Privacy Policy

Last updated: 04 August 2026

(If copies of this privacy policy have been made in languages other than German, only the German version is binding.)

This privacy policy applies to our website bluepic.io and its subdomains (in particular studio.bluepic.io and template.bluepic.io).

Depending on how you interact with us, a different section applies to you. Please first read the general part (sections 1–6) and then the section relevant to you:

  • Section A: You visit our public website bluepic.io.
  • Section B: You are a registered customer and use our software at studio.bluepic.io.
  • Section C: You are an end user of one of our customers and come into contact with our application through our widget (embedded in the customer's website or app or shared as a link; delivered via template.bluepic.io).

The topics that apply to all groups (processors, third-country transfers, storage periods, your rights, security, complaints) can be found in sections 7–12.

Protecting your personal data is important to us. Below we inform you in detail about how we handle your data in accordance with the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

The controller within the meaning of the GDPR is:

FellowBlue GmbH
Im Mediapark 5
50670 Cologne
Germany


Tel.: +49 221 95674830
Email: info@bluepic.io


Authorised managing directors: Markus Hiller, Thomas Wicke
Commercial register: Local Court of Cologne, HRB 116136
VAT ID: DE364437752

Insofar as we act not as controller but as processor for our customers with regard to certain processing activities, this is explained separately in section 2 and in section C.

2. Data protection contact

For questions regarding data protection and to exercise your rights, you can reach us at privacy@bluepic.io.

A data protection officer has not been appointed, as in our assessment there is no legal obligation to do so (Section 38 (1) BDSG, Art. 37 (1) GDPR).

3. Who this privacy policy is addressed to (user groups and our role)

We distinguish three groups. The distinction matters because we act for you in different roles:

A) Website visitors (bluepic.io). You visit our public website without being logged in. We are the controller for the limited processing associated with this. Details: Section A.

B) Registered customers (studio.bluepic.io). You have an account and use our software. We are the controller for your account data (registration, billing, settings, use of the application). For the personal data of your end users that you process via our software (e.g. when they use a widget you have created), we act as your processor within the meaning of Art. 28 GDPR (see section 4). Details: Section B.

C) End users of our customers (widget, template.bluepic.io). You come into contact with our application because one of our customers embeds our widget in their own website or app or shares it as a link with their end users. In this case, the respective customer is the controller for the processing of your data. We are their processor and merely provide the technical infrastructure. Details, and the exception in which we ourselves are the controller (embedding of the widget on our own website bluepic.io), can be found in section C.

4. Our role as a processor for customer data

As a registered customer, you process personal data of your own end users via our software. For this data we are your processor within the meaning of Art. 28 GDPR and you are the controller. The basis is the data processing agreement (DPA) concluded with you.

As the controller, you are obliged to inform your end users about the processing in accordance with Art. 13/14 GDPR and, where necessary, to establish a legal basis for it. We process this data exclusively on your instructions and for the purposes set out in the DPA.

5. Legal bases

We base processing on the following legal bases:

Activity Legal basis
Provision of the software to registered customers; provision of requested services Art. 6 (1)(b) GDPR (performance of a contract)
Pre-contractual measures at your request Art. 6 (1)(b) GDPR
Processing based on your separate, revocable consent Art. 6 (1)(a) GDPR
Storage/access on your device for technologies requiring consent Section 25 (1) TDDDG in conjunction with Art. 6 (1)(a) GDPR
Technically necessary storage on your device Section 25 (2) TDDDG
Fulfilment of legal obligations (e.g. commercial/tax retention) Art. 6 (1)(c) GDPR
Operation, security, abuse prevention and improvement of our services Art. 6 (1)(f) GDPR (legitimate interest)

Where we rely on a legitimate interest, we name the specific interest in connection with the respective processing. You may object to such processing under Art. 21 GDPR.

6. General information on data processing, cookies and storage periods

6.1 Scope of processing

As a rule, we process personal data only insofar as this is necessary to provide a functional website, our application and our content and services, or where you have given your consent.

