Skip to content

Privacy

Privacy policy

How blueprnt handles personal data.

Last updated: 26 September 2026

1. Who is responsible for the personal data?

Blueprnt Group AB is the data controller for the processing of personal data described in this privacy policy.

You can contact us with questions about personal data and privacy at hello@blueprnt.se.

2. When does this policy apply?

This policy applies when you:

  • visit blueprnt's website,
  • contact us through the contact form, email or other business communication,
  • are a contact person at a customer, supplier or other business partner,
  • have a user account or are in contact with us about blueprnt's service.

Customer data in the blueprnt platform

When a customer uses blueprnt to process data about its employees, roles, salaries or compensation, the customer is normally the data controller. blueprnt then normally processes the personal data as a data processor and on the customer's instructions.

Two separate data flows

What data?
Website and contact enquiriesName, company, email address, number of employees, selected need and message submitted in the contact form.
The blueprnt platformThe customer's HR, employee, role and pay data used in the blueprnt service.
Why?
Website and contact enquiriesTo answer enquiries and follow up a possible customer dialogue.
The blueprnt platformTo provide the blueprnt service on the customer's instructions.
Technical environment
Website and contact enquiriesEmail through our email provider Sweego to blueprnt's Google Workspace environment. Enquiries are not stored in any database.
The blueprnt platformblueprnt's separate production platform with production databases in the EU (Ireland).
Responsibility
Website and contact enquiriesblueprnt is normally the data controller.
The blueprnt platformThe customer is normally the data controller and blueprnt normally the data processor.
Retention
Website and contact enquiriesThe data is deleted no later than 12 months after the dialogue ends, or earlier on request, with the exceptions stated in this policy.
The blueprnt platformAccording to the customer's instructions, the customer agreement and the data processing agreement.

The contact form is used only for data submitted through the website. Customer data is not stored in, synchronised to or processed through the website's contact form.

The processing of customer data in the blueprnt platform is governed by a separate data processing agreement between blueprnt and the customer. The customer's own privacy policy and internal data protection information primarily govern how the customer's employees are informed about the processing.

3. When blueprnt is responsible for the processing

These are the most common situations in which blueprnt is itself the data controller.

  • Contact enquiry

    Data we may process
    Name, company, email address, number of employees, selected need and any message
    Why we process the data
    To answer the enquiry and follow up a possible customer dialogue
    Legal basis
    Legitimate interest and, where relevant, steps prior to entering into a contract
    Retention
    Up to 12 months after the dialogue ends
  • Customer and business contacts

    Data we may process
    Name, employer, role, email address and communication
    Why we process the data
    To administer customer relationships, agreements, support and business communication
    Legal basis
    Contract and legitimate interest
    Retention
    For the duration of the business relationship. Contractual and accounting records are kept as applicable law requires. Other contact details are deleted or anonymised when they are no longer needed for the relationship or for legal claims.
  • User administration and support

    Data we may process
    Name, work email address, role, permissions and support communication
    Why we process the data
    To administer access, provide support and stay in contact with the customer
    Legal basis
    Contract and legitimate interest
    Retention
    For the duration of the customer relationship. Data is deleted or anonymised under the customer agreement's deletion routines, unless it has to be kept longer by law or for legal claims.
  • The website

    Data we may process
    Technical data necessary for operation and security, and visit statistics without cookies
    Why we process the data
    To make the website work, protect it and improve it
    Legal basis
    Legitimate interest and necessary functionality
    Retention
    The language is part of the web address, and nothing is stored in your browser. Technical security logs are kept only as long as they are needed for operation, troubleshooting and security. We see the visit statistics only in aggregate.

We only process data that is relevant for each purpose.

4. Contact enquiries

When you contact blueprnt through the website, we process the data you give in the form: name, company, email address, number of employees, what you need help with and any message.

The data is used to answer your enquiry and follow up a possible customer dialogue. The enquiry is sent as an email through our email provider Sweego to blueprnt's Google Workspace, where it is handled for contact and follow-up. It is not stored in any database.

The contact form is technically and functionally separate from blueprnt's production platform and is not used for customers' HR, employee or pay data.

The data is deleted no later than 12 months after the dialogue ends, or earlier if you ask us to. We may need to keep some data longer if that is required to perform a contract, comply with legal requirements or handle an ongoing matter.

