Legal
Privacy Policy
Last updated
This policy explains what personal information BlueX collects, why, who receives it, how long it is kept and what you can do about it.
In short
- BlueX sets up and runs AI voice assistants for businesses, which we also call AI receptionists, and builds websites. This policy covers our website, our client portal, and the calls and conversations our assistants handle.
- Our assistants are artificial intelligence, not people. Their calls and voice conversations are recorded and transcribed, and the recordings and transcripts have no time limit: they stay until someone asks for them to be deleted. See the section “AI, recordings and automated processing”.
- If you called or talked to a business that uses BlueX, that business is responsible for your information. BlueX handles it on that business's behalf. See the section “If you spoke to a business that uses BlueX”.
- We do not sell personal information. Our website has no advertising, no analytics trackers and no tracking cookies.
- We give information to the companies that run the service for us, such as our voice, telephone, hosting and email providers, to the business you contacted, and to Google when an appointment is booked. Most of these providers are in the United States. The full list is in the section “Who receives your information”.
- Wherever you live, you can ask for a copy of your information, ask us to correct or delete it, and object to how we use it. Email hey@bluex.agency. You can also complain to a regulator: see the section “Complaints”.
Who we are
BlueX (“we”, “us”) is an agency that sets up and runs AI voice assistants for businesses, which we also call AI receptionists, and builds websites. You can write to us at 128 City Road, London EC1V 2NX, United Kingdom.
For anything in this policy, or to use your rights, email hey@bluex.agency.
We have not appointed a data protection officer. Privacy questions are answered by the people who run BlueX.
Which part applies to you
BlueX handles personal information in two different roles. Which one applies depends on who you were dealing with.
You dealt with BlueX
You visited bluex.agency, wrote to us, asked us to call you, talked to our own AI assistant, or you have a client account. Here BlueX decides why and how your information is used. In legal terms we are the “controller”. Start at the section “What we collect and why”.
You dealt with a business that uses BlueX
You phoned a business and its AI assistant answered, the assistant called you, or you talked to the assistant on the business's website. Here that business is responsible for your information. The business is the controller, and BlueX works for it as its “processor”. Start at the section “If you spoke to a business that uses BlueX”.
What we collect and why
This section covers the information BlueX itself is responsible for. For each situation it says what we collect, why, the legal basis we rely on under UK and EU data protection law, and how long we keep it.
Visiting our website
- What we collect
- Your IP address and the technical details every browser sends with a request, such as the browser type and the page asked for. Our public pages set no cookies and run no analytics or advertising scripts.
- Why
- To deliver the pages and to keep the site secure. When you send a form or start a conversation, we count requests per IP address so that nobody can overload the site.
- Legal basis
- Our legitimate interest in running a secure website.
- How long we keep it
- Our application keeps no record of who visited which page; the hosting server in front of it can keep standard technical logs of requests, which include IP addresses. The request counters do not hold your IP address. They hold a code computed from it with a secret key, from which the address cannot be worked back (a keyed one-way hash), and they are deleted after at most 24 hours. When something fails, our application writes a technical error log so that we can fix it.
Pictures on our blog and in our portfolio are delivered by an image host, normally Cloudinary. When your browser loads one of these pictures, the image host receives your IP address, as any web server does.
Writing to us
Through the contact form, by email or on WhatsApp.
- What we collect
- Your name and email address, your phone number and company if you give them, what you need and the message you write.
- With a form message, a keyed one-way hash of the IP address the message came from.
- With an email, the sender's name and email address, the subject and the text. Emails sent to our address are also copied from our mailbox into our own database, so that we can read and answer them in our dashboard. Attachments are not copied.
- Why
- To answer you, to discuss what you need, and to keep a record of what was said. The hash helps us recognise repeated spam.
- Legal basis
- Our legitimate interest in answering people who contact us. If you are asking about becoming a client, also the steps needed before a contract.
- How long we keep it
- There is no automatic deletion and no time limit. We keep correspondence as our record of the conversation. We delete it when you ask, unless the law requires us to keep it or we need it for a legal claim.
If you message us on WhatsApp, WhatsApp also handles your messages under its own privacy policy. We do not control that.
Asking us to call you
- What we collect
- Your name, phone number, business name and, if you give it, your email address.
- The web address of the page you asked from and the time, as our record that you asked for the call.
