BLASFAME

privacy · 1 Oct 2026

Privacy

Effective 1 October 2026.

This policy explains what personal data Blasfame collects, why we hold it, who we share it with and how long we keep it. It applies to visitors to blasfame.com, to people who contact us, and to our clients.

Back to the rate card

Who we are

  1. 01

    Blasfame is a marketing business registered in Denmark. We are the data controller for the personal data described in this policy.

  2. 02

    You can contact us about anything in this policy at hello@blasfame.com.

  3. 03

    We are not required to appoint a data protection officer. Privacy questions are handled by the owner of the business.

What we collect

  1. 04

    Contact details. Your name, business name, email address, and phone number if you give us one.

  2. 05

    Billing details. Your billing address, VAT number where you have one, and a record of what you bought and when. We do not receive or store your full card number.

  3. 06

    Correspondence. The emails you send us and our replies, including anything you attach.

  4. 07

    Material you send us for a job. Pages, prices, plans, figures, brand material, and occasionally a mailing list or a file containing customer records.

  5. 08

    Access to your accounts. Where a job requires it, an invitation to your advertising account, analytics property, tag manager, website editor, business profile or email tool.

  6. 09

    Technical data. Our host, Vercel, records standard server logs when a page is requested, including IP address, timestamp, the page requested, browser user agent and response code. These are used to serve the site and protect it from abuse, and we do not use them to identify individual visitors.

How we use it, and our lawful basis

  1. 10

    To answer your enquiry and quote for work. Our basis is taking steps at your request before entering a contract.

  2. 11

    To deliver the job you bought, and to support it afterwards. Our basis is performance of our contract with you.

  3. 12

    To take payment and issue invoices. Our basis is performance of our contract, and compliance with a legal obligation for the accounting record itself.

  4. 13

    To keep our website available, secure and functioning. Our basis is our legitimate interest in operating the site.

  5. 14

    To meet our legal and tax obligations. Our basis is compliance with a legal obligation.

  6. 15

    We do not use your data for marketing to you, we do not build advertising profiles, and we do not sell personal data.

Cookies and local storage

  1. 16

    We do not use advertising cookies, analytics cookies or tracking pixels, and we do not operate a consent banner because we do not set cookies that require consent.

  2. 17

    Your light or dark display preference is saved in your browser's local storage so the site renders the way you chose on your next visit. It stays on your device and is not transmitted to us.

  3. 18

    You can clear it at any time by clearing site data for blasfame.com in your browser.

Analytics

  1. 19

    We do not run analytics software, session recording, heat mapping or visitor fingerprinting on our website.

  2. 20

    Where a job involves analytics on your own property, that data belongs to you, sits in your own account, and is governed by your agreement with that provider.

Payments

  1. 21

    Payments are processed by Stripe Payments Europe, Ltd. Your card details are entered directly with Stripe and are handled under their PCI DSS certification.

  2. 22

    We receive confirmation that a payment succeeded, the amount, the date, the last four digits of the card and the billing details needed to issue your invoice. We never receive your full card number, expiry date or security code.

  3. 23

    Stripe acts as an independent controller for fraud prevention and for meeting its own regulatory obligations, and applies its own privacy policy to that processing. You can read it at stripe.com/privacy.

  4. 24

    Invoices are issued and stored in e-conomic, our accounting system, supplied by Visma e-conomic A/S in Denmark.

Working inside your accounts

  1. 25

    Most jobs are carried out inside your own systems rather than by copying your data into ours. We are added as a user on the account and removed when the job is delivered.

  2. 26

    Where a job involves personal data belonging to your customers, you are the controller of that data and we act as your processor. We process it only on your documented instructions.

  3. 27

    We will enter into a written data processing agreement on request, and we will not engage a new sub-processor for your data without telling you.

  4. 28

    Please send us only the data a job actually needs. If you send us more than that, we will tell you and delete the excess.

The providers we use

  1. 29

    Vercel Inc., United States. Hosts blasfame.com and records the server logs described above.

  2. 30

    Google Ireland Limited, Ireland. Google Workspace provides our email, calendar and file storage, so your correspondence and any files you send us are held there.

