This Data Processing Addendum ("DPA") forms part of the Blunox Terms of Service or other agreement between Blunox and Customer governing the Services (the "Agreement") and applies where Blunox processes Personal Data on behalf of Customer in providing the Services.
"Data Protection Laws" means all laws applicable to the processing of Personal Data under the Agreement, including as applicable: EU Regulation 2016/679 ("GDPR"), the GDPR as retained in UK law ("UK GDPR") and the UK Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws, and UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"). "Personal Data" means Customer Data that identifies or relates to an identified or identifiable natural person. "Controller", "Processor", "Data Subject", "Processing", and "Supervisory Authority" have the meanings in the GDPR, and equivalent terms in other Data Protection Laws are read accordingly (e.g., "Business" and "Service Provider" under the CCPA). "Subprocessor" means a third party engaged by Blunox to process Personal Data. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the EU SCCs.
2.1 Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Blunox is the Processor of Personal Data. Where Customer is itself a Processor, Customer warrants that its instructions to Blunox are consistent with its Controller's instructions.
2.2 The subject matter, duration, nature and purpose of Processing, and the categories of Personal Data and Data Subjects, are described in Annex 1.
3.1 Blunox will process Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services, unless required by law to process otherwise, in which case Blunox will inform Customer of the legal requirement before processing (unless the law prohibits it). Blunox will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
3.2 Blunox will not sell Personal Data, share it for cross-context behavioral advertising, or retain, use, or disclose it for any purpose other than performing the Services, as those concepts are defined under the CCPA, and certifies that it understands and will comply with these restrictions.
Blunox ensures that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data-protection training, and limits access to personnel who need it to perform the Services.
Blunox will implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2 (Security Measures). Blunox may update Annex 2 provided the updates do not materially reduce the overall protection of Personal Data.
6.1 Customer provides general authorization for Blunox to engage the Subprocessors listed at blunox.ai/legal/subprocessors. Blunox will give at least 30 days' notice (via the subprocessor page mailing list or in-product notice) before adding or replacing a Subprocessor.
6.2 Customer may object on reasonable data-protection grounds within 15 days of notice. The parties will discuss in good faith; if no resolution is reached, Customer may terminate the affected Order Form with a prorated refund of prepaid fees for the unused remainder.
6.3 Blunox will impose data-protection obligations on Subprocessors that are no less protective than this DPA and remains liable for Subprocessors' performance.
Taking into account the nature of the Processing, Blunox will assist Customer by appropriate technical and organizational measures (including self-service export, correction, and deletion features of the Services) in fulfilling Customer's obligation to respond to Data Subject requests. If Blunox receives a request directly, it will promptly forward it to Customer and will not respond except to direct the Data Subject to Customer, unless legally required.
Blunox will provide reasonable assistance to Customer with data protection impact assessments, consultations with Supervisory Authorities, and Customer's security and breach-notification obligations, taking into account the nature of Processing and the information available to Blunox.
Blunox will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data, providing (as information becomes available): the nature of the breach, categories and approximate numbers of Data Subjects and records affected, likely consequences, and measures taken or proposed. Blunox's notification is not an acknowledgement of fault or liability. Blunox will cooperate with Customer's reasonable investigation and remediation.
10.1 Blunox will make available information reasonably necessary to demonstrate compliance with this DPA, including (where held) current third-party audit reports and certifications (the underlying cloud platform, Google Cloud, is independently certified to SOC 2 and ISO 27001; Blunox holds no third-party certifications of its own yet), security questionnaires, and this DPA's Annexes.
10.2 Where Data Protection Laws grant Customer an audit right that cannot be satisfied by the materials above, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit of Blunox's relevant controls, no more than once per 12 months, on at least 30 days' notice, during business hours, without access to other customers' data, and at Customer's expense. Findings are Blunox Confidential Information.
11.1 Blunox stores Customer Data at rest in the hosting region selected in the Order Form or Service configuration; where none is selected, the default regions are listed at blunox.ai/legal/subprocessors.
11.2 EEA/UK/Swiss transfers. Where Processing involves a transfer of Personal Data subject to the GDPR to a country without an adequacy decision, the parties enter into the SCCs (Module 2: Controller → Processor, or Module 3 where Customer is a Processor), which are incorporated by reference, completed as follows: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 30 days' notice); Clause 11 optional language excluded; Clause 17: law of Ireland; Clause 18: courts of Ireland; Annexes I–III of the SCCs are completed by Annexes 1–2 of this DPA and the subprocessor page. For UK transfers, the UK Addendum applies with Table 4 permitting either party to end the addendum as set out in Section 19; for Swiss transfers, the SCCs apply with references adapted to the FADP.
11.3 UAE transfers. For Personal Data subject to the UAE PDPL, transfers outside the UAE are made in accordance with PDPL Articles 22–23, on the basis of contractual safeguards no less protective than this DPA and the SCC mechanics above, or another lawful mechanism (adequacy decision of the UAE Data Office, Data Subject consent, or other statutory basis).
11.4 If a competent authority or change in Data Protection Laws invalidates a transfer mechanism relied on under this DPA, the parties will cooperate in good faith to implement a lawful alternative.
Upon termination or expiry of the Agreement, Blunox will, at Customer's election exercised within 30 days, return Personal Data in a machine-readable format and/or delete it, and will delete remaining copies within 90 days, except as retained in backups (deleted on backup-cycle expiry, max 35 days) or as required by law. On written request, Blunox will confirm deletion in writing.
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Data Protection Laws prohibit such limitation. In case of conflict, this DPA prevails over the Agreement with respect to Processing of Personal Data, and the SCCs prevail over this DPA.
Questions about this document can be sent to legal@blunox.ai.