Legal
Data Processing Addendum
Version 1.0 · Effective 5 October 2026 · Last updated 5 October 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Getreach Limited ("Blizo", "Processor") and the Customer. It applies automatically when the Customer accepts the Terms; no separate signature is required. Customers who need a countersigned copy can request one at support@blizo.com.
1. Scope and incorporation
This DPA applies to personal data that Blizo processes on behalf of the Customer when providing the Service ("Customer Personal Data"). It reflects the requirements of Article 28 GDPR and Article 28 UK GDPR. It does not apply to data that Blizo processes as an independent controller, such as account, billing and website data, which is described in the Privacy Policy.
2. Definitions
"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as retained in the law of the United Kingdom, together with the Data Protection Act 2018. "Data Protection Laws" means the GDPR, the UK GDPR and any other data protection laws applicable to the processing, including U.S. state privacy laws. Terms such as "controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in the GDPR. "Subprocessor" means a processor engaged by Blizo to process Customer Personal Data.
3. Roles of the parties
The Customer is the controller (or a processor acting on behalf of its own clients) and Blizo is the processor (or subprocessor) of Customer Personal Data. The Customer is responsible for the lawfulness of the processing, including having a legal basis and providing required information to data subjects. The Customer will not submit special categories of personal data or data of children to the Service.
4. Processing on instructions
Blizo processes Customer Personal Data only on documented instructions of the Customer. The Terms, this DPA, the Customer's configuration of the Service and its use of Service features are the Customer's complete instructions. Blizo will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws, and is not obliged to follow such an instruction. Blizo may process Customer Personal Data where required by EU or Member State law, in which case it will inform the Customer unless the law prohibits this.
5. Confidentiality of personnel
Blizo ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive only the access they need.
6. Security
Blizo implements and maintains the technical and organizational measures described in Annex 2, appropriate to the risk in accordance with Article 32 GDPR. Blizo may update these measures as long as the overall level of protection is not reduced.
7. Subprocessors
- The Customer gives Blizo general authorization to engage subprocessors. The subprocessors listed in Annex 3 and on our subprocessor page are approved.
- Blizo will inform the Customer of any intended addition or replacement of a subprocessor at least 30 days in advance by updating the subprocessor page and notifying workspace owners by email or in the app. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service with effect before the change, and will receive a refund of prepaid fees for the unused period.
- Blizo imposes data protection obligations on each subprocessor that are substantially equivalent to those in this DPA and remains responsible for its subprocessors' performance.
8. Data subject requests and assistance
Taking into account the nature of the processing, Blizo assists the Customer with appropriate technical and organizational measures in responding to data subject requests, and with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation). If Blizo receives a request directly from a data subject regarding Customer Personal Data, it will refer the data subject to the Customer and will not respond itself unless required by law.
9. Personal data breaches
Blizo notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification includes the information required by Article 33(3) GDPR as far as available, which may be provided in phases. Blizo takes reasonable steps to contain and remedy the breach. A notification is not an acknowledgment of fault.
10. International transfers
- Blizo hosts the Service in the European Union. Blizo transfers Customer Personal Data to a third country only in compliance with Chapter V GDPR and the UK GDPR, in particular on the basis of an adequacy decision (including the EU-U.S. Data Privacy Framework and its UK Extension) or the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs") with the UK International Data Transfer Addendum.
- Where the Customer is located outside the EEA and Blizo, as an EU processor, returns Customer Personal Data to the Customer, Module Four of the SCCs (processor to controller) is incorporated by reference to the extent required. Where the Customer is in the EEA and Blizo engages a subprocessor in a third country, Blizo concludes Module Three (processor to processor) with that subprocessor.
- For the SCCs: the docking clause (Clause 7) applies; under Clause 9, option 2 (general written authorization, 30 days' notice) applies; the optional language in Clause 11(a) does not apply; under Clauses 17 and 18, the laws and courts of the Republic of Cyprus apply. For the UK Addendum, the tables are completed with the information in this DPA and its Annexes.
