Third Party Index

Snapshot 27530

Document
Data processing addendum
URL
https://www.blackfog.com/data-processing-agreement/
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
432313 bytes
SHA-256 (raw)
c9180c2909d418784a8c0f0376ee6734adf1fbc0324fa061d08826db05873c70
SHA-256 (normalized text)
98c2a1f6a68479f0e06d3fb66db223f763ba384cd586c72e6497db8f1a714b16

Normalized text

Scripts and page chrome removed; this is what change detection compares.

NEW
BlackFog Launches ADX Vision 2.0 to Secure the Next Generation of Enterprise AI
Studio Gang Strengthens Data Security with BlackFog’s Last Line of Defense
BlackFog Receives 2026 AI in Cybersecurity Innovation Award from TMCnet
Login
Demo
Data Processing AgreementWendy McCague2026-09-22T14:47:41+01:00
DATA PROCESSING AGREEMENT
What we do with personal data when we process it for you.
This agreement forms part of the Contract for Services under the BlackFog Terms of Service. It sets out the terms on which BlackFog acts as your processor, the security measures applied, and the subprocessors involved.
LAST UPDATED: APR 14, 2024
Read the Terms of Service
Who it covers
Business customers whose personal data BlackFog processes as a processor. It does not apply to individuals using the software for purely personal or family activity.
How long it runs
The term follows the term of the Principal Agreement. Terms not defined here carry the meaning given in that agreement.
When it changes
We update this agreement periodically. Active account holders are notified by email at least 28 days before changes take effect.
on this page
General
Rights & obligations
Security measures
Data subject rights
Third-country transfers
Subprocessors
Changes to this DPA
Liability
Annexes
01
General
This Data Processing Agreement forms part of the Contract for Services under the BlackFog Terms of Service (the “Principal Agreement”). It is an amendment to the Principal Agreement and is effective on its incorporation into it, which may be specified in the Principal Agreement or in an executed amendment. Once incorporated, this agreement forms part of the Principal Agreement.
For the processing activities described in Annex 1, where BlackFog acts as the customer’s processor, the parties agree to the following provisions on the commissioned processing of personal data until further notice. This DPA does not apply where the customer is a natural person using the software or services in the course of a purely personal or family activity (Art. 2(2)(c) GDPR).
02
Rights and obligations of BlackFog
2.1 Compliance with applicable laws
BlackFog’s obligations arise from this DPA and from applicable law, which includes in particular the Federal Data Protection Act (FDPA) and the GDPR.
2.2 Processing on instructions only
BlackFog processes personal data only within the scope of this DPA and on documented instructions from the customer, mutually agreed by the parties and defined in particular by the product functionality — unless required to act otherwise by Union or member state law to which BlackFog is subject, in which case BlackFog informs the customer of that requirement before processing unless the law prohibits it on important grounds of public interest. The customer may give additional written instructions where needed to comply with data protection law, and keeps the documentation of issued instructions for the term of the DPA.
2.3 Obligation of confidentiality
BlackFog ensures that persons authorized to process the personal data have committed themselves to confidentiality, unless they are already subject to an appropriate legal obligation of secrecy.
2.7 Records of processing activities
BlackFog provides the customer with the information necessary to maintain their records of processing activities.
2.8 Deletion and return at the end of processing
At the customer’s choice, BlackFog deletes or returns the personal data processed on their behalf, to the extent that EU or member state law to which BlackFog is subject does not require the data to be stored.
2.9 – 2.11 Demonstrating compliance and notifying problems
•BlackFog provides all information necessary to demonstrate compliance with the obligations in sections 2 and 3 of this DPA.
•If BlackFog considers that carrying out an instruction could breach applicable data protection law, it informs the customer immediately and may suspend that instruction until the customer confirms or changes it in writing.
•If BlackFog detects any violation of applicable data protection law, this DPA, or the customer’s instructions on commissioned processing, it informs the customer immediately.
2.12 Data protection officer
BlackFog has appointed a data protection officer, reachable by email at our privacy address or in writing at BlackFog, Inc., for the attention of the Data Protection Officer, 1712 Pioneer Av., Cheyenne, WY 82001, USA.
03
Security measures under Art. 32 GDPR
