BlupintaSign in

Privacy notice

In effect from Version 1.0

This notice is given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Italian Legislative Decree 196/2003. We wrote it to be read, not just to be published.

1.Data controller

The data controller is the company that builds and runs Blupinta. We have not appointed a data protection officer (DPO), as our activities don’t require one: you can write to us directly with any question.

Ensiria S.r.l.
Via Federico da Montefeltro 3, 37135 Verona
VAT IT04975100233, share capital € 10.000,00
Email: info@ensiria.eu
Certified email (PEC): ensiriasrl@pec.it

2.What this covers

This notice covers the website blupinta.app, the application at editor.blupinta.app and the emails Blupinta sends. It explains which personal data we handle when you visit the website, create an account, draw and furnish your projects and work with other people. It does not cover other sites Blupinta links to: their own notices apply there.

The content of projects (the homes you draw, the files you upload, the comments) belongs to you and the people you share it with: we keep it and handle it only so you can use Blupinta. If you put other people’s data in it, or invite someone by giving their email address, make sure you may.

3.The data we handle

We handle only the data your account and your projects need to work.

Account data

Your email address, your name if you give it, the language of the interface and the account’s plan.

Sign-in data

  • Passkeys: the public key, the name you give the device, when it was created and when it was last used. The fingerprint, face or PIN that unlocks the passkey stays on your device and never reaches us.
  • Email sign-in links: only a cryptographic fingerprint of the link.
  • Sessions: a fingerprint of the session code, how you signed in, the description of the browser and operating system your browser sends, when it was last used and when it expires.

Project content

The homes you draw and everything you write in them: walls, rooms, measurements, furniture, names, notes and, if you enter them, an address or coordinates. With them, the published versions, the history of changes and the files you upload, such as scans and PDFs of floor plans.

Working together

Who is in a project and with which role; invitations, with the invited person’s email address, who invited them, the role offered and when it expires; comments, mentions and notifications.

Technical data

For each change made through the application we record who made it, the kind of request, the project and the time, without its content. For server errors we record the kind of request and the description of the error, never the page’s address or the data sent.

We handle no biometric data, no payment data (Blupinta has no payments today) and no special categories of data. We don’t keep IP addresses: neither the website nor the application records them. To limit repeated attempts, the application holds in memory only, for a quarter of an hour at most, the address requests come from when whoever sends them hasn’t signed in yet.

4.Where the data comes from

From you

What you enter when you create your account, draw your projects and use the application.

From other people

Whoever invites you to a project gives us your email address; the people you work with can mention you in a comment; shared projects hold what their other members write in them.

From your browser

The description of the browser and operating system, sent automatically with each request, and the time of the requests.

5.How we use the data, and on what basis

Each use has a precise purpose and a legal basis under Article 6 of the GDPR.

5.1Signing you in and running your account

  • Creating the account, letting you in with a passkey or a link, keeping you signed in between visits.
Data
Account data, sign-in data.
Legal basis
Performance of a contract (GDPR Art. 6(1)(b)): it is the service you ask for by signing up.

5.2Keeping your projects and letting you use them

  • Saving the homes you draw, showing them in 2D and 3D, keeping them the same on all your devices.
  • Publishing their versions, keeping their history, letting you undo and restore.
  • Exporting them as a file when you ask.
Data
Project content.
Legal basis
Performance of a contract (GDPR Art. 6(1)(b)): it is the service you ask for by signing up.

5.3Letting you work with other people

  • Sending invitations, giving each person their role, showing who is working and where.
  • Publishing comments and mentions, telling you with notifications.
Data
Working together, account data.
Legal basis
Performance of a contract (GDPR Art. 6(1)(b)) for people with an account; for someone invited who has none, the inviter’s and our legitimate interest in delivering the invitation (GDPR Art. 6(1)(f)).

5.4Writing to you for the service

  • The sign-in link when you ask for it, invitations to a project, mentions in comments.
Data
Email address, name.
Legal basis
Performance of a contract (GDPR Art. 6(1)(b)): it is the service you ask for by signing up.

5.5Protecting the service and your data

  • Limiting repeated attempts, such as requests for sign-in links or invitations.
  • Tracing who did what in a project, when needed.
Data
Technical data, sessions and, in memory only and for a few minutes, the IP address of whoever hasn’t signed in.
Legal basis
Legitimate interest (GDPR Art. 6(1)(f)): the security of the service and of its users’ data.

5.6Finding and fixing errors

Data
Technical data about errors.
Legal basis
Legitimate interest (GDPR Art. 6(1)(f)): the service working well.

5.7Meeting the law

  • Answering requests from authorities and meeting legal obligations.
Data
Whatever the law requires.
Legal basis
Legal obligation (GDPR Art. 6(1)(c)).

Where we rely on legitimate interest we have checked that it does not override your rights: the data is little, holds none of your projects’ content and protects you too. You can still object, as explained under your rights.

6.What happens if you don’t give us the data

An email address is needed to create an account and sign in: without it we can’t provide the service. Your name is optional. What to write in your projects is up to you: an address, coordinates and notes are never required.

7.The emails you receive

Blupinta writes to you only for the service: the sign-in link when you ask for it, invitations to a project and mentions in comments. We send no newsletters or promotional messages; if we ever do, it will only be with your explicit consent, which you can withdraw at any time.

8.Cookies and browser storage

The website blupinta.app uses no cookies, no analytics and loads nothing from other sites: even its fonts come from our server.