5. Where the data is processed

blueprnt uses separate technical environments for the website's contact enquiries and for customer data in the blueprnt platform.

  • The blueprnt platform: customer data is processed in blueprnt's production platform and stored in the EU (Ireland).
  • The website: hosted by Vercel in the EU (Ireland). Visit statistics are collected with Vercel Web Analytics, without cookies.
  • Contact enquiries: sent as email through Sweego, legally Mindbaz SAS (France), and handled in Google Workspace.
  • Google Workspace: used for company email and contact communication.
  • Suppliers involved with customer data: Convex (database, Ireland), Vercel (application hosting, Ireland), Sweego, legally Mindbaz SAS (email, France) and Mistral AI (AI models, France). Mistral AI never receives personal data.

We choose technical suppliers with regard to security, data protection and the need to deliver the service. When a supplier processes personal data on our behalf, we use the relevant agreements and instructions.

6. Transfers outside the EU/EEA

Customer data in the blueprnt platform is stored and processed within the EU (Ireland). Our hosting and database providers have US parent companies, which means that operational data such as logs may be processed outside the EU. Such transfers are covered by the European Commission's standard contractual clauses. For website and communication services, some suppliers may, depending on the service's configuration and support arrangements, process or access data from countries outside the EU/EEA.

If a transfer outside the EU/EEA takes place, blueprnt uses the relevant safeguards under the GDPR, for example the European Commission's standard contractual clauses and, where relevant, supplementary technical and organisational measures. Contact us at hello@blueprnt.se if you would like to know more about current suppliers and transfers.

7. Sharing of personal data

We do not share personal data with others except where it is needed to:

  • provide and administer our services,
  • handle contact enquiries, customer relationships or support,
  • comply with legal obligations,
  • protect the rights and safety of blueprnt, customers or other people.

This may mean that data is processed by our technical suppliers, for example for operation, storage, email or website functions. We do not sell personal data.

8. Secure handling of data in the blueprnt platform

For data processed in the blueprnt platform, we use technical and organisational security measures adapted to how the service is used.

  • Data is encrypted at rest with AES-256.
  • Data is encrypted in transit with TLS 1.2 or later.
  • The platform keeps a complete change log of relevant changes and events.
  • The platform has a built-in function for deleting personal data. When deletion is started, the data is removed from the active production database by hard delete.
  • Access to data is limited to authorised users and to people who need the data to administer or provide the service.

AI features in blueprnt

blueprnt's AI features run on EU-hosted models from Mistral. The features are technically separated from customers' personal data in the blueprnt platform. They cannot retrieve or send customers' personal data to the AI model, and they use only permitted, non-personal content for the feature in use.

Structured information security work

blueprnt works on information security in a structured, risk-based way, adapted to our operations and the data we handle.

  • Ongoing management of security risks.
  • Clear responsibilities for systems, data and security.
  • Control of permissions and access.
  • Multi-factor authentication in relevant systems.
  • Security updates and protection of work devices.
  • Handling and follow-up of incidents.
  • Checks of backup and restore.
  • Assessment of suppliers that process customer or personal data.

We see information security as continuous work. Our routines and controls are reviewed and updated when our operations, systems or risks change.

9. Your rights

When blueprnt is the data controller, you have, depending on the situation, the right to:

  • receive information about how your personal data is processed,
  • request access to your personal data,
  • request correction of inaccurate data,
  • request erasure of data in certain cases,
  • request restriction of the processing in certain cases,
  • object to processing based on legitimate interest,
  • receive data processed on the basis of a contract or consent in a structured format, where the right to data portability applies.

To exercise any of your rights, contact us at hello@blueprnt.se.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), the Swedish supervisory authority for data protection.

10. Cookies and local storage

The website sets no cookies and stores nothing in your browser. Visit statistics are collected with Vercel Web Analytics, which uses no cookies. It records the page address, referring page, browser, operating system, device type and approximate country, and we see it only in aggregate. We do not use marketing or third-party cookies, and we do not sell the data.

If this changes, we will update this policy and, where necessary, ask for consent before cookies or similar technology that are not necessary are activated.

11. Changes to the policy

We may update this privacy policy when our services, processing or legal requirements change. The latest version is always published on blueprnt's website with the date of the most recent update.

12. Contact

For questions about privacy, personal data or this policy, contact:

Blueprnt Group AB559600-7640hello@blueprnt.se