Legal

Privacy Policy

Last updated 13 May 2026.

Bleinks Ltd ("we") is the data controller for personal data processed via bleinks.com. We are a UK-incorporated company; UK GDPR governs our processing, and we comply with EU GDPR for EU-based users. This policy explains what we collect, why we collect it, and what your rights are.

What we collect

Why we process it

Retention

Signed documents are retained for 90 days after completion. After that, we delete the document and its fields, keeping only an anonymised summary in the audit log. You can delete a document earlier at any time. If you close your account, we delete your personal data immediately, except where we are required to retain it to comply with legal obligations.

Sharing

We share data only with processors we need to run the Service:

We do not sell your data. We do not share it with third parties for marketing purposes.

International transfers

Our infrastructure is hosted in the United Kingdom and the European Economic Area. Some processors (e.g. Stripe) may transfer data to the United States under standard contractual clauses.

Your rights

Under the UK GDPR you have the right to:

Security

Documents are encrypted at rest (AES-256) and in transit (TLS 1.2+). The audit log is append-only and enforced at the database level so even a compromised application cannot rewrite signing history.

Cookies

See our Cookie Policy.

Contact

Data Protection: info@bleinks.com