Venture Track — Data Processing Agreement

Effective date: 31 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Blank Cut Inc. ("Processor", "we") and the customer identified in the applicable order ("Controller", "you"), and applies where we process personal data on your behalf.

If there is a conflict, this DPA controls over the Terms of Service on data protection matters.


1. Definitions

"Data Protection Laws" means all applicable laws on the processing of personal data, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA"), and any successor legislation.

"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the GDPR.

"Customer Personal Data" means Personal Data contained within Customer Data that we process on your behalf under the Terms of Service.


2. Roles

You are the Controller of Customer Personal Data. We are the Processor. We process Customer Personal Data only on your documented instructions, which the Terms of Service and your use of the Service constitute.

Where the CCPA applies, we act as a Service Provider. We will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than performing the Service, or combine it with data from other sources except as permitted by the CCPA.


3. Scope of processing

Subject matter: provision of the Venture Track platform.

Duration: the term of the subscription, plus the retention period in §9.

Nature and purpose: hosting, storage, retrieval, analysis, transmission, and deletion of Customer Data to provide monitoring, alerting, and analysis features.

Categories of Data Subject:

  • Your personnel who use the Service (named users, administrators, billing contacts)
  • Individuals named within Customer Data you upload (for example, founders and executives of tracked companies)
  • Individuals appearing in third-party source material ingested by the Service

Categories of Personal Data:

  • Identification and contact data (name, work email, role, firm)
  • Authentication and session data
  • Usage and audit data (actions taken, timestamps, IP address)
  • Free-text content in uploaded documents, notes, and chat messages, which may contain Personal Data determined by you

Special category data: the Service is not designed for and should not be used to process special category data under Article 9 GDPR. You must not upload it.


4. Our obligations

We will:

(a) process Customer Personal Data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we will notify you first unless the law prohibits it;

(b) ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations;

(c) implement the technical and organizational measures in Annex A;

(d) respect the conditions in §5 for engaging subprocessors;

(e) assist you, by appropriate technical and organizational measures and insofar as possible, in responding to Data Subject requests under Chapter III GDPR;

(f) assist you with your obligations under Articles 32–36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of processing and the information available to us;

(g) at your election, delete or return Customer Personal Data at the end of the Service, as set out in §9;

(h) make available the information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as set out in §8.

4.1 Instructions we will not follow

We will notify you if, in our opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is resolved.


5. Subprocessors

You give general written authorization for us to engage subprocessors.

The current list is maintained in our Privacy Policy at https://venture-track.blankcut.com/legal/privacy.

We will give at least 30 days' notice before adding or replacing a subprocessor that processes Customer Personal Data. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected subscription and receive a prorated refund of prepaid fees for the remaining term.

We impose data protection obligations on each subprocessor no less protective than those in this DPA, and remain fully liable to you for their performance.


6. International transfers

We process Customer Personal Data in the United States, and we do not currently offer the Service to customers established in the EEA, the UK, or Switzerland.

If you are established in one of those jurisdictions, or you instruct us to process Personal Data subject to the GDPR, the UK GDPR, or the Swiss FADP, contact us before sending it: we will execute the appropriate transfer mechanism — the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), together with the UK International Data Transfer Addendum or the Swiss addendum as applicable — as a signed addendum to this DPA. Where those clauses and this DPA conflict, the clauses prevail.


7. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will describe, to the extent known: the nature of the breach and categories and approximate number of Data Subjects and records affected; likely consequences; and measures taken or proposed. Where information is not available at once, we will provide it in phases without undue further delay.

We will not make public statements identifying you in connection with a breach without your prior written consent, except where legally required.


8. Audit

On reasonable written request, no more than once per twelve months (unless required by a supervisory authority or following a Personal Data Breach), we will make available information necessary to demonstrate compliance with this DPA.

Where that information is insufficient, you may conduct an audit, subject to reasonable notice (at least 30 days), confidentiality obligations, conduct during business hours without unreasonable disruption, and at your cost. We may satisfy an audit request by providing a current third-party audit report or security assessment where one is available.


9. Deletion and return

On termination of the Service, we will delete Customer Personal Data within 30 days, except where retention is required by law.

During those 30 days you may export Customer Data through the Service. On written request within that period we will provide a machine-readable export.

Backup copies are purged on our standard rotation, no later than [BACKUP RETENTION PERIOD] after deletion. Until purged, backup data remains subject to this DPA.


10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Laws prohibit limiting liability.


11. General

This DPA takes effect when the Terms of Service take effect and continues while we process Customer Personal Data. It is governed by the same law as the Terms of Service, except where Data Protection Laws require otherwise.

Contact. Notices and requests under this DPA — including a transfer mechanism under §6, a subprocessor objection under §5, an audit request under §8, and deletion or return under §9 — go to support@blankcut.com. Ours to you go to the administrative contact on the account.


Annex A — Technical and organizational measures

Access control

  • Role-based access control with platform-operator and firm-scoped roles held separately
  • Tenant isolation enforced at the query layer — every tenant-scoped query derives its scope from the authenticated session, never from client input
  • Passwordless authentication using single-use sign-in links that expire after 15 minutes
  • Least-privilege staff access, granted only where operationally necessary

Encryption

  • TLS for all data in transit
  • Encryption at rest for the primary database and object storage

Secrets management

  • Application secrets held in a managed secret store (AWS Parameter Store), never in source control
  • Secrets injected at runtime; not written to logs

Resilience and recovery

  • Managed database with automated daily physical backups, retained on a rolling 7-day window by the database provider

Monitoring

  • Application health endpoint covering database, cache, and object storage
  • Error and access logging with defined retention

Organizational

  • Confidentiality obligations for all personnel with data access
  • A documented incident response plan