This is a professionally structured template, not legal advice. It must be reviewed, completed, and approved by qualified legal counsel (including Indian counsel for the DPDP Act, 2023) before publication or use. All bracketed items must be completed.
Introduction
This Privacy Policy ("Policy") explains how [LEGAL ENTITY NAME] ("BluePrint", "we", "us", or "our"), the operator of the BluePrint platform and the website located at [WEBSITE URL] (together, the "Services"), collects, uses, shares, stores, and protects Personal Data.
BluePrint is an AI-powered software development lifecycle (SDLC) orchestration platform. This Policy applies to visitors to our website, users who register for an account, and other individuals whose Personal Data we process as a Data Fiduciary (also known as a data controller).
Customer Content and our role as a processor. Where you use the Services to process personal data contained in your projects, source code, prompts, or connected systems ("Customer Content"), you (or your organisation) are the Data Fiduciary and we act as a Data Processor on your behalf. That processing is governed by our Data Processing Agreement (DPA), not this Policy. This Policy addresses Personal Data for which BluePrint is the Data Fiduciary.
By accessing or using the Services, you acknowledge that you have read and understood this Policy. Where the law requires consent, we will obtain it as described below.
Definitions
Personal Data — Any data about an individual who is identifiable by or in relation to such data.
Data Principal / Data Subject — The individual to whom the Personal Data relates.
Data Fiduciary / Controller — The person who determines the purpose and means of processing Personal Data.
Data Processor — A person who processes Personal Data on behalf of a Data Fiduciary.
Processing — Any operation performed on Personal Data (collection, storage, use, disclosure, erasure, etc.).
Consent — Free, specific, informed, unconditional, and unambiguous agreement to processing.
DPDP Act — The Digital Personal Data Protection Act, 2023 (India) and rules made under it.
GDPR — The EU/UK General Data Protection Regulation, where applicable.
Who we are & how to contact us
Data Fiduciary: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].
Grievance Officer / Data Protection Officer: [NAME], [EMAIL], [PHONE / ADDRESS]. Under the DPDP Act, you may contact our Grievance Officer with any questions or complaints about how we handle your Personal Data (see Section 15).
Personal Data we collect
Identity & account data — Name, username, email address, hashed password, profile details, role.
Authentication data — OAuth identifiers and tokens from Google or GitHub sign-in; multi-factor authentication data.
Billing & transaction data — Billing name and address, tax identifiers (e.g. GSTIN), plan, and limited payment details processed by our payment provider (we do not store full card numbers).
Usage & technical data — IP address, device and browser information, log data, pages viewed, actions taken, timestamps, and cookie identifiers.
Project & content data — Projects, artefacts, prompts, instructions, and any source code or documents you create, upload, or connect — which may contain Personal Data you control.
Integration data — Data we access from third-party services you connect (e.g. repositories, documents, tickets), limited to the permissions you grant (see Section 6).
Communications — Support requests, correspondence, and feedback.
We do not intend to collect special category or sensitive Personal Data through the Services. Please do not submit such data except where strictly necessary and lawful. [CONFIRM POSITION ON SENSITIVE DATA]
How we collect Personal Data
Directly from you — when you register, configure the Services, make a payment, or contact us.
Automatically — through cookies and similar technologies as you use the website and platform (see Section 18).
From third parties — from OAuth providers (Google, GitHub) when you sign in, and from integrations you authorise.
Access & permissions we request from you
To provide the Services, BluePrint requests access to certain third-party accounts and systems. We only request the access needed for the features you use, and you can review or revoke these permissions at any time in the relevant provider's settings or in BluePrint.
Google sign-in (OAuth) — Basic profile and email address, to create and authenticate your account.
GitHub sign-in (OAuth) — Basic profile and email address, to create and authenticate your account.
Google Drive — Files and documents you authorise, to import or store project documents.
GitHub repositories — Read/write access to authorised repositories, to provision repos, create branches, and open pull requests.
Jira / Azure DevOps / Confluence / Notion — Project, issue, and document data you authorise, to sync project artefacts and plans.
Slack / Microsoft Teams / WhatsApp — Ability to send messages to authorised channels, to deliver notifications you enable.
Your own model account (BYOLLM) — API credentials you provide, to route AI processing through your account.
Device permissions (web push) — Notification permission, to send in-browser notifications you enable.
Revoking access. You may disconnect any integration within BluePrint and revoke access in the third party's security settings. Revoking access may limit related features.
Purposes of processing & legal bases
We process Personal Data for the purposes and on the legal bases set out below. Under the DPDP Act we rely on your consent or a permitted "legitimate use"; under the GDPR we rely on the corresponding legal basis: to create and administer your account and provide the Services; to process payments and manage subscriptions; to operate AI features and generate outputs from your inputs; to communicate with you; to improve, secure, and troubleshoot the Services; for marketing communications where applicable (consent, which you may withdraw); and to comply with law and enforce our terms.
