Data Processing Addendum (Summary)
Roles
NextBlitz: Controller of personal data for the Service. Processors: vendors we use to operate the Service.
Instructions
Processors act only on documented instructions to provide the Service, secure data, and comply with law.
Security
Appropriate technical/organizational measures: encryption in transit; access controls; least privilege; logging; incident response.
Sub‑processors
We may use vetted sub‑processors and remain responsible for their performance. See Sub‑processors page.
International Transfers
Transfers outside EEA/UK use SCCs or equivalent safeguards, or your consent.
Assistance
Processors assist with data‑subject requests, DPIAs, and incident notifications, as required by law.
Return/Deletion
On termination or request, processors delete or return personal data unless retention is legally required.
Audit
On reasonable notice and where legally required, processors provide information necessary to demonstrate compliance.
Last updated: 12 October 2025