This Service Provider Privacy Policy ("Policy") explains how Blue T processes personal data when a service listing, quote, order, purchase flow, or service interface links to this Policy (each, a "Service").
This Policy applies only to those Services. It does not govern a Blue T application, website, subscription, or other business that displays a different privacy notice.
Blue T's role
Blue T generally determines the purposes and means needed to quote, validate, secure, perform, deliver, support, renew, transfer, or terminate a Service and acts as the controller or responsible business for that processing.
For a particular Service, the Service Details may expressly identify processing that Blue T performs solely on a Customer's documented instructions in a processor or service-provider role. The applicable agreement and law govern that processing. Blue T's legal role depends on the actual processing and is not changed merely by the label used by an ordering platform.
A Customer is the natural person or legal entity that orders or receives a Service. An Agent is an AI agent, software agent, computer program, or other automated system acting for a Customer.
Agents and personal data
An Agent is not a natural person and does not itself have personal data rights. Its identifiers, instructions, transactions, and communications may nevertheless identify or relate to the Customer, Customer personnel or customers, or other individuals. This Policy applies to that personal data.
The Customer must configure its Agent to provide only information the Customer may lawfully disclose and that is reasonably necessary for the Service. Technical access to information does not by itself give an Agent authority to disclose it.
Personal data we process and sources
Depending on the Service, Blue T may process:
- Customer identity, representative, business contact, Agent, account, authority, and support information;
- quote, order, payment, refund, transaction, tax, and dispute information;
- Service inputs, task status, delivered artifacts, asset or account records, supplier references, renewal, transfer, and support history;
- personal or sensitive data required for a particular Service, such as addresses, identifiers, identity evidence, signatures, or government and tax information;
- IP address, authentication, access, device or client, diagnostic, security, fraud, sanctions, and incident information; and
- communications and attachments submitted through approved channels.
We receive personal data from the Customer, its personnel and Agents, ordering and payment platforms, suppliers and subcontractors, government agencies and registries, public blockchains, verification and security sources, public records, and people who communicate with us.
If the Customer or its Agent provides information about another person, the Customer represents that it has authority to do so and has given any notice or obtained any permission required by law.
Purposes and legal bases
Blue T uses personal data to:
- quote, validate, perform, deliver, support, renew, transfer, suspend, and terminate Services;
- verify identity, authority, ownership, eligibility, and supplied information;
- detect fraud, sanctions risk, security threats, misuse, and unlawful activity;
- communicate notices and respond to support, privacy, security, and dispute requests;
- reconcile payments, refunds, supplier costs, accounting, and taxes;
- protect Services, systems, Customers, suppliers, and other people;
- maintain necessary supplier, transaction, audit, incident, dispute, and legal records;
- enforce agreements and protect legal rights; and
- comply with law, regulation, and valid legal process.
Where applicable law requires a legal basis, Blue T relies as appropriate on performance of a contract or steps requested before entering one, Blue T's legitimate interests in providing and securing Services, compliance with legal obligations, protection of rights and safety, or consent for a specific optional use. Consent may be withdrawn prospectively when it is the applicable basis.
Blue T does not use payment authorization to create a separate legal-document acceptance ledger. Blue T does not sell personal data for money, share it for cross-context behavioral advertising, or process it for targeted advertising. Blue T does not use Service data to train a general-purpose AI model.
Recipients
Blue T may disclose personal data as reasonably necessary to:
- ordering platforms, payment services, wallets, transaction networks, and public blockchains;
- suppliers, subcontractors, registries, and other recipients performing or supporting the Service;
- government agencies, regulators, and other recipients required for a filing, registration, verification, or legal obligation;
- hosting, communications, security, identity, fraud-prevention, AI, support, accounting, and professional-service vendors;
- courts, authorities, law enforcement, and other parties responding to valid legal process or protecting rights and safety; and
- successors or transaction counterparties in a financing, reorganization, merger, acquisition, or sale of assets, subject to appropriate safeguards.
Recipients process information under their own legal obligations, their agreements with Blue T, or their own privacy notices, as applicable.
Automated and AI-assisted review
Blue T may use automated rules or AI-assisted services to review minimized and, where practicable, redacted non-sensitive information for compatibility, completeness, safety, fraud prevention, sanctions risk, abuse detection, and escalation.
An automated review may permit an order to proceed, identify missing information, reject or pause an order, trigger an available refund, or escalate the order for human review. Blue T may require human confirmation for sensitive, regulated, ownership-related, destructive, irreversible, or otherwise high-impact actions. Where required by law or reasonably appropriate for a materially adverse automated action, the Customer or affected individual may request human review through the contact route in Section 17.
Private keys, seed phrases, passwords, government identifiers, tax identifiers, identity documents, complete sensitive artifacts, and other secrets must not be submitted to an AI model. An automated result does not establish that the Customer had legal authority to provide particular data or request a particular action.
Sensitive data and secure intake
When a Service requires sensitive personal data, Blue T provides or identifies an authenticated intake route and a point-of-collection notice describing the required fields, purpose, material recipients, necessity, and expected retention. If applicable law requires consent, Blue T obtains it separately; agreement to Service terms is not consent for unrelated sensitive-data processing.
Sensitive data must not be placed in public blockchain fields, ordinary logs, analytics, general support tools, screenshots, ordinary Agent messages, or AI model prompts. Blue T limits access to sensitive data according to the Service and deletes or de-identifies local copies when they are no longer needed, subject to legal requirements and documented holds.
