Blossom

Legal · Data Processing Addendum

Blossom Data Processing Addendum

Version 0.1 — Last updated July 22, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Polymath HQ, Inc., a Delaware corporation based in New York and operating as Blossom (“Blossom”) and the customer identified in the agreement (“Customer”) governing Customer’s use of the Services (the “Agreement”). It applies when Blossom processes Customer Personal Data on Customer’s behalf.

By accepting the Agreement, each party enters into this DPA on behalf of itself and, where applicable, its permitted affiliates. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls.

1. Scope and roles

In short: Customer decides why and how Customer Personal Data is used. Blossom processes it only to provide the Services and follow lawful instructions.

“Customer Personal Data” means personal data, personal information, or equivalent regulated information contained in Customer Data that Blossom processes on Customer’s behalf through the Services. It does not include information for which Blossom independently determines the purposes and means of processing, such as website leads, account administration, billing-relationship records, and direct support contacts covered by the Privacy Policy.

As between the parties, Customer is the controller or business and Blossom is the processor or service provider. If Customer is itself a processor, Blossom is Customer’s subprocessor. Customer determines the purposes and essential means of processing and is responsible for its instructions, notices, lawful basis, consents, and responses to individuals.

Capitalized terms not defined here have the meanings in the Agreement. “Data Protection Law” means privacy or data-protection law applicable to the processing under this DPA.

2. Customer instructions

In short: The Agreement, Customer’s settings, and authorized use of the Services are Customer’s documented instructions.

Blossom will process Customer Personal Data only:

  • to provide, secure, maintain, and support the Services described in the Agreement and Annex I;
  • through Customer’s configuration, connections, agent instructions, support requests, and other documented directions;
  • as needed to comply with applicable law, after notifying Customer unless law prohibits notice; or
  • with Customer’s additional written instruction.

Blossom will promptly inform Customer if, in Blossom’s reasonable opinion, an instruction violates Data Protection Law, and may suspend the affected processing until the parties resolve the issue. Blossom will not sell Customer Personal Data, share it for cross-context behavioral advertising, use it for targeted advertising, or combine it with personal information received from another person except as permitted for a service provider under applicable law.

3. Customer responsibilities

In short: Customer must have authority over the data and give lawful, proportionate instructions.

Customer represents and warrants that it has provided all required notices and obtained all rights, permissions, lawful bases, and consents for Blossom and its subprocessors to process Customer Personal Data under this DPA. Customer will use the Services and configure access consistently with data minimization, purpose limitation, and least privilege. Customer is responsible for assessing whether the Services are appropriate for Customer’s data and use case, including regulated, sensitive, recorded, or third-party data.

Customer will not instruct Blossom to process Customer Personal Data in violation of Data Protection Law, the Agreement, or another person’s rights. Customer will provide legally sufficient instructions and information needed for Blossom to assist with rights requests, impact assessments, regulator consultations, or other obligations.

4. Confidentiality and personnel

In short: People authorized to handle Customer Personal Data must keep it confidential and access only what they need.

Blossom will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access only as needed for their responsibilities. Blossom will provide appropriate privacy and security guidance to relevant personnel and will revoke access when it is no longer needed.

5. Security

In short: Blossom maintains risk-appropriate safeguards and will not reduce them materially during the Services.

Blossom will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures in Annex II and the Security Overview describe Blossom’s current security posture. Blossom may update those measures as technology and risk change, provided it does not materially decrease overall protection during the applicable Service term.

Customer is responsible for securely configuring its accounts, users, permissions, agents, connected services, and approval settings, and for using available security controls.

6. Security incidents

In short: Blossom will notify Customer without undue delay after confirming a breach affecting Customer Personal Data and will help with the response.

“Personal Data Breach” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Blossom. It does not include unsuccessful attempts that do not compromise Customer Personal Data.

Blossom will notify Customer without undue delay after becoming aware of a Personal Data Breach. The notice will include available information reasonably needed for Customer to meet its obligations, such as the nature of the incident, affected data and people, likely consequences, measures taken or proposed, and a contact point. Blossom may provide information in phases as it becomes available. Blossom will take reasonable steps to contain, investigate, and remediate the incident and will reasonably cooperate with Customer. Notification is not an admission of fault or liability.

Customer is responsible for notifications to individuals and regulators unless law places that duty directly on Blossom.

7. Individual rights

In short: Blossom will pass along requests it receives and provide reasonable tools or assistance so Customer can respond.

