Privacy notice
This draft privacy notice explains how Blunt Logic handles personal data across its public site, customer onboarding, private workspaces, billing, support, monitoring, and managed deployments. It is intended for legal review before live paid onboarding.
Version 2026-07-06.2 · Effective 2026-07-06
Blunt Logic Ltd operates the Blunt Logic website, private customer workspaces, onboarding flows, billing controls, operator console, and managed deployment namespace. Contact: hello@bluntlogic.ai. Privacy contact: privacy@bluntlogic.ai.
Registered number: PENDING_COMPANY_NUMBER. Registered in England and Wales. Registered office: PENDING_REGISTERED_OFFICE_ADDRESS.
We have not appointed a statutory Data Protection Officer. Data protection enquiries should be directed to privacy@bluntlogic.ai.
We may collect business contact details, owner login details, billing contacts, company details, support messages, onboarding acceptance records, Stripe customer and subscription identifiers, AI credit balances, top-up purchases, checkout sessions, payment status, credit adjustments, deployment configuration, audit logs, security events, usage telemetry, and redacted monitoring summaries.
Customer workspaces may also contain customer-provided business records such as organisations, contacts, prompts, documents, notes, replies, research material, and workflow history. The customer controls what it uploads or asks the service to process.
We use personal data to provide and secure the service, create and manage workspaces, authenticate owners, process onboarding, record legal acceptance, administer billing and subscriptions, provide support, monitor service health, investigate faults or abuse, maintain auditability, comply with law, and communicate about the service.
We do not sell or rent personal data, and we do not disclose it to unrelated third parties for those parties' own purposes.
Where Blunt Logic Ltd is the controller, we rely on the following lawful bases: performance of a contract, for creating and operating workspaces, onboarding, authentication, billing, and support; legitimate interests, for securing private deployments, preventing misuse, monitoring service health, keeping appropriate audit records, and improving reliability; legal obligation, for tax, accounting, and regulatory record-keeping; and consent where required, for example for optional communications or any future non-essential cookies.
For records inside a customer workspace that are processed on the customer's instructions, the customer is the controller and determines its own lawful basis; we process those records as processor under the Data Processing Addendum. We also comply with the Privacy and Electronic Communications Regulations 2003 (PECR) where applicable to our own service communications.
Some workspace features send prompts, context, usage data, or outputs to approved AI, hosting, database, email, billing, monitoring, and support providers. Secrets and API credentials are kept server-side and are not exposed to the browser. Monitoring and operator-console summaries use redacted or aggregated data; raw customer CRM records, prompts, replies, or documents are not centralised in the operator console unless needed to provide support or as otherwise agreed.
Categories of recipients include AI inference providers (US), hosting and database providers (UK/EU/US), billing providers (EU/UK/US), email and support providers (EU/UK/US), and monitoring and background-job providers (EU/US).
The current list of subprocessors and service providers, including their roles and processing locations, is published on the subprocessors page of the operator site at /subprocessors. The customer should review the Data Processing Addendum together with that list before live use.
We do not train our own AI models on customer workspace content. AI providers are engaged through their commercial APIs under business terms that limit use of submitted content to providing the service; a data-use note for each provider is included on the subprocessors page.
Stripe processes payment and billing data through Stripe Checkout as an independent controller under Stripe's own privacy notice. Payment card details are entered directly into Stripe's hosted checkout and are not processed or stored by Blunt Logic Ltd, which receives only Stripe customer identifiers and subscription or payment status.
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals. AI-assisted features support human-led workflows, and outputs are reviewed by the customer before any external action is taken.
The operator console may poll deployment status endpoints to collect redacted health, workflow, usage, billing, and delivery summaries. The service may also keep audit records for login, legal acceptance, billing, AI usage, approvals, sends, support actions, webhook activity, and security-relevant events.
We use essential cookies and similar storage for authentication, session security, preferences, and service operation. We do not set non-essential marketing or analytics cookies. Stripe Checkout is hosted by Stripe and sets its own cookies under Stripe's terms and privacy notice. We will add consent controls and update this notice before enabling any non-essential cookies.
We keep personal data only for as long as needed for the purposes described above, using these default periods: billing, invoicing, and tax records are kept for the periods required by UK tax and accounting law (generally at least six years); onboarding and legal acceptance records are kept for the life of the contract plus six years; authentication and security logs are kept on a rolling twelve-month basis unless an open investigation requires longer; and support correspondence is kept for up to twenty-four months after a ticket is closed.
Customer workspace content is retained for the life of the workspace and is deleted or anonymised after termination in line with the Data Processing Addendum, subject to backup rotation. Limited redacted operational, billing, security, support, and audit summaries may be retained for the stated legal, accounting, and security periods after raw workspace data is deleted.
Some providers may process data outside the UK or EEA. Where required, we rely on appropriate safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or equivalent provider commitments. Provider processing locations are listed on the subprocessors page at /subprocessors.
Under UK data protection law, you have rights to access, correct, delete, restrict, object to, or receive a copy of personal data about you, and the right to complain to the UK Information Commissioner's Office or another relevant regulator. If you are located outside the UK, additional rights under your local law may also apply. Contact privacy@bluntlogic.ai to exercise privacy rights.
Where processing is based on consent, you may withdraw consent at any time by contacting privacy@bluntlogic.ai. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Where personal data is processed inside a customer workspace on the customer's instructions, the customer is the controller and Blunt Logic Ltd acts as processor. Individuals should direct access, correction, deletion, or other rights requests about that data to the customer, and Blunt Logic Ltd will support the customer's response under the Data Processing Addendum.
For prospect, contact, CRM, outreach, and document records in a customer workspace, the customer is responsible for providing any privacy notice its outreach or processing requires and for identifying its own lawful basis. This notice explains Blunt Logic Ltd's own controller processing and is not a substitute for the customer's notices to its own contacts.
We may update this notice as the service, providers, or legal requirements change. Material changes to the Terms of Service or Data Processing Addendum will be presented for renewed acceptance before continued paid workspace access where required by law or where the change materially affects customer rights or obligations.