6.2 Cookies and similar technologies

We distinguish:

  • Technically necessary cookies/storage that are required for operation. Legal basis: Section 25 (2) TDDDG and Art. 6 (1)(f) GDPR.
  • Non-necessary cookies/services (in particular analytics and marketing), which are only set with your consent. Legal basis: Section 25 (1) TDDDG in conjunction with Art. 6 (1)(a) GDPR.

On our public website bluepic.io and on template.bluepic.io we do not use any analytics or marketing cookies requiring consent.

The reach and usage analysis used there (PostHog) is carried out without storing or reading information on your device and on a pseudonymous basis (see A.2 and C.4). However, the widget delivered via template.bluepic.io uses functional local storage (sessionStorage) solely to retain your own inputs – not for analytics or marketing purposes (details in C.3). No cookies are set for this.

Overview of the technically necessary or functional storage used:

Name Provider Purpose Storage period Category
bluepic_lang FellowBlue GmbH (first-party) Stores your language selection (German/English) 12 months Technically necessary / functional
Session/CSRF token FellowBlue GmbH (first-party, studio.bluepic.io only) Session and form protection in the application Session Technically necessary

In the application (studio.bluepic.io) further device-related processing may occur; see section B for this.

6.3 Erasure and storage period

Personal data is erased or blocked as soon as the purpose of storage ceases to apply. Storage beyond this takes place where statutory retention obligations (in particular commercial and tax-law periods) provide for it. Specific periods are stated with the respective processing or in section 9.

6.4 Overview of the connections established in the browser

Depending on which of our offerings you use, your browser establishes connections to the following domains. The "Context" column indicates the section in which the respective connection occurs (A = bluepic.io, B = studio.bluepic.io, C = template.bluepic.io). Services that we use exclusively on the server side are not listed. You will find these in the processor overview in section 7.

Domain / Service Purpose Context
bluepic.io Delivery of the website A
studio.bluepic.io Delivery of the application B
template.bluepic.io Delivery of the widget / preview A, B, C
api.bluepic.io Loading the configuration / backend API A, B, C
auth.bluepic.io Login / authentication B
feed.bluepic.io Loading projects / campaigns B
fontdelivery.bluepic.io Delivery of the self-hosted fonts A, B, C
sandbox.bluepic.io Rendering environment of the generator A, B, C
imagedelivery.net Delivery of the image assets A, B, C
eu.i.posthog.com / eu-assets.i.posthog.com Anonymous error and reach analysis A, B, C
beacon-v2.helpscout.net Support widget (only after an active click) A (/help), B
d3hb14vkzrxvla.cloudfront.net Help Scout CDN (Amazon CloudFront) A (/help), B
meetings-eu1.hubspot.com Appointment booking (only after opening the link) A
cdn.auth0.com Login / authentication B
secure.gravatar.com Profile picture display (integrated in Auth0) B
i0.wp.com Avatar images (integrated in Auth0) B
billing.stripe.com Payment processing (direct connection only via "Manage via Stripe" (Settings → Billing)) B
accounts.google.com / appleid.apple.com / github.com Social login (only when actively selected) B
www.linkedin.com / api.linkedin.com LinkedIn login, import of profile data and publishing of posts (only when the LinkedIn feature is activated) B, C

Section A – Website visitors (bluepic.io)

This section applies when you visit our public website bluepic.io without being logged in. The controller is FellowBlue GmbH. An overview of the connections (domains) established during your visit can be found in section 6.4.

A.1 Provision of the website and log files (hosting)

Our website is hosted by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. On each access, Cloudflare, as a processor, automatically collects server log files:

  • IP address of the requesting device
  • Date and time of access
  • Page accessed, volume of data transferred and status message
  • Browser type and version, operating system
  • Referring website (referrer)

This data is technically necessary to deliver the website and to ensure stability and security.

Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in technically error-free and secure provision as well as in the prevention and investigation of fraud and abuse).

