Data Processing Addendum (DPA)
This English translation is provided for convenience only. The French version is the legally binding one and prevails in case of discrepancy.
This Data Processing Addendum (the “DPA”) supplements and forms an integral part of the General Terms of Use (the “Terms”) entered into between Vitruhome, a French simplified joint-stock company (société par actions simplifiée) with a share capital of 1,000 euros, registered with the Salon-de-Provence Trade and Companies Register (RCS) under number 994 224 715, whose registered office is at 16 rue du Citis, 13140 Miramas, France (“Vitru'home”), and the Customer.
This DPA governs the Processing of Personal Data carried out by Vitru'home on behalf of the Customer in connection with the provision of the Vitru'home Services, where Vitru'home acts as a Processor within the meaning of Article 28 of Regulation (EU) 2016/679 (“GDPR”). It is automatically accepted by the Customer upon acceptance of the Terms.
In the event of any conflict between this DPA and the Terms concerning the protection of Personal Data, the provisions of this DPA will prevail to the extent of that conflict, in accordance with Section 11.2.
1. Definitions
Capitalised terms used but not defined in this Data Processing Addendum (the “DPA”) have the meaning given to them in the General Terms of Use (the “Terms”). For the purposes of this DPA:
- “Applicable Data Protection Law” means any applicable law or regulation relating to privacy, data security or the protection of personal data, including Regulation (EU) 2016/679 (the “GDPR”), French Law No. 78-17 of 6 January 1978 on Information Technology, Data Files and Civil Liberties (“Informatique et Libertés”), as amended, Directive 2002/58/EC (“ePrivacy”) and, to the extent applicable, the California Consumer Privacy Act (“CCPA”).
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- “Description of Processing” means the description set out in Annex 1 to this DPA.
- “Personal Data” means Customer Data that constitutes personal data within the meaning of Applicable Data Protection Law.
- “Data Subjects”, “Controller”, “Processor”, “Processing” and “Personal Data Breach” have the meaning given to them by Applicable Data Protection Law.
- “Restricted Country” means any country outside the European Economic Area (EEA) that does not benefit from an adequacy decision of the European Commission within the meaning of Article 45 of the GDPR.
- “Sub-processor” means any processor engaged by Vitru'home to carry out all or part of the Processing on behalf of the Customer.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
2. Role of the Parties and description of the Processing
2.1 Role of the Parties
Where the Customer uses the Vitru'home Services to have Personal Data processed for which it is the Controller, the Parties acknowledge that: (a) the Customer acts as Controller, and (b) Vitru'home acts as Processor, in accordance with Article 28 of the GDPR. Where several Controllers jointly determine the purposes and means of a Processing, the Customer undertakes to have entered into an arrangement with those joint Controllers that complies with Article 26 of the GDPR.
2.2 Description of the Processing
The purposes, categories of Personal Data, categories of Data Subjects, durations and nature of the Processing carried out by Vitru'home on behalf of the Customer are described in Annex 1. Vitru'home may update Annex 1 to reflect new Services, features or Sub-processors, subject to the change procedure set out in Section 7.2 for Sub-processors and in Section 13 of the Terms for other changes.
2.3 Processing for which Vitru'home acts as Controller
Vitru'home acts as an independent Controller, and not as a Processor, for the following Processing, described in its Privacy Policy (vitruhome.com/politique-confidentialite):
- (a) management of Customer Accounts (registration, authentication, billing);
- (b) improvement and security of the Services (automated moderation, abuse detection), within the limits set out in Section 4 of the Terms;
- (c) production of anonymised or aggregated usage statistics, excluding the training of models except in the cases provided for in Section 4.2 of the Terms;
- (d) compliance with Vitru'home's legal obligations (accounting, tax, retention under the LCEN, the French Law for Confidence in the Digital Economy).
