Data processing agreement

Version of 2026-09-10

Agreement concluded under article 28 of regulation (EU) 2016/679 (GDPR), covering the personal data the institution entrusts to VirtIoT Lab. This page is printable: the institution can keep a dated copy without having to request a separate document.

The parties

The client institution — school, training organisation or company — determines the purposes and means of the processing of its students' and teachers' data. It is therefore the controller within the meaning of article 4.7 of the GDPR.

Joffrey Herard, Sole proprietor (French “micro-entreprise”), whose registered office is at Maison L, 34 rue de Solférino, 51100 Reims, France, publisher of VirtIoT Lab, processes that data on behalf of the institution and on its instructions. It acts as processor within the meaning of article 4.8 of the same regulation.

Any request relating to this agreement is sent to the processor at contact@ofnir.fr. How the agreement is accepted is described in the final clause.

Purpose, duration, nature and objective

The purpose of this agreement is the supply, by the processor, of the VirtIoT Lab teaching platform, and the framing of the personal data processing that this supply entails.

The nature of the operations is as follows: hosting of accounts and their data, running of the virtual network lab environments, retention of the resulting activity records, and return of that work to the institution as an export.

The objective pursued is the teaching delivered by the institution. The processor pursues no purpose of its own: it does not exploit this data for itself or for any third party, and derives from it no profiling, no commercial statistics and no training data.

The duration of the processing is that of the subscription taken out by the institution, renewals included. It ends under the conditions of the “Return or deletion of data” clause.

Categories of data and of persons

The categories below are exhaustive: they describe everything the platform collects, and nothing more.

  • Identity: students' first and last names, as imported by the teacher, and the normalised login identifier derived from them.
  • Contact: email address, used as the login identifier and to deliver service messages.
  • Lab activity records: the student's attachment to a cohort and to the sessions they join, frames sent and received, simulated device configurations, scripts written by the student, execution logs of the virtual environments.
  • Data subjects: the students enrolled by the institution and the teachers who supervise their lab work.
  • No data falling under article 9 of the GDPR — origin, opinions, beliefs, health, biometric data or any other special category — is requested or collected. The platform's free-text fields must not be used to enter any.

Processor obligations

The processor undertakes to comply with the obligations of article 28.3 of the GDPR. They are restated below point by point, in the order of the text and under their original letter, rather than left to a cross-reading of the regulation.

  • (a) Documented instructions — the processor processes the data only on documented instructions from the controller, including for any transfer to a third country. This agreement, the terms and conditions, and the settings chosen by the teacher in their workspace constitute those instructions. The processor informs the controller if it considers an instruction to infringe the regulation.
  • (b) Confidentiality — the persons authorised to process this data are, to date, the publisher himself and no one else. He is bound by confidentiality and will impose it in writing on anyone he may later authorise.
  • (c) Security — the measures of article 32 are implemented: encryption of exchanges with the site, passwords stored as hashes and never in clear text, isolation of each student in their own container and their own subnet, separation of workspaces between institutions, resource limits on the scripts that are run, and regular backups of the database.
  • (d) Sub-processors — the processor engages none without prior information to the controller, under the conditions of the “Sub-processors” clause.
  • (e) Assistance with data subject rights — the processor assists the controller, by appropriate technical and organisational measures, in responding to requests for access, rectification, erasure, restriction, portability and objection. A request a student sends directly to the processor is forwarded to the controller, whose responsibility it is to answer.
  • (f) Assistance with articles 32 to 36 — the processor assists the controller in ensuring the security of the processing, in notifying breaches, in informing the data subjects and, where applicable, in carrying out a data protection impact assessment and the prior consultation of the supervisory authority.
  • (g) Return or deletion — at the end of the service, the data is returned or deleted at the controller's choice, under the conditions of the “Return or deletion of data” clause.
  • (h) Information and audit — the processor makes available to the controller all the information needed to demonstrate compliance with these obligations and allows audits to be carried out, under the conditions of the “Audit” clause.

Sub-processors

The processor uses two sub-processors, and only two. They are named here rather than referred to a list kept elsewhere: a list you have to go and look for is not prior information.

Adding or replacing a sub-processor is subject to prior information of the controller, by email, at least thirty days before it takes effect. The controller has that period to raise a reasoned objection. If the objection is maintained, it may terminate the subscription without penalty, only the current period remaining due.

  • OVH — delivery of the service's outgoing emails (address verification, password reset, notifications). Company established in the European Union, servers located in France.
  • Indy — bookkeeping and invoice issuance. Company established in the European Union. This provider only accesses the institution's billing data, never student data.

Personal data breach

The processor notifies the controller of any personal data breach without undue delay, and at the latest 48 hours after becoming aware of it. This deadline is contractual and deliberately shorter than the 72 hours article 33 allows the controller to notify the supervisory authority: that is what lets the controller meet its own deadline, and what makes this agreement enforceable rather than declarative.

The notification is sent by email to the reference teacher declared by the institution. It describes the nature of the breach, the categories and approximate number of persons and records concerned, its likely consequences, and the measures taken or proposed to address it and mitigate its effects.

Where all of this information is not available at the time of notification, it is provided in phases, without undue further delay. Notification to the supervisory authority and, where applicable, communication to the data subjects fall to the controller. The internal procedure followed by the processor is set out in its operating document “GDPR — breach procedure”.

Return or deletion of data

At the end of the service, the controller chooses between the return of the data followed by its deletion, and direct deletion. The choice is the controller's: the processor does not decide in its place and keeps nothing “just in case”.

Return takes the form of a JSON export of the sessions, configurations and accounts concerned. This function already exists and can be used at any time during the agreement, without waiting for its end.

Deletion covers all existing copies, including in backups, as their rotation cycle expires. It does not extend to data the law requires to be kept, first among them invoices, retained for 10 years under article L123-22 of the French commercial code.

Closing a lab session already destroys the containers that made it up: this is the platform's normal behaviour, not an end-of-contract operation. The export performed before closing is the only means of resuming the work.

Audit

The processor makes available to the controller the information needed to demonstrate compliance with the obligations of this agreement: a description of the technical and organisational measures in place, an up-to-date list of sub-processors, and the log of any breaches.

The controller, or an independent auditor it mandates who is not a competitor of the processor, may carry out audits or inspections. They are announced with reasonable notice of thirty days, take place during business hours, on documents or on site, and must neither disrupt the operation of the service nor give access to another institution's data.

The costs of the audit are borne by the controller, unless it reveals a failure by the processor to meet its obligations.

Place of processing

Hosted in France, on our own servers — no transfer outside the European Union.

The server belongs to the processor and is located at its registered office, Maison L, 34 rue de Solférino, 51100 Reims, France. No third-party host and no foreign cloud service is involved in storing this data.

No transfer to a third country or international organisation takes place. Such a transfer, were it to become necessary, would require a documented instruction from the controller and the appropriate safeguards of articles 44 and following of the GDPR.

Acceptance

This agreement is accepted by subscribing to an Académique or Institution plan, with no handwritten signature: accepting the terms and conditions when subscribing also accepts this agreement.

The applicable version is the one whose date appears at the top of this page. Each new version is dated and published here; the institution is informed by email whenever a version changes its rights or its obligations.

This page is printable — the dedicated button produces a document without navigation or footer — so that the institution can file a dated copy in its record of processing activities.