Bluelake
Data Processing Agreement
Last updated October 4, 2026
This Data Processing Agreement (the "DPA") sets out how Bluelake (a French simplified joint-stock company, 60 rue François 1er, 75008 Paris, SIREN 101 883 510, R.C.S. Paris) processes personal data on behalf of its customers, as required by Article 28 of the General Data Protection Regulation (GDPR). It applies, without signature, to every company whose team uses Bluelake (the "Customer"), as soon as Bluelake processes Customer Personal Data. It supplements our Terms of Use and, on the processing of Customer Personal Data, prevails over them. For any question: privacy@getbluelake.ai.
1. Roles and scope
Customer Personal Data means the personal data of people other than the Customer's users that Bluelake processes on the Customer's behalf:
- the files the Customer's users attach to Billy, such as CVs and job descriptions, and the text read from them;
- what Billy reads in the Customer's CRM, what Bluelake writes there at a user's request, the record of those writes and the reviews of list imports;
- what Billy reads in the Gmail mailbox and the Google Calendar of a user who connects them;
- what users write to Billy about other people, in Bluelake or in Slack, Billy's answers about them, and Billy's memory.
For Customer Personal Data, the Customer is the controller and Bluelake its processor. Bluelake remains the controller, under its Privacy Policy and outside this DPA, of the users' own data (account, use of the product, billing, feedback), of its relationship with the Customer's contacts, and of the public professional data presented in Bluelake, including the contact details found at a user's request.
2. Details of the processing
- Purpose: providing Bluelake to the Customer's users, by keeping what they attach and write so that they can find it again, and by letting Billy read it, with the tools the Customer connects, to answer their questions and do what they ask, such as adding a contact to the CRM.
- Duration: as long as the Customer uses Bluelake, then until deletion under section 10.
- People concerned: the Customer's candidates, consultants, contacts and prospects, and anyone named in a document, a CRM record, an email, a calendar event or a conversation with Billy.
- Data: identity and contact details, professional background (career, skills, availability, daily rates, references), the content of documents, CRM records (notes, calls, meetings), emails and calendar events.
- Sensitive data: Bluelake needs no special category of personal data (Article 9 GDPR) and no data relating to criminal convictions. The Customer's users should not attach or write any.
3. Instructions
Bluelake processes Customer Personal Data only on the Customer's documented instructions, which are this DPA, the Terms of Use and what its users do in Bluelake, including for transfers outside the European Union (section 7). Bluelake tells the Customer if it believes an instruction infringes data protection law.
Bluelake does not sell Customer Personal Data, does not use it to train AI models or to prospect the Customer's clients, and never shows it to another customer.
Bluelake administrators can read conversations with Billy, including the files attached to them, to understand how Billy is used and improve Bluelake. For this use, Bluelake acts as a controller, on the basis of its legitimate interest, and the Customer authorizes it by this DPA. Every reading is logged. Each user can turn this off at any time with Help improve Bluelake, in My profile.
4. Confidentiality
The people at Bluelake who can access Customer Personal Data are bound by confidentiality, and access it only as needed to provide, secure and improve Bluelake.
5. Security
Bluelake implements the technical and organizational measures described in the Annex, and adapts them as Bluelake changes, so that Customer Personal Data keeps a level of security appropriate to the risk (Article 32 GDPR).
6. Sub-processors
The Customer authorizes Bluelake to use the following sub-processors for Customer Personal Data:
- Supabase (database, authentication and file storage): European Union (Paris, France).
- Vercel (application hosting): the application runs in Paris, France.
- Anthropic (the AI model behind Billy): United States. Anthropic does not use the data to train its models and deletes it within 30 days, unless a legal obligation or a breach of its usage policy requires keeping it longer.
- Google Cloud (daily backups of the database): European Union (Belgium). Each backup is deleted after 30 days.
- Sentry (error monitoring): European Union. Error reports leave Bluelake without request content, cookies, headers or user identity.
