Data Processing Agreement

Blackmount.ai Inc
Effective: October 1, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Blackmount.ai Inc, a Delaware corporation ("Blackmount", "Processor"), and the customer ("Customer", "Controller") under Blackmount's Terms of Service (the "Terms"). It applies where Blackmount processes Customer Personal Data on the Customer's behalf. Capitalised terms not defined here have the meaning given in the Terms.

1. Definitions, roles and instructions

1.1 Definitions. "Data Protection Law" means all data protection and privacy laws that apply to the processing of Customer Personal Data under the Terms, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws. "Customer Personal Data" means personal data that Blackmount processes on the Customer's behalf in providing the Services. "Personal data breach", "controller", "processor" and "data subject" have the meanings given in the GDPR.

1.2 Roles. The Customer is the controller and Blackmount the processor of Customer Personal Data. Blackmount processes it only on the Customer's documented instructions — the Terms, the order form, the Customer's configuration of the Services, and the Customer's written instructions — unless required by law, in which case Blackmount will inform the Customer before processing unless the law prohibits it. Blackmount will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.

Exception — template improvement. For the limited purpose described in Terms §5.3 (deriving de-identified, generalised patterns from build observations to improve shared industry templates), Blackmount acts as an independent controller of those build observations and is responsible for complying with Data Protection Law for that processing, as described in its Privacy Policy. Blackmount will never disclose Customer Content or these observations to other customers. If the Customer opts out by emailing info@blackmount.ai, Blackmount will stop that processing and delete the stored observations linked to the Customer's project.

1.3 Customer responsibilities. The Customer is responsible for the lawfulness of its instructions and for providing any notices to, and obtaining any consents from, data subjects that Data Protection Law requires for the processing.

2. Confidentiality of personnel

Blackmount ensures that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.

3. Security

Blackmount implements the technical and organisational measures described in Annex 2. Blackmount may update those measures provided the overall level of protection of Customer Personal Data is not reduced.

4. Subprocessors

4.1 The Customer gives general authorisation for Blackmount to engage the subprocessors listed in Annex 3.

4.2 Blackmount will give at least 30 days' notice before adding or replacing a subprocessor listed in Annex 3, by updating Annex 3 and emailing the Customer's account contact. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.

4.3 Model hosting through OpenRouter. Blackmount selects the models used by the live agent (currently Anthropic Claude and OpenAI GPT models). OpenRouter routes each request to a hosting provider that serves the selected model; this may be the model's publisher or another provider hosting the same model, and OpenRouter may change which provider serves a request. The Customer authorises this category of downstream providers as described in Annex 3. Notice under §4.2 applies when Blackmount changes the model gateway or adds a new model publisher, not to OpenRouter's request-by-request choice of host.

4.4 Blackmount will impose data-protection obligations on each subprocessor that are no less protective than those in this DPA, to the extent applicable to the services it provides, and remains responsible to the Customer for each subprocessor's performance of those obligations.

5. Assistance

Taking into account the nature of the processing and the information available to it, Blackmount will assist the Customer with responding to data-subject requests, with security, with personal-data-breach notification, and with data protection impact assessments and prior consultations. Requests are handled by Blackmount staff on written request to info@blackmount.ai. If Blackmount receives a request directly from a data subject about Customer Personal Data, it will refer the data subject to the Customer.

6. Personal data breach

Blackmount will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event no later than 72 hours after Blackmount confirms the breach. The notice will include the information then reasonably available — the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point — and Blackmount will supplement it as more information becomes available. Blackmount will take reasonable steps to contain and remediate the breach. Notice is sent to the Customer's account contact by email.

7. Deletion and return

This section is the single source of Blackmount's deletion commitment; Terms §14.4 and Privacy Policy §6 refer to it.

(a) On termination, the Customer may request return of Customer Personal Data and Customer Content within 30 days after termination (the "export window"). Blackmount will delete Customer Personal Data and Customer Content within 30 days after the export window closes.

(b) On written request at any time — during the term, or after termination, including before the export window closes — Blackmount will delete the specified Customer Personal Data (or, after termination, all of it) within 30 days of the request.

(c) Return is provided as a machine-readable export, prepared by Blackmount staff within 30 days of the request, (for example CSV or JSON) of the Customer's stored records: conversations, leads, documents and their text, attribution data, desktop task and tool-call records, and account records. One export on termination is provided at no charge.

(d) Copies in database backups are deleted when those backups expire in the hosting provider's ordinary backup cycle, and are not restored to active use in the meantime except for disaster recovery. Blackmount may retain data where required by law, subject to this DPA's confidentiality and security obligations. Data held by subprocessors is deleted in accordance with their retention terms.

(e) On request, Blackmount will confirm in writing that deletion under this section has been completed.

8. Audits

8.1 Blackmount will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR.

8.2 The Customer may audit Blackmount's compliance once in any 12-month period, on at least 30 days' written notice, at the Customer's cost. Audits are conducted first by written questionnaire, which Blackmount will answer accurately and within a reasonable time. An on-site inspection, by the Customer or an independent auditor bound by confidentiality, is available only where the questionnaire is insufficient and an on-site audit is required by Data Protection Law or by a competent supervisory authority. An audit required by a supervisory authority is not limited to once in 12 months. Nothing in this section limits the Customer's audit rights under Clause 8.9 of the SCCs where they apply.

