Data Processing Agreement
This document sets out what [À COMPLÉTER — raison sociale] does with the data you entrust to us when you use Maatron: which data, where it goes, who else touches it, how it is protected, and how long it takes to disappear.
Last revised:
Roles: who decides, who executes
You are the controller of the personal information held in your account: you decide why it is processed, and how far. [À COMPLÉTER — raison sociale] is the processor: we process it on your behalf, on your documented instructions, and for nothing else.
Documented instructions means Terms of Service, this document, and the use you make of the product's features. Uploading a backup is an instruction to analyze it; deleting a controller is an instruction to erase it. We do not go beyond that.
If an instruction appears to us to breach applicable law, we tell you before carrying it out, rather than carrying it out in silence.
Processing lasts for the term of your subscription, plus the deadlines in the retention and deletion section. If Terms of Service and this document conflict on the processing of personal information, this document prevails.
What is processed: two categories, not one
The distinction matters, because the two categories differ in volume, in sensitivity, and in use.
Account data: email address, name, organization name, password hash — never the password itself — and an opaque session identifier, held server-side and meaningless outside our systems. That is little, and deliberately so. The cookie that carries the session is described in Cookies.
Customer content: the FANUC controller backup archives you upload, and everything derived from them — the structured cell model, findings, comparisons, reports.
This is industrial data: cell topology, programs, I/O mapping, frames, machine safety parameters (DCS). It is commercially sensitive intellectual property, often your own customer's. We treat it as such, not as one more file.
This content is not made of personal information, but it may incidentally contain some: a program author's name, an initial in a comment, a file name. We do not look for those identifiers and we build no index of them, but we do not pretend they are absent — customer content is protected to the same standard as if it were nothing but personal.
The data subjects are therefore your employees, your contractors and the users you invite, and, at the margin, the authors of the programs present in the files.
Subprocessors, named
Three providers touch your data. They are named, with their role and their region, because an evasive list in a document like this one reads as a list you do not have.
Render Services Inc. — application hosting and execution of the processing (analysis, comparison) — Oregon, United States.
Cloudflare, Inc. — object storage of uploaded archives and derived artifacts — United States.
Vercel Inc. — web front-end hosting — United States.
No other subprocessor touches customer content. [À COMPLÉTER — raison sociale] remains answerable to you for the acts of these three providers as for its own, and binds them by contract to obligations at least equivalent to those in this document.
Before adding or replacing a subprocessor, we notify you — name, role, region — with reasonable notice, and before the new provider receives anything. If the change does not suit you, you may terminate on that ground.
Where the data goes, and what that entails
All three providers host in the United States. Your data therefore leaves Quebec and Canada: it is stored and processed there, and it is subject to United States law, including access demands from that country's authorities. We would rather write it down than let you discover it.
Quebec law requires you to assess the risks before disclosing personal information outside Quebec. That assessment is yours; we supply what it takes to run it — the list above, the measures in the next section, and a written answer to your questions.
A Canadian hosting region is not available today. If your contract requires one, say so before signing rather than after: this is not a setting, it is a move.
Security measures
The detail, measure by measure and with what each one protects, is set out in Security and trust. The binding summary is here.
In transit: TLS on every access to the service — web interface, API, object storage. At rest: object storage and the database are encrypted by the platforms that host them.
Isolation between organizations is enforced at two independent levels: by the application, which ties every query to one organization and one only, and by the database itself, through PostgreSQL row-level security policies. Two levels rather than one, because a single level is enough only while the code is perfect.
The application role that serves traffic is neither a superuser nor an owner of the tables: in PostgreSQL, those situations allow row-level policies to be bypassed. The service refuses to start if it detects any of them, rather than starting with isolation silently switched off.
Archives sit in private storage with no public access whatsoever, under unguessable keys that are never derived from your file name. They are reachable only through a short-lived signed link, issued for one specific object to a member of the organization that owns it, and checked on both counts before it is issued. The link expires within minutes.
