Governs BITS Blackrock IT Solutions LLC's processing of personal data on behalf of the Customer under GDPR Art. 28 and equivalent PDPL provisions. Forms part of the Terms of Service.
BITS Blackrock IT Solutions LLC · Last updated 2026-08-22
The Customer is the controller of personal data it enters into RisQore. BITS Blackrock IT Solutions LLC is the processor, acting only on the Customer’s documented instructions — which include operating the Service as configured.
The Customer authorises the use of the sub-processors listed below. We impose data-protection obligations on each that are no less protective than this DPA, and remain responsible for their performance. We will give reasonable notice of any intended change, and the Customer may object on reasonable data-protection grounds.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting, primary database & delivery | Germany (EU) |
| Supabase Inc. (Storage) | File storage for uploaded evidence and documents | UK (London, eu-west-2) |
| Clerk Inc. | Authentication & identity | USA (SCCs) |
| Anthropic PBC | AI assistant and drafting features you invoke, including tenant-scoped GRC record metadata | USA (SCCs, no training on your data) |
| OpenAI, LLC | Alternative AI model for assistant features, including tenant-scoped GRC record metadata | USA (SCCs, no training on your data via API) |
| Google LLC | Optional alternative AI model for assistant features; customer data requires a paid Gemini API configuration | Global processing (Google DPA and applicable transfer safeguards) |
| Deepgram, Inc. | Voice assistant — speech recognition and synthesis, only while you use it | USA (SCCs, no training on your data) |
| ElevenLabs Inc. | Arabic speech synthesis for the voice assistant (only while you use it) | USA (SCCs, no training on your data) |
| Lemon Squeezy, LLC | Billing & payments (merchant of record) | USA (SCCs) |
| ActiveCampaign, LLC (Postmark) | Transactional & report email | USA (SCCs) |
Full detail is on our Security & Trust page.
The application and the primary database are hosted in Germany (EU); uploaded files are stored in London, United Kingdom. Where personal data is transferred outside the Customer’s region by a sub-processor, the transfer is covered by Standard Contractual Clauses or an equivalent approved safeguard, as reflected in the sub-processor table.
BITS Blackrock IT Solutions LLC is established in Egypt. Remote administrative access to the Service by our personnel from Egypt is itself a restricted transfer under GDPR Chapter V. For this access the parties agree that the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller → processor), are incorporated into this DPA by reference, with the Customer as data exporter and BITS Blackrock IT Solutions LLC as data importer. Supplementary measures applied to this access: least-privilege and role-restricted administrative accounts, encryption in transit, and audit logging of administrative actions. A transfer impact assessment is available on request at privacy@bits-solution.com.
For personal data of individuals residing in the Kingdom of Saudi Arabia, the transfer mechanism is the one set out in Section 9 (Kingdom of Saudi Arabia addendum).
We will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer data, with the information reasonably available to support the Customer’s own obligations. For personal data covered by Section 9 the notice period is 24 hours.
On termination, and at the Customer’s choice, we will return or delete Customer personal data within 30 days, except where retention is required by law.
Application. This Section applies to the extent the Customer is established in the Kingdom of Saudi Arabia or the Customer data includes personal data of individuals residing in the Kingdom (“KSA personal data”). It supplements this DPA; for KSA personal data it prevails over the rest of the DPA, and the SDAIA Standard Contractual Clauses referred to below prevail over both.
Roles and law. The Personal Data Protection Law (Royal Decree M/19 of 1443H as amended by Royal Decree M/148 of 1444H), its Implementing Regulation and the Regulation on Personal Data Transfer Outside the Kingdom (together “PDPL”) may apply to KSA personal data. Where the Customer determines purposes and means, the Customer is the controller and BITS Blackrock IT Solutions LLC the processor. Where the Customer processes on behalf of its own clients, the client is the controller, the Customer is the processor and BITS Blackrock IT Solutions LLC is a sub-processor; the Customer warrants that it has obtained the controller’s prior acceptance of BITS Blackrock IT Solutions LLC as required by Article 17(5) of the Implementing Regulation.
