Skip to content
Legal

Privacy Policy

How Bluvense handles personal data: the account data we hold about our customers, the business contact data held in the platform, why we are allowed to process it, and what you can ask us to do about it.

Last updated: 29 August 2026

About this document

This is a good-faith document written to describe how Bluvense Lead Intelligence actually works today, not a generic template. It is not legal advice, and it should be reviewed by a qualified lawyer before commercial launch.

Who we are

Bluvense (“we”, “us”) operates Bluvense Lead Intelligence, a B2B lead-generation and business-intelligence platform available at leads.bluvense.com.

For anything in this policy — including access, correction and deletion requests — write to support@bluvense.com. A named data protection contact will be published before commercial launch.

The two roles we play

Data protection law distinguishes between deciding why data is processed and processing it on someone else’s instructions. We do both, in different places, and the distinction determines who is answerable for what.

  • We are the controller for the data we hold about our own customers and their users — account details, organisation membership, sessions, audit records and support correspondence — and for the business contact data we compile into the platform’s own database.
  • We are the processor for data you upload, import or otherwise put into your workspace. You decide what it is for; we process it to run the service and on your instructions. You remain the controller of it, and of any outreach you carry out using it.

A written data processing agreement covering the processor role will be offered alongside the commercial contract.

Personal data we hold about you as a customer

  • Account data. Your name, email address, organisation name and your role within it.
  • Credentials. We never store your password. It is hashed with Argon2id, and only that hash is kept. Email verification and password reset tokens are stored as hashes too. If you sign in with Google we never receive your Google password; we store Google’s account identifier so we can recognise you next time.
  • Session records. When you sign in we record the session, the IP address and browser user agent it was created from, and when it was last used. This is what lets you see and revoke your own sessions, and it is our main evidence if an account is compromised.
  • Audit records. Security- and permission-relevant actions are logged with who did them and when.
  • Support correspondence. Emails you send us and our replies.
  • Assistant conversations. If you use the on-site assistant, we store the messages, a coarse visitor identifier for anonymous threads, and the token counts the model reported. We keep them so we can enforce allowances, investigate abuse, and improve the product. They are not used to train a public model, and they are not joined to an advertising profile.

We do not operate an advertising business, we do not sell customer account data, and we do not buy behavioural profiles about you.

Business contact data in the platform

The purpose of the product is to identify businesses and the people who make buying decisions within them. That means the platform holds personal data about individuals in their professional capacity, most of whom are not our customers.

  • What we hold. Business identifiers: name, job title, employer, business email address, business telephone number, professional profile links, and firmographic information about the employing company.
  • What we do not seek. Personal email addresses, home addresses, personal phone numbers, and anything in the special categories under Article 9 of the GDPR — health, race or ethnicity, religion, political opinions, trade union membership, sexual orientation, genetic or biometric data. We do not knowingly collect it, we do not infer it, and our Acceptable Use Policy forbids customers from using the platform to derive it.
  • Where it comes from. Publicly available business sources and licensed third-party data providers. Every value carries a provenance record naming the source that supplied it and when.

Our lawful basis

  • Legitimate interests, Article 6(1)(f). For compiling and supplying business contact data for B2B prospecting. The interest is our customers’ ordinary commercial interest in reaching relevant businesses, and our own in operating the service. We restrict the data to the professional sphere, attach a source to every record, and provide an unconditional route to object or be removed. A legitimate interests assessment supports this basis and is available on request.
  • Contract, Article 6(1)(b). For creating and running your account and delivering the service you have signed up for.
  • Legal obligation, Article 6(1)(c). For tax, accounting and responding to lawful requests.
  • Consent, Article 6(1)(a). Where we ask for it, such as optional marketing email from us. You can withdraw it at any time without affecting anything done beforehand.

Consent is not the basis for the business contact database, and objecting to that processing does not require you to give a reason.

Provenance, freshness and accuracy

Accuracy is a data protection obligation and it is also the governing rule of this product: it never invents data. Where a source cannot supply a value, the record says so rather than being filled with a plausible guess.

  • Every field records which source supplied it, when, and how confident that source was. When two sources disagree, the conflict is resolved by reliability and recency, and the working is kept.
  • Every record carries raw timestamps — first seen, last seen, last enriched, last verified. Freshness is computed from those at the moment you look, never stored as a stale label.
  • An email address is described as verified only when a verification provider says so. Accept-all, role-based, disposable and unknown results are shown as exactly that.
  • If you tell us a record about you is wrong, we will correct or remove it and record the correction against the source.

How we use personal data

  • Providing, securing and supporting the service.
  • Authenticating you, protecting accounts against credential stuffing and abuse, and enforcing rate limits.
  • Sending transactional email: verification links, password resets and security notices.
  • Compiling and maintaining the business contact database, and supplying it to customers for B2B prospecting.
  • Meeting legal, tax and regulatory obligations, and handling disputes.

Cookies

We set strictly necessary cookies only: a session cookie, a CSRF token, and a short-lived cookie while Google sign-in is in progress. There are no analytics, advertising or tracking cookies, and no third-party cookies at all. The Cookie Policy names them and explains exactly what each one does.

