Skip to content

Courtesy translation. Only the French version of this contract is authoritative (art. 25.6). This translation is provided for ease of reading and has no contractual value.

General Terms and Conditions for the Supply of the « DMARC » Service

Version 1.4 — applicable as of 19 August 2026

HUCENCY is a limited liability company (société à responsabilité limitée) with a share capital of 50 000 €, registered with the Rouen Trade and Companies Register (Registre du commerce et des sociétés) under number 832 080 055, whose registered office is located at 313 rue Edouard Delamare Deboutteville, 76160 Saint-Martin-du-Vivier (hereinafter « HUCENCY »). HUCENCY's contact details are as follows: Tel: 02.79.49.15.79 – E-mail: contact@hucency.com

HUCENCY specializes in the provision of cybersecurity services. In the course of its business, it has developed a service to assist with the implementation, supervision and management of the « DMARC » (Domain-based Message Authentication, Reporting & Conformance) email authentication protocol, intended for businesses, enabling them in particular to collect and analyze aggregate reports (RUA), to identify their sending sources, to verify SPF and DKIM alignment, to obtain the DNS records to be published and to move their DMARC policy from « p=none » to « p=reject » (hereinafter the « Service »).

Depending on the options subscribed, this Service may include:

  • The provision, as software as a service (SaaS), of a software solution enabling the collection and analysis of DMARC reports (RUA), the supervision of the authentication posture of the Client's domains, and access to various modules contributing to the implementation of the DMARC protocol (Dashboard, « Thomas » AI assistant, Observatory, etc.) (hereinafter the « Solution »);

These General Terms and Conditions for the supply of the Service (hereinafter the « CGS ») apply between HUCENCY and any professional client (together the « Parties ») having subscribed to the Service with HUCENCY. « Professional » means any natural or legal person, public or private, acting for purposes falling within the scope of its commercial, industrial, craft, professional or agricultural activity, including where it acts in the name of or on behalf of another professional. Any client subscribing to the Service undertakes, without restriction or reservation, to comply with these terms in their entirety.

HUCENCY reserves the right to update the CGS, in particular by reason of modifications or technical developments introduced by its subcontractors or imposed by the applicable legal framework, and undertakes to inform the Client thereof beforehand by any means.

1. Definitions

Each capitalized term used in this Contract has the meaning set out below:

« Anomaly » means any error, bug, malfunction, non-conformity or other reproducible defect affecting the Solution and preventing its optimal use.

« Blocking Anomaly » means an Anomaly that renders the Solution totally unavailable or that severely restricts or removes a basic service or an essential feature of the Solution.

« Major Anomaly » means an Anomaly which, without restricting a basic service or an essential feature of the Solution, causes the concerned service or feature to be used in a degraded mode.

« Minor Anomaly » means an Anomaly that is neither major nor blocking or that affects a non-essential function of the Solution.

« Purchase Order » means any purchase order, including in electronic format, established by HUCENCY in relation to the supply of the Service, namely the initial purchase order (i.e. the one constituting the subscription to the Service) and any purchase orders established in the event of a modification of the scope of the Service.

« Client » means the professional who enters into the Contract.

« Contract » means the contractual whole governing the conditions for the supply of the Service entered into between the Client and HUCENCY, consisting of these CGS which define the general conditions thereof and of the Purchase Order, or of the online subscription validated by the Client, which defines the particular conditions thereof, together with the annexes to these documents.

« User Account » means the personal account of a User allowing them to access the Solution by means of unique and personal credentials.

« Client Data » means all data, information, content, elements, files, DMARC reports (RUA), connection logs, configuration data and analysis results and, more generally, any data of whatever nature, provided or generated by the Client or resulting from its use of the Solution, excluding the software, source codes, tools, models, knowledge bases and other elements falling under the intellectual property of the Provider.

« Anonymized Data » means Client Data that has undergone irreversible processing making it impossible, both in law and in practice, to directly or indirectly identify a natural person, in accordance with the applicable regulations on the protection of personal data.

« Aggregated Data » means Anonymized Data grouped together and presented in statistical or summary form, not allowing the Client or a specific person to be identified.

« Exportable Data » means the Client Data created or used by the Client when it uses the Service, identified as such in the Contract or in the Documentation, and technically transferable to another provider or to an on-site TIC infrastructure, in accordance with the Data Act (EU) 2023/2854 of 13 December 2023.

« Client Interface » means the interface of the Solution accessible to the Client.

« Modules » means the various modules contributing to the implementation and management of the DMARC protocol included in the Solution, whether or not integrated within the Client Interface.

« DMARC Reports » means the aggregate reports (RUA) issued by the recipient mail servers pursuant to the DMARC protocol, collected and processed by the Solution on behalf of the Client. HUCENCY does not collect incident/forensic reports (RUF).

« Thomas » means the Solution's conversational assistant, based on artificial-intelligence technologies (large language models), presented as a « virtual CISO » and intended to assist the Client in DMARC remediation. The conditions and limits of this assistant are set out in Article 6 bis.

« Service » means the service supplied by HUCENCY taken as a whole, comprising all the services provided by HUCENCY under the conditions of these terms, namely the provision of the Solution and the associated services (commissioning, right of access, hosting, support, maintenance, etc.).

« Solution » means the cloud-hosted « DMARC » software solution, developed and published by HUCENCY, comprising the Modules, accessible in SaaS (Software as a Service) mode and made available to the Client under the conditions of these terms.

« User » means any person authorized by the Client to access the Client Interface and holding, as such, a User Account (employees and/or staff of the Client, or even third parties).

2. Purpose

The purpose of this Contract is to define the contractual conditions applicable to the supply of the Service by HUCENCY to the Client, as well as the rights and obligations of the Parties in this context.

3. Contractual documents

The contractual relationship between the Parties is governed by these CGS and the Purchase Order(s) or the online subscription (together the « Contract »). In the event of a contradiction between the CGS and a Purchase Order, the Purchase Order prevails. Only these documents govern the contractual relationship of the Parties, to the exclusion of any other document such as the Client's general purchasing conditions. No annotation, whether handwritten or electronic, by the Client on the Purchase Orders or on any other contractual document shall have any value between the Parties save with the written agreement of HUCENCY.

4. Entry into force – Duration

The Contract enters into force upon the validation of the Purchase Order or of the online subscription by the Client. It is entered into for an initial term corresponding to the commitment period agreed between the Parties or, in the case of an online subscription, for the subscription period chosen (monthly or annual).

Save contrary stipulation in the Purchase Order or at the time of the online subscription, the services start date is set at the first (1st) day of the month following the date of validation of the Purchase Order, or, in the case of an online subscription, at the date of the subscription.

At the end of the initial term, the Contract is renewed by tacit renewal for successive periods of a duration equal to the initial term, save contrary stipulation in the Purchase Order, save termination by either Party notified to the other Party by registered letter with acknowledgment of receipt or, for an online subscription, from the Client Interface at least three (3) months before the expiry of the current period. By way of exception, an online subscription entered into for a monthly term may be terminated at any time from the Client Interface, without notice: the termination takes effect at the end of the current billing period and the Contract is not renewed beyond that. For Clients subject to public procurement rules, the stipulations relating to the duration, renewal and reconduction of the Contract are applicable only to the extent provided by the public contract entered into with the Client. In the event of a contradiction between these terms and the procurement documents, the latter prevail.

5. Description of the Service

5.1. Scope of the Service

The Service comprises the following services:

✓ Provision of a right of remote access to and use of the Solution in SaaS mode and of the associated services (commissioning, hosting, availability, support and maintenance);

The services included in the Service supplied to the Client, in particular the Modules subscribed by the latter, are listed and described in the Purchase Order or at the time of the online subscription. The Service is supplied in accordance with and within the limits of the scope provided in the Purchase Order or the online subscription. Any service not expressly listed above or indicated in the Purchase Order is in principle excluded from HUCENCY's scope of intervention.

5.2. Subscription to an option or Module during the Contract

The Client may subscribe to options or Modules during the Contract, at its choice:

  • By sending a written request to HUCENCY, which will then issue a specific Purchase Order. This Purchase Order will be integrated into the existing contractual framework and will supplement the Purchase Order(s) in force as soon as it is signed by the Client;
  • By subscribing directly online, through a User, where this possibility is offered by HUCENCY.

Any User carrying out an online subscription is deemed to hold the powers necessary to contractually bind the Client. Thus, the Client expressly acknowledges that it is bound by any online subscription validated via the Solution by a User. The subscription becomes firm and final upon the validation carried out by the User on the Solution, via the activation of the button provided for this purpose. A subscription confirmation is then sent to the Client by email.

5.3. Description of the Solution

The cloud-hosted software solution known as SaaS is designed first and foremost to collect and analyze the DMARC Reports transmitted by the recipient mail servers, in order to assist the Client in the implementation and hardening of the DMARC protocol. It provides access to various Modules, some of which are integrated within the Client Interface and others of which are standalone tools, comprising a Main Module and Additional Modules:

▪ Main Module or « Dashboard »:

  • ✓ Visualization of the DMARC posture of the supervised domains (published policy p=none / quarantine / reject, SPF and DKIM alignment rate, volumes); identification and qualification of sending sources (servers, third-party services, unauthorized senders); aggregation and historization of DMARC Reports (RUA); generation of summary reports; management of domains and Users, etc.

▪ Additional Modules

Apart from the « Dashboard » Module, which is integrated as standard into the Client Interface, the Modules are designed to be added to or removed from the Client Interface according to the Client's requests.

✓ « Multi-organization supervision » Module: allows access to several accounts/domains on the Client Interface to be managed.

✓ « AI Assistant – Thomas » Module: makes available to the Client a conversational assistant based on artificial-intelligence technologies, intended to help it interpret DMARC Reports, identify its sending sources, obtain the DNS records (SPF, DKIM, DMARC) to be published and sequence the transition from « p=none » to « p=reject ». Use of the assistant is measured in credits under the conditions of Article 11. The limits of this assistant are set out in Article 6 bis.

✓ « Observatory » Module: a public sector barometer of DMARC protection, established exclusively from public DNS data, containing no Client Data.

✓ « Verification pages (Check) » Module: public pages indicating, for a given domain, its level of protection against spoofing, established from public DNS data.

