Privacy Policy

Blueprint Technologies B.V.

Last updated: 17 September 2026

This policy explains what personal data Blueprint Technologies B.V. (“Blueprint”, “we”, “us”) collects, why, and what you can do about it. It covers our website at blueprint.tl, the Blueprint platform, and our contact with customers and prospects. Section 11 also sets out the terms under which we process personal data on behalf of our customers, which the Terms of Service incorporate by reference.

1. Who is responsible

Blueprint Technologies B.V.
Moerdijkstraat 45-2, 1079XM, Amsterdam, the Netherlands
KvK: 42135393
VAT: NL869879832B01
Email: [email protected]

We have not appointed a data protection officer. Questions about this policy go to the email address above.

2. What the platform does with data

The platform monitors publicly accessible information retailer websites and marketplace. This data describes products and shops, not people. We do not build the platform to collect personal data from the pages it monitors, and our Terms of Service forbid customers from pointing it at pages that contain personal data, with the exempt of product reviews.

3. Personal data we collect and why

3.1 Account and sign-in data

When someone creates an account or is invited into a customer’s workspace, we receive their name, email address, the organization they belong to and their role. Sign-in is handled by our authentication provider (see section 5); we keep their identifier, the times they sign in and the IP address a session came from. We use this to run the account, keep it secure and tell the right people about changes to the platform.

3.2 Notification settings

Customers configure where the platform sends alerts: email addresses, Slack channels, etc. These may contain names and work email addresses of the customer’s staff. We use them only to deliver the alerts the customer set up. Here we act on the customer’s behalf; section 11 applies.

3.3 Technical and usage data

Our servers log requests to the platform: the time, the path, the user and organization identifier, the IP address, the browser type and any error that occurred. We use these logs to keep the service running, find and fix faults, detect abuse and understand which features are used.

3.4 Contact, sales and support

If you fill in a contact form, book a meeting, email us or ask for support, we keep your name, email address, company, the content of the correspondence and any notes we make. We keep prospects and customers in a customer relationship system so we know who we have spoken to and what was agreed.

3.5 Billing

For invoicing we hold the customer’s company details, the billing contact’s name and email address, and payment records.

3.6 Website visitors

Our provider’s servers log the usual technical data for each visit: IP address, browser, pages viewed and the referring site.

4. What we do not do

We do not sell personal data. We do not use it for advertising. We do not make automated decisions about individuals that have legal or similar effects on them. We do not knowingly collect data from anyone under 18, and the platform is not meant for them. We do not process special categories of personal data such as health or political opinions, and we ask you not to send us any.

5. Who we share data with

We use a small number of providers to run the platform. Each one processes data only on our instructions, under a written agreement, and only for the purpose listed.

Provider

Purpose

Data

Location

Hetzner Online GmbH

Hosting of the platform, database and stored images

All platform data

Germany and Finland (EU)

WorkOS, Inc.

Authentication, organizations and user invitations

Name, email address, organization, role, sign-in events

United States

Resend, Inc.

Sending transactional email and alerts

Recipient email address, message content

United States

Framer B.V.

Hosting of the marketing website

Visitor technical data

Netherlands

AI model provider

Generating content and analyzing data

Product information, no customer personal data

United States

We name the page retrieval and AI model providers on request. We will tell customers at least 30 days before we add or replace a provider that handles their data (see section 11.6).

Beyond these providers we share personal data only with our accountants and legal advisers where needed, with a buyer or successor if our business is sold or merged, and with authorities where the law requires it.

6. Transfers outside the European Economic Area

Some providers above are in the United States. Where we transfer personal data outside the EEA we rely on the European Commission’s adequacy decision for the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the Commission’s standard contractual clauses, together with any extra measures needed. Copies of the relevant clauses are available on request.

7. How long we keep data

Data

Retention

Account and workspace data

For the life of the account, then 30 days so the customer can export it, then deleted

Notification settings

Same as the account

Server and security logs

90 days

Contact, sales and support correspondence

2 years after the last contact

Billing records

7 years, as Dutch tax law requires

Website visitor logs

As set by Framer, at most 30 days on our side

Backups are kept for 30 days and then overwritten. Data in a backup is deleted when the backup expires.

8. Security

We protect personal data with encrypted connections, access limited to the people who need it, separate credentials per system, logging of access, and regular updates of the software we run. Customer workspaces are separated from each other in the platform. No system is completely secure; if we learn of a breach that affects your data we will tell you and, where required, the Dutch Data Protection Authority, without undue delay.

9. Your rights

Under the General Data Protection Regulation (GDPR) you can ask us to:

  • tell you what personal data we hold about you and give you a copy;

  • correct data that is wrong or incomplete;

  • delete your data;

  • limit what we do with it;

  • give you your data in a machine readable format;

  • stop processing based on our legitimate interest, where your situation gives you reason to object.