Storage period: The server log files, including the IP address, are stored for 90 days and then deleted. This period serves in particular the prevention and investigation of fraud and abuse.

For the third-country transfer to Cloudflare, see section 8.

A.2 Pseudonymous reach and usage measurement with PostHog

To analyse the use of our website and to improve our offering, we use the analytics service PostHog provided by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, via its EU infrastructure. According to the provider, the data is processed on servers in Germany.

On bluepic.io, the measurement is carried out on a pseudonymous basis and without storing or reading information on your device (no analytics cookies). To technically correlate related events, we use a daily rotating identifier that is generated from the IP address, the User-Agent and further technical characteristics together with a salt that changes on a daily basis; the source characteristics are processed solely to generate this identifier and are not stored. Due to the daily rotation, linking across days and across devices is excluded; no individual user profiles are created.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in data-minimised reach and usage measurement). As no information is stored on or read from your device, no consent pursuant to Section 25(1) TDDDG is required.

A.3 Fonts

For a consistent presentation we use web fonts that we host ourselves (self-hosting) and deliver exclusively via our own content delivery network. No connection to third-party servers takes place in this process.

A.4 Support widget (Help Scout)

In our help area (pages under bluepic.io/help) we offer a support widget ("Beacon") from Help Scout Inc., 131 Tremont Street, Boston, MA 02111, USA.

The widget is not loaded automatically. Initially, only a button ("Help") provided by us is displayed. Only when you actively click on it is the widget loaded from Help Scout. Until then, no connection to Help Scout takes place, no IP address is transmitted and nothing is stored on your device. After you click, your IP address is transmitted to Help Scout and information required for the operation of the widget is stored in your browser's local storage. If you use the widget, we also process the information you provide (e.g. name, email address, message content).

Legal basis: The loading and the associated storage take place on the basis of your active request for the support service and are strictly necessary for this (Section 25 (2) no. 2 TDDDG). We base the processing of your information on Art. 6 (1)(b) GDPR and Art. 6 (1)(f) GDPR (efficient handling of support requests). For the third-country transfer, see section 8.

A.5 Appointment booking (HubSpot Meetings)

For demo and consultation appointments we integrate the "Meetings" scheduling service from HubSpot (HubSpot Ireland Limited, 1 Sir John Rogerson's Quay, Dublin 2, Ireland; parent company HubSpot, Inc., USA), which acts as our processor.

As soon as you open a corresponding booking link ("Book a demo"), HubSpot sets cookies on the booking page operated by HubSpot and processes technical access data (including your IP address). As long as you do not open the link, no data is transmitted to HubSpot. If you book an appointment, HubSpot processes the data you provide (e.g. name, email address, desired appointment) in order to organise the appointment for us.

Legal basis: Art. 6 (1)(b) GDPR (pre-contractual measures) and Art. 6 (1)(f) GDPR (legitimate interest in arranging consultation appointments). For the third-country transfer, see section 8.

A.6 Embedded generators and widgets (Bluepic Embed)

On various pages we embed our own widget or our generators as a live preview (iframe) from our subdomain template.bluepic.io. Depending on the context, we communicate this differently (e.g. as "Free Design Generator", "Template Demo" or "Website Widget"). Technically, in all cases this is the same application as in section C.

Because the embedding takes place on our own website, we are the controller for the technical processing involved. With regard to the connection to our infrastructure and the domains loaded, the technical data processed, uploaded images and the anonymous error and reach analysis, the explanations in section C, in particular C.3 and C.4, apply accordingly.

Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in presenting our product features); insofar as you actively request a specific service (e.g. creation of an individual design), Art. 6 (1)(b) GDPR.

Optional delivery of the result by email (Brevo)

For individual generators (e.g. "Free Design Generator") you can provide an email address to which we send you the result or the link. Your email address is transmitted to Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany) for this purpose and used exclusively to send the requested result. Legal basis: Art. 6 (1)(b) GDPR. Storage period of the email address stored at Brevo: 30 days.

