Privacy Policy
How Bluvense handles personal data: the account data we hold about our customers, the business contact data held in the platform, why we are allowed to process it, and what you can ask us to do about it.
Last updated: 29 August 2026
About this document
Who we are
Bluvense (“we”, “us”) operates Bluvense Lead Intelligence, a B2B lead-generation and business-intelligence platform available at leads.bluvense.com.
For anything in this policy — including access, correction and deletion requests — write to support@bluvense.com. A named data protection contact will be published before commercial launch.
The two roles we play
Data protection law distinguishes between deciding why data is processed and processing it on someone else’s instructions. We do both, in different places, and the distinction determines who is answerable for what.
- We are the controller for the data we hold about our own customers and their users — account details, organisation membership, sessions, audit records and support correspondence — and for the business contact data we compile into the platform’s own database.
- We are the processor for data you upload, import or otherwise put into your workspace. You decide what it is for; we process it to run the service and on your instructions. You remain the controller of it, and of any outreach you carry out using it.
A written data processing agreement covering the processor role will be offered alongside the commercial contract.
Personal data we hold about you as a customer
- Account data. Your name, email address, organisation name and your role within it.
- Credentials. We never store your password. It is hashed with Argon2id, and only that hash is kept. Email verification and password reset tokens are stored as hashes too. If you sign in with Google we never receive your Google password; we store Google’s account identifier so we can recognise you next time.
- Session records. When you sign in we record the session, the IP address and browser user agent it was created from, and when it was last used. This is what lets you see and revoke your own sessions, and it is our main evidence if an account is compromised.
- Audit records. Security- and permission-relevant actions are logged with who did them and when.
- Support correspondence. Emails you send us and our replies.
- Assistant conversations. If you use the on-site assistant, we store the messages, a coarse visitor identifier for anonymous threads, and the token counts the model reported. We keep them so we can enforce allowances, investigate abuse, and improve the product. They are not used to train a public model, and they are not joined to an advertising profile.
We do not operate an advertising business, we do not sell customer account data, and we do not buy behavioural profiles about you.
Business contact data in the platform
The purpose of the product is to identify businesses and the people who make buying decisions within them. That means the platform holds personal data about individuals in their professional capacity, most of whom are not our customers.
- What we hold. Business identifiers: name, job title, employer, business email address, business telephone number, professional profile links, and firmographic information about the employing company.
- What we do not seek. Personal email addresses, home addresses, personal phone numbers, and anything in the special categories under Article 9 of the GDPR — health, race or ethnicity, religion, political opinions, trade union membership, sexual orientation, genetic or biometric data. We do not knowingly collect it, we do not infer it, and our Acceptable Use Policy forbids customers from using the platform to derive it.
- Where it comes from. Publicly available business sources and licensed third-party data providers. Every value carries a provenance record naming the source that supplied it and when.
Our lawful basis
- Legitimate interests, Article 6(1)(f). For compiling and supplying business contact data for B2B prospecting. The interest is our customers’ ordinary commercial interest in reaching relevant businesses, and our own in operating the service. We restrict the data to the professional sphere, attach a source to every record, and provide an unconditional route to object or be removed. A legitimate interests assessment supports this basis and is available on request.
- Contract, Article 6(1)(b). For creating and running your account and delivering the service you have signed up for.
- Legal obligation, Article 6(1)(c). For tax, accounting and responding to lawful requests.
- Consent, Article 6(1)(a). Where we ask for it, such as optional marketing email from us. You can withdraw it at any time without affecting anything done beforehand.
Consent is not the basis for the business contact database, and objecting to that processing does not require you to give a reason.
Provenance, freshness and accuracy
Accuracy is a data protection obligation and it is also the governing rule of this product: it never invents data. Where a source cannot supply a value, the record says so rather than being filled with a plausible guess.
- Every field records which source supplied it, when, and how confident that source was. When two sources disagree, the conflict is resolved by reliability and recency, and the working is kept.
- Every record carries raw timestamps — first seen, last seen, last enriched, last verified. Freshness is computed from those at the moment you look, never stored as a stale label.
- An email address is described as verified only when a verification provider says so. Accept-all, role-based, disposable and unknown results are shown as exactly that.
- If you tell us a record about you is wrong, we will correct or remove it and record the correction against the source.
How we use personal data
- Providing, securing and supporting the service.
- Authenticating you, protecting accounts against credential stuffing and abuse, and enforcing rate limits.
