Auftragsverarbeitungsvertrag
Unsere Pflichten, wenn wir in Ihrem Auftrag als Auftragsverarbeiter tätig sind.
Zuletzt aktualisiert: 5. Oktober 2026
This Data Processing Agreement (the "DPA") is concluded between:
- NEXT BP, a French simplified joint-stock company (SAS) with a share capital of €100, registered with the Paris Trade and Companies Register under number 920 753 233, whose registered office is at 127 rue de la Tour, 75016 Paris, France ("NEXT BP" or the "Processor"); and
- the legal entity that subscribes to Blast Audit or starts a free trial (the "Client").
It forms part of the Terms and Conditions and of the End-User License Agreement (EULA) (together, the "Principal Agreement"). It sets out the conditions under which NEXT BP processes Personal Data on behalf of the Client when it provides Blast Audit: the Excel add-in, the web dashboard, the connectors to the Client's cloud storage, the MCP server and the engagement agent (together, the "Software"). It is the contract required by Article 28 of the GDPR.
This DPA draws on the standard contractual clauses of Commission Implementing Decision (EU) 2021/915, without reproducing them where a clause so indicates: Annex 1 corresponds to their Annexes I and II, Annex 2 to their Annex III and Annex 3 to their Annex IV.
1. Definitions
Terms defined in the GDPR (including "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority") have the meaning given to them in the GDPR. In addition:
- "GDPR" means Regulation (EU) 2016/679 of 27 April 2016.
- "Data Protection Legislation" means the GDPR, French Law No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, and any other Union or Member State law on the protection of Personal Data that applies to the Processing.
- "Client Data" means the documents, files, images, audio, text, instructions, workpapers and results that the Client or its Users submit to the Software or that the Software produces from them, and the Personal Data they contain.
- "Sub-processor" means any processor engaged by NEXT BP to carry out Processing of Client Data on behalf of the Client.
- "Users" means the persons whom the Client authorises to use the Software.
- "Annexes" means the four annexes to this DPA, which form part of it.
This DPA is read and interpreted in the light of the GDPR. It may not be interpreted in a way that runs counter to the rights and obligations provided for in the GDPR or in a way that prejudices the fundamental rights or freedoms of Data Subjects.
2. Roles and Scope
2.1 The Client is the Controller of the Personal Data contained in Client Data. It determines the purposes of the Processing and alone decides which documents its Users submit to the Software. Where the Client itself processes these data as a processor on behalf of a third party, NEXT BP acts as its sub-processor and the Client passes on to NEXT BP the instructions it receives.
2.2 NEXT BP is the Processor. It processes Client Data only to provide the Software to the Client, in accordance with this DPA.
2.3 Data outside this DPA. NEXT BP acts as an independent Controller, and not under this DPA, for the data it needs to run its own business: Users' accounts and authentication, billing, support requests, security of the service, product analytics and commercial relations. These data are described in the Privacy Policy. Technical usage metrics (for example, the number of pages processed or the duration of a task) belong to this category: they contain no document content and NEXT BP uses them only for billing, quotas, security and service reliability.
2.4 Scope. This DPA is without prejudice to the obligations to which the Client is subject as Controller under the GDPR. It is not enough on its own to govern transfers outside the European Economic Area, which are covered by Section 8 and Annex 4.
3. Details of the Processing
The subject matter, nature, purpose and duration of the Processing, the types of Personal Data and the categories of Data Subjects are described in Annex 1. The Processing lasts as long as the Principal Agreement, then until Client Data are deleted or returned in accordance with Section 7.
4. Obligations of NEXT BP
4.1 Documented instructions. NEXT BP processes Client Data only on the documented instructions of the Client, including with regard to transfers of Personal Data to a third country or an international organisation, unless it is required to do so by Union or Member State law to which it is subject. In that case, NEXT BP informs the Client of that legal requirement before the Processing, unless that law prohibits such information on important grounds of public interest. The Principal Agreement, this DPA, the Users' actions in the Software and the settings chosen by the Client's administrators (for example, enabling a connector) constitute the Client's documented instructions. The Client may give further instructions throughout the duration of the Processing; they are always documented, for example by e-mail to privacy [at] blast-audit.com. If NEXT BP cannot carry out a further instruction with the functions of the Software, it informs the Client without delay and Section 12 applies.