A.7 Contact by email or telephone

If you contact us by email (info@bluepic.io) or by telephone, your details are stored in order to process your request.

Legal basis: Art. 6 (1)(b) GDPR, provided your request serves the performance of a contract, otherwise Art. 6 (1)(f) GDPR. The data is deleted as soon as it is no longer required and no retention obligations conflict with this.


Section B – Registered customers (studio.bluepic.io)

This section describes the processing that we carry out regarding you as a registered customer. For the personal data that you process via our software regarding your own end users, section 4 (processing on behalf) and the DPA concluded with you apply; the perspective of your end users is described in section C. An overview of the connections (domains) established in the application can be found in section 6.4.

B.1 Account and authentication (Auth0/Okta)

For registration and login we process your account data (in particular name, email address, company and account-related settings). For user and access management we use Auth0/Okta, Inc., Okta HQ North America, 100 First Street, San Francisco, CA 94105, USA as a processor; the processing takes place in the EU region. Auth0 stores your account information (including email address, name, company, password hash).

Login via third-party providers (social login): As an alternative to logging in with email and password, you can log in (via Auth0) with an account at Google, Apple or GitHub. If you select one of these options, you are redirected to the respective provider; this provider authenticates you and then transmits the profile data required to create the account (in particular name and email address) to us or Auth0. Beyond the data you have released, we receive no further information. The respective provider processes the login under its own responsibility in accordance with its privacy policy. The providers are:

  • Google Ireland Limited (Ireland) or Google LLC (USA); Google LLC is certified under the EU-U.S. Data Privacy Framework
  • Apple Distribution International Ltd. (Ireland) or Apple Inc. (USA). "Sign in with Apple" allows the use of an anonymised relay email address on request. Apple is not certified under the EU-U.S. Data Privacy Framework; transfers to the USA take place on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR).
  • GitHub Inc. (USA); GitHub Inc. is certified under the EU-U.S. Data Privacy Framework

Legal basis: Art. 6 (1)(b) GDPR (performance of the login you have chosen and provision of the account); the selection of a provider and the associated data transmission are based on your active decision. For the third-country transfer, see section 8.

To display profile pictures, Auth0 integrates services of Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA as a sub-processor: the avatar service Gravatar (secure.gravatar.com) and the image CDN "Jetpack Image CDN"/Photon (i0.wp.com), via which, among other things, Auth0 default avatars are delivered. In this process your browser establishes a connection to these services; a hashed value of your email address and your IP address are transmitted to Gravatar in order to retrieve an associated profile picture. Automattic Inc. is certified under the EU-U.S. Data Privacy Framework.

Legal basis: Art. 6 (1)(b) GDPR (provision of access and operation of the account); for the integration of Gravatar, Art. 6 (1)(f) GDPR (legitimate interest in displaying a profile picture). For the third-country transfer, see section 8.

B.2 Provision of the software and hosting

The application is operated via Cloudflare, Inc. (hosting/CDN, USA). The assets and images you create in the application are also stored in the Cloudflare infrastructure.

Your personal data is thereby distributed across three service providers: account information at Auth0 (see B.1), the assets and images you create at Cloudflare, and name, email address and, where applicable, payment data at Stripe (see B.3). We no longer use a separate database of our own for this.

Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) and Art. 6 (1)(f) GDPR (secure and stable operation). For the third-country transfer, see section 8.

B.3 Payment processing (Stripe)

For the processing of payments we use Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA). We do not store card data ourselves; it is processed by Stripe on its PCI-DSS-certified infrastructure.

When a Bluepic account is created, a customer record is created at Stripe, and name and email address are transmitted to Stripe. Further (payment) data is added when paid features are used. Transmission to Stripe generally takes place on the server side via api.bluepic.io. In the settings (Settings → Billing) the "Manage via Stripe" button is also available to you; if you open it, a direct connection is established between your browser and Stripe.

Legal basis: Art. 6 (1)(b) GDPR (performance of a contract) in conjunction with Art. 6 (1)(c) GDPR for billing documents subject to retention. For the third-country transfer, see section 8.