3. General obligations
3.1 Obligations of Vitru'home
Vitru'home undertakes to:
- (a) process Personal Data only on documented instructions from the Customer, as set out in the Terms, this DPA, any Order Form or any subsequent written instruction, including with regard to transfers of Personal Data to a third country or an international organisation;
- (b) immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and, where appropriate, suspend the relevant Processing until clarification;
- (c) ensure that any person authorised to process Personal Data (employees, contractors) is subject to an appropriate obligation of confidentiality, whether contractual or statutory, and receives the necessary training;
- (d) implement the technical and organisational measures described in Annex 2, in accordance with Article 32 of the GDPR;
- (e) provide the Customer with reasonable assistance, taking into account the nature of the Processing and the information available to it, to help the Customer comply with its obligations under Articles 32 to 36 of the GDPR (security, breach notifications, data protection impact assessments, prior consultation of the supervisory authority);
- (f) maintain a record of the categories of processing activities carried out on behalf of the Customer, in accordance with Article 30(2) of the GDPR, and make it available to the supervisory authority on request;
- (g) notify the Customer within a reasonable time if Vitru'home determines that it can no longer meet its obligations under this DPA or applicable law.
3.2 Obligations of the Customer
The Customer warrants: (a) that it complies with all of its obligations as Controller, including providing Data Subjects with the required information (Articles 13-14 GDPR) and obtaining the consents or other legal bases required (Article 6 GDPR); (b) that it does not transmit, save under a specific written agreement in accordance with Section 2.2(j) of the Terms, any data falling within Articles 9 and 10 of the GDPR; and (c) that it gives Vitru'home lawful instructions that comply with Applicable Data Protection Law.
4. Rights of Data Subjects
4.1 Responsibility of the Customer
The Customer is solely responsible for responding to requests made by Data Subjects in the exercise of their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, objection, portability, automated decision-making).
4.2 Assistance by Vitru'home
Vitru'home provides the Customer, insofar as possible and taking into account the nature of the Processing, with commercially reasonable assistance, by means of appropriate technical and organisational measures, to enable it to respond to Data Subject requests. Such assistance includes, in particular, making available features to export, modify or delete Customer Data within the Customer Account.
4.3 Requests made directly to Vitru'home
If a Data Subject makes a request directly to Vitru'home relating to a Processing carried out on behalf of the Customer, Vitru'home (a) will not respond directly to that request without the Customer's prior written consent, unless otherwise required by law, and (b) will forward the request to the Customer within a reasonable time. Where Vitru'home is legally required to respond, it will inform the Customer beforehand, unless prohibited by law.
5. Technical and organisational measures
5.1 Security measures
Vitru'home implements and maintains the technical and organisational measures described in Annex 2, designed to protect Personal Data against any Data Breach, in accordance with the requirements of Article 32 of the GDPR.
5.2 Changes to the measures
Vitru'home may update the measures in Annex 2 to reflect changes in the state of the art, identified threats or its certifications, provided that the overall level of security is not materially reduced. In the event of a material reduction, the Customer will be notified in advance, in accordance with Section 13 of the Terms.
6. Data Breach notification
6.1 Notification
Vitru'home notifies the Customer of any Data Breach affecting Personal Data processed on its behalf without undue delay and, wherever possible, no later than seventy-two (72) hours after becoming aware of it. The notification is sent to the point of contact designated by the Customer in its Customer Account or, failing that, to the email address of the primary administrator. The notification does not constitute an acknowledgement of fault by Vitru'home.
6.2 Content of the notification
To the extent the information is available, the notification will include:
- (a) a description of the nature of the Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and volume of Personal Data concerned;
- (b) the contact details of the point of contact from whom more information can be obtained (DPO or equivalent);
- (c) the likely consequences of the Breach;
- (d) the measures taken or proposed to address the Breach, including, where appropriate, measures to mitigate its possible adverse effects;
- (e) the measures the Customer could take to mitigate the effects on Data Subjects.
Where it is not possible to provide all of this information at the same time, it may be provided in phases as it becomes available, without further undue delay.
6.3 Assistance
Vitru'home provides the Customer with commercially reasonable assistance in fulfilling its own obligations to notify the supervisory authority (Article 33 GDPR) and, where applicable, Data Subjects (Article 34 GDPR), and in implementing corrective measures.