BlackFog takes the measures necessary for the security of processing under Article 32 GDPR. For each commissioned processing activity, a level of security appropriate to the risk to the rights and freedoms of the affected individuals is guaranteed. The protection objectives of Art. 32(1) GDPR: confidentiality, integrity and availability of systems and services, and their resilience given the nature, scope and context of the processing, are taken into account so that risks are permanently mitigated by appropriate measures.
The measures adopted are described in detail in the documentation attached as Annex 2, which also describes the procedures for regular review, assessment and evaluation of their effectiveness. Security measures are subject to technical progress: BlackFog may implement alternative appropriate measures, provided the level of security never falls below the level already in place.
04
Assisting with data subject rights and Art. 32 to 36
Taking into account the nature of the processing, BlackFog assists the customer as far as possible with appropriate technical and organizational measures in fulfilling requests from data subjects exercising their rights under Chapter III of the GDPR. If a data subject contacts BlackFog directly about data processed on the customer’s behalf, and the customer is identifiable, BlackFog forwards the request to the customer immediately.
BlackFog likewise supports the customer in meeting the obligations in Articles 32 to 36 GDPR: security of processing, notification of a personal data breach, data protection impact assessments and consultation with supervisory authorities. For the effort arising from such assistance, the customer remunerates BlackFog at an hourly rate of 100 Euros, if and as far as applicable data protection law permits.
05
Data transfers to a third country
BlackFog generally transfers personal data processed under this DPA to a country outside the EU or EEA for which no EU Commission adequacy decision exists (an “unsafe third country”) only where:
•the customer or the customer’s user instructs BlackFog to do so, for example by requesting a connection to an endpoint located in such a country, in which case the customer is responsible for ensuring the transfer complies with Art. 44 et seq. GDPR; or
•BlackFog is obliged to do so under EU or member state law to which it is subject, in which case BlackFog informs the customer of those legal requirements before processing, unless the law prohibits it on important grounds of public interest.
BlackFog may also use subprocessors in a third country to process personal data, insofar as the requirements of Art. 44 GDPR are met.
06
Subprocessors
BlackFog uses a number of other processors. The current list for each BlackFog product is published in the Trust Center and referenced as Annex 3. By concluding this DPA, the customer agrees to the engagement of the subprocessors listed in Annex 3 at the time of conclusion for the relevant product.
•Further or replacement subprocessors are selected with the required care and due diligence, and Annex 3 is updated on each appointment.
•Subprocessors in third countries may only be engaged where the requirements of Art. 44 et seq. GDPR are fulfilled.
•Contracts with subprocessors are structured to comply with applicable data protection law and this DPA.
•Subprocessors are obliged not to commission additional or different subprocessors without observing the notification provisions toward BlackFog.
•Subprocessors are contractually bound to provide sufficient guarantees that appropriate technical and organizational measures are implemented, so processing meets the requirements of the GDPR and this DPA.
See the current subprocessor list →
07
Changes to this DPA
BlackFog is generally entitled to amend the provisions of this DPA. We inform the customer of the planned change and the content of the new DPA at least 28 days before it becomes effective.
08
Liability
Reference is made to Art. 82 of the GDPR. For the rest, the provisions on limitation of liability in the corresponding license agreement apply.
09
Annexes
Annex 1: Details of processing
Amazon Web Services Data Processing Addendum.
Open PDF
Annex 2: Technical and organizational measures
Access controls and security measures documentation (April 3, 2024).
Open PDF
Annex 3: Subprocessor list
Every provider we use as a subprocessor, maintained in the Trust Center.
View list
Need a countersigned copy?
Our support team can provide an executed DPA for your records. Certifications, subprocessors and every agreement we publish live in the Trust Center.
Request a copy
GDPR Statement
Company
Home
LOCATIONS · San Francisco · London · Belfast
Home
Platform
Resources
Headquarters
BlackFog Inc.
1 Embarcadero Ctr, Suite 1200, San Francisco, CA 94111, United States
United Kingdom
BlackFog UK Ltd.
7 Bell Yard, London WC2A 2JR, United Kingdom
Northern Ireland
BlackFog UK Ltd.
Custom House, Custom House Square,Belfast BT1 3ET, Northern Ireland
© 2026 BlackFog. All Rights Reserved.
Go to Top