Data Processing Agreement
Last updated on
1. Introduction
This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Principal Agreement") between Blooms ("Processor") and the User ("Controller"). This DPA applies to the extent that Blooms processes Personal Data on behalf of the Controller in the course of providing the Services.
2. Definitions
- "CCPA" means the California Consumer Privacy Act.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679.
- "Sub-processor" means any third party appointed by or on behalf of the Processor to process Personal Data.
- "Standard Contractual Clauses" (SCCs) means the clauses attached hereto pursuant to the European Commission's decision (EU) 2021/914.
3. Roles and Responsibilities
- Controller (You): You determine the purposes and means of processing Personal Data (e.g., the content you put on your website, your visitors' data).
- Processor (Blooms): We process Personal Data only on your documented instructions (which are essentially to provide the Service as described).
4. Processing of Personal Data
Blooms shall process Personal Data:
- In accordance with the Principal Agreement and this DPA.
- In compliance with applicable Data Protection Laws (GDPR, CCPA).
- Only for the purpose of providing the Services, including: hosting websites, generating analytics, AI assistance (Bloomie), social media integrations, email communications, and content moderation.
5. Security Measures
Blooms implements industry-standard technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit: All connections are encrypted using industry-standard protocols.
- Encryption at rest: Sensitive credentials are encrypted at rest.
- Anonymized analytics: Visitor identifiers are anonymized. Raw IP addresses are not stored in our analytics system.
- Access control: Role-based access control for administrative functions with audit logging.
- Infrastructure security: Primary hosting in Germany (EU) with CDN and DDoS protection. Database hosted with a certified provider.
- Backups: Regular automated backups stored in redundant locations.
6. Sub-processors
You grant Blooms a general authorization to engage Sub-processors.
Current Sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| Infrastructure provider | Hosting and analytics | Germany (EU) |
| Cloudflare, Inc. | CDN, DNS, DDoS Protection, Media Storage | Global |
| Database provider | Application database | USA |
| Stripe, Inc. | Payment Processing | Global |
| Google LLC | AI Assistant (Bloomie), Analytics | USA |
| Microsoft Corporation | Behavior Analytics | USA |
| Email service provider | Transactional Email | USA |
| Meta Platforms, Inc. | Instagram Integration (only if connected) | USA |
Changes: We will notify you of any intended changes concerning the addition or replacement of Sub-processors via our website or email. You have the right to object to such changes within 30 days.
7. International Data Transfers
Blooms' primary infrastructure is hosted in Germany (EU), meaning your core data resides within the European Economic Area.
For Sub-processors located in the United States:
- For EU/EEA Controllers: The parties agree that the Standard Contractual Clauses (SCCs) allow for the transfer of personal data to the US. By using the Service, the SCCs are deemed signed and incorporated into this DPA.
- Data Privacy Framework: Where applicable, our US-based Sub-processors participate in the EU-US Data Privacy Framework (Stripe, Google, Microsoft).
8. Data Subject Rights
If Blooms receives a request from a Data Subject (e.g., one of your website visitors) to exercise their rights (access, rectification, erasure, portability, restriction, objection), we will:
- Notify you promptly (unless prohibited by law).
- Not respond to the request directly, except to redirect the Data Subject to you.
- Provide reasonable assistance to help you fulfill the request.
9. Data Breach Notification
In the event of a Personal Data Breach affecting your data, Blooms will:
- Notify you without undue delay (and in any event within 72 hours of becoming aware).
- Provide sufficient information to allow you to meet any obligations to report the breach to data protection authorities.
10. Audit Rights
Upon written request, Blooms will make available information necessary to demonstrate compliance with this DPA. If you require an on-site audit, it shall be:
- At your expense.
- Conducted during normal business hours with reasonable advance notice.
- Subject to a confidentiality agreement.
11. Deletion of Data
Upon termination of your account, Blooms will delete all Customer Data in accordance with our standard retention procedures (typically within 30 days), unless applicable law requires storage. Analytics data is retained for up to 13 months. Admin audit logs auto-expire after 30 days.
Annex 1: Details of Processing
A. Subject Matter: The provision of the Blooms SaaS platform (website builder and link-in-bio tool).
B. Nature and Purpose: Storage, retrieval, and display of user-generated content; visitor analytics; AI-assisted content generation; social media data integration; payment processing; email communications; content moderation.
C. Categories of Data Subjects: The Controller's users, visitors to the Controller's website, social media contacts (if Instagram integration is connected).
D. Types of Personal Data: Names, email addresses, profile information, images, text content, IP addresses (hashed), geolocation data, device information, social media data (messages, media, analytics), AI conversation content, payment identifiers, usage data.
Annex 2: Technical and Organizational Measures
- Encryption: Industry-standard encryption in transit and at rest for sensitive credentials.
- Pseudonymization: Visitor analytics use anonymized identifiers.
- Access control: Role-based access for platform administration; session-based authentication.
- Audit logging: Administrative actions are logged with appropriate retention periods.
- Data minimization: Only necessary data collected per purpose; credit card data handled entirely by Stripe.
- Infrastructure: EU-hosted primary infrastructure (Germany) with CDN and DDoS protection.
- Incident response: 72-hour breach notification; documented incident response procedures.
Related Policies
Learn about our privacy practices, refund policy, and cancellation terms.