7. Sub-processing
7.1 General authorisation
The Customer grants Vitru'home a general authorisation, within the meaning of Article 28(2) of the GDPR, to engage Sub-processors for the purpose of providing the Vitru'home Services. The current list of Sub-processors is available at vitruhome.com/sous-traitants (or any successor URL). Vitru'home:
- (a) maintains an up-to-date list of Sub-processors, including their identity, the country of Processing and the categories of Personal Data concerned;
- (b) offers the Customer the option to subscribe to email notifications of changes to that list;
- (c) enters into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those of this DPA;
- (d) remains fully liable to the Customer for the performance by the Sub-processor of its data protection obligations.
7.2 Notification and objection
Vitru'home notifies the Customer of any change to the list of Sub-processors with reasonable prior notice before the change goes into production. The Customer may object to a new Sub-processor, on legitimate and reasonable grounds relating to Applicable Data Protection Law, by sending its written objection to team@vitruhome.com within ten (10) days of the notification. In the absence of an objection within that period, the Sub-processor is deemed approved.
In the event of a reasoned objection, the Parties will seek a solution in good faith (in particular, configuration of an alternative region). Failing agreement within a reasonable time, Vitru'home may, at its option, (i) refrain from using the Sub-processor concerned, or (ii) terminate the affected Service or Services, or (iii) terminate the contract in its entirety, without such termination giving rise to any compensation, it being specified that the Customer will be refunded pro rata for the Services not provided.
8. International transfers
8.1 Principle
Vitru'home gives preference, wherever possible, to hosting and Processing Personal Data within the European Union. Where a transfer to a Restricted Country is necessary for the provision of the Vitru'home Services, the Customer authorises it, provided that the transfer is subject to appropriate safeguards within the meaning of Chapter V of the GDPR.
8.2 Standard Contractual Clauses (SCCs)
Where the transfer is not covered by an adequacy decision (within the meaning of Article 45 of the GDPR, in particular the EU-US Data Privacy Framework for certified recipients), the Parties agree to incorporate into this DPA, by reference, the applicable Standard Contractual Clauses:
- (a) for transfers from the Customer (Controller established in the EU) to Vitru'home (Processor) or to a Sub-processor located in a Restricted Country, Module 2 (Controller to Processor) or, where applicable, Module 3 (Processor to Processor);
- (b) for a Customer located in a Restricted Country and acting as Controller, Module 4 (Processor to Controller).
For the purposes of the SCCs: (i) the docking clause is deemed activated; (ii) Option 2 of Clause 9 applies (general authorisation for sub-processing with 10 days' notice); (iii) Clause 17 (governing law) designates French law; (iv) Clause 18 (choice of forum and jurisdiction) designates the courts of Aix-en-Provence, France; (v) the Annexes to the SCCs are deemed completed by Annex 1 (Description of Processing) and Annex 2 (Technical and Organisational Measures) of this DPA, and by the list published at vitruhome.com/sous-traitants.
8.3 Supplementary measures (Schrems II)
In accordance with the Schrems II judgment (CJEU, 16 July 2020, C-311/18) and Recommendations 01/2020 of the European Data Protection Board, Vitru'home has assessed the level of protection in the relevant Restricted Countries and implements, where appropriate, supplementary technical, contractual or organisational measures (end-to-end encryption, pseudonymisation, clauses on resisting government access requests, annual audits). Details of these measures are available on written request to team@vitruhome.com.
9. Audit
9.1 Documentary audit
Upon the Customer's reasonable written request, Vitru'home makes available all documents and information reasonably necessary to demonstrate its compliance with this DPA and Article 28 of the GDPR, within a reasonable time, subject to its confidentiality obligations and the protection of its trade secrets. Vitru'home may in particular provide: (a) a self-audit certificate signed by an authorised representative; (b) independent audit reports (for example SOC 2 Type II or ISO 27001 where available); (c) responses to standard security questionnaires such as CAIQ/SIG.