- Why
- To phone you. The call is placed by our AI assistant, usually within minutes, and is recorded. What we keep from the call itself is set out under “Talking to our AI assistant”. We keep the request and its outcome so that we can follow up. To stop the same number being called repeatedly, we count requests per phone number for up to 24 hours.
- Legal basis
- You asked for the call, and we rely on that as your consent to it. You can withdraw your consent at any time by telling us. We place a call only when one is requested, so we will not ring you again unless a new request is made with your number. We keep the record of the request under our legitimate interest in following up an enquiry and in being able to show that the call was asked for.
- How long we keep it
- There is no automatic deletion and no time limit. We delete the request when you ask, unless the law requires us to keep it or we need it for a legal claim. A second copy, kept only to stop the same request being sent twice, is deleted after 24 hours.
A phone number is needed to ask for a call. Please enter only your own phone number.
Talking to our AI assistant
In your browser on our website, by phoning our number, or when our assistant calls you back.
- What we collect
- In the browser: the name and email address you type before you start, and your phone number and business name if you add them; your browser's language and time zone; and your approximate location (country, region and city), worked out from your IP address. We do not store the IP address itself.
- By phone: your phone number.
- In the browser and by phone: when the conversation took place and how long it lasted, the audio recording, a written transcript, a short summary written by an AI model, the details the assistant notes down (such as your name, email address, company and what you asked about), and automatic labels and assessments such as “appointment booked”, “question answered” or “needs follow-up”.
- If you book an appointment: its title and any notes the assistant wrote, its time, the names and email addresses of the people invited, and the links to the meeting and to the calendar event.
- Why
- To answer your questions, to book what you ask for and to follow up afterwards; to keep a record of what was said; and to check that the assistant is answering people properly. Your browser's time zone lets the assistant offer appointment times on your clock, your browser's language tells us which language you are likely to prefer, and the approximate location tells whoever follows up roughly where the enquiry came from.
- Legal basis
- Our legitimate interest in answering people who contact us, keeping an accurate record of what was said and checking the quality of the answers. If you are asking about becoming a client, also the steps needed before a contract.
- How long we keep it
- The transcript, summary and details are stored in our database. ElevenLabs stores the recording and its own copy of the transcript, summary and details. None of these is deleted automatically, and there is no time limit. We delete them when you ask, unless the law requires us to keep them or we need them for a legal claim. A separate copy of what you type in the browser, kept so that it can be attached to the conversation record, is deleted after 7 days.
A name and an email address are needed to start a conversation in the browser. If you would rather not give them, email us instead.
The assistant does not need sensitive information. Please do not give the assistant health details, payment card numbers or passwords.
Having a client account
- What we collect
- Your name, email address, company and phone numbers. If we invited you, someone at BlueX entered these details first, usually from what you or a colleague told us.
- Your password, stored only as a one-way hash that we cannot read.
- What you set in the portal: a profile photo if you add one, your time zone, business hours, language and the emails you want.
- Account records: when the account was created and by whom, when you last signed in, failed sign-in attempts, the services you use, the talk time you have used, and the requests and messages you send us.
- The notes you write on conversations in the portal.
- Why
- To give you the portal and the services you bought, to keep the account secure, and to send the emails the service needs: sign-in links, notices about appointments and calls to follow up, balance warnings and receipts. We send no newsletters and no marketing emails.
- Legal basis
- Our contract with you. If the account belongs to your employer or business, our legitimate interest in providing the service that business bought. For the security measures, our legitimate interest in protecting accounts.
- How long we keep it
- For as long as the account is open, except for what the section “When an account is closed” says stays after the account is closed. A signed-in session ends after 8 hours. A sign-up that is never confirmed is deleted after 24 hours.
A name and an email address are required to open an account; without them we cannot create one. Emails about appointments and follow-ups are on by default, and you can switch them off in the portal under Profile, Notifications.
Paying us
- What we collect
- The plan or top-up you chose, the amount, your payment reference and the dates.
- Payment is made through PayPal, so PayPal handles your payment details under its own privacy policy. We see what PayPal shows the person being paid: your name, your email address, the amount and any note you add. We never see or store card or bank details.
- Why
- To add the talk time you paid for, to send your receipt and to keep our accounts.
- Legal basis
- Our contract with you, and our legal duty to keep accounting records.
- How long we keep it
- For as long as tax and accounting law requires, which for a company in the United Kingdom is at least six years. Nothing deletes payment records automatically after that, and they are kept after an account is closed.
