Legal / Data Processing Addendum

Data Processing Addendum

Version 1.0 — Effective 2026-08-07
On this page
  1. 1. Definitions
  2. 2. Roles and Scope
  3. 3. Processing Instructions
  4. 4. Confidentiality and Personnel
  5. 5. Security
  6. 6. Subprocessors
  7. 7. Data Subject Requests
  8. 8. Assistance
  9. 9. Personal Data Breach
  10. 10. Audits
  11. 11. International Transfers
  12. 12. Return and Deletion
  13. 13. Liability; Order of Precedence
  14. Annex 1 — Description of Processing
  15. Annex 2 — Technical and Organizational Security Measures

This Data Processing Addendum ("DPA") forms part of the Blunox Terms of Service or other agreement between Blunox and Customer governing the Services (the "Agreement") and applies where Blunox processes Personal Data on behalf of Customer in providing the Services.

1. Definitions

"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including as applicable: EU Regulation 2016/679 ("GDPR"), the GDPR as retained in UK law ("UK GDPR") and the UK Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws, and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"). "Personal Data" means Customer Data that identifies or relates to an identified or identifiable natural person. "Controller", "Processor", "Data Subject", "Processing", and "Supervisory Authority" have the meanings in the GDPR, and equivalent terms in other Data Protection Laws are read accordingly (e.g., "Business" and "Service Provider" under the CCPA). "Subprocessor" means a third party engaged by Blunox to process Personal Data. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the EU SCCs.

2. Roles and Scope

2.1 Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Blunox is the Processor of Personal Data. Where Customer is itself a Processor, Customer warrants that its instructions to Blunox are consistent with its Controller's instructions.

2.2 The subject matter, duration, nature and purpose of Processing, and the categories of Personal Data and Data Subjects, are described in Annex 1.

3. Processing Instructions

3.1 Blunox will process Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services, unless required by law to process otherwise, in which case Blunox will inform Customer of the legal requirement before processing (unless the law prohibits it). Blunox will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

3.2 Blunox will not sell Personal Data, share it for cross-context behavioral advertising, or retain, use, or disclose it for any purpose other than performing the Services, as those concepts are defined under the CCPA, and certifies that it understands and will comply with these restrictions.

4. Confidentiality and Personnel

Blunox ensures that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data-protection training, and limits access to personnel who need it to perform the Services.

5. Security

Blunox will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2 (Security Measures). Blunox may update Annex 2 provided the updates do not materially reduce the overall protection of Personal Data.

6. Subprocessors

6.1 Customer provides general authorization for Blunox to engage the Subprocessors listed at blunox.ai/legal/subprocessors. Blunox will give at least 30 days' notice (via the subprocessor page mailing list or in-product notice) before adding or replacing a Subprocessor.

6.2 Customer may object on reasonable data-protection grounds within 15 days of notice. The parties will discuss in good faith; if no resolution is reached, Customer may terminate the affected Order Form with a prorated refund of prepaid fees for the unused remainder.

6.3 Blunox will impose data-protection obligations on Subprocessors that are no less protective than this DPA and remains liable for Subprocessors' performance.

7. Data Subject Requests

Taking into account the nature of the Processing, Blunox will assist Customer by appropriate technical and organizational measures (including self-service export, correction, and deletion features of the Services) in fulfilling Customer's obligation to respond to Data Subject requests. If Blunox receives a request directly, it will promptly forward it to Customer and will not respond except to direct the Data Subject to Customer, unless legally required.

8. Assistance

Blunox will provide reasonable assistance to Customer with data protection impact assessments, consultations with Supervisory Authorities, and Customer's security and breach-notification obligations, taking into account the nature of Processing and the information available to Blunox.

9. Personal Data Breach

Blunox will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data, providing (as information becomes available): the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. Blunox's notification is not an acknowledgement of fault or liability. Blunox will cooperate with Customer's reasonable investigation and remediation.

10. Audits

10.1 Blunox will make available information reasonably necessary to demonstrate compliance with this DPA, including (where held) current third-party audit reports and certifications (the underlying cloud platform, Google Cloud, is independently certified to SOC 2 and ISO 27001; Blunox holds no third-party certifications of its own yet), security questionnaires, and this DPA's Annexes.

