Snapshot 27530
Normalized text
Scripts and page chrome removed; this is what change detection compares.
NEW BlackFog Launches ADX Vision 2.0 to Secure the Next Generation of Enterprise AI Studio Gang Strengthens Data Security with BlackFog’s Last Line of Defense BlackFog Receives 2026 AI in Cybersecurity Innovation Award from TMCnet Login Demo Data Processing AgreementWendy McCague2026-09-22T14:47:41+01:00 DATA PROCESSING AGREEMENT What we do with personal data when we process it for you. This agreement forms part of the Contract for Services under the BlackFog Terms of Service. It sets out the terms on which BlackFog acts as your processor, the security measures applied, and the subprocessors involved. LAST UPDATED: APR 14, 2024 Read the Terms of Service Who it covers Business customers whose personal data BlackFog processes as a processor. It does not apply to individuals using the software for purely personal or family activity. How long it runs The term follows the term of the Principal Agreement. Terms not defined here carry the meaning given in that agreement. When it changes We update this agreement periodically. Active account holders are notified by email at least 28 days before changes take effect. on this page General Rights & obligations Security measures Data subject rights Third-country transfers Subprocessors Changes to this DPA Liability Annexes 01 General This Data Processing Agreement forms part of the Contract for Services under the BlackFog Terms of Service (the “Principal Agreement”). It is an amendment to the Principal Agreement and is effective on its incorporation into it, which may be specified in the Principal Agreement or in an executed amendment. Once incorporated, this agreement forms part of the Principal Agreement. For the processing activities described in Annex 1, where BlackFog acts as the customer’s processor, the parties agree to the following provisions on the commissioned processing of personal data until further notice. This DPA does not apply where the customer is a natural person using the software or services in the course of a purely personal or family activity (Art. 2(2)(c) GDPR). 02 Rights and obligations of BlackFog 2.1 Compliance with applicable laws BlackFog’s obligations arise from this DPA and from applicable law, which includes in particular the Federal Data Protection Act (FDPA) and the GDPR. 2.2 Processing on instructions only BlackFog processes personal data only within the scope of this DPA and on documented instructions from the customer, mutually agreed by the parties and defined in particular by the product functionality — unless required to act otherwise by Union or member state law to which BlackFog is subject, in which case BlackFog informs the customer of that requirement before processing unless the law prohibits it on important grounds of public interest. The customer may give additional written instructions where needed to comply with data protection law, and keeps the documentation of issued instructions for the term of the DPA. 2.3 Obligation of confidentiality BlackFog ensures that persons authorized to process the personal data have committed themselves to confidentiality, unless they are already subject to an appropriate legal obligation of secrecy. 2.7 Records of processing activities BlackFog provides the customer with the information necessary to maintain their records of processing activities. 2.8 Deletion and return at the end of processing At the customer’s choice, BlackFog deletes or returns the personal data processed on their behalf, to the extent that EU or member state law to which BlackFog is subject does not require the data to be stored. 2.9 – 2.11 Demonstrating compliance and notifying problems •BlackFog provides all information necessary to demonstrate compliance with the obligations in sections 2 and 3 of this DPA. •If BlackFog considers that carrying out an instruction could breach applicable data protection law, it informs the customer immediately and may suspend that instruction until the customer confirms or changes it in writing. •If BlackFog detects any violation of applicable data protection law, this DPA, or the customer’s instructions on commissioned processing, it informs the customer immediately. 