Back to TaskGlaze

Data Processing Agreement

Effective date: July 20, 2026·Last updated: July 20, 2026

BLUELINKS GROUP LTD (company no. 16277222), registered office: 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency.

If you use TaskGlaze's Outreach CRM or audit features to process personal data belonging to other people — your prospects, contacts, or individuals whose data appears on a website you audit — you are the data controller for that data, and we act as your processor. This Data Processing Agreement sets out the Article 28 GDPR/UK GDPR terms that govern that processing, and applies automatically alongside our Terms of Service.

1.Parties, scope & how this Agreement applies

This Data Processing Agreement ("DPA") is entered into between you, the TaskGlaze account holder, acting as data Controller("Customer", "you"), and BLUELINKS GROUP LTD, a company registered in England and Wales under company number 16277222, whose registered office is at 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF, trading as Bluelinks Agency and operating TaskGlaze ("Processor", "we", "us"), and forms part of, and is incorporated into, our Terms of Service.

This DPA applies automatically, without any further signature required, whenever you use the Service to process personal data of third parties for which you act as Controller — most commonly, Outreach CRM prospect/contact records and any personal data encountered while auditing a website you submit. It supplements, and does not replace, our Privacy Policy, which separately covers our processing of your ownAccount data (where we act as Controller, not Processor — see that Policy's "When we are controller vs. processor" section).

If your organization requires a separately countersigned copy of this DPA (for example, for your own vendor-approval process), contact support@taskglaze.com and we will provide one on the same terms set out below.

2.Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Sub-processor" have the meanings given in UK GDPR / the EU General Data Protection Regulation (Regulation (EU) 2016/679), as applicable (together, "Data Protection Law"). "Customer Personal Data" means the personal data described in "Nature, purpose & categories of processing" below that we process on your behalf as Processor.

3.Subject matter & duration

The subject matter of processing is our provision of the TaskGlaze Service to you, as described in the Terms of Service. Processing lasts for the duration of your Account's active subscription (including any trial), plus the retention/ deletion period described in "Return or deletion of data" below.

4.Nature, purpose & categories of processing

Nature and purpose.We process Customer Personal Data solely to provide the Service's Outreach CRM, audit, and related features to you — storing, organizing, transmitting (including sending email through a Connected Account at your instruction), and displaying that data back to you within the Service.

Duration. We process Customer Personal Data for as long as necessary to provide the Service under the Terms of Service — in practice, for as long as your Account remains active, plus the retention/deletion period described in the Privacy Policy's "Data retention" table, or as otherwise required by applicable law.

Categories of data subjects: your outreach prospects/contacts, and individuals whose personal data is incidentally published on a website you submit for auditing.

Categories of personal data:

CategoryExamples
Outreach CRM prospect/contact dataName, email address, job title, company, phone number, and any notes or correspondence you add about them
Outreach correspondence contentThe subject/body of emails sent and received through a Connected Account, on your instruction
Website/technical data encountered during auditsPublicly accessible page content and metadata for domains you submit — may incidentally include personal data published on those pages (e.g. a named author, a listed contact email)

Special categories of data.We do not knowingly process special category (Article 9 GDPR) personal data — data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation — through the Service, and you agree not to submit such data. This prohibition also covers financial account credentials and authentication secrets (passwords, API keys, tokens) — see the Privacy Policy's "AI processing disclosure" section for where this matters most in practice.

5.Processing only on your instructions

We will process Customer Personal Data only on your documented instructions — which consist of this DPA, the Terms of Service, and your ordinary use of the Service's features (e.g. importing a contact, sending an outreach email, running an audit) — unless we are required to do otherwise by law, in which case we will inform you before processing (unless that law prohibits us from doing so on important grounds of public interest). If we reasonably believe an instruction infringes Data Protection Law, we will inform you promptly.

6.Confidentiality of personnel

We ensure that any person we authorize to process Customer Personal Data (including employees and contractors) is subject to a binding obligation of confidentiality, and processes that data only as necessary for the purposes of this DPA.

7.Security measures (Article 32)

We implement appropriate technical and organizational measures to protect Customer Personal Data, including:

  • Encryption in transit (HTTPS/TLS) for all traffic to the Service;
  • Encryption at rest (AES-256-GCM) for sensitive stored secrets, including connected-mailbox credentials;
  • Password hashing (bcrypt) and optional two-factor authentication for Account access;
  • Account-lockout and rate-limiting controls against automated credential-guessing;
  • Access to Customer Personal Data restricted to designated staff on a need-to-know basis, gated by an admin-only flag and mandatory two-factor authentication on that access;
  • Regular encrypted backups, and a documented incident-response process.

Full detail is in our Privacy Policy's "Data security" section.

8.Sub-processors

You provide us with general written authorization to engage the Sub-processors listed in our Privacy Policy's subprocessor table, each engaged for the purpose stated there and bound by data-protection terms materially no less protective than this DPA.

If we add a new Sub-processor or replace one in a way that materially changes how Customer Personal Data is handled, we will update that table (and the "Last updated" date on this page and the Privacy Policy) with reasonable advance notice. If you have a reasonable data-protection objection to a new Sub-processor, notify us at support@taskglaze.com within 14 days of the update; we will work with you in good faith to address the objection, which may include your right to terminate the affected feature or your subscription without penalty if it cannot be resolved.

