Data Processing Agreement
Last updated July 2026
This Data Processing Agreement (“DPA”) applies when a customer uses Bloggent to process personal data subject to applicable privacy law and Bloggent acts as a processor or service provider on the customer's behalf.
Scope and roles
The customer remains the controller for personal data it submits to the service, including workspace content, prompts, research inputs, and generated drafts. Bloggent processes that data only to provide, secure, support, and improve the contracted service in line with the customer's documented instructions and applicable law.
Processor obligations
Bloggent will process personal data confidentially, restrict internal access to personnel with a legitimate need to know, maintain written security practices, and promptly inform the customer if an instruction appears to violate applicable law. Bloggent will not sell customer personal data or use it for unrelated advertising purposes.
Data subject rights assistance
Taking into account the nature of the processing, Bloggent will provide reasonable assistance so the customer can respond to requests for access, correction, deletion, restriction, objection, or portability. Customers may submit requests by emailing meet@bloggent.com.
Sub-processors
Bloggent may engage sub-processors to deliver infrastructure, AI processing, SERP data, transactional email, and support functions. Bloggent remains responsible for ensuring that each sub-processor is bound by written data protection obligations appropriate to the service it provides. The current list is published on the sub-processor page.
Security measures
Bloggent maintains administrative, technical, and organizational safeguards appropriate to the risk, including encryption in transit, encrypted storage provided by core infrastructure vendors, access controls, logging, and change-managed application deployments. Additional details are summarized in the Security Overview.
Data deletion and return
Upon account closure or written request, Bloggent will delete or return customer personal data within a commercially reasonable period unless retention is required by law, needed to resolve security incidents, or preserved in short-lived backups that are overwritten in the normal course of operations.