9.2 On-site audit
Where the documentary audit provided for in Section 9.1 is insufficient to demonstrate Vitru'home's compliance, the Customer may request an on-site audit, subject to all of the following conditions:
- (a) the audit is limited to once (1) per calendar year, except in the event of a well-founded suspicion of a security incident or a reasoned request from a supervisory authority;
- (b) the audit is requested in writing with reasonable notice of at least ninety (90) days, specifying the scope, methods and timetable;
- (c) the audit is carried out by an independent auditor appointed by mutual agreement between the Parties, bound by a confidentiality obligation equivalent to that of Section 6 of the Terms and who is not a direct competitor of Vitru'home;
- (d) the audit takes place during business hours, without unreasonable disruption to the Services;
- (e) it covers only the information and Personal Data relating to the Customer;
- (f) the audit report is delivered to both Parties in an identical version and constitutes Confidential Information of Vitru'home (Section 6 of the Terms).
9.3 Costs
The reasonable costs of the audit are borne by the Customer, unless the audit reveals a material breach of this DPA attributable to Vitru'home, in which case Vitru'home bears the reasonable costs up to the amount paid by the Customer to Vitru'home during the previous twelve (12) months.
10. Return and deletion
10.1 Customer's choice
In accordance with Article 28(3)(g) of the GDPR, at the end of the provision of the Vitru'home Services and, in any event, upon termination or expiry of the Terms, Vitru'home will, at the Customer's choice expressed in writing to team@vitruhome.com at least fifteen (15) days before the effective end date: (a) return to the Customer the Personal Data processed on its behalf, in a structured, commonly used and machine-readable format (for example JSON, CSV), or (b) delete it.
10.2 In the absence of instructions
Vitru'home will remind the Customer, by email sent to the administrator of the Customer Account thirty (30) days before the effective end date, of the option available to it under Section 10.1. If, despite this reminder, the Customer has given no instruction within the period set out in Section 10.1, Vitru'home will delete the Personal Data within thirty (30) days of the effective end date, subject to statutory retention obligations.
10.3 Statutory retention
Vitru'home is authorised to retain Personal Data for the periods and solely for the purposes set out in Section 11.4(d) of the Terms (invoices, tax data, LCEN logs, CRM data). Such data is kept in a restricted-access environment and is not subject to any Processing other than that strictly necessary for its statutory retention.
10.4 Certificate of deletion
Upon written request, Vitru'home will provide the Customer with a certificate of deletion signed by an authorised representative, within a reasonable time after completion of the operations.
10.5 Backup copies
The deletion provided for in Sections 10.1 and 10.2 is immediate in production systems. Backup copies, write-protected for integrity and resilience purposes, expire automatically no later than one hundred and eighty (180) days after that deletion. Until they expire, they remain encrypted, subject to all the obligations of this DPA, and are not accessible for any purpose other than restoration following an incident. Upon the Customer's written request, Vitru'home purges them early.
11. General provisions
11.1 Term
This DPA takes effect on the earlier of the following two dates: (a) the effective date of the Terms, or (b) the date on which Vitru'home first processes Personal Data on behalf of the Customer. It remains in force for the entire term of the Terms, and thereafter for the period necessary to complete the return or deletion operations referred to in Section 10 and the statutory retention.
11.2 Incorporation and conflict
This DPA is incorporated into the Terms by reference and forms an integral part of them. In the event of any conflict between the provisions of this DPA and those of the Terms relating to the protection of Personal Data, the provisions of this DPA will prevail to the extent of that conflict.
11.3 Liability
Each Party's liability under this DPA is subject to the exclusions and limitations of liability set out in Section 9 of the Terms, it being specified that, in accordance with Article 82 of the GDPR, liability towards Data Subjects remains governed by the applicable statutory rules.
11.4 Updates to the DPA
Vitru'home may update this DPA in accordance with the procedure set out in Section 13 of the Terms. Updates required by a change in Applicable Data Protection Law take effect upon publication, without prejudice to the Customer's right to object under Section 13.4 of the Terms where the update has a material adverse effect.
11.5 Governing law and jurisdiction
This DPA is governed by French law. Any dispute relating to its interpretation or performance is subject to the amicable resolution procedure and the jurisdiction set out in Section 14.10 of the Terms.
12. Specific provisions (CCPA)
12.1 Application of the CCPA
This Section 12 applies only to the extent that the Customer is subject to the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and that the Personal Data processed on its behalf falls within that regime. Terms used in this Section have the meaning given to them by the CCPA.
