Privacy Policy
Last updated: 8 October 2026 (version 1.16) · the French version is authoritative.
Privacy Policy · bloo.Cards
Last updated: 8 October 2026 · Version 1.16. The French version is the legal and original version and is authoritative (see Article 18).
At bloo.Cards, protecting your privacy is a priority. This Privacy Policy explains how we collect, use, share and protect your personal data, in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the "ePrivacy" Directive (2002/58/EC, as amended) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.
The bloo.Cards service ("the Platform", "the Service") is currently operated on the domain blcrds.com (back office and Wallet application); public cards are served on mybloo.cards. The domains bloo.cards, mybloo.cards, wallet.bloo.cards and cards.blcrds.com are part of the same ecosystem.
Contents
- Article 1. Data controller
- Article 2. Categories of data collected
- Article 3. Legal bases for processing
- Article 4. Purposes of processing
- Article 5. Data recipients
- Article 6. Processors and service providers
- Article 7. Retention periods
- Article 8. Data security and protection
- Article 9. International data transfers
- Article 10. Cookies and tracking technologies
- Article 11. Profile access and portability
- Article 12. User rights (GDPR)
- Article 13. Consent management
- Article 14. Children and minors
- Article 15. Changes to the Policy
- Article 16. Contact and exercise of rights
- Article 17. Wallet, business card scanning, loyalty and partner applications
- Article 18. Reference language and language primacy
Article 1. Data controller
The controller of your personal data is:
- MOLDEREZ-CONSULT SRL
- Company number (BCE): 0842.262.084
- Intra-community VAT number: BE 0842.262.084
- Registered office: Square Valère-Gille 13, box 5, 1050 Ixelles, Belgium
- Privacy / data protection contact: privacy@bloo.cards
- Legal contact: legal@bloo.cards
- General contact: hello@bloo.cards
As the data controller, Molderez-Consult SRL determines the purposes and means of the processing of your data. A dedicated data protection contact point is available at privacy@bloo.cards for any question relating to your personal data.
To date, Molderez-Consult SRL has not appointed a Data Protection Officer (DPO) within the meaning of Article 37 of the GDPR, as such appointment is not mandatory given the current nature and scale of our processing activities. A privacy contact point nevertheless ensures compliance monitoring and the handling of your requests.
Article 2. Categories of data collected
2.1 Overview
We collect various categories of personal data depending on your use of the Platform. Here is a detailed overview:
| Category | Type of data | Source | Mandatory? |
|---|---|---|---|
| Identification data | First name, last name, e-mail address, phone number, profile photo | Registration, user profile | E-mail: yes · Others: no |
| Authentication data | Hashed password (Argon2id), hashed opaque session token (SHA-256), one-time verification code (OTC) sent by e-mail or SMS, OAuth identifiers (Google / LinkedIn) | Registration, login | Yes |
| Company data | Company name, VAT number, postal address, country, billing details | Profile, B2B billing | No (except business billing) |
| Digital card data | Text, images (JPEG/PNG/WebP), videos (MP4/WebM), PDF, links, contact details | Card creation / editing | No |
| Audience data (card analytics) | Number of views, QR scans, NFC taps, device type, browser, referrer, city-level geolocation (no individual identification of visitors) | Consultation of public cards | No |
| Payment metadata | Dates, amounts, payment method, status, transaction identifier (via Mollie). No card number or CVV code is stored by bloo.Cards | Transactions via Mollie | Yes (if paid subscription) |
| Preference / consent data | Cookie consent choices, language (bloo-lang), theme (bloo-theme) | Browsing, user settings | Functional: yes · Analytics: no |
| Contact data (forms) | Content of requests sent via our forms | Contact forms | No |
| Wallet / Network data | Contacts saved by the user (card exchange, scanned business card, manual entry) and the identity that collected them, history of card exchanges and interactions (see Articles 5.4 and 17.1) | Wallet application / Network feature | No |
| Devices linked to the Wallet | Device name derived from the browser and operating system, dates added, last used and expiry, device token hashed with SHA-256 (see Article 17.1) | Linking a phone from the backoffice | No (only if you link a phone) |
| Business card scanning | Photo of the card (sent for reading, not kept), fields read that the user checks, technical scan log (see Article 17.2) | Scanner in the Wallet application | No |
| Loyalty data | Membership (dates of joining, first visit and last visit), stamps, points, number of visits, cumulative amount of recorded purchases, status, reward vouchers, record of operations (see Article 17.3) | Merchants' loyalty programmes (Wallet) | No |
| Partner programme applications | Programme chosen, company, contact name, e-mail, country; for an application: phone, website, expected number of clients, motivation; date and version of consent (see Article 17.4) | Forms on the partner programme page | Programme, company, name, e-mail and consent (motivation for an application): yes · Others: no |
| Technical data | IP address, User-Agent, access logs, timestamps | Servers, logs | Yes (infrastructure operation) |
2.2 Sensitive data (Article 9 GDPR)
We do not deliberately collect sensitive data within the meaning of Article 9 of the GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation).
If you choose to publish such data in the content of your card (text, images, videos), you assume full responsibility for it as the party responsible for that content, and you grant us a licence to host and display it, in accordance with our Terms of Use.
2.3 Optional data
Certain data are not necessary in order to use the Platform:
- profile photo;
- phone number;
- detailed company information (other than billing);
- card content (images, videos, PDF);
- audience data (analytics may be limited).
Refusing to provide this optional data does not affect access to the essential services.
