Legal

Privacy Policy

This Privacy Policy explains how BliBling Agency (“we”, “us”, “our”) processes personal data when you use www.blibling.com — including the contact form, BlingAI chatbot, cookie notice, and related server scripts. It is written to match how the live site actually works (no advertising pixels or analytics suites are embedded).

Last updated: 19 July 2026
Controller: BliBling Agency · Slovenia, European Union
Contact: web@blibling.com

1. Who we are (data controller)

The data controller for personal data processed through this website is:

BliBling Agency
Slovenia, European Union
Email: web@blibling.com
Phone (Europe): +386 41 229 988
Phone (United States): (737) 204-9141
Website: https://www.blibling.com/

We provide web design and development, brand services, and custom AI chatbot / automation solutions (including offerings marketed as MySite, BlingSite, and BlingAI).

If you are a client under a separate service agreement, that contract may describe additional processing for your project. This policy covers the public marketing website and its interactive features.

2. Scope

This policy applies to personal data processed when you:

  • Visit or browse www.blibling.com (and the same site at blibling.com when redirected);
  • Submit the contact form;
  • Use the on-site BlingAI chatbot (including optional image attachments and human-handover requests);
  • Interact with the cookie / privacy notice;
  • Use related technical endpoints such as contact.php and WordPress REST routes under /wp-json/gcw/.

It does not cover third-party websites we only link to (for example demo portfolios or external tools) unless those pages are operated by us and state otherwise.

3. What personal data we collect

We design the site to minimise data collection. There is no advertising pixel network and no third-party analytics product (such as Google Analytics) embedded in the public front-end. Below is what the live code actually processes.

3.1 Data you provide voluntarily

Feature Data When collected
Contact form Name (required), email (required), service interest (optional), industry / niche (optional), project message (required). A hidden honeypot field may also be present for bot filtering (see below). When you click Send Message and the form is submitted successfully over HTTPS.
BlingAI chatbot Message text you type; optional images you attach; conversation context kept in your browser for the session; if you request a human handoff, contact details you provide (email or phone) and the summary message for our team. When you send a chat message, attach an image, or complete a handoff flow that posts to our server endpoints.
Direct email / phone Whatever you choose to include when you email or call us. When you initiate contact outside the form/chat.

3.2 Data collected automatically

Source Data Purpose
Contact form security IP address, UTC timestamp, rate-limit counters stored temporarily on the server Abuse prevention (limited submissions per IP per hour); security diagnostics
Chatbot security IP-based rate limits (message and image upload caps); optional server log lines for errors / handoff diagnostics Protect the service, debug failures, process handoffs
Hosting / server logs Standard web server logs (e.g. IP address, user agent, request path, time) operated by our host (DreamHost) as part of providing the website Security, availability, troubleshooting
Cookie notice preference Browser localStorage key blibling_cookie_consent (version, accepted flag, timestamp, method: e.g. ok, scroll, continue) Remember that you dismissed the notice so we do not show it again unnecessarily

3.3 Honeypot (bot filter)

The contact form includes a hidden field (company_website) that humans do not see. If it is filled, the submission is treated as automated spam and is not processed as a real inquiry.

4. Purposes and legal bases (GDPR)

We process personal data only where we have a lawful basis under the EU GDPR / Slovenian ZVOP-2 aligned rules, including:

Purpose Legal basis
Respond to contact form inquiries and follow up about our services Art. 6(1)(b) steps prior to a contract at your request, and/or Art. 6(1)(f) legitimate interests in operating a business website and answering leads
Provide the BlingAI chatbot answers and optional human handoff Art. 6(1)(f) legitimate interests in offering product demos and support automation; where you voluntarily share contact details for a callback/email, also steps toward a contract / your request to be contacted
Security, rate limiting, spam prevention, debugging Art. 6(1)(f) legitimate interests in protecting our systems and users
Cookie notice preference in localStorage Art. 6(1)(f) / essential storage to respect your UI preference; informational notice only (no non-essential advertising trackers)
Legal compliance (e.g. responding to lawful requests) Art. 6(1)(c) legal obligation where applicable

We do not use your contact or chat content to train public advertising models for third parties. Chat content is processed to generate a reply via our AI provider and to run our service.

5. Cookies, local storage & similar technologies

We do not set advertising cookies or third-party marketing trackers on this site. The on-site notice is primarily informational for essential site operation and preference memory.

5.1 Essential preference (localStorage)

Name Type Purpose When set
blibling_cookie_consent localStorage (browser only) Remembers that you dismissed the cookie notice. Stores consent version, accepted flag, ISO timestamp, and method (ok, scroll, or continue). When you click OK, scroll past a short threshold, or continue by navigating while the notice is visible.