B.4 Product analytics and session recording (PostHog)

Within the application we use PostHog (PostHog Inc., EU region, server location Germany) in order to understand how the product is used, to operate, secure and improve it, and to support you in the event of problems or malfunctions of the application. Unlike on the public website, the events here are linked to your account (user-related product analytics).

Session recording (session replay): For quality assurance and customer support we record your session in the application and create a playable, video-like reproduction from it. This helps us in particular to understand which steps led to an error, in order to fix it and support you. In particular, the page content displayed, mouse and scroll movements, clicks and page changes are captured; inputs in form fields are masked. The session recordings are automatically deleted after 90 days.

Legal basis: Art. 6 (1)(f) GDPR (legitimate interest in operation, security, support and error diagnosis as well as in improving the product). Insofar as information is stored on or read from your device for this purpose, we obtain your consent under Section 25 (1) TDDDG in conjunction with Art. 6 (1)(a) GDPR. You can object to product analytics and session recording at any time with effect for the future or revoke consent you have given.

B.5 Support (Help Scout)

For customer support within the application we use Help Scout Inc. (USA). For logged-in customers, the support widget is part of the contractually owed service and is automatically available. In this process we process your profile and session data as well as the content of your support conversation. To deliver the widget components, Help Scout uses the globally distributed content delivery network Amazon CloudFront as a sub-processor (Amazon Web Services, Inc., certified under the EU-U.S. Data Privacy Framework). In this process your browser establishes a connection to d3hb14vkzrxvla.cloudfront.net. Delivery takes place via the nearest edge location (for users from the EU, regularly within the EU), while the underlying content originates from the AWS origin region chosen by Help Scout (USA). The transfer is safeguarded via the Data Privacy Framework.

Legal basis: Art. 6 (1)(b) GDPR (support as part of the contractual service) and Section 25 (2) no. 2 TDDDG for the storage required to provide the service. For the third-country transfer, see section 8.

B.6 Email communication (Cloudflare Email Service, Brevo)

For sending emails we use different services depending on the purpose:

  • Transactional and notification emails to logged-in users (e.g. account, system and activity notifications in the application) are sent via the Cloudflare Email Service (Cloudflare, Inc.). Legal basis: Art. 6 (1)(b) GDPR (performance of a contract). For the third-country transfer to Cloudflare, see section 8.
  • Newsletters, product news and advertising are sent (only with your consent) via Brevo (Brevo GmbH, Berlin, Germany; primarily EU servers). For this we transmit the required contact data (in particular name and email address) to Brevo as a processor. Legal basis: Art. 6 (1)(a) GDPR; revocable at any time via the unsubscribe link in each such email or by email to privacy@bluepic.io.

For the free tools on our website (use without an account), the transactional delivery of the result continues to take place via Brevo; details in section A.6.

Storage period (Brevo): 30 days

B.7 Creation, preview and testing of widgets (template.bluepic.io)

When you create a widget in the application, the same delivery infrastructure is loaded via template.bluepic.io for preview and functional testing that later also reaches your end users. Likewise, you can copy the URL of a widget from the application and open it yourself (e.g. in a new browser tab) and thereby come into direct contact with this service.

For the technical processing involved (domains loaded, technical data processed, uploaded images and the anonymous error and reach analysis), the explanations in section C, in particular C.3 and C.4, apply accordingly. As this use is part of the service contractually owed to you, we are the controller in relation to you.

Legal basis: Art. 6 (1)(b) GDPR (provision and testing of the widget function as part of the software) and Art. 6 (1)(f) GDPR (operation and security).

B.8 Fonts

In the application, too, web fonts are self-hosted and delivered via our own CDN.

B.9 Deletion of the account

You can terminate your account at any time. After closure, we delete your account data within 30 days, subject to statutory retention obligations (in particular for billing documents, see section 9). You can request the deletion of the account or of individual data, as well as a data export, at privacy@bluepic.io.

