Privacy Policy

Last updated: 22 July 2025

1. Introduction

BlobBridge (“we”, “us”, “our”) is committed to protecting your personal data and respecting your privacy. This policy explains how we collect, use, share and protect information in accordance with the UK General Data Protection Regulation (UK GDPR), the Privacy and Electronic Communications Regulations (PECR) and the Data (Use and Access) Act 2025.

2. What data we collect

We collect the following categories of personal data:

3. How we use your data & legal bases

PurposeDataLegal basis
Process your purchase and issue licenceIdentity, Contact, TransactionContract (Article 6 (1)(b))
Provide support and respond to enquiriesIdentity, Contact, Tenant IDLegitimate interest – to deliver customer service (Article 6 (1)(f))
Maintain financial records for HMRCTransaction, IdentityLegal obligation (Article 6 (1)(c))
Measure site performance (aggregated, cookieless analytics)Legitimate interest Consent (Article 6 (1)(f))

4. Who we share data with

We use trusted third‑party service providers (“processors”):

ProcessorServiceData sharedSafeguards
Stripe Payments Europe LtdPayment processingIdentity, Contact, TransactionUK extension to EU–US DPF
Cloudflare Inc.Licence delivery, CDN & securityIdentity, Contact, IPUK extension to EU–US DPF
Formspree Inc.Contact‑form relayIdentity, Contact, MessageStandard Contractual Clauses
MailChannels CorporationTransactional e‑mailIdentity, Contact, Tenant IDSCCs + data-at‑rest encryption

We do not sell or share your data with unrelated third parties for marketing purposes.

5. International transfers

Your data may be processed outside the UK/EEA (e.g., in the United States). Where this occurs we rely on:

6. Data retention

We retain:

7. Your rights

You have the right to:

To exercise any right, e‑mail [email protected].

8. Cookies

We use Cloudflare Web Analytics in cookieless mode; no persistent identifiers or personal data are stored. We do not set any marketing or analytics cookies. Cloudflare Web Analytics collects traffic metrics without cookies or localStorage. Your browser may still receive a transient ‘__cf_bm’ security cookie, set by Cloudflare to mitigate bots; it expires within 30 minutes.

9. Security

We employ TLS 1.3 encryption, strict CSP headers, vulnerability scans and role‑based access controls. Our Stripe integration is PCI DSS Level 1 compliant.

10. Children

Our site is not intended for children under 13. We do not knowingly collect their data.

11. Changes to this policy

We may update this notice periodically. Significant changes will be announced on the website or by e‑mail.

12. Contact

E‑mail: [email protected]