Privacy Policy
What data arises here, what for, how long it stays and who else gets to see it. As of 11 August 2026.
Controller
The controller within the meaning of the GDPR is the service provider named in the imprint. This policy covers the shop: the account you buy with, and the purchase itself. For the content an institute then creates inside BlueAgent — projects, geometry, conversations — BlueAgent's own privacy policy applies.
What we process — and why
Account and sign-in. Your email address, your password (stored
only as an argon2id hash, never in clear text), whether the address has
been confirmed, and the identifier of your workspace once there is one. The legal
basis is the contract (Art. 6(1)(b) GDPR). Signing in sets one
technically necessary cookie: blueshop_session, signed, HttpOnly,
SameSite=Lax, lifetime 14 days. There are no tracking, analytics or
advertising cookies.
Loading a page touches no other server. Everything these pages
load comes from our own server: no fonts from Google, no CDN, no embedded
services, no tracking pixels. A Content Security Policy
(default-src 'self') stops the browser from departing from that.
Your choice of language is remembered locally by your browser and sent nowhere.
Orders. What you bought — plan, number of seats, prepaid credit — the amount charged with its currency, the timestamps, and on the first purchase the name you give your workspace. The basis is the contract; that the order is kept beyond that follows from the statutory duty to retain records (Art. 6(1)(c) GDPR).
Payment. Payment happens at Paddle. Paddle is the merchant of record, which makes it the seller towards you: Paddle issues the invoice, remits the VAT, and processes your payment data as its own controller under its own privacy policy. To pay, you are taken to a page at Paddle; no script of Paddle's runs on our pages. We neither see nor store card, bank or PayPal details. What comes back for each event is an event id, the order number, the amount, the currency and the time.
Provisioning. To turn a paid order into working access, your email address and the workspace name you chose are sent to BlueAgent. The same person operates both services (see the imprint); no third party receives anything in the process.
Email. We send you the confirmation of your address and, if you ask for it, a link to reset your password. Only a hash of those links is stored — the link itself exists exactly once, in the message to you. Expired links are deleted.
Enquiries from institutes. The form on “For institutes” stores nothing: what you write becomes one email and afterwards exists only in our mailbox. That message also carries the IP address it came from — solely to attribute abuse of the form (Art. 6(1)(f) GDPR).
Logs. The server writes technical logs, the access log including your IP address, to run the service securely and to fend off abuse (Art. 6(1)(f) GDPR). They roll daily, are compressed after 7 days and deleted after 90 days. Passwords, tokens and keys are stripped before a line reaches the disk.
Abuse limits. Registration and sign-in are rate limited, by IP address and, for sign-in, additionally per account. The counters for that live in memory only and do not survive a restart.
Audit trail. Purchases, changes to an account and operator interventions are written down — with the account's identifier, not your address. That is the trail by which a bill can be reconstructed if it is ever disputed.
Recipients
- netcup GmbH
- Hosting. Daimlerstraße 25, 76185 Karlsruhe, Germany. Processor under Art. 28 GDPR.
- Scaleway SAS
- Delivery of our email, account and transactional mail only. France. Processor under Art. 28 GDPR.
- Paddle.com Market Ltd
- Payment and invoicing. United Kingdom. Not a processor but a controller in its own right; the transfer rests on the European Commission's adequacy decision for the United Kingdom.
Beyond this we pass on nothing, and we do not sell your data.
How long
- Account
- As long as it exists. You can delete it yourself from your account — a real deletion, not a “deleted” flag (Art. 17 GDPR).
- Orders
- Seven years, outliving the deletion of the account: receipts fall under the statutory retention period (§ 132 BAO, the Austrian Federal Fiscal Code). What remains names an account identifier for which there is no account.
- Logs
- 90 days.
- Links sent by email
- Until they expire, then deleted.
- Enquiries via the form
- Not stored at all.
Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection — informally, to the email address in the imprint. You may lodge a complaint with the Austrian Datenschutzbehörde (data protection authority), Barichgasse 40–42, 1030 Vienna. For the data that arises during payment, Paddle is the right address.
Institutional licences
Where an institution runs BlueAgent as its own deployment, it is itself the controller of its users’ data; we then process on its behalf. What applies there is in the data processing agreement (Art. 28 GDPR).
The German version of this page is the authoritative one.