Between: Blade Agent AI ("Processor") and the Customer identified in the applicable Order Form/Signup ("Controller")
Effective as of: the date Customer accepts the Terms of Service
1. Purpose
This DPA governs the processing of personal data that Controller submits to, or that Processor collects on Controller's behalf via, the Blade Agent AI Service (defined in the Terms of Service), specifically: data of individuals who submit inquiries through Controller's own website lead forms ("End Lead Data").
2. Roles
- Controller (Customer) determines the purposes and means of collecting End Lead Data, meaning operating their own website and deciding what data to collect from prospective clients.
- Processor (Blade Agent AI) processes End Lead Data solely on Controller's documented instructions, as described in the Terms of Service and this DPA, to provide the Service.
3. Scope and Nature of Processing
| Subject matter | Real time classification, alerting, and (Growth plan) enrichment of website lead form submissions |
| Duration | For the term of the subscription and any limited diagnostic retention period described in the Privacy Policy |
| Nature/purpose | Intent and budget classification (AI), instant alert delivery, CRM sync, email drafting |
| Categories of data subjects | Individuals submitting inquiries via Controller's website (prospective buyers/sellers) |
| Categories of personal data | Name, email, phone number, free text inquiry message, AI inferred intent/budget tier, and (Growth) enriched company/professional data where a business email is provided |
4. Processor Obligations
Processor shall:
- Process End Lead Data only on Controller's documented instructions (as set out in the Terms of Service), unless required otherwise by law.
- Ensure personnel authorized to process End Lead Data are bound by confidentiality obligations.
- Implement appropriate technical and organizational security measures, including encryption in transit (TLS), encrypted storage for integration credentials, production workflow settings that minimize retention of successful execution payloads, and restricted administrative access limited to personnel who need it to configure or support the Service.
- Not engage a new sub-processor without giving Controller reasonable prior notice and an opportunity to object (see Section 5).
- Assist Controller, within 10 business days of a request, in responding to data subject requests (access, deletion, correction) that End Leads may direct to Controller.
- Notify Controller without undue delay, and in any event within 72 hours of becoming aware, after a personal data breach affecting End Lead Data, providing available details to help Controller meet its own notification obligations.
- At Controller's request, delete or return any End Lead Data still retained by Processor upon termination of the Service, except as required by law. Data already delivered to Controller's Slack, email, or CRM environment remains under Controller's control.
- Make available to Controller information reasonably necessary to demonstrate compliance with this DPA.
5. Sub-Processors
Controller provides general authorization for Processor to engage the sub-processors listed in the Privacy Policy, currently including:
- Anthropic (AI classification/drafting)
- n8n (workflow automation)
- Slack and our email delivery provider (e.g., Resend)
- Our enrichment data provider (Growth plan)
- Controller's own Follow Up Boss, HubSpot, or Salesforce account (Growth plan)
Processor will notify Controller of any new sub-processor with a minimum of 15 days' notice, during which Controller may object on reasonable data protection grounds.
6. International Transfers
Not currently applicable. Processor does not currently process End Lead Data of individuals located in the EU or UK, and this Service is offered only in the United States and Canada as of the Effective Date. Should Controller's End Leads come to include EU/UK individuals, this section will be completed with appropriate transfer mechanisms (for example, Standard Contractual Clauses) before such processing begins, reviewed with counsel.
7. Controller Obligations
Controller warrants that:
- It has a lawful basis to collect End Lead Data via its own website and to instruct Processor to process it as described.
- Its own privacy notice (on its website) adequately discloses this processing to End Leads.
- It will not instruct Processor to process special categories of data (health, precise financial account data, government IDs, and similar) without prior written agreement.
8. Liability
Liability under this DPA is subject to the limitation of liability set out in the Terms of Service, except where applicable law prohibits limiting liability for data protection violations.
9. Term and Termination
This DPA remains in effect for as long as Processor processes End Lead Data on Controller's behalf, and terminates automatically upon termination of the underlying Service subscription, subject to Section 4(g).
10. Audit Rights
Controller may request reasonable evidence of Processor's compliance with this DPA (for example, a summary of security practices) no more than once per year, or following a security incident, with reasonable advance notice.