Public records
A Service may require information to be submitted to a government agency, registry, public blockchain, public attestation system, or another public record. Public information may include a wallet or Agent identifier, transaction data, Service outcome, buyer confirmation, filing information, ownership information, or other data required for the Service.
Those recipients control their copies under their own rules. Public records may be permanent, searchable, copied by others, and outside Blue T's ability to correct or delete.
Cookies and analytics
Blue T may use cookies or similar technologies necessary for security, session management, preferences, secure intake, and basic operation of the pages and interfaces covered by this Policy. Blue T may use limited analytics to understand reliability and Service use and does not use third-party behavioral-advertising cookies for these Services.
Where required, Blue T will provide additional notice or choice before using nonessential cookies or similar technologies.
Retention
Blue T retains personal data only for as long as reasonably necessary for the purposes described in this Policy, including the Service lifecycle, support, renewal and transfer, security and fraud prevention, supplier requirements, accounting and tax obligations, applicable limitation periods, disputes, legal holds, and other legal requirements. Personal data is not kept indefinitely merely because storage is technically possible.
In applying those criteria:
- temporary credentials, authorization codes, and transfer secrets are kept only until verified use, expiration, or the end of a short troubleshooting period;
- abandoned or completed sensitive-intake data and local sensitive copies are deleted when no longer needed for transfer, performance, verification, support, or a documented legal purpose;
- active Service, asset, account, registration, and fulfillment records are kept during the Service lifecycle and for a reasonable period afterward for support, transfer, disputes, supplier obligations, and compliance;
- quote, order, payment, refund, supplier, accounting, tax, sanctions, and compliance records may be retained for periods required by applicable law and reasonably necessary for audits, disputes, and enforcement;
- diagnostic, security, fraud, incident, support, and privacy-request records are kept only while reasonably useful for those purposes; and
- backup copies are overwritten or deleted through Blue T's ordinary backup cycle after source data is deleted.
Blue T periodically reviews retained data and deletes or de-identifies it when it is no longer needed, subject to legal holds and documented exceptions. Properly de-identified information that no longer identifies a person may be retained indefinitely. Supplier, Customer, government, registry, ordering-platform, and public-blockchain copies follow their own retention rules and may outlive Blue T's copy.
Privacy choices and rights
Depending on applicable law and the circumstances, an individual may have rights to:
- confirm whether Blue T processes personal data and access it;
- correct inaccurate personal data;
- delete personal data;
- obtain a portable copy of personal data the individual provided;
- restrict or object to particular processing;
- opt out of sale, targeted advertising, or qualifying profiling;
- limit or withdraw consent for sensitive-data processing when consent is the legal basis;
- request appropriate human review of qualifying automated processing;
- appeal denial of a request; and
- exercise rights without unlawful discrimination.
Requests may be submitted through the contact route in Section 17. Blue T may verify identity and authority proportionately. A legally authorized representative may act for an individual upon sufficient proof of authority.
Blue T will respond within the period required by applicable law. Rights are subject to exceptions, including information needed for security, fraud prevention, another person's rights, supplier obligations, accounting, tax, legal claims, public records, or compliance. Blue T cannot delete copies controlled by an independent third party or public system.
Because Blue T does not sell personal data, share it for cross-context behavioral advertising, or process it for targeted advertising, an opt-out request for those activities ordinarily will not change Service processing.
European Economic Area data rights
This section applies only when the European Union General Data Protection Regulation applies to Blue T's processing.
In that circumstance, an individual may have rights of access, rectification, erasure, restriction, portability, and objection and may withdraw consent when consent is the legal basis. The individual may also lodge a complaint with the supervisory authority in the country where the individual lives or works or where the alleged infringement occurred.
Blue T operates from the United States. If applicable law requires a recognized transfer mechanism or additional safeguards for a transfer of personal data, Blue T will implement the required mechanism or safeguards before making the transfer. When Blue T acts as a processor for an EEA controller, the parties must enter any data-processing terms required by applicable law before that processing begins.
Security
Blue T uses administrative, technical, and organizational safeguards designed for the nature of the data and Service, including access controls, encryption in transit, protection of sensitive data at rest where appropriate, credential separation, logging controls, and data minimization. No system is completely secure.
Customers are responsible for protecting their Agents, credentials, wallets, devices, data sources, tools, delivered assets, and approval mechanisms and for promptly reporting suspected compromise without sending secrets in the initial message.
Data about minors
Age requirements apply to natural people, not Agents. Services are not intended to collect personal data about anyone under 18 unless the Service Details expressly permit it and the Customer has all authority, notices, and consents required by law.
Other services and notices
This Policy does not replace the privacy notice of an ordering platform, payment service, supplier, registry, government agency, or other independent recipient. The Customer and its Agent must review the notices linked for the Service before supplying personal data.
A Service-specific point-of-collection notice may supplement this Policy for particular fields or recipients without requiring a separate general privacy policy for every Service.
Changes
Blue T may update this Policy prospectively by posting a revised version and effective date at https://bluetgroup.com/service-provider-privacy-policy. Blue T will provide reasonable notice of material changes when practicable. A revised Policy does not authorize retroactive handling of data contrary to the notice and law applicable when the data was collected.
Contact
All support, legal, privacy, and security communications may be sent to [email protected], or mailed to Blue T Group, LLC, 1521 Blake St, #27674, Denver, CO 80202.
