Datenschutzerklärung
Wie Blast Audit Ihre Daten erhebt, nutzt, weitergibt und schützt, wo sie verarbeitet werden, wie lange sie gespeichert werden und welche Rechte Sie haben.
Zuletzt aktualisiert: 5. Oktober 2026
This Privacy Policy explains how NEXT BP processes personal data when you visit blast-audit.com or use Blast Audit: the Excel add-in, the web dashboard, the connectors to cloud storage, the MCP server and the engagement agent (the "Software"). It is the information required by Articles 13 and 14 of the General Data Protection Regulation (GDPR).
1. Who We Are
The controller is NEXT BP, a French simplified joint-stock company (SAS) with a share capital of €100, registered with the Paris Trade and Companies Register under number 920 753 233, whose registered office is at 127 rue de la Tour, 75016 Paris, France.
For any question about your personal data or to exercise your rights, write to privacy [at] blast-audit.com. NEXT BP has not appointed a data protection officer; this address reaches the person in charge of data protection at NEXT BP.
The Software is intended for professionals. It is not intended for children.
2. Controller or Processor
NEXT BP processes personal data in two capacities.
- As controller, for the data it needs to run its own business: visitors to the website, accounts and authentication of users, billing, support, security, product analytics, prospecting and sales relations. This Policy describes these processing operations.
- As processor, for the documents and content that audit and accounting firms submit to the Software (for example bank statements, invoices, contracts or payroll records) and the personal data they contain. The firm that uses Blast Audit is the controller of these data and decides what it submits. NEXT BP processes them only on that firm's instructions, under the Data Processing Agreement (DPA).
If your data appear in a document that a firm has submitted to Blast Audit, contact that firm to exercise your rights. If you write to us, we forward your request to the firm concerned.
3. Data We Collect and Where It Comes From
- Identity and account data: name, e-mail address, organisation, role, language, identifiers from your identity provider when your organisation uses single sign-on, sign-in dates.
- Billing data: name of the billing contact, company details, address, VAT number, subscription, invoices and payment status. Card details are entered on Stripe's pages; we never receive the full card number.
- Usage data: features used, number of pages processed, AI credits consumed, technical identifiers, browser and device data, IP address, pages viewed.
- Support and communications: messages, e-mails and attachments you send us, and the e-mails we send you.
- Prospecting data: what you enter in our contact and demo forms (name, professional e-mail address, phone number, company, job title, team size, message).
- Connector data: when you connect Google Drive or Microsoft 365, the access tokens and the account identifier that the provider returns.
- Content submitted to the Software: documents, extracted values, instructions, voice input. NEXT BP processes this content as processor (Section 2).
Most of these data come from you. Some come from other sources:
- your organisation's administrator, who invites you and assigns your role;
- your organisation's identity provider, through WorkOS, when single sign-on is used;
- Stripe, for the status of payments;
- Google or Microsoft, when you connect a connector.
4. Purposes, Legal Bases and Retention
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Create and manage your account, authenticate you, manage your organisation's users | Identity and account data | Performance of the contract with your organisation (Art. 6(1)(b)); for users invited by their organisation, our legitimate interest and that of the organisation in giving them access to the service (Art. 6(1)(f)) | For the life of the account, then deleted within 30 days after it is closed |
| Provide the features of the Software, apply quotas and meter usage | Usage data, connector data | Performance of the contract (Art. 6(1)(b)) | For the life of the account, then deleted within 30 days after it is closed |
| Invoice, collect payments, keep accounting records | Billing data | Performance of the contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting records | For the life of the subscription; invoices and accounting records: 10 years (Article L. 123-22 of the French Commercial Code) |
| Answer support requests | Support and communications, identity data | Performance of the contract for customers; legitimate interest in answering visitors and prospects (Art. 6(1)(f)) | Until you ask us to delete them. Automatic deletion 24 months after the last message (90 days for unanswered conversations from visitors who are not signed in) is not active yet |
| Send service e-mails: invitations, onboarding, trial and billing reminders | Identity data, language, organisation, plan, subscription events | Performance of the contract (Art. 6(1)(b)); for onboarding advice, our legitimate interest in helping customers use the service (Art. 6(1)(f)) | For the life of the account |
| Secure the service, prevent fraud and abuse, detect errors | IP address, technical logs, error reports | Legitimate interest in protecting the service and its users (Art. 6(1)(f)) | Logs: 30 days; error reports: 90 days |
| Product analytics in the Excel add-in | User identifier, e-mail address, organisation, usage events | Legitimate interest in understanding how the product is used and improving it (Art. 6(1)(f)) | 25 months |
| Anonymous audience measurement on the website and the dashboard, without consent | Pages viewed, interactions, IP address and browser user agent, which PostHog turns into a hash with a salt that changes every day; PostHog does not store the IP address | Legitimate interest in measuring the audience of the website and the dashboard (Art. 6(1)(f)) | 25 months |
| Audience measurement and session recording on the website, and product analytics in the dashboard, with your consent | Browser identifier, pages viewed, interactions, recordings with text masked; when you are signed in, user identifier, e-mail address and organisation | Consent (Art. 6(1)(a)), given in the cookie banner | Events: 25 months; recordings: 90 days |
| Usage statistics of the Excel add-in | Session and visitor identifiers, page, referrer, country and city derived from the IP address, which is kept only in hashed form | Legitimate interest in measuring the use of the add-in (Art. 6(1)(f)) | 25 months |
| Prospecting and sales relations with professionals | Prospecting data | Legitimate interest in presenting our services to professionals (Art. 6(1)(f)) | 3 years after the last contact from the prospect |
| Handle feedback on the product | Organisation, e-mail address, content of the feedback | Legitimate interest in improving the product (Art. 6(1)(f)) | 3 years |
| Comply with legal obligations, establish or defend legal claims | The data concerned | Legal obligation (Art. 6(1)(c)); legitimate interest (Art. 6(1)(f)) | Statutory limitation periods (5 years in commercial matters) |
Where we rely on our legitimate interest, you can object at any time (Section 8).
