Account data
Your email address, your name if you give it, the language of the interface and the account’s plan.
In effect from Version 1.0
This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003. We wrote it to be read, not just to be published.
The data controller is the company that builds and runs Blupinta. We have not appointed a data protection officer (DPO), as our activities don’t require one: you can write to us directly with any question.
Ensiria S.r.l.This notice covers the website blupinta.app, the application at editor.blupinta.app and the emails Blupinta sends. It explains which personal data we handle when you visit the website, create an account, draw and furnish your projects and work with other people. It does not cover other sites Blupinta links to: their own notices apply there.
The content of projects (the homes you draw, the files you upload, the comments) belongs to you and the people you share it with: we keep it and handle it only so you can use Blupinta. If you put other people’s data in it, or invite someone by giving their email address, make sure you may.
We handle only the data your account and your projects need to work.
Your email address, your name if you give it, the language of the interface and the account’s plan.
The homes you draw and everything you write in them: walls, rooms, measurements, furniture, names, notes and, if you enter them, an address or coordinates. With them, the published versions, the history of changes and the files you upload, such as scans and PDFs of floor plans.
Who is in a project and with which role; invitations, with the invited person’s email address, who invited them, the role offered and when it expires; comments, mentions and notifications.
For each change made through the application we record who made it, the kind of request, the project and the time, without its content. For server errors we record the kind of request and the description of the error, never the page’s address or the data sent.
We handle no biometric data, no payment data (Blupinta has no payments today) and no special categories of data. We don’t keep IP addresses: neither the website nor the application records them. To limit repeated attempts, the application holds in memory only, for a quarter of an hour at most, the address requests come from when whoever sends them hasn’t signed in yet.
What you enter when you create your account, draw your projects and use the application.
Whoever invites you to a project gives us your email address; the people you work with can mention you in a comment; shared projects hold what their other members write in them.
The description of the browser and operating system, sent automatically with each request, and the time of the requests.
Each use has a precise purpose and a legal basis under Article 6 of the GDPR.
Where we rely on legitimate interest we have checked that it does not override your rights: the data is little, holds none of your projects’ content and protects you too. You can still object, as explained under your rights.
An email address is needed to create an account and sign in: without it we can’t provide the service. Your name is optional. What to write in your projects is up to you: an address, coordinates and notes are never required.
Blupinta writes to you only for the service: the sign-in link when you ask for it, invitations to a project and mentions in comments. We send no newsletters or promotional messages; if we ever do, it will only be with your explicit consent, which you can withdraw at any time.
The data is kept in the European Union: on OVH’s server and, for files and backups, in Amazon Web Services’ Stockholm region (eu-north-1).
Amazon Web Services belongs to a group based in the United States. Its data processing addendum includes the Standard Contractual Clauses approved by the European Commission, and Amazon takes part in the EU-US Data Privacy Framework. On top of that, the database’s backups are encrypted on our server before they are sent: whoever stores the file can’t read it.
| Data | For how long |
|---|---|
Account | As long as the account exists |
| Projects, files, versions, comments | Until you delete them, or until you delete your account. A deleted project is removed with all its files |
| Database backups | 7 days: what you delete is gone from the backups within a week |
Sessions | 30 days from their last use, or until you sign out |
| Email sign-in links | Valid for 15 minutes, then useless |
Invitations | 7 days, if not accepted |
| Technical data | 12 months at most |
| IP address for the request limits | 15 minutes at most, in memory only |
When you delete your account we remove your data and the projects you own. The comments and changes you left in other people’s projects stay in those projects, as part of their work, but no longer carry your name or email address.
Much of it you decide yourself, without writing to us:
The GDPR gives you these rights, which you can use at any time and free of charge:
Knowing which data we have about you and getting a copy.
Correcting inaccurate data. You change your name and language yourself on the account page.
Having your data deleted, except what the law requires us to keep. You do it yourself by deleting the account from its page.
Asking us only to store your data and do nothing else with it, for instance while we look into a complaint of yours.
Receiving the data you gave us in a structured format other applications can read. You download everything as a zip file from the account page; each project also exports from the editor as a .home.json file.
Objecting, on grounds relating to your situation, to the uses based on our legitimate interest.
For those the application doesn’t already let you use yourself, write to the address in the contacts, preferably from your account’s address: we may ask you to confirm who you are. We answer within one month; if the request is complex we may extend that by two more months, telling you so.
If you believe your data is handled against the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la Protezione dei Dati Personali, or with the authority of the country where you live or work.
Blupinta makes no decisions based solely on automated processing that have legal effects on you, and builds no profiles. If we introduce artificial intelligence features in the future, this notice will say which data they use and how before they become available.
Should a data breach put your rights at risk, we will notify the Garante within 72 hours and, where the risk is high, tell you as well.
Blupinta is not meant for anyone under 14. If you find out that a child under 14 has given us their data without the consent of whoever holds parental responsibility, write to us and we will delete it.
If this notice changes, we publish the new version here with its date and keep the list of earlier versions. If the change concerns what we do with your data, we also tell you by email before it takes effect.
For any question about this notice or to use your rights:
Ensiria S.r.l.