Download DPA (PDF)
EN: This DPA is the legally binding version (English only). It applies automatically upon account creation per Art. 28 GDPR.
IT: Il presente DPA è la versione legalmente vincolante (solo in inglese). Si applica automaticamente con la creazione dell'account ai sensi dell'Art. 28 GDPR.
DE: Dieser AVV ist die rechtsverbindliche Fassung (nur auf Englisch). Er gilt automatisch mit der Kontoerstellung gemäß Art. 28 DSGVO.
FR:Le présent DPA constitue la version juridiquement contraignante (uniquement en anglais). Il s'applique automatiquement lors de la création du compte conformément à l'Art. 28 du RGPD.

Data Processing Agreement

Effective Date: April 23, 2026
Version: 1.4 (self-service, pre-enterprise)
Processor: Arti-IT / Albert Milaqi, Pinner Straße 11, 42579 Heiligenhaus, Germany
Contact (DPO / privacy): info@blina-desk.com

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Albert Milaqi, operating as Blina Desk ("Processor", "we", "us"), and the customer ("Controller", "you") who subscribes to the Blina Desk platform ("Service"). This DPA is entered into in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Definitions

  • Controller: The customer who determines the purposes and means of processing personal data through the Service. This is you, the subscribing organization or individual.
  • Processor: Albert Milaqi, operating as Blina Desk, who processes personal data on behalf of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
  • Processing: Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.
  • Sub-processor: A third party engaged by the Processor to process personal data on behalf of the Controller.

2. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Service. The processing will continue for the duration of the Controller's active subscription and for any retention period required by law or agreed upon in the Terms of Service.

3. Nature and Purpose of Processing

The Processor processes personal data for the following purposes, solely as instructed by the Controller through use of the Service:

  • Storage and retrieval: Storing Customer Data in databases hosted in the EU and making it accessible through the Service interface.
  • Display and presentation: Rendering Customer Data in dashboards, lists, reports, and other views within the Service.
  • Search and filtering: Indexing and querying Customer Data to enable search, sorting, and filtering functionality.
  • AI analysis started by a user: When a user asks a question, requests a draft or a summary, or otherwise starts a generative feature, transmitting the content submitted for that request to the AI provider. This happens only on that action.
  • Semantic indexing: Preparing Customer Data so it can be searched by meaning. This runs by default, without a user starting it, and sends the indexed content to the embedding provider configured for the Service. The Controller chooses which sources it covers, and can have it switched off for its account.
  • Communication: Sending system notifications, emails, or alerts as configured by the Controller.
  • Telephone conversations (only if the module is active): Answering incoming calls with an AI assistant: recognising what the caller says, synthesising the reply, matching the calling number against the Controller's own contacts, and writing the resulting transcript and any action taken (an appointment, a ticket, a note) into the Controller's data. The audio itself is not stored.

4. Types of Personal Data

The following categories of personal data may be processed depending on the Controller's use of the Service:

  • Names and contact information (email addresses, phone numbers, postal addresses)
  • Business records (invoices, orders, contracts, notes)
  • Documents and file attachments uploaded by users
  • User account information (usernames, roles, login history)
  • Communication records (messages, comments, activity logs)
  • Where the AI phone assistant is active: the calling number, the audio of the conversation while it is in progress, and the written transcript that remains afterwards
  • Any other personal data the Controller chooses to input into the Service

The Service is not intended for special categories of personal data within the meaning of Art. 9 GDPR. The audio of a telephone call is processed to recognise what is said, not to identify who is speaking: no voiceprint or other biometric template is created, so the processing is not biometric identification within the meaning of Art. 9 (1) GDPR. Where the Controller nevertheless enters data falling under Art. 9 — or where a caller volunteers it — the Controller remains responsible for the legal basis.

