Legal
Last updated: August 25, 2026
Blotwise is designed with privacy-by-default principles. We process only the minimum data necessary to deliver the service and give you full control over that data.
We process personal data under the following lawful bases:
The browser extension does not transmit the text you type while scanning. Incident logs store a hashed user identifier, a device fingerprint, a policy match summary and a timestamp, never raw conversation content — with one user-initiated exception: reporting a false positive or requesting permission attaches an excerpt of up to 100 characters, stored encrypted for the organization administrator to review.
We sign a Data Processing Agreement (DPA) with all customers who request one. Sub-processors (Supabase, Vercel, Brevo, Paddle, Sentry) operate under their own DPAs and are all GDPR-compliant.
Our database is hosted in Singapore (ap-southeast-1). Personal data of EEA residents is therefore transferred outside the EEA, and we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism, as described in our Privacy Policy. Tell us if your organization requires a specific hosting region and we will discuss it with you.
We retain your data for as long as your account is active. Incident logs are archived after 60 days and permanently deleted after 90 days, on every plan. Upon account deletion, all personal data is removed within 30 days per GDPR Article 17.
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, in accordance with GDPR Articles 33 and 34.
For GDPR-related requests, contact our privacy team at support@blotwise.com. You also have the right to lodge a complaint with your local supervisory authority.