8.3 Blackmount does not currently hold SOC 2 or ISO 27001 reports.

9. International transfers

9.1 Customer Personal Data is stored and processed in the United States, and may be processed by subprocessors in other countries as listed in Annex 3.

9.2 Where the Customer transfers Customer Personal Data subject to the GDPR to Blackmount in a country without an adequacy decision, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs") are incorporated into this DPA by reference: Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is itself a processor. For the SCCs: the optional docking clause (Clause 7) applies; under Clause 9 option 2 (general written authorisation) applies with the notice period in §4.2; the optional language in Clause 11 does not apply; under Clause 13 the competent supervisory authority is the one determined by Clause 13 according to the Customer's establishment or, if it has none in the EU, its representative or the data subjects concerned; under Clauses 17 and 18 the law and courts of Ireland apply; Annex I is completed by Annex 1 of this DPA (with the Customer as data exporter and Blackmount as data importer, contact details as in the Terms and order form); Annex II is completed by Annex 2; and Annex III by Annex 3.

9.3 For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs (version B1.0, issued by the UK Information Commissioner) is incorporated by reference, with Tables 1 to 3 completed by the information in this DPA and its Annexes, and neither party may end the Addendum under its Section 19 except as it permits.

9.4 For transfers subject to Swiss law, the SCCs apply with these amendments: references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" includes Switzerland so that data subjects in Switzerland can enforce their rights there.

9.5 If the SCCs conflict with this DPA or the Terms, the SCCs prevail. If any provision of this DPA is held invalid, the remaining provisions, and the SCCs, continue in effect.

10. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations in Terms §16 (including the Super Cap), except where Data Protection Law or the SCCs do not permit limitation. This DPA prevails over the Terms for the processing of Customer Personal Data. This DPA lasts as long as Blackmount processes Customer Personal Data on the Customer's behalf.


Annex 1 — Details of processing

Item Description
Data exporter The Customer, as identified in the order form; contact: the Customer's account contact named in the order form
Data importer Blackmount.ai Inc, a Delaware corporation; contact: info@blackmount.ai; role: processor
Competent supervisory authority As determined under SCC Clause 13 (see §9.2)
Retention For the term of the Agreement, then deleted as set out in §7
Subject matter Hosting and operating an AI sales or technical assistant on the Customer's behalf
Duration Term of the Agreement plus the deletion period in §7
Frequency Continuous, for the duration of the Agreement
Nature and purpose Collecting, ingesting and indexing Customer Content; answering End User questions with citations; detecting purchase intent; capturing leads and emailing them to the Customer's designated sales address; reporting; processing results of desktop-agent tools run on Customer-selected local files
Data subjects Visitors to the Customer's agent or widget; the Customer's staff and authorised users; individuals named in Customer Content or local files
Categories of data Chat messages; name, email, company, phone and request details volunteered by visitors; IP address, user-agent, referrer, campaign ref tag, country and timestamps; account identifiers (email, Firebase user ID) and device IDs; usage records; personal data contained in documents or local files the Customer chooses to process, including desktop tool results, file names and task state
Special categories None intended. The Customer must not submit special-category data unless agreed in writing
Storage location Supabase Postgres (with pgvector) and Railway application hosting, in the United States

Annex 2 — Technical and organisational measures

Annex 3 — Subprocessors

Subprocessor Purpose Data Location
Supabase, Inc. Primary database (Postgres with pgvector) All stored data United States
Railway Corp. Application hosting (web app, API, widget endpoints) All data in transit through the application United States
OpenRouter, Inc. Model gateway for the live agent — answer generation, re-ranking, query rewriting and classification User questions, retrieved document excerpts, desktop tool results, conversation context United States
↳ Model hosting providers selected by OpenRouter (see §4.3) Serving the selected Anthropic and OpenAI models; may include the model publisher or other providers hosting the same model As above Depends on the provider; may be outside the United States
OpenAI, L.L.C. (directly or through OpenRouter) Text embeddings for documents and each user question Document text; user questions United States
Anthropic, PBC and OpenAI, L.L.C. (Blackmount's own accounts) Building and testing agents: extracting product catalogs, generating and grading evaluation questions from Customer Content Customer Content United States
LlamaIndex, Inc. (LlamaParse) PDF and document parsing during agent builds and uploads Customer documents United States
Resend, Inc. Lead notification email to the Customer's sales address Lead contact details, request details, conversation excerpt United States
Google LLC (Firebase Authentication) Sign-in for desktop-agent and API account users Email, authentication identifiers United States
Google LLC (Google Analytics 4) Analytics on Blackmount-hosted pages Cookie IDs, page URLs, device and browser data, IP address United States
Mendable, Inc. (Firecrawl cloud) — used only if enabled Web collection, as a fallback when Blackmount's self-hosted crawler is unavailable URLs and pages of the Customer's websites United States
Langfuse — used only if enabled; self-hosted by Blackmount Tracing of agent requests for debugging and quality review Conversation and tool-call content Blackmount-operated infrastructure, United States

Not subprocessors. Web crawling runs on a Firecrawl instance self-hosted on Blackmount-controlled infrastructure, or on Firecrawl's cloud service where enabled (listed above). Tool servers that a Customer connects to its own agent receive tool arguments under the Customer's control. Card payments are not processed through the Services; billing is by invoice.