SYAGA AuditMicrosoft 365 Edition
Home Features Security How it works Pricing
Sign in Lancer mon audit gratuit

Data Processing Agreement (DPA)

Concluded pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) (source: gdpr-info.eu/art-28-gdpr)

Service concerned: SYAGA Audit -- Microsoft 365 security and compliance audit, read-only

Version: 1.0 -- Date: 27 June 2026 -- Effective date: 27 June 2026


Identification of the Parties

The Processor:

SYAGA CONSULTING, a limited liability company (EURL) with share capital of 20 000 euros, registered with the Aix-en-Provence Trade and Companies Register under SIREN 518 489 471, created on 08/12/2009, represented by its manager Sébastien Questier, with its registered office at 2 Impasse Paul Langevin, 13110 Port-de-Bouc, publisher of the SYAGA Audit service, hereinafter referred to as the Processor.

AND

The Data Controller: the Client having subscribed to the SYAGA Audit service under the terms of the T&Cs available at cgu.html, whose contact details are those provided at the time of subscription, hereinafter referred to as the Data Controller.

Hereinafter jointly referred to as the Parties.


Preamble

This Data Processing Agreement (DPA) is entered into pursuant to Article 28 of the GDPR, which requires that processing carried out by a processor on behalf of a controller be governed by a contract defining the subject matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects, as well as the obligations and rights of the controller.

This DPA is ancillary to the SYAGA Audit General Terms and Conditions of Sale and Service (GTC) (the main Contract). In the event of a contradiction between this DPA and the main Contract on a matter relating to data protection, this DPA prevails. In the event of a contradiction relating to the protection of personal data, this DPA prevails over the Terms of Use.

By subscribing to the SYAGA Audit service, the Client accepts the terms of this DPA. Electronic acceptance constitutes acceptance of the DPA in accordance with the provisions applicable to the conclusion of contracts by electronic means.


Article 1 -- Purpose and doctrine of the service

This DPA sets out the conditions under which the Processor undertakes to carry out, on behalf of and on the documented instructions of the Controller, the personal-data processing operations necessary for the provision of the SYAGA Audit service.

SYAGA Audit performs a security and compliance audit of the Controller's Microsoft 365 environment in read-only mode: the Service does not write, modify or delete any data in the audited tenant.

The Processor applies a zero-knowledge doctrine: collection and pseudonymisation run in the Client's browser (extension). The Processor never receives the raw tenant data nor the Client's Microsoft access token: only pseudonymised fingerprints. Tokenised audit results are retained on the server side only for the periods set out in Article 2.3, for as long as the Client needs to download its files; they are re-contextualised in clear text only on the Client's own workstation, which alone keeps the durable copy.


Article 2 -- Nature, purpose and duration of the processing

2.1 Nature of the operations. The operations consist of: collection (read, least privilege) via the Microsoft APIs, carried out by a browser extension running on the Client's machine; local pseudonymisation; analysis by the Processor of the pseudonymised fingerprints alone against security frameworks (ANSSI, Microsoft recommendations, GDPR, NIS2); delivery in the form of reports recontextualised on the Client's machine.

2.2 Exclusive purpose. The purpose is the assessment of the security and compliance posture of the Data Controller's Microsoft 365 tenant and the production of the associated audit reports. No other purpose (canvassing, profiling, reuse for the Processor's own ends) is permitted.

2.3 Duration. The processing is carried out for the duration of the main Contract. Pseudonymised audit data is deleted as soon as the Controller gives the signal from its report (retrieval discharge), in accordance with the choice open to it under Article 28(3)(g) GDPR. Failing such signal, it is deleted automatically no later than two (2) hours after completion of the scan, that period being extended to twenty-four (24) hours for the sole data that the Controller supplies itself (company profile, answers to the declarative questionnaire). The Microsoft session token is encrypted at rest and its lifetime does not exceed fifty-eight (58) minutes; the technical token used during the scan expires no later than three (3) hours after it is issued. Billing data is retained for ten (10) years from the close of the financial year, pursuant to Article L. 123-22 of the French Commercial Code.


