1.Scope and roles
This Addendum applies where an organisation (the "Customer") uses BLEUN to process personal data in Professional BLEUNs. For that processing the Customer is the controller and Perseids Ltd is the processor. Where Perseids Ltd processes data for its own account administration, security and billing, it acts as controller.
This Addendum forms part of the Terms of Service. For a countersigned copy, contact legal@bleun.ai.
2.Subject matter and nature of processing
- Subject matter: provision of the BLEUN Intent OS — objective interpretation, planning, agent coordination, document analysis, decision tracking and progress reporting.
- Duration: for the term of the Customer's subscription, plus retention periods stated in the Privacy Policy.
- Categories of data subjects: the Customer's personnel, collaborators and any individuals referenced in objectives or uploaded documents.
- Categories of personal data: identity and contact data, employment and business data, objective content, document content and agent activity records.
- Special-category data: not requested by BLEUN; the Customer must not upload it unless strictly necessary and lawful.
3.Processor obligations
- Process personal data only on the Customer's documented instructions, which include use of the product's features.
- Ensure personnel with access are bound by confidentiality and operate on a least-privilege basis.
- Implement and maintain appropriate technical and organisational measures.
- Assist the Customer with data subject requests, DPIAs and regulator engagement, so far as reasonably practicable.
- Delete or return personal data at the end of the engagement, subject to legal retention duties.
4.Security measures
- Encryption of data in transit and at rest with our infrastructure providers.
- Row-level access control scoping records to their owning account or workspace.
- Private document storage with short-lived, access-checked links.
- Authentication and role-based permissions inside Professional BLEUNs.
- Audit logging of agent actions, approvals and executions.
- Approval gates for sensitive, irreversible or external agent actions.
- Segregated environments and least-privilege administrative access.
Further detail is on the Security & Trust page. We do not claim certifications we do not hold.
5.Subprocessors
The Customer authorises the subprocessors listed at /subprocessors. Each is engaged under written terms imposing data protection obligations no less protective than this Addendum. We remain responsible for their performance. On request, we will notify the Customer of intended additions so it can object on reasonable data protection grounds.
6.AI processing
7.International transfers
Where personal data is transferred outside the UK or EEA, the parties rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses (module two, controller to processor), together with supplementary measures where required by a transfer risk assessment.
8.Personal data breach
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, with the information reasonably available to us, and will cooperate on investigation and remediation. Notification is not an acknowledgement of fault.
9.Audits and information
On reasonable written request, and no more than once per year unless required by a regulator, we will provide information necessary to demonstrate compliance with this Addendum. Where available, documentation and provider attestations satisfy audit rights before an on-site audit is considered.
10.Return and deletion
On termination, the Customer may export or delete Professional BLEUN content from the product. Remaining active-system data is deleted within a reasonable period, and encrypted backups age out on their rolling cycle. Data we must keep by law (for example billing records) is retained for the statutory period only.
11.Parties and contact
- Processor: Perseids Ltd, private limited company registered in the United Kingdom; company number To be confirmed; registered office To be confirmed.
- Data protection contact: privacy@bleun.ai.
- Governing law: the laws of England and Wales.
