Legal
Data Processing Information
Last updated 4 September 2026
This page summarises how Blueprint to Brilliance approaches data processing and the technology suppliers used by the platform. It is intended to support transparency and does not replace a client-specific data processing agreement where one is required.
1. Our roles
Blueprint to Brilliance is generally the controller for information used to operate our own website, sales, bookings, client administration and business records. Where a client instructs us to process personal information solely on its behalf as part of an agreed service, we may act as a processor and the client may act as controller.
Where we act as processor, the parties should put appropriate written data processing terms in place covering the subject matter and duration of processing, nature and purpose, types of personal data, categories of data subjects, documented instructions, confidentiality, security, sub-processors, assistance obligations, deletion or return, and audit/information rights as required by applicable law.
2. Current technology suppliers
The platform uses Supabase for database and authentication functionality, Railway for production hosting, and Stripe for secure payment processing. Stripe handles payment-card details directly; those card details are not stored in the Blueprint to Brilliance application.
3. Sub-processors and suppliers
We use suppliers only where they are reasonably necessary to operate the platform or deliver contracted services. Before material production use, we assess the supplier's role, security, contractual terms and relevant data-location or international-transfer considerations. A current list of material sub-processors can be provided to clients where required by contract.
4. Security measures
Our platform uses authenticated access, role-based permissions, encrypted network connections and Supabase row-level security policies designed to restrict access to protected records. We also use validation and rate-limiting controls for public forms and maintain administrative access controls for staff functions.
Security is reviewed as the service develops. Clients remain responsible for access they grant to their own authorised users and for notifying us promptly when user access should be changed or removed.
5. International processing
Technology providers may operate infrastructure in more than one country. Where personal information subject to UK transfer restrictions is transferred internationally, we will use an applicable adequacy arrangement, approved contractual safeguard or other lawful mechanism where required.
6. Retention and deletion
Controller records are retained in accordance with our Privacy Policy and legal or contractual requirements. Where we act as a processor, retention, deletion or return will follow the client's documented instructions and the applicable service or data processing agreement, subject to information we are legally required to retain.
7. Incidents and assistance
We maintain procedures intended to identify and respond to relevant security incidents. Where we act as processor and become aware of a personal data breach affecting client-controlled data, we will notify the relevant client without undue delay in accordance with the applicable agreement and law, and provide reasonable information available to us to support the client's response obligations.
8. Questions and client DPAs
Clients that require a data processing agreement, sub-processor information, security questionnaire response or other privacy documentation should contact us using the details on our Contact page before production processing begins.
Contact Blueprint to Brilliance
Questions or rights requests may be sent to hello@blueprinttobrilliance.co.uk.
Telephone: +44 7496 865603.
These website legal pages are intended to provide clear operational terms and privacy information for the current Blueprint to Brilliance service. They should be reviewed whenever the business structure, payment provider, hosting, analytics, marketing technology, client platform or processing activities materially change. For bespoke regulated, high-risk or cross-border services, obtain appropriate professional legal advice.
