In force as of 9 September 2026.
This annex is the data processing agreement required by Article 28 of the GDPR. It forms an integral part of the terms of use and completes the privacy rules. Those describe what we do with YOUR data; this one describes what we do with the data of YOUR customers.
This document also exists in French. In the event of any discrepancy between the two versions, the French version prevails.
You are the controller: these are your customers, your prospects, your contacts, and you are the one who decides why and how their data is used. Muzau is the processor: we process it on your behalf, on your instructions, and for nothing else.
Muzau is published by Arthur Osstyn EI, a sole trader trading under the name O2S, SIREN 900 494 048. Contact: contact@muzau.fr. Full details are in the legal notice.
Subject matter and purpose. Running the service you subscribed to: letting your agents read, decide and act according to your rules, and reporting back to you on what they did.
Duration. That of your contract, then the erasure period described below.
Nature of the operations. Collection, recording, storage, consultation, use, transmission to the language model and to the tools you have connected, and erasure.
Data subjects. Your customers and prospects, the people who write to your agents or talk to them on your site, and the members of your team that you declare.
Data concerned. Identity and contact details, the content of exchanges (messages received, replies sent, chat conversations), rows of the tracking files you point us to, calendar slots, and the documents you allow your agents to attach.
Special category data. The service is not designed to process Article 9 data (health, opinions, orientation, trade union membership, biometric data). You undertake not to entrust any to the service, and our guardrails never grant it to an agent automatically.
Your documented instructions are these, and only these:
1. Running the service you asked for, as your agents, your rules and your authorisations describe it.
2. Securing the service and your data, including detecting and stopping abuse or an attack.
3. Maintaining and debugging the service: diagnosing an incident, understanding why an agent got something wrong, and fixing the platform. This is the instruction the next section spells out.
4. Complying with the law, where it requires us to.
You may change or add to these instructions in writing at any time. If an instruction appears to us to breach the GDPR, we tell you rather than carry it out.
What it is. A setting in your workspace, on by default, that lets us open the technical detail of an exchange handled by your agents when the platform has detected a defect or when you report an incident to us. Without it, diagnosing an error means asking you to reproduce it.
It is not consent within the meaning of Article 6 of the GDPR: you cannot consent on behalf of your customers, and we are not asking you to. It is a contractual instruction you give us as controller, and one you can withdraw.
You can switch it off at any time from your settings, without giving a reason and without losing access to the service. Diagnostics then become strictly reactive: we open your data only on an incident you report to us, or for a security reason.
Every opening leaves a record: who looked, which company, what, and when. That record never stores the content consulted.
It does not cover data from your Google tools. Spreadsheets, calendar and files remain subject to Google's limited use requirements: no human consults them, except with your explicit agreement, to resolve an incident you reported to us, for security reasons, or where the law requires it. The setting above changes none of that.
Train a language model on your data, neither ours nor a provider's. Cross-reference one company's data with another's to run the service. Sell, rent or transfer your data. Take the content of an exchange outside the platform.
Improving the product is therefore never done from what an exchange contains, but from what we learn from it: a short, rewritten statement of need is drawn from it, stripped of addresses, links and strings of digits, and a check reads it again just before it goes anywhere, refusing to let it out at the slightest remaining marker.
We do not, however, call that statement anonymous. Redacted text remains personal data under the GDPR, and we treat it as such: the commitments in this annex apply to it in full.
You authorise the following providers, each for the role indicated. All process the data on our behalf, under standard contractual clauses where they are established outside the European Union.
Vercel Inc. (United States, processing executed in the Paris region): hosting of the application.
Supabase Inc. (United States, database hosted in the Paris region): database.
Resend Inc. (United States): delivery of the emails your agents send and receive.
OpenAI (OpenAI Ireland Limited, Ireland; OpenAI, L.L.C., United States) and Anthropic PBC (United States): the language models that make your agents reason. They receive the context useful to a decision, and this data is not used to train any model. We choose which one is used for each task and may change it, without that altering the nature of the data passed on.
Stripe (Stripe Payments Europe, Ireland; Stripe, Inc., United States): collecting subscription and credit payments, and issuing invoices. It receives only your own billing data, never your customers'.
Google Ireland Limited: only the tools you connect yourself (calendar, spreadsheets, files), within the limits of the authorisations you grant and can withdraw.
We inform you in writing at least thirty days before adding or replacing a sub-processor. You may object on data protection grounds; failing agreement, you may terminate at no cost.
We impose on each of them, by contract, the same protection obligations as those we owe you here, and we remain fully liable to you for the way they perform them.
Each company's data is partitioned, and the database itself refuses to let one workspace read another's. The authorisations giving access to your tools are encrypted before being stored (AES-256-GCM). Every action an agent takes is written to a log you can consult, and sensitive actions (sending, attaching a document, committing) go through your approval according to the rules you set. Human access to your data is restricted to the people who need it, and recorded.
The persons authorised to process your data are bound by confidentiality. As of today the publisher is the only person concerned; anyone added will be bound in writing before any access.
We inform you without undue delay and at the latest forty-eight hours after becoming aware of it, with what we know: what happened, which data is concerned, the likely consequences and what we are doing. It falls to you, as controller, to notify the supervisory authority and, where applicable, the data subjects; we help you do so.
We inform you without delay, so that you can exercise your rights, except where the law expressly forbids us to. We first check that the request is lawful, in writing and proportionate, we answer it only so far as it is binding, and we challenge those that do not meet these conditions.
When a person exercises their rights with you (access, rectification, erasure, restriction, portability, objection), we give you the means to answer, and we carry out your erasure requests. We help you in the same way with your impact assessment and your record of processing, within the limits of the information we hold.
You may export your data at any time during the contract. At its end, we erase it within thirty days, unless you ask us to return it to you first, or unless the law requires us to keep it. Access logs are kept for one year for security purposes, then erased.
We make available to you the information needed to demonstrate compliance with this agreement. You may request an audit once a year, on reasonable notice, during business hours and without disrupting the service. We will also answer your customers' security questionnaires where they concern the service.
This annex is governed by French law. Where it conflicts with the terms of use on the processing of personal data, this annex prevails.