Overview
We’re committed to protecting personal data and complying with the General Data Protection Regulation (GDPR). This page explains our roles and responsibilities, how and why we process personal data, the measures we take to keep it secure, and how individuals can exercise their rights.Roles & responsibilities
- Controller: For our website and marketing activities, we act as a controller.
- Processor: For customer content processed in our services, we generally act as a processor under a Data Processing Agreement (DPA).
Lawful bases
- Performance of a contract (e.g., providing the service).
- Legitimate interests (e.g., improving and securing the service).
- Consent (e.g., optional marketing).
- Legal obligations (e.g., compliance and record keeping).
Personal data we process
The types of personal data depend on how you use our products and services. Typical categories include account data, usage and diagnostic data, support communications, and billing/contact details. We limit collection to what’s necessary and implement data minimization.International transfers
When personal data is transferred internationally, we rely on lawful transfer mechanisms (e.g., SCCs and UK Addendum) and apply supplementary safeguards where appropriate. See our Sub-processors for infrastructure and service providers.Security measures
- Defense-in-depth security controls and secure SDLC.
- Encryption in transit and at rest where appropriate.
- Access controls and least-privilege.
- Vulnerability management and regular testing.
- Supplier due diligence and contractual safeguards.
Data retention
We retain personal data only as long as necessary for the purposes described, to comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by data category and regulatory requirements.Your GDPR rights
- Right of access, rectification, erasure, and restriction.
- Right to data portability.
- Right to object to processing (including direct marketing).
- Right to withdraw consent at any time (where relied upon).
- Right to lodge a complaint with a supervisory authority.
Contacts & representatives
For privacy questions, to exercise rights, or to contact our DPO/representatives, email privacy@blueprecision.co.uk . Mailing details are listed below.Data Subject Access Request (DSAR)
If you have any questions about our use of your personal data, or if you would like to exercise your rights, please fill in DSAR form or contact us at privacy@blueprecision.co.uk . We will respond to your request within 30 days.Changes to this notice
- 2025-08-10 — Initial publication of GDPR page.