Article 3 -- Categories of personal data processed

The Processor processes the following categories of data:

  • Configuration data and security metadata: tenant settings, conditional access policies, MFA configuration, administrative roles and permissions, sharing settings, activation states of security features
  • Identity and directory metadata: account identifiers (UPN), display names, group membership, directory attributes relevant to the audit
  • Security event logs and metadata: sign-in logs, audit events, metadata required to assess controls

Express exclusions. The Processor does not process the content of emails, files or documents. Only metadata and configuration data are processed.

Special categories. The processing is not intended to process special categories of data within the meaning of Article 9 of the GDPR. The Controller undertakes not to configure the service in a way that leads to such processing.


Article 4 -- Categories of data subjects

The data subjects are the account and identity holders within the Microsoft 365 tenant of the Data Controller: employees, directors, administrators, contractors and guests holding an account in the audited directory.


Article 5 -- Documented instructions of the Controller

The Processor processes the data solely on documented instructions from the Controller (art. 28.3.a GDPR), including with regard to transfers to a third country, unless required to do so by mandatory legal obligation (in which case it informs the Controller before processing, unless legally prohibited).

This DPA, its appendices and the GTS constitute the initial documented instructions. The Processor shall immediately inform the Controller if it considers that an instruction constitutes a breach of the GDPR (Art. 28.3, final paragraph GDPR).


Article 6 -- Confidentiality

The Processor ensures that the persons authorised to process the data commit to respecting confidentiality or are subject to an appropriate statutory obligation of confidentiality (Art. 28.3.b GDPR), and receive the necessary data-protection training. This commitment survives the cessation of duties and the end of this DPA.


Article 7 -- Security measures (art. 32 GDPR) and framework alignment

The Processor implements appropriate technical and organisational measures to ensure a level of security adapted to the risk (Art. 32 GDPR). The measures in place include in particular:

  • Zero-Knowledge architecture: collection and pseudonymisation carried out in the Client's browser (extension); the Processor only receives pseudonymised fingerprints; the raw tenant data and the Microsoft token are never transmitted to it
  • Least privilege: connection via Microsoft OAuth with the narrowest permissions offered by Microsoft for each scope; the Service never writes, modifies or deletes any data of the audited tenant
  • Encryption in transit: TLS 1.2/1.3 on all communications; SPF, DKIM and DMARC enabled
  • Microsoft Token: never leaves the Client's browser; the Processor neither receives nor stores it, ever
  • Hosting in France: OVH infrastructure (France) operated for SYAGA CONSULTING
  • Access management: principle of least privilege; named authorisations; regular review
  • Anti-abuse: cap of 2 audits/day/tenant; anti-DDoS measures
  • Logging: traceability of data access
  • Regular testing of the effectiveness of the security measures

Alignment with recognised security frameworks

The measures above are designed in line with the following frameworks. SYAGA claims no formal certification against these frameworks; the measures are aligned with the requirements of the ISO/IEC 27001 standard, with a certification process under way but no certification obtained to date; this is a functional alignment:

FrameworkRelevance to SYAGA AuditOfficial source
GDPR (EU) 2016/679 Directly applicable regulatory basis. Art. 32: technical and organisational measures. Ephemeral architecture = minimisation measure compliant with Art. 5.1.e. eur-lex.europa.eu CELEX:32016R0679
NIS2 Directive (EU) 2022/2555 Cybersecurity risk management measures (Art. 21 NIS2): business continuity, incident management, network security, encryption. SYAGA Audit helps clients assess their own NIS2 compliance within their M365 tenant. SYAGA, whose headcount and turnover are below the thresholds for important entities within the meaning of Directive (EU) 2022/2555 (50 employees or EUR 10M), does not fall within the scope of entities subject to NIS2. SYAGA Audit nevertheless helps its clients measure their compliance with this framework. eur-lex.europa.eu CELEX:32022L2555
DORA Regulation (EU) 2022/2554 Digital operational resilience for regulated financial entities. SYAGA Audit can help financial clients document their DORA posture within their M365 tenant. As SYAGA is not a regulated financial entity, DORA does not apply to it directly; contractual obligations may apply on a case-by-case basis for financial-sector clients subject to DORA. eur-lex.europa.eu CELEX:32022R2554
ISO/IEC 27001 ISMS framework: security policy, risk management, access controls, encryption, logging. SYAGA Audit's measures are aligned with the corresponding ISO 27002 controls. SYAGA Audit's measures are aligned with the requirements of the ISO/IEC 27001 standard, a certification process being under way, with no certification obtained to date. iso.org/standard/27001
ANSSI recommendations IT hygiene guide, information systems security recommendations. Measures inspired by ANSSI recommendations on account management, encryption and logging. SYAGA Audit assesses M365 configurations against ANSSI recommendations. ssi.gouv.fr

The full detail of the technical and organisational measures is set out in Annex 1.