4.2 Unlawful instructions. NEXT BP immediately informs the Client if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions. NEXT BP may suspend the execution of that instruction until the Client confirms or amends it in writing.
4.3 Confidentiality. NEXT BP ensures that persons authorised to process Client Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they access Client Data only to the extent strictly necessary to provide the Software, to answer a support request from the Client, or to handle an incident.
4.4 Sub-processors.
(a) General authorisation. The Client gives NEXT BP a general written authorisation to engage Sub-processors. The Sub-processors engaged on the date of this DPA are listed in Part A of Annex 3, which constitutes NEXT BP's dated sub-processor list.
(b) Obligations of Sub-processors. NEXT BP engages each Sub-processor by way of a contract that imposes on it, in substance, the same data protection obligations as those imposed on NEXT BP under this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. NEXT BP ensures that each Sub-processor complies with these obligations. NEXT BP remains fully liable to the Client for the performance of its Sub-processors' obligations and informs the Client of any failure by a Sub-processor to fulfil its contractual obligations of which NEXT BP is aware.
(c) Changes. NEXT BP informs the Client of any intended addition or replacement of a Sub-processor at least thirty (30) days before it takes effect, by e-mail to the address of the Client's account owner and by publishing an updated, dated Annex 3. The notice states the name of the Sub-processor, its role, the location of the Processing and the transfer mechanism.
(d) Objection. Within this thirty-day period, the Client may object to the change in writing to privacy [at] blast-audit.com, on reasonable grounds relating to the protection of Personal Data. NEXT BP and the Client then seek a solution in good faith, for example a configuration in which the new Sub-processor does not process the Client's data. If no solution is found before the change takes effect, the Client may terminate the affected subscription, without penalty, with effect on the date of the change. The Client is then entitled to the refund provided for in Section 12.5.
(e) Copies of contracts. At the Client's request, NEXT BP provides a copy of the applicable contract concluded with a Sub-processor, in the version in force, and of any amendments to it, including where that contract consists of the standard terms the Sub-processor publishes. NEXT BP may redact trade secrets and other confidential information, including Personal Data.
(f) Disappearance of NEXT BP. NEXT BP uses the standard terms of its Sub-processors and cannot have a clause added to them for the Client's benefit. If NEXT BP has factually disappeared, has ceased to exist in law or has become insolvent, the Client may ask the administrator or liquidator to delete or return Client Data; Client Data remain subject to the retention periods in Annex 1.
(g) Urgent replacement. Where a Sub-processor stops its service or puts the security of Client Data at risk, NEXT BP may replace it with shorter notice. No Client Data are transmitted to the new Sub-processor before the Client is informed. The Client then has the rights in Section 4.4(d) for thirty (30) days. If the Client objects, NEXT BP stops transmitting Client Data through that Sub-processor for that Client.
4.5 Security. NEXT BP implements the technical and organisational measures described in Annex 2 to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. NEXT BP may change these measures provided that the overall level of protection is not reduced.
4.6 Requests from Data Subjects. Taking into account the nature of the Processing, NEXT BP assists the Client by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If NEXT BP receives such a request directly, it forwards it to the Client without undue delay and does not respond to it itself, except to tell the Data Subject that the request has been forwarded.
4.7 Data protection impact assessment and prior consultation. Taking into account the nature of the Processing and the information available to it, NEXT BP assists the Client in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR. In particular, it provides the Client, on request, with the information the Client needs to carry out a data protection impact assessment (description of the Processing, data flows, Sub-processors, retention periods, security measures) and assists it in any prior consultation of the CNIL or of another competent Supervisory Authority. NEXT BP informs the Client without delay if it becomes aware that Personal Data it processes on the Client's behalf are inaccurate or have become outdated.