B.10 Campaign evaluation and LinkedIn feature

For campaigns that you create via our software, you can optionally activate the LinkedIn feature. Your end users can then log in with their LinkedIn account in the widget, transfer selected profile data into the design and publish the created draft as a post on their LinkedIn profile. For this purpose we provide you with a campaign dashboard that evaluates the resulting posts (impressions as well as clicks on the affiliate links contained in the caption).

When creating the campaign, you choose between two evaluation modes: (1) by name – the metrics are assigned per post to the respective LinkedIn profile (personal); (2) anonymous-aggregated – without assignment to individual persons. For the processing of your end users' data in the context of this feature, you are the controller and we are your processor (see section 4); the choice of mode, the legal basis and the information of your end users are your responsibility. LinkedIn's role is explained in section C.7.

Storage period: The campaign evaluation data is stored for the duration of the campaign, at most 2 years, and then deleted or anonymised.

Legal basis (provision of the feature to you): Art. 6 (1)(b) GDPR.


Section C – End users (widget, template.bluepic.io)

C.1 What you are reading here and who this section is addressed to

You are reading this section because you come into contact with our application without being a customer of ours yourself.

Note for registered customers: You, too, come into contact with this infrastructure when you create a widget in the application and test it in the preview, or when you open a widget URL yourself. The following sections C.3 and C.4 apply accordingly to the technical processing; who is the controller in this case is determined by section B (see B.7).

One of our customers uses our widget, i.e. the part of our software that contains a design template and the associated form fields. The widget is either embedded as content in the customer's website or app, or shared as a link with their end users. Technically, in both cases it is delivered via our subdomain (template.bluepic.io). It is often not immediately apparent to you that our application is being used in the background; this section provides the necessary transparency.

C.2 Who is responsible? (Two constellations)

As a rule, use takes place via one of our customers. The customer who provides you with the widget (embedded in their website or app, or shared as a link) is the controller for the processing of your data. We are their processor (Art. 28 GDPR) and provide exclusively the technical infrastructure; we act on the instructions of the controller. What that controller then uses your data for and on what legal basis can be found in the privacy information of the respective entity. For information and to exercise your rights with regard to this processing, please contact the respective responsible customer.

This does not apply to the pseudonymous technical telemetry used to operate, secure and improve our service: for this we act as controller in our own right on the basis of our legitimate interest (details in C.4).

A further exception is the case in which the embedding takes place on our own website. If we embed the same widget on our own website bluepic.io (see A.6), we are the controller for the processing involved.

The technical processing described below is essentially the same in both constellations; they differ only in the question of who is the controller.

C.3 Technical provision

When the widget is loaded, your browser establishes connections to our infrastructure. In this process, technically necessary data is processed, in particular your IP address, timestamp, resource accessed and browser/device information, in order to deliver the content and enable the interaction. The connections established in the browser are listed in the overall overview in section 6.4. Hosting, CDN and image storage are carried out via Cloudflare, Inc. as a processor; the delivery of the fonts is carried out from our own infrastructure (self-hosting).

Local processing

As far as technically possible, your inputs are processed exclusively locally on your device. The generated result (e.g. a profile picture) is usually rendered locally on your device and not stored on our servers; your other inputs (e.g. texts) also do not leave your device in this process. Only if local rendering fails, or if the responsible customer forces server-side rendering in the application settings, does a purely temporary server-side generation take place. This runs on a rendering server of Hetzner Online GmbH (location Germany, Falkenstein; region eu-central). The result is not stored, but returned to you within the same request. A data processing agreement (Art. 28 GDPR) is in place with Hetzner.

Uploaded images

If you upload an image into an input field, the original image is stored on the server side purely temporarily for a maximum of 24 hours (Cloudflare R2, firmly set to EU storage) and then automatically deleted. EXIF metadata is removed from the outset. Any replications in backups or CDN caches are overwritten or expire at the latest within 14 days.

