This Privacy Policy explains how Blunox ("we") processes personal data when you visit blunox.ai, register for or use our services, or interact with us. "Blunox" means the Blunox contracting entity responsible for your data: for services you have purchased, the entity identified on the Contracting Entities page at blunox.ai/legal/contracting-entities or in your agreement; for website visitors and prospects, Blunox FZE (UAE). It is written to satisfy the transparency requirements of the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), the EU/UK GDPR, and US state privacy laws.
Two roles. For personal data contained in content our customers submit to the services ("Customer Data"), we act as a processor on the customer's behalf — the customer's own privacy policy governs, and our processing is governed by our Data Processing Addendum (blunox.ai/legal/dpa). This Privacy Policy covers personal data for which we are the controller: website visitors, account holders, billing contacts, prospects, and event or support interactions.
| Purpose | Legal basis (GDPR/PDPL) |
|---|---|
| Providing and administering accounts and the services | Contract performance |
| Billing, accounting, tax | Legal obligation; contract |
| Security, fraud prevention, abuse detection | Legitimate interests |
| Product analytics and service improvement | Legitimate interests (aggregated where possible) |
| Marketing communications | Consent, or legitimate interests with opt-out where permitted |
| Legal compliance and claims | Legal obligation; legitimate interests |
We do not sell personal data and do not share it for cross-context behavioral advertising.
We share personal data with: (a) our service providers and subprocessors (hosting, payments, communications, analytics, support tooling) under contracts restricting their use of the data — the current list is at blunox.ai/legal/subprocessors; (b) professional advisers; (c) authorities where required by law; and (d) a successor entity in a corporate transaction, with notice.
Blunox operates globally and hosts data in the regions described at blunox.ai/legal/subprocessors. Where personal data is transferred across borders, we use appropriate safeguards: EU Standard Contractual Clauses and the UK Addendum for EEA/UK data, and contractual safeguards consistent with UAE PDPL Articles 22–23 for data transferred from the UAE.
We retain personal data for as long as needed for the purposes above: account data for the life of the account plus 12 months; billing records for the period required by tax law (7 years); marketing data until you opt out or 24 months of inactivity; logs 12 months. Customer Data retention is governed by the DPA.
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to lodge a complaint with a supervisory authority (including the UAE Data Office, an EEA authority, or the UK ICO). California residents have the rights set out in the CCPA, and we do not discriminate for exercising them. To exercise rights, email privacy@blunox.ai. We will respond within the period required by applicable law (30 days under the PDPL and GDPR unless extended).
We maintain technical and organizational measures described at blunox.ai/trust, including encryption in transit and at rest and access controls.
Our services are for business use and not directed to children under 18. We do not knowingly collect children's data.
Data protection contact: privacy@blunox.ai (Data Protection Officer). We will post updates to this policy with a revised effective date and notify you of material changes.
Questions about this document can be sent to privacy@blunox.ai.