Skip to content
BlazeSphere
SolutionsProductsIntegrationsResourcesCompanyContact
Español Open customer portal
SolutionsProductsIntegrationsResourcesCompanyContact Español Open customer portal

Privacy and data

Blaze privacy policy

Effective October 2, 2026 · Last updated: October 2, 2026.

This policy explains personal-data processing across the corporate website, business relationships and Blaze services and integrations.

1. Scope and contact

This policy describes personal-data processing relating to the Blaze corporate website, business relationships and Blaze software and integration services an organization purchases or enables, including BlazeISP, BlazeTeams, WhatsLite and API/MCP connections according to the agreed scope. It applies according to the service, feature and relationship with the individual. It does not itself authorize processing incompatible with permissions, the agreement or law.

The business entities are BlazeSphere LLC and BlazeSphere Technology S.R.L. Contact privacy@blaze.do for privacy, rights and deletion requests, and legal@blaze.do for contractual matters. The responsible entity for each purpose and its address will be identified in the relevant collection notice and contractual documentation and may be requested through these contacts.

2. Who determines how data is used

For business inquiries, account administration, its own billing, service security and its own legal obligations, the entity determining the purposes and means acts as controller. Receiving a payment or issuing an invoice does not automatically assign that role for other operations.

When a business uses Blaze to manage information about its employees, users or customers, that business normally determines the purposes and Blaze processes the data on its behalf under the service and documented instructions. If the customer acts for another organization, Blaze may be a subprocessor. The agreement or data processing agreement identifies the roles, instructions and limits. A provider may have different roles for different operations.

If a Blaze business customer messages you, its notice explains its decisions about your data. You can contact that business or write to us so that we can identify and coordinate the appropriate response. You do not need a direct Blaze account to submit a request.

3. Website data and inquiries

The corporate website uses email, phone and outbound links to other Blaze services. It has no forms or page-based submission of inquiries to a CRM. If you choose to email or call us, we receive the contact details and content you provide to respond and follow up on that inquiry.

The corporate website code does not incorporate cookies, browser local storage, analytics tools, Meta Pixel, tag managers or advertising scripts. It uses Google Fonts to display Manrope, which involves browser requests to an external provider. Hosting and delivery may also generate technical data; the relevant categories, recipients and retention will be described in the applicable service information. This description does not extend to linked portals, products or websites with their own functionality.

4. Data categories and sources by feature

Depending on enabled features, services may process account and business identification; administrator and user details; contacts and CRM relationships; messages, files and other customer-submitted content; billing and payment-status information; support requests; technical, activity and security records; and operational data connected by the customer. Listing a category does not mean that every product collects it.

Data may come from the individual, their organization's administrator, customer communications or systems connected using granted permissions. Each service must identify its actual categories, functions and sources in its notice or processing documentation. We do not request data unrelated to the service purpose. Avoid unnecessary sensitive information in inquiries or free-text fields.

5. Purposes and applicable legal bases

Purposes are to provide contracted features; respond to inquiries; administer accounts and business relationships; process payments and accounting records; provide support; maintain security and prevent abuse; and meet legal obligations. Promotional communications are a separate purpose from messages needed to operate the service.

Where law requires a legal basis, it is determined for each operation: performing a contract with the individual where relevant; legal obligations; consent for activities requiring it; or assessed legitimate interests where that basis is available and the individual's rights do not override it. A B2B contract with a company is not automatically a contractual legal basis for all its employees or customers. As processor, Blaze follows documented instructions and does not repurpose customer data for incompatible independent purposes.

6. Meta WhatsApp and Coexistence

When a Meta integration is enabled, data and permissions necessary for the authorized feature are processed. Depending on the channel, these may include account and number identifiers, contacts, content and attachments, templates, message status and technical records. Actual scope must match approved permissions and the contracted configuration.

If Coexistence between WhatsApp Business app and Cloud API is enabled, the business can choose whether to share history during onboarding. Synchronization of contacts, history and new messages is limited to authorization and enabled capabilities. That choice does not replace notices and permissions owed to message recipients. Meta and WhatsApp process information under their own terms. Disconnecting an integration does not automatically erase every previously retained copy.

7. API MCP and artificial intelligence

APIs and MCP connections process data needed for authorized operations and, where relevant, activity records for security and support. Permissions must fit the integration's purpose. Customers must review enabled actions and information access.

When an AI feature is enabled, its documentation will identify the purpose, data categories sent, providers and conditions for retaining and using inputs and outputs. Blaze will limit processing to the contracted feature and will not use customer content to train general-purpose models without separate express authorization. AI output requires human review and must not be used for solely automated high-impact decisions about people without the necessary safeguards and legal authorization.

8. Access and recipients

Data is accessible to authorized customer and Blaze personnel according to their roles and to providers that need it to deliver the service. These categories may include hosting, storage, communications, support, payments and AI or analytics only where enabled. Stripe participates in processing payments to BlazeSphere LLC. The payment-flow notice and Stripe terms provide additional information about that processing.

Processors and subprocessors will be bound by written obligations concerning instructions, confidentiality, security, assistance and deletion or return. You may request information at privacy@blaze.do about providers involved in your service, their functions, and applicable locations and transfer safeguards.

We will not sell personal data or share customer content for cross-service behavioral advertising. Meta Platform Data will not be sold, licensed or reused beyond permitted purposes. Data will not be disclosed to other customers. Legally required disclosures will be limited to what is necessary, with notice to the affected party when permitted.