Article 3. Legal bases for processing (Article 6 GDPR)
We process your personal data only on the basis of one of the following legal bases provided for in Article 6 of the GDPR:
| Legal basis | GDPR Article | Type of processing | Examples |
|---|---|---|---|
| Performance of the contract | 6(1)(b) | Necessary to create and administer your account and provide the Service | Identification, authentication, hosting of card data, billing, sending invoices, Wallet (linking a phone, contacts, loyalty cards), review of partner programme applications, translation of Multilingual chat messages |
| Legitimate interest | 6(1)(f) | Securing, improving and maintaining the Service | Server logs, fraud and abuse prevention, security, technical diagnostics, business card scan log (usage quota) |
| Consent | 6(1)(a) | Processing requiring your prior agreement | Cookies and audience measurement (Google Analytics 4), any commercial communications, signing up to be notified when applications to the partner programme open |
| Legal obligation | 6(1)(c) | Compliance with Belgian and EU legal obligations | Archiving of invoices (10 years from 1 January following their issue, Belgian VAT Code, Article 60), responses to legitimate requests from authorities |
Important: for each processing operation, only one legal basis applies. Where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
Article 4. Purposes of processing
Your data are processed exclusively for the following purposes:
4.1 Contractual purposes (Art. 6(1)(b) GDPR)
- Account creation and management: registration, authentication, access to the Platform;
- Mobile number: account verification and contact detail of the first card (performance of the contract);
- Provision of the Service: creation, editing, customisation and sharing of digital cards;
- Subscription management: assigning the appropriate plan and managing feature limits;
- Billing and payments: issuing invoices, processing payments via Mollie, archiving for tax compliance purposes (10 years);
- Customer support: handling requests, technical assistance, incident resolution;
- Wallet: linking your phone, displaying your identities and your sharing QR code, managing your contacts and your loyalty cards, reading the business cards you scan (see Article 17);
- Partner programme applications: reviewing and answering your application (pre-contractual measures taken at your request, see Article 17.4);
- Multilingual chat: automatic translation of messages exchanged through the Chat module, when the card holder has subscribed to the Multilingual chat option and, for the visitor, at their own request when they choose their language; only the text of the messages is sent to the translation provider, never the name, e-mail address or IP address of the participants (see Articles 6 and 7);
- Identity check for a suspicious account: if the name on an account appears fictitious, we ask you, through a personal link sent by e-mail, to give your real first and last name within 48 hours, then to confirm your e-mail address (kept or new) within 8 hours through a single-use link sent to that address; if the address changes, a notice is sent to the old address. Data processed: first and last name (before and after correction), old and new e-mail address, timestamps of the steps. Without a valid answer within the time limit, your cards are paused and your account is suspended; you receive a notice stating the reasons and may contest the decision at hello@bloo.cards. Legal basis: performance of the contract (Terms of Use, articles 9.3 and 5.4) and the legitimate interest of bloo.Cards in fighting fake accounts (see Article 4.2); retention period: see Article 7;
- Service communications: legal notices, changes to the Terms or the Policy, maintenance notices.
4.2 Purposes based on legitimate interest (Art. 6(1)(f) GDPR)
- Security and fraud prevention: detecting unauthorised access, monitoring abnormal behaviour, protecting accounts;
- Maintaining and improving the Service: technical diagnostics, bug fixing, performance optimisation;
- Handling complaints and disputes: dealing with disputes and defending our rights;
- Quota and abuse prevention: technical log of business card scans (without image or text read) and limiting submissions of the partner form (hash of the IP address);
- Web application firewall (WAF) and IP addresses of accounts: recording of the IP address and country (determined locally from the DB-IP database, without any third-party service) at sign-up and at each sign-in, and for requests refused by the firewall (IP address, country, page requested), in order to detect and block fake accounts, bots and attacks; this data is not passed on to any third party and is kept for 90 days (see Article 7);
- Fighting fake accounts: identity check for a suspicious account (see Article 4.1);
- Analysis of technical logs: detecting outages and attacks.
Balancing test: for processing based on legitimate interest, we have assessed that our interest in providing a secure, reliable and compliant Service prevails over your interests, rights and freedoms, in particular because you can object to such processing (see Article 12).
4.3 Purposes based on consent (Art. 6(1)(a) GDPR)
- Audience measurement: Google Analytics 4, activated only after your consent (opt-in);
- Partner programme: notifying you by e-mail when applications open, if you have signed up for this (see Article 17.4);
- Newsletter: sending you our news and the launch offer if you have signed up through the website's newsletter form and confirmed your address (double opt-in), with the ability to unsubscribe at any time (see Article 13.3).
4.4 Purposes based on a legal obligation (Art. 6(1)(c) GDPR)
- Tax archiving: retention of invoices and transactions for 10 years from 1 January following their issue (Belgian VAT Code, Article 60);
- Requests from authorities: responding to court decisions and legitimate law enforcement requests;
- Legal declarations: accounting and tax obligations.
4.5 Purposes explicitly excluded
We never use your data for:
- the sale of your personal data to third parties;
- discriminatory profiling (origin, religion, sexual orientation, etc.);
- fully automated decisions producing legal effects or significantly affecting you (see Article 12.7);
- non-consented sharing with external marketing partners;
- credit scoring or assessment for insurance purposes;
- mass surveillance or behavioural cataloguing.
Article 5. Data recipients
Your data may be disclosed to the following categories of recipients:
5.1 Internal recipients
- Technical team: access for support, debugging and infrastructure maintenance;
- Customer support: access to handle your requests;
- Compliance / legal: access to verify GDPR compliance and handle requests to exercise rights;
- Billing: access to invoice, payment and subscription data.
Internal access is limited to authorised persons only, on a need-to-know basis.
5.2 Public authorities and law enforcement
We may disclose your data:
- to data protection authorities, in response to investigation requests;
- to law enforcement and judicial authorities, upon a court decision, warrant or legal requisition;
- to tax authorities, as part of our accounting and tax obligations.
We only respond to such requests when we are legally required to do so and inform the user, except where the law prohibits us from doing so.
VAT numbers are sent for verification to the European Commission's VIES service (see Article 6).
5.3 Visitors to your cards
When a third party consults your public digital card:
- they only see the data you have chosen to publish (text, images, links, contact details);
- audience statistics are aggregated (number of views, general city-level location) and do not individually identify visitors;
- if a visitor saves you via the Wallet application, the exchange of contact details is based on their own initiative.
5.4 Other users (Wallet / Network feature)
The Wallet application offers a "Network" feature (lightweight CRM) allowing a user to save and organise the contact details of contacts they have met, and to export them. These contacts may come from a card exchange, a scanned business card or manual entry (see Article 17).
Allocation of roles (Articles 26 and 28 GDPR): for the third-party contact data thus saved, the card-holding user acts as the data controller: it is they who decide to save, retain and use these contact details, and who must have a legal basis for doing so (for example the voluntary exchange of a business card or the consent of the data subject). bloo.Cards acts as a processor on behalf of that user: we host and process these contacts according to their instructions and solely for the purposes of the Network feature, without using them for our own purposes.
Network search: showing links between public cards to other users (search up to the 3rd level and 3D graph) is a feature of the Platform for which bloo.Cards is the controller; it is described in Article 17.7. The contacts in your address book never appear there.
If you are a person whose contact details have been saved by a bloo.Cards user and you wish to exercise your rights, please first contact that user (the data controller). We will relay your request to them and assist within the limits of our role as processor: privacy@bloo.cards.
5.5 Merchants (loyalty programmes)
If you join a merchant's loyalty programme, the merchant only sees your first name, the initial of your last name and the data of your membership of their programme (stamps, points, visits, recorded purchases, status, reward vouchers). They see neither your e-mail address nor your phone number (see Article 17.3).
5.6 Partner resellers
If you created your account by following the sign-up link of a bloo.Cards partner reseller (address containing "?reseller=", on the sign-up page or in the Wallet), your account is attributed to that reseller when it is created. The reseller is shown before the account is created. bloo.Cards may also attribute an existing account to a reseller, or move it to another reseller, for follow-up: such a follow-up attribution gives rise to no commission. An account can only be attributed to one reseller.
