Skip to content

Privacy Policy

Last updated: March 3, 2026

1. Data Controller

The data controller for the personal data described in this Privacy Policy is:

Bluemarlin Ventures S.L.
Avenida de San Anton 37, 29018, Malaga, Spain
Email: info@bluemarlinchat.com
VAT: ESB27665173

2. Personal Data We Collect

2.1 Account Data. When you create an account or are invited to an organization, we collect: identity data (full name, email address, profile picture from Google sign-in), authentication data (OAuth tokens, session identifiers, email verification codes), organization data (organization name, slug, member roles, invitation records), and a record of your acceptance of our Terms of Service (timestamp, IP address, browser identification string, and the version of the terms accepted).

2.2 Billing Data. When you subscribe to a paid plan, our payment processor (Stripe) collects credit/debit card details and billing address. Important: BlueMarlin does not store credit card numbers or payment card details. All payment data is processed exclusively by Stripe under PCI DSS Level 1 compliance. We only store a reference to your Stripe customer ID and subscription metadata (plan name, status, renewal date).

2.3 Platform Usage Data. As you use the Platform, we process: collections and records (customer data you import or create, including data imported from third-party services you connect, such as Airtable — connection credentials are stored encrypted); WhatsApp messages (content, media files, voice notes and their automatic transcripts, delivery statuses, timestamps, phone numbers in E.164 format — where you connect a number in coexistence mode, this includes the chat history WhatsApp synchronizes from your WhatsApp Business app); campaign data (recipient lists, template variables, delivery metrics, response tracking); AI data (knowledge base content, agent configuration, conversation logs, and the internal assistant's threads and saved organization memory); notes, tags, and segments; files and generated documents (including PDF pages rendered from your records); public share links you choose to publish (views, records, or documents, optionally password-protected); API usage (API key metadata hashed, request/response logs); and chat widget configuration.

2.4 Technical Data. Collected automatically when you access the Platform: device data (browser type, operating system, screen resolution), connection data (IP address, access timestamps), and session data (authentication cookies, organization preferences).

2.5 Data We Do NOT Collect. We do not use analytics or advertising trackers (no Google Analytics, no Facebook Pixel, no ad networks). We do not sell, rent, or trade personal data to third parties. We do not profile users for advertising purposes. We do not use third-party cookies for tracking. We do use an error-monitoring service (Sentry, see Section 4) that receives technical error reports when something goes wrong; these reports are used solely for diagnostics, never for advertising or profiling.

3. How We Use Your Data

We process personal data only for the following purposes, together with the corresponding legal basis under GDPR Article 6: account creation and authentication (Art. 6(1)(b) — performance of contract); providing Platform services (Art. 6(1)(b)); processing payments and billing (Art. 6(1)(b)); sending transactional emails such as OTP and invitations (Art. 6(1)(b)); AI response generation and assistant features (Art. 6(1)(b)); generating text embeddings for AI search (Art. 6(1)(b)); transcribing voice messages to text (Art. 6(1)(b)); WhatsApp message delivery (Art. 6(1)(b)); campaign delivery and tracking (Art. 6(1)(b)); recording acceptance of our Terms of Service as evidence of contract conclusion (Art. 6(1)(b) and (f)); platform security, error monitoring, and abuse prevention (Art. 6(1)(f) — legitimate interest); compliance with legal obligations (Art. 6(1)(c)); and responding to support requests (Art. 6(1)(b)).

We do not process personal data based on consent for marketing purposes, as we do not engage in direct marketing or behavioral advertising.