Where we process your data on a customer’s behalf (section 11), we will pass your request to that customer, who decides on it. Otherwise email [email protected] and we will answer within one month. We may ask you to confirm your identity first.

You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or the supervisory authority of the EU country where you live or work.

10. Cookies

The platform sets two cookies, both needed for it to work: a session cookie from our authentication provider that keeps you signed in, and a cookie that remembers which table columns you chose to show. Neither is used for tracking, and neither needs consent.

11. Processing on behalf of customers

This section is the written agreement that article 28 of the GDPR requires between a customer (the “Customer”, as controller) and Blueprint (as processor). It applies whenever Blueprint processes personal data on the Customer’s behalf under the Terms of Service, and it forms part of the Agreement defined there. The Customer accepts it by accepting the Terms. Capitalized terms not defined here have the meaning given in the Terms.

11.1 Scope of the processing

Subject matter: the personal data the Customer and its Authorized Users enter into the platform, chiefly notification settings (section 3.2) and the details of Authorized Users the Customer invites.
Duration: the term of the Agreement plus the 30 day export period after it ends.
Nature and purpose: hosting, storing and displaying the data, and using it to send the alerts and reports the Customer configures.
Categories of data subjects: the Customer’s employees, contractors and other staff.
Categories of personal data: names, work email addresses, roles, and identifiers in Slack channels or webhook URLs. No special categories of data.

11.2 Instructions

Blueprint processes this data only on the Customer’s documented instructions. The Agreement, the settings the Customer makes in the platform and any written instruction sent to [email protected] count as instructions. If Blueprint believes an instruction breaks the law it will tell the Customer and may pause the affected processing. If EU or Dutch law requires Blueprint to process the data otherwise, Blueprint will inform the Customer beforehand unless the law forbids that.

11.3 Confidentiality

Only people who need the data to provide the Service have access to it, and each of them is bound by a confidentiality obligation.

11.4 Security

Blueprint takes the technical and organizational measures described in section 8 and keeps them appropriate to the risk. Blueprint helps the Customer meet its own security obligations under article 32 of the GDPR, taking into account the nature of the processing and the information available to Blueprint.

11.5 Personal data breaches

If Blueprint learns of a breach affecting the Customer’s personal data, it informs the Customer without undue delay and in any case within [48] hours of becoming aware of it. The notice describes the nature of the breach, the data and people concerned as far as known, the likely consequences, the measures taken, and a contact for more information. Blueprint helps the Customer with the notifications the Customer must make.

11.6 Sub-processors

The Customer authorizes Blueprint to use the providers in section 5 as sub-processors. Blueprint binds each sub-processor to obligations equivalent to those in this section and remains responsible to the Customer for their performance. Blueprint tells Customers at least 30 days before adding or replacing a sub-processor, by email to the Account administrators. A Customer that objects on reasonable data protection grounds may terminate the affected Subscription before the change takes effect, and Blueprint refunds prepaid fees for the remaining term.

11.7 Transfers

Blueprint transfers personal data outside the EEA only under the safeguards in section 6.

11.8 Help with rights and assessments

Blueprint forwards to the Customer any request from a data subject about the Customer’s data, and helps the Customer answer it. Blueprint gives the Customer the information it needs for a data protection impact assessment or a consultation with a supervisory authority, as far as that concerns Blueprint’s processing.

11.9 Deletion and return

For 30 days after the Agreement ends the Customer can export its data through the platform. After that Blueprint deletes the Customer’s personal data, and copies in backups expire on the schedule in section 7, unless EU or Dutch law requires Blueprint to keep some of it.

11.10 Audits

Blueprint gives the Customer the information needed to show that it meets the obligations in this section. Once a year, or after a breach, the Customer may audit Blueprint’s compliance on 30 days’ written notice, during business hours, without disrupting the Service, at the Customer’s cost, either itself or through an independent auditor bound by confidentiality. Blueprint may satisfy an audit request with a recent third party audit report or certification where it has one.

11.11 Liability

Liability under this section is subject to the limitations in the Terms of Service. If Blueprint engages a sub-processor, it remains liable towards the Customer for that sub-processor’s obligations to the extent set out there.

11.12 Precedence

If this section and the Terms of Service conflict on the processing of personal data, this section prevails. Mandatory data protection law prevails over both.

12. Changes to this policy

We may update this policy when the platform, our providers or the law change. We post the new version at blueprint.tl/privacy with a new date, and we email Account administrators about changes that affect how we handle customer data at least 30 days in advance.

13. Contact

Blueprint Technologies B.V.
Moerdijkstraat 45-2, 1079XM, Amsterdam, the Netherlands
Email: [email protected]

Retail intelligence for brands that sell through online channels.

Resources

Company

Careers

© 2026 Blueprint Technologies / Amsterdam

Privacy / Terms / Status