1. Introduction
Bluprynt, Inc. ("the Company," "we," "us," or "our") operates the website bluprnyt.com (the "Service"). Bluprynt provides AI-powered compliance automation for teams issuing regulated digital securities under Reg D and Reg A+, including automated generation of state disclosure filings and 50-state transfer restriction monitoring. This Privacy Policy explains what information we collect from compliance teams and their organization contacts who use or inquire about the Service, how we use it, and the choices available to you.
The Company is based at 601 Massachusetts Avenue NW, Suite 500, Washington, DC 20001, and can be reached at [email protected].
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly when you use or request access to the Service, including:
- Account registration details: name, work email address, company name, role, and phone number when you sign up for a trial or paid subscription;
- Offering and disclosure documents you upload to the platform so Bluprynt can generate the required state notice filings and transfer restriction schedules for your offering;
- Compliance workflow data you enter or generate within the platform, such as offering parameters, issuer details, investor accreditation classifications, and state filing status records;
- Contact details (name, email, company) when you fill out our contact form, request a demo, or correspond with us;
- The content of messages you send us directly.
Offering documents and compliance workflow data are processed solely to provide the Service -- generating disclosure drafts, monitoring state transfer restrictions, and maintaining your compliance audit trail. We do not use your offering document contents or compliance data to train models without your explicit written consent.
2.2 Information Collected Automatically
When you visit bluprnyt.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5).
2.3 We Do Not Knowingly Collect Children's Data
bluprnyt.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
3. How We Use Information
We use the information we collect to:
- Provide and operate the Service: processing uploaded offering documents to generate state disclosure filings, populating transfer restriction schedules, and maintaining audit trail records for your compliance team;
- Manage your account and respond to support requests;
- Send service and compliance-alert notifications (for example, notifications when a state updates its transfer restriction rules affecting your active offerings);
- Send marketing communications where you have not opted out or where consent is required by applicable law;
- Detect, investigate, and prevent fraud or misuse;
- Comply with legal obligations, including securities regulations applicable to our operation as a compliance-automation tool provider.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see your state's section below.
4. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (for example, cloud hosting, email delivery, and anonymized site analytics) under contractual confidentiality and data-processing terms;
- Authorities, when required by law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties. We do not share your offering documents or compliance workflow data with any party other than subprocessors necessary to deliver the Service.
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Policy.
6. Data Retention
We retain account and compliance workflow data for the duration of your subscription and for a reasonable period thereafter to support any compliance audit or dispute resolution need. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated. If you request deletion of your account data, we will honor that request subject to any legal obligation to retain certain records.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information and compliance data, including TLS encryption in transit, restricted-access databases, and least-privilege access controls. No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. District of Columbia Residents
The District of Columbia does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (for example, GLBA with respect to financial data), those laws may give you additional rights with respect to data covered by them. Because Bluprynt processes data related to securities offerings, issuers and their compliance teams should note that certain information within the platform may also be subject to SEC and FINRA recordkeeping rules (including SEC Rule 17a-4 obligations applicable to registered broker-dealers who use our platform as a workflow tool). Nothing in this policy limits any obligation arising under those regulations.
California residents visiting from outside California may also exercise rights under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising. To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new effective date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints can be sent to:
Bluprynt, Inc.601 Massachusetts Avenue NW, Suite 500
Washington, DC 20001
Email: [email protected]
Phone: +1 (202) 554-0191