---
title: "Data Processing Addendum"
effective: 2026-09-05
version: "1.0"
source: "https://getbloggable.com/legal/dpa"
---

# Data Processing Addendum

Effective 5 September 2026 · Version 1.0

> **In plain English.** Where your blog's readers, or people mentioned in your content, are concerned, you are the data controller and we process data for you. This document is the contract UK data protection law requires for that: we only act on your instructions, keep the data secure, tell you if something goes wrong, help you with your obligations, use only the sub-processors listed and delete the data when you leave. It applies automatically; no signature is needed.

## 1. Background and application

1.1 This Data Processing Addendum (**"DPA"**) forms part of the [Terms of Service](/legal/terms) (the **"Terms"**) between **Referr Ltd**, trading as **Bloggable** (**"Processor"**, **"we"**, **"us"**), and the customer that holds the Account (**"Controller"**, **"you"**).

1.2 This DPA applies to the extent we process **Customer Personal Data** (defined below) on your behalf in providing the Services. It does not apply to personal data of which we are the controller, such as your own account, billing and usage data, which is governed by our [Privacy Policy](/legal/privacy).

1.3 This DPA is incorporated by reference and takes effect on the date you accept the Terms. A countersigned copy is available on request from hello@support.getbloggable.com.

## 2. Definitions

2.1 **"Data Protection Law"** means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003, each as amended, and, where applicable to the Controller, the EU GDPR.

2.2 **"Customer Personal Data"** means personal data that we process on your behalf in providing the Services, as described in Annex 1, including personal data contained in Customer Content and data about readers of your blogs.

2.3 **"Sub-processor"** means a third party engaged by us to process Customer Personal Data.

2.4 **"controller"**, **"processor"**, **"data subject"**, **"personal data"**, **"personal data breach"** and **"processing"** have the meanings given in Data Protection Law. Other capitalised terms have the meanings given in the Terms.

## 3. Roles and instructions

3.1 You are the controller (or, where you act for a client, a processor authorised by the controller) of Customer Personal Data, and we are your processor.

3.2 We will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless we are required to do so by law, in which case we will inform you of that requirement before processing unless the law prohibits it on important grounds of public interest.

3.3 Your instructions are: (a) the Terms and this DPA; (b) your use of the Services and their settings, including publishing content, enabling Autopilot, connecting integrations and running AI features; and (c) any further reasonable written instruction consistent with the Terms. We will tell you if, in our opinion, an instruction infringes Data Protection Law, without any obligation to review your instructions for compliance.

3.4 You are responsible for: the lawfulness of Customer Personal Data and of your instructions; providing any notice and obtaining any consent required from data subjects, including readers of your blogs; responding to data subjects' requests; and ensuring that you are entitled to appoint us as processor, including where you act for a client.

## 4. Our obligations

4.1 **Confidentiality.** We will ensure that persons authorised to process Customer Personal Data are bound by obligations of confidentiality and receive appropriate training.

4.2 **Security.** We will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Our current measures are summarised in Annex 2 and described in more detail on our [Trust Centre](/trust). We may update them provided the overall level of security is not reduced.

4.3 **Sub-processors.** You give general authorisation for us to engage the Sub-processors listed in Annex 3. We will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance. We will give you at least **30 days' notice** of any intended addition or replacement of a Sub-processor by publishing it on the [Trust Centre](/trust) and, for material changes, by email to the Account owner. You may object on reasonable data protection grounds within that period; if we cannot address your objection, you may terminate the affected part of the Services under the Terms, and we will refund any prepaid fees for the unused period.

4.4 **Data subject rights.** Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, so far as possible, in responding to requests from data subjects to exercise their rights. If a data subject contacts us directly about Customer Personal Data we will, where we can identify you, pass the request to you without responding on your behalf unless you instruct us to.