AI, recordings and automated processing
This section applies to every conversation with an AI assistant that BlueX runs, whether the assistant answers for BlueX or for another business.
You are talking to software
The assistant is an artificial intelligence with a computer-generated voice. It is not a person. BlueX's own assistant says so when it introduces itself on the phone, and on a website the conversation window is labelled as an AI assistant.
Conversations are recorded and transcribed
Every phone call and browser conversation with an assistant is recorded. ElevenLabs, the company that runs the assistants for us, turns the audio into a written transcript, and an AI model writes a summary and notes down details such as your name and what you asked for. In the browser, your microphone is used only after you press the start button, and it is released when the conversation ends.
What the AI writes about a conversation
The summary, the noted details and labels such as “question answered” or “needs follow-up” are produced automatically. They exist so that a person can read a conversation quickly and follow it up. We do not use them, or any other automated system, to make decisions about you that have legal or similarly significant effects.
Automatic limits
Our forms and widgets apply automatic limits to stop abuse. If you think you were blocked by mistake, email hey@bluex.agency.
Your voice
We use recordings to hear what was said. BlueX does not use anyone's voice to identify them and creates no voiceprints.
Training AI models
BlueX does not use your conversations to train AI models. ElevenLabs processes conversations in order to provide the service to us. ElevenLabs' terms of service also allow it to use the content of conversations to improve its services and train its models, unless BlueX, as its customer, switches that off in its account. Until this page says that we have switched it off, assume that it applies.
Talking to a person instead
You never have to use BlueX's AI assistant. Email hey@bluex.agency or use the contact form on our website, and a person at BlueX will answer. If the assistant answered for another business, contact that business.
If you spoke to a business that uses BlueX
Businesses use BlueX to answer their phones, to call back people who ask for a call, and to talk to visitors on their websites. If that is how you came into contact with BlueX, this section is for you. The sections “AI, recordings and automated processing”, “Who receives your information” and “Where your information goes” apply to you as well.
Who is responsible
The business you contacted is responsible for your information. That business is the controller, and its own privacy notice applies. BlueX provides the AI assistant and handles the conversation for that business, as its processor. Some laws call this a “service provider”.
For two things BlueX is itself responsible: stopping abuse of the service, for example by limiting how often one phone number can be called, whichever business asked; and measuring the talk time we bill. We do both under our legitimate interest in a secure and correctly billed service.
What we handle for the business
- Your phone number, when you call or are called.
- When the conversation took place and how long it lasted.
- The audio recording of the conversation, the transcript, a summary written by an AI model, the details the assistant notes down, and automatic labels and assessments such as “appointment booked”.
- What you type before a website conversation: your name and email address, and your phone number and business name if you add them. Also your browser's language and time zone.
- What you type in a call-back request: your name, phone number and, if you give it, your email address, with the web address of the page you asked from and the time.
- What the business gives us about you so that its assistant can call you: your name and phone number and, if the business chooses, your email address, your company and a few notes about your enquiry, with how the business says you agreed to be called.
- For a website conversation, your approximate location (country, region and city), worked out from your IP address. We do not store the IP address itself.
- When the assistant books an appointment: its title and any notes the assistant wrote, its time, the names and email addresses of the people invited, and the links to the meeting and to the calendar event.
What we do with this information
We give this information to the business you contacted: in that business's private list of conversations in our client portal, where the business can read the transcript, listen to the recording and export its conversations; in emails that tell the business about a new appointment or a call to follow up; and, if the business has connected its own systems, through our API.
We do not use this information for our own marketing, we do not sell it, and we do not show it to other clients.
The assistant calls a number only when a call to that number was requested through a form on the business's website, or the business has told us that the person agreed to be called. We cannot check who typed a number into a form, so we limit how often any number can be called. If you were called without asking, tell the business or us.
Sensitive information
What you say is recorded as you say it. If you tell the assistant something sensitive, such as a health detail, it becomes part of the record the business receives. Each business is responsible for telling you how it uses sensitive information. If you would rather not say something to an AI assistant, ask the business for another way to reach it.
Appointments
When the assistant books an appointment, the event is created in the Google Calendar connected to that business's assistant, and Google can email you an invitation from that calendar. If our record shows that Google was not asked to invite you, we send you a short confirmation by email in the business's name. The confirmation gives the time and the meeting link, and a reply to it goes to the business.
