1. Who we are (data controller)
The data controller for personal data processed through this website is:
BliBling Agency
Slovenia, European Union
Email: web@blibling.com
Phone (Europe): +386 41 229 988
Phone (United States): (737) 204-9141
Website: https://www.blibling.com/
We provide web design and development, brand services, and custom AI chatbot / automation solutions (including offerings marketed as MySite, BlingSite, and BlingAI).
If you are a client under a separate service agreement, that contract may describe additional processing for your project. This policy covers the public marketing website and its interactive features.
2. Scope
This policy applies to personal data processed when you:
- Visit or browse www.blibling.com (and the same site at blibling.com when redirected);
- Submit the contact form;
- Use the on-site BlingAI chatbot (including optional image attachments and human-handover requests);
- Interact with the cookie / privacy notice;
- Use related technical endpoints such as
contact.phpand WordPress REST routes under/wp-json/gcw/.
It does not cover third-party websites we only link to (for example demo portfolios or external tools) unless those pages are operated by us and state otherwise.
3. What personal data we collect
We design the site to minimise data collection. There is no advertising pixel network and no third-party analytics product (such as Google Analytics) embedded in the public front-end. Below is what the live code actually processes.
3.1 Data you provide voluntarily
| Feature | Data | When collected |
|---|---|---|
| Contact form | Name (required), email (required), service interest (optional), industry / niche (optional), project message (required). A hidden honeypot field may also be present for bot filtering (see below). | When you click Send Message and the form is submitted successfully over HTTPS. |
| BlingAI chatbot | Message text you type; optional images you attach; conversation context kept in your browser for the session; if you request a human handoff, contact details you provide (email or phone) and the summary message for our team. | When you send a chat message, attach an image, or complete a handoff flow that posts to our server endpoints. |
| Direct email / phone | Whatever you choose to include when you email or call us. | When you initiate contact outside the form/chat. |
3.2 Data collected automatically
| Source | Data | Purpose |
|---|---|---|
| Contact form security | IP address, UTC timestamp, rate-limit counters stored temporarily on the server | Abuse prevention (limited submissions per IP per hour); security diagnostics |
| Chatbot security | IP-based rate limits (message and image upload caps); optional server log lines for errors / handoff diagnostics | Protect the service, debug failures, process handoffs |
| Hosting / server logs | Standard web server logs (e.g. IP address, user agent, request path, time) operated by our host (DreamHost) as part of providing the website | Security, availability, troubleshooting |
| Cookie notice preference |
Browser localStorage key blibling_cookie_consent
(version, accepted flag, timestamp, method: e.g. ok, scroll, continue)
|
Remember that you dismissed the notice so we do not show it again unnecessarily |
3.3 Honeypot (bot filter)
The contact form includes a hidden field (company_website) that humans do not see.
If it is filled, the submission is treated as automated spam and is not processed as a real inquiry.
4. Purposes and legal bases (GDPR)
We process personal data only where we have a lawful basis under the EU GDPR / Slovenian ZVOP-2 aligned rules, including:
| Purpose | Legal basis |
|---|---|
| Respond to contact form inquiries and follow up about our services | Art. 6(1)(b) steps prior to a contract at your request, and/or Art. 6(1)(f) legitimate interests in operating a business website and answering leads |
| Provide the BlingAI chatbot answers and optional human handoff | Art. 6(1)(f) legitimate interests in offering product demos and support automation; where you voluntarily share contact details for a callback/email, also steps toward a contract / your request to be contacted |
| Security, rate limiting, spam prevention, debugging | Art. 6(1)(f) legitimate interests in protecting our systems and users |
| Cookie notice preference in localStorage | Art. 6(1)(f) / essential storage to respect your UI preference; informational notice only (no non-essential advertising trackers) |
| Legal compliance (e.g. responding to lawful requests) | Art. 6(1)(c) legal obligation where applicable |
We do not use your contact or chat content to train public advertising models for third parties. Chat content is processed to generate a reply via our AI provider and to run our service.
7. International transfers
Our primary operations and controller are in the European Union (Slovenia). Some processors (notably Google services and global CDNs) may process data in the United States or other countries.
Where GDPR applies to transfers outside the EEA/UK, we rely on appropriate safeguards recognised under GDPR (for example the providers’ contractual terms / Standard Contractual Clauses and related transfer tools they publish), and we limit data to what is needed for the feature you use.
8. How long we keep data
- Contact form emails: kept in our business mailbox for as long as needed to handle your inquiry and ordinary business correspondence, then deleted or archived according to our operational needs and legal retention duties (typically up to the period needed for potential claims or accounting, unless a longer period is required by law).
- Chat content: processed to generate replies; we do not run a separate marketing warehouse of full chat logs on the front-end. Server-side diagnostic logs (if written) are kept only as long as useful for security and debugging, then removed or overwritten.
- Handoff spreadsheet rows: retained while useful for sales follow-up, then deleted or minimised.
- Rate-limit files: short-lived (on the order of hours) and tied to abuse prevention.
- localStorage consent preference: until you clear site data or we change the consent version (which may re-show the notice).
- Server access logs: per hosting provider defaults / our security needs (often weeks to months).
9. Your rights
If GDPR applies to you, you may have the right to:
- Access your personal data;
- Rectify inaccurate data;
- Erase data (“right to be forgotten”) in certain cases;
- Restrict processing in certain cases;
- Object to processing based on legitimate interests;
- Data portability where processing is based on consent or contract and carried out by automated means;
- Withdraw consent where processing is consent-based (withdrawal does not affect prior lawful processing);
- Lodge a complaint with a supervisory authority.
For Slovenia, the supervisory authority is the Information Commissioner of the Republic of Slovenia (www.ip-rs.si. You may also contact your local EEA authority if you live elsewhere in the EEA.
To exercise rights, email web@blibling.com with enough detail for us to verify and fulfil your request. We may need to confirm your identity before acting.
10. Security
We implement appropriate technical and organisational measures, including:
- HTTPS encryption in transit for the public site and form/chat endpoints;
- Server-side validation and rate limiting on the contact form and chatbot;
- Honeypot bot filtering on the contact form;
- Access controls on hosting, mailbox, and API credentials;
- Minimising non-essential trackers on the marketing front-end.
No method of transmission or storage is 100% secure. If you believe there has been a personal data incident affecting you, contact us promptly at web@blibling.com.
11. Children
Our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16 for marketing purposes. If you believe a child provided data to us, contact us and we will delete it where appropriate.
12. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or operational changes. The “Last updated” date at the top will change when we do. Material changes may also be highlighted on the website or via the cookie notice version where relevant.
13. Contact us
For privacy questions, data subject requests, or complaints about this website’s processing:
BliBling Agency
Email: web@blibling.com
Contact form: www.blibling.com/#contact
This document is provided for transparency based on the live website implementation as of the last updated date. It is not personalised legal advice. For formal compliance review of your own projects, consult a qualified attorney.