4.5 **Assistance.** We will assist you, taking into account the nature of the processing and the information available to us, in meeting your obligations regarding security, personal data breach notification, data protection impact assessments and prior consultation with the ICO.

4.6 **Deletion and return.** On closure or termination of your Account, we will delete Customer Personal Data in accordance with clause 19.5 of the Terms: content remains available for export for 30 days, after which it is deleted from live systems, with backup copies expiring on their normal rotation, unless the law requires us to retain it. During the term you can export published content in Markdown from its URL and export content from the app.

4.7 **Information and audit.** We will make available to you the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, on the following basis: (a) you first request our written responses and any third-party reports we hold, which will satisfy the audit right unless a supervisory authority requires more or you have reasonable grounds to suspect non-compliance; (b) any on-site audit is limited to once in any 12-month period, on at least 30 days' written notice, during business hours, subject to reasonable confidentiality and security requirements, and at your cost; and (c) audits do not extend to the systems of our Sub-processors, in respect of which we will provide the information they make available to us.

## 5. Personal data breach

5.1 We will notify you **without undue delay, and in any event within 72 hours, after becoming aware** of a personal data breach affecting Customer Personal Data. The notice will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. We may provide the information in phases as it becomes available.

5.2 We will cooperate with you and take reasonable steps to contain, investigate and remediate the breach. We will not notify data subjects or authorities on your behalf unless you instruct us to or the law requires it.

## 6. International transfers

6.1 We may process Customer Personal Data outside the United Kingdom through the Sub-processors listed in Annex 3. Where we do so, we ensure that the transfer is covered by: adequacy regulations under the UK GDPR; the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses issued by the ICO; the recipient's certification under the UK Extension to the EU–US Data Privacy Framework; or another valid transfer mechanism. Copies of the relevant safeguards are available on request.

## 7. Liability

7.1 Each party's liability under this DPA is subject to the exclusions and limitations in the Terms, which apply to this DPA as if set out in full. Nothing in this DPA limits either party's liability to a data subject or supervisory authority under Data Protection Law.

## 8. Term and precedence

8.1 This DPA lasts for as long as we process Customer Personal Data. Clause 4.6 survives termination.

8.2 In the event of conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails.

8.3 This DPA is governed by the law of England and Wales in accordance with clause 21.10 of the Terms.

## Annex 1 — Details of processing

**Subject matter.** Provision of the Services described in the Terms: hosting and publishing blogs, generating and editing content with AI, monitoring performance, repurposing content, and integrating with services you connect.

**Duration.** For as long as you hold an Account, plus the deletion period in clause 4.6.

**Nature and purpose.** Storage, hosting, retrieval, transmission, display, analysis, transformation and, on your instruction, publication of Customer Content; collection of aggregate reader statistics; transmission of content to AI providers to generate results; transmission of content to third-party destinations you connect; and deletion.

**Categories of data subjects.**

- Readers and visitors of your blogs.
- Individuals whose personal data appears in your content: authors, contributors, interviewees, people quoted or referred to, and personas where they correspond to real people.
- Your clients and their staff, where you operate blogs for clients.
- Individuals whose data appears in websites you add as content sources or competitors, to the extent captured in analyses.

**Categories of personal data.**

- For readers: IP address, browser identifier and requested page in transient server logs; a daily-rotating, irreversible hash used for unique-reader counts.
- In content: names, images, roles, biographical details, opinions, contact details and any other personal data you choose to include.
- In integration data: names and addresses of authors and sites on the destinations you connect.

**Special category data.** None intended. You must not include special category data or criminal-offence data in content submitted to AI features, and should avoid publishing it.

## Annex 2 — Technical and organisational measures

A summary of the measures in place at the effective date. The [Trust Centre](/trust) carries the current detail.