4.8 Personal Data Breaches.
(a) NEXT BP notifies the Client of any Personal Data Breach affecting Client Data without undue delay and within 48 hours after becoming aware of it, by e-mail to the address of the Client's account owner.
(b) The notification contains, to the extent known at that time: the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and of records concerned; the name and contact details of NEXT BP's contact point (privacy [at] blast-audit.com); the likely consequences of the breach; and the measures taken or proposed by NEXT BP to address the breach and mitigate its possible adverse effects. Where all the information cannot be provided at the same time, NEXT BP provides it in phases, without further undue delay.
(c) NEXT BP cooperates with the Client so that the Client can notify the Supervisory Authority and, where required, the Data Subjects. NEXT BP does not make these notifications on the Client's behalf unless the Client instructs it to do so in writing.
(d) Where a Personal Data Breach concerns data processed by the Client itself, for example after a User's account has been compromised, NEXT BP assists the Client, taking into account the nature of the Processing and the information available to it, in notifying the Supervisory Authority, gathering the information required by Article 33(3) of the GDPR and, where required, communicating the breach to the Data Subjects.
4.9 Information. The parties are able to demonstrate compliance with this DPA. NEXT BP deals promptly and adequately with the Client's inquiries about the Processing of Client Data and answers them within ten (10) business days. It makes available to the Client all information necessary to demonstrate compliance with Article 28 of the GDPR and with this DPA, under the conditions of Section 6. It makes this information, including the results of any audit, available to the competent Supervisory Authority on request.
5. Artificial Intelligence
5.1 No training. NEXT BP does not use Client Data to train, fine-tune or otherwise improve any artificial intelligence or machine learning model, whether its own or a third party's.
5.2 AI providers. Except where the Client uses its own API key (Section 5.7), the AI models that process Client Data are operated by Microsoft (Azure OpenAI, Azure AI Content Understanding, Azure AI Speech) under Microsoft's data protection terms, which prohibit Microsoft from using Client Data to train or improve its models. NEXT BP will engage no other AI model provider without imposing the same prohibition, and only in accordance with Section 4.4.
5.3 No storage of requests for later retrieval. Requests sent to Azure OpenAI carry the store:false parameter: the service does not keep the prompts or the responses for later retrieval. NEXT BP does not use the stored completions, assistants, files, vector stores, batch or fine-tuning features of Azure OpenAI. The abuse monitoring in Section 5.4 does, however, lead Microsoft to temporarily store all requests and all responses.
5.4 Abuse monitoring by Microsoft. Microsoft temporarily stores all requests sent to Azure OpenAI and all responses, to monitor for and prevent abusive or harmful uses or outputs of the service (abuse monitoring). Microsoft's contract sets no duration for this storage. Only data that has triggered its automated systems may be reviewed by authorised Microsoft employees; for EU Data Boundary deployments, those employees are located in the European Economic Area. Microsoft's terms (Privacy & Security Terms) also allow its personnel located outside the EU Data Boundary to access data processing systems inside it remotely, as necessary to operate, troubleshoot, support and secure its services. Microsoft does not use this content to train generative AI foundation models without its customer's documented instructions, and NEXT BP gives no such instructions (Section 5.2). On 2 October 2026, NEXT BP applied for modified abuse monitoring, which removes this storage; Microsoft refused it on 4 October 2026, as it reserves it for customers managed by its account teams. This storage therefore takes place.
5.5 Web search. The Excel agent can propose a web search. The search query, written by the model, is shown to the User, and it is sent to Exa (Annex 3) only if the User approves it. The query may contain names or amounts taken from Client Data. Web search is not offered in a conversation once it has used document analysis features.
5.6 No automated decision. The Software produces suggestions (extracted values, answers, classifications, matches) linked to the words of the source document so that the User can check them. It makes no decision producing legal effects concerning Data Subjects or similarly significantly affecting them: the Client and its Users validate each result and remain responsible for their conclusions.
