RisQore← Back to site
Pending legal review. These documents are a good-faith, GDPR- and PDPL-oriented baseline and not legal advice. Final review by counsel is in progress; material changes will be reflected in the effective date below.

Data Processing Agreement

Governs BITS Blackrock IT Solutions LLC's processing of personal data on behalf of the Customer under GDPR Art. 28 and equivalent PDPL provisions. Forms part of the Terms of Service.

BITS Blackrock IT Solutions LLC · Last updated 2026-07-17

1.Roles

The Customer is the controller of personal data it enters into RisQore. BITS Blackrock IT Solutions LLC is the processor, acting only on the Customer’s documented instructions — which include operating the Service as configured.

2.Scope of processing

3.Our obligations

4.Sub-processors

The Customer authorises the use of the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of any intended change, and the Customer may object on reasonable data-protection grounds.

ProviderPurposeLocation
Hetzner Online GmbHApplication hosting & deliveryGermany (EU)
Supabase Inc. (PostgreSQL)Primary database & file storageUK (London, eu-west-2)
Clerk Inc.Authentication & identityUSA (SCCs)
OpenAI, L.L.C.AI-assisted features you invoke (policy drafting, auto-linking)USA (SCCs, no training on your data)
Lemon Squeezy, LLCBilling & payments (merchant of record)USA (SCCs)
Resend, Inc.Transactional & report emailUSA (SCCs)

5.Security measures

Full detail is on our Security & Trust page.

6.International transfers

The application and database are hosted in the United Kingdom (London). Where personal data is transferred outside the Customer’s region, the transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard, as reflected in the sub-processor table.

7.Personal data breach

We will notify the Customer without undue delay, and in any event within 72 hoursof becoming aware of a personal data breach affecting Customer data, with the information reasonably available to support the Customer’s own obligations.

8.Return & deletion

On termination, and at the Customer’s choice, we will return or delete Customer personal data within 30 days, except where retention is required by law.

9.Signing this DPA

A countersigned copy is available on request at legal@bits-solution.com. Accepting the Terms of Service incorporates this DPA where the Customer is a controller under GDPR or PDPL.