- Sending transactional email: verification links, password resets and security notices.
- Compiling and maintaining the business contact database, and supplying it to customers for B2B prospecting.
- Meeting legal, tax and regulatory obligations, and handling disputes.
International transfers
We operate from Pakistan and our infrastructure providers are based in, and host data in, the United States and Europe. Personal data therefore moves outside the UK and the EEA.
Where it does, transfers rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus technical measures including encryption in transit and at rest. A copy of the relevant safeguards is available on request.
How long we keep data
Several of these periods are operational settings an administrator can change; the values below are the defaults in force.
- Sessions. A session lasts at most 30 days, and expires after 72 hours of inactivity. Expired sessions are deleted by a background job. Revoked sessions are kept for seven days so that a security investigation can still establish when and why a session ended.
- Email verification links. Valid for 48 hours, then purged.
- Password reset links. Valid for 60 minutes, then purged. They are single-use, and a completed reset revokes every other session for that account.
- Account and organisation data. Kept while the account is open, and deleted or anonymised within 90 days of closure, except where we must keep records for legal, tax or dispute purposes.
- Audit records. Kept for as long as needed to investigate security and access questions.
- Assistant conversations. Kept for 90 days, then deleted. An operator may delete a thread sooner on request.
- Suppression records. When someone asks to be removed from the business database we keep the minimum needed to honour that — typically a hashed identifier — so the record does not reappear from a later source refresh. Deleting this too would defeat the erasure.
Your rights
If you are in the UK, the EEA, or another jurisdiction with comparable law, you have the right to:
- Access the personal data we hold about you, and be told where we got it.
- Rectify anything inaccurate or incomplete.
- Erase your data, including removal from the business contact database.
- Restrict processing while a dispute about accuracy or legitimate interests is resolved.
- Object to processing based on legitimate interests. Where you object to direct marketing or to prospecting use, we will stop — there is no balancing test to pass.
- Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Withdraw consent where consent was the basis, and complain to a supervisory authority, such as the Information Commissioner’s Office in the UK.
Send requests to support@bluvense.com. We will respond within one month, and will tell you if we need a further two months because the request is complex. We may ask for enough information to be sure who you are, but no more than that. There is no charge unless a request is manifestly unfounded or excessive.
Self-service tooling for these requests is not built yet. Until it is, they are handled by a person, on the same timescales.
If your details appear in our business database
You do not need an account, and you do not need to be a customer, to exercise the rights above. Email support@bluvense.com from or quoting the address or record concerned and we will tell you what we hold, where it came from, and remove it on request.
Because our customers may already have exported a copy of a record before you contacted us, removal from our database does not automatically remove it from theirs. Our terms require customers to honour opt-out and erasure requests in their own systems, and we will tell you if we know a record was supplied to a customer.
If you are our customer
When you contact prospects using data from the platform, you are the controller of that outreach. You are responsible for having your own lawful basis, for identifying yourself honestly, for providing a working opt-out and honouring it promptly, and for complying with the marketing rules that apply where your recipients are — including the GDPR and UK GDPR, the Privacy and Electronic Communications Regulations in the UK, and the CAN-SPAM Act in the United States.
Supplying you with a contact record is not a representation that contacting that person is lawful in your circumstances. That assessment is yours to make.
How we protect data
- Passwords are hashed with Argon2id. Sign-in performs a dummy verification for unknown accounts so response timing does not reveal whether an address is registered.
- Session tokens are opaque random values. The database stores only their SHA-256 hash, so a database dump yields no usable credentials, and any session can be revoked instantly.
- Cross-site request forgery is defended in three independent layers: a SameSite cookie, an origin check, and a double-submit token.
- A Content Security Policy with a per-request nonce is issued from edge middleware, and the page loads nothing from third-party domains.
- Rate limits apply to sign-up, sign-in, password reset and verification resend, with account lockout after repeated failures.
- Authorisation is enforced server-side in every route. Probing an administrative URL as a customer returns a not-found response rather than confirming the page exists.
- Sensitive configuration values are encrypted at rest, and all traffic is served over TLS.
No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly where the risk to you is high.
Automated decision-making
The platform scores and ranks records against an ideal customer profile. That is a relevance ranking of business records to help a human decide who to contact. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.
Children
The service is for business use by adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.
Changes to this policy
We will update this page when our processing changes, and change the date at the top. If a change materially affects your rights we will tell account holders by email before it takes effect.