This page explains how blueclip (Blueclip Limited) complies with the EU General Data Protection Regulation (GDPR). It summarizes the lawful bases on which we process personal data, your rights as a data subject, how we handle international transfers, and how to contact us. For full detail, see our Privacy Policy.
1. Our Role: Controller and Processor
blueclip acts in two capacities:
- Data Processor for Customer Business Data. When you use the blueclip platform, you (the customer) are the data controller and blueclip processes that data on your behalf under a Data Processing Agreement (DPA).
- Data Controller for account information, website visitor data, and communications we collect directly (for example, when you register, contact our sales team, or visit our website).
2. Lawful Bases for Processing
We process personal data under the following lawful bases in Article 6 of the GDPR:
- Contract performance - to provide access to the platform, manage accounts and user access, deliver support, and issue invoices.
- Legitimate interests - to analyze anonymized and aggregated usage data, improve our platform and AI capabilities, ensure security and integrity, and prevent fraud and abuse. We have conducted Legitimate Interest Assessments for these activities, available on request.
- Consent - for non-essential cookies and marketing communications. Where processing is based on consent, you may withdraw it at any time.
- Legal obligation - where required to comply with applicable law, such as tax and regulatory requirements.
3. Your Rights as a Data Subject
If you are located in the EEA, you have the following rights over your personal data:
| Right | What it means |
|---|---|
| Access | Obtain confirmation of whether we process your data and a copy of it. |
| Rectification | Have inaccurate or incomplete personal data corrected. |
| Erasure | Have your data deleted where it is no longer necessary ("right to be forgotten"). |
| Restriction | Restrict processing of your data in certain circumstances. |
| Data portability | Receive your data in a structured, commonly used, machine-readable format. |
| Object | Object to processing based on legitimate interests, and to direct marketing at any time. |
| Withdraw consent | Withdraw consent at any time where processing is based on consent. |
| Lodge a complaint | Complain to your local supervisory authority (in Ireland, the Data Protection Commission). |
To exercise any of these rights, contact us at privacy@blueclip.ai. We respond within the timeframe required by law (generally one month). We may need to verify your identity first. If you are an end user of a customer organization, we may direct your request to that organization, as blueclip acts as a processor on its behalf.
4. International Data Transfers
Blueclip Limited is established in Ireland, and customer data is processed and stored within the European Union / European Economic Area (EEA). Where personal data is transferred outside the EEA, we rely on appropriate safeguards:
- Transfers outside the EEA: Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions where applicable, and supplementary technical and organizational measures.
Our Data Processing Agreement incorporates the SCCs. You may request a copy by contacting privacy@blueclip.ai.
5. Sub-Processors
We engage sub-processors to help operate the platform (for example, cloud infrastructure, authentication, AI inference, and monitoring providers). Each is bound by a written contract providing data protection no less protective than our DPA. The current list of authorized sub-processors is maintained in Annex C of the DPA and is available on request. We notify customers at least 30 days before engaging or replacing a sub-processor.
6. Data Retention and Security
We retain personal data only as long as necessary for the purposes for which it was collected or as required by law, and we delete or anonymize it on account termination within the timeframes set out in our Privacy Policy. We protect personal data with encryption at rest and in transit, role-based access control, multi-factor authentication, tenant isolation, and audit logging. blueclip maintains SOC 2 compliance; our security documentation is available to customers under NDA.
7. Data Protection Officer and Contact
For any GDPR or data protection inquiry, including exercising your rights, contact:
Data Protection Officer
Blueclip Limited
Venture Hub, 136 Capel Street, Dublin, D01 T2C9, Ireland
Email: privacy@blueclip.ai
You also have the right to lodge a complaint with your local data protection supervisory authority. In Ireland, this is the Data Protection Commission (dataprotection.ie).