# Data Privacy & Storage

We take data privacy and security seriously. This page explains how we handle, protect, and store your data in compliance with global privacy regulations.

## Our Privacy Commitment

### Data Protection Principles

We follow these core principles:

**Transparency:**

* Clear information about how we use your data
* Easy-to-understand privacy policies
* Regular updates on data practices

**Security:**

* Industry-standard encryption and security measures
* Regular security audits and assessments
* Secure data centers and infrastructure

**Control:**

* User control over their personal data
* Easy opt-out and deletion options
* Clear consent management

**Compliance:**

* GDPR, CCPA, and other global privacy regulations
* Regular compliance audits and updates
* Dedicated privacy and legal teams

## Data We Collect

### Information You Provide

Data you directly share with us:

**Account Information:**

* Name, email address, company details
* Payment and billing information
* Account preferences and settings

**Content Data:**

* Video content and templates you create
* Contact lists and audience data
* Custom branding and assets

**Usage Data:**

* How you use our platform
* Feature usage and preferences
* Support interactions and feedback

### Information We Collect Automatically

Data gathered through normal platform usage:

**Technical Data:**

* IP addresses and device information
* Browser type and version
* Operating system and platform

**Usage Analytics:**

* Pages visited and features used
* Time spent on different sections
* Error logs and performance data

**Video Analytics:**

* View counts and engagement metrics
* Interaction data and completion rates
* Performance and delivery statistics

## How We Use Your Data

### Platform Operations

Essential functions to provide our service:

**Account Management:**

* Create and maintain your account
* Process payments and billing
* Provide customer support

**Service Delivery:**

* Generate and deliver personalized videos
* Process data for personalization
* Maintain platform functionality

**Improvement:**

* Analyze usage patterns to improve features
* Develop new functionality
* Optimize performance and reliability

### Marketing and Communication

With your consent, we may use data for:

**Product Updates:**

* New feature announcements
* Platform improvements and changes
* Security updates and maintenance

**Educational Content:**

* Best practices and tips
* Tutorial videos and guides
* Industry insights and trends

**Promotional Offers:**

* Special pricing and discounts
* Event invitations and webinars
* Partner promotions and integrations

## Data Storage and Security

### Storage Infrastructure

Where and how we store your data:

**Data Centers:**

* Enterprise-grade cloud infrastructure
* Multiple geographic regions for redundancy
* Regular backups and disaster recovery

**Encryption:**

* **In transit** — TLS/SSL encryption for all data transfers
* **At rest** — AES-256 encryption for stored data
* **Database** — Encrypted database connections and storage

**Access Controls:**

* Role-based access permissions
* Multi-factor authentication
* Regular access reviews and audits

### Data Retention

How long we keep your data:

**Account Data:**

* **Active accounts** — Retained while account is active
* **Inactive accounts** — Deleted after 12 months of inactivity
* **Billing data** — Retained for 7 years for tax compliance

**Content Data:**

* **Videos and templates** — Available while account is active
* **Analytics data** — Retained for 2 years for insights
* **Contact lists** — Deleted when account is closed

**Usage Data:**

* **Logs and analytics** — Retained for 12 months
* **Performance data** — Retained for 6 months
* **Error reports** — Retained for 3 months

## Your Privacy Rights

### Data Access and Control

Your rights regarding your personal data:

**Access:**

* View all personal data we hold about you
* Download your data in standard formats
* Request information about data processing

**Correction:**

* Update inaccurate or incomplete information
* Modify account preferences and settings
* Correct contact and billing information

**Deletion:**

* Request deletion of your personal data
* Close your account and remove all data
* Opt out of marketing communications

**Portability:**

* Export your data in machine-readable formats
* Transfer data to other services
* Download your content and templates

### Consent Management

Control how we use your data:

**Marketing Consent:**

* Opt in/out of marketing emails
* Choose communication preferences
* Manage promotional offers

**Data Processing:**

* Control data enrichment and analytics
* Manage third-party integrations
* Set data sharing preferences

**Cookies and Tracking:**

* Manage cookie preferences
* Control analytics tracking
* Opt out of targeted advertising

## Third-Party Services

### Service Providers

We work with trusted partners for:

**Infrastructure:**

* Cloud hosting and storage providers
* CDN and content delivery services
* Database and analytics platforms

**Business Services:**

* Payment processing and billing
* Customer support and help desk
* Email delivery and marketing tools

**Data Enrichment:**

* Company and contact data providers
* Email validation and verification
* Analytics and insights services

### Data Sharing

We only share data when necessary:

**Legal Requirements:**

* Court orders and legal requests
* Regulatory compliance requirements
* Law enforcement cooperation

**Business Operations:**

* Service providers under strict contracts
* Partners with explicit consent
* Analytics and improvement services

**Never Shared:**

* Personal contact information without consent
* Video content without permission
* Sensitive business data

## Compliance and Certifications

### Global Privacy Regulations

We comply with major privacy laws:

**GDPR (European Union):**

* Data protection by design and default
* Lawful basis for data processing
* Data subject rights and freedoms
* Breach notification requirements

**CCPA (California):**

* Right to know about data collection
* Right to delete personal information
* Right to opt out of data sales
* Non-discrimination protections

**Other Regulations:**

* PIPEDA (Canada)
* LGPD (Brazil)
* POPIA (South Africa)
* Various state and national laws

### Security Certifications

Industry-recognized security standards:

**SOC 2 Type II:**

* Security, availability, and confidentiality
* Regular independent audits
* Comprehensive security controls

**ISO 27001:**

* Information security management
* Risk assessment and mitigation
* Continuous improvement processes

**GDPR Compliance:**

* Regular compliance assessments
* Data protection impact assessments
* Privacy by design implementation

## Data Breach Response

### Incident Response Plan

How we handle security incidents:

**Detection:**

* 24/7 security monitoring
* Automated threat detection
* Regular security assessments

**Response:**

* Immediate incident response team
* Containment and investigation
* Customer notification within 72 hours

**Recovery:**

* System restoration and validation
* Post-incident analysis
* Security improvements and updates

### Customer Notification

We notify you of any data incidents:

**When We Notify:**

* Personal data is compromised
* Unauthorized access occurs
* Data is lost or corrupted

**How We Notify:**

* Email to registered addresses
* In-platform notifications
* Public announcements if necessary

**What We Provide:**

* Details about the incident
* Steps we're taking to resolve it
* Actions you should take
* Contact information for questions

## Contact Us

### Privacy Questions

If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at <privacy@blings.io>.

***

**Need help with data management?** Learn about [data quality and spam prevention](https://help.blings.io/personalization-data-management/data-quality-spam-prevention) to maintain effective campaigns.
