CMMS with AI
Integrations
Blog
For the purposes of this Agreement, the definitions set out in the GDPR shall apply. In addition, the following terms are defined below:
Personal Data: Any information relating to an identified or identifiable natural person, including names, email addresses, telephone numbers, location data, online identifiers, or any other data enabling direct or indirect identification.
Processing: Any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure or destruction.
Controller: The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing.
Processor: The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Controller. Under this DPA, Fracttal acts as Processor.
Sub-processor: Any third party authorised by the Processor to carry out Processing activities on its behalf, subject to obligations equivalent to those set out in this DPA.
Security Breach: Any breach of security leading to the accidental or unlawful destruction, loss, alteration of, or unauthorised disclosure of or access to, Personal Data transmitted, stored or otherwise processed.
International Transfer: Any transmission of Personal Data to a third country or international organisation outside the European Economic Area (EEA).
Technical and Organisational Measures: Measures implemented to ensure a level of security appropriate to the risk, including pseudonymisation and encryption of Personal Data, the confidentiality, integrity, availability and resilience of processing systems, and the ability to restore availability and access in the event of an incident.
Main Agreement: The Fracttal One subscription agreement entered into between Fracttal and the Client, of which this DPA forms an integral part.
MCP Service: Optional access to Fracttal One via the Model Context Protocol (MCP), governed by the MCP Annex to the Main Agreement.
Annexes: The documents attached to this DPA which form an integral part of it: Annex I (Description of Processing), Annex II (Security Measures), Annex III (List of Sub-processors) and Annex IV (Security Breach Notification Procedure).
The purpose of this DPA is to govern the Processing of Personal Data carried out by Fracttal, as Processor, on behalf of the Client, in connection with the SaaS services described in the Main Agreement.
The Processing shall be strictly limited to what is necessary for the provision of such services, in accordance with the Client's documented instructions and the description set out in Annex I.
Where the Client activates the MCP Service, this DPA covers exclusively the Processing carried out by Fracttal through the MCP endpoint it manages. The processing of personal data carried out by the external artificial intelligence provider chosen by the Client (including, without limitation, Anthropic, OpenAI, Microsoft or Google) falls outside the scope of this DPA and is the sole responsibility of the Client as Controller.
This DPA shall enter into force on the date of its acceptance and shall remain in effect throughout the term of the Main Agreement and for such subsequent period during which Fracttal processes Personal Data on behalf of the Client, including any legally required retention period.
Following termination of the Main Agreement, this DPA shall remain in force until the complete return or destruction of the Personal Data in accordance with Clause 10.
Fracttal, as Processor, undertakes to:
Upon completion of the provision of the service, and at the Client's election, Fracttal shall return or delete all Personal Data processed on the Client's behalf, and delete any existing copies, unless applicable law requires their retention, in which case Fracttal shall ensure the confidentiality of such data and process it solely for the purposes required by such law.
The Client grants Fracttal a general authorisation to subcontract parts of the Processing to the Sub-processors listed in Annex III, subject to the following conditions:
The up-to-date list of Sub-processors is available in Annex III and at https://www.fracttal.com/subprocessors. Should the Client object to a Sub-processor, Fracttal shall discontinue its use or, if this would render the provision of the service impossible, the parties shall negotiate an alternative solution in good faith.
Specific note on the MCP Service: external artificial intelligence providers (Anthropic, OpenAI, Microsoft, Google) do not act as Sub-processors of Fracttal in connection with the MCP Service. In this context, such providers operate under the Client's direct instructions, as the Client selects them and directs data to them through Fracttal's endpoint; their engagement, oversight and regulatory compliance are the sole responsibility of the Client, as Controller.
This relationship is independent of any relationship that some of these same providers may have with Fracttal as Sub-processors listed in Annex III for other platform functionalities unrelated to the MCP Service. Both scenarios are governed by different rules: as a Sub-processor of Fracttal, the provider acts under the instructions and the DPA entered into by Fracttal; as a provider chosen by the Client in connection with MCP, it acts under the instructions and sole responsibility of the Client.
The Personal Data processed by Fracttal under the Main Agreement is hosted, primarily, on AWS servers located in Paris (France, EU-West-3), within the European Economic Area.
However, the Processing involves certain International Transfers arising from the involvement of certain Sub-processors located outside the EEA, in particular: (i) the Claude artificial intelligence system, provided by Anthropic, headquartered in the United States; and (ii) certain affiliated companies of the Fracttal group headquartered in South American countries. The up-to-date list of Sub-processors and their location is set out in Annex III.
