Data Processing Agreement
DATA PROCESSING ADDENDUM — MODEL TERMS
This model Data Processing Addendum (“DPA”) is available for incorporation into a signed services agreement, order, or other written agreement between the customer (“Customer”) and the Blaze entity identified there (“Blaze”). Visiting this page does not execute it. Before processing begins, the parties must identify the contracting entities and complete the engagement record in section 12, including any applicable transfer instrument and security or retention variation. “Agreement” means the agreement incorporating this DPA. This DPA applies only when and to the extent Blaze processes personal data on Customer’s behalf in providing the contracted services. It prevails over inconsistent general terms concerning that processing; mandatory law and an applicable transfer instrument prevail within their scope.
1. ROLES, DEFINITIONS AND SCOPE
Customer acts as controller (or a processor acting for another controller) and Blaze acts as processor or subprocessor for Customer Data. “Customer Data” means personal data made available to Blaze by or for Customer for the services, including data accessed during authorized testing and personal data in findings, evidence, and reports. “Data Protection Laws” means the GDPR and UK GDPR where applicable, Brazil’s LGPD and ANPD regulations where applicable, the California Consumer Privacy Act as amended and its implementing regulations (“CCPA”) where applicable, and other privacy laws applicable to the relevant processing. Terms such as controller, processor, operator, personal data, data subject, consumer, sale, and sharing have their meanings under the applicable law. Each party is independently responsible for its own compliance. Blaze is a separate controller for its own account administration, billing, legal compliance, and business contact data as explained in its privacy policy; this DPA does not govern that separate processing.
The subject matter is the agreed security assessment and related service delivery. Processing lasts for the service period and the deletion or return period stated in the engagement record, subject only to legally required retention. Its nature and purposes are authorized access, inspection and testing of scoped systems; limited collection and analysis of evidence needed to validate findings; preparation and secure delivery of reports; remediation discussion and retesting; and administration of the engagement. Data subjects may include Customer personnel, users, customers, suppliers and other individuals whose data is present in scoped systems. Data may include identifiers, contact details, account and authentication data, technical logs and communications, and other data present in those systems, potentially including special-category or sensitive data where unavoidable. Customer must identify prohibited or unusually regulated datasets, geographic restrictions and special handling instructions before access. The scope and rules of engagement refine this description; a materially different purpose, data category or processing operation requires a documented change before it begins.
2. INSTRUCTIONS AND CONFIDENTIALITY
Blaze will process Customer Data only on documented instructions in the Agreement, this DPA, the scope and rules of engagement, and Customer’s subsequent written instructions, unless law requires otherwise. Where legally permitted, Blaze will tell Customer before legally compelled processing. Blaze will promptly tell Customer if an instruction appears to infringe applicable Data Protection Laws and may suspend that instruction while the parties resolve it. Customer is responsible for lawful collection, notices, permissions, and authority to instruct the testing, including third-party systems. Blaze will limit access to personnel and contractors who need it for the services and are bound by confidentiality obligations.
3. SECURITY AND ASSESSMENT DATA
Blaze will implement technical and organizational measures appropriate to the nature and risk of the processing, including role-based access and least privilege; strong authentication; appropriate encryption in transit and at rest; protected transfer and storage of evidence; logging and access review; vulnerability and patch management; confidentiality and training; backup and recovery; incident response; and periodic assessment of the effectiveness of those measures. The parties will record any heightened measures, prohibited locations or approved evidence channels in the engagement record. Measures may evolve without materially reducing the overall level of protection. Customer should provide test accounts and masked or synthetic data where feasible and use approved channels for secrets and personal data. Blaze will minimize collected evidence, avoid full datasets when a smaller sample proves a finding, and restrict reports and evidence to authorized recipients.
