Legal
Privacy Policy
Last updated 13 May 2026.
Bleinks Ltd ("we") is the data controller for personal data processed via bleinks.com. We are a UK-incorporated company; UK GDPR governs our processing, and we comply with EU GDPR for EU-based users. This policy explains what we collect, why we collect it, and what your rights are.
What we collect
- Account data: email address, name, password hash (held by our authentication provider, Firebase — we never see the cleartext password), Stripe customer ID.
- Document data: the PDFs you upload, the fields you place on them, the values your recipients submit (signatures as PNG images, text values, dates, checkboxes).
- Signing metadata: the IP address and user-agent of each signer when they view and sign a document. This is required to produce the audit certificate that gives the signature its legal weight.
- Usage data: aggregate counts of documents created, sent, signed. We do not log document contents in analytics.
Why we process it
- Contract (Art. 6(1)(b)): to provide the signing service.
- Legal obligation (Art. 6(1)(c)): to retain audit logs and signed documents so that signatures remain evidentially sound.
- Legitimate interest (Art. 6(1)(f)): service security, fraud prevention, and product improvement.
Retention
Signed documents are retained for 90 days after completion. After that, we delete the document and its fields, keeping only an anonymised summary in the audit log. You can delete a document earlier at any time. If you close your account, we delete your personal data immediately, except where we are required to retain it to comply with legal obligations.
Sharing
We share data only with processors we need to run the Service:
- Stripe (payments) — billing information.
- Brevo (transactional email) — recipient email + signing link.
- Google Firebase (authentication) — account identity and password hash.
- Our infrastructure provider — encrypted storage of documents.
We do not sell your data. We do not share it with third parties for marketing purposes.
International transfers
Our infrastructure is hosted in the United Kingdom and the European Economic Area. Some processors (e.g. Stripe) may transfer data to the United States under standard contractual clauses.
Your rights
Under the UK GDPR you have the right to:
- access the personal data we hold about you (export your data);
- request correction of inaccurate data;
- request deletion of your data (delete your account);
- object to processing or request restriction;
- lodge a complaint with the Information Commissioner's Office (ICO).
Security
Documents are encrypted at rest (AES-256) and in transit (TLS 1.2+). The audit log is append-only and enforced at the database level so even a compromised application cannot rewrite signing history.
Cookies
See our Cookie Policy.
Contact
Data Protection: info@bleinks.com