Roles
customer is the data controller. blueprint is the data processor (or sub-processor where the customer is itself a processor).
● New: the 2026 Operating Letter is live Read it →
Effective May 28, 2026
this DPA forms part of the MSA between blueprint and the customer and governs the processing of personal data.
customer is the data controller. blueprint is the data processor (or sub-processor where the customer is itself a processor).
blueprint processes personal data only as necessary to deliver the services described in the MSA or applicable SOW.
current list at /legal/sub-processors. 30-day change notification.
aligned with our SOC 2 Type II controls. described at /platform/security.
we assist the customer in responding to data subject requests within applicable legal timeframes.
customer notified without undue delay, generally within 72 hours of confirmed breach.
annual SOC 2 report available. on-site audit on request, at customer expense.
SCCs in place for EU↔US transfers. data residency options on enterprise tier.
Questions?
contact legal@theblueprintcompany.org.