- What the reseller sees: in their partner area, only your first and last name, your company name, your e-mail address, the status of your account, your plan, the number of your cards, the status and billing frequency (monthly or annual) of your subscription, the date and origin of the attribution (reseller link or bloo.Cards), the date of your first payment, the end of your first year (after which their commission moves to the rate of the following years), the total commissions generated and paid and, to calculate their commission, the date and amount excluding VAT of your paid subscription invoices that give rise to commission (during your first year and the following years). For a follow-up attribution, no commission or end of period is shown. They do not see the private content of your cards, your contacts, your statistics or your payment methods, and have no access to your management area;
- Co-branding: the reseller's logo and name may appear, together with the words "Powered by bloo.cards", on your card, in your management area and in bloo.Cards e-mails. This display does not pass any data to the reseller;
- Legal basis: bloo.Cards' legitimate interest in tracking and rewarding the customers referred by its partners, and in allowing you to be supported by them (Article 6(1)(f) GDPR); performance of the contract between bloo.Cards and the reseller (Article 6(1)(b) GDPR);
- Reseller commitments: their contract with bloo.Cards forbids them to use this data for any purpose other than the commercial follow-up of their bloo.Cards customers, to pass it on, or to keep it after the end of the partnership;
- Your right to object: you can object to this sharing at any time by writing to privacy@bloo.cards. The reseller then no longer sees your name, company and e-mail address; only the data needed to account for commissions already due is kept (see Article 7).
Article 6. Processors and service providers (Article 28 GDPR)
To provide the Service, we use the providers listed below. The processors that process data on our behalf are bound by a data processing agreement (DPA). YouTube and Vimeo, as well as OpenStreetMap Foundation (Nominatim), are not processors bound by such an agreement: they are third-party services to which certain data is sent, as recipients (as is the European Commission's VIES service, see Article 5.2):
| Processor | Function | Location | Safeguards |
|---|---|---|---|
| Falcon Internet · OVHcloud (Gravelines) | Hosting of the infrastructure and servers (including the MariaDB database, the logs and the media files: images, videos and documents) | European Union | DPA, GDPR, SCC (where applicable) |
| Mollie | Payment processing (Bancontact, cards, iDEAL, PayPal, SEPA), including appointment deposits paid by card visitors; deposits and prepayments for restaurant bookings are collected through the restaurant's own Mollie account; PCI-DSS certified | Netherlands (EU) | DPA, GDPR |
| AuthSMTP | Sending transactional e-mails (verification, invoices, notifications) | United Kingdom | EU adequacy decision + SCC, DPA |
| Google (Google Ireland / Google LLC) | Maps, Places, OAuth (SSO) and Google Analytics 4 (optional, subject to consent) | Ireland (EU) / United States | EU-US Data Privacy Framework + SCC |
| LinkedIn Corporation (Microsoft) | "Sign In with LinkedIn" (optional SSO, OpenID Connect) | United States | EU-US Data Privacy Framework |
| ModernMT | Automatic translation of card content, at the request of the card's administrator, and of Multilingual chat messages (as a fallback); data sent: texts of card content and text of chat messages (without the participants' name, e-mail address or IP address) | European Union | DPA, GDPR |
| Langbly | Automatic translation of Multilingual chat messages, when this provider is activated (otherwise: ModernMT); data sent: text of the messages only | Access point in the European Union (eu.langbly.com) | GDPR |
| Z.ai (JINGSHENG HENGXING TECHNOLOGY PTE. LTD) | Artificial intelligence reading of business cards scanned in the Wallet; the photo is not kept (see Article 17.2) | Singapore | DPA, standard contractual clauses (SCC) |
| Anthropic PBC | Back-office AI assistant: text suggestions for empty fields of the card (tagline, job title, hobby, headline, SEO title, description and keywords), only at the user's request; data sent: card name and type, first name, last name, job title, company, department and tagline from the Contact module, types of active modules, city of the first address and texts already entered in these fields; never an e-mail address, phone number or address book contact | United States | Standard contractual clauses (SCC) |
| Twilio Inc. | Sending the verification code at registration (mobile number, 6-digit code) and SMS notifications to the card holder (video call request from the card, new conversation in the card's chat when the holder has enabled SMS alerts); data sent for notifications: holder's phone number, first name or name given by the visitor and a link to reply | United States | EU-US Data Privacy Framework + SCC |
| Recommand | Sending electronic invoices via the Peppol network; data sent: invoice in UBL format (customer's name or company name, address, VAT and company numbers and e-mail address, lines and amounts) | Belgium (EU) | GDPR |
| OpenStreetMap Foundation (Nominatim service) | Geocoding of addresses and cities entered by holders in the back office; data sent: the text of the address entered, sent from our server | United Kingdom | EU-UK adequacy decision |
| YouTube (Google LLC) · Vimeo | Playback of videos embedded by holders in their cards; the video is loaded from YouTube or Vimeo only after the visitor clicks | United States | EU-US Data Privacy Framework |
The MariaDB database and the application sessions are hosted on our infrastructure at OVH (EU); these are not separate third-party services but software components operated under our control.
This list is also published, with its update date, on the Processors page.
6.1 Data processing agreements (DPA)
Our processors are bound by data processing agreements compliant with Article 28 of the GDPR, guaranteeing in particular:
- processing in accordance with our instructions only;
- the confidentiality and security of the data;
- the notification of data breaches;
- assistance with our GDPR obligations;
- the deletion or return of the data at the end of the contract.
6.2 Sub-processors (Article 28(2) and (4) GDPR)
Certain processors (in particular Mollie, Google, AuthSMTP and Z.ai) may use sub-processors. An up-to-date list is available on request at privacy@bloo.cards.
6.3 International transfers
Google (including YouTube), LinkedIn, Anthropic, Twilio and Vimeo (United States), AuthSMTP and OpenStreetMap Foundation (United Kingdom) and Z.ai (Singapore) may receive certain data. The applicable safeguard mechanisms are detailed in Article 9.
