Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Blackbelt Labs OÜ ("Blackbelt Labs") and the customer of the Daslab service ("Customer"). It governs the processing of personal data that Customer submits to the Service.
It applies from the date Customer's account was created. Execution below produces a countersigned copy naming Customer's entity and does not alter the date from which the obligations apply.
Location and Sub-Processors
The application and the database operate in Frankfurt, Germany. Object storage is located in the European Union. Four sub-processors are engaged for all customers; three further sub-processors are engaged only where the relevant feature is used. The controlling list is Annex III below.
A row-by-row account of what is held where, on Daslab Cloud and on Customer-operated servers, is published at daslab.run/security.
Engaged for all customers
Engaged only where the relevant feature is used
Engaged only where the relevant feature is used. A workspace that does not use the feature is not processed by the sub-processor listed against it.
Kept current at daslab.run/subprocessors. We give 30 days notice before this list changes.
Clauses
1Relationship of the Parties
Customer is the controller and Blackbelt Labs OÜ ("Blackbelt Labs") is the processor in respect of Personal Data that Customer submits to the Service. Blackbelt Labs processes such Personal Data solely to provide the Service to Customer.
This DPA applies from the date Customer's account was created. Execution of this DPA produces a countersigned copy for Customer's records and does not alter the date from which the obligations apply.
Blackbelt Labs acts as a controller in respect of account registration, billing and operation of the Service. That processing is described in the privacy notice and is not governed by this DPA.
2Scope and Instructions
Blackbelt Labs processes Personal Data only on Customer's documented instructions. Customer's instructions comprise this DPA, the Terms of Service, and Customer's configuration and use of the Service.
Where Blackbelt Labs is required by applicable law to process Personal Data other than on Customer's instructions, it will inform Customer before processing, unless that law prohibits such notification.
Blackbelt Labs will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
Blackbelt Labs does not sell Personal Data and does not use the contents of Customer's scenes to train models.
3Confidentiality
Access to Personal Data is restricted to personnel who require access in order to provide the Service. Such personnel are bound by confidentiality obligations that survive the termination of their engagement.
4Security of Personal Data
Blackbelt Labs implements the technical and organisational measures set out in Annex II and will not materially reduce them during the term of this DPA.
Measures that are not implemented are stated in Annex II rather than omitted from it.
5Sub-Processors
Customer grants general authorisation for Blackbelt Labs to engage the sub-processors listed in Annex III, which is maintained at daslab.run/subprocessors.
Blackbelt Labs will give Customer 30 days notice before appointing or replacing a sub-processor. If Customer objects within that period, Blackbelt Labs will either refrain from the change in respect of Customer's Personal Data or, where that is not reasonably possible, Customer may terminate the affected part of the Service and receive a refund of the unused portion of any prepaid fees.
Each sub-processor is bound by data protection obligations no less protective than those set out in this DPA. Blackbelt Labs remains liable to Customer for the performance of each sub-processor.
6Rights of Data Subjects
Customer may access, export, rectify and delete Personal Data directly within the Service.
Where Customer is unable to do so, Blackbelt Labs will provide reasonable assistance with requests by data subjects to exercise rights of access, rectification, erasure, restriction of processing, portability and objection, taking into account the nature of the processing.
Where a data subject contacts Blackbelt Labs directly, Blackbelt Labs will not respond on Customer's behalf and will forward the request to Customer without undue delay.
7Personal Data Breaches
Blackbelt Labs will notify Customer of a personal data breach affecting Customer's Personal Data without undue delay and in any event within 72 hours of becoming aware of it.
The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the measures taken or proposed, and recommended actions. Where the information is not available at the time of notification, it will be provided in phases as it becomes available.
Security issues may be reported to security@daslab.run. Blackbelt Labs responds within two working days and states the action taken.
8Data Protection Impact Assessments
Blackbelt Labs will provide reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, limited to information concerning its processing that is not otherwise available to Customer.