- **Encryption in transit** using TLS for all connections, with HTTP Strict Transport Security preloaded on our domains.
- **Encryption at rest** for the database and file storage, managed by our infrastructure providers, plus application-level encryption of integration credentials.
- **Access control**: authentication by Google OAuth or emailed sign-in links (no passwords stored); role-based permissions enforced server-side on every request; every database query scoped to the Account; staff access to the administration console restricted to named personnel and re-verified on each request.
- **Tenant isolation** of content, settings, AI memory and integration credentials by Account and by blog.
- **Application security**: server-side sanitisation of customer-authored content; browser security headers; restricted outbound fetching; rate limiting on public and sensitive endpoints; signed tokens on links in email; authenticated scheduled jobs.
- **AI safeguards**: web content treated as untrusted data in prompts; personal data redacted from stored assistant memory; server-side verification of confirmations for destructive actions; no use of Customer Personal Data to train models.
- **Payment data** never touches our systems; Stripe, a PCI DSS Level 1 service provider, handles it.
- **Logging and audit**: append-only credit ledger, job logs and administrative action records.
- **Availability**: managed, replicated database with automated backups; globally distributed serverless hosting; caching of public content.
- **Personnel**: confidentiality obligations and least-privilege access for anyone with access to production systems.
- **Incident response**: documented process for containment, investigation, notification under clause 5, and post-incident review.

## Annex 3 — Sub-processors

Authorised Sub-processors at the effective date. The live list, with the date each was added, is at [/trust](/trust#sub-processors).

| Sub-processor | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| **Vercel** (Vercel Inc.) | Application hosting and serverless compute, global edge network, file storage for uploaded media (Vercel Blob), cookieless web analytics, and the AI Gateway that routes our model requests. | All service data in transit and at rest on the platform; uploaded media; request logs (IP address, user agent). | Ireland (Dublin region); cached public content served from a global edge network | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States |
| **MongoDB Atlas** (MongoDB, Inc.) | Managed primary database. | All account, content, billing-metadata, support and usage records. | Ireland (Dublin region) | UK adequacy regulations (EEA); UK Extension to the EU–US Data Privacy Framework or the UK Addendum to the EU SCCs for any access from the United States |
| **Anthropic** (Anthropic, PBC) | Large language model inference (Claude) for research synthesis, drafting, editing, scoring, repurposing and the Joe assistant. Accessed through the Vercel AI Gateway. | Prompts and content submitted for generation — post text, voice samples, brief and topic details, Joe conversations (with personal data redacted from stored memory). Not used to train models. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| **Tavily** (Tavily, Inc.) | Web research search API used by the research and competitor pipelines. | Search queries derived from the topic, keywords and competitor URLs a customer supplies. No account identifiers. | United States | UK Addendum to the EU SCCs / IDTA |
| **Stripe** (Stripe Payments UK Ltd and Stripe, Inc.) | Payments, subscription billing, invoicing, the customer billing portal and payment fraud prevention. | Name, email address, billing address, payment card details (entered directly with Stripe and never seen by Bloggable), transaction history. | United Kingdom, European Union and United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| **Resend** (Resend, Inc.) | Delivery of transactional, notification and product-update email; receipt of inbound support email. | Name, email address, message subject and content, delivery events (sent, bounced). | United States | UK Addendum to the EU SCCs / IDTA |
| **Google** (Google LLC) | Sign in with Google (OAuth); and, only for customers who connect it, the Google Search Console API for search performance data. | Google account email, name and profile image at sign-in; Search Console performance data for the sites a customer authorises. | United States | UK Extension to the EU–US Data Privacy Framework, or the UK Addendum to the EU SCCs |
| **Unsplash** (Unsplash, Inc.) | Stock photography search and download for featured images. | Image search terms only. No account identifiers or personal data. | Canada | UK adequacy regulations (Canada) |

## Contact

- **Processor:** Referr Ltd, trading as Bloggable
- **Address:** 2nd Floor College House, 17 King Edwards Road, Ruislip, London, HA4 7AE, United Kingdom
- **Data protection enquiries:** hello@support.getbloggable.com
