1. Who is responsible for your information?
Blueprint SME is the trading name of Alexander Loredan, a sole trader based in Blackpool, United Kingdom.
For data-protection purposes, Alexander Loredan trading as Blueprint SME is the controller of the personal information described in this policy.
Email: info@blueprint-sme.co.uk
Telephone: 07706 049742
Data-protection enquiries and complaints should be sent to info@blueprint-sme.co.uk with “Data protection” in the subject line.
2. Information we may collect
The information collected depends on how you use the website and whether you contact or work with Blueprint.
Information you provide
- Your name
- Business name
- Email address
- Telephone number
- Preferred contact method
- The service you are interested in
- Information included in an enquiry or message
- Information and documents supplied while discussing or delivering a project
- Billing, payment and transaction information where paid work is agreed
- Feedback or correspondence you send to Blueprint
Information collected through the website
- IP address and technical request information processed to deliver and protect the website
- Browser, device, approximate location and traffic-source information
- Pages viewed and selected contact interactions, where analytics consent is given
- Security, diagnostic and error information needed to deliver and protect the website
OpenAI ChatGPT Sites and Cloudflare process technical information needed to deliver and protect the website. If a visitor allows optional analytics, Google Analytics 4 collects aggregated usage information. Advertising signals and personalised tracking are disabled, and contact-form names, contact details and message content are not sent to Analytics.
Sensitive information
Blueprint does not ask website visitors to provide passwords, payment-card details or highly sensitive personal information through the general enquiry form. Please avoid including this information in an enquiry.
If sensitive information is required for an agreed project, Blueprint will explain why it is needed and how it should be provided securely.
3. How we use personal information
| Purpose | Information used | Lawful basis |
|---|---|---|
| Responding to enquiries and arranging an initial conversation | Contact details, business information and enquiry content | Taking steps at your request before entering into a contract and Blueprint’s legitimate interest in responding to genuine business enquiries |
| Preparing quotations and discussing proposed work | Contact details, project requirements and relevant business information | Taking steps at your request before entering into a contract |
| Delivering agreed services and communicating about a project | Contact details, business information, project documents and correspondence | Performance of a contract |
| Managing invoices, payments, accounts and business records | Identity, contact, transaction and billing information | Performance of a contract and compliance with legal obligations |
| Protecting the website and preventing spam, fraud or misuse | Technical, security and website-usage information | Blueprint’s legitimate interest in operating a secure and reliable website |
| Understanding and improving website use | Analytics and website-usage information | Consent |
| Complying with legal claims, regulatory requests or professional obligations | Information relevant to the request or claim | Legal obligation or Blueprint’s legitimate interest in establishing, exercising or defending legal rights |
Blueprint does not currently use the enquiry form to add people automatically to a marketing list. If marketing communications are introduced later, the privacy information and consent process will be updated before they are sent.
4. Legitimate interests
Where Blueprint relies on legitimate interests, we consider whether using the information is necessary and whether your rights and interests outweigh the business purpose.
The relevant interests may include responding to genuine enquiries, protecting the website, preventing misuse, maintaining business records and dealing with legal claims.
Your right to object
You may object to processing based on legitimate interests. To raise an objection, email info@blueprint-sme.co.uk with “Data protection” in the subject line. Blueprint will consider the circumstances and explain the outcome.
6. International data transfers
OpenAI, Cloudflare, Brevo and Google operate internationally and may process information outside the United Kingdom. Blueprint uses these services under their applicable contractual and privacy terms. Where UK data-protection law requires a transfer safeguard, the provider’s relevant contractual mechanism or an applicable adequacy regulation will be relied upon.
Information supplied for client work will not be transferred through a new provider without considering whether that provider and the proposed method are appropriate for the information involved.
7. How long information is kept
Blueprint keeps personal information only for as long as it is reasonably needed for the purpose for which it was collected, including legal, accounting and dispute requirements.
- General enquiries that do not lead to paid work are normally kept for up to 24 months after the last meaningful contact.
- Client project records are normally kept for up to six years after the work ends where they may be needed for contractual, tax, insurance or legal purposes.
- Accounting and transaction records are kept for the period required by applicable tax and accounting rules.
- Google Analytics cookies created after consent are configured for no more than 12 months. Aggregated Analytics event information is retained according to the retention setting in the Blueprint Google Analytics property.
- Information may be kept for longer where a dispute, legal claim or regulatory requirement makes this necessary.
These periods are review points rather than a claim that every system deletes information automatically on a fixed date. Information that is no longer reasonably required should be securely deleted or anonymised.
8. How information is protected
Blueprint uses reasonable organisational and technical measures to protect personal information. These may include secure accounts, access controls, password protection, multi-factor authentication, encrypted connections, software updates and limited access to project information.
No internet or storage system can be guaranteed completely secure. If a personal-data breach creates a legal reporting or notification duty, Blueprint will follow the applicable requirements.
9. Your data-protection rights
Depending on the circumstances and lawful basis, you may have the right to:
- Be informed about how your information is used
- Ask for access to your personal information
- Ask for inaccurate information to be corrected
- Ask for information to be erased in certain circumstances
- Ask for processing to be restricted in certain circumstances
- Object to certain processing
- Ask for certain information to be transferred
- Withdraw consent where processing relies on consent
These rights are not absolute in every situation. To make a request, email info@blueprint-sme.co.uk with “Data protection request” in the subject line. Blueprint may need to verify your identity before acting on a request.
10. Data-protection complaints
If you are unhappy with how Blueprint has used your personal information, contact us first so the issue can be investigated.
Send complaints to info@blueprint-sme.co.uk with “Data protection complaint” in the subject line.
Blueprint will provide a clear way to submit the complaint, acknowledge it within 30 days, investigate it appropriately, respond without undue delay, and explain the outcome and any action taken.
You also have the right to complain to the Information Commissioner’s Office complaints service.
12. Changes to this policy
This policy may be updated when the website, services or legal requirements change. The latest version will always appear on this page with its review date.