✓ Free security-testing tools (« /tools » page): freely accessible tools, independent of the subscription to the Service, allowing a domain's exposure to a given vulnerability to be tested. The first of these tools, « WP2SHELL », tests a WordPress site's exposure to the vulnerability known as « wp2shell ». These tools perform a non-intrusive diagnostic under the conditions and limits of Article 6 ter.

Subscription to a Module during the Contract is possible under the conditions provided in Article 5.2 above.

Retention of DMARC Reports. The fine-grained data of the collected aggregate reports (RUA) are retained according to the plan subscribed by the Client: thirty (30) days for the Free plan, ninety (90) days for Starter, one hundred and eighty (180) days for Pro, three hundred and sixty-five (365) days for Business and seven hundred and thirty (730) days for Enterprise. Upon expiry of this period, the fine-grained data are deleted; anonymized monthly aggregates are retained in order to maintain the posture history. The applicable period is that of the plan in force under the Contract; these periods may change with the commercial offer.

5.4. Additional services

Where the Client expresses a need for a service not included in the Service, HUCENCY may, at its sole discretion, offer to supply one or more additional services. The description of the additional services and the applicable financial conditions are set out in a dedicated quote or Purchase Order. The additional services are invoiced in addition to the price of the Service, at the rates in force on the day of the order.

The additional services are invoiced in addition to the price of the Service, at the rates in force on the day of the order, and may be:

  • (a) invoiced on a fixed-fee basis (fixed price per service); and/or
  • (b) invoiced according to the actual consumption of the Client and its Users (for example number of calls, volume of requests processed, number of units or credits consumed, processing time, or any other usage indicator defined in the Purchase Order or at the time of the online subscription).

HUCENCY may in particular supply to the Client, upon the latter's order, the following additional services:

✓ « Pay-as-you-go » services: mean the additional services based on variable use of the Services (for example use of artificial-intelligence (AI) features, automated processing, service calls or credits), invoiced according to the actual consumption of the Client and/or its Users, in accordance with the units of measure, thresholds and rates defined in the Purchase Order or the quote or at the time of the online subscription. The units of consumption and the corresponding rates are defined in the Purchase Order or the dedicated quote or in the online price list. Consumption is calculated on the basis of the technical logs and the usage counters of the DMARC platform, which are authoritative between the Parties, save proof to the contrary provided by the Client. The Client is informed that certain AI features may be subject to consumption thresholds (for example number of requests included per period, monthly caps) beyond which additional overage charges may be invoiced, according to the financial conditions indicated in the Purchase Order or in the online price list.

6. Information – Warning

HUCENCY warns the Client, and the Client expressly acknowledges, that:

  • The Service is supplied to it without any obligation of result, performance obligation or warranty, such that HUCENCY may in no event be held liable for damage of any nature caused to the Client or to any other person resulting from a domain-identity spoofing attack, a phishing attack or any other malicious attack targeting the Client, its correspondents or a third party;
  • The Solution analyzes the DMARC Reports and makes configuration recommendations, but the actual publication of the DNS records (SPF, DKIM, DMARC) and any modification of the DMARC policy fall under the sole responsibility of the Client, who retains control thereof. The Client is informed that a premature or erroneous hardening of the DMARC policy (transition to « p=quarantine » or « p=reject ») may result in legitimate emails being quarantined or rejected. It is incumbent upon the Client to verify its sending sources and to test its configurations before any modification. HUCENCY may not be held liable for the consequences of a DNS or policy modification decided upon and applied by the Client, nor for any deliverability failure resulting therefrom;
  • More generally, the Service in no way constitutes a security audit service, nor a guarantee of security or deliverability, such that HUCENCY may in no event be held liable for any damage caused to the Client or to any other person by reason of a security breach or any other malfunction affecting the Client's IT environment.

6 bis. « Thomas » AI Assistant — nature, limits and absence of warranty

The Client is expressly informed of and accepts that the « AI Assistant – Thomas » Module is based on generative artificial-intelligence technologies (large language models) provided in particular by a third-party subcontractor (see Annex 2). The current artificial-intelligence provider is the company Anthropic. HUCENCY reserves the right to replace it at any time with any other model or provider, in particular a model hosted within the European Union by a third party or by HUCENCY itself, in accordance with the subcontractor-change procedure provided in Annex 2 (Article 5). Such a replacement may modify the location of the processing and, where applicable, remove any transfer of data outside the European Union.

In this respect, the Client acknowledges that:

  • the analyses, interpretations, DNS records, recommendations and remediation sequences proposed by Thomas are provided for information purposes, for the purposes of assistance, and may contain errors, inaccuracies, omissions or outdated information (including plausible but inaccurate answers);
  • these elements constitute neither professional, legal or security advice, nor a guarantee of result or compliance;
  • it is incumbent upon the Client to have any recommendation of Thomas verified by a qualified person before applying it, in particular before any publication or modification of a DNS record or of a DMARC policy;
  • the decision whether or not to apply a recommendation, as well as its implementation, fall under the sole responsibility of the Client.

HUCENCY implements reasonable measures for the quality of the assistant's answers (in particular by basing its analyses on the Client's data) but does not guarantee their accuracy, exhaustiveness or suitability for a particular need. HUCENCY may not be held liable by reason of a decision taken or an action carried out by the Client on the basis of an answer of the assistant, within the limits provided in Article 21. Exchanges with the assistant are processed under the conditions of Annex 2; they are not used to train the models of the third-party subcontractor.

6 ter. Free security-testing tools — nature, limits and authorization

HUCENCY makes available, freely accessible on its site (« /tools » page), free tools allowing a domain's exposure to a given vulnerability to be tested. The first of these tools, « WP2SHELL », tests a WordPress site's exposure to the vulnerability known as « wp2shell ». The use of these tools is independent of the subscription to the Service and is subject to the stipulations of this article, which the user of the tool accepts prior to each test.

By requesting a test, the user of the tool:

  • attests that it is the owner of the tested domain or its duly authorized administrator, and expressly authorizes HUCENCY to carry out the requested test thereon. Ownership of the domain is verified beforehand by means of a technical challenge (publication of a DNS TXT record); testing a domain over which the user of the tool holds no right or authorization is strictly prohibited and falls under its sole responsibility;
  • acknowledges that the test is a non-intrusive diagnostic: it is limited to reading publicly accessible signals, exploits no vulnerability and makes no modification to the tested domain or site;
  • acknowledges that the result communicated constitutes a risk assessment, provided for information purposes and without any obligation of result, which constitutes neither proof of exploitability, nor a security audit service, nor a security warranty within the meaning of Article 6. It is incumbent upon the user to have any potential exposure verified and, where applicable, corrected by a qualified person;
  • accepts that its consent to the test be time-stamped and retained, together with its IP address, as evidence, in accordance with Article 25 and the privacy policy accessible on the site.

HUCENCY implements reasonable measures for the reliability of these tools, but does not guarantee the accuracy or exhaustiveness of the diagnostic, nor the absence of false positives or false negatives. It may not be held liable by reason of a decision taken or an action carried out by the user of the tool on the basis of a result, within the limits provided in Article 21.

7. Subscription terms

Subscription to the Service requires the validation (electronically or by hand) by the Client of a Purchase Order established by HUCENCY on the basis of the information and needs transmitted by the Client, comprising the particular conditions applicable to the supply of the Service (scope, options subscribed, price, etc.), to which these CGS are annexed, or, for online subscription, the acceptance of these CGS and the validation of the chosen subscription on the Client Interface. The validation of the Purchase Order or of the online subscription by the Client constitutes unreserved acceptance on its part of the said CGS. The Client expressly accepts that the validation of the Purchase Order or of the subscription may be carried out by any electronic means.

The Client expressly acknowledges that its validation of the Purchase Order or of the online subscription constitutes a firm and final order for the Service on the conditions of the Contract. By validating, the Client further acknowledges having benefited from all the information and advice enabling it to assess the suitability of the Service to its needs. Accordingly, any liability of HUCENCY shall be excluded in the event of unsuitability of the Service or if the latter does not prove to be in conformity with the Client's expectations, in particular as regards result and performance.

Save contrary stipulation, the Purchase Orders issued by HUCENCY have a validity period of one (1) month.

8. Technical prerequisites

Compliance with certain technical prerequisites and instructions is necessary for the proper performance of the Service. These prerequisites and instructions are brought to the Client's attention in the « Technical Prerequisites » annex to the Purchase Order, on the Client Interface or in the Documentation. The Client is in particular informed that the reception of the DMARC Reports requires the publication, in the DNS zone of the concerned domains, of the records indicated by the Solution, and that it must hold the necessary rights over this DNS zone.

Prior to the validation of the Purchase Order, the Client undertakes to carry out all necessary due diligence to comply with the prerequisites thus specified. Failing this, HUCENCY may not be held liable in the event of non-performance, non-conformity or malfunction of the Service that may result therefrom, in whole or in part. Likewise, the Client may in no event claim termination of the Contract in this scenario.

9. Commissioning

In order to be able to supply the Service in accordance with the Contract, HUCENCY must first ensure its commissioning with the collaboration of the Client. The preliminary commissioning phase may comprise, depending on the size of the Client's organization, the following steps and operations:

✓ Meeting to present the implementation steps and the elements necessary for the launch of the Service; ✓ Configuration and customization of the Solution; ✓ Publication of the DNS records allowing the reception of the DMARC Reports and verification of their proper handling.

After completion of the aforementioned operations, the Solution will be made available to the Client (opening of the User Accounts on the Client Interface) and the collection of the DMARC Reports will be initiated.

The practical arrangements for the services (duration, schedule or other) are provided in the Purchase Order. The deadlines or schedules communicated by HUCENCY are provided for information purposes.

The Client undertakes to collaborate actively and in good faith with HUCENCY and to make itself available in the context of the services, in particular at the commissioning stage. Failing this, HUCENCY may in no event be held liable in the event of non-performance or late performance. Likewise, the Client may not terminate the Contract early in this scenario.

The Client is further informed that the supply of the Service will start upon the end of the preliminary commissioning phase, with no possible deferral.

