating to persons, the counting of active users, relies on data pseudonymised with a secret key dedicated to this processing, kept for 35 days at most;
  • no attempt is made to re-identify a person from these statistics;
  • neither the Customer's data nor statistics that designate the Customer are disclosed to any third party or published;
  • when the Organisation is deleted, its identifier is replaced in these statistics by a random identifier.

This authorisation, added in version 0.4, is notified to Customers at least 30 days before it takes effect.

Maketools may process the data without instructions if required to do so by Union or Member State law; in that case it informs the Customer, unless that law prohibits it.

4. Confidentiality

Maketools ensures that persons authorised to process the data are bound by an obligation of confidentiality and only access it to the extent necessary for their duties.

Access by Maketools staff relies on separate internal roles, assigned to named individuals and limited to their purpose. The catalogue curation role (publishing, trying out and featuring Maketools games) gives access to no Customer data. A staff member accesses the Customer's Organisation, for example to customise a custom-built game, only on the Customer's invitation and with the role the Customer assigns; this access leaves a trace in the Organisation's audit log, and the Customer can withdraw it at any time. The only exceptions are service operations (security, support, billing, moderation), carried out by named, authorised operators using a personal key with a limited lifetime, with every read and every action logged under their name (annex 2), and a last-resort administration account, reserved for incidents, protected by two-step verification and with every action logged.

5. Security

Maketools implements the technical and organisational measures described in Annex 2, appropriate to the risk. It may change them, provided that it does not reduce the level of protection.

6. Sub-processors

The Customer gives Maketools a general authorisation to engage the sub-processors listed in Annex 3, which is also published in the trust center.

Maketools informs the Customer of any addition or replacement at least 30 days in advance, by email to the Organisation's Owners and in the trust center. The Customer may object in writing on reasonable grounds relating to data protection; failing agreement, it may terminate the affected part of the service free of charge.

Maketools imposes on each sub-processor, by contract, data protection obligations at least equivalent to those of the DPA, and remains liable to the Customer for their performance.

7. Location and transfers

The data is hosted in the European Union (AWS, Paris region). A transfer outside the European Economic Area only takes place to a sub-processor listed in Annex 3, and only with appropriate safeguards within the meaning of Chapter V GDPR (adequacy decision or standard contractual clauses).

8. Assistance to the Customer

8.1 Data subject rights

The service provides the Customer and data subjects with self-service tools: export of account data, account deletion, profile correction, removal of a member, deletion of the Organisation. If a person sends Maketools directly a request relating to the Customer's data, Maketools forwards it to the Customer without delay and does not respond to it itself, unless instructed by the Customer.

8.2 Impact assessment and authorities

Maketools provides the Customer with the information useful for its impact assessments and for any prior consultation of the supervisory authority.

9. Data breach

Maketools notifies the Customer of any personal data breach concerning it without undue delay, and at the latest 48 hours after becoming aware of it, by email to the Organisation's Owners. The notification specifies, as far as possible: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact. Missing information is provided as soon as it is known.

It is the Customer's responsibility, as controller, to notify the supervisory authority and, where applicable, the data subjects.

10. Data at the end of the contract

When the Customer deletes the Organisation, or at the end of the contract, Maketools erases the Customer's data from all its services, then from backups at the end of their rotation cycle (30 days at most), unless there is a legal obligation to retain it. Before that, the Customer may export its reports and each user may export their account data.

On written request, Maketools confirms the erasure.

11. Audit

Maketools makes available to the Customer the information necessary to demonstrate compliance with the DPA: trust center, ISO 27001 and SOC 2 controls matrix, and, where they exist, audit reports or certifications.

If this information is not sufficient, the Customer may have an audit carried out, at most once a year, at its own expense, by an independent auditor bound by confidentiality, giving Maketools at least 30 days' notice. The audit takes place during business hours, without disrupting the service or giving access to other customers' data.

12. Customer's obligations

The Customer undertakes to:

  • have a legal basis for the processing entrusted, and inform data subjects (in particular its players of the named reporting mode, if it enables it);
  • not introduce into the service sensitive data within the meaning of Article 9 GDPR, or data unrelated to training;
  • give instructions that comply with the regulations;
  • manage the roles and access of its Organisation.