9. International transfers

A global service may involve processing outside an individual's country. Service information will identify actual hosting and relevant provider countries or regions. No country-specific data residency is promised without a written agreement and verified technical capability.

Where transfers face special requirements, the appropriate mechanism will be assessed and implemented, such as an adequacy decision, authorized contractual clauses or another permitted safeguard, with supplementary measures where necessary. Using Stripe, Meta or a cloud provider does not by itself resolve every transfer obligation. You can request information about applicable safeguards at privacy@blaze.do, subject to legitimate confidentiality limits.

10. Retention by category

We retain data for as long as needed for its purpose, the agreement, rights requests and applicable obligations. The following framework establishes category-specific criteria. Operational periods will be determined according to the service, purpose and applicable obligations and communicated in contractual documentation or when handling a request. Data will not be kept indefinitely merely because storage is technically possible.

CategoryPeriod or criterionEnd of purpose
Business inquiries and opportunitiesWhile a legitimate inquiry or follow-up is active; periodic review of inactive contactsClose, delete or anonymize when the purpose ends; honor opt-outs
Accounts and administratorsDuring the relationship and approved operational closureRemove unnecessary identifiers; separate records subject to independent duties
Customer content and integrationsDuring service under instructions, settings and agreementExport where appropriate; then delete or anonymize without incompatible reuse
Billing and tax receiptsFor the period required by applicable tax/accounting lawRetain only required records with restricted access; delete at expiry
SupportAs needed to resolve and reasonably document the issueMinimize attachments and sensitive data; close under the applicable schedule
Logs and securityPeriod proportionate to risk, diagnosis and investigationRotate; retain only relevant evidence for an incident or legal hold
Permissions and technical credentialsWhile needed for an authorized integrationRevoke or remove on disconnection; remove copies from logs
Rights requests and opt-outsMinimum needed to evidence handling and respect preferencesKeep limited evidence without retaining deleted content
BackupsDocumented and bounded rotation cycleIsolate from ordinary use; reapply deletion after restoration

11. Security and incidents

Blaze will maintain technical and organizational measures proportionate to risk: access and privilege controls, credential protection, customer separation, vulnerability management, security records and recovery. Specific controls will be described according to verified implementation. There is no promise of end-to-end encryption for every copy or general Meta certification.

Following an incident, its scope will be assessed, risk contained and corrective measures taken. Where Blaze is a processor, it will notify the relevant controller of personal-data breaches affecting it without undue delay and under applicable law and contract, providing further information as it becomes available. Notifications to individuals or regulators depend on each party's role, the risk and applicable requirements. No universal notification or resolution SLA is established.

12. Your rights and requests

Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, portability, objection and withdrawal of consent, and specific rights regarding sale, sharing for advertising or sensitive information where those regimes apply. Contact privacy@blaze.do. Everyone using Meta integrations may request deletion of data processed by Blaze regardless of residence.

Identify the related service or business and a contact detail that helps locate the information. Verification will be proportionate and use existing information first; we will not request passwords, access codes or unnecessary complete identity documents. Representatives may establish their authority. Requests will be handled within applicable legal periods, with notice of permitted extensions or reasons for refusal. Exercising rights will not result in retaliation or unlawful discrimination. You may complain to the competent authority or use available remedies.

13. Deletion, cancellation and backups

Commercial cancellation, channel disconnection and data deletion are different operations. A valid request may affect access, histories or account features; we will explain relevant consequences before actions requiring clarification of scope. Where data is processed for a business, handling and propagation to providers will be coordinated without using that coordination as a reason to disregard the request.

Backups that do not allow granular deletion will remain isolated from ordinary use until their documented rotation, unless legitimately retained. If a backup is restored, the operational procedure will be followed to reapply recorded deletion requests before data returns to normal operation. We do not promise instant deletion of every copy or of data independently controlled by other providers. Public deletion instructions explain how to submit and follow up on a request.

14. Communications, children and special data

The business sending messages must maintain required notices, permissions and opt-in and honor opt-out requests on or off WhatsApp. Company registration, a sales inquiry or acceptance of notices does not itself authorize marketing. Opt-outs apply to the relevant purpose without removing minimal records needed to respect them or legitimate operational communications.

The services are intended for business use and not independent purchasing by children. Child-directed uses and specially protected data categories will not be enabled without assessing need, law, notices and required safeguards. If you believe information about a child or sensitive information was improperly received, notify privacy@blaze.do. Requirements concerning children will be assessed according to their jurisdiction and the feature used.

15. Changes and specific notices

Effective date and last updated: October 2, 2026. Material changes will be communicated through means appropriate to the relationship and law; required consent will be obtained before new processing. Product notices and regional supplements may add specific details without reducing mandatory rights. This policy is not a GDPR, CCPA or other compliance certification.

Back to home
BlazeSphere

Customer care, operations and systems connected with better context.

Explore

Products Customer care ISP Operations Integrations Domains

Products

BlazeTeamsBlazeISPBlazePBXBlazeConnectorBlazeACSBlazeTransferBlaze WhatsLiteBlazeDSP · In developmentBlazeBEP · In development

Contact

Talk to the team contacto@blaze.do +1 (829) 819-3765

Access

Open customer portal Resources For AI agents

© 2026 BlazeSphere. All rights reserved.

Products and capabilities are subject to project availability.

Privacy · Terms · Cookies · Data deletion