10. Provision of the Solution

10.1. Mode of access

The Solution is accessible over the internet from the IT environment of the Client or that of the Users (terminals, internet network, etc.).

The Users access the Client Interface by connecting to their User Account by means of their credentials.

Certain public features of the Solution (in particular the public analysis of a domain and the Thomas assistant in public mode) may be accessible without the creation of a User Account, under the conditions indicated on the Solution.

HUCENCY is not responsible for the acquisition, implementation, configuration, connection and maintenance of the various elements of the configuration and of the telecommunications means allowing access to the Solution.

10.2. Rights of access and use

By these terms, HUCENCY grants the Client a right of remote access to and use of the Solution. This right of access and use is granted on a personal, non-exclusive, non-assignable and non-transferable basis, for the whole world and for the duration of the Contract. It is granted solely for the internal needs of the Client directly related to its activity and for the sole and unique purpose of allowing the use of the Solution by the Client and the Users in accordance with its intended purpose and the stipulations of the Contract. To this end, HUCENCY also grants the Users a right of remote access to and use of the Solution under the same conditions. Any other use or exploitation of the Solution is expressly prohibited and may give rise to the termination of the Contract for breach by the Client, without prejudice to any damages to which HUCENCY may be entitled.

10.3. User Accounts – Credentials

According to the Client's needs, HUCENCY makes available to the latter one or more User Accounts allowing access to the Solution. The Client is solely responsible for the use made of the Solution, whether by itself or by the Users. Access to the accounts is by means of credentials (login and password). The credentials are unique, personal and strictly confidential. It is expressly prohibited to transfer them to a third party. Actions carried out on the Solution once connected by means of its credentials are deemed to be performed by the Client. The Client is solely responsible for maintaining the confidentiality of the credentials, to the exclusion of HUCENCY, and must take the necessary measures so that they cannot be used by unauthorized persons. HUCENCY is released from any liability in the event of loss, unlawful or fraudulent use of the credentials and is in no event responsible in such case for the actions that may be carried out by unauthorized third parties on the Solution made available to it. In the event of loss, suspicion of disclosure or disclosure of credentials, the Client must immediately generate a password renewal and contact HUCENCY.

10.4. Service levels

HUCENCY ensures the hosting, availability, support and maintenance of the Solution in accordance with the service levels provided below.

Hosting - Availability The Solution is hosted under the responsibility of HUCENCY with one or more third-party hosting providers of its choice. HUCENCY remains free to change hosting provider during the Contract insofar as this does not cause any degradation of access to the Solution. Hosting is carried out on servers located in France (Scaleway, fr-par region). It is planned that the Solution will be hosted on HUCENCY's own servers, located in France, no later than 30/09/2026.

HUCENCY uses its best efforts to ensure that the Solution made available to the Client remains available 24 hours a day, 7 days a week and 365 days a year, with a monthly availability rate of 99.50%.

The Parties agree that unavailability corresponds to the total impossibility for any User to access the Solution in its entirety.

The Client is informed that the Solution may experience periods of unavailability by reason of scheduled maintenance interventions and the deployment of updates carried out by HUCENCY. The unavailability times generated by these operations will not be taken into account in the calculation of the monthly availability rate, where applicable.

Technical support (level 1) HUCENCY makes available to the Client a support service (level 1) responsible for handling the Client's requests for information concerning the use of the Solution in general and for dispensing usage recommendations and advice if necessary.

The technical support service may be contacted:

  • By any User;
  • Monday to Friday from 9 a.m. to 12 p.m. and from 2 p.m. to 5 p.m. (business days and business hours, excluding public holidays);
  • By telephone at (+33)2 21 81 41 81
  • By E-mail at the address support@dmarc.com

HUCENCY undertakes to respond to requests for information as soon as possible. Responses are sent by E-mail or directly by telephone.

Corrective maintenance (level 2) HUCENCY makes available to the Client a corrective maintenance service responsible for handling reports and the resolution of Anomalies affecting the Solution. Corrective maintenance includes, if necessary, the development of source-code fixes, but not the development of new features.

The corrective maintenance service may be contacted:

  • By any User;
  • Monday to Friday from 9 a.m. to 12 p.m. and from 2 p.m. to 5 p.m. (business days and business hours, excluding public holidays);
  • Through the ticketing tool made available by HUCENCY.

Any report of an Anomaly must imperatively include a description of the Anomaly and a proposed qualification of the Anomaly (Minor Anomaly, Major Anomaly, Blocking Anomaly). Failing to include this information, the report will not be taken into account by HUCENCY without this being able to engage its liability in any respect whatsoever. The report is effective from the receipt of the report on the ticketing tool.

Upon receipt, HUCENCY's technical service acknowledges receipt and carries out a preliminary remote study of the problem encountered, in order to identify its origin and qualify the Anomaly. Only the qualification established by HUCENCY will be taken into account to determine the applicable handling times.

If possible, HUCENCY resolves the Anomaly immediately. Failing this, the Anomaly will be resolved under the conditions defined hereafter according to the qualification adopted.

HUCENCY will use its best efforts to resolve the Anomalies within the times stipulated below:

Main Module:

Qualification Time to take up the report* Resolution time**
Blocking Anomaly 12 business hours 24 business hours
Major Anomaly 24 business hours 14 business days
Minor Anomaly 5 business days 30 business days

Additional Modules:

Qualification Time to take up the report* Resolution time**
Blocking Anomaly 24 business hours 14 business days
Major Anomaly 48 business hours 60 business days
Minor Anomaly 5 business days 120 business days

* the take-up times run from the receipt of the report and end when the maintenance operations begin. They include the time for HUCENCY to qualify the Anomaly.

** The resolution times run from the end of the intervention time and end when the Anomaly is resolved (workaround included).

HUCENCY's intervention may give rise to the provision of a workaround pending the supply of a definitive corrective solution.

An intervention report will be sent to the Client following the intervention by E-mail or via the ticketing software. The request will then be closed.

Evolutive maintenance – Updates The Client benefits from the updates and functional developments of the Solution carried out at HUCENCY's initiative, which are subject to the Contract from their entry into production.

HUCENCY ensures the provision and deployment of the updates and developments and, where applicable, transmits to the Client the related documentation.

HUCENCY will inform the Client by any means (E-mails or via the Solution) of the updates to be carried out by the latter, where applicable, when their deployment requires an action on its part. HUCENCY may not be held liable in the event of malfunction, unavailability, or non-conformity of the Solution with the stipulations of the Contract resulting from a refusal or failure to implement an update required by HUCENCY. The deployment of updates may render all or part of the Solution unavailable, which the Client expressly accepts, without this being able to constitute a breach by HUCENCY.

Scheduled maintenance HUCENCY may be required to carry out scheduled maintenance interventions from time to time in order to ensure the proper functioning of its Services. In such case, HUCENCY will inform the Client beforehand at least two (2) business days in advance, save imperative security necessity, indicating to it the expected duration of the intervention. HUCENCY will endeavor to carry out these operations outside office hours (before 9 a.m. and after 6 p.m., business days and business hours). These interventions may render the Solution temporarily unavailable, which the Client expressly accepts, without this being able to constitute a breach by HUCENCY.

Exclusions HUCENCY will not be bound by the service-level commitments provided in this article, nor may it be held liable or be required to pay any penalty whatsoever in the following cases:

  • Refusal of the Client to collaborate with HUCENCY in the resolution of Anomalies and in particular to answer HUCENCY's questions and requests for information, or inaction of the Client following a recommendation or request sent by HUCENCY;
  • Use of the Solution in a manner not in conformity with its intended purpose or with any rule, prerequisite, documentation, notice, or usage instruction brought to the Client's attention;
  • Unauthorized modification of the Solution by the Client or by a third party, and more generally, any unauthorized intervention by the Client, a User or a third party;
  • Breach by the Client of one of its obligations under the Contract;
  • Deployment or use of any hardware, browsers, software packages, software or operating system that is obsolete or not compatible with the Solution;
  • Failure of the electronic communication networks, and more generally, occurrence of a case of force majeure;
  • Deliberate act of degradation, malice, sabotage, intentional fault of the Client or of a person under its responsibility;
  • Cyberattack on the Client's system;
  • Damage affecting software not supported by HUCENCY under the maintenance (third-party software);
  • Malfunction outside HUCENCY's technical control, such as malfunctions attributable to or affecting the IT environment of the Client or of one of its staff, or the third-party mail servers sending the DMARC Reports.

Any intervention by HUCENCY following an Anomaly caused directly or indirectly by one of the above causes, or more generally, not handled under support or maintenance, may be invoiced additionally on the basis of the applicable hourly rate.

11. Financial conditions

11.1. Price of the Service

In consideration for the supply of the Service, the Client will be required to pay HUCENCY:

  • Where applicable, a fixed sum corresponding to the commissioning or onboarding services, the amount of which is set out in the Purchase Order, payable on the day of subscription;
  • A monthly and/or annual fee per Module or option, which may be calculated:
  • Either according to the subscription plan and the thresholds (number of domains, seats, credits included) subscribed by the Client, any threshold overage giving rise to the application of additional invoicing;
  • Or according to actual consumption (in particular AI assistant credits);
  • Or on a fixed-fee basis.

The amounts and methods of calculation of the applicable fees are indicated in the Purchase Order or in the online price list on the day of subscription.

In the case of online subscription, the subscription plans and their rates are those displayed on the Solution's price list on the day of subscription. For information purposes at the date of these terms: Free plan (0 €), Starter (199 € HT/month), Pro (349 € HT/month), Business (699 € HT/month) and Enterprise (on quote). The annual subscription is invoiced on the basis of ten (10) months for twelve (12) months of access (two months free). Use of the « Thomas » AI assistant is counted in credits: each plan includes a monthly volume of credits; the assistant displays an estimate before each action and is invoiced only according to actual consumption, which may not exceed the estimate communicated. Credit top-ups may be offered for sale. The volumes of DMARC Reports included in each plan constitute a reasonable usage threshold; exceeding them gives rise to an invitation to change plan and not to per-unit invoicing.

Save contrary stipulation, the fees are invoiced in advance and the invoices are payable within 30 days of their issuance, by bank card, transfer or direct debit. No early-payment discount will be granted in the event of early payment.