5.7 Provider chosen by the Client. When the Client saves in the Software an API key of an AI or OCR provider with which it has contracted itself, the requests concerned are sent to that provider, under the Client's account and on the terms the Client accepted. That provider is chosen by the Client and bound to it by its own contract: it is not a Sub-processor of NEXT BP and is not listed in Annex 3. The Client is responsible for checking that this contract meets Article 28 GDPR and, where data is transferred, Chapter V. Sections 5.2 to 5.4 do not apply to those requests; Section 5.1 still binds NEXT BP. The Client may remove its key at any time; later requests go back to the providers in Annex 3.
6. Audits
6.1 Documentation first. On request, NEXT BP provides the Client with the documentation that demonstrates its compliance: this DPA and its Annexes, answers to a reasonable security questionnaire, and the certifications and reports that Microsoft makes available for its hosting services (SOC 3 report and ISO certificates published on the Microsoft Service Trust Portal).
6.2 On-site audit. If the Client reasonably considers that this documentation is not sufficient to demonstrate compliance with this DPA, it may carry out, itself or through an independent auditor bound by confidentiality who is not a competitor of NEXT BP, an on-site audit or an audit by remote access, at most once per twelve-month period, with at least thirty (30) days' written notice. The scope, date and duration are agreed in advance. The audit takes place during business hours, without unreasonably disrupting NEXT BP's activity and without access to the data of other clients or to the facilities of Sub-processors, which are covered by their own audit reports.
6.3 Additional audits. The limit of one audit per year does not apply to an audit required by a Supervisory Authority, to an audit carried out following a Personal Data Breach affecting Client Data, or to an audit justified by serious indications that NEXT BP does not comply with this DPA, which the Client states in writing. For these audits, the notice period is reduced to ten (10) business days.
6.4 Costs. Each party bears its own costs. The Client bears the costs of the audit and of its auditor, unless the audit reveals a material breach by NEXT BP of its obligations under this DPA, in which case NEXT BP bears the reasonable costs of the audit. NEXT BP remedies any breach identified without undue delay.
7. End of Processing: Return and Deletion
7.1 Data already deleted during the subscription. Most Client Data are deleted during the subscription in accordance with the retention periods in Annex 1: document content submitted for OCR, analysis or the Excel agent is deleted at most 24 hours after upload. Workbooks remain in the Client's own Excel files.
7.2 Export. Until the end of the Principal Agreement, the Client can export the data that NEXT BP still holds, in particular engagements of the engagement agent, from the Software.
7.3 Deletion. At the end of the Principal Agreement, NEXT BP deletes all Client Data within thirty (30) days, unless the Client asks, within that period, for the return of data still held; NEXT BP then returns them in a structured, commonly used format and deletes them afterwards. Copies in database backups disappear when the backups expire, within seven (7) days after deletion. NEXT BP keeps no copy, unless Union or Member State law requires storage of the Personal Data. The requests and responses that Microsoft temporarily stores for abuse monitoring (Section 5.4) are subject to Microsoft's terms; they are not covered by the deletion within thirty (30) days above, because NEXT BP cannot delete them for each Client; Microsoft's contract sets no duration for this storage.
7.4 Certificate. On request, NEXT BP provides the Client with a written certificate of deletion.
8. Transfers Outside the European Economic Area
8.1 Client Data are hosted and processed within the European Union, except for the transfers described in Annex 4. By accepting this DPA, the Client instructs NEXT BP to carry out these transfers. NEXT BP makes no other transfer to a third country or an international organisation, except on the documented instructions of the Client or to fulfil a requirement of Union or Member State law to which it is subject, and always in accordance with Chapter V of the GDPR.
8.2 Where a Sub-processor is located outside the European Economic Area, or may access data from outside it, the transfer is covered by the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework for certified recipients, or by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. Annex 4 sets out the mechanism used for each recipient. The Client can obtain a copy of these safeguards by writing to privacy [at] blast-audit.com.
9. Obligations of the Client
9.1 The Client ensures that the Processing it entrusts to NEXT BP has a legal basis and that the Data Subjects have received the information required by Articles 13 and 14 of the GDPR.