Storage in the browser. The application uses sessionStorage solely to retain your own inputs in the input fields (recoverability and convenient continued use). This data remains exclusively local in your browser and is not transmitted to us or otherwise processed. The data stored in sessionStorage is deleted when the browser session ends. No cookies are set for this.

Legal basis: Art. 6 (1)(f) GDPR (technical provision and security) or – in the processing relationship – the instructions and legal basis of the controller. For strictly necessary storage on your device, Section 25 (2) TDDDG applies.

C.4 Pseudonymous error and usage analysis (PostHog)

On template.bluepic.io, we use PostHog (EU infrastructure, server location Germany) for technical telemetry, error and security analysis, and for product and usage analysis. To technically correlate related events, we use a daily rotating identifier that is generated from the IP address, the User-Agent and further technical characteristics together with a salt that changes on a daily basis. The source characteristics (in particular the IP address and User-Agent) are processed solely to generate this identifier and are not stored; only the pseudonymous identifier is stored. Due to the daily rotation, linking across days and across devices is excluded. No direct identifiers are collected, no individual user profiles are created, no information is stored on or read from your device, and no session replay is used.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the stability, security, error analysis and improvement of our service). We are the controller for this processing. As we do not access your device, no consent pursuant to Section 25(1) TDDDG is required.

C.5 Marketing/analytics technologies of our customers

Apart from the optional LinkedIn feature (see C.7), we do not load any marketing or non-anonymous analytics scripts towards you and do not carry out any personal evaluation. Insofar as such technologies are used on the embedding website, the respective customer is responsible for this as the controller.

C.6 Your rights

The data subject rights described in section 10 apply to you. For matters concerning the use of your data by the responsible customer (such as deletion or objection to marketing), please contact that responsible entity directly. For questions about our own processing, you can reach us at privacy@bluepic.io.

C.7 LinkedIn integration (optional feature; only if activated by the controller)

If the responsible customer uses the optional LinkedIn feature, you can log in with your LinkedIn account in the widget (OAuth). After your authorisation, (A) selected profile data (e.g. name, profile picture, position) is retrieved from LinkedIn and inserted into the design and/or (B) the draft you created is, at your instigation, published as a post on your LinkedIn profile.

LinkedIn (LinkedIn Ireland Unlimited Company, Ireland, and LinkedIn Corporation, USA, part of the Microsoft group of companies) is an independent controller for the login, the profile retrieval and the publishing; the data release is based on your authorisation. LinkedIn processes this data under its own responsibility in accordance with its privacy policy. For the transfer to the USA, see section 8.

Evaluation: If you become active via a post created in this way, impressions and clicks on the affiliate links contained therein may be evaluated. The click tracking takes place via our own infrastructure (Cloudflare); whether the evaluation is carried out by name or anonymous-aggregated is determined by the controller (see C.2). For this processing we are their processor; the data is stored for at most 2 years and then deleted or anonymised.

Legal basis or responsibility: in the processing relationship, the instructions and legal basis of the controller; for our own technical provision, Art. 6 (1)(f) GDPR.


Applicable to all user groups

7. Processors (overview)

We work with carefully selected service providers as processors (Art. 28 GDPR). A data processing agreement (DPA) is in place with each of them. Sub-processors used by them (e.g. Gravatar/Automattic via Auth0, Amazon CloudFront via Help Scout) are included via the respective contracts and are likewise DPF-certified.

Provider Purpose Location/Region Third country
Cloudflare Inc. Hosting / CDN / log files / image storage (R2, EU pinning) / image CDN (imagedelivery.net) / transactional email delivery USA (image storage EU) Yes (see section 8)
PostHog Inc. Usage/product analytics EU infrastructure (server location Germany) Generally no; any group access in the USA safeguarded
Help Scout Inc. Support widget USA Yes
HubSpot Ireland Ltd. / HubSpot, Inc. Appointment booking Ireland / USA Yes
Brevo GmbH Email delivery Germany / EU No
Stripe Payments Europe Ltd. / Stripe, Inc. Payment processing Ireland / USA Yes
Okta, Inc. (Auth0/Okta) Authentication / user management / account data EU region Yes
Hetzner Online GmbH Server-side rendering (fallback / can be forced by the customer) Germany (Falkenstein, eu-central) No

8. Data transfer to third countries

Some service providers are based in the USA or may transfer data to group companies there. For transfers to the USA we rely on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (DPF) (Art. 45 GDPR). In addition, or for cases not covered by the DPF, the EU Standard Contractual Clauses apply (Art. 46 (2)(c) GDPR).