In the case of online subscription, the invoicing, collection and issuance of receipts and invoices are carried out through the payment provider Stripe (see Annex 2). Payment is made by bank card (auto-renewing subscription) or, for annual subscriptions, by bank transfer. The Service is activated upon effective receipt of payment. HUCENCY does not retain any bank-card data.

The prices charged by HUCENCY are indicated in euros and are understood exclusive of tax (HT). They will be increased by the amount of the VAT applicable on the day of invoicing. They include, where applicable, the rebates and discounts granted to the Client.

11.2. Rate revision

The rates may be revised each year to be indexed on the Syntec index, taking into account the formula P = (Po x S) / So, in which:

P represents the pre-tax price of the concerned services after the revision; Po represents the pre-tax price of the services at the date of entry into force of the Contract or at the date of the previous revision; S represents the value of the last Syntec index published at the date of revision; So represents the value of the last Syntec index published at the date of entry into force of these terms or at the date of the previous revision.

In addition to the aforementioned indexation, HUCENCY reserves the possibility of modifying its rates at the end of each contractual period. The parties agree that the revised rate may not be higher than the rate indexed on the basis of the last Syntec index published at the date of revision, increased by three (3) points. In such case, HUCENCY informs the Client in writing at least 30 days before the deadline of the applicable notice period. In the event of refusal of the new rates, the Client must terminate the Contract in compliance with the notice period agreed between the Parties. Failing this, the revised rates will be fully applicable from the date of renewal of the Contract.

11.3. Payment default

Any payment default by the Client within the times set in the Contract may result in the suspension of the supply of the Service, in whole or in part.

Furthermore, any sum not paid at maturity will give rise to the payment of late-payment penalties due on the day following the agreed settlement date. The penalties are equal to the interest rate applied by the European Central Bank to its most recent refinancing operation, increased by 10 percentage points. The late-payment penalties are payable as of right without a reminder being necessary. Any payment delay entails as of right, in addition to the late-payment penalties, an obligation for the debtor to pay a fixed indemnity of 40 € for recovery costs.

The Client must in addition reimburse all costs occasioned by the contentious recovery of the sums due, including the fees of ministerial officers. The late-payment penalties are payable without formality or particular formal notice. In no event may payments be suspended or be the subject of any set-off without the prior written agreement of HUCENCY. Any partial payment will first be imputed to the sums whose maturity is the oldest. In the event of non-payment of a matured invoice, the other invoices will become immediately payable.

12. Obligations of the Client

12.1. Payment

The Client undertakes to pay any sum due to HUCENCY pursuant to the Contract in accordance with the payment terms provided between the Parties.

12.2. Collaboration

The Client is informed that active and loyal cooperation on its part is decisive in order for HUCENCY to be able to make the Solution available to it and supply the Services to it in a conforming manner.

In this respect, the Client undertakes:

  • To inform HUCENCY spontaneously and in a timely manner of any particularity of its company and its business likely to influence the supply of the Service, and the performance of HUCENCY's contractual commitments in general;
  • To answer HUCENCY's requests for information insofar as they are necessary for the supply of the Service and to make itself available in particular in the context of the commissioning;
  • To communicate without delay to HUCENCY any information or document that it may request, within the limit of what is necessary for the supply of the Service;
  • To perform all the tasks incumbent upon it (communication of the necessary information and documents, answers to HUCENCY's requests for information, cooperation in the context of the commissioning and maintenance, etc.), and more generally, to carry out any action required by HUCENCY with a view to the proper performance of the Service;
  • To alert HUCENCY spontaneously and in a timely manner of any event of which it becomes aware during the Contract that may affect the supply of the Service;
  • To make available in a timely manner all the human and material resources necessary for the perfect performance of the Services, and to give any instruction to its personnel so that the latter fully collaborates with HUCENCY.

HUCENCY may in no event be held liable in the event of non-performance due to a lack of cooperation of the Client under the conditions defined in this clause. Likewise, the Client may in no event claim termination of the Contract for fault in this scenario.

12.3. Conforming use of the Solution

The Client undertakes to use the Solution:

  • In accordance with the stipulations of these terms and within the limits of the rights granted by them;
  • In a normal, reasonable, non-fraudulent manner and in accordance with its intended purpose;
  • In compliance with all usage rules or recommendations communicated by HUCENCY or made accessible, in particular by way of display, publication, or notification on the Solution;
  • In compliance with the intellectual property rights of HUCENCY and those of third parties, and with any regulations in force.

In particular, the Client refrains notably from:

  • Using the Solution for purposes other than those resulting from its strict intended purpose, such as in particular supervising or analyzing domains over which it holds no right or authorization, or using the Solution for malicious purposes;
  • Creating or attempting to create derivative works of the Solution, translating it, disassembling it, recompiling it, compiling it, decompiling it, carrying out reverse engineering or attempting to do so, save within the limits authorized by law;
  • Assigning, selling, renting, lending, sublicensing, distributing, transferring, representing, disseminating, marketing or making available the Solution, in whole or in part, or authorizing or designating a third party to do so, other than within the framework and within the limits permitted by this Contract;
  • Modifying all or part of the Solution and/or merging all or part of the Solution into other computer programs or providing anyone with the means to do so;
  • Transferring its User Account and/or its credentials to an unauthorized third party or, more generally, making available to unauthorized third parties its account on the Solution by any means whatsoever without the express, prior and written consent of HUCENCY;
  • Disrupting or attempting to disrupt the proper functioning of the Solution, in particular by integrating into it viruses or other malicious software and technologies likely to alter its functions in whole or in part;
  • Circumventing the access- and/or use-limitation measures of the Solution, such as robot-exclusion protocols;
  • Using robots or automated agents (bots, spiders, scrapers or others) or any other automated process to access the Solution;
  • Carrying out data mining on the Solution;
  • Extracting and/or reusing a qualitatively or quantitatively substantial part of HUCENCY's databases;
  • Extracting and/or reusing, in a repeated and systematic manner, all or part of HUCENCY's databases;
  • Correcting or having corrected by a third party the alleged errors, bugs or other non-conformities of the Solution, HUCENCY reserving the maintenance of the Solution.

The Client guarantees compliance with all of these obligations by any User, including where the Client entrusts the use of the Solution to a third party on its behalf. Any violation by a User of any one of these obligations will engage the liability of the Client.

12.4. Use of the Solution by a third party on behalf of the Client

Where the Client intends to entrust the use of the Solution on its behalf to a third party, it must seek the prior written authorization of HUCENCY. Failing this, any use of the Solution by a third party will constitute a violation of the Contract on the part of the Client.

Where authorization is granted to it, the Client undertakes to communicate to the designated third party all the rules applicable to the use of the Solution (content of these general conditions, excluding any particular conditions agreed between the Parties, and any usage documentation possibly provided by HUCENCY).

The Client guarantees compliance with these rules by this third party. Any violation of the usage rules by the designated third party will engage the liability of the Client.

13. Intellectual Property

13.1. Rights over the Solution

HUCENCY is and remains the holder of the intellectual property rights over the Solution and over all the elements that compose it (structure, source codes, documentation, graphic content, images, texts, photographs, visuals, sounds, videos, trademarks, logos, domain names, etc.), and of the know-how attached to it.

These elements are protected by the laws relating to intellectual property and others, and in particular by copyright and trademark law. The rights of access to and use of the Solution granted to the Client under these terms confer upon it no intellectual property right over it.

Consequently, the Client undertakes to respect the intellectual property rights bearing on the Solution and all its components and, more generally, not to use or exploit all or part of the Solution for purposes other than those strictly agreed under these terms. Any unauthorized exploitation, any total or partial reproduction or representation of all or part of the Solution by any process whatsoever, is prohibited and would constitute an infringement sanctioned by the French Intellectual Property Code.

13.2. Warranty against eviction

HUCENCY warrants the Client against its own act in accordance with the provisions of Article 1628 of the French Civil Code. HUCENCY also warrants to the Client that the elements of the Solution subject to the distribution right integrate no element over which a third party could claim intellectual property or exclusive rights, and that it holds all rights authorizing it to grant the rights of access to, use of and distribution of the Solution under the conditions of these terms.

In this respect, HUCENCY undertakes to defend the Client at its own expense against any infringement action from a third party invoking an intellectual property right to which the exploitation of the Solution by the Client under the conditions of these terms would have caused harm, or an act of unfair and/or parasitic competition, subject to having been immediately notified thereof by the Client and provided that the alleged violation is not the act of the Client or of a person under its responsibility. Consequently, HUCENCY will bear all damages to which the Client would be ordered resulting from one of the aforementioned actions.

If an element of the Solution is recognized, by an enforceable court decision, to constitute an infringement or if it is likely that this element may be qualified as an infringement, HUCENCY may, at its choice, and subject to the indispensable character of this element for the provision of the Solution under equivalent conditions, either (1) obtain at its own expense the right for the Client to continue to use and exploit the element concerned; (2) replace the element concerned or modify it so that it is no longer in violation of the third party's rights; (3) or, subject to the Client's agreement, reduce the scope of the Solution.

14. Data

The Client remains the sole holder of the intellectual property rights and, where applicable, of the industrial property rights and/or the sui generis rights over the Client Data that it provides or that are generated in the context of the use of the Platform, subject to the pre-existing rights of HUCENCY over the Platform, its components and its content.

The Client remains in any event solely responsible for the content of the Data that it transmits, enters or uploads onto the Solution and exploits it in accordance with the rights of third parties and any applicable regulations. HUCENCY may not be held personally liable if the exploitation of the Data, by means of the Solution or more generally in the context of the supply of the Service, were to constitute a violation of a right of a third party (intellectual property right, image right, or others), a publication of unlawful content (insulting, defamatory, violent, discriminatory, etc.) or a breach of a regulation in force, such as in particular the regulations relating to the protection of personal data. In this respect, the Client undertakes to defend HUCENCY at its own expense against any action from a third party or an authority invoking a right to which the exploitation of the Data via the Solution or the Service would have caused harm or the violation of any regulation. Consequently, the Client will bear all damages or other penalties or fines to which HUCENCY would be ordered.