Artificial intelligence & automated processing
The Services use artificial intelligence models — including models provided by Anthropic — to process your inputs, prompts, and Customer Content in order to generate outputs (such as documents and code). To provide these features, relevant inputs are transmitted to our AI sub-processor(s) for processing.
Where you use the "bring your own model" (BYOLLM) option, AI processing is routed through your own model account and is subject to that provider's terms.
Model training. Your inputs and Customer Content are used to provide the Services to you. [CONFIRM DEFAULT AND CONTROLS — recommended: by default we do not use your Customer Content or inputs to train foundation models; any model-improvement option is controlled by a setting in your account and is off unless you enable it.]
Human oversight. BluePrint is designed to keep a human in the loop: outputs are proposed for your review and approval at each stage. We do not use solely automated processing to make decisions producing legal or similarly significant effects on you without human involvement. [CONFIRM]
Consent & withdrawal
Where we rely on your consent, you may withdraw it at any time by contacting us or using in-product controls. Withdrawal does not affect processing carried out before withdrawal, and may limit your ability to use certain features. The ease of withdrawing consent will be comparable to the ease of giving it.
How we share & disclose Personal Data
We do not sell your Personal Data. We share it only as described here: with service providers / sub-processors who process data on our behalf under contract; within our group with affiliates that support the Services; for legal & regulatory reasons where required by law, court order, or to protect rights, safety, and security; in connection with business transfers such as a merger, acquisition, or sale of assets; and with your consent for any other disclosure.
Sub-processors
We engage sub-processors including Anthropic (AI model processing) and Amazon Web Services (hosting and managed database), plus an authentication provider, a payment provider, and transactional email/monitoring services. A current sub-processor list is available at [URL].
International data transfers
Your Personal Data may be processed in countries other than your own, including where our sub-processors operate. Where we transfer Personal Data internationally, we do so in accordance with applicable law. Under the DPDP Act, transfers are permitted except to any country restricted by the Central Government by notification. Under the GDPR, where applicable, we use approved transfer mechanisms such as Standard Contractual Clauses.
Data retention
We retain Personal Data only for as long as necessary for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements. Indicative periods are set out in our retention schedule; on account closure or a valid erasure request, data is deleted or anonymised within [PERIOD]. See our Data Retention, Deletion & DPA document.
Security
We implement reasonable technical and organisational measures to protect Personal Data, including encryption in transit, access controls, tenant isolation, isolated execution of generated code, multi-factor authentication for administrators, audit logging, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Further detail is in our Security Overview.
Your rights
Subject to applicable law, you have rights in relation to your Personal Data. Under the DPDP Act: the right to access a summary of your Personal Data and processing; to correction, completion, updating, and erasure; to grievance redressal; and to nominate another individual to exercise your rights in the event of death or incapacity. Under the GDPR (where applicable): access, rectification, erasure, restriction, data portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority. To exercise your rights, contact us at [PRIVACY EMAIL]. We may need to verify your identity and will respond within the timeframe required by law.
Grievance redressal
If you have a concern or complaint about our handling of your Personal Data, please contact our Grievance Officer at [GRIEVANCE OFFICER NAME & EMAIL]. We will acknowledge and endeavour to resolve your grievance within the period prescribed by law. If you are not satisfied, you may escalate to the Data Protection Board of India or the relevant supervisory authority in your jurisdiction.
Children's data
The Services are intended for users aged 18 and over and are not directed to children. Under the DPDP Act, a "child" is an individual under 18. We do not knowingly process the Personal Data of a child without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe we have collected a child's data without appropriate consent, contact us at [EMAIL] and we will take appropriate action.
Cookies & similar technologies
Our website uses cookies and similar technologies for essential functionality, preferences, and analytics: strictly necessary cookies enable core site and login functionality; functional cookies remember preferences and settings; analytics cookies help us understand usage to improve the Services. You can manage non-essential cookies through our consent banner and your browser settings. For details, see our Cookie Policy: [URL]
Data breach
We maintain procedures to detect, assess, and respond to personal data breaches. Where required by the DPDP Act, the GDPR, or other applicable law, we will notify the relevant authority (such as the Data Protection Board of India) and affected individuals within the prescribed timeframes.
Third-party links
The Services may link to third-party websites or services that we do not control. We are not responsible for their privacy practices; please review their policies.
Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a revised "Last updated" date and, for material changes, provide additional notice where required.
Governing law
This Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000, and, where applicable, the data-protection laws of other jurisdictions in which our users reside.
Contact us
[LEGAL ENTITY NAME] · [ADDRESS] · [PRIVACY EMAIL] · Grievance Officer: [NAME & EMAIL]