Blendpoint

Privacy Policy

Last updated: September 2026

Skytte Visuals ('we', 'us', 'our') operates Blendpoint and is the data controller for personal data collected through this website and the Blendpoint application. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Danish data protection law.

1. Data We Collect

Your photographs never leave your computer. Blendpoint converts and merges your RAW files entirely on your own Mac. We do not upload, receive, store or have any access to your images, your converted files, or their file names. Everything described below concerns your account and your licence — never your photographs. When you create an account we collect your name, email address, and a hashed (encrypted) version of your password. We never store your password in plain text. When you subscribe, our payment processor Stripe collects and stores your payment card details on our behalf. We receive only a payment confirmation and your Stripe customer ID — we do not see or store full card numbers. When you activate Blendpoint on a machine, we store a hardware fingerprint (machine ID) that identifies which computer holds your active licence. It says nothing about you personally and nothing about the contents of your computer, but because it is tied to your account we treat it as personal data and describe it here accordingly. It is used solely to enforce the one-machine-at-a-time licence policy. We collect basic usage data such as licence verification timestamps to detect abuse and enforce subscription status. We process your IP address when you register, log in, request a password reset, or ask for a new verification email. It is used to rate-limit those requests against automated abuse and is held in memory for at most one hour. When you sign in — on this website or in the Blendpoint app — and when the app activates or checks your licence, we also record where that sign-in came from: the country and city your IP address resolves to, the date and time, and a one-way hash of the IP address. We do not store the IP address itself. The hash is computed with a secret key held only on our server, so it cannot be turned back into an address; it exists solely so that two sign-ins from the same connection can be recognised as coming from the same connection. The country and city are resolved on our own server from a local MaxMind GeoLite2 database — your IP address is never sent to a geolocation service or any other third party. Where the request carries a machine ID, the record also holds the same one-way machine hash described above. We use these records for one purpose only: to detect a single licence key being used by several people, which our terms do not allow. We retain them as described in section 5. Separately, our web server keeps standard access logs (IP address, timestamp, requested page, browser user-agent) for up to 52 days for security and troubleshooting.

2. How We Use Your Data

We use your data to: • Create and manage your account • Deliver and verify your software licence • Process subscription payments and send receipts • Send transactional emails (welcome, trial reminders, payment notifications) • Respond to support enquiries • Detect and prevent fraudulent use of licences We do not use your data for advertising, behavioural tracking, or any purpose unrelated to operating Blendpoint.

3. Legal Basis (GDPR)

We process your personal data on the following legal bases under Article 6 GDPR: • Contract performance (Article 6(1)(b)) — processing your name, email, and machine ID is necessary to provide the software licence you have agreed to. • Legitimate interests (Article 6(1)(f)) — detecting licence abuse and maintaining service security, including the sign-in records described in section 1. • Legal obligation (Article 6(1)(c)) — retaining transaction records as required by Danish bookkeeping law.

4. Data Sharing

We share your data with the following third-party processors only to the extent necessary to operate the service: Stripe, Inc. — payment processing. Stripe is certified to PCI DSS Level 1 and processes payments under its own privacy policy. Stripe may transfer data to the United States under Standard Contractual Clauses. Resend, Inc. — transactional email delivery. We share your email address with Resend solely to deliver emails you have triggered (e.g. welcome email, trial reminder). Webdock.io ApS — server hosting. Our application and database run on a virtual server operated by Webdock.io ApS in Denmark. Your account data is stored within the EU. We do not sell, rent, or share your personal data with any other third parties.

5. Data Retention

We retain your account data for as long as your account is active. You can delete your account yourself at any time from your account page. Doing so immediately removes your name, email address, password hash, licence key, and machine ID, and cancels any active subscription so it is never billed again. You can also ask us to delete your account by email, and we will do so within 30 days. Where the law requires it, some records are kept longer. If you have ever made a payment, your customer record at our payment processor — which holds your name, email address and billing address — and the invoices attached to it are retained for at least 5 years, as Danish bookkeeping legislation requires. Deleting your account cancels any subscription immediately but does not delete those payment records, and they are not deleted automatically once the 5 years have passed. They are never used to contact you or to re-create your account. If you have never made a payment, no such record exists and nothing is kept. When you transfer your licence to another computer, we stop storing the previous machine ID. We do keep a one-way hash of it together with the date of the transfer, so that a licence key being passed around between several people shows up as a pattern we can act on. Those transfer records are automatically deleted after 180 days, cannot be turned back into a machine ID, and contain nothing else about your computer. The sign-in records described in section 1 — country, city, date and time, and the one-way hashes — are deleted automatically after 180 days as well. Deleting your account removes all of it at once — your current machine ID, the transfer history, the sign-in records, and the hashes — along with the rest of your account data. We take a backup of our database every night and keep each one for 14 days. When you delete your account your data is removed from the live database immediately, but it may still exist in those backups until the last backup taken before your deletion expires — at most 14 days. Backups are used only to restore the service after a failure; they are never searched, and are never used to look up or re-create an account.

6. Your Rights

Under the GDPR you have the following rights regarding your personal data: • Right of access — request a copy of the data we hold about you • Right to rectification — ask us to correct inaccurate data • Right to erasure — ask us to delete your data ("right to be forgotten") • Right to restriction — ask us to limit how we use your data • Right to data portability — receive your data in a machine-readable format • Right to object — object to processing based on legitimate interests To exercise any of these rights, contact us at Markus@skyttevisuals.com. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.

7. Cookies

We use a small number of strictly necessary cookies and browser storage entries. None of them track you across other websites. We use no advertising cookies, no analytics cookies, and no third-party tracking scripts of any kind. Cookies: • __Secure-next-auth.session-token — keeps you signed in. Set only once you log in, and removed when you log out. • __Host-next-auth.csrf-token — protects the login and account forms against cross-site request forgery. • __Secure-next-auth.callback-url — remembers which page to return you to after signing in. • NEXT_LOCALE — remembers whether you are reading the English or Danish version of the site. Browser storage (localStorage): • bp_cookies_accepted — records that you have dismissed the cookie notice so it is not shown again. • nextauth.message — keeps multiple open tabs in sync when you sign in or out. • admin-tab and admin-collapse:… — remember which section of the admin dashboard was last open. These are only ever set for an administrator account, never for a normal visitor. All of these are either strictly necessary to deliver a service you have requested, or record a preference you have expressed. Under the ePrivacy rules they therefore do not require your consent — the notice we show is for transparency, not to collect consent.

8. Security

We use industry-standard security measures including TLS encryption for all data in transit, bcrypt hashing for passwords, and access controls limiting who can access the production database. Despite these measures, no system is completely secure — please use a strong, unique password for your account.

9. Children

Blendpoint is not directed at children under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the website. The date at the top of this page indicates when the policy was last updated.

11. Contact

Data controller: Skytte Visuals CVR no. 41069120 Promenadebyen 36, 2. 3. 5000 Odense C Denmark Markus@skyttevisuals.com For privacy-related questions or to exercise your rights, please email us and we will respond within 30 days.