Data processing agreement
The processing terms between your business as controller and Bloomod as processor, for the event-attendee records you bring to Bloomod.
Last updated 9 August 2026 · Version 1.1
1. Parties and roles
Controller: the business operating the Bloomod account. Processor: the operator of the Bloomod service, referred to in this agreement as “Bloomod”. This agreement applies to personal data in the event-attendee records the controller uploads or creates, and to the invitation and RSVP data derived from them.
Where Bloomod processes account data about the controller's own members, Bloomod acts as controller under the privacy notice and this agreement does not apply.
2. Scope of processing
Bloomod processes personal data only to provide the calendar invitation service: storing event-attendee records, verifying attendee participation, transmitting invitations to calendar providers, recording delivery and RSVP state, enforcing limits and review, and providing support.
3. Instructions
Bloomod processes personal data only on the controller's documented instructions. Using the platform — creating an Event, approving an invitation send or importing records — constitutes an instruction. Bloomod will tell the controller if an instruction appears to breach applicable data protection law, and may decline to act on it.
4. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and receive access only where needed to perform their role.
5. Security measures
Subject to the deployed service and final agreement, relevant technical and organisational measures may include:
- Protection of personal data in transit and at rest where supported by deployed infrastructure
- Role-based access control for authorised organisation members
- Need-to-know operational access for authorised Bloomod personnel
- Recording of important Event, verification, consent and account activity where implemented
- Ownership verification for Business custom sender domains
- Scoped credentials and review controls if planned API access is provided
Current product security context is summarised on the security page.
6. Subprocessors
The controller authorises Bloomod to engage subprocessors for hosting, storage, monitoring and delivery. Bloomod imposes data protection obligations on each subprocessor no less protective than this agreement, and remains responsible for their performance. A current list is available from hello@bloomod.com. Bloomod will give notice of an intended change and the controller may object on reasonable data protection grounds.
Calendar and mail providers necessarily receive invitation data in order to deliver it to the attendee. This is inherent to the service rather than an optional integration.
7. Data subject requests
Where an attendee contacts Bloomod directly to exercise a right, Bloomod will not respond substantively but will forward the request to the controller and assist in answering it. The platform provides the record, consent state and invitation history needed to do so.
8. Breach notification
Bloomod will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, with the information available at the time and updates as the investigation progresses.
9. International transfers
Where personal data is transferred outside its country of origin, the transfer is made under a recognised transfer mechanism, and Bloomod will provide the information the controller needs for its own transfer assessment.
10. Deletion and return
On termination, Bloomod will delete or return event-attendee records within a defined window, except that suppression and unsubscribe records are retained — removing them would undo the recipient's withdrawal of consent, which would harm the very people data protection law is there to protect.
11. Audit
Bloomod will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits on reasonable notice, at reasonable frequency, and in a manner that does not compromise the security or confidentiality of other customers' data.
Annex — processing details
| Subject matter | Delivery of calendar invitations and management of event-attendee records |
| Duration | The term of the account, plus the deletion window |
| Nature and purpose | Storage, consent filtering, transmission, RSVP recording, support |
| Categories of data | Name, email address, segment and attributes, consent state, invitation and RSVP history, time zone |
| Categories of data subject | The controller's customers, clients, members and event registrants |
| Special category data | Not requested and not intended to be stored |
| Frequency | Continuous for the term |