How long this information is kept
The business's conversation records are not deleted automatically, and neither are the recordings and transcripts held by ElevenLabs. There is no time limit: they stay until the business tells us to delete them.
Your rights over this information
To see, correct or delete this information, contact the business you spoke to. If you write to us instead, we will pass your request to that business and help it respond.
If the business no longer uses BlueX, we can still hold the record. BlueX is then responsible for it, and you can ask us directly for a copy or to delete it.
Cookies and browser storage
Our public pages set no cookies. We use no analytics, no advertising cookies, no tracking pixels and no fingerprinting, and our own code keeps nothing else in your browser.
The client portal and its sign-in screens use the cookies below. The last two in the list are set only for BlueX staff.
bx_client- Keeps you signed in to the client portal.
- 8 hours
bx_lang- Remembers the language you picked on a sign-in screen or in the portal. Set only when you pick one.
- 1 year
bx_tz- Holds the name of your browser's time zone, so that the portal shows times on your clock. Set automatically while you are signed in, unless you have chosen a time zone in your profile.
- 1 year
bx_admin- Keeps BlueX staff signed in to our own dashboard.
- 8 hours
__prerender_bypass- Lets BlueX staff preview a blog post before it is published.
- Until the browser is closed
The sign-in cookies are needed to stay signed in. The language and time zone cookies only remember a display setting. We use cookies for nothing else, which is why we do not show a consent banner.
You can refuse the language and time zone cookies. Delete or block them in your browser and the portal still works: it uses the language and time zone saved in your profile, or your browser's language and UTC. If you choose a time zone in your profile, the time zone cookie is removed and is not written again. Without a sign-in cookie you cannot stay signed in.
The voice and call-back buttons, on our website and on our clients' websites, set no cookies. When a page carrying one of these buttons loads, your browser asks our server how the button should look, so our server receives your IP address and browser details as it would for any request. We keep no record of that request.
We do not track you across websites, and no other company collects information about your visit to our pages for its own purposes. The site therefore behaves the same whether or not your browser sends a Do Not Track or Global Privacy Control signal.
Who receives your information
We share personal information with the organisations below. Each receives what it needs to do its job; the one exception we know of is described under “Training AI models”.
Companies that process information for us
ElevenLabsEleven Labs Inc.
ElevenLabs runs the AI assistants. It receives the live audio of each conversation and the phone number or details that come with it, produces the transcript and the summary, and stores the recordings and transcripts. The assistant's replies, the summary and the noted details are written by AI language models. Some of these models are operated by other companies that work for ElevenLabs, and what is said in the conversation is passed to them for that purpose.
Where: United States. ElevenLabs can also process information in the European Union and Singapore.
TwilioTwilio Inc. / Twilio Ireland Limited
Twilio carries the phone calls. It handles the caller's number and the number called, the time and length of each call, and the audio while the call is in progress.
Where: United States, where Twilio processes voice calls by default. Calls also pass through the telephone networks of the countries involved.
MongoDBMongoDB, Inc.
MongoDB hosts our database, where accounts, messages, call-back requests, conversation records and settings are stored.
Where: United States.
Hostinger
Hostinger hosts the server that this website and the client portal run on, and provides our email. Every email we send or receive passes through Hostinger.
Where: A Hostinger data centre. Hostinger operates data centres in Europe, Asia and the Americas.
CloudinaryCloudinary Ltd. / Cloudinary Inc.
Cloudinary stores and delivers images: the profile photos clients upload, and pictures on our website. When your browser loads one of these images, Cloudinary receives your IP address, as any web server does.
Where: Stored in the United States by default. Images are delivered through networks with servers in many countries, usually one near you.
Organisations that act under their own policies
GoogleGoogle LLC / Google Ireland Limited
Google provides the calendar that appointments are booked into. When the assistant books an appointment, the event is created in the Google Calendar connected to the assistant of the business you contacted, which is BlueX's own calendar if you contacted BlueX, and Google sends the invitations. The assistant can check free time in that calendar and add, change or cancel the events it books. BlueX keeps a copy of each booking the assistant makes.
Where: United States and the other countries where Google operates.
PayPal
Clients pay us through PayPal. PayPal handles the payment under its own privacy policy.
WhatsAppWhatsApp LLC / WhatsApp Ireland Limited
If you choose to message us on WhatsApp, WhatsApp handles your messages under its own privacy policy.