The Client authorizes HUCENCY, for the duration of the contract:

  • (a) to process the Client Data to ensure the operation, maintenance, security, improvement and customization of the Solution, in compliance with the applicable regulations;
  • (b) to process them for the needs of the supply of the agreed services;
  • (c) to transform, anonymize and aggregate them in order to produce Anonymized Data and Aggregated Data.

The Client expressly authorizes HUCENCY, after anonymization, to use the Anonymized Data and the Aggregated Data to:

  • (a) develop, train, configure and improve the algorithms, detection and analysis models of the DMARC posture, of the identification of sending sources, and more generally any technical solution used in the context of the Solution or related services;
  • (b) carry out statistical analyses, studies, including for commercial communication, marketing or publication purposes, provided that no information allows the Client or its Users to be identified;
  • (c) design, test and offer new services, features or content.

HUCENCY refrains from using the Anonymized and Aggregated Data in a manner allowing the identification of the Client, its Users or any natural person. HUCENCY undertakes to implement appropriate technical and organizational measures aimed at guaranteeing a level of anonymization in conformity with the state of the art and the applicable regulations.

15. Hyperlinks

The various interfaces of the Solution may contain elements and/or hyperlinks referring to websites managed by persons distinct from HUCENCY, over which the latter exercises no kind of control. As these sites are not published by HUCENCY, the latter may in no event be held liable for their content or their operation.

16. Confidentiality

The Parties agree that the following information is considered, on a non-exhaustive basis, as confidential information: any information relating to the content of the Contract or to the discussions that led to its conclusion; any information relating to the methodologies, know-how, products, services, tools, software, hardware, industrial designs and data of the parties; any information, in whatever form, relating to the clients, prospects, business relationships, partners, natural person or legal person, of the parties; any information relating to the management, commercial operations, administrative, financial and marketing activities, to their businesses and their projects in the functional and technical fields, even those not expressly linked to the provisions of the Contract; the specific know-how of HUCENCY in matters of cybersecurity and email authentication; the Data; any other information identified as confidential by the parties.

The Parties agree that this confidential information constitutes a trade secret within the meaning of the French Commercial Code.

Consequently, each Party undertakes not to disclose this information to third parties, other than employees or providers who need to know it, and to use the confidential information of the other Party only for the purposes of performance of the Contract.

Confidentiality does not apply to information: that has fallen into the public domain; already known to the Party receiving it at the time of its receipt; the use or disclosure of which has been expressly authorized in writing by the other party; that must be disclosed by virtue of the law or by order of a court.

This clause applies during the duration of the Contract and for as long, after its end, as the concerned information remains confidential for the party disclosing it and, in any event, for a period of two (2) years after the end of the Contract.

The Parties further undertake to ensure compliance with these provisions by their personnel, and by any agent or third party that may intervene in any capacity whatsoever in the context of the performance of their respective obligations.

17. Personal data

17.1. Compliance with the regulations

The Parties undertake to comply with the legal obligations respectively incumbent upon them under the protection of personal data, in particular with regard to the European Regulation 2016/679 of 27 April 2016 on data protection (GDPR) and the French Data Protection Act of 6 January 1978 as amended.

17.2. Processing carried out in the context of the commercial relationship

HUCENCY is required to carry out processing of personal data in the capacity of data controller within the meaning of the GDPR in the context of the management of the commercial relationship with the Client. The arrangements for this processing are detailed in Annex 1 to these terms.

17.3. Processing carried out in the context of the supply of the Service

HUCENCY is required to carry out processing of personal data on behalf of the Client in the context of the supply of the Service in the capacity of processor within the meaning of the GDPR. The arrangements for this processing are detailed in a data processing agreement entered into between the parties in accordance with the applicable regulations and reproduced in Annex 2 to these terms.

18. Commercial reference

Save refusal formulated in writing, the Client expressly authorizes HUCENCY to use its trademarks and other distinctive signs as a commercial reference exclusively, on its communication media, such as its websites and social networks.

19. Termination – Defense of non-performance

19.1. Termination according to the term of the Contract

Where the Contract is entered into for a fixed term, it ends automatically upon the expiry of the contractual duration, without particular formality, save express or tacit reconduction provided in the Particular Conditions. In the case of a fixed-term Contract accompanied by tacit reconduction, each Party may oppose the renewal of the Contract by notifying the other Party of its intention not to renew, subject to a notice period, the duration of which is set in the Particular Conditions, before the expiry date of the current period.

Where the Contract is entered into for an indefinite term, each Party may terminate it at any time, without having to justify a particular reason, subject to compliance with a notice period as agreed in the Particular Conditions.

19.2. Termination for fault – serious breach

In the event of a serious breach or repeated breaches of one or more obligations of the Contract or in the event of a breach of an obligation considered essential between the Parties, the aggrieved party may notify the other party of the termination of the Contract for fault by registered letter with acknowledgment of receipt, without prejudice to the possibility of claiming damages, subject to sending a prior formal notice to perform the obligation in question within a period of thirty (30) days by registered letter with acknowledgment of receipt and provided that the defaulting party has not remedied the situation within this period. The Client's payment obligation is considered essential by the Parties.

In addition to the option of termination under the conditions indicated above, HUCENCY may, in the event of payment default or other breach on the part of the Client, suspend as of right the performance of its obligations, and in particular suspend the Client's access to the Solution in whole or in part until the Client performs.

In the event of termination of the Contract for HUCENCY's fault, the Client will be required to pay for the Service only in proportion to the effective supply of the Service by HUCENCY, it being understood that any month commenced is due in full.

In the event of termination for the Client's fault, the latter will be immediately liable to HUCENCY, without prejudice to any damages, for the entirety of the sums matured or to mature until the normal term of the Contract. It follows that the Client must immediately pay all the sums remaining due to HUCENCY as if the Contract had continued until its term and that HUCENCY will retain, where applicable, all sums already paid by the Client.

The end of the Contract, for whatever cause, further obliges the Client to cease all use of the Solution, except to ensure the extraction of its Data according to the arrangements indicated below.

19.3. Termination at the Client's initiative in the event of a change of provider

The Client may end the Contract at any time, before its term or without waiting for the expiry of the notice period, when it decides to have recourse to another provider of services of a comparable nature (the « Replacement Provider »), subject to notifying HUCENCY in writing of its intention (i) to migrate to the services of another data-processing service provider identical to the one offered by HUCENCY; or (ii) to migrate to its own internal IT infrastructure (on-premise). The notice period applicable in this respect may not exceed two (2) months from the receipt of this notification. During this notice period, the Contract remains in force and the Services continue to be supplied under the usual conditions. In such case, HUCENCY implements the portability, export and cooperation obligations defined in the « Change of Provider » clause and, where applicable, the migration services agreed between the Parties. Where this change of provider at the Client's initiative entails early termination of the Contract (before the expiry of the initial term or of a renewal period), the stipulations of the « Change of Provider » clause apply.

The Parties acknowledge that the charges possibly applicable in the event of termination for a change of provider have the purpose of compensating the technical costs and the tariff advantages linked to the duration of the commitment, without having the effect of abusively hindering the Client's ability to change provider.

The Contract is considered terminated upon the completion of the change process or of the transition to on-site infrastructure successfully completed.

19.4. Survival of certain stipulations

The clauses relating in particular to confidentiality, to intellectual property, to limitations of liability, to early-termination charges, as well as to the portability and migration of the Client's Data, survive the termination or expiry of the Contract for the duration necessary for their implementation.

20. Reversibility and Portability of Data and restitution of data

20.1. Definitions

« Client Data » means all data, information, content, elements, files, DMARC reports (RUA), connection logs, configuration data and analysis results and, more generally, any data of whatever nature, provided or generated by the Client or resulting from its use of the Solution, excluding the software, source codes, tools, models, knowledge bases and other elements falling under the intellectual property of HUCENCY.

« Exportable Data » means the Client Data created or used by the Client when it uses the Service, identified as such in the Contract or in the Documentation, and technically transferable to another provider or to an on-site TIC infrastructure, in accordance with the Data Act (EU) 2023/2854 of 13 December 2023.

20.2. Principle of portability and change of provider

The Client may, at any time and in particular with a view to a change of data-processing service provider or a transfer to its own TIC infrastructure within the meaning of the Data Act, request the portability and restitution of its Exportable Data.

HUCENCY undertakes to facilitate in good faith the change of provider, by cooperating with the Client and, where applicable, with the new provider designated by the Client, in order to ensure the transfer of the Exportable Data under reasonable conditions of time, security and service continuity, in accordance with the Data Act (EU) 2023/2854.

The Client remains liable for the entirety of the Service fees due until the effective date of termination of the Contract.

20.3. Request and authentication arrangements

The portability or change-of-provider request is formulated by the Client in writing (including electronically), through the authorized representative designated in the Contract. The Provider may implement appropriate authentication procedures in order to verify the identity of the requester and to prevent any unauthorized access to the Client Data, in compliance with Article 12 of Regulation (EU) 2016/679 (GDPR) where personal data is concerned. The change process or the transition to on-site infrastructure begins with the written notification of the Client.

20.4. Formats, standards and interoperability

The Exportable Data are made available in a structured, commonly used and machine-readable format, allowing their reuse by the Client and/or their import to another provider, in accordance with Article 20 of the GDPR for personal data and with the provisions of Regulation (EU) 2023/2854 for other data.

HUCENCY undertakes to maintain the compatibility of its export interfaces with the applicable harmonized interoperability specifications and standards for SaaS services, within twelve (12) months following their publication, in accordance with Regulation (EU) 2023/2854.

20.5. Times – Notice – Transitional period

Upon receipt of the portability or change-of-provider request, the Provider acknowledges receipt and communicates to the Client the provisional schedule of the transfer operations. The Client notifies its change-of-provider decision in compliance with a maximum notice period of two (2) months before the desired date of launch of the change process, in accordance with Regulation (EU) 2023/2854. At the end of the notice period, the change process takes place over a maximum transitional period of thirty (30) calendar days, which may be extended by common agreement without being able to exceed seven (7) months in total, according to the volume and complexity of the Exportable Data.

At the end of the transitional period, a period for the Client to recover the data is opened for a maximum duration of thirty (30) calendar days, at the end of which the Exportable Data are deleted by the Provider under the conditions provided in this article.

