Data Processing Addendum
This draft DPA describes how Blunt Logic Ltd processes customer workspace data for private deployments. It is intended to sit alongside the Terms of Service and any customer-specific order form, subject to legal review before live paid onboarding.
Version 2026-07-06.2 · Effective 2026-07-06
Blunt Logic Ltd is registered in England and Wales (company number PENDING_COMPANY_NUMBER). Registered office: PENDING_REGISTERED_OFFICE_ADDRESS.
The customer acts as controller for customer personal data it submits to, stores in, or asks the workspace to process. Blunt Logic Ltd acts as processor when hosting, operating, securing, supporting, monitoring, troubleshooting, or updating the private deployment according to customer instructions. This DPA applies to personal data processed for the customer through the private workspace and related managed services.
This DPA forms part of, and is incorporated into, the Terms of Service; terms defined there have the same meaning here. Processing begins when the customer first submits personal data to the workspace and continues for the duration of the customer's subscription. Post-termination processing is limited to return, export, deletion, backup expiry, and legally required retention.
Blunt Logic Ltd will process customer personal data only to provide the service, follow documented customer instructions, comply with law, and perform related security, support, monitoring, backup, billing, and operational activities. The Terms of Service, order form, workspace configuration, and customer use of the service are documented instructions.
If Blunt Logic Ltd considers that a customer instruction infringes UK GDPR, the Data Protection Act 2018, or other applicable data protection law, Blunt Logic Ltd will inform the customer without undue delay and may suspend performance of the affected instruction until the customer has confirmed or amended it in writing.
Blunt Logic Ltd will not sell, rent, or disclose customer personal data to unrelated third parties for those parties' own purposes. Disclosures are limited to subprocessors under contract, disclosures required by law, or disclosures made with the customer's documented instruction.
The documented instructions do not authorise processing of special category data, criminal offence data, payment card data, or other highly sensitive information unless this has been expressly agreed in writing and the deployment has been configured for that data type. Blunt Logic Ltd may suspend, quarantine, or decline processing that appears outside the agreed scope and will notify the customer where it does so.
Customer personal data may include business contact details, CRM records, messages, notes, prompts, generated content, uploaded documents, support content, audit logs, usage records, and AI credit, top-up, and billing status records. Data subjects may include customer staff, prospects, suppliers, business contacts, and other individuals whose personal data the customer submits to or processes through the workspace.
Blunt Logic Ltd will use appropriate technical and organisational measures designed to protect customer personal data, including encryption in transit (TLS) and encryption at rest for stored customer data, owner-gated access, MFA-capable authentication, server-side secret handling, deployment isolation, audit logging, provider access controls, backup discipline, vulnerability and dependency maintenance, and redacted monitoring where practical.
Blunt Logic Ltd will ensure that persons authorised to process customer personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality. Access should be limited to what is reasonably needed for hosting, support, security, maintenance, incident response, billing, or agreed work.
The customer provides general authorisation for Blunt Logic Ltd to use subprocessors needed to provide the service, such as hosting, database, authentication, email, billing, monitoring, support, and AI providers. Blunt Logic Ltd will engage subprocessors under contractual terms that protect customer personal data and remains liable to the customer for the acts and omissions of its subprocessors in respect of customer personal data to the same extent as if Blunt Logic Ltd had performed them itself, subject to the limits of liability in the Terms of Service.
The current subprocessor list, including each provider's role and processing locations, is published on the operator site at /subprocessors. Blunt Logic Ltd will update that list with reasonable prior notice before adding or replacing a subprocessor that processes customer personal data. The customer may object to a change on reasonable data-protection grounds; if no resolution is agreed, the customer may terminate the affected service in line with the Terms of Service.
Stripe processes payment card data entered in Stripe Checkout as an independent controller under Stripe's own terms and privacy notice. Blunt Logic Ltd processes only Stripe identifiers and subscription or payment status, and Stripe appears on the subprocessor list for that billing-event data.
Where customer personal data is transferred outside the UK or EEA and a contractual safeguard is required, Blunt Logic Ltd will rely on UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or equivalent provider commitments, applied in unmodified form where used.
Taking into account the nature of the processing and information available, Blunt Logic Ltd will provide reasonable assistance with data subject requests, security obligations, data protection impact assessments, consultations with regulators, and customer compliance duties relating to the service. Assistance required by UK GDPR is provided at no additional charge; additional cooperation requested by the customer beyond what UK GDPR reasonably requires may be charged at reasonable rates notified in advance.
Blunt Logic Ltd will notify the customer without undue delay, and in any event within 72 hours of becoming aware of a confirmed personal data breach affecting customer personal data. The notice will include available information about the nature of the breach, affected data, likely consequences, and mitigation steps, where known.
The customer must notify Blunt Logic Ltd promptly of any suspected unauthorised access, credential compromise, unlawful data, or incident affecting the workspace so that both parties can respond appropriately.
On written request at or after termination, Blunt Logic Ltd will provide the customer's workspace content in a standard machine-readable format (such as CSV, JSON, or a file archive) within 30 days. Blunt Logic Ltd will then delete or anonymise customer personal data within 90 days of termination, subject to backup rotation and legally required retention.
Limited records may be retained where needed for billing, audit, legal compliance, dispute resolution, security, and legitimate business records, and limited redacted operational, billing, security, support, and audit summaries may be retained for the retention periods stated in the Privacy Notice after raw workspace data is deleted.
Blunt Logic Ltd maintains a record of processing activities carried out on behalf of each customer as required by UK GDPR Article 30(2), and will make reasonable information available to demonstrate compliance with this DPA. Any audit must be proportionate, scheduled in advance, protect other customers and confidential information, and avoid disrupting production systems. Independent reports or summaries may be used where appropriate, and any third-party auditor appointed by the customer must first enter into a reasonable confidentiality agreement.
Data protection enquiries: privacy@bluntlogic.ai. General enquiries: hello@bluntlogic.ai.