Other recipients
- The business you contacted, when our AI assistant answered or called for that business.
- The people at BlueX who need the information to run the service.
- Courts, regulators or the police, when the law requires it.
- Professional advisers such as accountants and lawyers, when they need the information to advise us.
- A buyer of our business, if BlueX is ever sold or merged, under the same commitments as this policy.
We do not sell personal information, and we do not share it for advertising.
Where this website is offered in other languages, its text is translated by a machine translation service. That service receives only text that is published on this website, which can include a client's published testimonial. It never receives anything from enquiries, conversations, conversation records or accounts.
Our pages link to other services, such as share buttons, Google Calendar and PayPal. They are plain links: nothing is sent until you click one, and then that service's own policy applies.
Where your information goes
BlueX's address is in the United Kingdom, and most of the providers above store or process information in the United States. The people at BlueX, and our providers' support staff, can also reach it from other countries where they work.
When information leaves the United Kingdom or the European Economic Area, the law requires safeguards. When we last checked, on 10 October 2026, the United States companies behind ElevenLabs, Twilio, MongoDB, Cloudinary and Google were certified under the EU–US Data Privacy Framework, its UK Extension and the Swiss–US Data Privacy Framework, which the EU, the UK and Switzerland accept as adequate protection. Where a framework does not apply, or stops applying, transfers rely on the standard contractual clauses approved by the European Commission, with the UK's international data transfer addendum, which these providers publish in their data processing terms.
You can ask us for a copy of the safeguards that apply to your information.
How long we keep information
Some records end or are deleted after a fixed time. For the rest we have not set a time limit. Nothing deletes them automatically: they stay until you ask us to delete them or we delete them ourselves. For conversations we handled for another business, see the section “If you spoke to a business that uses BlueX”.
What ends or is deleted after a fixed time
- A signed-in session ends after 8 hours.
- A sign-up that is never confirmed, with the name, email address, company and phone number entered, is deleted after 24 hours.
- The links we email you stop working: a sign-up link after 24 hours, an invitation after 72 hours and a password reset link after 1 hour. We store only a one-way hash of each link.
- Abuse counters, which are keyed to a hashed IP address, a hashed email address, a phone number or an account, are deleted after at most 24 hours.
- The separate copy of what is typed before a browser conversation is deleted after 7 days.
- The copy of a call-back request kept to stop duplicates is deleted after 24 hours.
What is kept with no time limit
- Enquiries, emails and call-back requests.
- Conversation records: the transcript, summary and details in our database, and the recording and transcript held by ElevenLabs.
- Client accounts, for as long as the account is open.
- Payment records, which tax and accounting law requires us to keep: for a company in the United Kingdom, for at least six years.
When an account is closed
We delete the account, its sign-in sessions, its access keys, the call-back requests people made to that client, the service requests the client sent us through the portal, and the record of its website project.
Four things are not deleted with the account: payment records, which the law requires us to keep; conversation records, including the notes the client wrote on them; the profile photo file, which stays with Cloudinary until we erase it; and emails we exchanged with the client. We delete the last three when we are asked to.
A profile photo you remove is taken off your profile at once. The file itself stays with Cloudinary until we erase it, which we do when you ask.
How we protect information
These are the main measures in place today.
- Connections to our website, the client portal and the voice widgets are encrypted.
- Passwords are stored only as salted one-way hashes. Sign-in sessions, the links we email and secret access keys are stored only as hashes too, so the originals cannot be read from our database.
- Sessions end after 8 hours, and changing your password signs out every other device.
- Repeated wrong passwords lock an account for a short time, and sign-in and form requests are limited per IP address.
- Each client can open only its own conversations. Recordings are not copied into our database: each time the client that owns a recording presses play, the recording is fetched from ElevenLabs and played to that client only.
- Our pages load no scripts from other companies, and a browser security policy limits what a page can load or connect to.
If a breach puts your rights at risk, we report it to the regulator, and if the risk to you is high we tell you directly. Where the information was handled for a client business, we tell that business without delay.
Your rights
Wherever you live, you have these rights over the information we hold about you.
- See it. You can ask whether we hold information about you and get a copy of it.
- Correct it. You can ask us to fix information about you that is wrong or incomplete.
- Delete it. You can ask us to erase information about you. We will, unless the law requires us to keep it or we need it for a legal claim.
- Limit its use. You can ask us to stop using information about you while a question about it is being settled.
