WP Umbrella Logo

DATA PROCESSING AGREEMENT (DPA)

Last update July 23rd 2026

1. Purpose and hierarchy

1.1. This agreement (the “DPA”) sets out the conditions under which LIVEN STUDIO (the “Processor”) processes personal data on behalf of the User (the “Controller”) in connection with the WP UMBRELLA solution (the “Solution”), in accordance with Article 28 of Regulation (EU) 2016/679 (“GDPR”) and Law No. 78-17 of 6 January 1978.

1.2. The DPA forms an integral part of the contract. In case of conflict, the order of precedence in art. 4 of the T&C applies (T&C, then DPA, then privacy policy). The DPA prevails over the privacy policy for all matters concerning processing carried out by LIVEN STUDIO as a processor.

1.3. The DPA takes effect on the creation of the User’s account and remains applicable for as long as LIVEN STUDIO carries out processing on the User’s behalf.

2. Definitions

Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject and Personal Data Breach have the meaning given by the GDPR. For the purposes of this DPA: the Controller in relation to LIVEN STUDIO is the User; the Processor is LIVEN STUDIO; Documented Instructions are the User’s written, electronic or contractual instructions, of which the T&C and this DPA form the initial basis.

3. Roles and processing chain

3.1. The User acts as Controller (or itself as processor for its own end clients); LIVEN STUDIO acts as Processor. For processing that LIVEN STUDIO performs as a controller (management of its site, billing, prospecting), the User is referred to the privacy policy.

3.2. Cascading sub-processing. LIVEN STUDIO processes data of the User’s end clients and of persons interacting with their sites. The User, a Controller in relation to LIVEN STUDIO and a processor in relation to its end clients, warrants that it has concluded with its end clients an Article 28 GDPR-compliant agreement authorising the use of the Solution, the installation of the WP UMBRELLA plugin and the processing described in art. 4, and warrants that this agreement reflects that processing.

4. Description of the processing

4.1. Nature and purposes: automatic backup of sites, security hardening,; production of maintenance reports; performance, uptime and security monitoring; database cleanup; access via the public API and MCP server. Operations: consultation, structuring, export, retention, transmission, deletion.

4.2. Categories of data subjects: the User’s end clients (site publishers); persons interacting with those sites (administrators, users, internet users).

4.3. Categories of data: end-client identification data (name, first name, site address, email, telephone); data stored on the end client’s site depending on its configuration (civil status, identity, images; connection data, IP addresses, logs, identifiers, timestamps; location data; personal-life data). The User warrants that no special-category data (art. 9 GDPR) is entrusted under this DPA without appropriate measures agreed in writing beforehand.

4 bis. Additional processing, On-demand Services for Malware removal (AI-assisted)

4 bis.1. Scope and trigger. This article applies only where the User orders an On-demand Service (Security Audit or Malware Removal, governed by Annex 1 to the T&C). The User’s order of the service constitutes its documented instruction (art. 28 GDPR) to carry out the processing described below, including transmission of data to the AI sub-processor (art. 4 bis.3). Absent an order, none of the processing described in this article is carried out and no data is transmitted to that sub-processor. A User who does not wish this processing refrains from ordering the service; accordingly, the 30-day prior information and objection procedure (art. 8.2) does not apply to this sub-processor for the User who orders.

4 bis.2. Nature, purposes and data. AI-assisted analysis of the elements of the designated site (files, database contents, logs, configuration) for the purposes of security diagnosis and malware detection/remediation. Operations: transmission to the AI provider, analysis, production of findings and a report, return to LIVEN STUDIO, deletion. The categories of data subjects are identical to art. 4.2. The data submitted may contain personal data of the site’s end clients and users; the User warrants that no special-category data (art. 9 GDPR) is entrusted without appropriate measures agreed in writing beforehand (art. 4.3) and endeavours to limit the data exposed where technically feasible.

4 bis.3. Sub-processor, Anthropic. LIVEN STUDIO engages Anthropic PBC (San Francisco, USA) for the provision of the AI model (“Claude”). Anthropic processes the submitted data solely to return the analysis to LIVEN STUDIO and does not use that data to train its models. LIVEN STUDIO concludes with Anthropic a data processing agreement imposing data-protection obligations equivalent to those of this DPA (art. 8.3) and remains fully liable to the User for Anthropic’s performance of its obligations (art. 8.4). Anthropic appears on the list of sub-processors provided on request (art. 8.1).

4 bis.4. Transfer outside the EU. As Anthropic is established in the United States, the processing entails a transfer outside the EEA, framed by appropriate safeguards under art. 46 GDPR — principally the Standard Contractual Clauses (SCCs), Module 3 (processor-to-processor), completed with a transfer impact assessment (TIA); where Anthropic benefits from an EU–US Data Privacy Framework certification, LIVEN STUDIO may rely on it (art. 9.2). Data in transit is encrypted (TLS).

4 bis.5. Retention. Data transmitted to Anthropic for an On-demand Service is deleted upon completion of the intervention, subject to the limited technical retention applied by the provider for security and abuse-prevention purposes. The audit report and the summary of actions are made available to the User (Annex 1 to the T&C, A.9) and deleted according to the timeframes of art. 14 at the end of the contract.

4 bis.6. Applicable provisions. Articles 7 (security), 10 (assistance), 11 (breach — notification within 48h), 13 (audit) and 15 (liability) apply to this processing. A pre-existing compromise of the site falls to the User as controller, LIVEN STUDIO assisting under this DPA.

5. Documented instructions

5.1. LIVEN STUDIO processes data only on the User’s documented instructions, including for transfers outside the EU, and does not use it for its own purposes.