20.6. Assistance and cooperation of the Provider

During the transitional period and the recovery period, HUCENCY provides the Client with reasonable assistance to:

  • prepare and execute the exports of Exportable Data;
  • document the structure, schema and metadata of the Exportable Data;
  • cooperate with the new provider designated by the Client, within the limit of the confidentiality and security obligations.

HUCENCY informs the Client of the risks of which it is aware linked to the transfer (loss of data, inconsistencies, technical limitations) and of the recommended security measures for the protection of the Client Data during their storage and processing by the Client or by the new provider.

20.7. Portability and change-of-provider charges

In accordance with Regulation (EU) 2023/2854, the change-of-provider and Exportable Data portability charges are progressively removed and, as of 12 January 2027, may not exceed the costs strictly necessary for the technically justified transfer operations, without margin or unjustified additional cost.

The charges possibly applicable, their method of calculation (in particular according to the volume, format and nature of the data, as well as the investments necessary for the collection and production of the data) and, where applicable, the cases of gratuity or capping (for example for certain types of clients) are provided upon the Client's request, in accordance with Articles 8 and 9 of Regulation (EU) 2023/2854.

20.8. Indemnities in the event of early termination of a fixed-term contract for a change of provider

a) Rebate recovery indemnity The Client acknowledges that the price level granted under the Contract takes into account the contractual commitment duration agreed between the Parties. Consequently, as partial compensation for the harm suffered by the Provider on account of the early termination, the Client will pay the Provider a rebate recovery indemnity equal to the total amount of the tariff rebates from which it has effectively benefited in consideration of the contractual duration initially provided and not respected, calculated pro rata to the unperformed commitment period.

The Parties acknowledge that this indemnity reflects the restitution of a tariff advantage expressly granted in consideration for the Client's duration commitment, distinct from the technical change-of-provider process, and must not be interpreted as an unjustified barrier to Switching within the meaning of the Data Act. If the evolution of the legal or regulatory framework, or of the applicable guidelines, were to call into question this proportionate character, the Parties undertake to adapt this article in good faith in order to ensure its compliance.

b) Early-termination penalties In the event of early termination of a fixed-term Contract with a firm commitment, on account of the Client, where this termination occurs following a change of provider (switching) and in the absence of serious fault of HUCENCY or legitimate reason within the meaning of the Contract, the Client pays HUCENCY a fixed early-termination indemnity calculated according to the degressive scale below.

The indemnity is determined according to the duration remaining to run between the effective date of termination and the expiry of the current contractual period, according to the following principles:

Where the termination occurs:

  • during the first year of performance: the Client pays an indemnity equal to 40% of the total amount of the fees remaining to run over the firm term initially agreed;
  • during the second year: an indemnity equal to 35% of the amount of the fees remaining to run;
  • during the third year: an indemnity equal to 30% of the amount of the fees remaining to run;
  • from the fourth year and until the end of the Contract: an indemnity equal to 25% of the amount of the fees remaining to run, it being specified that this percentage may be zero as the term approaches.

The Parties acknowledge that this indemnity takes into account the initial investments and the amortization of the costs of implementation and operation of the Services, decreases as the Contract is performed, so that its amount remains reasonable with regard to the duration of services already supplied, and has neither the purpose nor the effect of constituting a disproportionate barrier to Switching within the meaning of the Data Act.

If an evolution of the legal or regulatory framework, or of the applicable guidelines, were to call into question this proportionate character, the Parties undertake to renegotiate this article in good faith in order to ensure its compliance with the Data Act.

20.9. Complete deletion of the data at HUCENCY

At the end of the recovery period and, in any event, within a maximum period of thirty (30) days following the termination or expiry of the Contract, the Provider proceeds with the complete deletion of the Exportable Data and the associated copies, save legal or regulatory retention obligation, and save contrary written agreement of the parties. The Provider retains, where applicable, the data strictly necessary for the proof of the performance of its contractual obligations, for the duration of the applicable limitation period, in compliance with the personal data protection rules. Upon the Client's written request, the Provider provides a certificate of deletion of the Exportable Data.

20.10. Portability of the personal data of end Users

Where the Client acts in the capacity of data controller within the meaning of the GDPR, it remains solely responsible for the management of the personal-data portability requests presented by the data subjects pursuant to Article 20 of the GDPR.

HUCENCY, acting where applicable in the capacity of processor, implements the technical means allowing the Client to satisfy these requests (export tools, API, machine-readable formats) and cooperates with the Client within the times provided by Articles 12 and 20 of the GDPR.

21. Liability

HUCENCY's liability is limited exclusively to direct and foreseeable damage resulting directly from a proven fault attributable to it. In no event may HUCENCY be held liable for indirect or intangible damage, including in particular, without this list being limitative, loss of operation, loss of production, loss of earnings, loss of profit, loss of contracts, harm to image or reputation, or costs linked to the immobilization of personnel or equipment.

In any event, in the scenario where HUCENCY's liability were to be retained in any capacity whatsoever, the total amount of the indemnities that HUCENCY may be required to pay the Client may not exceed, all sums and all damages combined, the pre-tax amount of the turnover effectively collected by HUCENCY under the Contract during the past year, and this, whatever the legal basis of the claim and the procedure employed to bring it to a successful conclusion.

The Client acknowledges that the limitations of liability stipulated above operate between the Parties a reasonable allocation of the risks and responsibilities with regard to the context and the conditions, in particular financial, of these terms. These limitations do not apply in the event of gross or willful fault on the part of HUCENCY.

HUCENCY's liability, in any capacity whatsoever, is expressly excluded for any damage resulting:

  • From a violation by the Client, or by a User, of any one of the obligations of this Contract;
  • From a defect, in particular of security, affecting the connection terminal (computer, mobile telephone, tablet, etc.) or more generally from a defect affecting or resulting from the IT environment of the Client, a User or a third party with which the Solution is used;
  • Resulting from the inaccessibility, unavailability, suspension, interruption or slowdown of all or part of the Solution due to the saturation at regional or global level of the Internet network, or at the level of the hosting provider's server center, or by reason of maintenance interventions carried out by HUCENCY;
  • Resulting from modification, intrusion, alteration, unavailability of the Solution voluntarily carried out by a third party (person, virus, etc.);
  • Resulting from errors committed by the Client or a User in the use of the Solution or from any use of it not in conformity with its intended purpose or with any documentation, instruction, notice, usage condition provided by HUCENCY, such as the loss, alteration, modification of the Client's Data;
  • Resulting from a decision of the Client to apply (or not to apply) a recommendation of the Solution or of the « Thomas » AI assistant, in particular the publication or modification of a DNS record or of a DMARC policy, or from any deliverability failure resulting therefrom;
  • Resulting from a lack of collaboration of the Client in the context of the maintenance of the Solution;
  • Resulting from any content or any Data put online by the Client or a User on or through the Solution;
  • Resulting from a case of force majeure.

22. Acceptance of the risks linked to the Internet

The Client declares having analyzed the suitability of the Service to its needs in the pre-contractual phase, with the help of a person qualified to advise it if needed, and to accept the characteristics of the Service. The Client declares that it accepts the risks and limits inherent to the Internet and acknowledges:

  • That the Internet presents risks and imperfections, which lead to temporary reductions in its technical performance, to the increase of response times during the online use of the Solution, or even to the temporary unavailability of the servers;
  • That it is incumbent upon it to take all appropriate measures so as to protect its computer hardware and its local network against threats, whatever their origin, and in particular viruses, intrusion attempts by a third party or cyberattack.

23. Force majeure

Neither Party may be held liable vis-à-vis the other for any breach of its obligations if the performance of the Contract is delayed or prevented by reason of a case of force majeure within the meaning of Article 1218 of the French Civil Code and the case-law of the Court of Cassation. The Parties agree in particular that the following events must be qualified as cases of force majeure, without this list being limitative: acts of war, acts of terrorism, riots, labor disputes, internal and external strikes, lock-outs, natural or health catastrophes, fire, water damage, lightning, legal or governmental restrictions, acts of administrative, governmental and judicial authorities not attributable to a fault of the defaulting Party, absence of energy supply, partial or total shutdown of the internet network or of any communication networks.

The Party affected by a case of force majeure informs the other Party thereof immediately by the means it deems appropriate, confirmed by registered letter with acknowledgment of receipt justifying the exceptional circumstances that make the performance of its contractual obligations impossible, and producing all useful justifications. In any event, the Party affected by the case of force majeure must use its best efforts to limit its duration and consequences. In the event that the event giving rise to the case of force majeure were to continue for more than 3 consecutive months, either Party may terminate the Contract by registered letter with acknowledgment of receipt, save express contrary agreement between the Parties.

24. Insurance

Each party declares that it is insured for its professional civil liability with a notoriously solvent company for all the consequences of the Contract. Each Party undertakes to maintain these guarantees throughout the duration of the Contract and to provide proof thereof upon the request of the other Party.

25. General stipulations

25.1. Evidence agreement - Electronic signature

The Parties recognize probative value in the computerized data exchanged between them by any electronic means and in particular through the Solution or any other solution (CRM type). The Client thus expressly recognizes the contractual value, validity and enforceability of any acceptance or action (validations, « clicks », etc.) carried out by it from the Solution or any other solution used once connected to it. The Client guarantees that any User carrying out contractual subscriptions via the Solution (in particular online Module subscriptions) holds all the powers necessary to bind it contractually. In this respect, the connection logs of the Solution or of any other solution used will be authoritative between the Parties and will be enforceable. The computerized registers, retained in HUCENCY's IT systems under reasonable conditions of security, are considered as proof of the communications that occurred between the Parties.

The Parties agree that this Contract or any other contractual documents entered into between them may be signed electronically by means of any electronic signature solution guaranteeing compliance with Articles 1366 and 1367 of the French Civil Code. The Parties recognize in their electronic signature the same value as their handwritten signature and in electronic writings the same value as writings on paper, and in particular that the documents signed electronically will be admitted as originals before the courts and will constitute proof of the contents they contain, admissible, valid and enforceable proof, in the same manner, under the same conditions and with the same probative force as a document bearing a handwritten signature or established on paper.