11. Information and audits
Blizo makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR. The Customer may audit Blizo's compliance once per year, or after a personal data breach, with at least 30 days' written notice, during normal business hours, without disrupting operations and subject to confidentiality. Blizo may satisfy an audit request by providing current documentation, certifications or reports of its subprocessors. Each party bears its own costs.
12. Return and deletion
After the end of the Service, the Customer can export Customer Personal Data during the 90-day read-only period described in the Terms. Afterwards Blizo deletes Customer Personal Data, unless EU or Member State law requires storage. Residual copies in backups are deleted in the regular backup cycle and protected in the meantime.
13. U.S. state privacy laws
To the extent U.S. state privacy laws (including the California Consumer Privacy Act) apply, Blizo acts as a service provider or processor and will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than providing the Service or as otherwise permitted by those laws; retain, use or disclose it outside the direct business relationship with the Customer; or combine it with personal data from other sources, except as permitted by law. Blizo will notify the Customer if it can no longer meet these obligations.
14. Liability and precedence
The limitations of liability in the Terms apply to this DPA, to the extent permitted by Data Protection Laws. In case of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Terms with respect to the processing of Customer Personal Data. This DPA remains in force as long as Blizo processes Customer Personal Data. It is governed by the laws of the Republic of Cyprus, except where the SCCs require otherwise.
15. Annex 1: Details of processing
- Controller
- The Customer, as identified in its Blizo account.
- Processor
- Getreach Limited, Dimotikis Agoras 20, 6021 Larnaca, Cyprus. Contact: support@blizo.com
- Subject matter
- Provision of the Blizo AI visibility measurement service.
- Duration
- Term of the contract plus the 90-day read-only and deletion period.
- Nature and purpose
- Hosting, storage, collection of AI answers and search results for configured prompts, reading public web pages, analysis, reporting, export and support.
- Data subjects
- The Customer's authorized users; the Customer's clients and business contacts whose details the Customer enters; individuals named in prompts, notes, public web pages or AI answers processed for the Customer.
- Categories of data
- Names, business contact details, user identifiers, usage logs, and any personal data contained in prompts, notes, reports, public web content and AI answers.
- Special categories
- None intended. The Customer must not submit special categories of data.
- Frequency
- Continuous, for the duration of the Service.
16. Annex 2: Technical and organizational measures
- Encryption: TLS for all data in transit; encryption at rest by our hosting and database providers; integration secrets encrypted at application level.
- Access control: authentication with verified email, hashed passwords, role-based workspace access, least-privilege administrative access, and logged support access.
- Tenant separation: workspace-scoped data access enforced in the application and database layer.
- Availability and resilience: managed infrastructure in the EU, automated backups, monitoring and alerting.
- Application security: content security policy, rate limiting, bot protection on authentication endpoints, dependency management and code review.
- Data minimization: prompts sent to AI providers contain business information, not account or contact data; analytics only with consent and with masked inputs and redacted URLs.
- Organizational measures: confidentiality obligations, processor agreements with all subprocessors, incident response procedures and regular review of these measures.
17. Annex 3: Approved subprocessors
Blizo uses the following subprocessors. The current list is always available at blizo.com/legal/subprocessors.
