Data Processing Agreement
Version 1.1 · Effective 31 October 2026
This Data Processing Agreement (the "Agreement") is made under Article 28 of Regulation (EU) 2016/679 ("GDPR"). The parties are:
- the Customer, the business or organisation that uses Sightelle, as controller;
- Blossom Solutions L.P., 111 Vasileos Pavlou, Spata 19004, Attica, Greece, VAT EL802462265, GEMI no. 176808501000 (the "Provider"), as processor.
This Agreement forms part of the Terms of Service and applies for as long as the Provider processes personal data on the Customer's behalf. If the Customer needs a signed copy, it can request one at dpo@blossom-solutions.gr.
1. Subject matter
The Provider processes the personal data contained in Customer Data solely to provide the Sightelle Service. The subject matter, nature, purpose, categories of data and categories of data subjects are described in Annex I.
2. Customer obligations
The Customer:
- has a legal basis for all data it imports into the Service, or that is imported on its behalf;
- informs data subjects (its customers, respondents, employees), for example with a link to its own privacy policy on its surveys;
- decides which sources it connects, which fields it imports, which users it invites, and where it sends data through webhooks, Slack or Teams;
- does not import special categories of data (Art. 9 GDPR) or children's data, unless it has assessed the risk and has a legal basis;
- when it uses the Service for employee surveys, fulfils its obligations as an employer. These include informing employees and, where required, carrying out an impact assessment and consulting their representatives.
The Customer's documented instructions to the Provider are the Terms of Service, this Agreement, and the settings the Customer chooses in the application.
3. Provider obligations
The Provider:
- processes the data only on the Customer's documented instructions, unless EU or Member State law requires otherwise; in that case, it informs the Customer unless the law prohibits it. If it considers that an instruction infringes the GDPR, it informs the Customer immediately;
- does not use the data for its own purposes and does not use it to train artificial intelligence models. The exception is aggregated, anonymous usage statistics (e.g. number of rows), which do not identify individuals and are used to run and bill the Service;
- ensures that everyone with access to the data is bound by confidentiality;
- takes the technical and organisational measures required by Article 32, as described in Annex II;
- complies with the conditions for sub-processors in section 4;
- assists the Customer in responding to data subject requests (section 5);
- assists the Customer with its obligations under Articles 32 to 36: security, breach notification, impact assessments and prior consultation;
- deletes or returns the data at the end of the service (section 8);
- makes available to the Customer all information needed to demonstrate compliance, and allows for audits (section 7).
4. Sub-processors
- The Customer gives the Provider general authorisation to use sub-processors. Those in use today are listed in Annex III.
- The Provider notifies the Customer of any addition or replacement of a sub-processor by email to the workspace Owner, at least 30 days in advance.
- The Customer may object on reasonable data protection grounds. If no solution is found, the Customer may terminate the Service and receives the pro-rata amount of any paid period not yet used.
- The Provider imposes on each sub-processor, by contract, data protection obligations equivalent to these, and remains liable to the Customer for them.
5. Data subject rights
- If a data subject contacts the Provider, the Provider forwards the request to the Customer without undue delay and does not respond on the substance itself, unless the Customer asks it to.
- The application gives the Customer an export of the whole workspace, a data reset, and workspace deletion.
- For requests concerning one specific person (access, erasure), the workspace Owner finds, exports and deletes that person's data on the "Your data" page, by email or full name. Deletion also removes their quotes from reports and audits already produced.
- For anything the application does not cover (for example rectification), the Customer can write to dpo@blossom-solutions.gr. The Provider locates and exports, corrects or deletes that person's data within 15 days, so that the Customer can respond on time.
6. Personal data breach
- The Provider notifies the Customer without undue delay and in any case within 48 hours of becoming aware of a breach affecting the Customer's data.
- Notification is sent by email to the workspace Owner and includes, to the extent known:
- the nature of the breach;
- the categories and approximate number of data subjects and records;
- the likely consequences;
- the measures taken or proposed.
- Anything not known at first is provided in phases.
- The Provider records every incident and assists the Customer with notifying the supervisory authority and data subjects.
7. Audits
- The Provider answers the Customer's reasonable security and compliance questionnaires.
- If these are not sufficient, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, on these conditions:
- at least 30 days' notice;
- no more than once a year, unless there has been a breach or a supervisory authority requests it;
- during business hours, and without affecting other customers' data.
- The Customer bears the cost of the audit.
8. Duration, return and deletion
- This Agreement applies for as long as the Customer's workspace exists.
- Return. The Customer can export its data from the application at any time. The expiry of a paid plan does not delete data.
- Deletion.
- When the Customer requests deletion of the workspace, the data is permanently deleted after 14 days, during which deletion can be cancelled.
- Backups containing it are deleted automatically within a further 14 days.
- With a reset, the data is deleted from the database immediately and leaves the backups within 14 days.
