Privacy Policy
How BlinkHost collects, uses, shares, retains and protects personal data.
Controller: BLINKHOST LTD (CAC 9479867), 09 Ije Avenue, Abakaliki, Ebonyi State, Nigeria. Privacy contact: privacy@blinkhost.me.
1. Scope and roles
This policy covers BlinkHost websites, accounts, control plane, support, billing and platform operations. BlinkHost is a controller for account, commerce, security and its own service-usage data. For personal data a customer submits through a deployed application, customer database or customer-selected application telemetry, BlinkHost generally acts as processor under the Data Processing Addendum; the customer remains responsible for its notices, lawful basis and visitor choices.
2. Data we process
- Identity and account: name, email, provider identifiers, memberships and settings.
- Commerce: billing identity and address, country, tax identifier, plan, invoice, non-secret transaction references, amount and payment status. Payment-card data is handled by the payment processor.
- Platform content: projects, connected-repository identifiers and permissions, Git references and committed source selected for import or build, artifacts, project assets, preview-session data, domains, configuration, database content, encrypted secrets, support messages and customer-provided data.
- Technical and usage: IP address, device and browser information, timestamps, technical identifiers, authentication and security events, source-control webhook and operation status, feature use, preview, build and runtime diagnostics, uploaded-file security scan results, performance and errors.
- Customer application telemetry: tenant-scoped logs, metrics, traces, runtime-policy decisions and real-user performance measurements that the customer activates for a project.
- Communications: support correspondence and delivery/preferences evidence.
Do not place secrets, payment-card data or unrelated sensitive personal data in support, feedback or log fields.
3. Purposes and lawful bases
We process data to create accounts and provide requested service (contract or pre-contract steps); secure the service, scan uploads for malware and platform threats, prevent abuse and improve reliability (legitimate interests and legal duties); bill, account and respond to authorities (contract and legal obligation); send service communications (contract or legitimate interests); and run non-essential analytics or marketing only with consent where required. We document balancing where legitimate interests are used.
4. Sharing and service providers
We disclose personal data only as needed to operate and secure the service, provide infrastructure, email and database services, process payments, perform source collaboration you authorise, follow lawful instructions, protect rights or comply with law. A connected source provider receives only the repository operations requested under the permission you granted. We require service providers to protect personal data consistently with their role and our legal obligations. We do not sell personal data or use customer content for third-party advertising. Contact privacy@blinkhost.me for information about relevant provider categories and transfer safeguards.
5. International transfers
Our service providers process data in Nigeria and other countries where they operate. We assess destination and recipient risk and use an applicable lawful mechanism, contractual safeguards and supplementary technical controls as required by the Nigeria Data Protection Act 2023. Contact us for relevant safeguard information.
6. Retention and deletion
We keep data only as long as needed for the stated purpose, active service, security, disputes and legal duties. Product and customer-application telemetry follow disclosed plan retention. Verified deletion removes attributable data from active stores; residual protected backups expire through controlled cycles. Billing and acceptance evidence may be retained for tax, accounting, fraud and legal periods. A documented legal hold may temporarily preserve a narrow scope. Internal retention schedules are reviewed at least annually.
7. Security and incidents
Measures include tenant-scoped authorisation, least-privilege access, managed identities, encryption in transit and at rest, secret isolation, uploaded-file validation and malware scanning, audit logging, monitoring, backups and incident procedures. Customers remain responsible for their users, application configuration and lawful content. Report a suspected security or privacy issue to security@blinkhost.me or privacy@blinkhost.me.
8. Your rights
Subject to applicable law, you may request information and access, correction, deletion, restriction, objection, portability, withdrawal of consent and review of a significant solely automated decision. We may verify identity, authority and scope. We may retain information where law permits or requires and will explain a refusal or limitation. Email privacy@blinkhost.me. You may complain to the Nigeria Data Protection Commission or another competent supervisory authority.
9. Cookies and analytics
Essential cookies and similar storage support sessions, CSRF protection, checkout continuity and preferences. Customer real-user monitoring is separate from BlinkHost account analytics, disabled by default and activated by an authorised customer for each project. We do not use third-party advertising cookies.
10. Children and automated decisions
BlinkHost is not directed to children, and account holders must be legally able to contract. Automated security and operational checks help detect risk, but we do not intentionally make solely automated decisions producing legal or similarly significant effects without applicable safeguards.
11. Changes and contact
We publish each version and effective date and give reasonable notice of material changes. Contact BLINKHOST LTD at 09 Ije Avenue, Abakaliki, Ebonyi State, Nigeria or privacy@blinkhost.me.
Connected-source collaboration records
When customers use source collaboration, templates or Agency handoffs, BlinkHost processes the participating account identifiers, access scope, invitations, acknowledgements, reviews, template and version identifiers, handoff decisions, security results and related activity records needed to provide, secure and evidence those features.
Short-lived presence data is removed when it is no longer needed for the active session. Recoverable collaboration history follows the retention included with the workspace plan. Source reviews, approvals, security attestations and handoff records may be retained for the service term and a reasonable period afterwards for security, disputes, legal compliance and establishment or defence of claims. Customer-requested evidence export files expire from BlinkHost download storage after seven days; a customer's downloaded copy is under that customer's control. Narrow records may be preserved longer where required by law or a documented legal hold.
Live editing and presence data
To provide live co-editing, BlinkHost processes the project and document identifiers, participating account display names, access roles, short-lived presence and cursor information, edit acknowledgements, synchronized document updates and recovery records. Presence expires shortly after a participant leaves. A browser may keep unacknowledged edits in that browser profile until they are accepted or the browser data is removed.
Acknowledged edit history follows the retention stated in the workspace plan and may be consolidated into integrity-checked checkpoints. Access, security and audit records may be retained for the periods described elsewhere in this Policy, including where reasonably needed for security, disputes or legal obligations.
Marketplace and referral information
For a Microsoft Marketplace order, BlinkHost receives and uses the subscription, offer, plan, purchaser-tenant and purchaser-object identifiers, lifecycle status, quantity, timestamps and reconciliation evidence needed to activate, provide, secure and account for the service. Microsoft separately processes purchasing, payment, invoicing, tax and payout information under its own applicable terms and privacy notice.
For an approved referral programme, BlinkHost processes the referral code, referring and referred workspace identifiers, attribution time, verified activation and paid-conversion state, benefit decision and fraud-prevention evidence. A Marketplace order or referral does not by itself provide permission for unrelated marketing.
Files uploaded through customer applications
When a customer application uses Hosted Object Storage, BlinkHost processes the files, related metadata, technical identifiers and security-scan results needed to receive, protect, store and deliver them. The BlinkHost customer determines why the application collects those files and who may access them. End users should direct requests about the content and use of their files to the operator of that application; BlinkHost supports the operator in responding as required by applicable law.