Version v3-2026-09, appended to the Dematerialisation Operator mandate.
This addendum governs the processing of personal data that Diamontis Informatique carries out on behalf of the client company. It is accepted together with the mandate, and its version is recorded alongside it.
Diamontis Informatique ("the Processor"), publisher of the Diamontis FX service ("the Service"), processes on behalf of the client company ("the Controller") the personal data appearing on its invoices and in the surrounding modules of the Service.
It does not cover the processing for which Diamontis Informatique is itself the controller - user account, subscription, security of the Service - described in the privacy policy.
Nature: collection, structuring, storage, consultation, transmission and erasure of data appearing on invoices.
Purposes: receiving, normalising, displaying and tracking the lifecycle of invoices; submission and transport to the Registered Platform; evidential archiving; making invoices available to their recipient; assisted analysis at import.
Duration: that of the mandate, extended by statutory retention periods, chiefly the ten-year tax retention of invoices and archived records, which survives termination.
Categories of data: company names, SIREN and SIRET numbers, intra-EU VAT numbers, postal addresses, e-mail addresses, names and roles of contacts, amounts, service descriptions, bank details (IBAN, BIC), invoice lifecycle and transport data.
Data subjects: contacts appearing on invoices issued or received by the Controller - directors, accountants, contacts at its suppliers and customers; recipients holding access to the end-customer portal; the accounting professional to whom the Controller grants access (article 4a).
The Processor processes the data only on documented instructions from the Controller. The following constitute such instructions: this addendum, the mandate to which it is appended, the Service documentation, and the Controller's actions in the interface.
The Processor immediately informs the Controller if it considers that an instruction infringes the GDPR or another applicable provision.
The Service lets the Controller grant access to their accountant. Granting it is the Controller's own act, and as such constitutes a documented instruction within the meaning of article 4.
What granting access entails: the designated professional gains access to the personal data contained in the Controller's invoices - contacts, addresses, bank details of their suppliers and customers. That is the very purpose of the access.
What the Processor guarantees in return:
The designated professional acts under the Controller's responsibility. The Processor is not a party to their relationship and exercises no control over how this third party uses the data it accesses.
Persons authorised to process the data are bound by confidentiality. The measures in place include:
What the Processor does not do, and states so: the invoice data itself, bank details included, is not encrypted at rest at application level, and writes to object storage are not encrypted server-side. Its protection rests on the measures above. This limit is stated so that it is known, and will be reconsidered should the risk change.
The Controller gives general authorisation to the following sub-processors. The Processor informs it of any addition or replacement at least thirty days before it takes effect, with the possibility of a reasoned objection.
Timestamping of archives uses a time authority that receives only a cryptographic hash of the document: no personal data is transmitted to it, so it is not a sub-processor.
The Processor assists the Controller in responding to requests to exercise data subject rights - a request received directly by the Processor is forwarded without delay, for the Controller to answer - as well as with security of processing, impact assessment and prior consultation, within the limits of the information available to it.
The Processor notifies any personal data breach within forty-eight hours of becoming aware of it, by e-mail to the account contact address, with the information available to it: nature of the breach, categories and approximate volume of data and data subjects concerned, likely consequences, measures taken. The notification deadline to the supervisory authority under Article 33 runs for the Controller.
At the end of the service, the Processor, at the Controller's choice, returns the data or deletes it, along with existing copies. The Controller has an export function available in the Service at any time.
Express reservation: this obligation yields to statutory retention obligations, foremost the ten-year tax retention of invoices and archived records. Data covered by such an obligation is kept until its term, with no processing other than that required for such retention, and then destroyed.
The Processor makes available the information needed to demonstrate compliance with Article 28, in particular its record of processing activities and its security audit reports. The Controller may request an audit, limited to once a year absent an incident, with reasonable notice, at its own expense, and without the audit compromising the confidentiality of other clients' data.