Blunom Inc. Privacy Policy
Last updated: July 2, 2026
1. Scope, Data Roles, & Global Compliance Frameworks
1.01. Parties and Scope: This Privacy Policy governs the data collection, data telemetry, and privacy management practices executed by Blunom Inc. ("Blunom," "we," "us," or "our") across our website, our waitlist systems, and our secure sovereign Artificial Intelligence orchestration control plane, policy engines, and low-code studio interfaces, collectively referred to as the "Service."
1.02. Blunom as a Data Controller: Blunom acts as a Data Controller under global data protection frameworks, including the European Union General Data Protection Regulation, referred to as GDPR, and the California Consumer Privacy Act, referred to as CCPA, with respect to the personal data we collect directly from website visitors, waitlist applicants, and account administrators. This information is utilized strictly to manage account context, authenticate users, facilitate direct platform relationships, and execute direct commercial transactions.
1.03. Blunom as a Data Processor: Blunom acts strictly as a Data Processor with respect to any data, internal code repositories, proprietary prompts, system configurations, or institutional knowledge assets ingested into or routed through our orchestration engines by a customer, corporate Affiliate, or authorized third-party partner, collectively referred to as "Customer Input." The corporate entity or customer deploying the Service remains the absolute Data Controller for all Customer Input and corresponding agent outputs, and Blunom processes such data solely under the explicit directions and configured workspace parameters established by that customer.
1.04. Channel and Services Partner Alignment: If access to the Service is provisioned, built, managed, or configured by an authorized reseller, distributor, system integrator, global system integrator, or managed service provider, collectively referred to as an "Authorized Partner," such partners are bound by separate data protection addendums. Customer acknowledges that actions taken by an Authorized Partner within a workspace are legally treated as actions executed on behalf of the Customer as the primary Data Controller.
2. Information Collected Across Deployment Models
2.01. Account Registration and Corporate Identity Data: When an individual registers an account, requests access, or submits a waitlist application, we collect voluntary professional indicators including full name, company name, corporate email address, job title, and phone number to verify business intent and establish communication lines.
2.02. Authenticated Profile Metrics: To protect workspace perimeters and enforce Role-Based Access Control, users must authenticate securely via approved federated identity single sign-on solutions, such as Google Open Authorization, commonly referred to as Google OAuth. Upon successful authentication, we collect basic profile metadata including your unique user token, email address, full name, and associated profile image to securely provision workspace settings and track authorization boundaries.
2.03. Telemetry and TokenOps Metadata: Regardless of the chosen deployment architecture, including SaaS Multi-Tenant, SaaS Single-Tenant, or Customer/Partner Self-Hosted Deployment inside a private Virtual Private Cloud, referred to as a VPC, Blunom collects structural operational metadata attached to Customer's unique organization identifier. This operational metadata consists of performance latency records, system error paths, user seat allocations, and token consumption metrics, collectively referred to as "TokenOps Metadata," which is utilized exclusively to verify active software licensing entitlements, prevent systemic security vulnerabilities, and monitor financial consumption boundaries.
2.04. Organization ID and License Anchoring Telemetry: Every unique Customer tenant environment strictly requires the provisioning of a unique, Blunom-issued corporate organization identifier, referred to as an "Organization ID," to anchor active software licenses, seat entitlements, and feature permissions. Blunom tracks usage telemetry mapped to this specific Organization ID across all deployment options to prevent multi-tenant pooling, unauthorized reselling, or license duplication exploits, while ensuring complete compliance with enterprise seats.
2.05. Deployment Isolation Parameters: For all Customer/Partner Self-Hosted Deployments executing within a customer-managed VPC or private data tenant, Blunom's data collection is strictly bounded. No text payloads, semantic data streams, proprietary systems code, or transactional Customer Inputs ever leave the customer's private infrastructure boundary, and Blunom's data access is structurally limited to the encrypted transmission of the automated licensing data and TokenOps Metadata.
3. Utilization of AI Engines & Non-Training Guarantees
3.01. Strict Enterprise Tenant Isolation: Blunom enforces technical and organizational isolation protocols across all workspace environments. Customer Inputs, execution paths, structured workflow charts, and systems logs generated by autonomous agents, collectively referred to as "Customer Content," are isolated securely within the customer's dedicated data perimeter to prevent unauthorized internal or external access.
