Legal

Data Processing Agreement

Auftragsverarbeitungsvertrag gemäß Art. 28 DSGVO · Version 1.0 · 23 August 2026

0. Read this first — who needs this document

If you use Blurt as an individual, for yourself, you do not need this page. In that case Blurt is the controller for the managed Cloud plan and our Privacy Policy is the document that describes your rights.

This agreement applies when you use Blurt as an organisation — a company, a practice, an authority, a freelancer with staff — and your people dictate content that contains personal data for which you are the controller. Then, for that content, you are the controller and Blurt is your processor.

Two roles run side by side, and it is worth being precise about them:

1. How this agreement is concluded

This agreement forms an integral part of the Terms of Use and is concluded together with them, at the moment you subscribe as an organisation. No separate signature is required, and there is no form to request. It is between:

If your own procurement process requires a signed paper copy, or your own DPA template, write to support-blurt@chbnk.one and we will sign it if its content is compatible with this one. Where a separately signed agreement exists, it prevails over this page.

We keep the version number and date at the top of this page. Where a change materially reduces your protection, we notify you at least 30 days before it applies, and you may terminate free of charge before it takes effect.

2. Subject matter, duration, nature and purpose (Art. 28(3) GDPR)

If your use case regularly involves special-category data — health, biometric identification, criminal matters — we advise the on-device mode instead, in which no data reaches us at all and this agreement is not needed.

3. Processing on documented instructions (Art. 28(3)(a))

We process personal data only on your documented instructions, including as regards transfers to third countries, unless required to do otherwise by EU or Member State law — in which case we inform you of that requirement before processing, unless the law prohibits it on important grounds of public interest.

Your instructions consist of: this agreement, the Terms, the settings your users choose in the app (which speech and clean-up model to use, whether history is stored), and any further instruction you give us in writing or by email. We will tell you if we consider an instruction to infringe the GDPR or other data protection law (Art. 28(3), final sentence), and may suspend the affected processing until it is resolved.

4. Confidentiality (Art. 28(3)(b))

Blurt is operated by one natural person, who is bound to confidentiality directly and permanently. There are no employees or contractors with access to your data. Should that ever change, any additional person will be bound by a written confidentiality undertaking that survives the end of their engagement, and will be trained in data protection before being granted access.

5. Security of processing (Art. 28(3)(c), Art. 32)

We implement appropriate technical and organisational measures. They are set out in full on our security page, which is Annex II to this agreement and is incorporated by reference. The measures include, in summary: TLS on every connection, no storage of audio at rest, hosting of backend and database in Germany, scrypt password hashing, hashed refresh tokens, container hardening, rate limiting, encrypted backups, and no third-party analytics, telemetry or crash-reporting SDKs. Blurt's own usage analytics is off unless the individual user switches it on, contains no content of any kind, is not linked to an account, and is processed on the same German infrastructure — it introduces no additional sub-processor.

The security page also states plainly what we do not have — no SOC 2, no ISO 27001, no third-party penetration test — so that your own risk assessment starts from the truth.

6. Sub-processors (Art. 28(2) and (4))

You give us a general written authorisation to engage sub-processors. The current list, with what each one receives, where it is and on what basis data may leave the EEA, is on our processor page, which is Annex III to this agreement.

We will inform you of any intended addition or replacement of a sub-processor normally at least 30 days in advance by updating that page and, if you have asked to be notified, by email. You may object on reasonable data-protection grounds within that period. If we cannot accommodate your objection, you may terminate the subscription with effect from the date the change takes effect, and we refund the unused part of what you have paid.

Where a sub-processor fails, withdraws its service, or has to be replaced at short notice to maintain the service or to address a security risk, we may make the change before the notice period has run. In that case we inform you without undue delay, stating the provider, the date and the reason, and your right to object and to terminate under the previous paragraph applies from that moment instead. This exception exists for genuine emergencies and will not be used to shorten the ordinary notice period.