25.2. Subcontracting

HUCENCY reserves the right to subcontract all or part of the services supplied under the Contract, which the Client expressly accepts. In such case, HUCENCY remains responsible for the proper performance of the subcontracted services vis-à-vis the Client. HUCENCY specifies that the hosting of the Solution will be subcontracted.

25.3. Severability of the clauses

If one or more clauses or stipulations of this Contract are held to be invalid or declared as such pursuant to the law, a regulation or a final decision of a competent court, the other clauses and stipulations will retain all their force and their validity.

25.4. Transmission of the Contract

The Parties undertake not to assign or transfer all or part of the Contract to a third party without the express and prior agreement of the other Party. Notwithstanding the foregoing, HUCENCY may freely assign all or part of the Contract in the context of any company-sale or restructuring operation, such as a merger, demerger, contribution or partial asset transfer.

25.5. Non-waiver

The fact for one of the Parties not to avail itself of a breach by the other Party of any one of the obligations referred to in this Contract may not be interpreted for the future as a waiver of the obligation in question.

25.6. Applicable law – Language

The Contract is governed by and subject to French law. It is drafted in the French language. In the event that it were to be translated into one or more languages, only the French text shall be authoritative in the event of a dispute.

25.7. Disputes

In the event of a dispute or contestation of any nature relating to the validity, interpretation or performance of the Contract, the Parties will seek, before any contentious action, an amicable agreement and will communicate to each other for this purpose all the necessary items of information. Failing an amicable agreement, THE COURTS OF ROUEN HAVING SUBJECT-MATTER JURISDICTION SHALL HAVE SOLE JURISDICTION IN THE EVENT OF A DISPUTE OF ANY NATURE or of a contestation relating to the formation or performance of the Contract, unless HUCENCY prefers to bring the matter before any other competent court. This clause applies even in the event of summary proceedings, incidental claim or plurality of defendants or warranty claim, and whatever the mode and arrangements of payment, without the jurisdiction clauses that may exist in the Client's documents being able to obstruct the application of this clause.

26. Annexes

The annexes below are attached to this Contract and form an integral part of it:

  • Annex 1: Policy on personal-data processing carried out by HUCENCY in the context of the commercial relationship
  • Annex 2: GDPR Data Processing Agreement

ANNEX 1 – POLICY ON PERSONAL-DATA PROCESSING CARRIED OUT BY HUCENCY IN THE CONTEXT OF THE COMMERCIAL RELATIONSHIP

This policy lists and explains the personal-data processing activities implemented by HUCENCY in the capacity of data controller in the context of the commercial relationship between the parties.

1. Data collected

Category Data
Identity of the client/partner, its representatives, employees and/or staff Title, name or company name, address (including registered office, billing location), telephone number, e-mail addresses, internal processing code allowing identification, accounting identification code, SIREN number.
Professional life Profession, position held, economic category, activity.
Settlement / Payment / Transaction Billing identity, billing address, intra-Community VAT number, amount, terms and methods of settlement. The payment data (bank card, bank details) are entered directly with the payment provider Stripe and are not retained by HUCENCY, which retains only the Stripe customer identifier. Transaction number, details of the purchase, order, subscription, and subscribed service.
Monitoring of the commercial relationship Requests for information and documentation relating to HUCENCY's offers. Orders, quotes, invoices, contracts, correspondence and after-sales service, exchanges, opinions and feedback on our offers.
For the purpose of solicitations Data necessary to carry out prospecting, loyalty-building, study, survey, testing and promotion activities.

Certain information must necessarily be provided to HUCENCY. Failing to do so, HUCENCY will not be able to contract with or perform its contractual obligations.

2. Purposes, legal bases of the processing and retention period

Purposes Legal basis Retention period
Conclusion of contracts, orders, provision of services, invoicing, customer support. Performance of the contract Duration of the contractual relationship
Compliance with applicable accounting, tax and legal obligations Compliance with a legal data-retention obligation Archiving for the legal period (up to 10 years for accounting obligations)
Management of pre-litigation and litigation HUCENCY's legitimate interest in establishing proof of a right/of the performance of a contract Duration of the legal limitation period linked to the service
Payment management Performance of the contract Duration of the contractual relationship
Prospecting HUCENCY's legitimate interest in developing its commercial activity; consent for electronic prospecting Up to 3 years from the last contact (730 days for non-converted prospects)
Management of an opt-out list HUCENCY's legitimate interest in being aware of persons who do not wish, or no longer wish, to receive commercial solicitations For 3 years from the exercise of the right
Management of requests to exercise rights (GDPR) Compliance with a legal obligation For 5 years from the request to exercise the right
Audience measurement and journey analysis (cookieless; IP not retained) Legitimate interest 180 days
Security and audit logging Legal obligation / legitimate interest (security) Security events 365 days; by default 180 days; consultations 90 days
Compilation of statistics HUCENCY's legitimate interest in having statistics on its clientele Without time limit in the form of aggregated (anonymized) data

3. Recipients

The recipients of the personal data collected are:

  • HUCENCY's teams, within the limit of their respective duties;
  • The administrative and accounting providers;
  • The technical subcontractors, in particular:
  • Microsoft, for the use of the Microsoft 365 office suite and the sending of transactional e-mails;
  • Stripe, for the management of payments, invoicing and VAT;
  • Close IO for the management of the prospect and client file;
  • Sellsy for the management of the client file;
  • Odoo for the management of the prospect and client file;
  • The administrative and judicial authorities upon requisition on their part or if the law requires it.

4. Transfer of data outside the European Union

Certain of the technical subcontractors of the company HUCENCY may process certain personal data outside the European Union. Where this is the case, the company HUCENCY ensures beforehand that the subcontractors in question take adequate safeguards compliant with the GDPR. List of the possible data transfers outside the European Union and the adequate safeguards taken:

Recipient concerned by the transfer outside the EU Adequate safeguards Countries concerned
Microsoft European Commission Standard Contractual Clauses United States and other third countries
Close IO European Commission Standard Contractual Clauses United States and other third countries
Odoo (backups in Canada) European Commission adequacy decision (Canada) Canada
Sellsy Hosting in France (EU) — no transfer outside the EU European Union (France)
Stripe Processing by Stripe Payments Europe (Ireland, EU) — no transfer outside the EU for this purpose European Union (Ireland)

5. Rights of the data subjects

Under the conditions provided by the regulations relating to the protection of personal data, the persons concerned by the processing have the following rights:

  • Right of access: right to request to access all the data concerning them.
  • Right of rectification: right to request the correction of the data concerning them if they are inaccurate.
  • Right to object: right to request that the use of the data concerning them cease where these data are processed by reason of a legitimate interest, and right to cease receiving commercial prospecting.
  • Right to erasure: right to request the erasure of the data concerning them so that the company HUCENCY ceases to use them.
  • Right to restriction: right to request the provisional cessation of the use of the data concerning them while requiring that they be temporarily retained.
  • Right to portability: right to request an export of the data concerning them in a reusable format and, if possible, to request their transmission to another organization.

The Client holding a User Account may exercise directly a part of these rights from the settings of its account (in particular export and deletion).

To exercise its rights with HUCENCY:

  • E-mail: dpo@hucency.com
  • Postal mail at the address: HUCENCY, 313 rue Edouard Delamare Deboutteville, 76160 Saint-Martin-du-Vivier.

HUCENCY will respond to the request within a maximum period of one (1) month following the date of receipt of the request. In the event of a complex request, a response will be sent within a maximum period of three (3) months following the date of receipt of the request. In the context of the exercise of the rights of a Data Subject, the company HUCENCY may oppose manifestly abusive requests, in particular by their number, their repetitive or systematic character.

6. Complaint to the CNIL

The Client or any other person concerned may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) as soon as it considers that the processing of its data constitutes a violation of the regulations relating to the protection of personal data.

To send a complaint to the CNIL:

  • On the CNIL website: http://www.cnil.fr/
  • By postal mail by writing to: CNIL - Service des Plaintes - 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07.

ANNEX 2 – GDPR DATA PROCESSING AGREEMENT

In the context of their contractual relations, the parties undertake to comply with the regulations in force applicable to the processing of personal data and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the « GDPR ») and Act No. 78-17 of 6 January 1978 on information technology, data files and civil liberties.

In the context of the supply of the Service, HUCENCY will be required to process personal data on behalf of the Data Controller, namely the Client (hereinafter the « Data Controller »), in the capacity of processor within the meaning of the GDPR.

To this end and in accordance with Article 28 of the GDPR, the Parties have therefore come together to agree on the following.

1. Definitions

In this agreement (hereinafter « the Agreement »), the words and expressions in capitals are defined in the contract to which this Agreement is annexed or take on the meanings indicated in the Agreement.

The terms « Personal Data », « Data Controller », « Processor », « Data Subject(s) », « Personal Data Breach », « Processing », « Supervisory Authority » and « Data Protection Officer » have the same meaning as that provided in the GDPR and their related terms must be interpreted accordingly.

2. Purpose of the Agreement

2.1. The purpose of the Agreement is to determine the conditions under which HUCENCY carries out the Processing of Personal Data on behalf of the Data Controller as well as the respective obligations of the Parties. The Processing of Personal Data carried out by HUCENCY on behalf of the Data Controller is detailed in the « Description of processing » Annex to the Agreement.

2.2. The Parties agree that they will provide each other with all useful information to comply with the obligations provided in the Agreement.

2.3 This Agreement constitutes the written instruction of the Data Controller.

3. Duration of the data processing

The duration of the Processing of Personal Data corresponds to the duration described in the « Description of processing » Annex.