No customer archive enters development, test or demonstration environments. Ever — not even to reproduce an incident or prepare a demonstration. Test material is built for the purpose, or derived from a real archive only under the written-authorization rule in the next section. Those are precisely the contexts where vigilance slips, so the rule there is stricter rather than relaxed.
Access to customer content is limited to the people who need it to operate the service, and those people are bound to confidentiality by a written undertaking that survives the end of their engagement.
What the processing cannot do
Maatron reads files. The product connects to no controller, writes to no robot, uploads no program and triggers no motion. This is not a missing feature: it is what makes it impossible for a mistake on our side to reach a production installation. Archives are read, never executed.
Analysis is deterministic: same bytes in, same findings out for a given engine version, and that version is stamped on every result. No probabilistic judgement takes part in the path that produces your reports.
Your content is not used to train any model, ours or a third party's, and is never pooled with another customer's. A customer file becomes a test case only after a separate written authorization and full anonymization; without that authorization, nothing is derived from it.
Findings are an engineering aid, not a compliance certification and not a machine-safety validation. The limits are set out in Disclaimer.
Retention and deletion: three tiers
Three deadlines rather than a single figure, because a single figure would be wrong in both directions: loss of access is immediate, while no serious backup system rewrites itself on demand. These deadlines are published, therefore they bind.
Access revocation: immediate, on request. The data stops being reachable by anyone, including you.
Erasure from live systems — object storage and database: thirty days at most.
Destruction of backup and disaster-recovery copies: sixty days at most, as their own retention cycle expires.
At the end of the contract, and at your choice, your content is returned to you in a usable format or destroyed. Absent an instruction from you within thirty days, it is destroyed according to the tiers above. We keep nothing in reserve.
One exception only: a legal obligation to retain. In that case we tell you which one and what it covers, and the data stays isolated and unused until the obligation lapses.
Your assistance, and ours
Data subject requests: if someone asks us directly for access to, correction of, or deletion of their information, we do not answer in your place. We forward the request to you without delay and we help you answer it, including through the product's export and deletion features.
Confidentiality incident: we notify you without undue delay after becoming aware of it, with what we know — the nature of the incident, the data affected, the organizations affected, the measures taken — and stating plainly what we do not yet know. A first incomplete notice is worth more than a late complete one.
We also assist you with your privacy impact assessments and with your dealings with a supervisory authority, to the extent they concern the processing described here.
Demonstrating compliance
You are entitled to the information reasonably necessary to verify that we comply with this document.
In practice: written answers to your security questionnaire, the relevant architecture documentation and Security and trust, within a reasonable time. Those answers come from the team that built the system, not from a sales function relaying them.
A documentary audit remains available, once a year, with reasonable notice, without access to any other customer's data, and at your expense — unless it reveals a failure on our part, in which case the cost is ours.
What does not exist yet
Three things a buyer looks for in a document like this one and will not find here: there is no contractual service level agreement, no public status page, and no third-party security certification — neither SOC 2 nor ISO 27001.
We write it down rather than work around it. A document like this one costs more to walk back later than to read today.
What stands in their place in the meantime: deletion deadlines that are published and dated, therefore binding; measures described at the level of the mechanism rather than in slogans, of which the two principal ones — isolation between organizations, and the absence of any network capability in the analysis engine — are checked by automated tests that block a release when they fail; a commitment to notify incidents without undue delay; and an architectural limit that rests on no promise at all — the product does not connect to your machines, so it cannot touch them.
The day one of the three exists, it will be written here, with a visible revision date.
Contact, revisions and the standing of this document
For a question about this document, a request to exercise rights, or to report an incident: info@maatron.dev. The full identification of the operator — [À COMPLÉTER — raison sociale], [À COMPLÉTER — adresse], NEQ [À COMPLÉTER — NEQ] — is set out in Legal notice.
This document is read together with Terms of Service, Privacy policy and Security and trust. Privacy policy addresses the people whose information is processed; this one addresses the organization that entrusts it to us.
Any change is published here with a new revision date. A change that reduces your rights or our obligations is flagged to you before it takes effect, not noticed after the fact.