Data processing agreement
The processing terms between your business as controller and Bloomod as processor, for the event-attendee records you bring to Bloomod.
Last updated 30 July 2026 · Version 1.0
Template content. Placeholder wording reflecting how the product works, written to demonstrate the layout. A real DPA must be reviewed by a lawyer and executed — this page is not a substitute for that, and is not legal advice.
1. Parties and roles
Controller: the business operating the Bloomod account. Processor: Bloomod, operator of Bloomod. This agreement applies to personal data in the event-attendee records the controller uploads or creates, and to the invitation and RSVP data derived from them.
Where Bloomod processes account data about the controller's own members, Bloomod acts as controller under the privacy notice and this agreement does not apply.
2. Scope of processing
Bloomod processes personal data only to provide the calendar invitation service: storing event-attendee records, verifying attendee participation, transmitting invitations to calendar providers, recording delivery and RSVP state, enforcing limits and review, and providing support.
3. Instructions
Bloomod processes personal data only on the controller's documented instructions. Using the platform — creating a campaign, approving a send, importing records — constitutes an instruction. Bloomod will tell the controller if an instruction appears to breach applicable data protection law, and may decline to act on it.
4. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and receive access only where needed to perform their role.
5. Security measures
Bloomod maintains technical and organisational measures including:
- Encryption of personal data in transit and at rest
- Role-based access control and scoped API keys
- Separation of test and live credentials
- Recording of campaign, consent and account activity
- Sender and domain verification before sending is permitted
- An approval gate that cannot be bypassed programmatically
The current control set is summarised on the security page.
6. Subprocessors
The controller authorises Bloomod to engage subprocessors for hosting, storage, monitoring and delivery. Bloomod imposes data protection obligations on each subprocessor no less protective than this agreement, and remains responsible for their performance. A current list is available from hello@bloomod.com. Bloomod will give notice of an intended change and the controller may object on reasonable data protection grounds.
Calendar and mail providers necessarily receive invitation data in order to deliver it to the recipient. This is inherent to the service rather than an optional integration.
7. Data subject requests
Where a recipient contacts Bloomod directly to exercise a right, Bloomod will not respond substantively but will forward the request to the controller and assist in answering it. The platform provides the record, consent state and invitation history needed to do so.
8. Breach notification
Bloomod will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information available at the time and updates as the investigation progresses.
9. International transfers
Where personal data is transferred outside its country of origin, the transfer is made under a recognised transfer mechanism, and Bloomod will provide the information the controller needs for its own transfer assessment.
10. Deletion and return
On termination, Bloomod will delete or return event-attendee records within a defined window, except that suppression and unsubscribe records are retained — removing them would undo the recipient's withdrawal of consent, which would harm the very people data protection law is there to protect.
11. Audit
Bloomod will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits on reasonable notice, at reasonable frequency, and in a manner that does not compromise the security or confidentiality of other customers' data.
Annex — processing details
| Subject matter | Delivery of calendar invitations and management of event-attendee records |
| Duration | The term of the account, plus the deletion window |
| Nature and purpose | Storage, consent filtering, transmission, RSVP recording, support |
| Categories of data | Name, email address, segment and attributes, consent state, invitation and RSVP history, time zone |
| Categories of data subject | The controller's customers, clients, members and event registrants |
| Special category data | Not requested and not intended to be stored |
| Frequency | Continuous for the term |