9.2 The Client submits to the Software only the documents necessary for its assignments. The documents processed may incidentally contain special categories of Personal Data or data relating to criminal convictions and offences (for example, a sick-leave line on a payslip or a court decision in a litigation file). The Client remains responsible for deciding to submit them; NEXT BP applies to them the additional safeguards described in Annex 1.
9.3 The Client's instructions comply with Data Protection Legislation. The Client designates its account owner as NEXT BP's contact for this DPA and keeps that person's e-mail address up to date in the Software.
10. Liability
Each party is liable for the damage it causes in breach of this DPA under the conditions and within the limits of the Principal Agreement, including the specific cap for breaches of data protection obligations set out in Section 11 of the Terms and Conditions. These limits do not apply to the rights of Data Subjects under Article 82 of the GDPR, nor to administrative fines imposed on a party, which remain borne by that party.
11. Precedence, Term and Governing Law
11.1 Precedence. In the event of a conflict between this DPA and any provision of another agreement between the parties, whether concluded before or after this DPA, including the Terms and Conditions, the EULA and any order form or quote, the DPA prevails for everything relating to the Processing of Personal Data. A provision that gives Personal Data greater protection is not a conflict.
11.2 Term. This DPA applies from the Client's acceptance of the Terms and Conditions, including at the start of a free trial, and remains in force as long as NEXT BP processes Client Data.
11.3 Signature. A version of this DPA signed by NEXT BP can be obtained on request at privacy [at] blast-audit.com.
11.4 Language. This DPA is published in French, English and Spanish. In the event of a discrepancy, the French version prevails.
11.5 Governing law. This DPA is governed by French law. Any dispute relating to it falls within the jurisdiction of the courts designated in the Terms and Conditions.
11.6 Amendment. NEXT BP informs the Client of any amendment to this DPA at least thirty (30) days before it takes effect, by e-mail to the address of the Client's account owner. An amendment cannot reduce the protection of Client Data without the Client's written agreement. Updates to Annex 3 follow Section 4.4.
12. Non-compliance with the DPA and termination
12.1 Suspension. Without prejudice to the GDPR, if NEXT BP breaches its obligations under this DPA, the Client may instruct it in writing to suspend the Processing of Client Data until it complies or until termination. NEXT BP promptly informs the Client if it is unable to comply with this DPA, for whatever reason.
12.2 Termination by the Client. The Client may terminate the Principal Agreement, insofar as it concerns the Processing of Personal Data, by e-mail to privacy [at] blast-audit.com, with immediate effect, if:
(a) the Processing has been suspended under Section 12.1 and compliance with this DPA is not restored within a reasonable time and in any event within one month of the suspension;
(b) NEXT BP is in substantial or persistent breach of this DPA or of its obligations under the GDPR;
(c) NEXT BP fails to comply with a binding decision of a competent court or of the competent Supervisory Authority regarding its obligations under this DPA or the GDPR.
The thirty-day cure period in Section 13.3 of the Terms and Conditions and Section 8.2 of the EULA does not apply to these cases.
12.3 Termination by NEXT BP. NEXT BP may terminate the Principal Agreement, insofar as it concerns the Processing of Personal Data, where, after NEXT BP has informed the Client that an instruction infringes Data Protection Legislation (Section 4.2), the Client maintains that instruction.
12.4 After termination. Section 7 applies.
12.5 Refund. Where the Client terminates under Section 4.4(d) or Section 12.2, NEXT BP refunds the portion of the subscription fees paid in advance that covers the period remaining after the effective date of termination, calculated pro rata by the number of days. The refund is made within thirty (30) days of the effective date, to the payment method used. It is without prejudice to the Client's other rights and remedies.