This value is not sent to our servers as an HTTP cookie. You can clear it anytime via browser site-data settings. Footer Cookie settings re-opens the notice for review.

5.2 Strictly necessary technical storage

The host and browser may use session or security mechanisms required to deliver pages, HTTPS, and rate limiting. Chat conversation history for the open widget is kept in page memory (JavaScript) for the session so the assistant can keep context; it is not stored in a marketing cookie.

5.3 Third-party resources loaded by the page

To render fonts and animation libraries, the site may request resources from:

  • Google Fonts (fonts.googleapis.com / fonts.gstatic.com)
  • jsDelivr CDN (animation libraries such as GSAP / Lenis)

Those providers may process technical data (such as IP address) under their own policies when your browser fetches the files. We load only what the site needs to function and display.

6. Who we share data with (processors / recipients)

We do not sell your personal data. We use carefully selected providers to operate the site:

Recipient Role Data involved
DreamHost Website hosting, server infrastructure, email delivery (SMTP) for web@blibling.com Site files, server logs, contact-form emails and related metadata
Google (Gemini / Generative Language API) AI model provider powering BlingAI chat replies Chat prompts / conversation content and any images you attach, as needed to generate a response
Google Sheets API (when handoff is used) Stores human-handoff leads for our team follow-up Handoff message, contact method (email/phone), channel, timestamp (as implemented in the chatbot plugin)
Google Fonts / jsDelivr Content delivery for fonts and front-end libraries Technical request data (e.g. IP) as part of loading assets

We may also disclose data if required by law, to protect rights and safety, or in connection with a business reorganisation, subject to appropriate safeguards.

7. International transfers

Our primary operations and controller are in the European Union (Slovenia). Some processors (notably Google services and global CDNs) may process data in the United States or other countries.

Where GDPR applies to transfers outside the EEA/UK, we rely on appropriate safeguards recognised under GDPR (for example the providers’ contractual terms / Standard Contractual Clauses and related transfer tools they publish), and we limit data to what is needed for the feature you use.

8. How long we keep data

  • Contact form emails: kept in our business mailbox for as long as needed to handle your inquiry and ordinary business correspondence, then deleted or archived according to our operational needs and legal retention duties (typically up to the period needed for potential claims or accounting, unless a longer period is required by law).
  • Chat content: processed to generate replies; we do not run a separate marketing warehouse of full chat logs on the front-end. Server-side diagnostic logs (if written) are kept only as long as useful for security and debugging, then removed or overwritten.
  • Handoff spreadsheet rows: retained while useful for sales follow-up, then deleted or minimised.
  • Rate-limit files: short-lived (on the order of hours) and tied to abuse prevention.
  • localStorage consent preference: until you clear site data or we change the consent version (which may re-show the notice).
  • Server access logs: per hosting provider defaults / our security needs (often weeks to months).

9. Your rights

If GDPR applies to you, you may have the right to:

  • Access your personal data;
  • Rectify inaccurate data;
  • Erase data (“right to be forgotten”) in certain cases;
  • Restrict processing in certain cases;
  • Object to processing based on legitimate interests;
  • Data portability where processing is based on consent or contract and carried out by automated means;
  • Withdraw consent where processing is consent-based (withdrawal does not affect prior lawful processing);
  • Lodge a complaint with a supervisory authority.

For Slovenia, the supervisory authority is the Information Commissioner of the Republic of Slovenia (www.ip-rs.si. You may also contact your local EEA authority if you live elsewhere in the EEA.

To exercise rights, email web@blibling.com with enough detail for us to verify and fulfil your request. We may need to confirm your identity before acting.

10. Security

We implement appropriate technical and organisational measures, including:

  • HTTPS encryption in transit for the public site and form/chat endpoints;
  • Server-side validation and rate limiting on the contact form and chatbot;
  • Honeypot bot filtering on the contact form;
  • Access controls on hosting, mailbox, and API credentials;
  • Minimising non-essential trackers on the marketing front-end.

No method of transmission or storage is 100% secure. If you believe there has been a personal data incident affecting you, contact us promptly at web@blibling.com.

11. Children

Our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16 for marketing purposes. If you believe a child provided data to us, contact us and we will delete it where appropriate.

12. Changes to this policy

We may update this Privacy Policy to reflect product, legal, or operational changes. The “Last updated” date at the top will change when we do. Material changes may also be highlighted on the website or via the cookie notice version where relevant.

13. Contact us

For privacy questions, data subject requests, or complaints about this website’s processing:

BliBling Agency
Email: web@blibling.com
Contact form: www.blibling.com/#contact

This document is provided for transparency based on the live website implementation as of the last updated date. It is not personalised legal advice. For formal compliance review of your own projects, consult a qualified attorney.