Taking into account the nature of processing, Blossom will provide reasonable assistance through available product tools and, where needed, additional technical measures so Customer can respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Blossom receives a request directly concerning data it processes for Customer, Blossom will direct the requester to Customer and notify Customer where legally permitted. Blossom will not independently fulfill the request unless Customer instructs it or law requires it.

Blossom may charge reasonable fees for assistance that is unusually burdensome or not included in the Services, after giving Customer an estimate, except where Data Protection Law prohibits a charge.

8. Compliance assistance

In short: Blossom will provide information reasonably needed for impact assessments, regulator consultations, and Customer compliance.

Considering the nature of processing and information available to Blossom, Blossom will reasonably assist Customer with data-protection impact assessments, prior consultations with regulators, records of processing, and other obligations under applicable Data Protection Law. This assistance does not include legal advice. Customer remains responsible for deciding whether an assessment or consultation is required and for the accuracy of its submissions.

9. Subprocessors

In short: Customer generally authorizes the listed subprocessors. New vendors get 30 days’ notice and a 15-day objection window.

Customer generally authorizes Blossom to use the subprocessors on the Subprocessor List. Blossom will bind each subprocessor by written terms that provide data-protection obligations materially protective of Customer Personal Data, taking account of the services it performs. Blossom remains responsible for each subprocessor’s performance of its data-protection obligations to the extent required by Data Protection Law.

Blossom will provide at least 30 days’ notice before authorizing a new subprocessor to process Customer Personal Data. Customer may object in writing within 15 days after notice on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection, including by considering a commercially reasonable configuration change. If they cannot resolve it, Customer may terminate the affected Service by notice before the new subprocessor begins processing and receive a pro rata refund of prepaid fees for the unused portion of that affected Service. Termination of the affected Service is Customer’s sole remedy for an unresolved subprocessor objection.

An urgent substitution needed to protect security or continuity may occur on shorter notice. Blossom will notify Customer as soon as reasonably practicable and preserve the objection process to the extent feasible.

10. Third-Party Services You Connect

In short: Services Customer connects under its own vendor agreements are not Blossom subprocessors merely because Blossom accesses them on Customer’s instruction.

Customer may direct Blossom to access or interact with third-party services Customer obtains independently, including Customer’s own Gmail or Google Workspace, Microsoft 365, Slack, Zoom, phone systems, notetakers, and tools in Blossom’s connector directory (“Customer-Connected Services”). Those services are selected and contracted for by Customer and are not Blossom subprocessors merely because Customer directs Blossom to access them.

Customer instructs Blossom to exchange Customer Personal Data with each Customer-Connected Service using the permissions Customer provides. Customer is responsible for the provider relationship, lawful basis, notices, consents, settings, permissions, and compliance with that provider’s terms. Blossom’s own vendors used to host, route, automate, or operate those connections remain Blossom subprocessors and appear on the Subprocessor List.

11. AI processing and training restrictions

In short: Customer Personal Data does not train outside AI models unless Customer gives prior, revocable, account-specific consent to an identified exception.

Blossom will not use Customer Personal Data to train, develop, or improve an AI model made available outside Customer’s account. Blossom will contractually prohibit each AI-model subprocessor from using Customer Personal Data to train, develop, or improve its models and will require provider retention restrictions appropriate to the service.

If a high-risk or newly available AI model cannot satisfy those restrictions, Blossom will not enable it for Customer’s account unless Blossom first discloses the model provider, data categories, purpose, and applicable training or retention terms and obtains Customer’s affirmative, account-specific consent. Customer may revoke consent at any time for future processing. After revocation, Blossom will stop sending new Customer Personal Data to that model. Refusal or revocation may make the optional feature unavailable but will not affect unrelated Services.

Raw Scout audit artifacts are purged no later than 90 days after collection and may be purged earlier at the end of onboarding. Model-provider handling within that period remains subject to the restrictions above and the applicable subprocessor agreement.

12. Return, deletion, and retention

In short: Workspace data is deleted within 30 days after account deletion; raw Scout artifacts expire after 90 days; legal records may remain as required.

During the term, Customer may export Customer Personal Data using available functionality. On account deletion or termination, Blossom will delete Customer Personal Data within 30 days, unless Customer requests its return before deletion or applicable law requires longer retention. Raw Scout artifacts are automatically purged no later than 90 days after collection, and a user may trigger earlier purge at the end of onboarding.

Blossom may retain data in limited, access-restricted backups until overwritten in the ordinary backup cycle, provided the data remains protected, is isolated from ordinary use, and is deleted when restored unless law requires otherwise. Blossom may retain billing, tax, legal, fraud, security, and suppression records only for its own lawful purposes and subject to the Privacy Policy; those records are no longer processed on Customer’s behalf.