Article 8 -- Use of sub-processors

The Controller authorises the Processor to engage the sub-processors listed in Annex 2. For any new sub-processor or replacement, the Processor shall inform the Controller in writing at least thirty (30) days before it takes effect, the Controller having a period of thirty (30) days to object on reasonable grounds relating to data protection (art. 28.2 and 28.4 GDPR). These periods and terms apply unless otherwise specifically agreed between the Parties.

The Processor imposes on subsequent subprocessors, by contract, the same data protection obligations as those provided in this DPA (Art. 28.4 GDPR) and remains fully liable to the Data Controller for their performance.


Article 9 -- Assistance to the Controller

9.1 Rights of data subjects (Articles 12 to 22 and 28.3.e of the GDPR). The Processor forwards to the Controller without delay any request to exercise rights received directly from a data subject and assists the Controller in responding to it.

9.2 Security and DPIA (art. 32 to 36 and 28.3.f GDPR). The Processor assists the Controller with the security of processing, carrying out a data protection impact assessment (DPIA) where necessary, and prior consultation of the CNIL where applicable.

9.3 Data breaches (GDPR art. 33 and 34). The Processor notifies the Controller of any data breach within a maximum period of forty-eight (48) hours of becoming aware of it, without undue delay, so as to enable the controller to meet the 72-hour deadline set out in Article 33 of the GDPR, providing the information relevant to any notification.


Article 10 -- Fate of the data at the end of the contract

At the end of this DPA, the Processor shall, within a period of thirty (30) days following the end of the contract, and according to the choice of the Controller notified in writing (Art. 28.3.g GDPR):

Note: given the ephemeral architecture of the service, no audit data is retained after the service is completed; only billing data is retained in accordance with the legal obligations (10 years).

  • either the return to the Controller of the personal data processed, in a structured format (JSON or CSV depending on availability);
  • or to the secure deletion of all data, including copies, save where legally required to retain it.

In accordance with the ephemeral architecture of the service, pseudonymised audit data is deleted as soon as the Controller gives the signal from its report (retrieval discharge), and failing that by automatic expiry within the periods set out in Article 2.3. The Processor provides, on request, a certificate of deletion.


Article 11 -- Audits and inspections

The Processor makes available to the Controller all the information necessary to demonstrate compliance with the obligations of Article 28 of the GDPR and allows for audits, including inspections, to be carried out (GDPR art. 28.3.h).

Audits are subject to the following conditions: written notice of at least thirty (30) working days, carried out during business hours, a maximum frequency of one (1) audit per twelve (12) month period save exceptional circumstances (in particular a proven security incident), costs borne by the Data Controller, confidentiality of the information obtained.


Article 12 -- Transfers outside the European Union

12.1 Primary location. Data is processed and hosted in France. SYAGA CONSULTING is an entity under French law. Indirect exposure to the CLOUD Act via third-party providers cannot be entirely ruled out; SYAGA limits it through hosting in France (OVH SAS) and, above all, through pseudonymisation: the service only receives tokens, never your data in clear text.

12.2 Use of Microsoft. The Controller acknowledges that the Microsoft Graph API is operated by Microsoft Corporation (United States). Transfers involving Microsoft are governed by the standard contractual clauses approved by the European Commission and, where applicable, the EU-U.S. Data Privacy Framework. The audited data is that of the Client's own Microsoft 365 tenant, accessed on a read-only basis on its behalf via Microsoft Graph. Microsoft acts as the Client's provider; SYAGA is not its downstream processor.

