Blunom Inc. Data Protection Addendum
Last updated: August 7, 2026
1. Structure, Incorporation, & Definitions
1.01. Incorporation and Precedence: This Data Protection Addendum, referred to as the "DPA," is incorporated into and forms an integral part of the commercial agreement or Order Form, collectively referred to as the "Agreement," executed between Blunom Inc. ("Blunom") and the customer ("Customer"). In the event of any conflict, the Standard Contractual Clauses shall prevail over this DPA, and this DPA shall prevail over the Agreement with respect to data protection.
1.02. Core Definitions: The terms "Controller," "Processor," "Data Subject," "Personal Data," and "Processing" carry the meanings prescribed under the European Union General Data Protection Regulation. "Applicable Data Protection Laws" means all privacy laws applicable to the processing under the Agreement, including the European Union General Data Protection Regulation, the United Kingdom General Data Protection Regulation, and the California Consumer Privacy Act. "Standard Contractual Clauses" refers to the data transfer clauses approved by the European Commission or the United Kingdom Information Commissioner's Office.
2. Roles, Scope, & AI Training Prohibition
2.01. Processor and Controller Roles: Customer is the Data Controller, or a Data Processor acting on behalf of a third-party Controller. Blunom is strictly a Data Processor acting on the documented instructions of Customer, except where Blunom processes telemetry and account, licensing, and usage data for security monitoring, service operation, and billing, wherein Blunom acts as an independent Data Controller.
2.02. Hosted Deployments: For cloud-hosted deployments, Blunom processes Customer Personal Data, including text payloads, strictly to facilitate the orchestration paths configured by Customer within the workspace.
2.03. Self-Hosted Deployments: For deployments executed within a Customer-managed Virtual Private Cloud, Blunom's processing scope is structurally limited. Blunom does not access, host, or transmit the underlying proprietary text payloads traversing the private orchestration plane, except where Customer explicitly grants time-bound support access. Blunom acts as a Data Processor exclusively concerning the encrypted transmission of automated licensing, error logs, and resource metering data required for software continuity.
2.04. Absolute Prohibition on Model Training: Blunom shall never use, process, or transmit Customer Personal Data or workspace content to train, refine, align, or optimize any artificial intelligence or machine learning model. Blunom does not control, and cannot guarantee, the data use or training practices of Customer-Configured Third-Party Services; Customer is solely responsible for reviewing and accepting the applicable policies of any model provider it selects.
3. Customer Responsibilities & Prohibited Data
3.01. Lawful Instructions: Blunom shall process Customer Personal Data only in accordance with Customer's documented lawful instructions, including the dynamic technical configurations established by Customer via the user interface.
3.02. California Privacy Rights: To the extent the California Consumer Privacy Act applies, Blunom acts as a "Service Provider." Blunom shall not sell or share Customer Personal Data. Blunom shall not retain, use, or disclose Customer Personal Data for any purpose other than for the specific business purposes specified in the Agreement, nor shall Blunom combine Customer Personal Data with personal information received from other sources, except as strictly permitted by law.
3.03. Prohibited Payloads: Customer shall not submit, route, or process special categories of personal data, protected health information, or payment card industry data through the Service unless explicitly agreed to in a separate, fully executed written addendum. Blunom offers no Business Associate Agreement by default.
3.04. Regulatory Allocation: Customer warrants it has secured all necessary legal bases to collect and transfer Customer Personal Data to Blunom. Under the European Union Artificial Intelligence Act, Customer retains all responsibilities of a "Deployer" and/or "Provider," and is solely responsible for determining whether its configured orchestration paths constitute a high-risk system.
4. Subprocessors, Integrations, & BYOM
4.01. Authorized Subprocessors: Customer authorizes Blunom to engage third-party Subprocessors. Blunom maintains a registry of authorized Subprocessors at a designated URL with an email subscription mechanism for updates. Blunom remains fully liable for the acts of its Subprocessors.
4.02. Subprocessor Objections: Blunom shall notify Customer of new Subprocessors at least thirty (30) days prior to engagement. If Customer objects on reasonable data protection grounds and the parties cannot mutually resolve the objection, Customer may terminate the affected services and receive a prorated refund of prepaid, unused fees.
4.03. Customer-Configured Third-Party Services: The Service allows Customer to independently select, credential, and integrate third-party artificial intelligence models and endpoints, collectively referred to as "Customer-Configured Third-Party Services." Blunom does not act as a Subprocessor for these integrations. Where Customer directs the platform to transmit data to services they select, Customer bears absolute responsibility for that transfer and for securing the necessary data processing agreements directly with those providers.