4. SUBPROCESSORS
Customer gives general written authorization for the subprocessors identified in the engagement record or current list supplied before the affected processing starts. Blaze will identify each relevant subprocessor, its function and processing location, and will notify Customer in advance through the agreed channel of a proposed addition or replacement, allowing the objection period specified in the engagement record (or, if none is specified, a reasonable period before use). Customer may object on documented data protection grounds. The parties will seek a practicable alternative; if none is available, Customer may terminate the affected unperformed service without penalty. Blaze will bind each subprocessor in writing to data protection obligations offering at least the same level of protection for Customer Data, including any applicable CCPA obligations and onward-transfer safeguards, and remains liable to Customer for its performance. A proposed subprocessor does not gain access before the required authorization and transfer mechanism are in place.
5. ASSISTANCE, REQUESTS AND AUDIT
Taking account of the nature of processing and information available, Blaze will assist Customer with data subject and consumer requests, security and breach obligations, data protection impact and risk assessments, prior consultations, and relevant regulatory inquiries. Blaze will forward a request about Customer Data without undue delay unless prohibited and will not answer for Customer without authorization except as law requires. Customer decides and communicates its response. Blaze will supply information needed to demonstrate compliance with the processor obligations and permit and contribute to audits or inspections by Customer or its appointed auditor, subject to reasonable notice, confidentiality, security and non-disruption arrangements. Appropriate recent independent evidence may address a request but does not remove a statutory audit right. Where the CCPA applies, Blaze will also provide relevant information in its possession, custody or control for a required cybersecurity audit, risk assessment or applicable automated-decisionmaking obligation. The parties will agree reasonable costs for extraordinary assistance not caused by Blaze’s breach, without limiting mandatory assistance.
6. PERSONAL DATA BREACH
Blaze will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, using the incident contact in the engagement record (or, if absent, Customer’s established Blaze contact). The initial notice will provide the facts then available; Blaze will follow with information about the nature, likely consequences, affected data and individuals, and containment and remediation measures as it becomes available. Blaze will investigate, contain and remediate matters within its control and reasonably assist Customer with its assessment and notifications. Customer decides whether and when to notify a regulator or individual unless law imposes a direct duty on Blaze. The parties may agree a shorter operational notice target in the engagement record. This contractual notice duty does not replace a regulator deadline applicable to Customer.
7. TRANSFERS
International transfers require the lawful mechanism applicable to the origin, destination, roles and onward transfers. For EU/EEA data, the parties will use the appropriate EU transfer Standard Contractual Clauses and module where required, with completed annexes, a transfer assessment and supplementary measures when necessary. For UK data, they will use the applicable UK Addendum or International Data Transfer Agreement where required. For Brazilian data, they will assess LGPD Article 33 and ANPD Resolution CD/ANPD No. 19/2024 as amended; when relying on ANPD standard contractual clauses, the exporter and importer must incorporate the approved text in full and without alteration, with the required transfer details and transparency information. A valid alternative mechanism may be used where its requirements are met. This DPA alone is not any of those transfer instruments. Customer may request applicable documents and relevant locations before transfer. Blaze will not make a restricted transfer or onward transfer until the necessary mechanism and safeguards are in place.
8. RETURN, DELETION AND RETENTION
At the end of the affected services, Blaze will, at Customer’s choice, return or securely delete Customer Data and delete existing copies within the period recorded for the engagement, unless applicable law requires storage. If Customer gives no choice after reasonable notice, the agreed default in the engagement record applies; absent one, Blaze will seek instructions and keep the data protected pending resolution. Legally retained data remains protected, limited to the required purpose and deleted when the obligation ends. Backup copies that cannot immediately be erased will be put beyond ordinary use, protected, and deleted on the next applicable cycle; they will not be restored for another purpose. Blaze will confirm completion on reasonable request. Report, evidence and backup periods must be stated in the engagement record rather than left to an undisclosed schedule.
