Skip to main content
Legal

Data Processing Agreement (GDPR Art. 28)

The processor terms that apply to every paid IPZilla plan: what we process, for how long, our security duties, sub-processors, breach notice, audits and deletion. Countersigned copy on request.

Last updated: 2026-08-28 · Version 1.0

1. Parties, scope and precedence

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer identified on the order or the account ("Customer", the controller) and ICRAFT SAS, RCS Paris 992 314 237, 58 rue de Monceau, 75008 Paris, France ("IPZilla", the processor).

It applies to all personal data that IPZilla processes on the Customer's behalf while providing the platform (the "Services"). Where this DPA conflicts with the Terms of Service, this DPA prevails for the processing of personal data. An Enterprise order form may add stricter terms, which then prevail over this DPA.

This DPA is executed by acceptance of the Terms of Service. A countersigned PDF, dated and signed by IPZilla's legal representative, is provided within five business days of a request through the contact form (subject "Legal").

2. Details of the processing (Art. 28(3))

The processing is characterised as follows:

  • Subject matter: operation of the IPZilla platform — patent landscaping, claim scoring, outcome prediction, AI-assisted drafting, filings monitoring and collaboration features.
  • Duration: the term of the Customer's subscription or One-Shot purchase, plus the deletion period in section 9.
  • Nature and purpose: hosting, storage, retrieval, analysis by large language models, rendering of office-format documents, notification e-mails, billing.
  • Categories of data subjects: the Customer's users (employees, counsel, collaborators invited to a cartography), inventors and applicants named in disclosures, contact persons of the Customer.
  • Categories of personal data: account identifiers (name, e-mail, Firebase UID), authentication metadata, usage and billing records, and any personal data the Customer includes in briefs, disclosures, drafts, uploaded documents and chat turns (typically inventor names, addresses, nationalities and contributions required by patent offices).
  • Special categories (Art. 9): not required by the Services. The Customer undertakes not to submit health, genetic or other special-category data about identifiable persons unless an Enterprise order form expressly provides for it.

3. Processing on documented instructions

IPZilla processes personal data only on the Customer's documented instructions, which are: the Terms of Service, this DPA, the configuration choices made in the account (including sharing a cartography with collaborators and Ephemeral Mode), and any written instruction sent through the contact form. IPZilla informs the Customer if, in its opinion, an instruction infringes the GDPR or other EU or Member State data-protection law.

Personal data is never used to train, fine-tune or evaluate machine-learning models, whether by IPZilla or by its sub-processors. Google Cloud's Vertex AI terms contractually exclude the use of prompts and completions for foundation-model training.

4. Confidentiality of personnel

Every person authorised by IPZilla to process personal data is bound by a written confidentiality obligation and has access only to the data strictly needed for their task. Production access is restricted to named administrators, protected by multi-factor authentication and a 12-hour step-up re-authentication for administrative surfaces, and logged.

5. Security measures (Art. 32)

IPZilla implements and maintains at least the following technical and organisational measures:

  • Encryption in transit (TLS 1.2+, HSTS preload) and at rest (Google-managed AES-256 keys on Firestore, Cloud Storage and BigQuery).
  • Tenant isolation by design: every document is keyed by the owning account; cross-account access is possible only through explicit, revocable collaborator invitations, and every read of a cartography is recorded in an access log the Customer can export.
  • Least-privilege service identities on Google Cloud; secrets held in Secret Manager, never in source code; automated secret scanning of the code base and its history.
  • Strict Content-Security-Policy on the application surface, signed webhooks, rate limiting, dependency vulnerability audits on every change.
  • Daily encrypted backups of the database with 30-day retention; restoration procedure tested.
  • Uptime monitoring with alerting from multiple regions; error tracking without personal data in payloads.
  • API keys issued to the Customer expire after at most one year, can be rotated and revoked at any time, and every lifecycle event is audited.

6. Sub-processors

The Customer gives general written authorisation to the sub-processors below. IPZilla imposes on each of them data-protection obligations equivalent to this DPA and remains fully liable to the Customer for their performance.

IPZilla notifies the Customer of any intended addition or replacement at least 30 days in advance through the account e-mail. The Customer may object on reasonable data-protection grounds within that period; if no solution is found, the Customer may terminate the affected Services with a pro-rata refund of prepaid fees.

  • Google Cloud EMEA Limited / Google LLC — hosting, database, storage, analytics warehouse and Vertex AI Gemini (us-central1, USA; EU region on Enterprise request). Transfer mechanism: EU-US Data Privacy Framework and Standard Contractual Clauses.
  • Google Firebase — authentication (identity providers, session tokens).
  • Stripe Payments Europe Ltd — payment processing and invoicing (Ireland; card data never reaches IPZilla).
  • Resend, Inc. — transactional e-mail delivery (USA; SCCs).
  • Functional Software, Inc. (Sentry) — error tracking (EU data region; payloads scrubbed of personal data).
  • Plausible Insights OÜ — privacy-first web analytics (EU; no cookies, no personal data).
  • ICRAFT (iCraft) internal tooling — support-ticket intake and referral attribution (France).

7. Assistance to the controller

Taking into account the nature of the processing, IPZilla assists the Customer by appropriate technical and organisational measures in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection). Self-service export and deletion are available in the account; other requests are handled within ten business days of receipt through the contact form.

IPZilla assists the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data-protection impact assessments and prior consultation), providing the information reasonably available to it.

8. Personal-data breach notification

IPZilla notifies the Customer without undue delay and in any event within 48 hours after becoming aware of a personal-data breach affecting the Customer's data. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.

9. Deletion and return of data

At the end of the Services the Customer may export its data (reports, drafts, verbatim claims, CSV) from the account. Thirty days after termination, or immediately on written request, IPZilla deletes all personal data processed on the Customer's behalf, including from the daily backups once their 30-day retention has lapsed, unless EU or Member State law requires longer storage (for instance invoicing records, kept for ten years under French commercial law).

Pseudonymised training transcripts (retained only where the Customer has not opted out and identified solely by a salted hash) contain no direct identifiers and are not affected by this deletion; the Customer can require their deletion as well.

10. Audits and information

IPZilla makes available all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, bound by confidentiality. Audits take place at most once per year, on 30 days' notice, during business hours, without disrupting the Services, and at the Customer's expense unless they reveal a material breach of this DPA. IPZilla may first satisfy the request with recent third-party reports (for example a penetration-test summary) where they cover the audited scope.

11. International transfers

Production infrastructure is operated in the United States (Google Cloud us-central1). Transfers of personal data from the EEA, the UK and Switzerland rely on the EU-US Data Privacy Framework certification of Google LLC and, as a fallback, on the European Commission's Standard Contractual Clauses (module 3, processor to processor, and module 2 where relevant), supplemented by the security measures above. Enterprise customers may require EU-region hosting; the applicable order form then records the region.

12. Liability, term and governing law

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where those limitations would be contrary to Article 82 GDPR. This DPA takes effect on acceptance of the Terms of Service and remains in force for as long as IPZilla processes personal data on the Customer's behalf. It is governed by French law; the courts of Paris have exclusive jurisdiction, without prejudice to the data subjects' rights and to the competence of supervisory authorities.

For questions, access / deletion requests, or to receive the full Enterprise DPA: contact form.

Suggested subject: Legal · terms