4. Sub-Processors

We use the following third-party service providers (sub-processors) to operate the Platform, each processing data only as necessary for its stated purpose and under contractual obligations that include appropriate data protection safeguards:

Supabase Inc. — Primary database (PostgreSQL) and real-time messaging. Processes all platform data. Located in the United States.
Cloudflare Inc. — File storage (R2), CDN, DDoS protection. Processes uploaded files, documents, media. Global with EU storage.
Vercel Inc. — Application hosting and deployment. Processes HTTP requests. Located in the United States.
Stripe Inc. — Payment processing and subscription management. Processes payment card data, billing addresses, invoices. Located in the United States.
Resend Inc. — Transactional email delivery. Processes email addresses, OTP codes. Located in the United States.
Meta Platforms Inc. — WhatsApp Business API messaging. Processes phone numbers, message content, media, delivery status. Located in the United States.
Anthropic PBC — AI response generation and assistant features (Claude API). Processes message text, knowledge base content, conversation context, and record data accessed by assistant tools. Located in the United States.
OpenAI LLC — Text embeddings for knowledge search and speech-to-text transcription of voice messages. Processes text chunks from knowledge sources and the audio of voice messages. Located in the United States.
Functional Software Inc. (Sentry) — Error monitoring. Processes technical error reports, which may include request metadata and IP addresses. Located in the United States.
Upstash Inc. — Rate limiting (Redis). Processes campaign throttling counters (no personal data). Global.
Google LLC — OAuth authentication (processes email, name, profile picture during sign-in) and, where the address autocomplete feature is used, Google Maps address lookups. Located in the United States.

We will notify you of any material changes to our sub-processor list at least 30 days before the new sub-processor begins processing personal data.

AI-specific processing: When AI features are enabled, Anthropic (Claude) receives the text needed for the requested task: incoming customer messages, relevant knowledge base excerpts, recent conversation history, and — when an assistant uses a tool that reads your data — the content of the records involved, which may include contact details you store (such as names or phone numbers). OpenAI receives text chunks from your knowledge sources for generating vector embeddings, and the audio of voice messages for transcription. Neither provider receives your billing information, and data belonging to one organization is never shared with another. Both providers operate under enterprise API agreements where your data is not used to train their models.

5. International Data Transfers

Our primary sub-processors are located in the United States. For transfers of personal data from the European Economic Area (EEA) to countries outside the EEA, we rely on: the EU-U.S. Data Privacy Framework (DPF) for certified sub-processors (Stripe, Google, Meta, Cloudflare, Vercel); Standard Contractual Clauses (SCCs) incorporated into our agreements with all sub-processors; and supplementary measures including encryption in transit (TLS 1.2+) and at rest, access controls, and contractual data protection obligations. You may request a copy of the applicable transfer mechanisms by contacting info@bluemarlinchat.com.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy or as required by law. Account data is retained for the duration of the account plus 30 days after deletion. Organization data, WhatsApp messages, collections, records, campaign data, and AI knowledge base data are retained for the duration of the subscription plus 30 days after termination. Billing records and invoices are retained for 6 years after the transaction (Spanish tax law). Technical request logs are retained for 48 hours; warning and error events are retained for up to 7 days. Authentication session data is retained until session expiry or logout.

After the retention period expires, data is permanently deleted or anonymized. Upon account termination, we retain your data for 30 days to allow recovery, after which it is irreversibly deleted from our systems and sub-processors.

7. Cookies and Tracking Technologies

BlueMarlin uses only strictly necessary and functional cookies required for the Platform to work. We do not use analytics, advertising, or tracking cookies. The cookies used are: authentication cookies prefixed bm. (secure, HTTP-only session tokens set by our authentication system), bm_last_org (last selected organization, persistent), PARAGLIDE_LOCALE (your language preference, ~13 months), and interface preference cookies (such as the sidebar state). Because all of these are either strictly necessary or store a preference you explicitly set, no cookie consent banner is required under the ePrivacy Directive (Directive 2002/58/EC, Art. 5(3)).

8. Your Rights Under GDPR

As a data subject under the General Data Protection Regulation, you have the following rights: Access (Art. 15) — request a copy of your personal data; Rectification (Art. 16) — request correction of inaccurate data; Erasure (Art. 17) — request deletion ("right to be forgotten"); Restriction (Art. 18) — request that we limit processing; Data portability (Art. 20) — receive your data in a structured, machine-readable format; Objection (Art. 21) — object to processing based on legitimate interests; Withdraw consent (Art. 7) — where processing is based on consent; Complaint (Art. 77) — lodge a complaint with a supervisory authority.