4.04. Marketplace Content: Where Customer installs workflows or agents published by third parties via a Blunom exchange, the publisher and Customer are solely responsible for the data processed through such content. Blunom's liability is strictly limited to infrastructure hosting.
5. Security, Audits, & Incident Response
5.01. Security Measures & Confidentiality: Blunom shall ensure its personnel are bound by strict confidentiality and shall implement appropriate technical and organizational security measures to protect Customer Personal Data against unauthorized disclosure.
5.02. Audits and Compliance: Blunom maintains a documented information security program and will make available, under a Non-Disclosure Agreement, a security overview and independent penetration testing summaries. Customer may audit Blunom not more than annually upon thirty (30) days advance written notice. Blunom may satisfy such requests by providing its aforementioned security documentation.
5.03. Incident Notification: If Blunom becomes aware of a Personal Data Breach compromising Customer Personal Data, Blunom shall notify Customer without undue delay, and in no event later than seventy-two (72) hours after becoming aware.
6. Data Subject Rights & International Transfers
6.01. Data Subject Requests: Blunom shall promptly notify Customer if it receives a request from a Data Subject to exercise their privacy rights, unless legally prohibited. Blunom shall not respond directly without Customer's authorization and shall provide reasonable functionality to assist Customer in fulfilling the request.
6.02. Cross-Border Transfers: For transfers outside the European Economic Area or the United Kingdom, the Standard Contractual Clauses are incorporated by reference. The parties select Module Two (Controller to Processor) or Module Three (Processor to Processor). Clause 7 docking applies; Clause 9(a) Option 2 applies with a thirty-day notice period; Clause 11(a) optional language is excluded; Clause 17 Option 1 dictates that the law of the Member State in which the data exporter is established governs; and Clause 18(b) stipulates the jurisdiction of the courts of that Member State. United Kingdom transfers are supplemented by the United Kingdom International Data Transfer Addendum.
7. Return and Deletion of Data
7.01. Post-Termination Deletion: Following termination of the Agreement, Blunom will delete or return Customer Personal Data within a defined period, subject to technical limitations, backup cycles, and legal-hold obligations, after which residual copies are overwritten in the ordinary course.
7.02. Archival Retention: Encrypted archival backups are retained strictly for disaster recovery, and system logs are retained for a defined operational period. Such backups and logs remain subject to the strict non-processing mandates of this DPA until overwritten.
8. General Provisions
8.01. Limitation of Liability: Any claims arising under or relating to this DPA shall be subject to the aggregate limitations of liability and exclusions of damages set forth in the Agreement, provided that this limitation shall not apply to claims brought directly by a Data Subject under the Standard Contractual Clauses.
8.02. Modifications and Acceptance: This DPA becomes legally binding upon Customer's execution of the Agreement or continued use of the Service. Blunom may update this DPA to reflect changes in law or platform architecture. Material changes will be communicated via platform dashboard notifications or the email subscription mechanism.
Annex I: Details of Processing
1. Subject Matter: Provision of the Blunom Artificial Intelligence orchestration platform and authorized support.
2. Duration: For the duration of the commercial Agreement plus authorized retention periods.
3. Nature and Purpose: To host workspace environments, execute logical Application Programming Interface routing commands, measure resource metering, and provide support. Certain features perform automated processing deriving data, such as embeddings and transcripts, using the artificial intelligence model provider the Customer configures. This is logically isolated, used solely to provide the Service, and not used by Blunom to train any model.
4. Data Subjects: Customer's employees, end-users, or individuals whose data is ingested into the platform by Customer.
5. Types of Data: Names, contact details, authentication tokens, system usage logs, organization identifiers, and unstructured text payloads.
6. Supervisory Authority: The competent supervisory authority shall be the supervisory authority of the Member State in which the Customer is established.
Annex II: Security Measures
1. Access Control: Restricted to authorized engineering personnel using Multi-Factor Authentication on a principle of least privilege.
2. Encryption Standards: Customer Personal Data is encrypted in transit using Transport Layer Security 1.2 or stronger, and at rest utilizing Advanced Encryption Standard 256-bit encryption.
3. Vulnerability Management: Regular automated vulnerability scanning and independent formal penetration testing.
4. Isolation Mechanisms: Logical isolation between tenants with encryption in transit and at rest to ensure secure partitioning.