Privacy Policy
This policy describes information handled through bluetier.ai, the contact form, client onboarding, and the authenticated dashboard. It does not replace a client-specific data-processing agreement.
Effective and last updated: 2026-08-06Information you provide
Contact inquiries may include your name, work email, company, and message. Onboarding may include contact details, company and role information, website and LinkedIn profile URLs, account context, target-audience and campaign preferences, authorization, typed signature, and submission date. BlueTier does not ask for a LinkedIn or email password through the onboarding form.
Information collected to operate the site
Hosting and security systems may process request data such as IP address, browser type, device information, timestamps, route requested, and security events. The dashboard uses an expiring, signed session cookie after authentication. We do not currently use advertising cookies or cross-site behavioral advertising on this application.
Why we use information
Each purpose below is paired with its legal basis under the GDPR and comparable privacy laws.
- Respond to inquiries and onboarding submissions — contract performance and steps taken at your request before a contract
- Evaluate, deliver, support, and improve contracted services — contract performance
- Operate authentication, security, abuse prevention, and troubleshooting — legitimate interest in keeping the service secure and reliable
- Send transactional confirmations and internal workflow notifications — contract performance
- Maintain records, enforce agreements, and meet applicable legal obligations — legal obligation and legitimate interest
- Analyze service performance using client and campaign records where authorized — legitimate interest; consent where required
- Optional marketing or product communications where offered — consent, which you can withdraw at any time
Responsible AI and automated processing
BlueTier uses AI-assisted features for tasks such as onboarding assistance, ICP discovery, profile analysis, messaging drafts, conversation summaries, and performance recommendations. AI prompts may include the profile, ICP, and messaging context that you provide or authorize for your own campaigns. Customer data is used only to provide that customer’s own service; it is not used to train shared models unless separately disclosed. AI-drafted messages are not sent without a customer approval checkpoint — a human reviews and approves content before it goes out. AI outputs are logged for troubleshooting and dispute resolution.
- Data entering AI prompts: profile, ICP, and messaging context you provide or authorize.
- Data use: only to provide your own service — no training on customer data unless separately disclosed.
- Human checkpoints: customer review and approval before AI-drafted messages are sent.
- Logging: AI outputs are logged to support troubleshooting and dispute resolution.
Audience targeting and sensitive categories
Onboarding includes optional fields that can touch protected or sensitive categories, such as ethnic or religious community affiliations. These fields are optional and entirely customer-directed: they are used solely to configure targeting for your own campaign and for no other purpose. Where AI-assisted features infer or suggest targeting criteria, those suggestions are presented to you for review before they are used — AI-inferred targeting is never applied without customer review.
Introduction Service data flows
Participation in the BlueTier Introduction Service is opt-in and is never enabled by default. The matching system uses industry, ICP, geography, and your stated introduction categories to identify potential introductions. When an introduction is approved, the other member sees only your name, headline and profile fields, and the introduction context. Contact details and campaign data are never shared across members.
- Visible to the matching system: industry, ICP, geography, and stated introduction categories.
- Shown to another member: name, headline/profile fields, and the introduction context — only when an introduction is approved.
- Never exposed cross-member: contact details and campaign data.
Service providers and disclosures
Information may be processed by providers used for hosting, data storage, transactional email, client records, and authorized account analytics. The current architecture includes Vercel (hosting), Google Sheets (operational records mirror), Neon (Postgres database), Brevo (transactional email), and Unipile (LinkedIn account connectivity) where configured. The current list is published on the subprocessors page. Providers process information for their service role and are subject to their own terms and privacy practices. We may also disclose information when required by law, to protect rights or security, or as part of a legitimate corporate transaction.
- BlueTier does not sell personal information.
- BlueTier does not use personal information for cross-context behavioral advertising in this application.
- BlueTier does not publish client onboarding records.
Retention
Contact inquiries are retained for up to 24 months after the last interaction, unless a longer period is required for an ongoing matter or legal obligation. Onboarding, authorization, service, and client-operation records are retained for the life of the customer relationship plus up to 6 years afterward for disputes, accounting, and legal requirements. Security logs are retained for 12 months. Records are deleted or de-identified when the applicable period ends, subject to required recordkeeping. Backups cycle out on a defined schedule, so deleted records expire from backups as the rotation completes.
International processing
Providers and authorized team members may process information in countries other than your own. Where required, BlueTier uses appropriate contractual or legal mechanisms and limits access to the service purpose.
Your choices and rights
Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, or information about processing. You may also object to or withdraw consent for processing that relies on consent. Some requests may be limited by identity verification, contractual needs, security, or legal recordkeeping. As an interim self-serve process, you can request an export or deletion of your data by email; requests are completed within 10 business days.
- Email IT@bbmgroup.io with “Privacy request” in the subject line.
- State whether you are requesting an export, a deletion, or another right.
- Describe the account or submission involved without sending passwords or sensitive credentials.
- We may ask for information necessary to verify identity and authority.
Children
The website and service are intended for business users and are not directed to children. Do not submit information about a child through the contact or onboarding forms.
Changes and contact
We will update the date on this page when the policy materially changes. Questions, complaints, and rights requests can be sent to IT@bbmgroup.io.
Authoritative references
UAE data protection laws — The Official Portal of the UAE Government ↗General Data Protection Regulation, Article 13 — EUR-Lex ↗What general notices are required by the CCPA? — California Privacy Protection Agency ↗Questions or correction requests?
Use the contact form or email IT@bbmgroup.io. Never include an account password or verification code.
Contact BlueTier →