BlankProductSecurity
Request Access
On this page
PreambleDefinitions1. Scope2. Instructions3. Confidentiality4. Security5. Sub-Processors6. Assistance7. Data Subject Requests8. Personal Data Breach9. Deletion10. Audit11. International Transfers12. Government Access13. LiabilityAnnex 1 — DescriptionAnnex 2 — Sub-ProcessorsAnnex 3 — Security Measures

Data Processing Addendum (Online / Self-Serve)

Version: July 18, 2026

Preamble

This Data Processing Addendum (the "DPA") forms part of the Blank terms of service (the "Terms") between Ambre LLC, a Texas limited liability company with offices at 1010 Waugh Drive, Houston, TX 77019, United States, publisher of the "Blank" service ("Blank" or the "Processor"), and the user or organisation accepting the Terms (the "Controller").

Execution. This DPA is concluded by electronic acceptance of the Terms at account creation, without the need for a separate signature. It applies to all plans, including the Free plan, from the first upload of a document. For Enterprise plan clients, this DPA applies until superseded by a data processing agreement executed separately between the parties, which then prevails.

Definitions

Capitalised terms not defined below have the meaning given by the GDPR or the Terms. "GDPR" means Regulation (EU) 2016/679. "Customer Data" means documents uploaded to the Service, data extracted from those documents, and generated deliverables. "SCCs" means the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021. "DPF" means the EU-U.S. Data Privacy Framework (and, where applicable, its UK Extension and the Swiss-U.S. DPF).

1. Scope and Description of Processing

1.1 This DPA applies exclusively to Customer Data containing personal data subject to the GDPR, which Blank processes as a processor on the Controller's documented instructions. It does not apply to account data, technical connection data or commercial contact data, which Blank processes as an independent controller as described in its privacy policy.

1.2 Subject matter and purpose: processing of documents provided by the Controller to generate structured deliverables, for the purposes determined by the Controller. Nature: collection (receipt of upload), extraction and analysis (OCR, AI-assisted generation), temporary storage, delivery, deletion. Duration: for as long as Blank processes Customer Data for the Controller. Data Subjects and categories of Data: as described in Annex 1.

2. Instructions

Blank processes the Customer Data only on the Controller's documented instructions — this DPA and the use of the Service constituting such instructions — unless required by Union or Member State law, in which case Blank informs the Controller before processing unless legally prohibited. Blank informs the Controller if it considers an instruction infringes the GDPR.

3. Confidentiality

Blank ensures that persons authorised to process the Customer Data are committed to confidentiality or under an appropriate statutory obligation of confidentiality.

4. Security (Article 32 GDPR)

Blank implements the technical and organisational measures detailed in Annex 3, including encryption in transit and at rest, strict per-client isolation, strong authentication and short-lived verified access tokens, production access restricted on a need-to-know basis, no document content stored in application databases and original file names not retained, automated deletion routines (source documents deleted no later than 15 minutes after completion of processing; documents uploaded but never processed deleted no later than 24 hours after upload; deliverables deleted upon expiry of the period configured by the Controller — 48 hours by default, adjustable between 1 and 168 hours; pseudonymised technical metadata deleted no later than 365 days after creation), and no use of Customer Data for profiling, indexing or AI model training.

5. Sub-Processors

5.1 The Controller grants a general written authorisation (Clause 9, Option 2 of the SCCs) for the sub-processors listed in Annex 2 and at blnksolutions.com/subprocessors.

5.2 Blank gives at least thirty (30) days' notice of any addition or replacement, by email to the registered contact address, before the change takes effect. The Controller may object on legitimate, documented data protection grounds within ten (10) days of such notice; failing a written objection within that period, the new sub-processor is deemed approved. The current list is maintained at blnksolutions.com/subprocessors.

5.3 If an objection cannot be resolved within thirty (30) days, the Controller may terminate the affected part of the Service without penalty; any pre-paid fees for the unused period are refunded pro rata.