- PostHog (usage measurement): European Union. It records the pages viewed and the actions taken: addresses leave without their search terms or the name in a profile link, clicks without the text clicked, and session replays mask all text, inputs, labels and tooltips.
Each sub-processor is bound by a contract with data protection obligations no less protective than those of this DPA, including, for the companies based in the United States, the standard contractual clauses adopted by the European Commission. Bluelake remains responsible to the Customer for its sub-processors.
Bluelake informs the Customer by email at least 15 days before a new sub-processor starts processing Customer Personal Data. Within that time, the Customer may object on reasonable grounds; if no solution is found, the Customer may stop using the feature concerned, or Bluelake.
The Customer's CRM, its Slack workspace and its users' Google accounts are run by their providers under the Customer's own agreements with them, and are not Bluelake's sub-processors. Bluelake reads them and writes to them only as described in our Privacy Policy, with the access the Customer grants.
7. Transfers outside the European Union
Bluelake stores Customer Personal Data in the European Union. When Billy answers, the question and the context it needs, including the text of attached files, are processed by Anthropic in the United States. This transfer, and any access from outside the European Union by the companies listed in section 6, are framed by the standard contractual clauses adopted by the European Commission.
8. Assistance
If a person asks Bluelake to exercise their rights over Customer Personal Data, Bluelake forwards the request to the Customer without answering it, and helps the Customer answer it. Users can also delete a conversation and its files themselves at any time.
Bluelake gives the Customer the information it reasonably needs to meet its own obligations on security, personal data breaches, data protection impact assessments and prior consultation (Articles 32 to 36 GDPR).
9. Personal data breaches
Bluelake notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice gives what Bluelake knows at that point: the nature of the breach, the categories and approximate number of people and records concerned, its likely consequences, the measures taken or proposed, and a contact point. Bluelake completes it as it learns more.
10. Deletion and return
When a user deletes a conversation, Bluelake deletes it with its files. When a user's account is deleted, access is closed at once and the Customer Personal Data it holds is permanently erased within 30 days. When the Customer stops using Bluelake, it chooses whether Bluelake deletes the accounts of all its users, or first returns a copy of the Customer Personal Data: write to privacy@getbluelake.ai. Each daily backup is deleted after 30 days. At the end of the service, Bluelake deletes the remaining copies, unless the law requires keeping them.
11. Audits
Bluelake makes available the information needed to demonstrate compliance with this DPA, starting with this page and our Privacy Policy, and answers the Customer's security and privacy questionnaires. The Customer, or an independent auditor it appoints who is bound by confidentiality, may also audit this compliance once a year, or more often after a personal data breach or at a supervisory authority's request, with 30 days' notice, during business hours and without access to other customers' data. Each party bears its own costs.
12. Liability, changes and governing law
Each party's liability under this DPA is governed by the Terms of Use. Bluelake may update this DPA. It informs the Customer by email at least 30 days before an update that reduces the protection of Customer Personal Data, and the Customer may then stop using Bluelake. A new sub-processor follows section 6. This DPA is governed by French law, and the courts of Paris have jurisdiction, as under the Terms of Use.
Annex: security measures
- The database, authentication and files are hosted in the European Union (Paris) and encrypted at rest by the host; all exchanges are encrypted in transit (HTTPS).
- Data is separated by account and by team in the database itself: a user sees only what their account can see, and Billy acts with the rights of the user who talks to it.
- Sign-in is passwordless, by a single-use link sent by email.
- The API keys of the Customer's CRM and the Slack and Google tokens are stored encrypted and never displayed again.
- Every reading of a conversation by the Bluelake team is logged.
- Error reports are stripped of request content, cookies, headers and user identity before they leave Bluelake. Usage measurement places no cookie; addresses leave it without their search terms or the name in a profile link, clicks without the text clicked, and its session replays mask all text, inputs, labels and tooltips.
- The database is backed up daily in the European Union (Belgium), and each backup is deleted after 30 days.
- Access to production systems is limited to the Bluelake team members who need it.