5.2. LIVEN STUDIO informs the User without delay if, in its opinion, an instruction infringes the GDPR or another applicable data-protection provision; LIVEN STUDIO may suspend performance of the instruction concerned until it is confirmed or amended.

5.3. Where LIVEN STUDIO is required by Union or Member State law to carry out a processing operation (in particular a transfer), it informs the User before processing, unless that law prohibits it on important public-interest grounds.

6. Confidentiality

LIVEN STUDIO ensures that persons authorised to process the data (staff, contractors) are bound by an appropriate confidentiality obligation. This obligation operates together with art. 16 bis of the T&C (mutual confidentiality) and survives the end of the contract.

7. Security (art. 32 GDPR)

7.1. LIVEN STUDIO implements appropriate technical and organisational measures, in particular:

Encryption: data at rest in AES-256; backups encrypted (AES-256 + HMAC-SHA256 authentication); data in transit in TLS 1.2/1.3.

Access controls: multi-factor authentication (MFA) for administrative access; role-based access restrictions (RBAC).

Minimisation and anonymisation; retention limited to the necessary duration.

Resilience and availability-restoration measures.

7.2. These measures may evolve with the state of the art, without reducing the level of security.

8. Sub-processing (art. 28(2) and 28(4) GDPR)

8.1. General authorisation. The User grants LIVEN STUDIO a general authorisation to engage sub-processors for hosting, payment, audience measurement and infrastructure. The current list of sub-processors is provided on request at support@wp-umbrella.com.

8.2. Notification of changes. LIVEN STUDIO informs affected Users at least thirty (30) days before any addition or replacement of a sub-processor, by email or notice in the User space, and gives them the opportunity to object on reasonable data-protection grounds. Failing a resolution, the User may terminate the affected Services without penalty, with a refund of any unused prepaid credit (T&C art. 7.3).

8.3. Equivalence of obligations (flow-down). LIVEN STUDIO concludes with each sub-processor a contract imposing the same data-protection obligations as those set out in this DPA, in particular sufficient guarantees under art. 28.

8.4. Liability. LIVEN STUDIO remains fully liable to the User for its sub-processors’ performance of their obligations.

9. Transfers outside the European Union

9.1. Data is processed within the European Economic Area (EEA). The Application is hosted on servers located in the EU.

9.2. Where a sub-processor is located outside the EEA in a country without an adequacy decision, LIVEN STUDIO frames the transfer with appropriate safeguards under art. 46 GDPR — principally the Standard Contractual Clauses (SCCs), Module 3 (processor-to-processor), of Implementing Decision (EU) 2021/914 of 4 June 2021, completed with their annexes and a transfer impact assessment (TIA). Where a recipient benefits from a valid adequacy decision (including EU–US Data Privacy Framework certification), LIVEN STUDIO may rely on it. Module 2 (controller-to-processor) is used only where a User established outside the EEA is itself the exporter.

10. Assistance to the User

10.1. Data-subject rights. LIVEN STUDIO assists the User, through appropriate technical and organisational measures and insofar as possible, in responding to requests to exercise rights (arts. 12 to 23 GDPR).

10.2. User obligations (arts. 32 to 36). LIVEN STUDIO assists the User, taking into account the nature of the processing and the information available to it, with: security (art. 32); notification of a breach to the supervisory authority and to data subjects (arts. 33 and 34); data protection impact assessments (art. 35); prior consultation (art. 36).

11. Personal data breach

In the event of a personal data breach, LIVEN STUDIO notifies the User without undue delay and no later than forty-eight (48) hours after becoming aware of it. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

12. Records and point of contact

12.1. In accordance with art. 30(2) GDPR, LIVEN STUDIO maintains a record of processing carried out on the User’s behalf.

12.2. LIVEN STUDIO’s privacy point of contact: Mr Aurelio Volle, support@wp-umbrella.com. (As LIVEN STUDIO is established in the Union, it is not required to designate a representative within the meaning of art. 27 GDPR; the earlier reference to a “GDPR representative” is corrected.)

13. Audit (art. 28(3)(h) GDPR)

13.1. LIVEN STUDIO makes available to the User all information necessary to demonstrate compliance with the art. 28 obligations and allows for and contributes to audits, including inspections.

13.2. Terms: once per twelve (12) month period (and following a confirmed breach affecting the User), on reasonable prior notice of at least thirty (30) days, during business hours, without disrupting operations. An audit may take the form of a questionnaire, the provision of existing certifications or reports, or a documentary/on-site review conducted by the User or a mandated third party bound by confidentiality. Each party bears its own costs, except where the audit reveals a material non-compliance, in which case LIVEN STUDIO bears the reasonable costs of the review.

14. Fate of the data at the end of processing (art. 28(3)(g) GDPR)

14.1. At the User’s choice, LIVEN STUDIO deletes or returns all personal data at the end of the contract, and deletes existing copies, unless legally required to retain them.

14.2. Timeframes: deletion within ninety (90) days of the end date; residual backups are deleted within fifty (50) days (consistent with T&C arts. 10.2 and 11.3). On request made before the end date, LIVEN STUDIO provides a machine-readable copy (CSV/JSON).

14.3. Free trial: trial data (dashboard, backups, reports) is deleted ninety (90) days after the end of the trial (consistent with T&C art. 6).

14.4. LIVEN STUDIO may retain anonymised or aggregated data that does not allow re-identification.

15. Liability

The parties’ liability under this DPA is governed by article 20 of the T&C, without prejudice to the allocation provided for in article 82 GDPR.

16. Term, governing law and jurisdiction

The DPA takes effect on account creation and applies for the duration of the processing. It is governed by French law; any dispute falls under the courts having jurisdiction under article 22 of the T&C. The French version prevails.