For such International Transfers, Fracttal implements one or more of the following mechanisms, as applicable to the Sub-processor and destination country:
Where necessary, Fracttal shall supplement such mechanisms with a transfer impact assessment and the corresponding additional technical and organisational measures.
The engagement of new Sub-processors located outside the EEA shall be governed by the notification and objection procedure set out in the Sub-processors section of this DPA (30 days' prior notice).
In addition, any change in the location of Fracttal's main servers (currently in EU-West-3) that constitutes a new International Transfer not contemplated in this DPA shall require prior notice to the Client of at least 60 days and the Client's express written authorisation, given that it affects the service's core infrastructure rather than the engagement of a specific Sub-processor.
Fracttal shall provide the Client, upon request, with a copy of the applicable International Transfer agreements.
Fracttal shall implement and maintain an Information Security Management System (ISMS) certified under ISO/IEC 27001:2022, which includes, at a minimum, the measures set out in Annex II.
Such measures shall be reviewed annually and updated where necessary to address new risks. Fracttal shall carry out periodic risk assessments, independent penetration testing at least once a year, and quarterly internal audits. Any significant change to the security measures shall be notified to the Client in advance.
The Client, as Controller, undertakes to:
The Client may audit Fracttal's compliance with this DPA, or appoint an independent auditor to do so, upon at least 45 days' prior written notice, during business hours and without unduly interfering with Fracttal's operations.
Fracttal shall cooperate by providing: access to relevant facilities, systems and documentation; third-party audit reports (e.g., SOC 2 Type II); and evidence of compliance with its obligations.
Audits shall be limited to one per calendar year, unless there are reasonable grounds to suspect non-compliance. The costs of the audit shall be borne by the Client, unless a significant non-compliance is detected, in which case Fracttal shall reimburse the reasonable costs. All information obtained during the audit shall be subject to confidentiality obligations.
Upon termination of the Main Agreement or of this DPA, Fracttal shall, at the Client's written election, return or destroy all Personal Data and copies thereof within a maximum of 30 days.
The return shall be carried out in a standard format (e.g., CSV, JSON) through secure channels. In the event of destruction, Fracttal shall issue a confidential certificate of destruction confirming that the data is unrecoverable, in accordance with standards such as EN 15713:2009.
Fracttal may retain Personal Data where required by applicable law, notifying the Client and limiting Processing to what is strictly necessary. The applicable legal retention periods are set out in Annex I.
In accordance with Article 82(1) and (2) GDPR, each party shall be directly liable to data subjects and supervisory authorities for material or non-material damage resulting from processing that infringes the GDPR. In particular, under Article 82(2) GDPR, Fracttal, as Processor, shall only be liable where (i) it has not complied with the GDPR obligations specifically addressed to processors, in particular those set out in Article 28 GDPR and Article 5 of the LOPDGDD (duty of confidentiality); or (ii) it has processed Personal Data outside of or contrary to the Client's lawful instructions.
Such liability is limited to compensation for damages actually proven as a direct consequence of Fracttal's breach (or that of its Sub-processors, in accordance with Article 28(4) GDPR), expressly excluding: legal defence costs, attorneys' or expert fees, loss of profit, indirect or consequential damages, and any item not constituting direct and proven damage. The foregoing is without prejudice to the administrative liability that, under Article 83 GDPR, the supervisory authority may impose directly on Fracttal for its own breaches as Processor, which is not limited by this paragraph.
Fracttal's aggregate liability under this DPA shall not exceed the total amount paid or payable by the Client to Fracttal under the Main Agreement during the twelve (12) months immediately preceding the event giving rise to the claim (the "Annual Contract Value"), except in cases of wilful misconduct or gross negligence.
The Client shall be liable to Fracttal for damages resulting from unlawful, inaccurate instructions or instructions contrary to data protection regulations provided by the Client, as well as for breach of the obligations incumbent upon it, as Controller, under Article 5(2) and Article 24 GDPR.
This DPA is governed by Spanish law. Any dispute arising therefrom shall be submitted exclusively to the courts of Madrid, the parties waiving any other jurisdiction.
For clients domiciled outside Spain and the European Union, the parties may agree to submit to arbitration under the International Chamber of Commerce (ICC), seated in Madrid, with the application of Spanish law, by express agreement prior to the signing of the Main Agreement. In the absence of such agreement, the jurisdiction of the courts of Madrid shall prevail.
Fracttal may amend this DPA where necessary to adapt to regulatory changes or service improvements, notifying the Client at least 30 days in advance by publication at fracttal.com/es/dpa and direct communication to the Client's registered email address. If the Client does not raise an express objection within that period, the amendment shall be deemed accepted.
Any amendment specifically agreed between the parties shall require the written consent of both.