Who we share data with

We do not sell personal data. We share it with service providers who process it on our behalf under contract, and only as far as they need it:

  • Hosting and infrastructure. The application is hosted on Hostinger’s managed Next.js platform.
  • Database. Application data is stored in a managed PostgreSQL database provided by Neon.
  • Email delivery. Transactional email is sent through our mail host’s SMTP service.
  • Data and verification providers. Where configured, third-party providers supply or verify business contact data. Provider credentials are not yet in place, and each adapter stays inactive until they are.
  • Google Sign-In. If you choose Continue with Google, you are sent to Google to authenticate. Google then tells us your email address, name, and a stable account identifier. We use that only to create or open your Bluvense account. We do not receive your Google password, and we do not ask Google for Gmail, Drive, or contacts.
  • An AI provider. Chat with the on-site assistant is sent to the configured model provider so it can generate a reply. Today that is Google Gemini by default; the deployment can be pointed at Groq, OpenRouter, OpenAI or Anthropic instead. The prompt we send includes your message, a short recent history of the same conversation, and a system prompt about the product. It does not include your password, session token, leads, or any record from the database. The assistant is switched off entirely until an operator sets an API key.

We may also disclose data where the law requires it, to enforce our terms, or as part of a merger or acquisition — in which case you will be told before your data becomes subject to a different policy. A current list of sub-processors is available on request, and material additions will be notified in advance.

International transfers

We operate from Pakistan and our infrastructure providers are based in, and host data in, the United States and Europe. Personal data therefore moves outside the UK and the EEA.

Where it does, transfers rely on an adequacy decision where one exists, and otherwise on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus technical measures including encryption in transit and at rest. A copy of the relevant safeguards is available on request.

How long we keep data

Several of these periods are operational settings an administrator can change; the values below are the defaults in force.

  • Sessions. A session lasts at most 30 days, and expires after 72 hours of inactivity. Expired sessions are deleted by a background job. Revoked sessions are kept for seven days so that a security investigation can still establish when and why a session ended.
  • Email verification links. Valid for 48 hours, then purged.
  • Password reset links. Valid for 60 minutes, then purged. They are single-use, and a completed reset revokes every other session for that account.
  • Account and organisation data. Kept while the account is open, and deleted or anonymised within 90 days of closure, except where we must keep records for legal, tax or dispute purposes.
  • Audit records. Kept for as long as needed to investigate security and access questions.
  • Assistant conversations. Kept for 90 days, then deleted. An operator may delete a thread sooner on request.
  • Suppression records. When someone asks to be removed from the business database we keep the minimum needed to honour that — typically a hashed identifier — so the record does not reappear from a later source refresh. Deleting this too would defeat the erasure.

Your rights

If you are in the UK, the EEA, or another jurisdiction with comparable law, you have the right to:

  • Access the personal data we hold about you, and be told where we got it.
  • Rectify anything inaccurate or incomplete.
  • Erase your data, including removal from the business contact database.
  • Restrict processing while a dispute about accuracy or legitimate interests is resolved.
  • Object to processing based on legitimate interests. Where you object to direct marketing or to prospecting use, we will stop — there is no balancing test to pass.
  • Portability — receive data you gave us in a structured, machine-readable format, or have it sent to another controller.
  • Withdraw consent where consent was the basis, and complain to a supervisory authority, such as the Information Commissioner’s Office in the UK.

Send requests to support@bluvense.com. We will respond within one month, and will tell you if we need a further two months because the request is complex. We may ask for enough information to be sure who you are, but no more than that. There is no charge unless a request is manifestly unfounded or excessive.

Self-service tooling for these requests is not built yet. Until it is, they are handled by a person, on the same timescales.

If your details appear in our business database

You do not need an account, and you do not need to be a customer, to exercise the rights above. Email support@bluvense.com from or quoting the address or record concerned and we will tell you what we hold, where it came from, and remove it on request.

Because our customers may already have exported a copy of a record before you contacted us, removal from our database does not automatically remove it from theirs. Our terms require customers to honour opt-out and erasure requests in their own systems, and we will tell you if we know a record was supplied to a customer.

If you are our customer

When you contact prospects using data from the platform, you are the controller of that outreach. You are responsible for having your own lawful basis, for identifying yourself honestly, for providing a working opt-out and honouring it promptly, and for complying with the marketing rules that apply where your recipients are — including the GDPR and UK GDPR, the Privacy and Electronic Communications Regulations in the UK, and the CAN-SPAM Act in the United States.

Supplying you with a contact record is not a representation that contacting that person is lawful in your circumstances. That assessment is yours to make.

How we protect data

  • Passwords are hashed with Argon2id. Sign-in performs a dummy verification for unknown accounts so response timing does not reveal whether an address is registered.
  • Session tokens are opaque random values. The database stores only their SHA-256 hash, so a database dump yields no usable credentials, and any session can be revoked instantly.
  • Cross-site request forgery is defended in three independent layers: a SameSite cookie, an origin check, and a double-submit token.
  • A Content Security Policy with a per-request nonce is issued from edge middleware, and the page loads nothing from third-party domains.
  • Rate limits apply to sign-up, sign-in, password reset and verification resend, with account lockout after repeated failures.
  • Authorisation is enforced server-side in every route. Probing an administrative URL as a customer returns a not-found response rather than confirming the page exists.
  • Sensitive configuration values are encrypted at rest, and all traffic is served over TLS.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly where the risk to you is high.

Automated decision-making

The platform scores and ranks records against an ideal customer profile. That is a relevance ranking of business records to help a human decide who to contact. We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you.

Children

The service is for business use by adults. It is not directed at children, and we do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, tell us and we will delete it.

Changes to this policy

We will update this page when our processing changes, and change the date at the top. If a change materially affects your rights we will tell account holders by email before it takes effect.

Privacy Policy · Bluvense Lead Intelligence