Blackprint Legal

Blackprint Data Processing Agreement

GDPR Article 28 terms for processing personal data contained in workflow data, documents, integrations, and platform usage.

Version 1.0·Effective 2026-06-14·Incorporated by reference in Order Forms
Draft for legal review. These terms are structured for publication but must be reviewed by qualified counsel before your first client signature. Replace entity placeholders in lib/legal/meta.ts.

1. Parties and roles

This Data Processing Agreement ("DPA") forms part of the agreement between Blackprint B.V. ("Processor", "Blackprint") and the customer identified in the Order Form ("Controller", "Customer").

For the Services, Customer is the controller and Blackprint is the processor with respect to personal data processed on Customer's documented instructions.

Where Blackprint determines purposes and means for website analytics, account administration, or direct prospect communication, Blackprint acts as an independent controller for those limited activities, as described in the Privacy Policy.

2. Subject matter and duration

Blackprint processes personal data to provide workflow discovery, documentation, AI-assisted analysis, automation operation, support, and security monitoring under the Platform & Services Terms.

Processing continues for the term of the agreement and any wind-down/export period stated in the Terms or Order Form.

3. Nature and purpose of processing

Processing may include:

  • Storage and display of workflow maps, milestones, stages, and operational metadata
  • Upload, transcription, and analysis of documents, notes, and audio provided by Customer
  • Generation of AI-assisted summaries, classifications, and automation outputs
  • Execution and logging of automations connected to Customer-approved systems
  • User authentication, authorisation, audit logging, and support

4. Categories of data subjects and personal data

Depending on Customer's use, this may include:

  • Data subjects: Customer employees, contractors, and individuals referenced in Customer workflows
  • Personal data: names, business contact details, role assignments, operational content in documents and emails, identifiers in connected systems, and usage logs tied to identifiable users

5. Instructions

Blackprint will process personal data only on documented instructions from Customer, including the agreement, Order Form, SOW, configuration of the Platform, and documented support requests.

If Blackprint believes an instruction infringes applicable data protection law, it will inform Customer without undue delay.

6. Confidentiality of processing

Blackprint ensures that persons authorised to process personal data are bound by confidentiality obligations or statutory duties of confidentiality.

7. Security measures

Blackprint implements appropriate technical and organisational measures as described in the Security Measures page and updated from time to time.

Measures include access control, encryption in transit, tenant separation, logging, backups, and least-privilege administration.

8. Subprocessors

Customer provides general authorisation for Blackprint to engage subprocessors listed at the Subprocessor List page.

Blackprint will impose data protection obligations on subprocessors substantially similar to this DPA and remain responsible for subprocessors' performance.

Blackprint will notify Customer of intended changes to subprocessors with reasonable notice so Customer may object on reasonable data protection grounds.

If Customer objects on reasonable data protection grounds and the parties cannot agree on a resolution within a reasonable period, Customer may terminate the affected Services or Order Form, as its sole and exclusive remedy, by written notice without penalty (other than fees due for Services already provided).

9. Data subject rights and assistance

Blackprint will assist Customer, taking into account the nature of processing, in responding to requests to exercise data subject rights under applicable law.

Customer is responsible for providing a lawful basis and handling data subject requests. Blackprint may charge reasonable fees for manifestly excessive requests.

10. Personal data breach

Blackprint will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and provide information reasonably required for Customer to meet its breach notification obligations.

11. Return and deletion

Upon termination, Blackprint will, at Customer's choice, delete or return personal data, and delete existing copies, within 90 days, unless retention is required by law (in which case the data remains subject to the protections of this DPA for as long as it is retained).

12. International transfers

Where personal data is transferred outside the EEA, Blackprint will ensure appropriate safeguards such as EU Standard Contractual Clauses or equivalent mechanisms, and supplementary measures where required.

Customer acknowledges that certain AI or infrastructure subprocessors may process data outside the EEA subject to such safeguards.

13. Audit and information

Blackprint will make available information reasonably necessary to demonstrate compliance and allow audits no more than once per year on reasonable notice, subject to confidentiality and security constraints.

14. Liability

Liability arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Platform & Services Terms, including the enhanced cap that applies to breaches of this DPA. Nothing in this DPA limits either party's obligations or liability under applicable data protection law to a data subject or supervisory authority.