Annex 1 — Description of the Processing
Parties. Controller: the Client, identified by the information it provides when it signs up and subscribes. Contact person: the account owner, at the e-mail address recorded in the Software, or the person the Client designates at privacy [at] blast-audit.com; data protection officer: the one the Client indicates, if any. Date of accession: date of acceptance of the Terms and Conditions. Processor: NEXT BP, French simplified joint-stock company (société par actions simplifiée, SAS), 127 rue de la Tour, 75016 Paris, France, RCS Paris 920 753 233. Contact person: the president of NEXT BP, privacy [at] blast-audit.com. NEXT BP has not designated a data protection officer.
Categories of Data Subjects. Natural persons whose data appear in the documents the Client submits: officers, employees, shareholders, customers, suppliers and other counterparties of the entities the Client audits or advises, bank account holders, signatories; and the Client's Users, insofar as their names or actions appear in Client Data (for example, in an engagement's task log).
Categories of Personal Data. Identification and contact data; professional data (position, employer); financial and banking data (account numbers, balances, transactions, invoices, payments); payroll and human resources data appearing on payslips and payroll records, which may include the social security number; tax data; contractual data; signatures; any other data contained in the documents submitted; voice recordings of Users when they use voice input, and the resulting transcripts.
Special categories of data and data relating to offences. Not sought. They may be present incidentally in documents (for example, health data on a payslip, trade union dues or a court decision). Additional safeguards: processing limited to the task requested by the User; retention limited to the periods below; access by NEXT BP personnel limited to the cases in Section 4.3; the measures of Annex 2.
Frequency. Continuous, at each action of a User or of the engagement agent.
Nature of the Processing. Receipt, hosting, optical character recognition (OCR), analysis by AI models, extraction of values, answers to questions about documents, classification, matching between workpapers and documents, web search approved by the User, transcription of voice input, display, export and deletion.
Purpose. To provide the functions of the Software that the Users request: reading and analysing audit documents, extracting values into workpapers, linking each value to its source, carrying out the tasks of the engagement agent, importing files from the Client's own cloud storage (Google Drive, Microsoft 365), and answering requests from the AI assistants that the Client connects to the MCP server.
Duration of the Processing. The term of the Principal Agreement, then until Client Data are deleted or returned under Section 7; for each category of data, the retention periods below apply.
Retention.
| Data | Retention |
|---|---|
| Document content submitted for OCR, document analysis (Probe, AI Extraction) and the Excel agent, and the related processing contexts | Deleted at most 24 hours after upload |
| Content of an engagement of the engagement agent (imported documents, task log, workpapers) | Kept while the engagement is open; deleted 30 days after it is closed. An engagement inactive for 6 months is closed after a 30-day notice |
| Requests from AI assistants through the MCP server | Content masked 10 minutes after the request; record deleted after 30 days |
| Voice input | NEXT BP does not keep the audio after transmitting it for transcription; the transcript follows the retention of the conversation it is entered in |
| Database backups, and deleted engagement files kept recoverable | 7 days, on a rolling basis |
| Operational logs (without document content) | 30 days |
| Files imported from the Client's Google Drive or Microsoft 365 | Not stored on import: passed to the User's browser, then subject to the rules above if submitted for processing |
| Workbooks | Not hosted by NEXT BP: they remain in the Client's Excel files |
Annex 2 — Technical and Organisational Measures
Hosting and location. The application, databases and file storage are hosted on Microsoft Azure in the France Central region (Paris). Part of the file storage is geo-replicated to the France South region (Marseille). AI and OCR processing runs on Microsoft resources in the Sweden Central region, in the European Union Data Zone.
Physical security. Client Data are hosted in Microsoft Azure data centres, whose physical security is covered by Microsoft's certifications and reports (Section 6.1).
Encryption. Data are encrypted in transit with TLS (version 1.2 or higher) between the Software, NEXT BP's servers and the Sub-processors. Databases, file storage and backups are encrypted at rest by Microsoft Azure with keys managed by Microsoft. The access tokens of the Google Drive and Microsoft 365 connectors are additionally encrypted by the application before they are stored.
Pseudonymisation. The Software must read document content to provide its functions and does not pseudonymise it; it limits its retention to the periods in Annex 1.