Facts the Customer relies on (Implementing Regulation Art. 17(1)(e), (g)). BITS Blackrock IT Solutions LLC is a limited liability company established in the Arab Republic of Egypt. It has no legal entity, branch, office, hosting or data storage in the Kingdom and has not appointed a representative in the Kingdom. The Service application and database are hosted in Germany and uploaded files in the United Kingdom; our personnel access the Service from Egypt. BITS Blackrock IT Solutions LLC is subject to Egyptian law (including Law No. 151 of 2020) and, for its EU/UK hosting, to the EU GDPR and the UK GDPR; we are not aware of any provision of those laws that prevents us from complying with the PDPL for KSA personal data and will notify the Customer in writing without undue delay if that changes. The current sub-processors and their processing locations are listed in Section 4. BITS Blackrock IT Solutions LLC is not registered with the Communications, Space & Technology Commission as a cloud service provider and holds no approval from the Saudi Central Bank; the Service is not suitable for Saudi government data, data of Critical National Infrastructure operators, or data of entities supervised by the Saudi Central Bank unless the Customer has obtained the approvals those authorities require, and the Customer shall not upload such data without our prior written agreement. A dedicated deployment hosted in the Kingdom may be agreed separately in writing; until then this paragraph describes the Service.
Transfer mechanism. The Customer (as data exporter) and BITS Blackrock IT Solutions LLC (as data importer) enter into the Standard Contractual Clauses for Personal Data Transfer issued by the Saudi Data & AI Authority (Version 1.0, September 2024) — Template Two (controller to processor) where the Customer is the controller, Template Three (processor to processor) where the Customer is a processor — which are incorporated by reference, unmodified, and completed as follows: Appendix 1 (parties) as identified in the order; Appendix 2 (description of the data) as in Section 2; Appendix 3 (security measures) as in Section 5. For the purposes of those Clauses only, BITS Blackrock IT Solutions LLC submits to the jurisdiction of the courts of the Kingdom and will cooperate with and respond to requests of the Saudi Data & AI Authority. The Customer is responsible for establishing the lawful purpose of the transfer under Article 29 of the PDPL and Article 2 of the Transfer Regulation, for carrying out and retaining the risk assessment under Article 7 of the Transfer Regulation, and for recording the transfer in its records of processing; we will provide the information reasonably needed for that assessment (processing locations, sub-processors, security measures, retention). Our sub-processors process under their own safeguards listed in Section 4 (EU Standard Contractual Clauses or equivalent); they have not acceded to the SDAIA Clauses, and the Customer shall take this into account in its risk assessment. Should the Authority publish a list of countries offering an adequate level of protection that includes the countries in which the Service is hosted, the parties may agree in writing to rely on it instead.
Our additional commitments for KSA personal data. We will (a) process it only on the Customer’s documented instructions and notify the Customer in writing without undue delay if we cannot follow an instruction or believe it would violate the PDPL; (b) notify the Customer of a personal data breach affecting it within 24 hours of becoming aware, with a description, causes, measures taken or planned and a contact, and keep the Customer updated so it can meet its 72-hour duty to SDAIA under Article 24 of the Implementing Regulation; (c) forward any data-subject request we receive to the Customer within 48 hours and not answer it without authorisation; (d) notify the Customer, where legally permitted, of any disclosure required by law applicable to us; (e) engage new sub-processors only under Section 4 and, where the Customer is itself a processor, not less than five days before the appointment; (f) apply and periodically review the security measures in Section 5 in line with Article 23 of the Implementing Regulation; (g) maintain a written record of the processing we perform for the Customer; and (h) keep a named data-protection contact ( Karim Bremer, privacy@bits-solution.com) as the point of contact for the Customer’s Data Protection Officer and, where required, for SDAIA.
Customer obligations. The Customer remains responsible for its own duties under the PDPL, including lawful basis and notices to data subjects, registration in the National Register of Controllers where required, appointment of a Data Protection Officer where required, impact assessments (a copy of which it shall provide to us where relevant, Implementing Regulation Art. 25(3)), and approvals of sectoral regulators.
No representation as to presence in the Kingdom. Nothing in this Section appoints BITS Blackrock IT Solutions LLC as the Customer’s representative in the Kingdom or represents that BITS Blackrock IT Solutions LLC is registered, licensed or established there.
A countersigned copy is available on request at legal@bits-solution.com. Accepting the Terms of Service incorporates this DPA where the Customer is a controller under GDPR or PDPL.