Privacy Policy
Last updated: 3 September 2026
This Privacy Policy explains how we handle personal data when you use our marketing site at bluplai.com and BluPlai Boards at boards.bluplai.com (together, the "Service"). The former workspace host at app.bluplai.com is closed and redirects to Boards; it is no longer a sign-up surface. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR).
1. Who is responsible
The controller (Verantwortlicher) within the meaning of Article 4(7) GDPR is:
NavAIgate GmbH & Co. KG
Gerhart-Hauptmann-Straße 59, 85055 Ingolstadt, Germany
Amtsgericht Ingolstadt, HRA 4530 — represented by its general partner NavAIgate
Management GmbH (Amtsgericht Ingolstadt, HRB 13007), managing director Daniel Wright
Email: dw@bluplai.com
bluplai is the product name; the company above operates it. Full register details are on our Impressum page. We have not appointed a data protection officer, because we are not required to under Article 37 GDPR and section 38(1) of the German Federal Data Protection Act (Bundesdatenschutzgesetz) — we employ fewer than 20 people on automated processing. Data protection requests reach a person directly at dw@bluplai.com, and we answer within the statutory one-month period.
2. Two different roles
It matters which hat we are wearing:
- We are the controller for data about you as a visitor or account holder — your registration and login details, your billing data, your support messages, and the technical logs of your use of the Service. This policy describes that processing.
- We are a processor (Auftragsverarbeiter) for the content you put into your workspaces — including personal data about your own customers, guests, stakeholders and survey respondents. For that data you are the controller, you decide the purposes, and we act only on your documented instructions. Article 28(3) GDPR requires a data processing agreement (Auftragsverarbeitungsvertrag) between us: ask at dw@bluplai.com and we will put one in place.
If you are a guest or a survey respondent and someone invited you into a workspace, the organisation that invited you is the controller for what happens in that workspace. Please direct requests about that data to them; we will pass on requests we receive and support them in answering.
3. What we collect, why, and on what legal basis
- Account information — name, email address, profile picture and the identifier your identity provider gives us when you sign in (for example via Google). Purpose: creating and securing your account and giving you access. Legal basis: Article 6(1)(b) GDPR (performance of the contract).
- Workspace and content data — organisations, accounts and their workspaces, stakeholders, projects, boards, surveys and documents you author. Purpose: providing the Service. Legal basis: Article 6(1)(b) GDPR for you as our customer; for personal data about third parties inside your workspace we act as your processor under Article 28 GDPR and you provide the legal basis.
- Usage and log data — pages visited, features used, device and browser type, IP address and timestamps. Purpose: keeping the Service available and secure, detecting and preventing misuse, and improving it. Legal basis: Article 6(1)(f) GDPR (our legitimate interest in a stable, secure and improving service).
- Billing data — the details needed to invoice you and to meet our tax obligations. Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR (compliance with legal obligations under German tax and commercial law).
- Support and enquiry correspondence — what you write to us and what we reply. Legal basis: Article 6(1)(b) GDPR where it concerns your contract, otherwise Article 6(1)(f) GDPR (answering enquiries).
- Consent-based processing — where we ask for your consent, the legal basis is Article 6(1)(a) GDPR and you can withdraw it at any time with effect for the future (Article 7(3) GDPR).
We do not sell personal data, and we do not use your workspace content to train our own or third-party AI models. We do not carry out automated decision-making producing legal effects within the meaning of Article 22 GDPR. Where the Service generates AI output, a person on your side decides what to do with it.
4. Cookies and similar technologies
Storing information on your device, or reading information already stored there, needs your consent unless it is strictly necessary to provide the service you asked for (section 25 of the German Telecommunications Digital Services Data Protection Act, Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz, TDDDG).
- Strictly necessary. The application sets cookies to keep you signed in and to protect the session (through Clerk), and our hosting providers set cookies for security and load distribution. These do not need consent (section 25(2) no. 2 TDDDG); the associated processing rests on Article 6(1)(f) GDPR.
- Non-essential. Where we want to use anything beyond the strictly necessary — analytics, for example — we will ask for your consent first and will not set it until you agree.
- Fonts. The typefaces on this website are served from our own infrastructure. Opening a page does not make your browser connect to Google Fonts, or to any other outside font service, so no IP address is disclosed to a third party in order to display type. Until 3 September 2026 the fonts were loaded from Google's servers; that is no longer the case.
5. Who we share data with
We share data with service providers who process it on our behalf as our processors under Article 28 GDPR, each bound by a data processing agreement and permitted to use the data only to provide their service to us:
- Authentication: Clerk
- Hosting and infrastructure: Vercel, Railway, Cloudflare
- Database and storage: Supabase
- File and media storage: Backblaze B2
- AI processing: OpenRouter (and the upstream model providers it routes to)
- Customer feedback: Gleap
We also work with our tax advisers and, where necessary, our lawyers and auditors, who are bound by professional secrecy.
We may disclose information where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights, property or safety of our users or others.
Boards. If you copy a board someone has shared with you ("Keep this board"), the board's owner is shown that a copy was made. Unless you choose otherwise at that point — the choice is yours, and it defaults to sharing — they are also shown your name and email. This disclosure to the board's owner rests on Article 6(1)(f) GDPR: an owner has a legitimate interest in knowing what happens to a board they shared, and the opt-out is there so you keep control.
6. International transfers
We operate the Service from Germany. Several of the providers listed above are based in the United States or process data there, so personal data may be transferred outside the European Economic Area.
Where a provider is certified under the EU–US Data Privacy Framework, we rely on the European Commission's adequacy decision of 10 July 2023 (Article 45 GDPR). Otherwise we rely on the European Commission's standard contractual clauses (Article 46(2)(c) GDPR) together with additional technical and organisational safeguards, having assessed the transfer. You can ask us at dw@bluplai.com which mechanism applies to a particular provider and to see a copy of the relevant safeguards.
7. How long we keep data
We keep account and workspace data for as long as your account is active and for the period set out in our Terms of Service after the contract ends, so that you can export it. Log data is kept only as long as needed for security and stability. Billing and accounting records are kept for the statutory retention periods under German tax and commercial law — between six and ten years depending on the document (section 147(3) of the Fiscal Code, Abgabenordnung, and section 257 of the Commercial Code, Handelsgesetzbuch). You can ask us to delete your account at any time by emailing dw@bluplai.com.
8. Security
We take the technical and organisational measures required by Article 32 GDPR, including TLS in transit, encryption at rest with our infrastructure providers, and role-based access control. No system is perfectly secure; we encourage strong, unique passwords and multi-factor authentication where available.
9. Your rights
Under the GDPR you have the right to:
- access your personal data (Article 15);
- have inaccurate data corrected (Article 16);
- have data erased (Article 17);
- have processing restricted (Article 18);
- receive your data in a portable format (Article 20);
- object to processing based on our legitimate interests, on grounds relating to your particular situation (Article 21); and
- withdraw any consent you have given, with effect for the future (Article 7(3)).
Write to dw@bluplai.com and we will answer within one month. If your request concerns data inside someone else's workspace, see Clause 2.
You also have the right to complain to a supervisory authority (Article 77 GDPR). Ours is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. You may instead complain to the authority where you live or work.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them.
11. Changes
We may update this Privacy Policy from time to time. Material changes will be posted on this page with a new "Last updated" date, and we will tell account holders about significant changes.
12. Contact
Questions or requests? Email dw@bluplai.com, or see the Impressum for our full company and register details.
Looking for the product? Open boards.bluplai.com. Read our Terms of Service and our Impressum.