Data Processing Agreement
I. Effective date
Updated on 7 August 2026.
This page summarises how The Wall d.o.o. (“Blekline”, “we”, “us”, “Processor”) processes personal data on behalf of business customers when they use the Blekline platform. It is a public summary for procurement and privacy diligence. The executable Data Processing Agreement (GDPR Article 28) is provided to business and enterprise customers on request.
Request a DPA: enterprise@blekline.com
Related: Privacy · Subprocessors · Terms
II. Roles
When you use Blekline for your own employees or end users, you are typically the Controller for that personal data. The Wall d.o.o. acts as Processor for Customer Data submitted through the Services.
For Blekline’s own account, billing, and marketing data, The Wall d.o.o. is Controller — see our Privacy Policy.
III. Scope of processing
The DPA covers personal data processed to deliver the Blekline Services, including:
- Masking and redaction of text submitted for policy evaluation
- Tool-call policy evaluation (allow, mask, block) before downstream execution
- Ingress proxy governance for model API traffic (request and response paths where enabled)
- Metadata-only audit logging (default configuration)
- Workspace administration, authentication, and billing metadata
Default configuration: Blekline is designed for metadata-only audit — full prompt or tool payloads are not retained in the Activity log by default. Masking may send text to subprocessors on the cloud mask path only; sidecar local_only deployments keep processing in your network.
Technical trust boundaries: app.blekline.com/docs/security/trust-boundaries
IV. Types of personal data
Special category data: Blekline does not require special category data (e.g. health, biometric). Do not submit special category data unless agreed in writing and lawfully permitted.
Data subjects: Your employees, contractors, and authorised end users.
V. Subprocessors
We use third parties to host and operate the Services. The authoritative list is published at blekline.com/subprocessors.
Under the DPA:
- You provide general authorisation for subprocessors on that list
- We give 30 days' advance notice of material subprocessor additions or replacements
- You may object on reasonable data protection grounds within 14 days of notice
- If we cannot resolve an objection within 30 days, you may terminate the affected Services without penalty
Subscribe to subprocessor updates: email hello@blekline.com with subject “Subprocessor updates”.
VI. International transfers
Default SaaS (EEA-first): Primary processing locations are in the European Economic Area — compute in Frankfurt, Germany; database in Ireland; cloud masking in Germany West Central. See the Subprocessor list.
Where personal data is transferred from the EEA or UK to countries without an adequacy decision, we rely on:
- EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor)
- UK Addendum to the SCCs where UK GDPR applies
- Supplementary measures as required
US-primary processing and EEA Processing Confirmation addenda are available for enterprise customers — contact enterprise@blekline.com.
VII. Security
We implement appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+)
- Workspace-scoped access controls and API token authentication
- Policy enforcement at the MCP, SDK, and ingress proxy boundary
- Metadata-only audit default; configurable retention per workspace
- Incident response procedures
Detailed measures are documented in Annex B — Technical and Organisational Measures (TOMs), provided with the executable DPA.
VIII. Personal data breaches
We will notify you without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer Data, with information required under GDPR Article 33(3) as it becomes available.
Report security concerns: hello@blekline.com
IX. Data subject rights
We will assist you in responding to data subject requests within 15 business days of your request, considering the nature of processing. Data subjects should contact you (the Controller) first. Blekline provides account export and workspace deletion tooling where applicable.
X. Deletion and return
Upon termination of your agreement, we will delete or return Customer Data per your written choice within 30 days, except where retention is required by law. Backup copies are deleted on a rolling schedule within 30 days thereafter. Workspace API tokens are revoked at termination.
Export audit metadata before termination if you need a local copy.
XI. Audits
We make information available to demonstrate compliance with the DPA. You may audit no more than once per 12 months on 30 days' notice, subject to confidentiality, security, and minimal disruption. We may satisfy audit requests with third-party reports (e.g. SOC 2) when available.
XII. How to obtain the DPA
The executable DPA incorporates the Blekline Terms or Master Services Agreement and includes annexes for TOMs, SCCs, and optional residency addenda.
VIII. Contact
The Wall d.o.o. (Blekline)
Mestni trg 10, 1000 Ljubljana, Republic of Slovenia
General: hello@blekline.com
Enterprise & DPA: enterprise@blekline.com
Supervisory authority (Slovenia): Informacijski pooblaščenc — www.ip-rs.si
This page is a public summary for diligence. It is not legal advice and does not replace a signed Data Processing Agreement.
