This policy explains what personal data BlueWire (the tool at blue-wire.net) collects, why we collect it, and what your rights are. It is written to comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Dutch Uitvoeringswet AVG.
01Who we are
BlueWire is operated by an independent marine electrical engineering practice based in the Netherlands. For the purposes of the GDPR we act as the data controller for personal data processed through this website and the configurator tool.
Blue·Wire is a trading name of Simply Online (eenmanszaak), KvK 64729273, Bentinckstraat 46/2, Amsterdam, the Netherlands.
If you prefer a postal address or need to reach our data protection contact directly, see section 12.
02What personal data we collect
We collect only the minimum we need to run the service. The table below lists every category.
| Data | When | Stored where |
|---|---|---|
| Email address | When you sign up / sign in | PostgreSQL (app.users) |
| Display name (optional) | When you sign up / sign in | PostgreSQL (app.users) |
| Account metadata — sign-in provider, creation date, last login time | Automatically, on every sign-in | PostgreSQL (app.users) |
| Password (only if you create an email + password account) | When you set or change your password | PostgreSQL (app.users) as a one-way bcrypt hash — never the plaintext |
Session cookie — a signed JWT (bw_session) |
When you sign in; expires after 30 days | Your browser only (HttpOnly) |
| Designs you save — the JSON of your configurator canvas (components, wires, settings) | When you click Save or auto-save runs | PostgreSQL (app.user_designs) |
| Quotes — a quote is just one of your saved designs; it holds no separate personal data | When you save a design as a quote | PostgreSQL (app.user_designs) — deleted with your account |
| Checkout & order details — email and shipping address, payment | When you place an order | Shopify (our checkout processor) — not stored on our own servers; we only ever hold your name and email |
| Support tickets — the subject and message you send us | When you open a ticket | PostgreSQL (app.support_tickets) |
| Server request logs — IP address, user-agent, URL, timestamp | Every request | Web-server logs; auto-rotated and purged after 90 days |
What we don't collect: we never store your password in plaintext (only a one-way bcrypt hash), we don't hold your card or bank details (our payment processor Shopify handles those — see section 6), we don't run advertising cookies, we don't integrate analytics platforms such as Google Analytics, and we don't track you across other sites.
03Why we process your data
- Authentication — to identify you across sessions so your designs follow you from device to device.
- Service delivery — to save, list, and restore your designs, quotes, and support history.
- Orders — when you place an order, your email and shipping address are processed by Shopify to take payment and ship to you (see section 6).
- Operations & abuse prevention — request logs let us diagnose errors and detect abuse.
- Newsletter (only if you opt in) — to send occasional product news. You choose this with an explicit, unticked checkbox and can unsubscribe at any time (see section 6).
- Legal records — invoices for your orders are kept for 7 years as required by Dutch fiscal law. They live with Shopify and in our bookkeeping system, never on our own servers, and are unaffected by account deletion (see section 7).
We do not use your data for automated decision-making or profiling. The only marketing we do is the opt-in newsletter above.
04Legal basis (GDPR Art. 6)
- Consent (Art. 6(1)(a)) — you tick the account consent box at sign-up (withdraw by deleting your account). The newsletter is a separate, explicit opt-in (unticked by default) that you can withdraw at any time by unsubscribing.
- Performance of a contract (Art. 6(1)(b)) — we need to process your account data to let you use the service you asked for, and to fulfil any order you place.
- Legitimate interest (Art. 6(1)(f)) — security logging and basic anti-abuse monitoring.
- Legal obligation (Art. 6(1)(c)) — retaining invoices for the statutory Dutch fiscal-retention period (held by Shopify and our bookkeeping system, not on our servers).
05Cookies & tracking
We use a single strictly-necessary cookie:
| Name | Purpose | Duration | Type |
|---|---|---|---|
bw_session |
Signed JWT that keeps you logged in | 30 days (rolling) | HttpOnly, SameSite=Lax |
We also use your browser's localStorage to remember small UX preferences (such as the email you last used in the contact form). This never leaves your device.
No advertising cookies, no third-party pixels, no cross-site trackers, no session replay.
06Third parties & where data flows
We keep your account data (name, email, saved designs) on our own infrastructure in the EU and don't share it with advertisers or data brokers. The subprocessors we rely on:
- Hosting provider (the data centre that runs our web server and PostgreSQL database). Located in the EU. Bound by a data-processing agreement under GDPR Art. 28.
