Last Updated: 2 April 2026
Privacy Policy

This Policy is designed to comply with:
the Swiss Federal Act on Data Protection (FADP) and its Ordinance (DPO/OFADP);
the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"); and
the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR").
Where you are located determines which of these laws primarily applies to you, but we apply GDPR-level protections to all users as our baseline standard.
1. Who is responsible for your data (Controller)
The controller responsible for processing your personal data is:
BLP Digital AG Schützengasse 16, 8001 Zürich, Switzerland Company reg. / VAT: CHE-295.990.745 MWST Email: privacy@blp-digital.com
BLP Digital AG acts as the lead controller for the BLP group. Depending on the entity you contract or interact with, one of the following group companies may also act as controller or joint controller:
BLP Digital GmbH (Schorndorf, Germany) — our establishment in the European Union;
BLP Digital UK Ltd (71–75 Shelton Street, London, United Kingdom) — our establishment in the United Kingdom;
BLP Digital US Inc. (447 Broadway, 2nd Fl #3400, New York, NY 10013, USA).
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who can be contacted on any matter relating to this Policy or the processing of your personal data:
Tim Groeger, Data Protection Officer BLP Digital AG, Schützengasse 16, 8001 Zürich, Switzerland Email: dpo@blp-digital.com
Representatives for EU and UK data subjects
We have appointed representatives for data subjects in the European Union and the United Kingdom. You may contact them on any matter relating to the processing of your personal data:
EU representative (Art. 27 GDPR): Maximilian Rothe c/o BLP Digital GmbH, Schorndorf, Germany Email: eu-representative@blp-digital.com
UK representative (Art. 27 UK GDPR): Rowan Saada c/o BLP Digital UK Ltd, 71–75 Shelton Street, London, United Kingdom Email: uk-representative@blp-digital.com
Our group Data Protection Officer, Tim Groeger, oversees data protection matters across all jurisdictions and can be reached at dpo@blp-digital.com.
2. Definitions
Personal data means any information relating to an identified or identifiable natural person.
Processing means any operation performed on personal data (collection, storage, use, disclosure, erasure, etc.).
Usage data means data collected automatically through your use of the Service (e.g. IP address, device and browser information, pages visited).
Service provider / processor means a third party that processes personal data on our behalf and under our instructions.
You / data subject means the individual whose personal data we process.
3. What personal data we collect
Data you provide to us when you contact us, book a demo, register for an account or communicate with us:
first and last name;
email address;
telephone number;
company name, role and business contact details;
the content of your enquiries or communications.
Data collected automatically (usage data) when you use the Service:
IP address, device identifiers, device type and operating system;
browser type and version;
pages viewed, date/time and duration of visits, referring pages;
diagnostic and analytics data.
Data from cookies and similar technologies — see Section 6.
We do not intentionally collect special categories of personal data (e.g. health, religion, biometric data) through the Service.
4. Why we process your data and our legal basis
We only process personal data where we have a valid legal basis. The table below maps each purpose to its legal basis under the GDPR/UK GDPR (Art. 6) and the corresponding justification under the FADP.
Under the FADP, we process personal data in good faith, proportionately, and for the purposes stated above. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, you have the right to object (see Section 10).
5. Who we share your data with (Recipients)
We share personal data only where necessary and with appropriate safeguards in place:
Service providers / processors who process data on our behalf under a data processing agreement — for example cloud hosting and infrastructure, analytics, CRM, email and communications, and customer-support tools. They may only process data on our instructions.
Group companies — the BLP entities listed in Section 1, where necessary for the purposes in this Policy and under intra-group data protection arrangements.
Professional advisers — lawyers, auditors and accountants, where necessary.
Authorities and courts — where we are legally required to disclose, or to establish, exercise or defend legal claims.
Acquirers or successors — in connection with a merger, acquisition, financing or sale of assets, subject to prior notice and continued protection of your data.
We do not sell your personal data, and we do not share it with third parties for their own independent marketing without your consent.
6. Cookies and tracking technologies
We use cookies and similar technologies (web beacons, tags, scripts) to operate the Service, remember your preferences, and — with your consent — to analyse usage and measure marketing.
Strictly necessary cookies are required to operate the Service (e.g. authentication, security). These do not require consent.
Functionality cookies remember your choices (e.g. language, login). Used with your consent where required.