5. Categories of Data Subjects

The personal data processed may relate to the following categories of data subjects:

  • The Controller's employees and staff members
  • The Controller's clients and customers
  • The Controller's business contacts, suppliers, and partners
  • Where the AI phone assistant is active: anyone who calls the Controller's number, including people who are not otherwise known to the Controller and have had no prior contact with it
  • Any other individuals whose data the Controller enters into the Service

6. Obligations of the Processor

The Processor shall:

  • Process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
  • Ensure that all persons authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures as described in Section 9 of this DPA.
  • Not engage another processor (sub-processor) without prior written authorization from the Controller, subject to Section 7.
  • Assist the Controller in fulfilling its obligations regarding data subject rights requests (access, rectification, erasure, portability, etc.).
  • Assist the Controller in ensuring compliance with obligations related to data protection impact assessments and prior consultation with supervisory authorities, where applicable.
  • At the Controller's choice, delete or return all personal data upon termination of the Service, as described in Section 11.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

7. Sub-processors

The Controller grants general authorization for the Processor to engage the following sub-processors. The Processor will notify the Controller of any intended changes to this list at least 30 days in advance, giving the Controller the opportunity to object.

Current Sub-processors

  • Hetzner Online GmbH (Gunzenhausen, Germany) — Infrastructure hosting and server provision. All data is stored on servers located in Germany.
  • Stripe, Inc.(San Francisco, USA; EU data processing via Stripe's EU entity) — Payment processing for subscription billing. Stripe processes payment card data and billing information only. Stripe is certified under the EU-US Data Privacy Framework.
  • OpenAI, Inc. (San Francisco, USA) — AI language model provider. Engaged only when the Controller opts into AI features. Data sent to OpenAI is limited to the content submitted for AI processing and is not used by OpenAI for training purposes under our API agreement.
  • Google LLC(Mountain View, USA) — AI language model provider (Gemini via Google AI / Vertex AI API). Engaged only when the Controller opts into AI features. Subject to Google's Cloud Data Processing Addendum. Customer data submitted via the paid Gemini API is not used by Google to train or improve generative models.
  • Anthropic, PBC (San Francisco, USA) — AI language model provider (Claude). Engaged only when the Controller opts into AI features. Data submitted via the API is not used for model training.
  • Brevo (Sendinblue SAS)(Paris, France) — Transactional email delivery for messages Blina Desk itself sends (login codes, account and subscription notices). Receives the recipient address, the message content and delivery metadata. Not used for marketing. Emails the Controller sends to its own contacts are delivered through the Controller's own mail server and do not pass through Brevo.
  • Cloudflare, Inc. (San Francisco, USA) — Content delivery, DNS and protection against attacks. Processes IP addresses and connection metadata, and terminates the TLS connection. Transfers are covered by the EU Standard Contractual Clauses.
  • Meta Platforms Ireland Ltd. (Dublin, Ireland) — WhatsApp Business Platform. Engaged only if the Controller activates the WhatsApp module, and processes the phone numbers and message content of the contacts the Controller communicates with.
  • ElevenLabs Inc.(New York, USA) — Speech recognition and speech synthesis for the AI phone assistant. Engaged only if the Controller activates that module. Processes, for the duration of a call, the caller's number and the audio of the conversation, plus the context the Processor supplies for that call (the caller's name and company where recognised, and the assistant's configuration). The caller's speech is transmitted for the duration of the call so that it can be recognised, and the assistant's replies are synthesised there. No audio is recorded or stored, on either side: voice recording is switched off in our account settings for the assistant, verified on 31 August 2026. What is kept is the written transcript, in the Controller's own call log on our servers in Germany. On the provider's side the conversation record is deleted after seven days. Audio recording of the call is not a function the Service currently offers. Transfers are covered by the EU Standard Contractual Clauses and, in addition, by the EU-US Data Privacy Framework; under the provider's own data processing addendum the Clauses are governed by the law of Ireland and the competent courts are the Courts of Ireland.

AI sub-processors are only engaged when the Controller actively uses AI features within the Service. This applies to generative features started by a user action. Semantic indexing of documents, which prepares content so it can be searched, runs by default and uses the embedding provider configured for the Service; the Controller can request that it be switched off for its account.

