Governs BITS Blackrock IT Solutions LLC's processing of personal data on behalf of the Customer under GDPR Art. 28 and equivalent PDPL provisions. Forms part of the Terms of Service.
BITS Blackrock IT Solutions LLC · Last updated 2026-07-17
The Customer is the controller of personal data it enters into SekuRad. BITS Blackrock IT Solutions LLC is the processor, acting only on the Customer’s documented instructions — which include operating the Service as configured.
The Customer authorises the use of the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of any intended change, and the Customer may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting & delivery | Germany (EU) |
| Supabase (PostgreSQL) | Primary database & file storage | EU |
| Clerk Inc. | Authentication & identity | USA (SCCs) |
| OpenAI | AI assistant (Keva) — features you opt into | USA (SCCs, no training on your data) |
| Anthropic | AI assistant (Keva) — features you opt into | USA (SCCs, no training on your data) |
| Resend | Transactional & alert email | USA (SCCs) |
| LemonSqueezy | Billing & payment processing | USA (SCCs) |
| Sentry (Functional Software, Inc.) | Error & performance monitoring (PII disabled) | USA (SCCs) |
Full detail is on our Security & Trust page.
Where personal data is transferred outside the Customer’s region, the transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard, as reflected in the sub-processor table.
We will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer data, with the information reasonably available to support the Customer’s own obligations.
On termination, and at the Customer’s choice, we will return or delete Customer personal data within 30 days, except where retention is required by law.
A countersigned copy is available on request at legal@sekurad.com. Accepting the Terms of Service incorporates this DPA where the Customer is a controller under GDPR or PDPL.