Article 7. Retention periods
Your data are kept only for as long as necessary for the purposes pursued:
| Data category | Retention period | Justification |
|---|---|---|
| Attribution of your account to a partner reseller (Article 5.6) | Lifetime of the account, or until you object | Tracking of referred customers and calculation of commissions |
| Reseller commission lines and proof of payment | 10 years after the end of the partnership | Accounting obligation (Belgian Code of Economic Law, Book III) |
| Reseller data (contact details, IBAN, contract acceptance, action log) | Duration of the partnership, then 10 years after its end for accounting records; IBAN and BIC erased once the last payment due after the end of the partnership has been made | Performance of the reseller contract; accounting obligation; evidence |
| Active account (identification, authentication) | Duration of the account + 30 days after deletion | Access to the Service; grace period for recovery |
| Digital cards | As long as the account is active; deletion after a grace period following archiving | User content; period before permanent deletion |
| Translations of Multilingual chat messages | Kept with the conversation, for the same period as the conversation | Operation of the Multilingual chat |
| Payment metadata (Mollie) | Duration of the account + 3 years | Handling of disputes and refunds (no card data is stored by bloo.Cards) |
| Invoices | 10 years from 1 January following the date of issue of the invoice | Belgian legal obligation: VAT Code, Article 60 |
| Audience data / analytics | Up to 13 months | Analysis of usage trends |
| Server logs (IP, User-Agent) | Up to 90 days | Security, debugging, attack detection |
| Log of calls to the Developers area API | 90 days; IP address and browser erased after 30 days | Rate limiting, security, follow-up of integrations by the customer company |
| Cookie consent records | Up to 6 months | ePrivacy compliance, proof of consent |
| Transactional e-mails | Up to 90 days (excluding invoices kept for 10 years) | Traceability of communications |
| GDPR rights requests | 3 years | Proof of processing, defence in the event of a dispute |
| Wallet / Network data | Duration of the user's account | Network feature (the user is the controller) |
| Devices linked to the Wallet | Device recognition limited to 90 days; device record deleted as soon as the device is revoked, and at the latest with the account | Security of access to the Wallet |
| Photo of a scanned business card | Not kept by bloo.Cards | Sent only for reading; according to its terms, Z.ai does not keep it |
| Business card scan log | Duration of the user's account | Usage quota, abuse prevention |
| Loyalty programme memberships | As long as you remain a member; deleted when you leave the programme or when your account is deleted | Operation of the programme |
| Record of loyalty operations | Kept with the merchant's programme; after a customer leaves, their operations remain in it without any link to their name | Traceability of operations, detection of any alteration |
| Partner programme applications | No more than 24 months after the last exchange | Reviewing the application and following up the relationship |
| Inactive accounts | E-mail warning after 36 months without signing in, then deletion 30 days later if you have not signed in (except with an active paid subscription) | Space management; possibility of recovery |
| Contact forms (non-customers) | 6 months | Handling of the request |
| Newsletter | Until you unsubscribe; unconfirmed sign-up deleted after 30 days; IP address and browser erased after 12 months; after unsubscribing, the address is kept on a block list so that we never write to you again | Sending the newsletter (consent, double confirmation) |
| Sign-up metadata (IP address, browser) | 12 months | Security of sign-ups, abuse prevention |
| Audit log | Entry kept; IP address pseudonymised when recorded (HMAC fingerprint, IP not readable) since 5 October 2026; browser erased after 24 months. Older entries keep the IP address: it is part of the fingerprint that guarantees the integrity of the log | Traceability of actions and security |
| Undo log for back-office actions | Previous state erased 10 minutes after the action (or as soon as it is undone); technical trace without content (type of action, date) deleted after 7 days | Allow a recent action to be undone or redone |
| One-time verification codes (OTC) sent at registration by e-mail or SMS | Valid for 10 minutes; deleted as soon as verification succeeds or a new code is sent, and at the latest about 24 hours after expiry (automatic purge) | Verification of the e-mail address or mobile number |
| Bug reports | 6 months after the report is closed; IP address and browser erased 30 days after the report is sent | Handling of the report |
| Support tickets (including messages) | Deleted 24 months after the ticket is closed (last update of the closed ticket); IP address and browser erased 30 days after the ticket is opened; a ticket that is still open is kept | Handling of the request and support follow-up |
| Events sent to a company's webhooks and CRM connectors (Developers area) | Content of the delivery (contact data) erased 30 days after the final delivery attempt (delivered, abandoned or cancelled); record of the delivery deleted 90 days after its creation | Delivery of the events requested by the company and ability to resend them |
| "Notify me when the card is online" requests | 12 months after the notice is sent (or 12 months after the request if the card never goes back online); IP address erased after 24 hours | Sending the requested notice |
| Appointments booked through a card | 24 months after the appointment date | Management of the appointment by the holder (see Article 17.6) |
| Messages and quote requests received by a holder | 24 months; permanent deletion 30 days after their deletion by the holder | Follow-up of the request by the holder (see Article 17.6) |
| Job applications submitted through a card | 6 months after the vacancy is closed | Recruitment by the holder (see Article 17.6) |
| Reports of illegal content (DSA) | 24 months | Handling of the report and proof of its follow-up |
| Expired sign-in tokens | 30 days after their expiry | Security |
| IP address and country recorded at sign-up and at each sign-in; requests refused by the firewall: IP address, country, page requested (Article 4.2) | 90 days; the sign-up country stays with the account | Security of the Platform |
| Identity check for a suspicious account: first and last name, old and new e-mail address, timestamps (Article 4.1) | 12 months after the check is closed (successful, cancelled or suspension lifted); kept while a suspension is ongoing; deleted with the account | Proof of the check and of the measure taken |
7.1 Permanent deletion
Upon expiry of the periods indicated:
- the data are irreversibly deleted from our production servers;
- backups containing this data are purged according to the backup retention cycle;
- anonymised or aggregated data (statistics without possible identification) may be kept indefinitely.
7.2 Requests for early deletion
You may request the early deletion of your data at any time (see Article 12.3). Certain data may nevertheless be retained where required by law (for example invoices, 10 years).
Article 8. Data security and protection
8.1 Technical measures
We implement appropriate technical measures to protect your data:
- Encryption in transit: all communications are encrypted via HTTPS (TLS 1.2 minimum, TLS 1.3 targeted), with forced redirection to HTTPS and an HSTS header. The TLS certificate is issued by a recognised certification authority;
- Encryption at rest: the credentials of connected CRMs are encrypted at rest (BlooCrypto, XChaCha20-Poly1305, with a key per organisation). Address book contacts (names, company, address, notes, email addresses and numbers) are encrypted at rest at the application level, with a key per account; the same mechanism covers the notes you add to an exchanged contact, the notes of your reminders and the history of your contacts in the Wallet. Existing data was encrypted when the feature was enabled, and new data is encrypted when saved;
- Password hashing: passwords are hashed with Argon2id, an algorithm resistant to brute-force and GPU attacks;
- Authentication tokens: authentication relies on opaque, random tokens, stored server-side in hashed form (SHA-256). bloo.Cards does not use JWT tokens;
- Secure sessions: PHP sessions relying on a Secure, HttpOnly, SameSite=Lax cookie, with regeneration of the session identifier after login (session fixation prevention);
- Prepared statements (PDO): all SQL queries use prepared statements (SQL injection prevention);
- Security headers: HSTS, Content-Security-Policy (CSP), X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy and Permissions-Policy; the X-Powered-By header is removed;
- Rate limiting: limiting authentication attempts in "fail-closed" mode (protection against brute force);
- Anti-CSRF tokens: per-session token and origin check (Origin / Referer) on sensitive operations;
- File validation: checking the MIME type and "magic bytes" during uploads;
- Application firewall: a proprietary application firewall (WAF) filters requests upstream of the entry points;
- Content isolation: public cards are protected against injection attacks (CSP, content escaping); media files are served directly by our servers, without any third-party content delivery network.