13. Term and liability

The DPA applies for as long as Maketools processes data on behalf of the Customer. Each party's liability is governed by the Terms of Sale or the Enterprise contract, within the limits permitted by Article 82 GDPR.

Annex 1: description of the processing

Item Description
Subject matter Provision of the Maketools platform: customised training games, management of members and access, reports, exports and connectors
Nature of the operations Collection, recording, storage, consultation, score calculation, aggregation, pseudonymisation, transmission (emails, LMS or LRS chosen by the Customer), erasure; production of aggregated and anonymous statistics on behalf of Maketools (article 3)
Data subjects Members and invited persons of the Organisation; players of the Organisation's games, including players without an account of its public games
Data Identification (name, work email); membership (role, groups); game data (answers, scores, durations, dates, pseudonym); optional nickname chosen by players without an account of its public games, shown on the leaderboard and on the presenter mode screen; attributes sent by the Organisation's SSO; technical audit log data (IP address, browser)
Sensitive data None expected; the Customer undertakes not to introduce any
Duration Term of the contract, then erasure (article 10); game events and nicknames of players without an account kept for 13 months at most (the nickname is deleted with the game session), audit log 12 months

Annex 2: security measures

  • Hosting in the European Union (AWS, Paris region), on infrastructure operated directly by Maketools and described as code; separate staging and production environments.
  • Segmented network: a single public entry point, the content delivery network (CDN) over HTTPS, filtered in production by a web application firewall; application servers reachable only from that content delivery network; databases and cache in isolated subnets with no Internet access; private file storage.
  • Encryption in transit (HTTPS only, TLS down to the databases and the cache) and at rest (databases, cache, message queues, files and backups); two-step verification secrets and connector credentials encrypted (AES-256-GCM).
  • Application secrets kept in a dedicated vault (AWS Secrets Manager), separate for each environment, never in the code or in the deployed images.
  • Hashed passwords (scrypt); session and API tokens stored as hashes.
  • Two-step verification required to manage the security of an Organisation (security settings, SSO, API keys) and to expose player data (named reports, xAPI connector); the Customer can require it from its privileged roles or from all its members, with a 7-day adjustment period; OIDC and SAML SSO; re-authentication for sensitive actions.
  • Role-based access control, decided at a single point; data isolation per organisation.
  • Access by Maketools staff through separate internal roles, with two-step verification: catalogue curation gives access to no Customer data; access to an Organisation happens on the Customer's invitation and leaves a trace in its audit log (article 4).
  • Access by the Maketools team to data restricted to named, authorised operators, using a personal key with a limited lifetime (one year at most) that never leaves their workstation; every read and every action is logged under their name.
  • No Maketools operations interface is exposed on the Internet: operators act from a local console, through requests signed one by one, timestamped and single-use.
  • Operator keys with a limited scope: a key reserved for statistics only reads aggregates (no data relating to a person) and cannot change anything.
  • Minimisation of internal statistics: a separate database containing only aggregates, whose finest level is the Organisation; activity days pseudonymised with a dedicated key and deleted after 35 days; no audience measurement tool or tracker.
  • Reports pseudonymised by default; no details for a group of fewer than 5 players.
  • Tamper-proof, chained audit log; technical logs redacted of personal data, centralised and monitored by security and availability alerts.
  • Attempt limiting, CSRF protections, strict content security policy, checks on imported files.
  • Code and dependency analysis on every change, security review; automated deployment, with no permanent access key.
  • Automatic backups with point-in-time recovery (transaction logs archived continuously), a production database protected against deletion, and a tested restore procedure, including to another availability zone.

Annex 3: sub-processors

Sub-processor Purpose Location
Amazon Web Services EMEA SARL (Luxembourg) Hosting of the application, databases, files and site, on infrastructure operated directly by Maketools European Union (Paris, eu-west-3)
Resend Sending transactional emails (invitations, codes, notifications) United States (Data Privacy Framework certified; standard contractual clauses incorporated into its DPA)

Stripe processes the Customer's billing data on behalf of Maketools, which is the controller of that processing; it has no access to players' data.

Edit this page on GitHub (opens in a new tab)