Isolation and access control. Each organisation's data are logically separated and every request is checked against the User's organisation and rights. Users authenticate through WorkOS, with single sign-on (SAML or OpenID Connect) available for organisations that use it. Access to production systems is limited to the named NEXT BP personnel who need it.
Key and secret management. Application secrets and keys are kept in the secret stores of Microsoft Azure (Container Apps secrets and Azure Key Vault), not in the source code. Connector tokens are encrypted with a key reserved for that purpose.
System configuration. The infrastructure is described as code (Terraform) and each change is reviewed before it is deployed.
Minimisation and deletion. Document content is kept only for the periods in Annex 1 and is deleted by automated purges, which retry any deletion that fails. Requests to Azure OpenAI are sent with store:false (Section 5.3); Microsoft does, however, temporarily store all requests and all responses for abuse monitoring (Section 5.4).
Portability and erasure. Export from the Software (Section 7.2), automated deletion according to the periods in Annex 1, and deletion or return at the end of the contract (Section 7.3).
Data quality. Each result is linked to its source in the document so that the User can check it (Section 5.6).
Logs and telemetry. Operational logs and error reports are designed not to contain document content; logs are kept 30 days. Product analytics record events without document content.
Backups and continuity. Databases are backed up automatically and backups are kept 7 days, which allows a restore after an incident.
Vulnerability management. NEXT BP publishes a vulnerability disclosure policy (security [at] blast-audit.com), keeps its dependencies up to date and fixes vulnerabilities according to their severity.
Incident handling. Incidents are handled by NEXT BP, which notifies the Client of Personal Data Breaches under Section 4.8.
Governance. The president of NEXT BP is responsible for security and data protection.
Certifications. NEXT BP holds an ISO/IEC 27001:2022 certificate for Blast Audit (design, development, operations and support), issued on 27 August 2026 by Sensiba Australia Pty Ltd and provided on request (Section 6.1). For hosting, it also relies on Microsoft Azure's certifications.
Annex 3 — Sub-processors
List dated October 5, 2026.
A. Sub-processors (Client Data)
Changes are announced under Section 4.4.
| Sub-processor (entity) | Service | Personal data | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Limited, Ireland) | Hosting of the application, databases, file storage, queues and logs | All Client Data | France Central (Paris); geo-redundant copy in France South (Marseille) | None: EU hosting (EU Data Boundary). Microsoft Products and Services Data Protection Addendum |
| Azure OpenAI (Microsoft Ireland Operations Limited) | AI analysis of documents, answers, classification | Text and images of documents, User instructions, results | Sweden Central, EU Data Zone | Possible remote access by Microsoft personnel located outside the EU Data Boundary, to operate, troubleshoot, support and secure the service: 2021 Standard Contractual Clauses (Module 3, processor to processor) between Microsoft Ireland Operations Limited and Microsoft Corporation, and EU-U.S. Data Privacy Framework (Microsoft Corporation), under the Microsoft Data Protection Addendum |
| Azure AI Content Understanding (Microsoft Ireland Operations Limited) | Optical character recognition (OCR) | Page images and text of documents | Sweden Central, EU Data Zone; results deleted from Microsoft once read | None: processing in the EU. Microsoft Data Protection Addendum |
| Azure AI Speech (Microsoft Ireland Operations Limited) | Transcription of voice input, when enabled | User's voice, transcript | Sweden Central | None: processing in the EU. Microsoft Data Protection Addendum |
| Azure Communication Services (Microsoft Ireland Operations Limited) | Transactional e-mail sent by the Software | Recipient's name and e-mail address, message content | Europe (data at rest) | EU storage; Microsoft Data Protection Addendum (SCC and DPF of Microsoft Corporation for any transit) |
| Cloudflare (Cloudflare, Inc., United States) | Hosting and delivery of the website and the web dashboard; receipt of support e-mail sent to reply.blast-audit.com | IP addresses and request data; content and attachments of support e-mails | Global network | EU-U.S. Data Privacy Framework (Cloudflare, Inc.) and Standard Contractual Clauses (Modules 2 and 3) |
| Sentry (Functional Software, Inc., United States) | Error monitoring | Technical error data, User identifier, browser and device data | European Union (Frankfurt, Germany) for events; account data in the United States | EU-U.S. Data Privacy Framework (Functional Software, Inc.) and Standard Contractual Clauses (Modules 2 and 3) |
| Exa (Exa Labs, Inc., United States) | Web search for AI features, only on the User's approval | Search queries written by the model | United States | Standard Contractual Clauses (Modules 2 and 3) |
Subject matter, nature and duration. The subject matter and nature of the Processing are set out in the "Service" and "Personal data" columns. Each Sub-processor processes Client Data for the term of the Principal Agreement, within the retention periods of Annex 1, except: Azure OpenAI, which does not keep requests or responses for later retrieval (Section 5.3) but temporarily stores all of them for abuse monitoring, for a duration Microsoft's contract does not set (Section 5.4); Azure AI Content Understanding, whose results are deleted once read and at most 24 hours after the operation is created.
