HomeTrust center › DPA
Legal & trust

Data Processing Addendum

This page is a public template summary of BlueTier’s Data Processing Addendum (DPA). The DPA is executed as part of the signed service agreement; where the executed agreement differs from this summary, the executed agreement controls.

Effective and last updated: 2026-08-06

Scope and roles

The DPA governs BlueTier’s processing of personal data while providing the platform and any contracted services. The customer is the controller of the personal data it provides or authorizes; BlueTier acts as the processor, processing that data only on the customer’s documented instructions and as needed to provide the service.

Processing purposes

Processing is limited to providing, maintaining, securing, and supporting the service: onboarding, campaign configuration and operation, AI-assisted drafting and recommendations the customer approves, analytics and reporting, transactional notifications, and recordkeeping required by law or the agreement.

Subprocessors

BlueTier engages the subprocessors listed on the subprocessors page for hosting, data storage, transactional email, and connected-account connectivity. The list is kept current as vendors change, and customers may request notice of material subprocessor changes.

Security measures

BlueTier maintains the technical and organizational measures described on the security page, including data minimization, signed and expiring sessions, TLS encryption in transit, managed at-rest encryption on the Postgres data store, rate limiting, and audit logging of operator access. BlueTier does not claim certifications it has not obtained.

International transfers

Where personal data is transferred across borders, BlueTier relies on an appropriate legal transfer mechanism — such as standard contractual clauses or an adequacy decision — as required by applicable data-protection law, and limits processing to the service purpose.

Audit rights

Customers may request reasonable information about BlueTier’s processing and security measures to verify compliance with the DPA. Requests are coordinated through IT@bbmgroup.io and scoped to protect other customers’ data and platform security.

Deletion at termination

On termination of the service, customer data is deleted or returned within a reasonable period, subject to the retention schedule in the privacy policy, backup rotation, and records BlueTier must keep for legal, accounting, or dispute purposes.

Contact

To request an executed DPA or ask a question about this template, email IT@bbmgroup.io with “DPA request” in the subject line.

Questions or correction requests?

Use the contact form or email IT@bbmgroup.io. Never include an account password or verification code.

Contact BlueTier →