Privacy Policy
Last updated: July 20, 2026
This Privacy Policy explains how Blina Desk AI ("we", "us", "our") collects, uses, stores, and protects your personal data when you use our platform. We are committed to protecting your privacy in compliance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and applicable German data protection laws.
A German translation of this policy is available upon request. Please contact us at [email protected].
1. Data Controller
The data controller responsible for your personal data is:
Albert Milaqi
Arti-IT — Einzelunternehmen
Pinner Straße 11, 42579 Heiligenhaus, Germany
USt-IdNr: DE458209074
Email: [email protected]
2. What Data We Collect
We collect and process the following categories of personal data depending on how you use the platform:
2.1 Account and Authentication Data
- Full name, email address, and password (hashed)
- Company or organization name
- Role and permissions within your tenant
- Two-factor authentication (OTP) enrollment data
2.2 Technical and Session Data
- IP address
- Browser type and version
- Operating system and device type
- Session tokens (JWT) and session identifiers
- Login timestamps and session activity
2.3 Business Data (Tenant Data)
Depending on which modules you use, we may process:
- CRM data: contacts, leads, deals, companies
- HR data: employee records, time tracking, leave requests
- Legal data: contracts, cases, deadlines
- Helpdesk data: tickets, customer communications
- Documents: uploaded files and attachments
- Email data: sent and received messages via integrated email
- Sales data: invoices, quotes, orders
- Clinic, real estate, and warehouse management data
2.4 Billing Data
- Subscription plan and billing cycle information
- Payment information is processed exclusively by Stripe and is never stored on our servers (see Section 7)
3. Why We Collect Your Data
We process personal data for the following purposes:
- Service provision: To operate the Blina Desk AI platform and provide you with access to its features and modules
- Authentication and security: To verify your identity, manage sessions, enforce concurrent session limits, and protect against unauthorized access
- Billing and subscription management: To process payments, manage subscriptions, and issue invoices through Stripe
- AI-powered features: To provide AI-assisted functionality such as text generation, summarization, and analysis when you opt to use these features
- Platform improvement: To monitor system performance, diagnose errors, and improve reliability
- Legal compliance: To fulfill legal obligations under applicable laws
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under the GDPR:
- Art. 6(1)(b) — Contract performance: Processing is necessary to provide the services you have subscribed to, including account management, platform access, and billing
- Art. 6(1)(f) — Legitimate interest: Processing is necessary for our legitimate interests, including platform security, fraud prevention, error monitoring, and system optimization, provided these interests are not overridden by your rights
- Art. 6(1)(a) — Consent: Where you explicitly opt in to optional features such as AI-powered processing, we rely on your consent. You can withdraw consent at any time by disabling AI features in your settings
- Art. 6(1)(c) — Legal obligation: Where processing is required to comply with applicable laws (e.g., tax and accounting regulations)
5. Data Storage and Location
All data is stored on servers operated by Hetzner Online GmbH in Nuremberg, Germany (European Union). Hetzner is a German hosting provider subject to EU data protection laws.
Your data does not leave the European Union for storage purposes. Our databases, file storage, Redis caches, and backups are all located within the EU.
6. AI Data Processing and Third-Country Transfers
Blina Desk AI offers optional AI-powered features that rely on third-party AI providers. When you use these features, specific data (such as text you submit for analysis, summarization, or generation) may be transmitted to the following providers:
- OpenAI (San Francisco, USA) — GPT models
- Anthropic (San Francisco, USA) — Claude models
- Google (Mountain View, USA) — Gemini models
- Self-hosted Ollama (on our EU servers) — local AI models with no third-country transfer
For US-based providers, these transfers are conducted under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as appropriate. All API integrations operate in API mode, meaning your data is processed for your request only and is not used to trainthe providers' models.
You can disable AI features entirely in your account or tenant settings. When AI features are disabled, no data is sent to any third-party AI provider.