10.2 Where Data Protection Laws grant Customer an audit right that cannot be satisfied by the materials above, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit of Blunox's relevant controls, no more than once per 12 months, on at least 30 days' notice, during business hours, without access to other customers' data, and at Customer's expense. Findings are Blunox Confidential Information.

11. International Transfers

11.1 Blunox stores Customer Data at rest in the hosting region selected in the Order Form or Service configuration; where none is selected, the default regions are listed at blunox.ai/legal/subprocessors.

11.2 EEA/UK/Swiss transfers. Where Processing involves a transfer of Personal Data subject to the GDPR to a country without an adequacy decision, the parties enter into the SCCs (Module 2: Controller → Processor, or Module 3 where Customer is a Processor), which are incorporated by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 30 days' notice); Clause 11 optional language excluded; Clause 17: law of Ireland; Clause 18: courts of Ireland; Annexes I–III of the SCCs are completed by Annexes 1–2 of this DPA and the subprocessor page. For UK transfers, the UK Addendum applies with Table 4 permitting either party to end the addendum as set out in Section 19; for Swiss transfers, the SCCs apply with references adapted to the FADP.

11.3 UAE transfers. For Personal Data subject to the UAE PDPL, transfers outside the UAE are made in accordance with PDPL Articles 22–23, on the basis of contractual safeguards no less protective than this DPA and the SCC mechanics above, or another lawful mechanism (adequacy decision of the UAE Data Office, Data Subject consent, or other statutory basis).

11.4 If a competent authority or change in Data Protection Laws invalidates a transfer mechanism relied on under this DPA, the parties will cooperate in good faith to implement a lawful alternative.

12. Return and Deletion

Upon termination or expiry of the Agreement, Blunox will, at Customer's election exercised within 30 days, return Personal Data in a machine-readable format and/or delete it, and will delete remaining copies within 90 days, except as retained in backups (deleted on backup-cycle expiry, max 35 days) or as required by law. On written request, Blunox will confirm deletion in writing.

13. Liability; Order of Precedence

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Data Protection Laws prohibit such limitation. In case of conflict, this DPA prevails over the Agreement with respect to Processing of Personal Data, and the SCCs prevail over this DPA.


Annex 1 — Description of Processing

  • Subject matter and nature of Processing: provision of Blunox cloud software services (data engineering, data integration, and related products), including hosting, storage, transmission, transformation, analysis, and display of Customer Data; support and troubleshooting.
  • Duration: the term of the Agreement plus the deletion periods in Section 12.
  • Purpose: performing the Services under the Agreement.
  • Categories of Data Subjects: Customer's Users; Customer's employees, contractors, customers, suppliers, and end users whose data is contained in Customer Data (as determined by Customer).
  • Categories of Personal Data: as determined by Customer's use of the Services; typically identification and contact data, professional data, transaction and usage records, and any other Personal Data Customer submits. Sensitive data: not intended to be processed unless Customer configures the Services to do so; where submitted, it is protected by the measures in Annex 2.
  • Frequency: continuous, for the duration of the Agreement.

Annex 2 — Technical and Organizational Security Measures

  1. Encryption: TLS 1.2+ in transit; AES-256 at rest.
  2. Access control: role-based access, least privilege, MFA for administrative access, logged and reviewed access to production.
  3. Tenant isolation: logical separation of customer environments and data.
  4. Network security: firewalls, network segmentation, vulnerability scanning, and annual penetration testing by an independent firm.
  5. Secure development: code review, dependency scanning, CI/CD controls, separation of environments.
  6. Operations: monitoring and alerting, capacity management, patch management SLAs by severity.
  7. Resilience: backups with defined RPO/RTO (RPO: 24h; RTO: 8h), geographically separated backup storage, restore testing.
  8. Incident response: documented IR plan, defined severities, customer notification without undue delay, post-incident review.
  9. Personnel: background screening where lawful, confidentiality undertakings, security training on hire.
  10. Vendor management: subprocessor due diligence and contractual flow-down.
  11. Physical security: inherited from cloud infrastructure providers (Google Cloud) certified to ISO 27001/SOC 2.
  12. Certifications: Blunox holds no third-party security certifications today; SOC 2 Type II is on our roadmap.

Questions?

Questions about this document can be sent to legal@blunox.ai.