Legal
Data Processing Addendum
Version 1.0 · Effective 2026-08-16
Scope and duration
This DPA applies when Block A Country processes personal data on behalf of a business customer to provide Website protection, hosted block telemetry, integrations, analytics, support, and related operations for the agreement term and documented retention period.
Data and people
Data may include domain/request metadata, rotating identifiers, country, normalized device/browser fields, reason, path targeting inputs, and account support information concerning Website visitors, authorized users, and customer contacts.
Documented instructions and confidentiality
Block A Country processes customer data on documented lawful instructions, including configured policies and integrations, and restricts access to people subject to confidentiality obligations.
Security and assistance
Controls include scoped accounts, encryption of provider tokens, authentication controls, minimized telemetry, controlled configuration provenance, and operational logging. We will provide reasonable assistance for data-subject requests, security incidents, impact assessments, and regulator consultation.
Subprocessors and transfers
Current subprocessors are listed publicly. Material additions require maintained notice. International transfers require an applicable mechanism such as an adequacy decision or appropriate Standard Contractual Clauses; annexes and transfer assessments require infrastructure and legal review.
Deletion, return, and audit information
On termination, customer data is deleted or returned subject to product controls, backups, legal retention, and security evidence. Reasonable compliance information will be made available; audit arrangements must protect other customers and service security.
Priority and review
This DPA supplements the Terms for Article 28 processing. It is a technical draft and requires qualified EU/Slovenian legal review, including SCC modules, annexes, subprocessors, hosting, backups, and incident commitments.