Privacy Policy
Last updated: May 2026
Skytte Visuals ('we', 'us', 'our') operates Blendpoint and is the data controller for personal data collected through this website and the Blendpoint application. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and applicable Danish data protection law.
1. Data We Collect
When you create an account we collect your name, email address, and a hashed (encrypted) version of your password. We never store your password in plain text. When you subscribe, our payment processor Stripe collects and stores your payment card details on our behalf. We receive only a payment confirmation and your Stripe customer ID — we do not see or store full card numbers. When you activate Blendpoint on a machine, we store a hardware fingerprint (machine ID) that identifies which computer holds your active licence. This fingerprint does not contain personal information — it is a derived identifier used solely to enforce the one-machine-at-a-time licence policy. We collect basic usage data such as licence verification timestamps to detect abuse and enforce subscription status.
2. How We Use Your Data
We use your data to: • Create and manage your account • Deliver and verify your software licence • Process subscription payments and send receipts • Send transactional emails (welcome, trial reminders, payment notifications) • Respond to support enquiries • Detect and prevent fraudulent use of licences We do not use your data for advertising, behavioural tracking, or any purpose unrelated to operating Blendpoint.
3. Legal Basis (GDPR)
We process your personal data on the following legal bases under Article 6 GDPR: • Contract performance (Article 6(1)(b)) — processing your name, email, and machine ID is necessary to provide the software licence you have agreed to. • Legitimate interests (Article 6(1)(f)) — detecting licence abuse and maintaining service security. • Legal obligation (Article 6(1)(c)) — retaining transaction records as required by Danish bookkeeping law.
4. Data Sharing
We share your data with the following third-party processors only to the extent necessary to operate the service: Stripe, Inc. — payment processing. Stripe is certified to PCI DSS Level 1 and processes payments under its own privacy policy. Stripe may transfer data to the United States under Standard Contractual Clauses. Resend, Inc. — transactional email delivery. We share your email address with Resend solely to deliver emails you have triggered (e.g. welcome email, trial reminder). We do not sell, rent, or share your personal data with any other third parties.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain records longer (e.g. payment records retained for 5 years under Danish bookkeeping legislation). Machine IDs are deleted immediately when you transfer your licence or delete your account.
6. Your Rights
Under the GDPR you have the following rights regarding your personal data: • Right of access — request a copy of the data we hold about you • Right to rectification — ask us to correct inaccurate data • Right to erasure — ask us to delete your data ("right to be forgotten") • Right to restriction — ask us to limit how we use your data • Right to data portability — receive your data in a machine-readable format • Right to object — object to processing based on legitimate interests To exercise any of these rights, contact us at Markus@skyttevisuals.com. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.
7. Cookies
We use a single session cookie to keep you logged in to your account. This cookie is strictly necessary for the service to function and does not track you across other websites. We do not use advertising cookies, analytics cookies, or any third-party tracking scripts.
8. Security
We use industry-standard security measures including TLS encryption for all data in transit, bcrypt hashing for passwords, and access controls limiting who can access the production database. Despite these measures, no system is completely secure — please use a strong, unique password for your account.
9. Children
Blendpoint is not directed at children under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the website. The date at the top of this page indicates when the policy was last updated.
11. Contact
Data controller: Skytte Visuals Markus@skyttevisuals.com For privacy-related questions or to exercise your rights, please email us and we will respond within 30 days.