Where your data is stored and for how long

What stays in your workbook, what reaches our servers in the EEA, how long document content is kept, and where to find our policies.

This page sums up what the Privacy Policy and the Data Processing Agreement say about where your data goes and how long it stays. Those two documents are the reference if anything here differs.

In your workbook

The documents you import and the snips you make are saved inside your Excel workbook. They stay wherever you store that file: your computer, a file server, SharePoint or OneDrive.

On our servers, while a task runs

Some features need our servers: OCR, and the automated analysis features. For those, the snipped images, the documents you submit and their metadata are sent to our servers over an encrypted connection and processed there.

That content is held only in short-lived processing contexts:

ProcessingHow long the content is kept
OCR, document analysis (Probe, AI Extraction) and the Excel agentAt most 24 hours after upload

An automated purge deletes expired contexts. If a deletion fails, it is retried on a later pass, so deletion can happen shortly after the deadline. Apart from temporary technical copies (caching, operational logs), which are purged regularly, the content of your documents is not stored, except in engagements (below).

Engagements (engagement agent)

If your organisation uses the engagement agent, the documents you import into an engagement, the task journal and the workpapers are kept on our servers while the engagement is open, so the agent can work without Excel open. They are deleted 30 days after the engagement is closed. Before that, you can export the engagement.

Where the servers are

Our infrastructure runs on Microsoft Azure, with production hosting in the European Economic Area, mainly in the France Central region. Where data is transferred outside the EEA, it is covered by safeguards such as the European Commission's Standard Contractual Clauses.

The companies that process data for us are listed, with where they process it, in Annex 3 of the Data Processing Agreement. For a security or privacy review, see also our Trust Center.

Account and billing data

To run your account we keep your name, email address, organisation and subscription details, and usage data such as the number of documents and pages processed. Payments are handled by Stripe; we do not store your full card number. We keep this data as long as we need it to provide the service and to meet billing, accounting and legal obligations.

Security and certifications

Data is encrypted in transit (TLS 1.2 or later) and at rest. Blast Audit has a SOC 2 Type 2 report and an ISO 27001:2022 certificate. More detail is on our Trust Center.

To report a vulnerability, see the Security page.

Your rights

You can ask to access, correct or delete your personal data, or object to its processing, by writing to privacy@blast-audit.com. For document content, these rights apply while a processing context is still live: once it has expired, we no longer hold the content.

Still stuck?

Email the team with what you tried and, if you can, a screenshot of what you see.

Email support