9. CALIFORNIA SERVICE PROVIDER TERMS
Where the CCPA applies and Blaze receives California personal information as Customer’s service provider or contractor, Customer discloses it only for these specific business purposes: authorized security testing of the systems and assets named in the engagement scope; collecting and analyzing the minimum evidence needed to validate and explain findings; preparing and securely delivering findings, reports and remediation advice to Customer; performing agreed retesting; and securing, administering and documenting those activities. A different purpose must be specifically documented in the signed engagement record before that processing begins. Blaze will comply with applicable CCPA provisions and provide the same level of privacy protection required of a business for this information. Blaze will not sell or share it, use or disclose it outside those specified purposes or the direct business relationship except as the CCPA permits, combine it with information from another source except as the CCPA permits, or use it for cross-context behavioral advertising. Blaze will notify Customer if it determines it can no longer comply. Customer may take reasonable and appropriate steps to verify compliant use and, on notice, stop and remediate unauthorized use. Customer will inform Blaze of consumer requests it must fulfill and provide information needed to do so, or Blaze will otherwise enable Customer to comply; Blaze will cooperate with applicable security audits, risk assessments and automated-decisionmaking duties. Blaze will impose the required CCPA contract terms on relevant subcontractors. These terms apply only to covered California processing and do not alter other legal roles.
10. BRAZILIAN PROCESSING
Where the LGPD applies, Customer as controlador determines purposes, legal bases, transparency, retention instructions and responses to titulares; Blaze as operador acts on lawful documented instructions, implements appropriate technical and administrative security, helps with rights and incident assessment, and provides information reasonably needed for Customer’s records and compliance. The parties will identify their operational privacy and incident contacts and any appointed encarregado in the engagement record. Blaze will report a relevant security incident to Customer without undue delay and provide available information so Customer can assess risk or relevant harm and meet any duty to notify the ANPD and titulares. Under ANPD Resolution CD/ANPD No. 15/2024, the controller’s notification period for a reportable incident is generally three business days from awareness, subject to any specific-law rule and applicable exceptions; Blaze’s duty is to alert and assist promptly, not to substitute for Customer’s notification decision. International transfers must satisfy the LGPD and current ANPD rules as described above. Nothing here assigns Customer’s non-delegable controller decisions to Blaze.
11. GENERAL
If Customer is itself a processor, it confirms that the controller has authorized its instructions and use of Blaze as subprocessor; Customer will pass through information and requests needed to perform this DPA. If an applicable law requires a more protective mandatory term, that term governs the relevant processing. Neither party is required to disclose another customer’s confidential information or compromise security in an audit. Liability, governing law, and dispute terms follow the Agreement except to the extent mandatory law or an incorporated transfer instrument requires otherwise. No change to a required transfer clause is implied by this DPA.
12. ENGAGEMENT RECORD
The signed Agreement, order, statement of work or attached schedule must identify: (a) the legal entities and their controller/processor or processor/subprocessor roles; (b) the services, systems and specific processing purposes, duration, data subject groups and data categories, with any special or regulated data; (c) documented instructions, approved evidence and report recipients, security variations and prohibited locations; (d) initial subprocessors, functions, locations, the change-notice channel and objection period; (e) processing and transfer locations, applicable transfer instrument and completed annexes; (f) incident and privacy contacts; and (g) return or deletion choice, report and evidence retention, and backup deletion cycle. The examples in this public model are defaults for ordinary security assessments and do not replace a material engagement-specific detail. If a required detail or transfer instrument has not been settled, the parties must settle it in writing before the affected processing or transfer begins.
13. REQUESTS AND CONTACT
For an executed DPA, current subprocessor and transfer information, the security measures or a data protection request, use Blaze’s contact page at /contact-us and identify your organization and the relevant service, system or report. No order number is required. Data subjects can use the privacy contact described at /legal/privacy-policy; where Blaze processes on behalf of a customer, Blaze may direct the request to that customer after reasonable identity and scope checks. The Blaze Trust Center at https://trust.blazeinfosec.com/ provides available assurance materials and may host current summaries of security measures, retention practices and subprocessors. If a document is not public or not yet posted, request it through the contact page. Trust Center content supplements this DPA; a posting does not by itself amend an agreed retention period, authorize a new subprocessor or replace required advance notice or a transfer instrument.