B. Other providers of NEXT BP (Section 2.3), for information
These providers process the data for which NEXT BP acts as Controller (Section 2.3). They are not Sub-processors within the meaning of this DPA.
| Provider (entity) | Service | Personal data | Location of processing | Transfer mechanism |
|---|---|---|---|---|
| Stripe (Stripe Payments Europe, Limited, Ireland; Stripe, LLC, United States) | Payment and invoicing | Billing contact, company details, VAT number, payment data | European Union and United States | EU-U.S. Data Privacy Framework (Stripe, LLC) and Standard Contractual Clauses |
| WorkOS (WorkOS, Inc., United States) | Authentication, single sign-on, organisation management | Name, e-mail address, organisation, identity provider identifiers, IP address | United States | Standard Contractual Clauses (Modules 2 and 3) |
| PostHog (PostHog, Inc., United States) | Product analytics | Pseudonymous identifiers, e-mail address of signed-in Users, usage events | European Union (Frankfurt, Germany) | EU hosting; EU-U.S. Data Privacy Framework (PostHog, Inc.) and Standard Contractual Clauses (Module 2) for any access from the United States |
| Google Workspace (Google Ireland Limited, Ireland; Google LLC, United States) | NEXT BP's e-mail, including e-mail sent to support [at] blast-audit.com, forwarded to reply.blast-audit.com | Sender's name and e-mail address, content and attachments of the e-mail | Google data centres worldwide | EU-U.S. Data Privacy Framework (Google LLC) and Standard Contractual Clauses |
| Customer.io (Peaberry Software Inc., United States) | Account and subscription lifecycle e-mail | Name, e-mail address, organisation, trial and subscription events | European Union (Belgium) | EU-U.S. Data Privacy Framework (Peaberry Software Inc.) and Standard Contractual Clauses (Module 2) |
Annex 4 — Transfers Outside the European Economic Area
A. Client to NEXT BP. The Client and NEXT BP are established in the European Union; the communication of Client Data to NEXT BP is not a transfer to a third country. If the Client is established outside the European Economic Area, the parties agree on the appropriate safeguards before any Processing.
B. NEXT BP to Sub-processors and other providers. For each Sub-processor or other provider in Annex 3 that is established in the United States or may access data from there:
- if it is certified under the EU-U.S. Data Privacy Framework, the transfer is based on Commission Implementing Decision (EU) 2023/1795 of 10 July 2023;
- otherwise, or in addition, the transfer is governed by the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Three (processor to processor) for Client Data, incorporated into the Sub-processor's data processing agreement. Where NEXT BP acts as Controller (Section 2.3), Module Two (controller to processor) applies.
C. Supplementary measures. Data are encrypted in transit and at rest; Client Data hosted by NEXT BP remain in the European Union; only the data necessary for each service are sent to the Sub-processor.
D. Copy. The Client can obtain a copy of the safeguards applicable to a Sub-processor by writing to privacy [at] blast-audit.com.