12.2 Commitments of Vitru'home
Vitru'home undertakes not to:
- (i) process Personal Data for any business purpose other than providing the Vitru'home Services to the Customer;
- (ii) sell or share (within the meaning of the CCPA) Personal Data;
- (iii) process Personal Data outside the direct business relationship with the Customer;
- (iv) combine the Customer's Personal Data with other personal information, except as expressly permitted by the CCPA.
Vitru'home acts as a Service Provider within the meaning of the CCPA. It certifies that it understands the above restrictions and will comply with them.
Annex 1: Description of Processing
A1.1 Nature and purpose of the Processing
Vitru'home processes Personal Data on behalf of the Customer solely for the purpose of providing the Vitru'home Services to which the Customer has subscribed, in particular: (i) site analysis for environmental certification (geolocation, aggregation of public data); (ii) AI-powered document analysis (AI chat, extraction, summarisation); (iii) analysis of plans by computer vision (element detection, OCR); (iv) regulatory compliance analysis.
A1.2 Categories of Data Subjects
- (a) users of the Customer Account (End Users): employees, contractors and collaborators of the Customer authorised to use the Services;
- (b) persons incidentally mentioned in Customer Data (for example, contacts mentioned in a document uploaded for analysis).
A1.3 Categories of Personal Data
- (a) identification data (surname, first name, email, technical identifiers);
- (b) professional data (job title, organisation, professional contact details);
- (c) connection data (IP address, logs, browser fingerprint);
- (d) content submitted for Processing (texts, documents, plans, photographs, conversations with the AI) which may incidentally contain Personal Data;
- (e) geolocation data relating to analysed sites, where it allows the indirect identification of a Data Subject.
Exclusion: in accordance with Section 2.2(j) of the Terms, the Customer shall not transmit any data falling within Articles 9 and 10 of the GDPR without a specific written agreement.
A1.4 Processing operations
Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to Sub-processors for the purposes of the Service, alignment, restriction, erasure, destruction.
A1.5 Duration of the Processing
For the entire term of the Terms, and thereafter for the statutory retention periods set out in Section 11.4(d) of the Terms. Active data in the Customer Account is retained for as long as the Account is active and deleted in accordance with Section 10 of this DPA.
A1.6 Sub-processors (list as at the date of the DPA)
The up-to-date list is available at vitruhome.com/sous-traitants. As at the date of publication of this DPA, the main categories of Sub-processors are:
- Hosting & compute: Vercel Inc. (application execution and temporary Vercel Blob storage in the European Union, Paris cdg1; company incorporated under US law, DPF; global delivery network for static content), Supabase Inc. (European Union, Paris eu-west-3), Amazon Web Services (European Union, Paris eu-west-3, including the training of vision models);
- Orchestration of asynchronous processing: Vercel Inc., through the durable workflow engine of the same platform (European Union, Paris cdg1). The execution state retained to allow processing to resume, namely the inputs and outputs of each step, is encrypted by the engine under a key specific to each execution; only step names and timestamps remain in clear text. The right to decrypt follows the right to access the project's environment variables, and each decryption is recorded in the platform's audit log. No third-party provider is involved in scheduling any longer;
- AI models (LLM): Vercel Inc. (headquartered in the United States, DPF), AI Gateway routing inferences to Google Cloud (Gemini) or Anthropic (Claude) with inference pinned to the European Union zone and Zero Data Retention requested on every call, which rules out any use of the content for model training;
- Payment: Stripe Payments Europe Ltd (Ireland);
- Transactional email & communication: Resend Inc. (United States, DPF); Nylas, Inc. for the project mailbox and reminders for supporting documents (email bodies, attachments, participants), processed in the European Union region (api.eu.nylas.com), US entity;
- Document generation: no third-party sub-processor. The conversion of DOCX reports into PDF and the rasterisation of plans are performed by services that the Processor hosts itself on its Amazon Web Services infrastructure in the Paris region (eu-west-3). The document is processed and then deleted; it is not retained. Adobe Inc. (Adobe PDF Services), which previously performed this conversion in the United States, was removed on 29 July 2026 and no longer receives any data;
- Anti-bot protection & DNS: Cloudflare, Inc. (Turnstile for forms, authoritative DNS service for the vitruhome.com domain), United States and global network of points of presence, DPF. The applications are not served through the Cloudflare network;
- Mapping: Mapbox Inc. (United States, DPF), Google Maps Platform (United States, DPF);
- Authentication: Google LLC (Sign-In), United States, DPF, solely for users who choose single sign-on;
- Observability: PostHog Inc. (European Union, eu.posthog.com), Sentry / Functional Software Inc. (company incorporated under US law, storage configured in the European Union region).