Notices shall be sent by certified email or an equivalent means and shall be deemed received within 48 hours.
This DPA, together with its Annexes, constitutes the entire agreement between the parties regarding the Processing of Personal Data. If any of its provisions is declared invalid, the remainder shall remain in force.
|
Field |
Detail |
|
Categories of Personal Data |
Names, email addresses, telephone numbers, maintenance personnel data (technicians, supervisors, managers), location data, online identifiers, and any other data uploaded by the Client to the platform. Where the MCP Service is activated, the personal data accessed through the MCP endpoint belongs exclusively to the Client's environment and is transmitted to the external AI assistant chosen by the Client. |
|
Categories of Data Subjects |
Client employees, maintenance technicians, platform users, and any other natural person whose data the Client uploads to Fracttal One. |
|
Purposes of Processing |
Provision of CMMS/EAM SaaS services, including asset management, work order management, notifications, system analytics and, where activated by the Client, access via the MCP protocol to Service data by external AI assistants authorised by the Client. |
|
Processing Operations |
Collection, storage, consultation, modification and erasure. |
|
Retention Period |
For the duration of the Main Agreement. Following its termination, Personal Data shall be retained for a maximum of 30 days for the purposes of return or destruction under Clause 10, unless applicable law requires a longer period. Minimum statutory periods: (i) accounting and tax records: 6 years (Law 58/2003, General Tax Law); (ii) commercial contracts: 6 years (Article 30, Commercial Code); (iii) electronic communications data: up to 12 months (Law 25/2007); (iv) employment data of Client personnel: 4 years (LGSS). |
|
Special Category Data |
Not envisaged. If applicable, express and specific written authorisation shall be required. |
|
Measure |
Detail |
|
Encryption |
Data in transit: TLS 1.3. Data at rest: AES-256. |
|
Access control |
Role-based access control (RBAC), multi-factor authentication (MFA), principle of least privilege. |
|
Monitoring |
24/7 access logging, intrusion detection/prevention systems (IDS/IPS). |
|
Backups |
Daily backups; restoration tested quarterly. |
|
Penetration testing |
Annual independent penetration testing by certified third parties; incident response drills. |
|
Training |
Annual data protection training for all personnel with access to Personal Data. |
|
Certification |
ISO/IEC 27001:2022 certified ISMS. SOC 2 Type II reports available upon request. |
|
Pseudonymisation |
Applied where technically feasible and proportionate to the risk. |
|
Incident response |
Documented incident response plan; breach response team available 24/7. |
|
Cloud infrastructure |
AWS Paris (EU-West-3); GDPR compliant; transfer agreements via SCCs and the EU-U.S. Adequacy Decision (DPF), as applicable. |
The following Sub-processors are authorised as of the date of this DPA. Updates are published in this section at least 30 days in advance.
|
Sub-processor |
Service |
Location |
Transfer mechanism |
Relationship with MCP |
|
Amazon Web Services (AWS) |
Cloud infrastructure and hosting |
EU — Paris (eu-west-3) and Netherlands |
GDPR + SCCs + Adequacy |
Yes — MCP endpoint infrastructure |
|
HubSpot, Inc. |
CRM and marketing automation |
USA |
SCCs + TIA |
No |
|
Twilio Inc. |
Messaging and notifications |
USA |
SCCs + TIA |
No |
|
Zendesk, Inc. |
Customer support |
USA |
SCCs + TIA |
No |
|
WhatsApp (Meta Platforms) |
Notifications |
USA |
SCCs + TIA |
No |
|
OpenAI, L.L.C. |
AI — Fracttal AI (Tony) |
USA |
SCCs + TIA |
No — exclusive to Fracttal AI |
|
Phase |
Timeframe |
Action |
|
Detection and assessment |
< 24 hours from becoming aware |
Fracttal's Security team identifies, classifies and assesses the scope and impact of the breach. |
|
Initial notification to the Client |
< 48 hours from becoming aware |
Preliminary written notice by email to the Client's designated contact, including: description of the breach, categories of data affected, initial risk assessment, and interim measures taken. |
|
Full incident report |
< 72 hours from becoming aware |
Detailed report including: root cause analysis, full scope of affected data, number of data subjects impacted, definitive mitigation measures, and remediation plan. |
|
Regulatory cooperation |
As applicable |
Fracttal assists the Client in notifying the competent supervisory authority (AEPD, SIC, ANPD, INAI, etc.) and affected data subjects, where required under Articles 33 and 34 GDPR or equivalent local regulations. |
|
Post-incident review |
Within 30 days |
Fracttal provides a post-incident report with lessons learned and preventive measures implemented. |
Fracttal privacy and breach contact: privacidad@fracttal.com