- Shopify — our checkout, payment and order processor. When you place an order, Shopify collects and stores your email, shipping address and payment details and issues your invoice; those never touch our own servers. Shopify also runs Shopify Email, which is the system of record for our opt-in newsletter (your subscription status and consent are held there). Bound by the Shopify Data Processing Addendum (GDPR Art. 28); Shopify may process data outside the EEA under Standard Contractual Clauses.
- Web fonts — we self-host all web fonts on our own EU infrastructure. No font CDN is used, so no data (not even your IP address) is sent to Google or any other third party in order to load fonts.
- Sign-in providers (planned) — if you choose "Sign in with Google" or "Sign in with Microsoft" once those are enabled, the provider sees that you're authenticating with BlueWire. We only receive your email, name, and avatar.
Apart from order and newsletter data handled by Shopify (covered by the Standard Contractual Clauses noted above), we do not transfer personal data outside the European Economic Area. Where any subprocessor we use operates outside it, the transfer is covered by an adequacy decision or standard contractual clauses.
07How long we keep it
| Data | Retention |
|---|---|
Account (app.users) and designs (including any saved quotes) |
Until you delete your account, or after 24 months of inactivity (we send a reminder first). |
| Support tickets | 12 months after the ticket is closed. |
| Invoices & order records | 7 years, as required by Dutch fiscal-retention law (bewaarplicht). Held by Shopify and in our bookkeeping system, not on our own servers. Because this is a legal obligation (GDPR Art. 17(3)(b)), invoices are not deleted when you delete your account. |
| Newsletter subscription & consent | Held in Shopify Email until you unsubscribe; the consent record is retained as proof of your prior opt-in. |
| Web-server logs (including IP address) | Auto-rotated and purged after 90 days. As these are kept for security and abuse-prevention, they are not scrubbed per-user on an erasure request. |
| Backups | Kept on a tiered schedule (daily for 7 days, weekly for 4 weeks, monthly for 6 months, yearly for 7 years). If you delete personal data, it may persist in a backup until the relevant tier expires. Backups are used solely for disaster recovery, are access-restricted, and are never used to reconstruct deleted accounts for any other purpose. |
08Your rights under the GDPR
You have the following rights regarding your personal data. To exercise them, email the address in section 12 or use the tools in your dashboard.
- Right of access (Art. 15) — request a copy of what we hold about you.
- Right to rectification (Art. 16) — fix anything that's wrong. Name and email are editable from your settings; for anything else, email us.
- Right to erasure (Art. 17) — "the right to be forgotten." You can self-service this by opening Dashboard → Settings → Delete account; it removes your account, designs (including saved quotes), and tickets immediately. Invoices for past orders are held by Shopify and our bookkeeping system under a legal retention obligation and are not deleted (Art. 17(3)(b); see section 7).
- Right to restrict processing (Art. 18).
- Right to data portability (Art. 20) — you can export each design as JSON directly from the configurator (Export button). For a full account export, email us.
- Right to object (Art. 21).
- Right to withdraw consent (Art. 7(3)) — withdrawing your account consent means deleting your account; the newsletter opt-in is withdrawn separately, at any time, by unsubscribing.
- Right to lodge a complaint with the Dutch data-protection authority (Autoriteit Persoonsgegevens) if you believe we haven't handled your data correctly.
09Security
- All traffic between your browser and our servers is encrypted with TLS.
- Session cookies are
HttpOnlyandSameSite=Laxso they can't be read by JavaScript or sent on cross-site requests. - Database backups are encrypted at rest.
- Access to the production database is restricted to a small number of engineers, each with named credentials.
No online service is perfectly secure. If we ever suffer a personal-data breach that's likely to affect your rights, we will notify the data-protection authority within 72 hours as required by GDPR Art. 33, and contact you directly if there's a high risk to you (Art. 34).
10Children
BlueWire is a professional tool for marine and off-grid electrical design. It is not directed at children and we don't knowingly collect data from anyone under 16. If you think a child has signed up, contact us and we will delete the account.
11Changes to this policy
We may update this policy when the service changes (for example when we enable the Google / Microsoft sign-in buttons, or add a new feature that processes data in a new way). When we make a material change we will:
- Bump the version number and the effective date at the top of this page.
- Where the change materially expands our data use, email registered users ahead of time.
Older versions of this policy are kept in git and can be produced on request.
12Contact us
For any privacy question — access requests, complaints, data-protection queries — reach us at:
- Email: privacy@blue-wire.net
- Phone: +31 20 778 1440
- Legal entity: Blue·Wire is a trading name of Simply Online (eenmanszaak), KvK 64729273, Bentinckstraat 46/2, Amsterdam, the Netherlands.
- Contact page: blue-wire.net/contact
We aim to respond to all requests within 30 days, as required by the GDPR.