Where the Processor engages a sub-processor, it does so under a written contract imposing on that sub-processor data protection obligations no less protective than those set out in this Agreement, in particular sufficient guarantees to implement appropriate technical and organisational measures. Where the sub-processor fails to fulfil those obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor's obligations (Art. 28 (4) GDPR).

The Processor shall immediately inform the Controller if, in its opinion, an instruction given by the Controller infringes the GDPR or other Union or Member State data protection provisions (Art. 28 (3) GDPR).

Sub-processor Data Processing Agreements

The following links provide access to each sub-processor's own data processing terms:

8. International Data Transfers

Primary data storage and processing takes place within the European Union (Germany). Where personal data is transferred to sub-processors located outside the EU/EEA — Stripe, OpenAI, Google, Anthropic, Cloudflare and, where the phone assistant is active, ElevenLabs, all in the USA — such transfers are safeguarded by:

  • The EU-US Data Privacy Framework, where applicable.
  • Standard Contractual Clauses (SCCs) adopted by the European Commission.
  • Additional technical safeguards including encryption in transit.

With some sub-processors the Clauses are not signed separately: they take effect together with that provider's own data processing addendum, which our contract with them incorporates. Where that is the case, the law governing the Clauses and the competent courts are those named in the provider's addendum, and they are stated in the entry for that provider in section 7 above.

Meta Platforms Ireland Ltd. contracts within the EU; its own onward transfers to Meta Platforms, Inc. in the USA are governed by the safeguards set out in Meta's terms for the WhatsApp Business Platform.

Obtaining a copy. The Controller may request a copy of the Standard Contractual Clauses concluded with any sub-processor named above by writing to info@blina-desk.com. The copy is provided within 30 days. Commercial terms unrelated to data protection (prices, volumes) may be redacted; the data protection provisions are not.

9. Technical and Organizational Measures

The Processor implements the following measures to ensure the security of personal data:

Encryption

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Database storage is encrypted at rest.
  • Sensitive credentials and tokens are encrypted before storage.

Access Control

  • Role-based access control (RBAC) within the Service.
  • Multi-tenant data isolation ensuring strict separation of customer data.
  • Two-factor authentication (2FA/OTP) available for user accounts.
  • Session management with configurable concurrent session limits.
  • Comprehensive audit logging of administrative and security-relevant actions.

Infrastructure Security

  • Servers hosted in Hetzner data centers in Germany, compliant with ISO 27001.
  • Firewalls and network segmentation to restrict unauthorized access.
  • Regular security updates and patch management.
  • Malware scanning (ClamAV) for uploaded files.

Backups and Availability

  • Regular automated database backups.
  • Backup data is stored encrypted and within the EU.
  • Disaster recovery procedures to restore service availability.

10. Data Breach Notification

In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 24 hours after becoming aware of the breach. The notification shall include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and records affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its effects.
  • The contact point for further information.

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

11. Data Deletion on Termination

Upon termination of the Service agreement, the Processor shall, at the Controller's choice:

  • Return all personal data to the Controller in a standard, machine-readable format (data export), or
  • Delete all personal data and confirm deletion in writing.

The Controller has 30 days from termination to request data export. After this period, the Processor may permanently delete all Customer Data. Any data retained for legal compliance purposes will be isolated and protected until deletion is permissible.

12. Audit Rights

The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall make available all information necessary to demonstrate compliance and shall allow and contribute to audits conducted by the Controller or an auditor mandated by the Controller.

Audits shall be conducted with reasonable advance notice (at least 30 days), during normal business hours, and in a manner that does not unreasonably disrupt the Processor's operations. The Controller shall bear the costs of any audit unless the audit reveals non-compliance by the Processor.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

14. Governing Law

This DPA is governed by the laws of the Federal Republic of Germany. Any disputes shall be subject to the exclusive jurisdiction of the courts of Düsseldorf, Germany.

Contact

For questions or requests related to data processing, please contact us at info@arti-it.de.