9Return and Deletion of Personal Data
On termination, Customer may export Personal Data for a period of 30 days. Blackbelt Labs will delete it earlier at Customer's written request.
Following that period, Blackbelt Labs deletes Personal Data. Deletion of a scene removes its contents and prunes the commit chain that referenced them. Erasure of a workspace removes its scenes, its credentials and its machines' tokens.
Copies may persist in backups for up to 7 days following deletion, after which they age out. Blackbelt Labs does not restore backups in order to recover deleted data.
Blackbelt Labs retains Personal Data where required to do so by applicable law, including billing records.
10Audit and Information
Blackbelt Labs will make available to Customer the information necessary to demonstrate compliance with this DPA.
Customer may audit Blackbelt Labs once in any twelve month period, on 30 days written notice, at Customer's cost, during business hours, without unreasonable disruption to the Service, and subject to confidentiality. Blackbelt Labs may provide an equivalent third-party report in place of an on-site audit.
Information covering much of this scope is published at daslab.run/security, and a number of the measures in Annex II are implemented in publicly available source code.
11Transfers of Personal Data
Blackbelt Labs is established in the European Union and the Service operates in Frankfurt, Germany. Personal Data submitted by Customer is processed there.
The standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, module two (controller to processor), are incorporated into this DPA by reference and apply to any transfer of Personal Data that is subject to a cross-border transfer restriction under applicable data protection law. This DPA, together with its Annexes, constitutes their appendices.
Part A of Annex IV states the mechanism relied on for each regime. Part B states the onward transfers made by Blackbelt Labs in providing the Service.
If a transfer mechanism is invalidated, superseded or amended by a competent authority, Blackbelt Labs will implement the replacement mechanism without undue delay.
12Region-Specific Terms
United Kingdom. Where the UK GDPR applies, the International Data Transfer Addendum to the EU standard contractual clauses, issued under section 119A of the Data Protection Act 2018, applies to the transfer and forms part of this DPA.
Switzerland. Where the Swiss Federal Act on Data Protection applies, the standard contractual clauses apply as amended in accordance with guidance of the Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the competent supervisory authority is the FDPIC, and data subjects in Switzerland may enforce their rights in Switzerland.
Thailand. Where the Personal Data Protection Act B.E. 2562 applies, the transfer relies on appropriate safeguards under section 28 of that Act, constituted by the standard contractual clauses incorporated under clause 11.
United States. Where a state privacy law applies, Customer is the business or controller and Blackbelt Labs is the service provider or processor. Blackbelt Labs does not sell or share Personal Data, does not retain, use or disclose it for any purpose other than performing the Service, and does not combine it with Personal Data received from another source except as permitted by that law.
Other jurisdictions. Where any other applicable law restricts cross-border transfer and recognises contractual safeguards, the standard contractual clauses incorporated under clause 11 constitute those safeguards.
13Precedence, Amendment and Liability
In respect of Personal Data, this DPA prevails over the Terms of Service to the extent of any conflict.
Blackbelt Labs may amend this DPA. Material amendments will be notified 30 days in advance to the address recorded on Customer's countersigned copy. That copy records the version Customer agreed. The current version is published at daslab.run/dpa.
Liability under this DPA is subject to the limitations of liability in the Terms of Service, except to the extent applicable law does not permit such limitation.
Details of the Processing
Technical and Organisational Measures
Each measure listed is implemented as at the version stated above. Where a measure carries a reference, it can be verified independently. The final row states the measures that are not implemented.
International Transfers
Part A · Mechanism relied on, by regime
Part B · Onward transfers made by Blackbelt Labs
Customer Personal Data is processed in Frankfurt, Germany. Part B lists every transfer of it beyond that location made by Blackbelt Labs in providing the Service.
Signature
Complete the fields below to execute this DPA. A countersigned copy naming Customer's entity, recording version 1.0, is sent to the address given.
Questions concerning this DPA: privacy@daslab.run. Answered in writing within two working days.