5.4 Blank imposes equivalent data protection obligations on each sub-processor by written contract and remains fully liable for their performance.

6. Assistance

Taking into account the nature of the processing and the information available to it, Blank assists the Controller, insofar as possible, with: security of processing (Article 32), breach notifications (Articles 33–34), and data protection impact assessments and prior consultations (Articles 35–36).

7. Data Subject Requests

Blank notifies the Controller without undue delay of any request received directly from a Data Subject and does not respond itself except on the Controller's instructions. Blank assists the Controller insofar as possible. Given the short retention cycle, part of the Customer Data may no longer exist when a request is processed.

8. Personal Data Breach

Blank notifies the Controller of any personal data breach affecting Customer Data without undue delay after becoming aware of it, and within seventy-two (72) hours at the latest, with the information reasonably available to it (nature of the breach, categories and approximate number of Data Subjects and records concerned, likely consequences, measures taken or proposed), and cooperates with the Controller's subsequent notifications.

9. Deletion at End of Provision

Upon termination of the services involving processing, Blank deletes the Customer Data — the automated deletion cycle in Section 4 ensuring this in the ordinary course — or returns it at the Controller's choice, and deletes existing copies unless Union or Member State law requires storage. A certificate of deletion is provided on request.

10. Audit

Blank makes available the information necessary to demonstrate compliance, in the first instance through documentation (security policy, summaries of third-party penetration test reports, attestations, responses to reasonable questionnaires). Where documentation is insufficient or following a breach affecting the Controller's Customer Data, the Controller may audit (itself or through an independent, non-competitor auditor under confidentiality), subject to thirty (30) days' notice, once per twelve (12) months maximum (except following a breach), during business hours, without access to other clients' data, at the Controller's cost.

11. International Transfers and SCCs

11.1 File storage (EU-located bucket) and OCR are performed in the European Union; other processing may involve transfers to the United States, where Blank is established, and to the sub-processors in Annex 2.

11.2 For transfers of Customer Data subject to the GDPR from the Controller (exporter) to Blank (importer), the SCCs are incorporated by reference and deemed completed and executed as follows: Module 2 (controller to processor) or Module 3 (processor to processor) where the Controller itself acts as processor; Clause 7 (docking): not applicable; Clause 9: Option 2, with the notice period in Section 5.2; Clause 11(a): the optional independent dispute resolution body does not apply; Clause 13 / Annex I.C: the supervisory authority of the Member State where the exporter is established; Clause 17: the laws of France; Clause 18: the courts of Paris, France; Annex I of the SCCs = Annex 1 below, Annex II = Annex 3, Annex III = Annex 2.

11.3 In the event of conflict, the SCCs prevail over this DPA, which prevails over the Terms, in respect of the processing and transfer of Customer Data.

11.4 Where a transfer is covered by an adequacy decision or the relevant importer is DPF-certified, that mechanism may serve as the transfer tool in place of the SCCs for the transfer concerned.

11.5 Where data subject to the UK GDPR or the Swiss FADP is concerned, the UK International Data Transfer Addendum and/or the Swiss adaptations of the SCCs apply mutatis mutandis.

12. Government Access Requests

If Blank receives a legally binding request from a public authority for Customer Data, it notifies the Controller without delay (unless legally prohibited) and redirects the authority to the Controller where possible. Blank reviews the legality of each request, challenges requests it considers unlawful or excessive, makes no voluntary disclosure, and discloses only the minimum legally required. Where such a request materially affects the guarantees of the SCCs, the parties assess in good faith whether the transfers concerned should be suspended.

13. Liability and Governing Law

13.1 Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms, applying in aggregate across the Terms and this DPA together.

13.2 Nothing in this DPA or the Terms limits or excludes (i) liability to Data Subjects under the third-party beneficiary provisions of the SCCs (Clause 12), (ii) liability under Article 82 GDPR, or (iii) any liability that cannot be limited or excluded under applicable law.