The application uses a single, technical cookie and keeps a few preferences in the browser’s storage (localStorage), which stay on your device:

NameKindWhat it is forHow long
pb_sessionTechnical cookie, editor.blupinta.appKeeping you signed in. It holds the session code, can’t be read by scripts and is only sent over encrypted connections30 days from its last use; removed when you sign out
project-blu.languagelocalStorageThe interface’s language before you sign inUntil you clear it
project-blu:drawing-look:…localStorageHow the scan looks in each project (opacity, contrast), for you onlyUntil you clear it
project-blu:setup-step:…localStorageHow far you are in each project’s guided setupUntil you clear it

All of them are technical tools needed for the service you asked for: that is why they need no consent and we show no banner. We use no profiling, analytics or third-party cookies.

9.Who we share the data with

We don’t sell your data and don’t hand it to anyone for commercial purposes. Only these see it:

The people in your projects

Whoever is in a project sees its content, its comments, your name or, if you haven’t given one, your email address, and while you work together the spot of the plan you are looking at.

Our providers

They handle data only on our behalf, as processors appointed with a contract under Article 28 of the GDPR:

  • OVH SAS (France): the server the website and the application run on, and the sending of emails.
  • Amazon Web Services EMEA SARL (Luxembourg): the storage of uploaded files and of the database’s encrypted backups.

The people at Ensiria

Those who work on Blupinta, only when needed to run the service or answer a request of yours, and bound to confidentiality.

Authorities

Only when the law requires it.

10.Where it is kept

The data is kept in the European Union: on OVH’s server and, for files and backups, in Amazon Web Services’ Stockholm region (eu-north-1).

Amazon Web Services belongs to a group based in the United States. Its data processing addendum includes the Standard Contractual Clauses approved by the European Commission, and Amazon takes part in the EU-US Data Privacy Framework. On top of that, the database’s backups are encrypted on our server before they are sent: whoever stores the file can’t read it.

11.How long we keep it

DataFor how long
AccountAs long as the account exists
Projects, files, versions, commentsUntil you delete them, or until you delete your account. A deleted project is removed with all its files
Database backups7 days: what you delete is gone from the backups within a week
Sessions30 days from their last use, or until you sign out
Email sign-in linksValid for 15 minutes, then useless
Invitations7 days, if not accepted
Technical data12 months at most
IP address for the request limits15 minutes at most, in memory only

When you delete your account we remove your data and the projects you own. The comments and changes you left in other people’s projects stay in those projects, as part of their work, but no longer carry your name or email address.

12.Your choices

Much of it you decide yourself, without writing to us:

  • Your name is optional: you can give it, change it or remove it on the account page, along with the language.
  • On the account page you see which devices you are signed in on and can sign them out, and you can add, rename and remove passkeys.
  • You can delete a project you own, and export any project as a .home.json file.
  • On the account page you download all your data as a zip file and delete the account. If you own projects shared with other people, you first hand them over to another member or delete them: nobody loses shared work unless you decided so.
  • You can decline an invitation, or let it expire, and leave a project you were invited to.
  • You can edit and delete your comments.

13.Your rights

The GDPR gives you these rights, which you can use at any time and free of charge:

Access (Art. 15)

Knowing which data we have about you and getting a copy.

Rectification (Art. 16)

Correcting inaccurate data. You change your name and language yourself on the account page.

Erasure (Art. 17)

Having your data deleted, except what the law requires us to keep. You do it yourself by deleting the account from its page.

Restriction (Art. 18)

Asking us only to store your data and do nothing else with it, for instance while we look into a complaint of yours.

Portability (Art. 20)

Receiving the data you gave us in a structured format other applications can read. You download everything as a zip file from the account page; each project also exports from the editor as a .home.json file.

Objection (Art. 21)

Objecting, on grounds relating to your situation, to the uses based on our legitimate interest.

For those the application doesn’t already let you use yourself, write to the address in the contacts, preferably from your account’s address: we may ask you to confirm who you are. We answer within one month; if the request is complex we may extend that by two more months, telling you so.

If you believe your data is handled against the GDPR, you can lodge a complaint with the Italian data protection authority, the Garante per la Protezione dei Dati Personali, or with the authority of the country where you live or work.

14.Automated decisions

Blupinta makes no decisions based solely on automated processing that have legal effects on you, and builds no profiles. If we introduce artificial intelligence features in the future, this notice will say which data they use and how before they become available.

15.How we protect the data

  • You sign in with a passkey or a one-time link: there are no passwords to steal.
  • Of sign-in and session codes we keep only a cryptographic fingerprint, useless for getting into your account.
  • Every connection is encrypted (HTTPS), and the session cookie travels only over them.
  • Every request declares who may make it: a project is visible only to the people in it, each with their role.
  • The database’s backups are encrypted before they leave the server.

Should a data breach put your rights at risk, we will notify the Garante within 72 hours and, where the risk is high, tell you as well.

16.Children

Blupinta is not meant for anyone under 14. If you find out that a child under 14 has given us their data without the consent of whoever holds parental responsibility, write to us and we will delete it.

17.Changes to this notice

If this notice changes, we publish the new version here with its date and keep the list of earlier versions. If the change concerns what we do with your data, we also tell you by email before it takes effect.

18.Contact

For any question about this notice or to use your rights:

Ensiria S.r.l.
info@ensiria.eu
Certified email (PEC): ensiriasrl@pec.it

Supervisory authority

Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Roma
www.garanteprivacy.it