Data Processing Agreement

Data Processing Agreement (DPA)

Effective Date: 8 January 2026

This Data Processing Agreement (“DPA”) is entered into between Bluedot (Twiso, Inc.), 30A Abbey, San Francisco, CA 94114, United States (“Bluedot”, “Processor”) and each Customer (“Customer”, “Controller”). This DPA forms part of the Order Form, Terms of Use, or Service Agreement between the parties (“Agreement”).

In the event of any conflict between this DPA and the Agreement regarding data protection matters, this DPA shall prevail.

1. INTRODUCTION
This DPA governs Bluedot’s Processing of Personal Data on behalf of Customer in connection with the Services. The Parties agree to comply with applicable data protection laws, including the GDPR and UK GDPR (“Applicable Data Protection Law”).

If Applicable Data Protection Law changes, the Parties shall cooperate in good faith to ensure continued lawful Processing.

2. ROLES AND SCOPE
Customer acts as the Controller and Bluedot acts as the Processor for Customer Personal Data, except where Bluedot acts as an independent Controller for limited purposes such as billing, fraud prevention, security, or legal compliance.

Bluedot shall:

3. PROCESSOR OBLIGATIONS
Bluedot shall:

Customer audit requests shall be limited to reasonable frequency and subject to confidentiality and security requirements.

4. SECURITY MEASURES
Bluedot maintains appropriate technical and organizational measures, including:

Infrastructure is hosted on AWS in data centers located in the EEA and/or other regions as necessary to provide the Services.

5. PERSONNEL
Access to Personal Data is limited to authorized personnel bound by confidentiality obligations and trained in security and privacy practices.

6. ASSISTANCE TO CUSTOMER
Bluedot shall reasonably assist Customer with:

7. SUB-PROCESSORS
Customer provides general written authorization for the use of Sub-processors.

Bluedot shall:

8. CUSTOMER OBLIGATIONS
Customer is responsible for ensuring lawful collection and use of Personal Data and providing appropriate notices and consents where required.

Customer agrees not to submit special categories of personal data unless appropriate safeguards and a valid legal basis are in place.

9. PERSONAL DATA BREACH
Bluedot shall notify Customer without undue delay and, where feasible, within forty‑eight (48) hours after becoming aware of a confirmed Personal Data Breach.

Bluedot will provide reasonable assistance to support Customer’s breach response obligations.

10. DATA RETENTION, RETURN AND DELETION
Upon termination of the Agreement:

11. GOVERNMENT REQUESTS
Bluedot shall review the legality of government or law enforcement requests, challenge unlawful or disproportionate requests where appropriate, and notify Customer unless legally prohibited.

12. INTERNATIONAL TRANSFERS
Where Personal Data is transferred outside the EEA, UK, or Switzerland, such transfers shall rely on:

13. LIABILITY
Liability arising under this DPA shall be governed by the limitations and exclusions set out in the Agreement.

14. GOVERNING LAW
This DPA shall be governed by the laws of Ireland.

15. INCORPORATION OF STANDARD CONTRACTUAL CLAUSES
The EU Standard Contractual Clauses (2021/914) are incorporated by reference and shall apply to applicable international data transfers.

For the purposes of the Standard Contractual Clauses:

Annex information is provided in the Exhibits below.

EXHIBIT 1 – PROCESSING DETAILS
Purpose: Provision of Bluedot SaaS meeting documentation services
Data Subjects: Employees, contractors, customers, and meeting participants
Data Types: Name, email, meeting metadata, transcripts, audio/video content
Special Categories: Not intended to be processed. Customer is responsible for avoiding submission unless legally permitted.
Duration: For the duration of the Agreement and the retention period described above.

EXHIBIT 2 – SECURITY MEASURES

EXHIBIT 3 – CCPA / CPRA TERMS
Bluedot acts as a Service Provider / Processor and: