Data Processing Addendum
Controller–processor terms for personal data in customer content.
This Data Processing Addendum ("DPA") forms part of the Terms or other agreement between the customer ("Controller") and BLINKHOST LTD ("Processor") where BlinkHost processes personal data in customer content on the Controller's behalf.
1. Instructions and compliance
Processor will process customer personal data only to provide and secure the service, on documented Controller instructions, or as required by law. Where law requires other processing, Processor will notify Controller unless prohibited. Each party will comply with the Nigeria Data Protection Act 2023 and other law applicable to its role. Controller is responsible for lawful instructions, notices, legal bases and responding to data subjects.
2. Processing details
Subject and purpose: authorised source collaboration, browser and isolated backend preview execution, build, hosting, deployment, project-asset storage and security scanning, edge delivery, managed database, application observability and support. Duration: service term plus disclosed export, retention and deletion periods. Nature: collection, validation, security scanning, execution, storage, organisation, retrieval, transmission, replication, aggregation, backup, export and deletion. Data: customer-selected application/database content, identifiers, contact, usage, device, communications, logs, traces, metrics and runtime decisions. Subjects: Controller's users, personnel, customers, application visitors and others whose data Controller submits.
3. Confidentiality and security
Authorised personnel are bound by confidentiality. Processor maintains measures appropriate to risk, including tenant-scoped access, encryption, identity and secret controls, logging, release controls, monitoring, backups and incident response. Controller remains responsible for its application security, user access, secrets and configuration.
4. Service providers
Controller authorises Processor to use service providers for infrastructure, storage, networking, email, managed databases, payments, source collaboration, security and support. Processor requires providers that process customer personal data to protect it under written data-protection obligations appropriate to the service and remains responsible as required by law. We will give reasonable advance notice by email or through the service before appointing a materially different provider that processes customer personal data. Controller may object on documented data-protection grounds; the parties will seek a reasonable alternative, and Controller may discontinue the affected service if none is available.
5. Assistance and incidents
Taking account of the processing and information available, Processor will reasonably assist with data-subject requests, security, breach assessment/notification, impact assessments, regulator consultation and compliance evidence. Processor will notify Controller without undue delay after confirming a breach affecting customer content and provide available material information as investigation progresses.
6. International transfers
Processor will use an applicable lawful transfer basis, appropriate contractual safeguards and supplementary technical/organisational measures for restricted international transfers.
7. Return, deletion and audit
On termination and request, Processor will provide reasonable tenant-scoped export and delete or return data unless law requires retention. Protected backup copies expire through controlled cycles. A documented, time-bounded legal hold may preserve a narrow scope. Processor will provide information reasonably necessary to demonstrate compliance and support proportionate audits, subject to confidentiality, security, reasonable notice and avoidance of disruption.
8. Precedence and contact
This DPA controls a conflict about processor activity. Liability follows the main agreement subject to non-excludable rights. Contact privacy@blinkhost.me.
Source collaboration instructions
Controller authorizes Processor to process connected source and participating-user data only as needed to perform the source import, synchronization, collaboration, template installation, review, handoff and evidence functions selected by Controller's authorized users. Controller is responsible for invitation authority, role selection, notice to invited users, lawful instructions and removal of access that is no longer required.
Recoverable collaboration content follows the contracted plan retention. Reviews, approvals and security evidence may be retained for security, dispute and compliance periods stated in the Privacy Policy or applicable retention schedule. Evidence export objects expire after seven days unless law requires preservation. These periods do not require Controller to retain a downloaded copy.
Live co-editing instructions
Controller instructs Processor to synchronize source changes and process participant identity, access, presence and recovery data when Controller's authorized users enable or use live co-editing. Controller is responsible for the lawful basis and notices applicable to invited users, the source placed in the service, role and file-scope decisions, endpoint security and timely access revocation.
Recoverable edit history follows the contracted plan retention, subject to documented legal holds and the deletion and security provisions of this Addendum. Short-lived presence is used only to provide and protect the active collaboration experience.
Hosted Object Storage
Where Hosted Object Storage contains Personal Data submitted through a customer application, that data is Customer Data processed under this Addendum. Processing may include receipt, security scanning, validation, storage, retrieval, delivery, backup and deletion. The Customer remains responsible for configuring public or private access and for giving end users the notices and choices required for the Customer's processing.
Asynchronous function processing
Where function payloads or results contain Personal Data, they are Customer Data processed to queue, execute, retry, observe, secure, retrieve, and delete the requested work. Processing may occur after the initiating browser or HTTP session ends. BlinkHost applies tenant scoping, integrity verification, access control, bounded retention, and deletion to stored invocation data.