Sales and compliance process
1. Security questionnaires
| Step | Who | Target time |
|---|---|---|
| Receipt and qualification (new format? urgent?) | Sales / customer success | 1 business day |
| Answers from the bank of standard answers | Security / compliance | 3 to 5 days |
| Validation of binding answers | RPRP | 2 days |
| Sending and follow-up | Sales | — |
Rule: only answer what is true and provable. Any question outside the bank is escalated.
2. Negotiating the DPA
Start from the standard template. Non-negotiable (to confirm with legal): use limited to the mandate, incident notice without delay, deletion at contract end, no AI training on customer data without written agreement. Escalate to legal as soon as a customer asks for a clause that contradicts these principles or for unlimited liability.
3. Subprocessors
Keep an up-to-date catalogue (name, role, location) and a notice process for customers whenever one is added.
4. Demos and trials
Use an isolated demo environment with fictitious data; never show another customer's real data.