13. Audits and information

In short: Blossom will provide reasonable compliance information and supports one proportionate audit per year when documents are not enough.

Blossom will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries, questionnaires, or third-party reports that Blossom possesses and may lawfully disclose. If that information is insufficient, Customer may conduct one audit in any 12-month period, and additional audits after a Personal Data Breach or where a regulator requires one.

An audit must be conducted by an independent qualified auditor bound by confidentiality; follow a mutually agreed scope and schedule; occur during normal business hours; avoid access to other customers’ data or material disruption; and comply with Blossom’s security requirements. Customer will give at least 30 days’ notice unless a shorter period is legally required. Customer bears its costs and will reimburse Blossom’s reasonable costs for assistance beyond ordinary questionnaires, unless the audit identifies a material breach by Blossom. Audit results are Blossom Confidential Information. Nothing requires Blossom to reveal data that would compromise another customer, privileged material, trade secrets unrelated to compliance, or information that would create a security risk.

14. US state privacy terms

In short: Blossom acts as a service provider/processor, uses Customer Personal Data only for defined business purposes, and certifies that it understands these restrictions.

For Customer Personal Data subject to US state privacy law, Blossom will:

  • process it only for the limited and specified purposes described in the Agreement, this DPA, and Customer’s lawful instructions;
  • not sell or share it, including for cross-context behavioral advertising;
  • not retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the permitted business purposes, except as allowed by law;
  • not combine it with personal information received from another person or from Blossom’s own interaction with an individual, except as permitted by law;
  • provide the same level of privacy protection required of service providers or processors by applicable law;
  • notify Customer if Blossom determines it can no longer meet its obligations; and
  • allow Customer to take reasonable and appropriate steps to help ensure compliant use and to stop and remediate unauthorized use.

Blossom certifies that it understands and will comply with the restrictions in this Section. The parties agree the processing is for the business purposes of providing, securing, maintaining, supporting, and improving the operation of the contracted Services—not for targeted advertising or sale of Customer Personal Data.

15. International transfers

In short: Blossom is a US service. If restricted data is lawfully transferred to the United States, an applicable recognized transfer mechanism governs, with the SCCs as fallback.

The Services are offered in the United States and Customer will not submit Customer Personal Data from another jurisdiction unless the transfer and use are lawful. If Data Protection Law requires a transfer mechanism for Customer Personal Data transferred to Blossom in the United States, the following applies in order:

  1. a valid adequacy framework, including the EU-U.S. Data Privacy Framework or an applicable extension, only if Blossom is validly self-certified and the framework covers the transfer at that time; then
  2. the European Commission’s 2021 Standard Contractual Clauses (“SCCs”) incorporated through Section 16 for transfers subject to the GDPR; and
  3. another valid mechanism the parties agree in writing.

Blossom does not represent in this DPA that it is currently certified under the Data Privacy Framework. Each party will reasonably cooperate with transfer assessments and supplementary measures required by law.

16. Standard Contractual Clauses

In short: Where needed, the 2021 SCCs apply automatically with practical selections stated here.

For a restricted transfer subject to the GDPR that lacks another valid mechanism, the SCCs adopted by European Commission Implementing Decision (EU) 2021/914 are incorporated by reference and completed as follows:

  • Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
  • the optional docking clause in Clause 7 applies;
  • in Clause 9, Option 2 general written authorization applies, with the notice period in Section 9 of this DPA;
  • in Clause 11, the optional independent dispute-resolution language does not apply;
  • in Clause 17, Option 1 applies and the governing law is the law of Ireland;
  • the courts of Ireland are selected under Clause 18;
  • Annex I of this DPA completes SCC Annex I;
  • the Irish Data Protection Commission is the competent supervisory authority where the SCCs permit that selection, otherwise the authority determined by Clause 13 applies;
  • Annex II of this DPA completes SCC Annex II; and
  • the Subprocessor List completes SCC Annex III.

If Customer Personal Data is subject to UK transfer restrictions, the then-current UK International Data Transfer Addendum issued by the Information Commissioner is incorporated and completed using the information in this DPA, with neither party permitted to end it solely under an optional termination table unless the law requires. For Swiss transfers, references in the SCCs to the GDPR and EU law include the Swiss Federal Act on Data Protection where applicable, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and Swiss residents may enforce applicable rights.

If the SCCs conflict with this DPA, the SCCs control. If a transfer mechanism is invalidated, the parties will cooperate in good faith to implement a valid replacement.

