Blob CRM
One Blob. Total Clarity.
Data Processing Addendum
Last updated: 21 July 2026
This Data Processing Addendum ("DPA") forms part of
the Terms of Service between you
("Customer", the data controller) and
Blob Works Limited ("Blob", the data processor). It applies
when Blob processes personal data on your behalf.
1. Subject matter & duration
Blob processes Customer Personal Data to provide the Blob CRM
service described in the Terms. Processing continues for the
duration of your subscription and the 30-day data-export window
after termination.
2. Nature & purpose
Blob stores, organises, retrieves, transmits, and deletes Customer
Personal Data as instructed by Customer through the service
interface and API. Blob does not use Customer Personal Data for
its own purposes (no analytics, no model training, no ads).
3. Categories of data subjects
- Customer's contacts (leads, prospects, customers)
- Customer's users (employees, admins, viewers)
- Recipients of Customer-sent emails / campaigns / sequences
- Booking guests and signing recipients
4. Categories of personal data
- Identifiers: name, email, phone, postal address
- Business context: company, role, deal value, deal stage
- Communications: email message bodies, call notes, meeting notes
- Authentication metadata: hashed passwords, TOTP secrets,
trusted-device identifiers, IP + user-agent on login
- Activity timestamps: page views inside Blob, action audit log
5. Blob's obligations as processor
Blob will:
- Process Customer Personal Data only on Customer's documented
instructions, unless required to do otherwise by applicable
law (in which case Blob will inform Customer first, where
permitted).
- Ensure people authorised to process Customer Personal Data
are bound by confidentiality.
- Implement the technical and organisational measures described
in the Security overview.
- Assist Customer in responding to data-subject rights requests
(access, rectification, erasure, portability, restriction,
objection).
- Assist Customer with DPIAs and prior consultations with
supervisory authorities, where reasonably necessary.
- Notify Customer without undue delay (within 72 hours) after
becoming aware of a personal-data breach affecting Customer
Personal Data, with the information required by Article 33 GDPR.
- Delete or return all Customer Personal Data after the
subscription ends (Customer's choice), unless legally required
to retain it. The default is deletion 30 days after termination.
- Make available all information necessary to demonstrate
compliance with Article 28, and allow + contribute to audits
on reasonable notice and at Customer's cost.
6. Sub-processors
Customer authorises Blob to engage the sub-processors listed in
Schedule 1 below. Blob will:
- Notify the workspace admin by email at least 30 days before
adding or replacing a sub-processor.
- Impose written data-protection obligations on each sub-
processor that are no less protective than this DPA.
- Remain liable for the acts and omissions of its sub-processors
as if they were Blob's own.
7. International transfers
Blob hosts Customer Personal Data on AWS in one or more of the
United States, United Kingdom, European Union, and Australasia
(with Cloudflare providing a global edge), depending on the region
assigned to your workspace. Where Customer Personal Data is
transferred out of the EEA, UK, or Switzerland to a country without
an adequacy decision, the transfer is covered by the European
Commission's Standard Contractual Clauses (SCCs, Module 2: Controller
→ Processor) and the UK International Data Transfer Addendum, which
are incorporated into this DPA by reference, together with the
technical safeguards described in our
Security overview.
8. Data subject rights
Blob provides in-product tools that allow Customer to fulfil
data-subject rights without contacting Blob: export, deletion,
rectification, and access are all self-serve through Settings →
Account. Where the tools don't cover an unusual request, Blob
will provide reasonable assistance on request.
9. Term
This DPA takes effect when Customer accepts the Terms of Service
and remains in force for the duration of the subscription plus
the 30-day data-export window.
10. Liability & conflicts
Each party's liability under this DPA is subject to the same
limitations as in the Terms of Service. If there is a conflict
between this DPA and the Terms, this DPA prevails to the extent
of the conflict on data-protection matters.
11. Contact
Data-protection questions:
[email protected]
Schedule 1 — Sub-processors
The current sub-processors, what they do, and where:
- Amazon Web Services (AWS) — origin servers,
compute, encrypted storage, backups. Regions: United States,
United Kingdom, European Union, and/or Australasia, per your
workspace's assigned region.
- Cloudflare, Inc. — DNS, global edge TLS
termination, WAF, DDoS protection.
- MXroute — outbound + inbound transactional
email delivery.
- Bulk-email provider (the one you configure —
e.g. Brevo, Elastic Email, SendGrid, or Amazon SES) — delivery of
your marketing campaigns, when you use the Campaigns feature.
- Stripe, Inc. — subscription billing, hosted
checkout, customer portal. Blob does not store full card numbers;
Stripe holds card data per PCI-DSS.
- ntfy — operational push notifications to the
platform operator (sign-in and new-workspace events). No customer
contact data is included in the payload.
- Anthropic / OpenAI / xAI — only when the AI
Assistant is enabled for your workspace. Conversation content is
sent to the chosen provider for inference.
- Google LLC / Microsoft Corporation — only when
you connect calendar sync, mailbox OAuth, or single sign-on for
your workspace.