4. Obligations of the Parties

4.1. HUCENCY undertakes to:

  • Process the data only on behalf of the Data Controller and for the sole purposes provided in the contract to which this Agreement is annexed as well as in its « Description of processing » Annex;
  • Process the data in accordance with the documented instructions of the Data Controller. Any options, instructions, actions of the Data Controller in the context of the use of the Solution, which imply, in order to be executed by HUCENCY, a Processing of Personal Data, will be considered as constituting the agreement of the Data Controller for the Processing of these Personal Data by HUCENCY. If HUCENCY considers that an instruction constitutes a violation of the GDPR or of any other provision of Union law or of the law of the Member States relating to data protection, it informs the Data Controller thereof immediately. In addition, if HUCENCY is required to carry out a transfer of data to a third country or to an international organization, by virtue of Union law or of the law of the Member State to which it is subject, it must inform the Data Controller of this legal obligation before the processing, unless the concerned law prohibits such information for important reasons of public interest;
  • Ensure the security and confidentiality of the Personal Data processed in the context of this Agreement;
  • Ensure that the members of its personnel authorized to process the personal data by virtue of this Agreement: respect confidentiality or are subject to an appropriate confidentiality obligation; receive the necessary training in matters of personal data protection;
  • Take into account, as regards its tools, products, applications or services that it uses to process the Personal Data, the principles of data protection by design and data protection by default, as defined in Article 25 of the GDPR;
  • Keep a register of all the categories of Processing activities carried out on behalf of the Data Controller in accordance with Article 30 of the GDPR;
  • Subcontract the activities that it carries out on behalf of the Data Controller only with the agreement of the latter in accordance with what is provided in Article 5 below;
  • Notify and assist the Data Controller in the event of a Personal Data Breach in accordance with what is provided in Article 7 below;
  • Assist the Data Controller in carrying out, where applicable, data protection impact assessments and prior consultations of the competent Supervisory Authority;
  • Make available to the Data Controller the documentation necessary to demonstrate compliance with all its obligations and to allow the carrying out of audits, including inspections, by the Data Controller or another auditor it has mandated, and contribute to these audits, and this under the conditions defined in Article 9 below.

4.2. The Data Controller undertakes to:

  • Provide HUCENCY with the data referred to in the « Description of processing » Annex to this Agreement;
  • Transmit and document in writing any instruction concerning the Processing of Personal Data by HUCENCY.

The Data Controller guarantees that the Personal Data processed by HUCENCY in the context of this Agreement and of the application of the contract to which the Agreement is annexed are collected and processed in accordance with the GDPR. In accordance with the European and French legislation on the protection of personal data and in particular the GDPR, the Data Controller guarantees to HUCENCY that it has collected and processes the Personal Data in a lawful, fair and transparent manner, for explicit and legitimate purposes.

The Data Controller is informed that the DMARC aggregate reports (RUA) processed in the context of the Service contain only technical data relating to the sending servers (IP addresses of mail servers, domains, authentication results, volumes), which do not constitute personal data, and that HUCENCY does not collect the forensic reports (RUF).

5. Subsequent subcontracting

HUCENCY is authorized to call upon other processors (hereinafter « the sub-processors ») to carry out specific processing activities. The sub-processors upon which HUCENCY calls are listed in the « Description of processing » Annex to this Agreement.

HUCENCY may call upon other sub-processors. In such case, it informs the Data Controller beforehand and in writing of any envisaged change concerning the addition or replacement of other sub-processors. This information must clearly indicate the subcontracted processing activities, the identity and contact details of the sub-processor and the dates of the subcontracting agreement. The Data Controller has a period of TEN (10) days from the date of receipt of this information to present its objections. If the Data Controller has not raised any objection at the end of this period, HUCENCY may proceed with the subsequent subcontracting.

In the event of an objection from the Data Controller, HUCENCY may waive recourse to the sub-processor or will use its best efforts to propose to the Data Controller an alternative solution in order to avoid processing by the sub-processor being objected to. In this context, the parties undertake to negotiate in good faith and reasonably in order to avoid a deadlock situation or the termination of the main contract.

The sub-processors are required to comply with the obligations of these terms on behalf of and according to the instructions of the Data Controller. It is incumbent upon HUCENCY to ensure that the sub-processors present the same sufficient guarantees as regards the implementation of appropriate technical and organizational measures so that the processing meets the requirements of the GDPR and to frame the processing activities that are the subject of the subsequent subcontracting by a contract comprising, in substance, the same obligations in matters of data protection as those imposed on HUCENCY by this Agreement. HUCENCY remains fully responsible before the Data Controller for the performance by the other processors of their obligations.

6. Exercise of the rights of the persons concerned by the processing

As far as possible, HUCENCY must help the Data Controller to fulfil its obligation to give effect to the requests to exercise the rights of the Data Subjects: right of access, of rectification, of erasure and of objection, right to restriction of processing, right to data portability, right not to be the subject of an automated individual decision (including profiling). All of these rights must be exercised by the said Data Subjects directly with the Data Controller, HUCENCY undertaking to comply with any written and lawful instruction on the part of the Data Controller in this respect.

Where the persons concerned exercise with HUCENCY requests to exercise their rights, HUCENCY will communicate these requests by electronic mail to the Data Controller as soon as possible after becoming aware of them.

7. Notification of personal data breaches

HUCENCY notifies the Data Controller of any personal data breach as soon as possible after becoming aware of it, and by electronic mail. This notification is accompanied by all useful documentation in order to allow the Data Controller, if necessary, to notify this breach to the competent supervisory authority.

It will then be incumbent upon the Data Controller to inform, where applicable, the Supervisory Authority on which it depends and the Data Subjects. On this point, HUCENCY will provide in writing the necessary items in its possession for the notification of the Personal Data Breach by the Data Controller. If, and insofar as it is not possible for HUCENCY to provide the Data Controller with this information at the same time, HUCENCY will communicate the latter to the Data Controller in a staggered manner and as soon as possible.

8. Carrying out of impact assessments and prior consultation of the supervisory authority

HUCENCY helps, as far as possible, the Data Controller for the carrying out of data protection impact assessments and for the carrying out of the prior consultation of the supervisory authority.

9. Audit

HUCENCY makes available to the Data Controller the documentation necessary to demonstrate compliance with its obligations and to allow, within the limit of one audit per contractual year, the carrying out of audits by the Data Controller, or another independent auditor it will have mandated and who must have been the subject of a prior written validation by HUCENCY. These audits will be carried out remotely and on the basis of the information requested by the Data Controller from HUCENCY with a view to demonstrating the procedures and the documentation put in place by HUCENCY to comply with the GDPR. The costs incurred in the context of the said audit will be exclusively borne by the Data Controller. In no event may the audit operations have the object or direct or indirect effects of disrupting the activities of HUCENCY and of accessing or harming, in any manner whatsoever, the elements, properties of HUCENCY, protected under intellectual property or trade secret, including the source codes of the software.

The Data Controller will communicate to HUCENCY, beforehand and at least two (2) months in advance, any request for an audit operation and the date of the audit and the envisaged scope. In any event, the auditor may not have an activity competing with that of HUCENCY, whether on a primary or subsidiary basis.

10. Security measures

HUCENCY undertakes to implement the adequate security measures in order to secure the Personal Data and to ensure their integrity and confidentiality. In this respect, HUCENCY implements the security measures in the following domains:

  • Governance — Watch and project management — Asset management — Classification and transmission of information — Access control — Supplier security — Incident management — Business continuity — Compliance with laws, regulations — Human resources security — Physical and environmental security — User terminals — Operational security — Information management — Logging and monitoring — Software installation — Network security — Cryptography — Change management — Tests and audits.

Are notably implemented: sovereign hosting in France (Scaleway, fr-par region), the encryption of backups (AES-256-GCM) with the key retained off the machine, the logging of 100% of authenticated actions, two-factor authentication and the minimization of the data transmitted to the AI assistant. The detail of the measures is set out in HUCENCY's security policy, available on request.

11. Fate of the data

At the end of the contractual relationship between the Parties, HUCENCY undertakes to destroy all the personal data within a maximum period of one hundred and twenty (120) days. HUCENCY will inform the Data Controller by any written means (E-mail, registered letter with acknowledgment of receipt, etc.) that this destruction has indeed been carried out. The Data Controller may derogate from this period on documented instruction on its part.

12. Data Protection Officer

HUCENCY's data protection officer may be contacted at the address: dpo@hucency.com. The Data Controller communicates to HUCENCY the contact details of its data protection officer in writing upon first request of HUCENCY.


Description of processing

The Personal Data processing activities carried out by HUCENCY in the capacity of processor of the Data Controller pursuant to the main contract to which this Agreement is annexed are described in this annex.

1/ Processing of the Personal Data of Users (Client Accounts)

Item Content
Data Subjects Employees and/or staff of the Client with access to the Client Interface of the Solution.
Nature of the processing Collection, retention, recording, modification, consultation, use, disclosure by transmission, updating, hosting, extraction, deletion, destruction.
Categories of data Identification data (title, first name, surname); professional-life data (professional e-mail address, position); connection data (IP address, date and time of connection, user agent); account identifiers.
Purposes Creation and management of access to the Solution; supply of the DMARC service (collection and analysis of DMARC Reports, posture supervision, assistance from the « Thomas » AI assistant), management of users and domains, sending of reports; management of the security of the Solution; hosting, availability and maintenance of the Solution.
Retention Duration of performance of the contract plus a maximum of 120 days.
Sub-processors Scaleway SAS (hosting, France); Anthropic PBC (« Thomas » AI assistant and analyses, minimized data, United States, CCT/SCC, no training on API data); Microsoft (transactional e-mails and SSO authentication).

2/ DMARC Reports (RUA) — infrastructure data, outside the « personal data » scope

The DMARC aggregate reports (RUA) processed on behalf of the Client contain only technical data relating to the sending servers (IP addresses of mail servers, sending domains, SPF/DKIM/DMARC authentication results, volumes). These data constitute infrastructure data and do not constitute personal data.

HUCENCY does not collect the forensic reports (RUF), which alone would be liable to contain personal data (headers, e-mail addresses).

Consequently, the DMARC reports do not give rise, as such, to a processing of personal data on behalf of the Client. The processing activities carried out by HUCENCY in the capacity of processor are described in the other points of this annex.

3/ Processing linked to the « Thomas » AI assistant in public mode (where applicable)

Item Content
Data Subjects Visitors using the public analysis / the Thomas assistant without an account.
Categories of data Analyzed domain and content of the conversation. Neither e-mail nor IP address is recorded or linked to an account.
Purposes Provision of the public analysis and improvement of the assistant (possible review by the team).
Legal basis Legitimate interest.
Retention 30 days, then automatic deletion.
Sub-processors Scaleway SAS (hosting, France); Anthropic PBC (AI assistant, United States, CCT/SCC).