2.12 Data protection officer BlackFog has appointed a data protection officer, reachable by email at our privacy address or in writing at BlackFog, Inc., for the attention of the Data Protection Officer, 1712 Pioneer Av., Cheyenne, WY 82001, USA. 03 Security measures under Art. 32 GDPR BlackFog takes the measures necessary for the security of processing under Article 32 GDPR. For each commissioned processing activity, a level of security appropriate to the risk to the rights and freedoms of the affected individuals is guaranteed. The protection objectives of Art. 32(1) GDPR: confidentiality, integrity and availability of systems and services, and their resilience given the nature, scope and context of the processing, are taken into account so that risks are permanently mitigated by appropriate measures. The measures adopted are described in detail in the documentation attached as Annex 2, which also describes the procedures for regular review, assessment and evaluation of their effectiveness. Security measures are subject to technical progress: BlackFog may implement alternative appropriate measures, provided the level of security never falls below the level already in place. 04 Assisting with data subject rights and Art. 32 to 36 Taking into account the nature of the processing, BlackFog assists the customer as far as possible with appropriate technical and organizational measures in fulfilling requests from data subjects exercising their rights under Chapter III of the GDPR. If a data subject contacts BlackFog directly about data processed on the customer’s behalf, and the customer is identifiable, BlackFog forwards the request to the customer immediately. BlackFog likewise supports the customer in meeting the obligations in Articles 32 to 36 GDPR: security of processing, notification of a personal data breach, data protection impact assessments and consultation with supervisory authorities. For the effort arising from such assistance, the customer remunerates BlackFog at an hourly rate of 100 Euros, if and as far as applicable data protection law permits. 05 Data transfers to a third country BlackFog generally transfers personal data processed under this DPA to a country outside the EU or EEA for which no EU Commission adequacy decision exists (an “unsafe third country”) only where: •the customer or the customer’s user instructs BlackFog to do so, for example by requesting a connection to an endpoint located in such a country, in which case the customer is responsible for ensuring the transfer complies with Art. 44 et seq. GDPR; or •BlackFog is obliged to do so under EU or member state law to which it is subject, in which case BlackFog informs the customer of those legal requirements before processing, unless the law prohibits it on important grounds of public interest. BlackFog may also use subprocessors in a third country to process personal data, insofar as the requirements of Art. 44 GDPR are met. 06 Subprocessors BlackFog uses a number of other processors. The current list for each BlackFog product is published in the Trust Center and referenced as Annex 3. By concluding this DPA, the customer agrees to the engagement of the subprocessors listed in Annex 3 at the time of conclusion for the relevant product. •Further or replacement subprocessors are selected with the required care and due diligence, and Annex 3 is updated on each appointment. •Subprocessors in third countries may only be engaged where the requirements of Art. 44 et seq. GDPR are fulfilled. •Contracts with subprocessors are structured to comply with applicable data protection law and this DPA. •Subprocessors are obliged not to commission additional or different subprocessors without observing the notification provisions toward BlackFog. •Subprocessors are contractually bound to provide sufficient guarantees that appropriate technical and organizational measures are implemented, so processing meets the requirements of the GDPR and this DPA. See the current subprocessor list → 07 Changes to this DPA BlackFog is generally entitled to amend the provisions of this DPA. We inform the customer of the planned change and the content of the new DPA at least 28 days before it becomes effective. 08 Liability Reference is made to Art. 82 of the GDPR. For the rest, the provisions on limitation of liability in the corresponding license agreement apply. 09 Annexes Annex 1: Details of processing Amazon Web Services Data Processing Addendum. Open PDF Annex 2: Technical and organizational measures Access controls and security measures documentation (April 3, 2024). Open PDF Annex 3: Subprocessor list Every provider we use as a subprocessor, maintained in the Trust Center. View list Need a countersigned copy? Our support team can provide an executed DPA for your records. Certifications, subprocessors and every agreement we publish live in the Trust Center. Request a copy GDPR Statement Company Home LOCATIONS · San Francisco · London · Belfast Home Platform Resources Headquarters BlackFog Inc. 1 Embarcadero Ctr, Suite 1200, San Francisco, CA 94111, United States United Kingdom BlackFog UK Ltd. 7 Bell Yard, London WC2A 2JR, United Kingdom Northern Ireland BlackFog UK Ltd. Custom House, Custom House Square,Belfast BT1 3ET, Northern Ireland © 2026 BlackFog. All Rights Reserved. Go to Top