- Take a copy elsewhere. You can ask us for the information you gave us in a common electronic format, or ask us to send it to someone else.
- Withdraw consent. Where we rely on your consent, as for a call you asked for, you can withdraw it at any time. Withdrawing consent does not undo what we did before.
You can object. Where we rely on our legitimate interests, you can object to our use of your information at any time. We will stop unless we have a compelling reason to continue, and we will tell you what that reason is. We do not use your information for direct marketing; if that ever changes, you can object to it and we will stop without asking for a reason.
How to ask
Email hey@bluex.agency and tell us what you want. It is free. We answer within one month. If a request is complex we can take up to two more months, and we will tell you if so. We may ask for proof of who you are before we act, so that nobody else can obtain your information. Someone you authorise can ask on your behalf.
Sometimes we hold your details because someone else gave them to us: a caller who added you to an appointment, or someone who typed your phone number or email address into a form. Ask us and we will tell you where your details came from.
If your information was handled for a business that uses BlueX, that business answers your request. See the section “If you spoke to a business that uses BlueX”.
What you can do yourself
With a client account you can change your details, business hours and email choices, remove your photo, change your password, export your conversations and download recordings, all in the portal. To close your account, email us.
Complaints
If you are unhappy with how we have used your information, please tell us first, at hey@bluex.agency. We will acknowledge your complaint within 30 days and tell you the outcome without undue delay.
You can also complain to a regulator at any time. In the United Kingdom the regulator is the Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113. Regulators for other countries are in the section “Information for specific regions”.
Information for specific regions
United Kingdom
The UK General Data Protection Regulation and the Data Protection Act 2018 apply to the information for which BlueX is the controller. The regulator is the Information Commissioner's Office.
European Economic Area and Switzerland
Where the EU General Data Protection Regulation or the Swiss Federal Act on Data Protection applies to our use of your information, this policy applies in the same way and the rights above are yours under those laws. The European Commission and Switzerland have both decided that the United Kingdom protects personal information adequately; transfers to other countries are covered in the section “Where your information goes”.
You can complain to the data protection authority where you live or work. The EU's authorities are listed at edpb.europa.eu. In Switzerland the authority is the Federal Data Protection and Information Commissioner.
United States
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we have done neither in the past 12 months. We do not use sensitive personal information to infer characteristics about anyone.
The sections above set out what we collect, where it comes from, why we use it, who receives it and how long we keep it. In the terms that US state privacy laws use, the categories are: identifiers such as your name, email address, phone number and IP address; audio recordings and their transcripts; commercial information such as the plans you bought; internet activity, limited to the requests your browser makes to our site; approximate location; and professional information such as your company.
Residents of California and of other states with privacy laws can ask us what we hold about them, and ask us to correct it, delete it and give them a copy. We give those rights to everyone, whether or not those laws apply to us and wherever they live. You can use an authorised agent, we will not treat you differently for asking, and if we refuse a request you can appeal by replying to our answer.
When we handle information for a client business, we act as its service provider or processor and use the information only to provide our services to that business.
Canada
Your information is processed outside Canada, mainly in the United States, where courts and authorities can require access to it under their own laws. Every right in the section “Your rights” is yours, including withdrawing consent. You can complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
Australia and New Zealand
The sections above set out the kinds of information we collect, how we collect and hold it, why, and where it is sent, mainly the United States. Every right in the section “Your rights” is yours. If you complain to us we will acknowledge your complaint within 30 days and tell you the outcome without undue delay. If you are not satisfied, you can contact the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner. We do not use computer programs to make decisions that significantly affect your rights or interests.
Other countries
Privacy laws differ between countries. Wherever you live, you can ask us what information we hold about you, ask for it to be corrected or deleted, object to how we use it, and complain to us or to your local data protection authority. If your local law gives you further rights, we will honour them where they apply to us.
Children
Our website and client portal are meant for adults acting for a business. We do not knowingly collect information from children. If you believe a child has given us personal information, tell us and we will delete it.
People of any age may phone a business that uses BlueX. That business is responsible for how children's information is handled.
Changes to this policy
We update this policy when what we do changes, and list each change below. The date at the top is the date the current version took effect. If a change materially affects how we use information we already hold, we will also email account holders.
- First version.
Contact
Email hey@bluex.agency, or write to BlueX, 128 City Road, London EC1V 2NX, United Kingdom.