13.3 This DPA is governed by the law governing the Terms, except that the SCCs are governed by the law designated under Clause 17 and disputes arising from the SCCs are resolved before the courts designated under Clause 18.

Annex 1 — Description of the Processing and Transfer (Annex I of the SCCs)

A. Parties. Data exporter: the Controller (the user or organisation accepting the Terms; contact details as registered at account creation); role: controller, or processor where Section 11.2 Module 3 applies. Data importer: Ambre LLC, 1010 Waugh Drive, Houston, TX 77019, United States; [email protected]; role: processor.

B. Transfer. Data Subjects: natural persons referred to in uploaded documents (e.g. executives, shareholders, employees, business contacts), as determined by the Controller. Categories of Data: content of uploaded documents; may include names, contact details, professional and financial information. Sensitive data: not intended; the Controller undertakes not to upload special categories of personal data (Article 9 GDPR) without Blank's prior written agreement on specific additional safeguards. Frequency: continuous, according to use of the Service. Retention: source documents deleted no later than 15 minutes after completion of processing; documents uploaded but never processed deleted no later than 24 hours after upload; deliverables deleted upon expiry of the configured period (48 hours by default, adjustable between 1 and 168 hours); no durable retention of content. Onward transfers: to the sub-processors in Annex 2, solely to provide the Service.

C. Competent supervisory authority. The supervisory authority of the Member State in which the exporter is established (for example, the CNIL for an exporter established in France).

Annex 2 — Authorised Sub-Processors (Annex III of the SCCs)

Sub-processorFunctionLocation of processingTransfer safeguard
AnthropicAI generation (US flow)United StatesSCCs (incorporated in provider DPA)
Amazon Web Services (Bedrock)AI generation — EU residency flowEuropean Union (Paris, eu-west-3)Processing in the EU; US entity — SCCs (2021/914) + DPF in reserve
Mistral AIOCR / document analysisEuropean Union (France)N/A (EEA); Zero Data Retention enabled on Blank's account
CloudflareFile storage (EU-located bucket)European UnionSCCs (incorporated in provider DPA)
RailwayApplication hostingUnited StatesSCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active)
VercelFrontend hostingUnited StatesSCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active)
ClerkAuthenticationUnited StatesSCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active)
ResendTransactional emailUnited StatesSCCs (provider DPA); EU-U.S. DPF + UK Extension + Swiss-U.S. DPF (active)
SentryFrontend and backend error monitoring (technical data only)EU data region; US entityEU data region; EU-U.S. DPF + SCCs (2021/914)

No sub-processor is authorised to use Customer Data to train or improve AI models (Sentry, our monitoring sub-processor, only receives technical error data, no document content and no personal data deliberately transmitted). Current list: blnksolutions.com/subprocessors. DPF certification statuses verified on the U.S. Department of Commerce register (dataprivacyframework.gov) as of June 11, 2026 and monitored periodically; in all cases, the SCCs incorporated in each provider's data processing agreement remain in place as the baseline transfer safeguard.

Annex 3 — Technical and Organisational Measures (Annex II of the SCCs)

Encryption in transit (TLS/HSTS) and at rest; strong authentication and short-lived verified access tokens; production access restricted on a need-to-know basis; logical per-client isolation with no cross-client access paths; no document content stored in application databases and original file names not retained; automated deletion routines running at short, regular intervals enforcing the retention periods in Annex 1.B; no backup or archive of source documents or deliverables; no profiling, indexing or AI training use — service improvement relies exclusively on technical metadata containing no document content; pseudonymised audit logs (timestamps, operation status, volume; no content, no organisation names) retained for a maximum of 365 days; vulnerability scanning in continuous integration and periodic security reviews; documented incident response process supporting Section 8; written sub-processor contracts with flow-down obligations.

Detailed security documentation is available on request, under confidentiality (Section 10).

© 2026 Blank
[email protected]
SecurityLegal noticeTermsPrivacy
/