  3. 31

    Stripe Payments Europe, Ltd., Ireland. Processes card payments and holds the payment record.

  4. 32

    Visma e-conomic A/S, Denmark. Our accounting system, holding invoices and billing details.

  5. 33

    AgileBits Inc., Canada. 1Password stores the credentials we use to reach the accounts we are invited into.

  6. 34

    Each of these is bound by a data processing agreement and may use the data only to provide its service to us. We will tell you before we add a new provider that handles client data.

  7. 35

    We also share data with the advertising, analytics and email platforms used for your job. Those are your own accounts under your own agreement with those platforms, and we act inside them as an invited user.

  8. 36

    We will disclose data to a professional adviser or a public authority where we are legally required to. We do not share personal data with anyone else and we do not disclose it for anyone else's marketing.

International transfers

  1. 37

    Google Ireland, Stripe Ireland and Visma e-conomic process data inside the European Economic Area.

  2. 38

    Vercel is based in the United States. That transfer is covered by the European Commission's standard contractual clauses together with Vercel's certification under the EU to US Data Privacy Framework.

  3. 39

    1Password is based in Canada, which the European Commission has recognised as providing an adequate level of protection for data handled by commercial organisations.

  4. 40

    Where a Google or Stripe service routes data to the United States, the same standard contractual clauses and Data Privacy Framework certifications apply.

  5. 41

    You can ask us which safeguard applies to a particular provider and we will tell you.

How long we keep it

  1. 42

    Enquiries that do not lead to work: twelve months from the last message.

  2. 43

    Client correspondence and delivered work: three years after the final job, so we can answer questions about what we produced for you.

  3. 44

    Invoices and accounting records: five years from the end of the financial year, as required by Danish bookkeeping law.

  4. 45

    Access to your accounts: removed on delivery of the job, or sooner if you ask.

  5. 46

    Mailing lists and customer files sent to us for a job: deleted once the job is delivered, unless another job already booked requires them.

  6. 47

    Server logs: retained on Vercel's standard retention schedule, which is measured in days rather than months.

How we protect it

  1. 48

    Access to client material is limited to the person carrying out the job.

  2. 49

    Credentials are stored in 1Password, never in a document or a spreadsheet, and every account we hold uses a unique password with two factor authentication enabled wherever the platform supports it.

  3. 50

    Traffic to blasfame.com is encrypted in transit over TLS, and the data our providers hold is encrypted at rest.

  4. 51

    We request the lowest level of access that will do the job, and we ask to be removed once it is delivered. We do not ask for your password, and you should not send us one.

  5. 52

    If a breach occurs that is likely to present a risk to people's rights, we will notify the Danish data protection authority within 72 hours and tell affected clients without undue delay.

Automated decisions

  1. 53

    We do not carry out automated decision making or profiling that produces legal effects or similarly significant effects for anyone.

Your rights

  1. 54

    Under the General Data Protection Regulation you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict how we process it, to receive it in a portable format, and to object to processing carried out on the basis of legitimate interests.

  2. 55

    To exercise any of these rights, email hello@blasfame.com setting out what you would like us to do. There is no charge.

  3. 56

    We respond within one month. If a request is complex we will tell you before that month is up and may take up to two further months.

  4. 57

    We may ask you to verify your identity where we cannot otherwise confirm it.

  5. 58

    Some records cannot be erased on request, most commonly an invoice we are required by law to retain. Where that applies we will tell you which record it is and which obligation requires it.

  6. 59

    Where we act as a processor for one of our clients, send your request to that business and we will assist them in responding.

Children

  1. 60

    Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16.

Complaints

  1. 61

    If you are unhappy with how we have handled your personal data, contact us first at hello@blasfame.com and we will try to resolve it.

  2. 62

    You also have the right to lodge a complaint with the Danish data protection authority, Datatilsynet, at datatilsynet.dk, or with the supervisory authority in the country where you live or work.

Changes to this policy

  1. 63

    We review this policy when our processing changes and at least once a year.

  2. 64

    When we update it we publish the revised version here with a new effective date. Where a change materially affects our clients, we tell them directly.

  3. 65

    This version is effective 1 October 2026.

Back to the rate card