8.2 Organisational measures
- Limited access: data are only accessible to authorised staff, on a need-to-know basis;
- Enhanced authentication: users can enable two-step verification (one-time code sent by e-mail) and sign in with a passkey; administrator accounts of the console can be protected by app-based two-factor authentication (TOTP);
- Confidentiality: persons with access to the data are bound by a confidentiality obligation;
- Security reviews: regular internal security reviews and audits;
- Incident management: data breach notification procedure;
- Backups: regular backups of the infrastructure.
8.3 Data breach notification (Articles 33-34 GDPR)
In the event of a personal data breach (unauthorised access, loss, alteration):
- Notification to the authority: notification to the Belgian Data Protection Authority within 72 hours (Art. 33 GDPR) where the breach presents a risk;
- Notification to users: informing the users concerned as soon as possible in the event of a high risk (Art. 34 GDPR);
- Content: nature of the breach, data concerned, possible consequences, measures taken and contact points;
- Documentation: each incident is documented and retained.
8.4 Limitation
Despite rigorous security measures, no IT security is absolute. We cannot guarantee total protection against, in particular: "zero-day" vulnerabilities, advanced persistent threats, compromise on the user's side (phishing, malware), acts of malicious third parties, or cases of force majeure.
Article 9. International data transfers (Chapter V GDPR)
9.1 Identification of transfers
Certain processors are established outside the European Union, resulting in international transfers within the meaning of Chapter V of the GDPR:
- Google (United States): Maps, Places, OAuth, Analytics (optional);
- LinkedIn (United States): "Sign In with LinkedIn";
- Anthropic (United States): back-office AI assistant (text suggestions);
- Twilio (United States): SMS with the registration code, SMS notifications for video calls and chat;
- YouTube (Google) and Vimeo (United States): videos embedded in cards, loaded only after the visitor clicks;
- AuthSMTP (United Kingdom): transactional e-mails;
- OpenStreetMap Foundation (United Kingdom): geocoding of entered addresses (Nominatim);
- Z.ai (Singapore): reading business cards scanned in the Wallet (see Article 17.2).
9.2 Safeguard mechanisms
| Provider | Safeguard mechanism | Status |
|---|---|---|
| Google (including YouTube), LinkedIn, Twilio, Vimeo | EU-US Data Privacy Framework (DPF) | European Commission adequacy decision (2023) |
| AuthSMTP (United Kingdom) | EU-UK adequacy decision + standard contractual clauses (SCC) | Adequacy in force; SCC as additional safeguard |
| OpenStreetMap Foundation (United Kingdom) | EU-UK adequacy decision | Adequacy in force |
| Z.ai (Singapore) | European Commission standard contractual clauses (SCC), Art. 46(2)(c) GDPR | No adequacy decision for Singapore; the SCC are the applicable safeguard |
| Anthropic (United States) | European Commission standard contractual clauses (SCC), Art. 46(2)(c) GDPR | The SCC are the applicable safeguard |
| All non-EU providers | Standard contractual clauses (SCC), Art. 46(2)(c) GDPR | Additional safeguard |
9.3 EU-US Data Privacy Framework
Google, LinkedIn, Twilio and Vimeo adhere to the EU-US Data Privacy Framework, recognised by the European Commission's 2023 adequacy decision. This framework aims to guarantee a level of protection substantially equivalent to that of the GDPR, with avenues of redress and independent oversight.
9.4 Derogations (Article 49 GDPR)
In the absence of an applicable safeguard mechanism, certain transfers may rely on the derogations of Article 49: your explicit consent, the necessity for the performance of the contract, or the establishment/defence of legal claims.
9.5 Your rights
- request a copy of the standard contractual clauses or safeguard mechanisms (privacy@bloo.cards);
- be informed of the risks associated with international transfers;
- refuse certain non-essential transfers (for example Google audience measurement) without affecting access to the essential services.
9.6 Regulatory monitoring
We follow the recommendations of the European Data Protection Board (EDPB) relating to transfers. Should the applicable legal framework change, we will implement the additional measures necessary to ensure compliance.
Article 10. Cookies and tracking technologies
10.1 Definition and classification
Cookies are small files placed on your device; certain information is also stored in the browser's local storage (localStorage). A dedicated Cookie Policy describes these trackers in more detail.
We currently use the following categories:
| Category | Examples | Purpose | Consent | Duration |
|---|---|---|---|---|
| Essential cookies | PHP session cookie; Wallet device cookie (bloo_wdev); cookie storing your consent choice; reseller link cookie (bloo_rs_ref, session cookie deleted when the browser is closed, only set if you follow a reseller's sign-up link) | Authentication, security, keeping the phone linked to the Wallet signed in, storing consent | Not required (exempt) | Session / 90 days for the device linked to the Wallet / up to 6 months for the consent choice |
| Functional preferences (localStorage) | bloo-lang (language), bloo-theme (light/dark theme) | Remembering your display preferences | Not required (user preference) | Until erased by the user |
| Offline operation of the Wallet (localStorage) | Public information of your identities, loyalty tokens for the next 10 minutes | Displaying your already-loaded card and QR code without a network connection | Not required (necessary for the service requested) | Until you log out of the Wallet |
| Audience measurement | Google Analytics 4 (_ga, _ga_<ID>) | Understanding and improving site usage | Yes (opt-in) | Up to 13 months |
Marketing / advertising cookies: to date, bloo.Cards uses no marketing cookies, no advertising pixels (for example Meta-type), and no remarketing or targeted advertising tools. Should such trackers be introduced in the future, they would only be activated after your explicit consent and this Policy would be updated beforehand.
10.2 Consent management
A consent banner is displayed on your first visit. It lets you accept or refuse audience measurement, the only category subject to consent. Google Analytics 4 is only loaded after you accept: as long as you have not made a choice, or if you refuse, no Google Analytics script is loaded and no data is sent to Google. Your acceptance applies only to audience measurement: Google's advertising signals remain refused.
10.3 Related technologies
- localStorage / sessionStorage: storing preferences (language, theme) on the browser side and, in the Wallet, what is strictly necessary to work offline;
- Wallet service worker: copy of the application and of the files displayed, for offline use; no API response is cached;
- Google Analytics 4: audience measurement, only after consent;
- we do not use aggressive browser "fingerprinting".
10.4 Third-party cookies
When a holder embeds a Google Maps map in their bloo.Cards card, it only loads after the visitor clicks "Show the Google map"; that click constitutes consent to Google Ireland Ltd placing its own cookies. Without a click, only a frame hosted by bloo.Cards and a link to Google Maps are displayed. We invite you to consult Google's privacy policy and Google's cookie policy.
