Download DPA (PDF)
EN: This DPA is the legally binding version (English only). It applies automatically upon account creation per Art. 28 GDPR.
IT: Il presente DPA è la versione legalmente vincolante (solo in inglese). Si applica automaticamente con la creazione dell'account ai sensi dell'Art. 28 GDPR.
DE: Dieser AVV ist die rechtsverbindliche Fassung (nur auf Englisch). Er gilt automatisch mit der Kontoerstellung gemäß Art. 28 DSGVO.
FR:Le présent DPA constitue la version juridiquement contraignante (uniquement en anglais). Il s'applique automatiquement lors de la création du compte conformément à l'Art. 28 du RGPD.

Data Processing Agreement

Effective Date: April 23, 2026
Version: 1.1 (self-service, pre-enterprise)
Processor: Arti-IT / Albert Milaqi, Pinner Straße 11, 42579 Heiligenhaus, Germany
Contact (DPO / privacy): [email protected]

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Albert Milaqi, operating as Blina Desk AI ("Processor", "we", "us"), and the customer ("Controller", "you") who subscribes to the Blina Desk AI platform ("Service"). This DPA is entered into in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

1. Definitions

  • Controller: The customer who determines the purposes and means of processing personal data through the Service. This is you, the subscribing organization or individual.
  • Processor: Albert Milaqi, operating as Blina Desk AI, who processes personal data on behalf of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
  • Processing: Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.
  • Sub-processor: A third party engaged by the Processor to process personal data on behalf of the Controller.

2. Subject Matter and Duration

The subject matter of this DPA is the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Service. The processing will continue for the duration of the Controller's active subscription and for any retention period required by law or agreed upon in the Terms of Service.

3. Nature and Purpose of Processing

The Processor processes personal data for the following purposes, solely as instructed by the Controller through use of the Service:

  • Storage and retrieval: Storing Customer Data in databases hosted in the EU and making it accessible through the Service interface.
  • Display and presentation: Rendering Customer Data in dashboards, lists, reports, and other views within the Service.
  • Search and filtering: Indexing and querying Customer Data to enable search, sorting, and filtering functionality.
  • AI analysis (opt-in): When the Controller enables AI features, transmitting relevant data to AI providers for generating summaries, suggestions, or analyses. AI processing is opt-in and does not occur unless actively used.
  • Communication: Sending system notifications, emails, or alerts as configured by the Controller.

4. Types of Personal Data

The following categories of personal data may be processed depending on the Controller's use of the Service:

  • Names and contact information (email addresses, phone numbers, postal addresses)
  • Business records (invoices, orders, contracts, notes)
  • Documents and file attachments uploaded by users
  • User account information (usernames, roles, login history)
  • Communication records (messages, comments, activity logs)
  • Any other personal data the Controller chooses to input into the Service

5. Categories of Data Subjects

The personal data processed may relate to the following categories of data subjects:

  • The Controller's employees and staff members
  • The Controller's clients and customers
  • The Controller's business contacts, suppliers, and partners
  • Any other individuals whose data the Controller enters into the Service

6. Obligations of the Processor

The Processor shall:

  • Process personal data only on documented instructions from the Controller, unless required by EU or member state law.
  • Ensure that all persons authorized to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures as described in Section 9 of this DPA.
  • Not engage another processor (sub-processor) without prior written authorization from the Controller, subject to Section 7.
  • Assist the Controller in fulfilling its obligations regarding data subject rights requests (access, rectification, erasure, portability, etc.).
  • Assist the Controller in ensuring compliance with obligations related to data protection impact assessments and prior consultation with supervisory authorities, where applicable.
  • At the Controller's choice, delete or return all personal data upon termination of the Service, as described in Section 11.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR.

7. Sub-processors

The Controller grants general authorization for the Processor to engage the following sub-processors. The Processor will notify the Controller of any intended changes to this list at least 30 days in advance, giving the Controller the opportunity to object.