We impose on each sub-processor, by contract, data protection obligations that are equivalent to those in this agreement, and we remain fully liable to you for their performance.

7. Assisting you with data subject rights (Art. 28(3)(e))

Because we do not store the content after a request completes, there is normally nothing on our side to search, correct or export for a data subject. Where a request nevertheless requires our help, we assist you by appropriate technical and organisational measures, insofar as possible, and we do not answer a data subject directly on your behalf — we refer them to you and tell you about the request without undue delay.

8. Assisting you with Art. 32 to 36 (Art. 28(3)(f))

9. Deletion or return at the end (Art. 28(3)(g))

At the end of the provision of services you choose whether we delete or return the personal data. In practice deletion is the default and is largely automatic, because content is never stored: what remains is account data, which is deleted when the account is deleted. Copies we are required by EU or Member State law to keep — chiefly billing records under § 147 AO and § 257 HGB — are retained for that period only, and blocked from any other use.

10. Information and audits (Art. 28(3)(h))

We make available to you all information necessary to demonstrate compliance with Art. 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

In the first instance we answer in writing and by providing the documentation on this site. Where that is not sufficient, an on-site or remote inspection may be carried out on reasonable notice, during business hours, no more than once a year unless there is a concrete reason, and subject to confidentiality. Blurt is a one-person operation: we will not pretend an audit programme exists that does not, but we will answer your questionnaire honestly and promptly.

11. International transfers

Several sub-processors are established in the United States; the processor page states for each one whether the transfer rests on the EU–US Data Privacy Framework adequacy decision (Art. 45) or on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) (Art. 46(2)(c)).

Where the Standard Contractual Clauses apply between you and us — for example because your own establishment is outside the EEA — the Clauses in that same version are hereby incorporated into this agreement by reference, with Annexes I to III below, and prevail over this agreement in the event of any conflict.

12. Liability and order of precedence

Liability follows Art. 82 GDPR and section 10 of the Terms of Use. Where the Standard Contractual Clauses apply, their liability provisions prevail over this agreement in respect of the processing they cover. In the event of a conflict, the order of precedence is: a separately signed data processing agreement, then the Standard Contractual Clauses, then this agreement, then the Terms of Use.

13. Governing law

German law applies. If any provision of this agreement is invalid, the rest remains in force and the statutory rules take the place of the invalid provision.

Annex I — Description of the processing

Annex I.A — the parties
RolePartyContact
Data exporter / controllerYou, the customer, as identified in your account and billing detailsThe contact address on your account
Data importer / processorIvan Chabanenko, Lutherstraße 12, 39112 Magdeburg, Germanysupport-blurt@chbnk.one
Annex I.B — description of the transfer
ItemDescription
Categories of data subjectsYour users, and any person mentioned in what they dictate
Categories of personal dataVoice recordings; the transcripts derived from them; any personal data contained in the spoken content
Special categoriesNot requested by us and not required by the service. Possible in principle, because the content is whatever your users choose to say — controlled by your own instructions to them
FrequencyContinuous, on each dictation initiated by a user
Nature of the processingTransmission, transient processing for speech recognition and text clean-up, return of the result. No storage after completion
PurposeProviding the managed Cloud dictation service
RetentionNone for content. Account and billing data as described in the Privacy Policy
Sub-processorsAs listed on the processor page, for the duration and purpose stated there

Annex I.C — competent supervisory authority. Landesbeauftragte für den Datenschutz Sachsen-Anhalt, Otto-von-Guericke-Straße 34a, 39104 Magdeburg, Germany.

Annex II — Technical and organisational measures

The measures set out on our security page, as amended from time to time, form Annex II to this agreement. We do not maintain a second, divergent copy of them — one document, kept current, is what keeps this accurate.

Annex III — Sub-processors

The providers listed on our processor page, as amended in accordance with section 6, form Annex III to this agreement.

Related

See our Terms of Use, Privacy Policy, security page and processor list.