10.5 User control
- Change your preferences: via the "Manage cookies" link at the bottom of every page, which reopens the choice panel;
- Withdraw your consent: at any time, as easily as you gave it;
- Browser settings: you can block or delete cookies via your browser settings.
10.6 ePrivacy compliance (Directive 2002/58/EC)
- prior consent before placing any non-essential tracker (Art. 5(3));
- clear information and refusal as easy as acceptance;
- exemption for strictly necessary trackers;
- reasonable consent retention period (up to 6 months);
- facilitated withdrawal of consent.
Article 11. Profile access and portability (Article 20 GDPR)
11.1 Access to your profile
From your area (backoffice), you can at any time view and modify your data (identity, e-mail, language), and request a copy of your data (see 11.3).
11.2 Rectification and updating
You can rectify inaccurate or outdated data. If incorrect data affects a calculation (for example the country for VAT), we correct it and recalculate the applicable amounts where relevant.
11.3 Right to data portability (Article 20 GDPR)
You may request the portability of the data you have provided to us, in a structured, commonly used and machine-readable format (JSON, CSV, vCard), where the processing is based on the contract or consent and carried out by automated means. This may include:
- account data (e-mail, name, preferences, language);
- the content of your digital cards and their configuration;
- billing history;
- Wallet / Network data (contacts you have saved).
Formats offered: JSON (full export, recommended), CSV (tabular data), vCard (contacts), or a ZIP archive combining the files. The request is handled within the time limits provided for in Article 12(3) GDPR (see Article 16).
Article 12. User rights (Articles 15-22 GDPR)
The GDPR grants you rights over your personal data. Unless stated otherwise, these rights are exercised with privacy@bloo.cards.
12.1 Right of access (Article 15)
You can obtain confirmation that your data are being processed and receive a copy, as well as information on the purposes, recipients, retention periods and your rights. The first copy is free.
12.2 Right to rectification (Article 16)
You can have inaccurate data corrected or incomplete data completed, directly from your area or on request. Where relevant, we inform the recipients of the data of the rectification, unless this proves impossible or requires disproportionate effort.
12.3 Right to erasure / right to be forgotten (Article 17)
You may request the erasure of your data, in particular where: it is no longer necessary; you withdraw your consent; you successfully object to the processing; or the processing is unlawful.
Exceptions: the right to erasure does not apply where retention is necessary for freedom of expression and information, compliance with a legal obligation (for example invoices kept for 10 years), or the establishment, exercise or defence of legal claims.
12.4 Right to restriction (Article 18)
You may request the temporary freezing of a processing operation (without deletion), in particular during verification of the accuracy of your data or the examination of an objection.
12.5 Right to data portability (Article 20)
See Article 11.3. You may also request, where technically feasible, the direct transmission of your data to another controller.
12.6 Right to object (Article 21)
You may object, on grounds relating to your particular situation, to processing based on our legitimate interest. You may object at any time and without justification to any commercial solicitation.
12.7 Automated individual decision-making (Article 22)
You are not subject to decisions producing legal effects or significantly affecting you based solely on automated processing. Certain automated checks (for example fraud detection, feature limits according to the plan, or a payment refusal decided by the payment provider) may exist; you have the right to obtain human intervention, to express your point of view and to contest the decision.
12.8 Withdrawal of consent
Where a processing operation is based on your consent, you can withdraw it at any time, without affecting the lawfulness of the consent-based processing carried out before its withdrawal.
Article 13. Consent management
13.1 Consent (Article 7 GDPR)
For processing based on consent (audience measurement, any commercial communications), we obtain freely given, specific, informed and unambiguous consent:
- Unambiguous: through a clear affirmative act (unticked opt-in); refusal is as easy as acceptance;
- Prior: before any relevant processing;
- Informed: after information about the purpose, duration and right of withdrawal;
- Revocable: you can withdraw it at any time, without penalty.
13.2 Cookie consent (ePrivacy)
Consent to non-essential trackers is managed via the consent banner (accept / refuse). Your choice is stored (up to 6 months) and can be changed or withdrawn at any time via the "Manage cookies" link in the footer; withdrawal deletes the _ga and _ga_<ID> cookies.
13.3 Commercial communications
The bloo.Cards newsletter (our news and the launch offer) is only sent to you with your consent (Art. 6(1)(a) GDPR), obtained in two steps (double opt-in): you enter your address in the newsletter form in the footer (website and blog), then click the confirmation link you receive by e-mail. Without this confirmation, no newsletter is sent to you; the confirmation link works only once.
Data processed: e-mail address; language of the form; origin of the request (footer form); status (pending, confirmed, unsubscribed); dates of the request, of the confirmation and of the unsubscription; IP address and browser (user agent) at the time of the request, which make it possible to demonstrate your consent; confirmation token (stored only in hashed form, erased after confirmation) and unsubscribe token. To limit abuse, requests are also counted per IP address (at most 10 per hour). The e-mails are sent by our processor AuthSMTP (see Article 6).
Unsubscribing: each newsletter contains your personal unsubscribe link; one click is enough, without logging in to an account, and your subscription immediately switches to the "unsubscribed" status. You can also write to privacy@bloo.cards.
Retention period: your data is kept as long as your subscription is active, that is, until you unsubscribe. After that, your address remains recorded with the "unsubscribed" status and the date of unsubscription, so that we no longer write to you; an unconfirmed request remains "pending" and no newsletter is sent. You can ask for this data to be erased at any time (see Article 12.3).
13.4 Service communications
Communications strictly related to the operation of the Service (legal notices, changes to terms, maintenance notices, billing information) are necessary for the performance of the contract and do not constitute solicitation: they cannot therefore be refused as long as you have an account.
Article 14. Children and minors
14.1 Target audience
The Platform is aimed at an adult and professional audience. The minimum age required to create an account and take out a subscription is 18 years.
14.2 Age of digital consent
In accordance with the Belgian Act of 30 July 2018 (Art. 7), the age of consent for information society services is set at 13 years in Belgium. We do not knowingly collect data concerning children who have not reached this age without the consent of the holder of parental authority.
14.3 Deletion
If we learn that an account has been created by a minor in breach of these terms, or that a child's data has been collected without the required consent, we delete the account and the data concerned as soon as possible. You can report such a situation to us at privacy@bloo.cards.
Article 15. Changes to the Policy
15.1 Right to modify
We may amend this Policy to reflect legal or operational developments (new processors, infrastructure), or to improve its clarity.
15.2 Notification of changes
Significant changes are notified by e-mail to the address associated with your account and/or by a notification in your area, within a reasonable time before they take effect. The date of the last update and the version number appear at the top and bottom of this page.
