Legal

GDPR Compliance

Last updated: August 25, 2026

Our commitment

Blotwise is designed with privacy-by-default principles. We process only the minimum data necessary to deliver the service and give you full control over that data.

Lawful basis for processing

We process personal data under the following lawful bases:

  • Contract — to deliver the service you signed up for
  • Legitimate interests — security monitoring and fraud prevention
  • Consent — where we rely on consent as a lawful basis, you may withdraw it at any time without affecting the lawfulness of prior processing

Data minimisation

The browser extension does not transmit the text you type while scanning. Incident logs store a hashed user identifier, a device fingerprint, a policy match summary and a timestamp, never raw conversation content — with one user-initiated exception: reporting a false positive or requesting permission attaches an excerpt of up to 100 characters, stored encrypted for the organization administrator to review.

Your rights under GDPR

  • Right of Access — export all your personal data from Settings → Data Export
  • Right to Erasure — delete your account and all associated data from Settings
  • Right to Rectification — update your name and contact details in Settings
  • Right to Portability — download your data in machine-readable JSON format
  • Right to Restrict Processing — contact us to pause processing while a dispute is resolved
  • Right to Object — opt out of any processing based on legitimate interests
  • Right not to be subject to automated decision-making — we do not make automated decisions that produce legal effects

Data Processing Agreements

We sign a Data Processing Agreement (DPA) with all customers who request one. Sub-processors (Supabase, Vercel, Brevo, Paddle, Sentry) operate under their own DPAs and are all GDPR-compliant.

Data transfers

Our database is hosted in Singapore (ap-southeast-1). Personal data of EEA residents is therefore transferred outside the EEA, and we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism, as described in our Privacy Policy. Tell us if your organization requires a specific hosting region and we will discuss it with you.

Retention

We retain your data for as long as your account is active. Incident logs are archived after 60 days and permanently deleted after 90 days, on every plan. Upon account deletion, all personal data is removed within 30 days per GDPR Article 17.

Breach notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, in accordance with GDPR Articles 33 and 34.

Contact & supervisory authority

For GDPR-related requests, contact our privacy team at support@blotwise.com. You also have the right to lodge a complaint with your local supervisory authority.