Sales and compliance process

1. Security questionnaires

Step Who Target time
Receipt and qualification (new format? urgent?) Sales / customer success 1 business day
Answers from the bank of standard answers Security / compliance 3 to 5 days
Validation of binding answers RPRP 2 days
Sending and follow-up Sales —

Rule: only answer what is true and provable. Any question outside the bank is escalated.

2. Negotiating the DPA

Start from the standard template. Non-negotiable (to confirm with legal): use limited to the mandate, incident notice without delay, deletion at contract end, no AI training on customer data without written agreement. Escalate to legal as soon as a customer asks for a clause that contradicts these principles or for unlimited liability.

3. Subprocessors

Keep an up-to-date catalogue (name, role, location) and a notice process for customers whenever one is added.

4. Demos and trials

Use an isolated demo environment with fictitious data; never show another customer's real data.