Skip to content
Blueprint to Brilliance Consultancy

Legal

Privacy Policy

Last updated 4 September 2026

This Privacy Policy explains how Blueprint to Brilliance ("we", "us" or "our") collects, uses, shares and protects personal information when you use our website, contact us, book a call, enquire about services, become a client, or use an account or service we provide.

1. Who we are

Blueprint to Brilliance provides business growth, consultancy, audit, systems and AI automation services. For personal information we collect for our own business purposes, Blueprint to Brilliance acts as the data controller. You can contact us using the details on our Contact page.

Where we process personal information solely on a client's documented instructions as part of a contracted service, the client may be the controller and Blueprint to Brilliance may act as a processor. Any service-specific data processing terms will apply in addition to this Privacy Policy.

2. Information we may collect

We may collect your name, business or organisation name, job title, email address, telephone number, enquiry details, booking preferences, service interests and any information you choose to provide in forms, calls, emails or other communications.

If you become a client or authorised team user, we may also process account details, authentication records, service records, project information, support communications, transaction and billing records, and records needed to deliver and administer our services.

We may also receive limited technical information needed to operate and secure the website and account services, such as IP address, device/browser information, timestamps, authentication events and security logs.

3. How and why we use personal information

We use personal information to respond to enquiries; arrange and manage calls; prepare proposals; provide audits, consultancy, implementation and automation services; manage client relationships; operate secure accounts; administer payments and records; provide support; prevent fraud and misuse; maintain security; comply with legal obligations; and improve our services.

Depending on the activity, our lawful bases under UK data protection law may include taking steps at your request before entering into a contract, performing a contract, complying with a legal obligation, our legitimate interests in running and protecting our business and serving business customers, and consent where the law requires it.

Where we rely on legitimate interests, we consider the impact on individuals and use that basis only where our interests are not overridden by your rights and freedoms.

4. Marketing communications

We may send relevant business-to-business communications where permitted by law. Where consent or another specific legal condition is required for electronic marketing, we will use it. You can opt out of marketing at any time by using the unsubscribe method in a message or contacting us.

If you opt out, we may keep a minimal suppression record so that we can respect your request and avoid sending marketing to you again by mistake.

5. Who we share information with

We may use trusted service providers that help us operate our business and deliver services, including database and authentication providers, hosting and infrastructure providers, email and communications providers, payment providers, professional advisers, and other suppliers engaged for a client project. They may process personal information only for the relevant purpose and subject to appropriate contractual and security requirements.

We use Supabase for database and authentication services, Railway for production hosting, and Stripe for secure payment processing. Payment-card details are handled by Stripe and are not stored in the Blueprint to Brilliance application. We do not sell personal information to advertisers.

We may also disclose information where required by law, court order, regulatory authority, or where reasonably necessary to establish, exercise or defend legal rights or protect users, clients, our business or others from fraud, misuse or security threats.

6. International transfers

Some technology providers or their infrastructure may process information outside the United Kingdom. Where UK data protection law requires safeguards for an international transfer, we will use an approved transfer mechanism, adequacy arrangement or other lawful safeguard, as applicable.

7. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, contractual, security and dispute-resolution requirements.

As a general guide, routine enquiries that do not become client matters may be retained for up to 24 months; core client, contract and transaction records may normally be retained for up to 6 years after the end of the relevant relationship where needed for legal and accounting purposes; security logs may be kept for a shorter period unless required for an investigation; and marketing records are retained until you opt out or they are no longer needed, with a minimal suppression record retained where appropriate.

A different retention period may apply where the nature of a service, a legal requirement, a dispute, safeguarding, fraud prevention or a client's documented instruction requires it.

8. Security

We use technical and organisational measures designed to protect personal information, including access controls, authenticated accounts, encrypted connections and database-level access restrictions. No online system can be guaranteed to be completely secure, so we also monitor and review our controls as the platform develops.

9. Your data protection rights

Depending on the circumstances, UK data protection law may give you rights to access your personal information, correct inaccurate information, request deletion, restrict processing, object to certain processing, receive certain information in a portable format, and withdraw consent where processing is based on consent. These rights are subject to legal conditions and exemptions.

To exercise a right, contact us using the details on our Contact page. We may need to verify your identity before acting on a request.

10. Data protection complaints

If you have a concern about how we use your personal information, please contact us first using the details on our Contact page and state that your message is a data protection complaint. We will acknowledge, investigate and respond to complaints in accordance with applicable UK data protection requirements.

You also have the right to complain to the UK Information Commissioner's Office (ICO). Information about raising a concern is available on the ICO website. We would appreciate the opportunity to address your concern before you approach the regulator, but this does not affect your right to contact the ICO.

11. Changes to this policy

We may update this Privacy Policy as our services, suppliers or legal obligations change. The current version will be published on this page with the date of the latest update.

Contact Blueprint to Brilliance

Questions or rights requests may be sent to hello@blueprinttobrilliance.co.uk.

Telephone: +44 7496 865603.

These website legal pages are intended to provide clear operational terms and privacy information for the current Blueprint to Brilliance service. They should be reviewed whenever the business structure, payment provider, hosting, analytics, marketing technology, client platform or processing activities materially change. For bespoke regulated, high-risk or cross-border services, obtain appropriate professional legal advice.