- What is kept after deletion.
- Orders and billing documents, for as long as tax law requires.
- The security history of user accounts, for 365 days, as set out in the Privacy Policy.
9. Transfers outside the EEA
- Hosting, the database and backups are in the EU.
- Text analysis by the AI model provider (Annex III) takes place in the USA. The transfer relies on:
- the EU-US Data Privacy Framework, where the recipient is certified;
- otherwise, the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, Module 3: processor to processor).
- Before anything is sent, email addresses, phone numbers, tax ids and IBANs are removed from the text (Annex II).
10. Liability and precedence
- The parties' liability is governed by the Terms of Service, without prejudice to Article 82 GDPR.
- In case of conflict on data protection matters, this Agreement prevails over the Terms of Service, and the Standard Contractual Clauses, where they apply, prevail over this Agreement.
- Greek law applies.
Annex I — Description of the processing
Nature and purpose. The processing serves the analysis of the Customer's feedback:
- importing text from files, connected systems, the API and surveys;
- removing contact details before analysis;
- extracting "signals" and estimating tone with AI models, and creating vector representations (embeddings);
- grouping into themes and linking to customers and revenue;
- producing screens, reports, alerts and documents;
- collecting responses to the Customer's surveys;
- recovery cases: when the Customer enables them, a low survey score opens a case with a deadline, so that the Customer's team can contact the respondent. The Provider does not contact the respondent.
Duration. For as long as the workspace exists, and as set out in section 8.
Categories of data subjects.
- customers and users of the Customer's products;
- survey respondents;
- the Customer's employees (when used for employee surveys);
- Customer staff mentioned in tickets;
- contacts in customer and recipient lists.
Categories of data.
- free text (tickets, comments, responses), which may contain any personal data its author wrote;
- author or recipient name and email;
- customer name, identifiers, revenue (ARR) and risk level, as imported by the Customer;
- survey scores and choices;
- a contact email optionally given by a respondent;
- an email or phone number given by a respondent who asks the Customer to contact them about their answer (consent to be contacted);
- notes by the Customer's team on recovery cases;
- metadata from connected systems (dates, categories, priority, channel).
Special categories. Not intended. The Customer does not import them without a legal basis (section 2).
Survey anonymity. In a survey the Customer has set as anonymous:
- the response is stored without a link to the recipient;
- only the day of the response is recorded on the recipient;
- no identifier from the link (
ref) is stored.
The only exception is consent to be contacted, when the Customer enables it on the survey. After a low score, the page asks the respondent whether they want the Customer to contact them, with text stating plainly that the answer will be linked to the details they give. If the respondent agrees:
- the link covers their own answer only; all other answers stay anonymous;
- the details do not appear in results, exports or webhooks, and are not sent to AI models; only the Customer's members who can change data see them, on the recovery case;
- they are removed with an erasure request for the person (section 5), together with the case.
Annex II — Technical and organisational measures
Isolation and access
- Each workspace is isolated at database level: without a workspace identity, data is invisible.
- Roles per workspace (Owner, Lead, Member, Viewer). Scoped API keys, of which only a fingerprint is stored.
- Passwords stored only as hashes, with a policy on minimum length, complexity, history and lockout after failures.
- A second authentication factor (TOTP), which the Customer can make mandatory.
- Provider staff access servers only with SSH keys, and access is limited to a small number of people.
Encryption
- All communication over TLS, with HSTS.
- Secrets (tokens for connected systems, webhook URLs, personal survey links) are stored encrypted.
Minimisation towards the AI provider
- Before each call, email addresses, phone numbers, tax ids and IBANs are removed. Names inside the text are not removed.
- The author's name is not sent.
- Each call is logged with its purpose, model and cost, but not its text.
Availability and resilience
- Nightly backups with an integrity check and a tested restore, kept for 14 days.
- Automatic availability monitoring.
- Firewall at provider and server level, and protection against repeated failed logins.
Logging and accountability
- A per-workspace activity log that is not erased by the actions it records.
- A separate security history per account.
- Rate limits on public endpoints and the API.
Development
- Automated tests on every code change, including tests of isolation between workspaces.
- Software and dependency updates with checks for known vulnerabilities.
Annex III — Sub-processors
| Sub-processor | Service | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Hetzner Online GmbH | Server and backup hosting | All Customer Data | Helsinki, Finland (EU) | Within the EU |
| OpenAI | AI models: signal extraction, classification, embeddings, report synthesis, answering questions | Text with emails, phone numbers, tax ids and IBANs removed; theme names; aggregated ARR per theme | USA | EU-US Data Privacy Framework or Standard Contractual Clauses. Under the provider's terms, data is not used for training and is kept up to 30 days for abuse monitoring. |
| [Email delivery provider — to be completed] | Sending platform emails (not to the Customer's customers) | User email and name, report figures and links | [location] | [safeguard] |