Translation provided for convenience. The French version is the only legally binding one.
GDPR data processing agreement
Data processing agreement (Article 28 of the GDPR). Version of September 30, 2026.
This agreement binds the Customer, meaning the organization that uses Please Send It in a professional capacity (company, association, self-employed person), as controller, and PAPEL SAS, a company with share capital of €100, Paris Trade and Companies Register 843 729 864, 58 rue de Monceau, 75008 Paris, which publishes the service, as processor. It forms part of the Terms of Use: it is accepted with them, when the account is created, and applies as soon as the service is used in a professional capacity; the accepted version, the date and the account that accepted it are recorded.
1. Purpose
Hosting, delivering and making available to the Customer the documents, links, answers and signatures its recipients upload, and sending invitations and reminders by email and text message on its behalf.
2. Data and data subjects
- Data subjects: the recipients designated by the Customer, and the members of the Customer's organization.
- Data: name, email, phone number; uploaded files, which may contain ID documents, bank details, pay slips, videos; links and written answers; date of last visit; electronic signatures and their certificate of completion.
- The Customer does not request health data collected in the course of prevention, diagnosis or care.
3. Term and retention
The agreement lasts as long as the Customer's account. Each file received is deleted automatically when the period chosen by the Customer for the project expires, from 30 days to one year after the deadline, and by default 90 days after the deadline; upload links are closed on the same date, and the Customer is notified by email 7 days before. The Customer can delete a project and its files at any time.
4. Instructions
PAPEL processes the data only on the Customer's documented instructions: the settings of its projects and its actions in the interface or through the API. PAPEL informs the Customer if an instruction appears to it to infringe the GDPR.
5. Confidentiality
The persons authorized to process the data at PAPEL are bound by a duty of confidentiality and only access the documents for a technical operation requested by the Customer or a legal obligation.
6. Security
- Encrypted connection (HTTPS) and strict security headers; no resources loaded from another site.
- Files isolated by project and by recipient, content of each file checked on arrival, personal and secret upload links.
- Passwords, API keys and security links stored as hashes; API keys revocable and rate-limited.
- Log of the organization's sensitive actions (invitations, roles, deletions, keys, automatic deletions).
7. Sub-processors
The Customer authorizes the following sub-processors:
- Hostinger International Ltd (Cyprus, server in France): hosting of the service, the database and the files.
- Brevo (Sendinblue SAS, France): delivery of the emails and text messages sent to recipients.
- Cloudflare: domain name management (DNS) only; no recipient data goes through it.
- Documenso: electronic signature software installed on PAPEL's servers, at Hostinger; it is not a third party.
- Anthropic (Anthropic PBC, United States, standard contractual clauses) or Microsoft (Azure OpenAI service), depending on the provider chosen by PAPEL: only if the Customer turns on AI document review, which is off by default. Analysis of the reduced image, or the first three pages, of each document received, with no file kept on their side or used to train their models; sensitive documents only if the Customer expressly allows it with a second checkbox.
Stripe processes the Customer's own payments, as PAPEL's provider; it receives no recipient data. Any addition or replacement of a sub-processor is announced to the Customer 30 days in advance; the Customer can object by terminating free of charge.
8. Assistance
PAPEL helps the Customer respond to requests to exercise data subjects' rights: any request received directly is forwarded to the Customer within 5 business days. PAPEL also helps the Customer, on request, with its impact assessments and its exchanges with the CNIL. Each message sent to recipients states the Customer's name and includes a link to stop receiving reminders; the Customer is notified when a recipient uses it.
9. Personal data breach
PAPEL notifies the Customer of any personal data breach as soon as possible, and no later than 48 hours after discovering it, with the information available, so that the Customer can, where applicable, notify the CNIL within 72 hours.
10. End of the agreement
At the end of the agreement, PAPEL deletes all data and copies within 30 days, unless a legal retention obligation applies. Before that, the Customer can export everything: one ZIP per project.
11. Audit
PAPEL makes available to the Customer the documentation demonstrating compliance with this agreement. The Customer may have an audit carried out at most once a year, at its own expense, with 30 days' notice.
12. Transfers
Recipient data is not transferred outside the European Economic Area.