9.Assistance with data subject rights

Taking into account the nature of the processing, we will assist you — through the Service's own account-management features where possible, and otherwise by responding to a request sent to support@taskglaze.com— in fulfilling your obligation to respond to a data subject's request to exercise their rights (access, rectification, erasure, restriction, portability, or objection) under Data Protection Law. If a data subject contacts us directly about your Customer Personal Data, we will promptly forward that request to you rather than respond to it ourselves.

10.Personal data breach notification

We will notify you without undue delay, and in any event within 72 hours of becoming aware of it, after a Personal Data Breach affecting Customer Personal Data — this is our own concrete commitment to you, not just a restatement of the separate 72-hour window UK/EU controllers themselves have to notify their supervisory authority.

Where reasonably available to us at the time, that notification will include:

  • The nature of the breach, including, where possible, the categories and approximate number of data subjects and personal data records concerned;
  • A contact point where you can get more information;
  • The likely consequences of the breach;
  • The measures we have taken or propose to take to address it, including to mitigate its possible adverse effects.

Where it is not possible to provide all of the above within 72 hours, we will provide it in phases without undue further delay. We will provide reasonable assistance in investigating and mitigating the breach's effects, and in meeting your own downstream notification obligations (including, for UK/EU controllers, their own 72-hour notification window to the relevant supervisory authority).

11.Assistance with DPIAs & prior consultation

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to you in complying with your own obligations relating to data protection impact assessments and prior consultation with a supervisory authority, where those obligations relate to your use of the Service.

12.International data transfers

Our own infrastructure is hosted in Germany (EU) — see the Privacy Policy. Where a Sub-processor transfers Customer Personal Data outside the UK/EEA, we rely on an appropriate transfer mechanism recognized under Data Protection Law (such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or the Sub-processor's own certification under an approved framework). A copy of the relevant mechanism for a specific Sub-processor is available on request at support@taskglaze.com.

13.Audit & information rights

On reasonable written request, no more than once per 12-month period (except following a Personal Data Breach affecting your Customer Personal Data, or where required by a supervisory authority), we will make available the information reasonably necessary to demonstrate compliance with this DPA, and will permit and contribute to an audit — which may, at our discretion, be satisfied by providing a written summary of our relevant security and compliance measures in place of an on-site audit, given the scale of a self-serve SaaS engagement. Any audit findings are Confidential Information under the Terms of Service.

14.Return or deletion of data

On termination or expiry of your subscription, we will make Customer Personal Data available for export for the period described in the Privacy Policy's retention table (30 days for account deletion; a locked, read-only Account otherwise retains full export access until you request deletion). After that period, we will delete Customer Personal Data, except: (a) suppression/opt-out records, which we retain independently to comply with anti-spam law and prevent re-contacting an opted-out individual (see the Terms' "Outreach CRM & connected email accounts" section); and (b) data we are required to retain by law (e.g. billing records).

Backups containing Customer Personal Data age out of our rolling backup retention schedule (see the Privacy Policy's retention table) in the ordinary course, without any separate action needed.

15.Liability

Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the "Limitation of liability" section of the Terms of Service.

16.Standard Contractual Clauses annex

Where a transfer of Customer Personal Data outside the UK/EEA under this DPA requires the Standard Contractual Clauses (or the UK International Data Transfer Addendum) to be formally completed, the following applies without further action needed from either party: the data exporter is you, the Customer, identified by the account/billing details on your TaskGlaze Account; the data importer is BLUELINKS GROUP LTD, at the registered office stated in the header of this document; the module that applies is Module Two (Controller to Processor), since we act as your processor for Customer Personal Data as described above; and the technical and organizational security measures required by Annex II of the SCCs are those listed in "Security measures (Article 32)" above.

By using the Service to transfer Customer Personal Data to us in a manner that requires the SCCs, you and we are each deemed to have executed the SCCs (including their annexes) on those terms. If your organization requires a separately completed and countersigned copy of the SCCs for your own records, contact support@taskglaze.com and we will provide one.

17.Term, governing law & general

  1. Term. This DPA takes effect on the date you first submit Customer Personal Data to the Service and continues for as long as we process Customer Personal Data on your behalf.
  2. Order of precedence. If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails to the extent of that conflict.
  3. Governing law. This DPA is governed by the laws of England and Wales, consistent with the Terms of Service.
  4. Changes. We may update this DPA to reflect changes in Data Protection Law or our processing activities, with reasonable advance notice for material changes, following the same process as changes to the Terms of Service.

18.Contact

BLUELINKS GROUP LTD, trading as Bluelinks Agency (operating TaskGlaze), can be reached for any question about this DPA, or to request a countersigned copy, at support@taskglaze.com.

Questions about this document?

Contact us at support@taskglaze.com and we'll get back to you within a few business days.

BLUELINKS GROUP LTD (company no. 16277222), 167-169, 5th Floor, Great Portland Street, London, England, W1W 5PF.