12.3 General guarantees. Any transfer outside the EU carried out by the Processor or a sub-processor is subject to the implementation of a valid mechanism within the meaning of Chapter V of the GDPR (adequacy decision, standard contractual clauses or other appropriate safeguard).


Article 13 -- Data protection contact

Processor (SYAGA CONSULTING): data protection point of contact -- dpo@syaga.eu. The appointment of a data protection officer is not mandatory within the meaning of Article 37 of the GDPR; the person responsible for data protection is the manager, Sébastien Questier, the point of contact for any question relating to personal data.

Controller: GDPR contact designated by the Client in accordance with its own obligations.


Article 14 -- Duration, amendment and applicable law

This DPA takes effect upon subscription to the SYAGA Audit service and remains in force for the entire duration of the processing carried out on behalf of the Controller.

Any substantial change is subject to prior notification to the Controller. Continued use of the service after the notification period constitutes acceptance of the changes. These amendment procedures comply with the requirements of Article 28 of the GDPR for processing agreements.

This DPA is governed by French law. Any dispute falls within the jurisdiction of the courts of Aix-en-Provence, subject to the mandatory public-policy rules applicable to cross-border disputes.


Annex 1 -- Detailed description of the processing and security measures (Article 32 of the GDPR)

SettingDescription
PurposesM365 security and compliance audit -- report production
Data categoriesConfiguration metadata, identity metadata (UPN, names), security logs
Special categories (Art. 9)None
Data subjectsAccounts and identities of the Client's Microsoft 365 tenant
Server-side retentionRaw tenant data: never transmitted (pseudonymisation in the browser). Tokenised results: retained on the server side until the Client's discharge, and no later than 2 hours after the end of the scan (24 hours for data supplied by the Client itself). Billing data: 10 years from the close of the financial year (Article L. 123-22 of the French Commercial Code).
Place of processingFrance (SYAGA CONSULTING infrastructure)
Encryption in transitTLS 1.2/1.3 -- all communications; SPF/DKIM/DMARC
Microsoft tokenNever leaves the Client's browser; never received by the Processor
ArchitectureCollection and pseudonymisation by an extension in the Client's browser; the Processor only analyses fingerprints
Access managementLeast-privilege principle; named authorisations
Anti-abuseCap of 2 audits/day/tenant; anti-DDoS
LoggingMinimal operational and security technical logs, without personal audit data, retained for approximately 12 months in accordance with CNIL recommendations.
Security framework alignmentMeasures aligned with GDPR art. 32, ISO/IEC 27001 (a certification process being under way, with no certification obtained to date), and ANSSI recommendations.

Annex 2 -- List of authorised subsequent subprocessors

Subsequent subprocessorServiceLocationTransfer safeguards
Microsoft Corporation Microsoft Graph API -- read access to the tenant's configuration data EU + United States (Microsoft infrastructure) Microsoft acts as a supplier of the Client (not a sub-processor of SYAGA). Transfers are governed by the EC standard contractual clauses and Microsoft's participation in the EU-U.S. Data Privacy Framework.
OVH SAS (hosting, Roubaix, France) SYAGA Audit platform hosting France Not applicable (EU)
Stripe Payments Europe, Limited Payment -- Client billing data only (excluding tenant data) United States / EU EU-U.S. Data Privacy Framework (Stripe certified) and, in the alternative, EC Standard Contractual Clauses (2021) -- Stripe's Data Transfers Addendum.

Legal references

  • CNIL -- processor, art. 28 GDPR obligations: cnil.fr/fr/sous-traitant
  • Regulation (EU) 2016/679 (GDPR), articles 4, 9, 12 to 22, 28, 32 to 36: EUR-Lex CELEX:32016R0679
  • Directive NIS2 (EU) 2022/2555, Art. 21: EUR-Lex CELEX:32022L2555
  • DORA Regulation (EU) 2022/2554: EUR-Lex CELEX:32022R2554
  • ISO/IEC 27001: iso.org/standard/27001
  • ANSSI -- IT hygiene guide: ssi.gouv.fr
  • Act No.° 78-17 of 6 January 1978 as amended: Légifrance
SYAGA Audit
Security Confidentiality CGU DPA Terms and Conditions of Sale Refund and Withdrawal Policy Legal notice © 2026 SYAGA