15.3 Continued use
Continued use of the Platform after the changes take effect constitutes acknowledgement of them. If you do not accept a substantial change, you may terminate your account without penalty.
Article 16. Contact and exercise of rights
16.1 Contact details
Molderez-Consult SRL · Privacy & Data
- Address: Square Valère-Gille 13, box 5, 1050 Ixelles, Belgium
- Privacy / GDPR rights: privacy@bloo.cards
- Legal contact: legal@bloo.cards
- General contact: hello@bloo.cards
- Company number (BCE): 0842.262.084 · VAT: BE 0842.262.084
16.2 How to exercise your rights
To exercise a right (access, rectification, erasure, restriction, portability, objection), send us an e-mail at privacy@bloo.cards specifying the subject of your request. In order to protect your data, we may ask you to confirm your identity (for example via the registered e-mail address) before taking action.
16.3 Response times
We respond to your request as soon as possible and, in any event, within one month of receipt (Art. 12(3) GDPR). This period may be extended by a further two months in the event of complexity or a large number of requests; we will then inform you within the month. We strive to handle routine requests more quickly.
16.4 Requests by a third party
A legal representative or authorised agent may exercise your rights on your behalf upon presentation of proof of their authority (mandate, power of attorney or proof of the legal relationship).
16.5 Right to lodge a complaint (Article 77 GDPR)
If you consider that the processing of your data does not comply, you may lodge a complaint with the Belgian Data Protection Authority:
- Data Protection Authority (APD / GBA)
- Rue de la Presse 35, 1000 Brussels, Belgium
- Tel.: +32 (0)2 274 48 00
- E-mail: contact@apd-gba.be
- Website: www.autoriteprotectiondonnees.be
You may lodge a complaint with the APD without having contacted us beforehand. You also have the right to a judicial remedy before the competent Belgian courts.
Article 17. Wallet, business card scanning, loyalty and partner applications
This article describes the processing relating to the bloo.Cards Wallet, business card scanning, merchants' loyalty programmes, applications to the partner programme, the reseller programme and the data of people who contact a card holder. The other articles of this Policy (rights, security, contact) also apply.
17.1 bloo.Cards Wallet
The Wallet is a web application that you can install on your phone (blcrds.com/wallet). It brings together your identities (cards), your sharing QR code, your contacts, a business card scanner (see 17.2) and your loyalty cards (see 17.3).
- Linking a phone: you use your phone to scan a QR code displayed in the backoffice (single-use code, valid for 5 minutes). A 4-digit verification code then appears on the phone and in the backoffice; after checking that it is the same on both, you authorise the device from your computer;
- Remembered device: the phone then stays signed in for 90 days thanks to the bloo_wdev cookie (see Article 10 and the Cookie Policy). The device token is kept on our servers only in hashed form (SHA-256). The list of your devices (name derived from the browser and operating system, date added, last use, expiry) is visible in the backoffice, where you can revoke any device at any time; logging out of the Wallet has the same effect;
- Contacts: the contacts you save (card exchange, scanned business card, manual entry) are kept in your account and linked to the identity (card) that collected them. The allocation of roles described in Article 5.4 applies to these contacts;
- Card exchanges: when you save the card of another bloo.Cards user, the exchange is recorded for both accounts: who shared, who received, with which identity, on which date and through which channel (QR code, NFC, link, etc.). The holder of the saved card can thus see the name, company, job title and photo of the identity with which you saved their card. You can delete a contact or hide an exchange from your list at any time;
- Storage on the phone: to work offline, the Wallet keeps only what is strictly necessary in your phone's browser: the public information of your identities and your loyalty tokens, which are valid for 10 minutes. These data are erased when you log out. No API response is cached by the service worker.
17.2 Business card scanning (artificial intelligence reading)
- How it works: in the Wallet, you take a photo of a business card. The photo, from which the metadata (including the GPS location) are removed, is sent encrypted (HTTPS) to the API of Z.ai (GLM-4.6V vision models), which extracts the printed fields: name, job title, company, e-mail addresses, phone numbers, address, website and VAT number. The fields read are shown to you: you check and correct them before saving the contact. Nothing is added to your contacts without your confirmation, and you can always enter a contact manually;
- Retention: bloo.Cards does not keep the photo. Only a technical log, linked to your account, is recorded in order to apply the usage quota and prevent abuse: hash (SHA-256) of the image, date, duration of the analysis, model used, technical result (for example successful, unreadable or failed) and, if you save the contact, the link to that record. This log contains neither the image nor the text read;
- Data subject and legal basis: the person whose card is scanned is a third party. Only the professional contact details printed on the card are extracted. The legal basis is the user's legitimate interest in saving the contact details handed to them (Article 6(1)(f) GDPR); for these contact details, the user is the controller (see Article 5.4). The automated reading produces no decision concerning anyone;
- Processor and transfer outside the European Union: Z.ai is operated by JINGSHENG HENGXING TECHNOLOGY PTE. LTD, a company established in Singapore, which states that it generally processes data in Singapore. According to Z.ai's terms applicable to its API, the content sent is processed in real time, is not stored on its servers and is not used to develop or improve its services without the explicit agreement of the customer (bloo.Cards). As Singapore does not benefit from an adequacy decision of the European Commission, this transfer is governed by standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR; see Article 9).
17.3 Merchants' loyalty programmes
A merchant who holds a bloo.Cards card can activate the Loyalty module and set its rules: stamps, points per euro, Silver, Gold and Platinum status based on purchases over the last 12 months, welcome bonus and reward vouchers.
- Joining: you join from your Wallet ("Join with my Wallet" link on the merchant's card) or automatically on your first visit to the checkout, when the merchant scans the loyalty QR code displayed in your Wallet. This QR code changes every 30 seconds and contains only an internal identifier, a time marker and a signature: no name, e-mail or phone number;
- Data processed for each programme: dates of joining, first visit and last visit; stamps, points and number of visits; cumulative amount of recorded purchases; status; reward vouchers (code, status, dates); record of operations (date, amount, changes in stamps and points, author of the operation, note), chained by hashes in order to detect any alteration;
- What the merchant sees: only your first name, the initial of your last name and the data of their own programme; neither your e-mail address nor your phone number. They can export their programme's data in CSV format;
- Your choices: your loyalty cards appear in your Wallet. You can leave a programme at any time: your membership is then deleted and your unused vouchers are cancelled; past operations remain in the merchant's record, without any link to your name;
- Roles: for the data of their programme, the merchant acts as controller and bloo.Cards as processor on their behalf; for your Wallet account, bloo.Cards is the controller. To exercise your rights over a programme's data, contact the merchant or write to us at privacy@bloo.cards: we will pass on your request.
17.4 Partner programme applications
The partner programme page (bloo.cards/www/resellers) offers a "Be notified when applications open" form until applications open on Tuesday 13 October 2026, and then an application form.
