{"id":"security-compliance","title":"Security and compliance","description":"Legal entity, GDPR, data processing, hosting and sub-processors, privacy controls in the product, and what to request during procurement.","language":"en","lastUpdated":"2026-09-11","urls":{"html":"https://bluepic.io/ai-info#security-compliance","markdown":"https://bluepic.io/ai-info/security-compliance.md","json":"https://bluepic.io/ai-info/security-compliance.json"},"markdown":"## Legal entity\n\nBluepic is operated by **FellowBlue GmbH**, Im Mediapark 5, 50670 Cologne, Germany (Amtsgericht Köln, HRB 116136; VAT ID DE364437752). The company is subject to the EU General Data Protection Regulation (GDPR) and German data protection law.\n\n## GDPR and end users\n\n- End users of a design generator need **no account, no app, and no tracking cookies**. They open a link or an embedded widget, fill in the form, and download or share the result.\n- Only the optional LinkedIn integration (profile pre-fill and direct posting) asks the end user to connect their LinkedIn account.\n- The marketing website bluepic.io sets no analytics or marketing cookies that require consent (only technically necessary cookies such as language and cookie settings): usage measurement is pseudonymous and cookieless; fonts are self-hosted with no requests to third-party font services.\n\n## Hosting and sub-processors\n\n- **Infrastructure and content delivery:** Cloudflare, Inc. (USA). End-user uploads (deleted after 24 hours), rendered outputs, and account assets are stored with EU jurisdiction pinning; templates, fonts, and backups without regional pinning.\n- **Server-side rendering fallback:** Hetzner Online GmbH, Falkenstein, Germany.\n- **Authentication and account management:** Auth0 (Okta, Inc.), EU region.\n- **Payments and invoicing:** Stripe (Stripe Payments Europe Ltd., Ireland; Stripe, Inc., USA).\n- **Product and website analytics:** PostHog Inc., EU infrastructure (Germany), pseudonymous.\n- **Support widget:** Help Scout Inc. (USA); on the website loaded only after clicking the help button.\n- **Email delivery:** Brevo GmbH, Berlin (transactional email for free tools, newsletters).\n- A data processing agreement is in place with each sub-processor; US transfers rely on the EU-US Data Privacy Framework.\n\nThe authoritative list with legal bases and transfer safeguards is the privacy policy at `https://bluepic.io/privacy`.\n\n## Privacy controls and access control inside the product\n\n- Organisations with team members and role management; team campaigns can be restricted to team members and/or a password.\n- API keys are account-level and can be created and revoked at any time. The key remains readable in the Studio for the account that owns it, so it should be handled like a password.\n- Trackable links in LinkedIn posts can be switched off per campaign.\n- Face-detection auto-crop for image fields runs entirely in the end user's browser; no image data leaves the device for it.\n- Background removal is opt-in per image field. When enabled, the uploaded image is processed server-side by Cloudflare Images (Cloudflare, Inc., USA) as processor, without EU pinning, and deleted after 24 hours at the latest.\n- Custom domains (Enterprise) let generators run under the customer's own domain."}