3.02. Zero Model Training Enforcement: Blunom maintains a strict, unalterable policy regarding machine learning and model alignment. We do not sell, rent, lease, or trade your personal data, profile indicators, or processed Customer Content to any third party, nor do we utilize, transfer, or permit downstream vendors to leverage data collected via the Service or Google Application Programming Interfaces, referred to as APIs, to train, refine, align, or optimize any artificial intelligence models, machine learning systems, or foundational large language models.
3.03. Downstream Model Endpoint Defenses: The Service operates by routing customer configurations to hosted model endpoints and third-party large language models based on parameters established within Customer's policy engines. Blunom ensures that all data transmissions to authorized model providers are encrypted using Transport Layer Security 1.2 or greater, and all external provider interactions are subjected to strict purpose-limitation data agreements.
4. Cookies, Tracking Technologies, & Consent Gating
4.01. Essential Cookie Operations: We utilize essential cookies and identical session tokens necessary to maintain active user authentication, preserve secure Single Sign-On states, log account configurations, and prevent fraudulent platform exploits. These cookies are required for core platform stability and cannot be deactivated.
4.02. Performance and Analytics Gating: Subject to your explicit approval via our interactive consent interface, we utilize cookies and tracking tokens from Google Analytics 4 to evaluate website interactions, assess platform speed, and track general acquisition channels. All behavioral telemetry collected via analytics cookies is aggregated and anonymized prior to review.
4.03. Granular Choice Controls: Visitors maintain full agency to accept or decline analytics or performance tracking cookies via our consent banner. Choosing to decline analytics trackers will not impede core platform performance, and users can adjust or revoke their tracking preferences at any time by visiting our dedicated privacy dashboard or emailing security@blunom.ai.
5. Data Protection Addendum & Information Security Compliance
5.01. Incorporation of the DPA: To the extent that Blunom processes any regulated personal data or personally identifiable information subject to the GDPR, the CCPA, or comparable data protection frameworks, the parties agree that Blunom’s formal Data Protection Addendum, referred to as a DPA, located at https://blunom.ai/legal/dpa, is fully incorporated into this Privacy Policy by reference.
5.02. Information Security Auditing: Blunom maintains a documented information security program containing physical, administrative, and technical controls designed to protect enterprise workspaces. In alignment with our commitment to independent third-party compliance validation, including ongoing Service Organization Control 2, referred to as SOC 2 Type II, auditing and tracking procedures, Blunom undergoes regular infrastructure security assessments.
5.03. Security Report Access: Authorized Partners and direct enterprise Customers may submit a formal request to security@blunom.ai once per rolling 12-month period to receive our latest independent security audit summary documentation, subject to the execution of a mutual non-disclosure agreement.
6. Contractual Recourse, Liability Limits, & Legal Safeguards
6.01. Contractual Liability Caps: Blunom's total aggregate liability for any systemic data breaches, operational errors, contract claims, or legal disputes arising under this Privacy Policy shall be strictly governed by the financial liability limits and aggregate caps set forth in Section 10.02 of our Master Terms of Service.
6.02. Contractual Claim Time-Bar: To provide commercial certainty for both parties, you agree that any legal claim, dispute, or cause of action arising out of or relating to Blunom's processing of data or platform availability must be commenced within one year after the cause of action accrues. Otherwise, such cause of action is permanently barred.
7. Modifications, Term, & Termination
7.01. Policy Duration: This Privacy Policy remains effective and binding upon all users, visitors, and administrators for the entire duration of their active platform orchestration, website utilization, or workspace retention.
7.02. Amendments and Updates: Blunom reserves the right to modify or replace this privacy and data telemetry policy at any time by publishing updated criteria to https://blunom.ai/privacy. We will proactively signal material shifts via platform dashboard notifications, email alerts, or internal workspace flags. Continued platform orchestration following an amendment constitutes binding acceptance.
7.03. Termination Data Retention and Purging: Upon the closure of a workspace or the formal termination of an Order Form, Blunom retains account metadata and profile logs strictly as required to fulfill legal compliance obligations, settle active financial balances, or protect system boundaries. All identifiable Customer Content remaining within live multi-tenant databases will be permanently deleted, overwritten, or irreversibly anonymized within 30 days of active service cessation, and cached archival snapshots will be completely overwritten within a standard rolling 180-day cycle.
8. Contact & Compliance
8.01. Compliance Intake Points: For questions regarding data rights, to execute a formal request for information deletion, or to submit a report of an acceptable use violation, please contact our privacy compliance infrastructure team directly at: hello@blunom.ai.