- Data collected: programme chosen (Reseller "Powered by bloo.cards" or White label), company name, contact name, e-mail address and, if you wish, country. For an application, also your motivation (free text) and, if you wish, phone, website and expected number of clients. We also record the language of the form, a file reference, and the date of your agreement and the version of the text displayed;
- IP address: it is not stored in plain text with your request; only a salted hash (SHA-256, with a salt renewed every month) is kept, in order to limit submissions to 5 per hour;
- Purposes and recipients: notifying you when applications open, reviewing your application and contacting you. An e-mail is sent to our team (hello@bloo.cards) and you receive an acknowledgement of receipt;
- Legal basis: for the "Be notified when applications open" sign-up, your consent (Article 6(1)(a) GDPR), given by ticking the box in the form; for an application, pre-contractual measures taken at your request (Article 6(1)(b) GDPR), your agreement also being recorded. You can withdraw your consent or your application at any time by writing to privacy@bloo.cards;
- Retention period: no more than 24 months after the last exchange with you.
17.5 Reseller programme (reseller data)
When you become a partner reseller, your existing bloo.Cards account gives you access to the portal bloo.cards/resellers.
- Data processed: company name, contact name, billing e-mail address, VAT number where applicable, IBAN and BIC, co-branding logo and colours, code of your sign-up link and number of visits to that link, attributed customers, commission lines and payouts, date, version and IP address of your acceptance of the reseller contract, log of actions taken on the portal and by our team;
- Security: the IBAN is never written to logs; signing in to the portal uses your bloo.Cards password and, if you have enabled it, two-step verification;
- Purposes and legal bases: performance of the reseller contract (Article 6(1)(b) GDPR), accounting and tax obligations (Article 6(1)(c) GDPR) and proof of acceptance of the contract (Article 6(1)(f) GDPR);
- Retention period: duration of the partnership, then 10 years for accounting records (see Article 7).
17.6 People who contact a card holder
This section is addressed to visitors of a bloo.Cards card who use one of its forms or services to contact the holder of the card.
- Data concerned: the data you enter in the card's forms (message, review, quote request, appointment booking, callback or video call request, reservation, waiting list registration, chat conversation, application) and the contact details you provide;
- Controller: the holder of the card, who decides to offer these forms and to use your data. bloo.Cards acts as a processor: we host and process this data on the holder's behalf, according to the holder's instructions, under the data processing agreement annexed to the Terms of Use;
- Providers: deposits are paid via Mollie; SMS notifications are sent to the holder via Twilio (see Article 6);
- Retention periods: messages and quote requests: 24 months, and permanent deletion 30 days after their deletion by the holder; appointments: 24 months after the appointment date; job applications: 6 months after the vacancy is closed; "notify me when the card is online" requests: 12 months after the notice is sent; invitation and meeting requests made at an event (Events module): 24 months after the request (see Article 7);
- Your rights: contact the holder of the card first. You can also write to privacy@bloo.cards: we will pass your request on to the holder;
- Local storage in the browser: the information the card stores in your browser is described in the cookie policy.
17.7 Network search and card occupations
The Wallet and the back office let you search for a person, an occupation or a company among the bloo.Cards linked to your contacts, up to the 3rd level (your contacts, your contacts' contacts, then their contacts), and expand these links in the 3D graph. For this feature of the Platform, bloo.Cards acts as data controller.
- What is shown: only public, indexed bloo.Cards (option « Index this card »), online, without a password, whose holder has not chosen « Do not appear in network search »: name, photo, main occupation, job title, company and link to the public card, with the level and the path (« via … »). Never an email address, phone number or postal address; never the contacts in your address book (scanned cards, entries, imports, forms), which remain visible to you alone; never the information that two cards belong to the same person;
- Visibility of your links: each link between one of your cards and another card is, as you choose, « Private », « My direct contacts » (default setting) or « My whole network (3 levels) ». You set it globally or link by link (back office: Network › Privacy; Wallet: « Network privacy »). A card is shown to a third party only if every link of the path allows it;
- Sensitive occupations: links to a card whose occupation relates to health, justice, religion, politics or a trade union (list based on the international ISCO-08 classification), and to a card whose occupation was entered outside the classification, stay private by default; you may share them link by link, with your direct contacts at most;
- Existing accounts: for accounts created before this feature went live, links stay private until 30 days after the information email we send you; they then switch to « My direct contacts », unless you have chosen another setting;
- Card occupations: you may state up to 3 occupations, chosen from the European ESCO classification (European Commission) or entered freely; the first is shown on your card and published in its structured data for search engines. This is information you publish yourself on your card;
- Legal bases: performance of the contract (Article 6(1)(b) GDPR) for the user who searches and shares links; legitimate interest (Article 6(1)(f) GDPR) for the holder of a public card shown in this way, who may object at any time with the « Do not appear in network search » setting; your explicit consent (Article 9(2)(a) GDPR) for a link to a sensitive occupation that you choose to share;
- Protection: search reserved to logged-in users, at least 3 characters, at most 20 results, limited number of searches; no number of hidden results is disclosed. A data protection impact assessment (Article 35 GDPR) has been carried out;
- Retention: your settings are kept as long as your account exists; the searched text is not stored (only an anti-abuse counter, without content, is kept for at most one hour).
Article 18. Reference language and language primacy
The French version is the legal and original version; the Dutch, German and English versions are courtesy translations; in the event of any discrepancy, the French version prevails.
This Privacy Policy (Version 1.16) takes effect as of 8 October 2026. We invite you to consult this page regularly to keep informed of any updates.
Version 1.9 of 5 October 2026: encryption at rest enabled (Article 8.1).
Version 1.10 of 5 October 2026: retention periods specified (Articles 7 and 17.6; retention period of invoices also corrected in Articles 3, 4 and 12).
Version 1.11 of 5 October 2026: undo log for back-office actions (Article 7).
Version 1.12 of 5 October 2026: network search up to the 3rd level, link visibility and card occupations (Articles 5.4 and 17.7).
Version 1.13 of 6 October 2026: firewall (WAF) and IP addresses of accounts, identity check for a suspicious account, follow-up attribution to a reseller and data visible to the reseller (Articles 4.1, 4.2, 5.6 and 7).
Version 1.14 of 7 October 2026: verification of registration by SMS (Twilio): data and purposes (Articles 2 and 4.1), processor and transfer (Articles 6 and 9.1), retention of verification codes (Article 7).
Version 1.15 of 8 October 2026: invoices kept for ten (10) years from 1 January following their issue, in accordance with the Belgian VAT Code, Article 60 (Articles 3, 4 and 7); data visible to the reseller with the recurring commission (Article 5.6); purpose of the Wallet's offline storage clarified (Article 10).
Version 1.16 of 8 October 2026: content delivery network (CDN) removed from the processors; media files are served directly by the hosting provider (Articles 6 and 8.1).