Analytics and marketing cookies (including tools such as Google Tag Manager and any linked analytics/advertising services) are only set after you give consent via our cookie banner.
When you first visit our website you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies, and to manage your preferences at any time. Rejecting non-essential cookies does not prevent you from accessing our website, though some optional features may be limited. You can also control cookies through your browser settings. For details, see our Cookie Policy.
7. International data transfers
As a Swiss company with group entities in the EU, UK and US, your personal data may be transferred to and processed in countries outside your own, including outside Switzerland, the EEA and the UK.
The main countries to which your data may be transferred are Switzerland, Germany (EU) and the United Kingdom, all of which are recognised as providing adequate protection, and the United States (BLP Digital US Inc. and certain service providers). Switzerland, the EEA and the UK benefit from mutual adequacy recognition. Transfers to the United States and any other country without an adequacy decision are made only where we have put appropriate safeguards in place, or — where the FADP requires it — with your explicit consent.
Where we transfer personal data to a country that does not provide an adequate level of protection, we put in place appropriate safeguards, in particular:
Standard Contractual Clauses (SCCs) adopted by the European Commission, and the UK International Data Transfer Addendum, and the SCCs recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) with the necessary Swiss amendments; or
transfers to countries recognised as providing adequate protection by the European Commission, the UK government and/or the Swiss Federal Council; or
another lawful transfer mechanism permitted under the GDPR, UK GDPR and FADP.
You may request a copy of the relevant safeguards by contacting privacy@blp-digital.com.
8. How long we keep your data (Retention)
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting obligations, and to resolve disputes or enforce our agreements.
In practice:
Account and contract data is retained for the duration of the relationship and for the statutory retention periods afterwards (generally up to 10 years under Swiss and applicable commercial/tax law).
Enquiry and demo-request data is retained for as long as needed to handle your request and for a reasonable follow-up period.
Marketing data is retained until you unsubscribe or withdraw consent.
Usage and analytics data is generally retained for a shorter period unless needed for security or service improvement.
When personal data is no longer needed, we securely delete or anonymise it.
9. How we protect your data (Security)
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction — including encryption in transit, access controls, and regular review of our security practices. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authorities of any personal data breach where legally required.
10. Your rights
Subject to the conditions and exceptions in applicable law, you have the right to:
Access — obtain confirmation of whether we process your data and a copy of it;
Rectification — have inaccurate or incomplete data corrected;
Erasure — request deletion of your data ("right to be forgotten");
Restriction — request that we limit processing in certain circumstances;
Data portability — receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller;
Object — object to processing based on our legitimate interests, and to object to direct marketing at any time;
Withdraw consent — where processing is based on consent, withdraw it at any time;
Not be subject to solely automated decisions producing legal or similarly significant effects (see Section 11).
How to exercise your rights: contact us at privacy@blp-digital.com or write to BLP Digital AG, Schützengasse 16, 8001 Zürich, Switzerland. We will respond within the timeframes required by law (generally one month under the GDPR/UK GDPR). We provide a copy of your personal data free of charge — in electronic form, or, under the FADP, in printed form on request. We do not charge a fee unless your request is manifestly unfounded or excessive.
Right to complain to a supervisory authority:
Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch
EU: your local Data Protection Authority, or the authority in the member state of our EU establishment (Germany).
UK: the Information Commissioner's Office (ICO), www.ico.org.uk
We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority.
11. Automated decision-making and profiling
Where our Service uses automated processing or AI-based features to analyse or make decisions about data, we do not make decisions producing legal or similarly significant effects about you based solely on automated processing without a lawful basis and appropriate safeguards. Where such processing occurs, you have the right to obtain human intervention, to express your point of view, and to contest the decision. We will provide meaningful information about the logic involved on request.
12. Children's privacy
The Service is intended for business users and is not directed at children. We do not knowingly collect personal data from children below the age of digital consent (16 in the EU by default, subject to lower national thresholds down to 13; 13 in the UK). If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Links to other websites
The Service may contain links to third-party websites we do not operate. We are not responsible for their privacy practices and encourage you to review their privacy policies.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on this page, update the "Last updated" date above, keep the previous version available on request, and — where changes are material — notify you by email and/or a prominent notice on the Service before the changes take effect.