5. Recipients
Personal data are accessible only to the NEXT BP personnel who need them. We share them with the following service providers, which act on our instructions:
- Microsoft (Microsoft Ireland Operations Limited): hosting on Microsoft Azure in France; Azure OpenAI (EU Data Zone, resource in Sweden) and Azure AI Content Understanding for document analysis and OCR; Azure AI Speech for voice input; Azure Communication Services for transactional e-mail, including our support replies;
- Cloudflare: hosting of the website and the dashboard, receipt of support e-mail sent to reply.blast-audit.com;
- Google (Google Workspace): NEXT BP's e-mail, including e-mail sent to support [at] blast-audit.com, which it forwards to reply.blast-audit.com;
- WorkOS: authentication and single sign-on;
- Stripe: payment and invoicing;
- PostHog: product analytics and audience measurement;
- Sentry: error monitoring;
- Customer.io: service e-mails linked to the account and the subscription;
- Exa: web search proposed by the Excel agent, only when you approve the search query;
- Discord: internal notification of contact form submissions and product feedback to our team.
The location of each provider and the safeguards for transfers are listed in Annex 3 of the Data Processing Agreement, which is our dated sub-processor list.
We may also disclose data to public authorities when the law requires it, to our professional advisers (lawyers, auditors) bound by confidentiality, and to an acquirer in the event of a merger or sale of the business, after informing you.
We do not sell personal data.
6. Transfers Outside the European Economic Area
We host our databases and files in the European Union. Some providers are established in the United States or may access data from there: Cloudflare, Google, Stripe, WorkOS, Sentry, Customer.io, PostHog, Exa and Discord. These transfers rely on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework when the recipient is certified (Cloudflare, Google, Stripe, PostHog, Sentry, Customer.io), and on the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914) in the other cases or in addition. You can obtain a copy of these safeguards by writing to privacy [at] blast-audit.com.
7. Data Retention
The retention period of each category of data is given in the table in Section 4. At the end of the period, data are deleted or anonymised. Database backups are kept 7 days, so a deleted item disappears from backups within 7 days.
For document content that NEXT BP processes as processor, the periods are set in Annex 1 of the Data Processing Agreement. In short:
- content submitted for OCR, document analysis or the Excel agent is deleted at most 24 hours after upload;
- the content of an engagement of the engagement agent is kept while the engagement is open and deleted 30 days after it is closed;
- operational logs, which contain no document content, are kept 30 days.
8. Your Rights
You have the right of access, rectification and erasure, the right to restrict processing, the right to data portability, and the right to object to processing based on our legitimate interest, including prospecting, which you can stop at any time without giving a reason. Where processing is based on your consent, you can withdraw it at any time; for cookies, use the Cookie settings link at the bottom of every page. Under French law, you can also give instructions on what happens to your data after your death.
To exercise these rights, write to privacy [at] blast-audit.com. We answer within one month; this period may be extended by two months for complex requests, in which case we tell you. We may ask for information to confirm your identity.
You can lodge a complaint with the French data protection authority, the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr), or with the authority of the Member State where you live or work.
9. Mandatory and Optional Data
Your name, e-mail address and organisation are required to create an account; without them, we cannot give you access to the Software. Billing data are required to take out a paid subscription. In our forms, required fields are marked; the other fields are optional. Accepting audience measurement cookies is optional and has no effect on access to the website.
