Parties and priority
This DPA forms part of the Bloom Terms between the business customer (the responsible party) and [LEGAL_ENTITY_NAME], trading under Plainspoken (the operator). It governs personal information the customer enters about its clients, staff and other people. If it conflicts with the Terms on this processing, this DPA controls.
Instructions and scope
The customer instructs us to process submitted data to provide, secure, support, back up and improve the contracted service, and as documented in product settings. The processing lasts while the service is used plus the retention and deletion period. Data subjects may include clients, prospective clients, staff and business contacts. Data can include identity, contact, appointments, services, notes, preferences, payment records and any sensitive details a customer lawfully enters. We will not use customer lists for our own marketing.
Customer obligations
The customer determines purposes and lawful grounds, gives required notices, manages its staff permissions, respects opt-outs and avoids unnecessary sensitive information. It is responsible for the legality, quality and accuracy of instructions and data. It must not direct us to process unlawfully.
Our obligations
We process only with the customer's knowledge or authorisation, except where law requires otherwise; bind authorised personnel to confidentiality; apply appropriate security safeguards; limit access; and help the customer respond to data-subject requests, security incidents and lawful compliance inquiries where reasonably possible. We will inform the customer if an instruction appears unlawful, unless prohibited.
Subprocessors and transfers
The customer authorises providers listed on the Subprocessor List for hosting, delivery and payment functions actually used. We require appropriate confidentiality and security obligations from subprocessors and remain responsible for their work under this DPA. We will give reasonable advance notice of material list changes and allow a customer to object on reasonable data-protection grounds. Cross-border transfers are subject to POPIA's conditions and suitable safeguards; deployment locations are recorded only when verified.
Security incidents and requests
We will notify the customer promptly after becoming aware of reasonable grounds to believe customer personal information was accessed or acquired without authority, share information reasonably available, and cooperate on containment and legally required notifications. The customer remains responsible for its notifications as responsible party. We will disclose customer data to authorities only where lawfully required and, where lawful, notify the customer.
Return, deletion and assurance
Owners may export business data through Bloom while access remains available. After termination, we delete or de-identify customer data under the Data Retention Policy, except legally required records and backup copies pending rotation. On reasonable request we provide information needed to demonstrate compliance, subject to confidentiality and security limits. Audit requests should be proportionate, agreed in advance and avoid exposing other tenants.