Send your request to info@bluemarlinchat.com. We will respond within 30 days. If we need to extend this period (by up to 60 additional days), we will inform you of the reasons for the delay. If you are not satisfied with our response, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos — AEPD), C/ Jorge Juan 6, 28001 Madrid, Spain.

9. How to Delete Your Account and Data

To request the deletion of your account and all personal data associated with it, send an email to info@bluemarlinchat.com from the email address linked to your account, stating that you want your account and data deleted. We will confirm your request and permanently delete your account data, organization data (where you are the sole owner), files, and conversations within 30 days. The only data we keep beyond that point are billing records and invoices, which Spanish tax law requires us to retain for 6 years, and the minimal records needed to document that the deletion was performed.

If you are a customer of a business that uses BlueMarlin (for example, you exchanged WhatsApp messages with a company that manages its conversations on our Platform), that business is the data controller for your conversation data. Please direct your deletion request to that business; we will assist them in fulfilling it as their data processor. You may also contact us directly at info@bluemarlinchat.com and we will forward your request to the business concerned.

10. Data Security

We implement appropriate technical and organizational measures to protect personal data, including: encryption in transit (TLS 1.2+) and at rest; API keys stored as SHA-256 hashes; third-party integration credentials stored encrypted (AES-GCM); presigned URLs with limited expiry for file access; webhook signature verification (Meta, Stripe); UUID v7 identifiers; session-based authentication with secure HTTP-only cookies; access to production systems restricted to authorized personnel; and incident response procedures for data breaches.

We do not store: payment card numbers (handled by Stripe under PCI DSS), plaintext passwords (authentication via OAuth and email OTP only), or plaintext API keys (stored as irreversible SHA-256 hashes).

11. Data Processing Agreement (DPA)

When you use BlueMarlin to process your customers' personal data (e.g., WhatsApp messages, contact records, campaign recipients), you act as the data controller and BlueMarlin acts as the data processor under GDPR Article 28. Our DPA governs this relationship and includes: description of processing activities, obligations of the processor, sub-processor management, data subject request handling, data breach notification (within 72 hours), audit rights, data deletion upon contract termination, and Standard Contractual Clauses (SCCs) for international transfers. To request a signed copy of our DPA, contact info@bluemarlinchat.com.

12. AI Features and Automated Decision-Making

12.1 Customer-facing AI assistant. When enabled, the AI assistant uses artificial intelligence to respond to incoming WhatsApp messages based on your knowledge base and the data access you configure. It does not create profiles of your customers or make decisions that produce legal effects concerning them. It includes automatic escalation to human operators when confidence is insufficient. Each organization's knowledge base and conversations are completely isolated. Your data is never used to train third-party AI models.

12.2 Internal operational assistant. The Platform includes an internal assistant available to your team members. It acts only on your own organization's data, only in response to your team's requests, and its actions are logged. It is never exposed to your customers.

12.3 Automated processing in campaigns. Campaign features involve automated message delivery based on recipient lists you define. This is not automated decision-making under GDPR Article 22, as it does not produce legal or similarly significant effects on individuals — it is a communication tool under your control.

13. Children's Privacy

The Platform is a business-to-business (B2B) service intended for use by businesses and their authorized representatives. We do not knowingly collect personal data from children under the age of 16. If we become aware that we have collected data from a child, we will delete it promptly.

14. Third-Party Links and Services

The Platform may contain links to third-party websites or integrate with third-party services (e.g., WhatsApp, Stripe billing portal, services you connect such as Airtable). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you interact with.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you via email or through the Platform at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the changes.

16. Contact

For any questions about this Privacy Policy, to exercise your data protection rights, or to request our Data Processing Agreement:

BLUEMARLIN VENTURES SL
VAT: ESB27665173
Avenida de San Anton 37
29018 Malaga, Spain
Email: info@bluemarlinchat.com

This Privacy Policy is governed by Spanish law and the General Data Protection Regulation (EU) 2016/679.