Hosting, database and infrastructure
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Vercel Vercel Inc. | Application hosting, content delivery, serverless functions (Frankfurt region) and bot protection (Vercel BotID) on sign-up and sign-in | All data processed by the application, IP address, request metadata, browser signals for bot detection | EU (Frankfurt) for functions; global edge network; USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
| Supabase Supabase, Inc. | Managed PostgreSQL database and file storage | Account, workspace, billing references, project data, prompts, AI answers, crawled content, logs | EU (Frankfurt, AWS eu-central-1) | EU Standard Contractual Clauses and UK Addendum |
| Trigger.dev Trigger.dev | Background job execution (measurements, reports, emails, billing reconciliation) | Job payloads containing workspace identifiers, prompts, domains and, for email jobs, recipient addresses | Provider-managed cloud (see provider DPA) | EU Standard Contractual Clauses and UK Addendum |
| Cloudflare Cloudflare, Inc. | Authoritative DNS for blizo.com (no application traffic is proxied) | DNS query metadata (resolver IP address, queried hostname) | Global network; USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
Payments and billing
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Stripe Stripe Payments Europe, Limited (Ireland) and Stripe, Inc. | Checkout, subscription billing, invoices, tax calculation, customer portal and payment fraud prevention | Name, email, company name, billing address, tax ID, payment method, transaction history | EU (Ireland); USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
Email delivery
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| Resend Plus Five Five, Inc. (Resend) | Transactional and service email delivery (verification, password reset, trial and billing notices, reports); delivered through Amazon SES in eu-west-1 (Ireland) | Recipient name and email address, email content, delivery and bounce events | EU (Ireland) for sending; USA for account administration | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
Product analytics (only with consent)
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| PostHog PostHog, Inc. | Product analytics, page views, interaction events and masked session recordings, only after you accept analytics cookies (only with your consent) | Pseudonymous device identifier, pages visited, clicks, browser and device data, coarse location, masked session recordings | EU (Frankfurt, PostHog EU Cloud) | EU Standard Contractual Clauses and UK Addendum |
AI platforms and model access
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| OpenRouter OpenRouter, Inc. | Model gateway for AI answers (Claude, Grok, Perplexity) and for onboarding research (brand, competitor and prompt suggestions) | Prompts, brand, competitor and market names, domains; no account or contact data | USA | EU Standard Contractual Clauses and UK Addendum |
| Anthropic Anthropic, PBC via OpenRouter | Claude answers and onboarding research models | Prompts, brand, competitor and market names, domains; no account or contact data | USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
| xAI X.AI LLC via OpenRouter | Grok answers | Prompts, brand, competitor and market names, domains; no account or contact data | USA | EU Standard Contractual Clauses and UK Addendum |
| Perplexity Perplexity AI, Inc. via OpenRouter | Perplexity (Sonar) answers | Prompts, brand, competitor and market names, domains; no account or contact data | USA | EU Standard Contractual Clauses and UK Addendum |
| OpenAI OpenAI, L.L.C. via OpenRouter | Onboarding research models | Prompts, brand, competitor and market names, domains; no account or contact data | USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
| Google Google LLC via OpenRouter | Gemini models for onboarding research | Prompts, brand, competitor and market names, domains; no account or contact data | USA | Data Privacy Framework and/or Standard Contractual Clauses (incl. UK Addendum) |
Search, SEO and website data
| Provider | Purpose | Personal data | Location | Transfer safeguard |
|---|---|---|---|---|
| DataForSEO DataForSEO | Search results, Google AI Overviews and AI Mode, ChatGPT and Gemini answer collection, keyword and market data | Prompts, keywords, brand and competitor names, domains, market and language | Outside the EU/EEA (see provider DPA) | EU Standard Contractual Clauses and UK Addendum |
| Ahrefs Ahrefs Pte. Ltd. | Competitor discovery and organic keyword data for your domain | Domains and competitor domains | Singapore | EU Standard Contractual Clauses and UK Addendum |
| Serper Serper | Search result lookups during onboarding research | Search queries containing brand, competitor or domain names | Outside the EU/EEA (see provider terms) | EU Standard Contractual Clauses and UK Addendum |
| SerpApi SerpApi, LLC | Fallback search result lookups during onboarding research | Search queries containing brand, competitor or domain names | USA | EU Standard Contractual Clauses and UK Addendum |
| Brave Search API Brave Software, Inc. | Fallback web search during onboarding research | Search queries containing brand, competitor or domain names | USA | EU Standard Contractual Clauses and UK Addendum |
| Jina AI Jina AI | Reading public web pages (Jina Reader) and fallback web search | Public URLs of your and your competitors' websites, search queries | EU (Germany) and/or USA (see provider terms) | EU Standard Contractual Clauses and UK Addendum |