Current Sub-processors

  • Hetzner Online GmbH (Gunzenhausen, Germany) — Infrastructure hosting and server provision. All data is stored on servers located in Germany.
  • Stripe, Inc.(San Francisco, USA; EU data processing via Stripe's EU entity) — Payment processing for subscription billing. Stripe processes payment card data and billing information only. Stripe is certified under the EU-US Data Privacy Framework.
  • OpenAI, Inc. (San Francisco, USA) — AI language model provider. Engaged only when the Controller opts into AI features. Data sent to OpenAI is limited to the content submitted for AI processing and is not used by OpenAI for training purposes under our API agreement.
  • Google LLC(Mountain View, USA) — AI language model provider (Gemini via Google AI / Vertex AI API). Engaged only when the Controller opts into AI features. Subject to Google's Cloud Data Processing Addendum. Customer data submitted via the paid Gemini API is not used by Google to train or improve generative models.
  • Anthropic, PBC (San Francisco, USA) — AI language model provider (Claude). Engaged only when the Controller opts into AI features. Data submitted via the API is not used for model training.

AI sub-processors are only engaged when the Controller actively uses AI features within the Service. No personal data is transmitted to AI providers unless the Controller initiates an AI-powered action.

Sub-processor Data Processing Agreements

The following links provide access to each sub-processor's own data processing terms:

8. International Data Transfers

Primary data storage and processing takes place within the European Union (Germany). Where personal data is transferred to sub-processors located outside the EU/EEA (specifically Stripe, OpenAI, Google, and Anthropic in the USA), such transfers are safeguarded by:

  • The EU-US Data Privacy Framework, where applicable.
  • Standard Contractual Clauses (SCCs) adopted by the European Commission.
  • Additional technical safeguards including encryption in transit.

9. Technical and Organizational Measures

The Processor implements the following measures to ensure the security of personal data:

Encryption

  • All data in transit is encrypted using TLS 1.2 or higher.
  • Database storage is encrypted at rest.
  • Sensitive credentials and tokens are encrypted before storage.

Access Control

  • Role-based access control (RBAC) within the Service.
  • Multi-tenant data isolation ensuring strict separation of customer data.
  • Two-factor authentication (2FA/OTP) available for user accounts.
  • Session management with configurable concurrent session limits.
  • Comprehensive audit logging of administrative and security-relevant actions.

Infrastructure Security

  • Servers hosted in Hetzner data centers in Germany, compliant with ISO 27001.
  • Firewalls and network segmentation to restrict unauthorized access.
  • Regular security updates and patch management.
  • Malware scanning (ClamAV) for uploaded files.

Backups and Availability

  • Regular automated database backups.
  • Backup data is stored encrypted and within the EU.
  • Disaster recovery procedures to restore service availability.

10. Data Breach Notification

In the event of a personal data breach, the Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. The notification shall include:

  • A description of the nature of the breach, including the categories and approximate number of data subjects and records affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its effects.
  • The contact point for further information.

The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

11. Data Deletion on Termination

Upon termination of the Service agreement, the Processor shall, at the Controller's choice:

  • Return all personal data to the Controller in a standard, machine-readable format (data export), or
  • Delete all personal data and confirm deletion in writing.

The Controller has 30 days from termination to request data export. After this period, the Processor may permanently delete all Customer Data. Any data retained for legal compliance purposes will be isolated and protected until deletion is permissible.

12. Audit Rights

The Controller has the right to conduct audits, including inspections, to verify the Processor's compliance with this DPA. The Processor shall make available all information necessary to demonstrate compliance and shall allow and contribute to audits conducted by the Controller or an auditor mandated by the Controller.

Audits shall be conducted with reasonable advance notice (at least 30 days), during normal business hours, and in a manner that does not unreasonably disrupt the Processor's operations. The Controller shall bear the costs of any audit unless the audit reveals non-compliance by the Processor.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

14. Governing Law

This DPA is governed by the laws of the Federal Republic of Germany. Any disputes shall be subject to the exclusive jurisdiction of the courts of Düsseldorf, Germany.

Contact

For questions or requests related to data processing, please contact us at [email protected].