17. Liability and general terms

In short: The Agreement’s liability framework applies, and updates will not materially reduce data protection during the term.

Each party’s liability under this DPA is subject to the Agreement’s exclusions and limits, except to the extent Data Protection Law or the SCCs prohibit a limitation. This DPA ends when Blossom no longer processes Customer Personal Data, except provisions intended to survive. Blossom may update this DPA with at least 30 days’ advance notice of a material change, unless law or an urgent security need requires faster action. An update will not materially reduce protection for Customer Personal Data during an existing term.

This DPA is governed by the law and dispute provisions of the Agreement unless Data Protection Law or the SCCs require otherwise.

18. Contact

In short: DPA questions and notices go to legal@blossom.fm.

Polymath HQ, Inc. d/b/a Blossom
New York, United States
Attention: Noah Lenz
legal@blossom.fm

Annex I — Processing details

A. Parties

In short: Customer exports or controls the data; Blossom imports or processes it to provide the Services.

Data exporter/controller: Customer and any permitted Customer affiliate identified in the Agreement. Contact details are those in the Order or account. Customer’s signature or acceptance of the Agreement is its signature for this DPA and the SCCs.

Data importer/processor: Polymath HQ, Inc. d/b/a Blossom, New York, United States; legal@blossom.fm, Attention: Noah Lenz. Blossom’s acceptance of the Agreement is its signature for this DPA and the SCCs.

B. Processing description

In short: Processing covers the business data Customer chooses to place in Blossom or direct Blossom to access.

ItemDescription
Subject matter and purposeProviding, securing, maintaining, and supporting configurable business software, audits, AI agents, automations, integrations, and related Services under the Agreement
DurationThe Agreement term plus the deletion periods in Section 12
Nature of processingCollection, access, import, organization, storage, retrieval, analysis, transcription, generation, transmission, display, modification at Customer’s instruction, logging, export, and deletion
FrequencyContinuous or as initiated/configured by Customer during the Service term
Data subjectsCustomer users, personnel, contractors, prospects, customers, end users, vendors, counterparties, communication participants, and other people whose data Customer submits or directs Blossom to access
Personal-data categoriesIdentity and contact details; account and organization data; communications and message contents; files and attachments; email, calendar, drive, chat, meeting, phone, audio, recording, and transcript data; business-process and knowledge data; transaction and billing-related data; support data; device, log, and connection data; OAuth tokens and credentials; generated analyses and outputs
Sensitive or special dataMay include account credentials and precise connection data; financial or transaction information; communications content; recordings and voice data; and any health, biometric, employment, demographic, or other sensitive data Customer chooses or instructs Blossom to process. Customer must apply the AUP and appropriate safeguards
Return and deletionStandard export where available; deletion within 30 days of account deletion; raw Scout artifacts purged no later than 90 days after collection, with optional earlier purge at onboarding end; legal retention and limited backups as described in Section 12

C. Transfers to subprocessors

In short: Subprocessor processing follows the purpose and duration needed for each listed service.

The subject matter, nature, and duration of a subprocessor’s processing are limited to the purpose identified on the Subprocessor List and the period Blossom uses that vendor to provide the Services, subject to contractual return, deletion, and legal-retention requirements.

Annex II — Technical and organizational measures

Security measures

In short: Blossom uses layered controls appropriate to a pre-certification service and states only controls it can substantiate.

Blossom’s measures include, as applicable to the Service:

  • authenticated access through WorkOS, organization roles, and user/team permissions;
  • logical tenant separation and authorization checks in application and data access paths;
  • encryption in transit using TLS and encrypted storage supplied by hosting and storage providers;
  • AES-256-GCM encryption for vault-held secrets, with restricted access to encryption keys;
  • OAuth and scoped tokens where supported, with managed token providers identified on the Subprocessor List;
  • customer-configurable connection, permission, approval, and disconnection controls;
  • activity and external-call logging for agent operations within Blossom’s execution path;
  • controls intended to keep payment-card data out of AI prompts and conversations through approved payment flows;
  • production access limited according to role and operational need, with confidentiality obligations;
  • vendor review and written data-protection obligations for subprocessors;
  • monitoring, investigation, containment, remediation, and customer notification procedures for security incidents;
  • data minimization and retention controls, including 90-day raw Scout artifact purge and account-deletion timelines; and
  • periodic review and improvement of safeguards based on risk and system changes.

These measures do not represent a certification. The Security Overview provides current public detail.

Changelog

In short: This is the first working-draft version.

DateVersionChange
July 22, 20260.1Initial working draft for counsel review.