Data Processing Agreement
Governs BITS Blackrock IT Solutions LLC's processing of personal data on behalf of the Customer under GDPR Art. 28 and equivalent PDPL provisions. Forms part of the Terms of Service.
BITS Blackrock IT Solutions LLC · Last updated 2026-07-17
1.Roles
The Customer is the controller of personal data it enters into RisQore. BITS Blackrock IT Solutions LLC is the processor, acting only on the Customer’s documented instructions — which include operating the Service as configured.
2.Scope of processing
- Subject matter: provision of the RisQore governance, risk & compliance platform.
- Duration: the term of the subscription, plus the deletion window.
- Nature & purpose: hosting, storing, and processing compliance data as directed.
- Data types: account identifiers, control and risk records, policies, evidence documents, audit records, and related metadata.
- Data subjects: the Customer’s staff, its clients’ staff, and other individuals recorded by its users.
3.Our obligations
- Process personal data only on the Customer's documented instructions.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 5).
- Assist the Customer with data-subject requests and with its own security/DPIA obligations, taking into account the information available to us.
- Make available information necessary to demonstrate compliance and allow for reasonable audits.
4.Sub-processors
The Customer authorises the use of the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of any intended change, and the Customer may object on reasonable data-protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting & delivery | Germany (EU) |
| Supabase Inc. (PostgreSQL) | Primary database & file storage | UK (London, eu-west-2) |
| Clerk Inc. | Authentication & identity | USA (SCCs) |
| OpenAI, L.L.C. | AI-assisted features you invoke (policy drafting, auto-linking) | USA (SCCs, no training on your data) |
| Lemon Squeezy, LLC | Billing & payments (merchant of record) | USA (SCCs) |
| Resend, Inc. | Transactional & report email | USA (SCCs) |
5.Security measures
- Per-tenant access checks enforced on every request, with an automated coverage test that fails the build if any tenant route ships without a scope check.
- Defense in depth: database row-level-security policies and tenant foreign-key constraints beneath the application checks.
- Encryption of data in transit (TLS) and at rest.
- Role-based access control; least-privilege internal access.
- Audit logging of security-relevant actions.
- Authentication delegated to a dedicated identity provider (Clerk) with MFA support.
Full detail is on our Security & Trust page.
6.International transfers
The application and database are hosted in the United Kingdom (London). Where personal data is transferred outside the Customer’s region, the transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard, as reflected in the sub-processor table.
7.Personal data breach
We will notify the Customer without undue delay, and in any event within 72 hoursof becoming aware of a personal data breach affecting Customer data, with the information reasonably available to support the Customer’s own obligations.
8.Return & deletion
On termination, and at the Customer’s choice, we will return or delete Customer personal data within 30 days, except where retention is required by law.
9.Signing this DPA
A countersigned copy is available on request at legal@bits-solution.com. Accepting the Terms of Service incorporates this DPA where the Customer is a controller under GDPR or PDPL.