The following are affected in particular:

  • Cloudflare, Inc. (hosting/CDN) (DPF-certified)
  • HubSpot, Inc. (appointment booking) (DPF-certified)
  • Help Scout Inc. (support widget) (DPF-certified) (sub-processor Amazon CloudFront/AWS likewise DPF-certified)
  • Stripe, Inc. (payment processing; primarily EU via Stripe Payments Europe Ltd.) (DPF-certified)
  • Okta, Inc. / Auth0 (authentication) (DPF-certified) (sub-processor Gravatar/Automattic likewise DPF-certified)
  • PostHog Inc. (EU hosting in Germany; any group access from the USA additionally safeguarded via Standard Contractual Clauses)
  • When using a social login (each an independent controller): Google LLC and GitHub, Inc. are DPF-certified; Apple is not DPF-certified and bases transfers to the USA on the EU Standard Contractual Clauses (Art. 46 GDPR)
  • When the LinkedIn feature is activated (independent controller): LinkedIn Corporation (USA, part of the Microsoft group of companies); transfers to the USA via the EU-U.S. Data Privacy Framework (Microsoft is a certified participant), subsidiarily the EU Standard Contractual Clauses (Art. 46 GDPR)

You can view the current DPF certification at https://www.dataprivacyframework.gov.

Additional safeguards and data localisation

The server-side storage of uploaded images takes place via Cloudflare R2 with a fixed EU restriction (EU jurisdiction pinning); storage outside the EU/EEA is thereby excluded. Only in the case of the edge-based execution of Cloudflare Workers and CDN functions can brief processing outside the EU not be entirely ruled out in individual cases; for these cases the DPF mechanism and, in addition, the EU Standard Contractual Clauses apply.

We last checked the DPF status of the US providers used (Cloudflare, Help Scout/AWS, HubSpot, Stripe-US, Okta, Google, GitHub, Automattic) on 21 July 2026. Operation and support by us take place from Germany or the EU; access by the providers' support/operations personnel bound to confidentiality within the scope of maintenance and error correction is limited to what is necessary (need-to-know) and is subject to the safeguards mentioned.

9. Storage period

We store personal data only for as long as is necessary for the respective purpose; specific periods are stated with the respective processing. Where statutory retention periods apply, the longer period applies; in particular, Sections 147 AO and 257 HGB require the retention of documents relevant under tax and commercial law for up to ten years. If erasure is not possible without impairing a retention obligation, the data is blocked instead.

10. Your rights as a data subject

You are entitled to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). In addition, you can revoke consent you have given at any time (Art. 7 (3) GDPR); the lawfulness of the processing carried out up to the revocation remains unaffected.

To exercise your rights, an informal message to privacy@bluepic.io is sufficient. Insofar as your request relates to processing for which one of our customers is the controller (section C), please contact that entity; otherwise we will forward requests.

Right to object

Insofar as we process your data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation.

Right to lodge a complaint

Without prejudice to other legal remedies, you have the right to lodge a complaint with a supervisory authority. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
https://www.ldi.nrw.de/

11. Data security (SSL/TLS encryption)

We use technical and organisational measures in line with the state of the art, in particular SSL/TLS encryption during transmission. You can recognise an encrypted connection by "https://" in your browser's address bar.

12. Currency and amendment of this privacy policy

This privacy policy is dated 24 July 2026. Due to the further development of our services or as a result of changed legal or regulatory requirements, an amendment may become necessary.