10. Artificial Intelligence and Automated Decisions
- We do not use your data or the content you submit to train, fine-tune or improve artificial intelligence models, and our AI provider, Microsoft, is contractually bound not to do so either.
- If your organisation saves its own API key for another AI or OCR provider, the requests concerned are sent to that provider under the contract your organisation has with it; that provider is not our processor (Section 5.7 of the DPA).
- Requests to Azure OpenAI are sent with the
store:falseparameter: the service does not keep them for later retrieval, subject only to the abuse monitoring described below. - Microsoft temporarily stores all requests sent to Azure OpenAI and all responses, to monitor for and prevent abusive or harmful uses or outputs of the service (abuse monitoring). Microsoft's contract sets no duration for this storage. Only data that has triggered its automated systems may be reviewed by authorised Microsoft employees; for EU Data Boundary deployments, those employees are located in the European Economic Area. Microsoft's terms (Privacy & Security Terms) also allow its personnel located outside the EU Data Boundary to access data processing systems inside it remotely, as necessary to operate, troubleshoot, support and secure its services. On 2 October 2026, NEXT BP applied to Microsoft for modified abuse monitoring, which removes this storage; Microsoft refused it on 4 October 2026. This storage therefore takes place.
- The Software makes no decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. Its results are suggestions that the user checks.
11. Cookies
The cookies and browser storage used by the website and the dashboard, their purpose, duration and how to change your choice are described in our Cookie Notice.
12. Specific Features
Voice input. When voice input is enabled, the add-in records your voice while you dictate and sends the audio to our servers, which have it transcribed by Azure AI Speech fast transcription in the Sweden Central region. Microsoft does not retain or store the audio (Microsoft documentation). NEXT BP does not keep the audio after transmitting it for transcription; the transcript is returned to you. This processing is carried out on behalf of your organisation, under the DPA.
Cloud storage connections (Google Drive, Microsoft 365). If you connect a Google Drive or Microsoft 365 account, Blast Audit reads your files so that you can choose and import documents from Excel. We never create, modify, share or delete files in your cloud storage. The access tokens are encrypted and stored for your account, and deleted when you disconnect the account from the Blast Audit dashboard. Disconnecting does not withdraw the authorisation on the provider's side: you can also revoke it from the permissions page of your Google or Microsoft account. Imported files are passed to your browser without being stored on our servers; if you submit them for processing, the retention rules in Section 7 apply.
Google user data. Blast Audit's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We request the scope https://www.googleapis.com/auth/drive.file, which gives Blast Audit access only to the files you choose in the Google Drive picker. We use it only to download the file you select so that it can be displayed and linked to cells inside your own Excel workbook. We do not use Google user data for advertising, we do not sell it, we do not use it to train artificial intelligence or machine learning models, and we do not transfer it to third parties except as necessary to provide the feature (our hosting provider Microsoft Azure) or as required by law.
MCP server. If you connect an AI assistant of your choice (for example Claude or ChatGPT) to Blast Audit through the MCP server, you authorise it with your Blast Audit account through WorkOS. The assistant's requests and the results returned by your add-in pass through our servers: their content is masked 10 minutes after the request and the record is deleted after 30 days. The assistant you connect is operated by its own provider, under that provider's terms; it is not a NEXT BP sub-processor. We keep the list of connected assistants (name, date of last use) so that you can see and disconnect them.
Engagement agent. If your organisation uses the engagement agent, the documents imported into an engagement, the task log and the workpapers are kept on our servers while the engagement is open, so that the agent can work without Excel open, and deleted 30 days after the engagement is closed.
Support. You can contact us through the support chat or by e-mail. Conversations and their attachments are stored on our servers, on Microsoft Azure in the European Union. When you have not read a reply from our team, we send it to you by e-mail through Azure Communication Services. Your replies to our support e-mails, and e-mails sent to reply.blast-audit.com, are received by Cloudflare's e-mail service and passed to our servers. E-mails sent to support [at] blast-audit.com first reach Google Workspace, our e-mail provider, which forwards them to reply.blast-audit.com.
13. Security
We protect personal data with technical and organisational measures appropriate to the risk: hosting in the European Union, encryption in transit (TLS) and at rest, separation of each organisation's data, restricted access and automatic deletion of document content. These measures are described in Annex 2 of the Data Processing Agreement. To report a vulnerability, see our security page.
14. Changes to this Policy
We may update this Policy to reflect a change in our processing or in the law. The date at the top shows the latest version. We inform users of any material change by e-mail or in the Software before it takes effect.
15. Contact
privacy [at] blast-audit.com
NEXT BP, 127 rue de la Tour, 75016 Paris, France