7. Third-Party Services
We use the following third-party services to operate the platform:
7.1 Stripe (Payments)
We use Stripe, Inc.(USA / EU) to process payments and manage subscriptions. Stripe processes your payment information (credit card number, billing address) directly. We do not store your full payment details — only a reference ID provided by Stripe. Stripe's privacy policy: https://stripe.com/privacy
7.2 Cloudflare (CDN and Security)
We use Cloudflare, Inc.(USA) for content delivery, DDoS protection, and DNS. Cloudflare may process your IP address and request metadata for security and performance purposes. Cloudflare's privacy policy: https://www.cloudflare.com/privacypolicy/
7.3 Hetzner Online (Hosting)
Our servers and infrastructure are hosted by Hetzner Online GmbH(Germany). All data remains within Hetzner's EU data centers. Hetzner's privacy policy: https://www.hetzner.com/legal/privacy-policy/
7.4 Google Calendar and Microsoft 365 (Calendar Sync)
Blina Desk AI offers an optional calendar integration that lets you connect your Google Calendar or Microsoft 365 account to synchronize appointments created in the platform. This integration is activated onlywhen you explicitly connect your account and grant consent on the provider's OAuth screen.
When connected, we request the minimum scopes required for appointment synchronization:
- Google —
https://www.googleapis.com/auth/calendar.events: read and write calendar events, used solely to create, update, and reflect your Blina Desk appointments in your Google Calendar. - Microsoft 365 —
Calendars.ReadWriteandoffline_access: the equivalent access for Microsoft calendars.
We store the OAuth access and refresh tokens in encrypted form on our EU servers, together with the minimum calendar event data (such as title, date, time, and participants) needed to keep your appointments in sync. This information is used only to provide the calendar-synchronization feature you requested. We do not sell it, use it for advertising, or use it to develop, improve, or train generalized AI or machine learning models. Human access to this data occurs only with your consent, for security purposes, to comply with applicable law, or as strictly necessary to operate the feature.
You can disconnect at any time under Appointments → Calendar integration in the app, or by revoking access from your Google Account permissions or Microsoft account. When you disconnect, the stored tokens are deleted.
Google API Services Limited Use disclosure.Blina Desk AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
8. Data Retention
We retain your data according to the following schedule:
- Account and business data: Retained for the duration of your active account. Upon account deletion or subscription cancellation, your data will be permanently deleted within 30 days, unless retention is required by law
- Server and access logs: Retained for 30 days, then automatically deleted
- Encrypted backups: Local backups retained for 7 days; offsite backups (Hetzner S3, EU) retained for 30 days, then automatically deleted
- Billing records: Retained as required by German tax law (up to 10 years for invoices and accounting records)
9. Your Rights Under the GDPR
As a data subject, you have the following rights under the GDPR. You can exercise any of these rights by contacting us at [email protected]:
- Right of access (Art. 15): You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data
- Right to rectification (Art. 16): You have the right to request correction of inaccurate personal data
- Right to erasure (Art. 17):You have the right to request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
- Right to restriction (Art. 18): You have the right to request restriction of processing under certain circumstances
- Right to data portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format
- Right to object (Art. 21): You have the right to object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
We will respond to your request within 30 days as required by the GDPR.
10. Cookies
Blina Desk AI uses only strictly necessary cookies for the operation of the platform:
- Session cookies: Used to maintain your authenticated session and store your language preference. These are functional cookies essential for the platform to work
We do not use tracking cookies, analytics cookies, advertising cookies, or any third-party marketing cookies. No cookie consent banner is required as we only use technically necessary cookies (per GDPR recital 30 and the ePrivacy Directive).
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS for all connections)
- Encrypted database backups stored within the EU
- Password hashing using secure algorithms (bcrypt)
- Two-factor authentication (TOTP-based OTP) available for all accounts
- Concurrent session limits and session management
- Row-Level Security (RLS) enforced at the database level to guarantee strict tenant data isolation in our multi-tenant architecture
- Antivirus scanning (ClamAV) on uploaded files
- Network-level isolation via Docker containers and firewalls
- GeoIP-based access restrictions and automated intrusion detection (fail2ban)
- SSH key-only authentication — no password access to servers
- Regular security updates via automated unattended upgrades
12. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by Art. 33 GDPR
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by Art. 34 GDPR
13. Right to Lodge a Complaint
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. The relevant authorities are:
- Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
Website: https://www.ldi.nrw.de
14. Contact for Data Protection Requests
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
Albert Milaqi — Arti-IT
Pinner Straße 11, 42579 Heiligenhaus, Germany
Email: [email protected]
We aim to respond to all data protection inquiries within 30 days.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify active users via email or an in-platform notification. The "Last updated" date at the top of this page indicates when the latest revision was made.