Annex 2: Technical and organisational measures
In accordance with Article 32 of the GDPR, Vitru'home implements the following technical and organisational measures, appropriate to the risk and to the state of the art.
A2.1 Encryption and confidentiality
- (a) encryption in transit via TLS 1.2+ (recommended: TLS 1.3) on all entry points;
- (b) AES-256 encryption at rest for databases (Supabase/PostgreSQL), object storage (Supabase Storage) and backups;
- (c) centralised secrets management (encrypted environment variables, regular rotation, no secrets committed to source repositories);
- (d) multi-tenant isolation through PostgreSQL Row-Level Security (RLS).
A2.2 Authentication and access control
- (a) short-lived JWTs (≤ 30 minutes) with refresh token rotation;
- (b)
HttpOnly,Secure,SameSite=Laxcookies for the session; - (c) protection against credential stuffing (rate limiting shared across instances) and anti-bot protection (Turnstile);
- (d) password policy enforced server-side on all creation and change paths: minimum 12 characters, including a lowercase letter, an uppercase letter and a digit;
- (e) role-based access control (RBAC) at application level, backed by row-level partitioning (Row Level Security) enabled on all tables;
- (f) access by employees and contractors to production data that is strictly individual, logged and subject to approval.
A2.3 Application security
- (a) Content-Security-Policy in enforcing mode on all applications, with per-request cryptographic nonces on the product applications;
- (b) systematic validation of input parameters (Zod schemas) on all API routes;
- (c) centralised rate limiting (protection against DoS and abuse);
- (d) OWASP Top 10 protections (XSS, CSRF, SQLi, IDOR, SSRF);
- (e) web application firewall and DDoS protection at hosting provider level (Vercel).
A2.4 Infrastructure security
- (a) primary hosting in the European Union (Supabase and AWS, Paris region eu-west-3; Vercel applications, Paris region cdg1; model inference pinned to the European Union zone by Vercel AI Gateway);
- (b) infrastructure provided by hosting providers certified ISO 27001 and SOC 2 Type II;
- (c) clear separation of environments (development, staging, production);
- (d) encrypted, automated and regularly tested backups (PostgreSQL Point-in-Time Recovery).
A2.5 Logging and detection
- (a) centralised logging of access, administrative actions and security events;
- (b) retention of technical logs for twelve (12) months in accordance with the LCEN;
- (c) monitoring of application errors (Sentry);
- (d) automated alerting on security anomalies.
A2.6 Secure development lifecycle
- (a) systematic code review before release to production;
- (b) static analysis (linting, strong TypeScript typing) and dependency scanning (CVE);
- (c) pre-commit hooks blocking the publication of secrets;
- (d) manual approval required for production deployments.
A2.7 Governance and organisation
- (a) record of processing activities (Article 30 GDPR) kept up to date;
- (b) documented procedure for managing Data Breaches (detection, assessment, notification ≤ 72h);
- (c) regular staff training on data protection and security issues;
- (d) confidentiality clauses in all employment and service contracts;
- (e) data protection point of contact: team@vitruhome.com (marked “For the attention of the data protection department”).
A2.8 Resilience and continuity
- (a) fault-tolerant distributed serverless architecture;
- (b) tested restoration from backups (target RPO ≤ 24h, RTO ≤ 4h for critical modules);
- (c) documented business continuity plan, reviewed annually.
Contact us
For any question relating to this DPA, to subscribe to email notifications of changes to Sub-processors, or to exercise a right of audit, objection or return of data:
- Address: Vitruhome, 16 rue du Citis, 13140 Miramas, France, marked “For the attention of the data protection department”
- Email: team@vitruhome.com
- List of Sub-processors: vitruhome.com/sous-traitants
Last updated: 11 September 2026