1.Who is responsible for your data
Perseids Ltd, a private limited company registered in the United Kingdom, registered office To be confirmed, is the controller for personal data processed through BLEUN, except where we act as a processor for a Professional or Enterprise customer (see the DPA). Privacy contact: privacy@bleun.ai.
2.What we collect
Account data
- Name, email address, authentication identifiers, language and preferences.
Objective data
- The objectives you state and how you word them;
- sub-objectives, milestones and deadlines;
- inputs, answers and preferences you provide;
- documents you upload;
- decisions, approvals and rejections; and
- confidence history and progress over time.
Agent activity data
- Which agents ran, what they were asked to do, what they produced, which actions were prepared, approved, executed or blocked, and the resulting activity log.
Technical data
- Device and browser information, IP address, timestamps, error and performance diagnostics, and security logs.
Billing data
- Plan, currency, billing interval, subscription status and invoice references. Card details are entered with Paddle and are never stored by BLEUN.
3.Why we process it
- To provide BLEUN: interpret objectives, plan work, run agents and track outcomes.
- To operate accounts, authentication and access control.
- To coordinate collaboration inside Professional BLEUNs.
- To process subscriptions, invoices and tax through our Merchant of Record.
- To keep the service secure, prevent abuse and investigate incidents.
- To provide support you request.
- To improve reliability and quality of the product.
- To comply with legal and accounting obligations.
4.Legal bases (UK GDPR / EU GDPR)
- Contract — providing the service you signed up for, including running agents on your objectives and billing you for a paid plan.
- Legitimate interests — security, abuse prevention, service reliability and product improvement, balanced against your rights.
- Consent — optional features such as non-essential cookies, marketing email, voice features and specific integrations. You can withdraw consent at any time.
- Legal obligation — tax, accounting and lawful requests.
5.AI processing
Delivering BLEUN requires sending relevant content to AI infrastructure providers. What is sent is scoped to the task: the objective text, the structured plan, the inputs you supplied and the specific document excerpts needed for the step being performed.
We may change or add providers as the product evolves; the current list is published in Subprocessors.
We do not sell your data, and we do not use your BLEUN content for advertising or profiling unrelated to your objectives.
6.Private BLEUNs
Content in a Private BLEUN is scoped to your account. Database-level access rules restrict reads and writes to your own records, so other customers cannot access your BLEUNs. It can become visible to others only if you share it, invite someone, convert it to a Professional BLEUN, or connect an integration that is granted access. Authorised personnel may access data only where strictly necessary to operate, secure or support the service.
7.Professional BLEUNs
In a Professional BLEUN, content is visible to members according to their role. The organisation or workspace owner controls membership and permissions and is responsible for ensuring it has the right to place information there. If you contribute to a Professional BLEUN, assume that its owner and authorised members can see your contributions and the related agent activity.
8.Documents and files
Uploaded files are stored in private storage and served only through short-lived, access-checked links. They are processed to extract the information needed for your objective. You can delete a document at any time; deletion removes it from active storage, and residual copies in encrypted backups age out on the backup cycle.
10.International transfers
Some providers process data outside the UK and EEA. Where that happens we rely on appropriate safeguards, such as UK International Data Transfer Agreements or Addenda and EU Standard Contractual Clauses, together with provider security commitments. You can ask us for information about the safeguards applied to a particular provider.
11.How long we keep data
- Account data: for the life of your account.
- Objective, input and agent activity data: for the life of the BLEUN, unless you delete it earlier.
- Uploaded documents: until you delete them or delete your account.
- Security and audit logs: a limited period appropriate to their purpose.
- Billing records: as required by tax and accounting law (typically six years in the UK).
- Encrypted backups: cycled and overwritten on a rolling schedule.
12.Deleting a BLEUN or your account
Deleting a BLEUN permanently removes its objective, sub-objectives, inputs, decisions and agent activity from the active service; the action is confirmed before it runs and cannot be undone. Deleting your account removes your account data and BLEUN content from the active service, other than records we must retain by law (for example invoices) and content that legitimately belongs to a Professional BLEUN owned by an organisation.
13.Your rights
Subject to applicable law, you can request:
- access to your personal data;
- correction of inaccurate data;
- deletion of your data;
- restriction of processing;
- portability of data you provided;
- objection to processing based on legitimate interests; and
- withdrawal of consent for optional features.
Email privacy@bleun.ai and we will respond within the statutory period, normally one month. You may also complain to the UK Information Commissioner's Office (ICO), or your local supervisory authority in the EEA.
14.Automated decision-making
BLEUN produces analysis, recommendations and confidence estimates using AI. It is designed so that consequential and irreversible actions require human approval, and autonomous execution happens only at the autonomy level you enabled. We do not use BLEUN to make solely automated decisions producing legal effects concerning you, such as credit, insurance or employment decisions.
15.Security
We use encryption in transit, encryption at rest with our infrastructure providers, row-level access controls that scope records to their owner, private document storage, least-privilege access for personnel and audit logging of agent actions. More detail is on the Security & Trust page. No system is completely secure; report a suspected vulnerability to security@bleun.ai.
16.Children
BLEUN is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided data, contact privacy@bleun.ai and we will delete it.
18.Changes to this policy
We will update this policy as BLEUN evolves. Each version carries an effective date, a last-updated date and a version number. For material changes we will notify you in the product or by email.

