Data protection and privacy
Privacy Policy
This concise notice explains how information is handled on BlueMarke.com's public pages, business profiles, and appointment-booking service.
Working draft — updated August 10, 2026
BlueMarke uses information only to provide and secure the public website, remember a selected language, process appointment requests, and send related service emails. BlueMarke does not sell booking data or use it for advertising, profiling, or AI.
Who we are and what this notice covers
This notice covers the public pages, public business profiles, and appointment-booking functions available on BlueMarke.com. It does not currently cover the separate business account service at panel.bluemarke.com. Participating businesses may publish their own privacy notices for their services and their handling of appointment information.
BlueMarke.com is a business being developed in Toronto, Canada. Its registered legal entity, full postal address, and dedicated privacy contact. BlueMarke has not yet confirmed an EU representative. This working draft must not be published as a final privacy notice until those details and the allocation of privacy responsibilities between BlueMarke and participating businesses have been legally confirmed.
BlueMarke determines how technical website data, language preferences, and direct communications are handled. Whether BlueMarke acts as a processor, separate controller, or joint controller for appointment information. BlueMarke's Canadian commercial processing may also be subject to the Personal Information Protection and Electronic Documents Act (PIPEDA).
Information we process and why
Website delivery and security. When you access BlueMarke.com, the Host Europe server processes technical request and connection information, which may include your IP address, request time, requested resource, response information, and technical errors. IP anonymization is enabled during log rotation, and server logs are retained for no longer than seven days. The purposes are to deliver the website, maintain security and reliability, prevent misuse, and investigate faults. Where the GDPR applies, the legal basis is BlueMarke's legitimate interests under Article 6(1)(f) GDPR.
Language preference. When you select a supported language, BlueMarke stores the selected language code in Local Storage under bluekortex.public-panel.language. It contains no unique visitor identifier and is not used for tracking. It remains until you change it or clear the site's browser data. This storage provides a language preference expressly requested by you and is treated as necessary under section 25(2)(2) TDDDG. To the extent the preference is personal data, the GDPR basis is Article 6(1)(f). The public service currently sets no cookies and uses no analytics or advertising technology.
Appointment requests. When you request an appointment, BlueMarke processes your name, email address, selected business and service, appointment start and end time, booking status, creation and update timestamps, and hashed confirmation or cancellation tokens. These details are used to check availability, submit and manage the request, verify your email address, allow confirmation or cancellation, send service messages, and provide the appointment to the selected business. Name and email address are required for the standard public booking flow; BlueMarke cannot process that request without them. To the extent BlueMarke is a controller, processing requested to arrange the appointment is based on Article 6(1)(b) GDPR, while security and abuse-prevention processing is based on Article 6(1)(f). The final role allocation and legal bases remain.
Booking invitations and direct contact. A participating business may provide your name and email address to BlueMarke so that BlueMarke can send an invitation to book. In that situation, the participating business is the source of the information. If you contact BlueMarke by email, BlueMarke processes your address, message, and related correspondence to answer you. Contract-related inquiries are handled under Article 6(1)(b) GDPR; other inquiries are handled under Article 6(1)(f). BlueMarke does not use this information for marketing, AI, profiling, or decisions based solely on automated processing.
Recipients, service providers, transfers, and retention
BlueMarke does not sell or rent personal information. Appointment details—name, email address, selected service, and appointment time—are made available to the participating business with which you requested the appointment. That business handles the information for its own appointment and service purposes under its own privacy responsibilities.
Host Europe GmbH, c/o Spaces, Gertrudenstraße 30–36, 50667 Cologne, Germany, provides the virtual private server, application hosting, and MySQL database infrastructure. The server and database are located in France. Host Europe may process website and booking information on BlueMarke's behalf when providing infrastructure or technical support. Whether the required data-processing agreement has been concluded.
Microsoft Azure Communication Services is used to send booking invitations, verification messages, confirmations, status messages, and cancellation links. Microsoft may receive the recipient's email address and the business, service, appointment, and link information included in the message. Microsoft states that email content is processed in real time using the configured data location, that diagnostic data required to provide the service is collected, and that recipient addresses associated with hard bounces may be retained temporarily for abuse prevention. The Azure contracting entity, configured data location, diagnostic settings, and applicable international-transfer safeguards.
BlueMarke is based in Canada, so information relating to European users may be accessed or otherwise processed in Canada. The European Commission recognizes Canada as adequate for transfers to commercial organizations, but whether that decision covers BlueMarke's final legal entity and each relevant data flow. Any required EU representative and additional transfer safeguards must be established before publication.
Server logs are retained for up to seven days. The Local Storage language preference remains until it is changed or cleared. Retention periods for appointment records, booking invitations, correspondence, and Microsoft email records. The current booking implementation has no automatic deletion schedule, so a retention schedule must be approved and implemented before this notice is published. No separate automated hosting backups are currently configured.
Your rights, complaints, and changes
Depending on the law that applies, you may request access to and correction of your personal information, ask for deletion or restriction, receive certain information in a portable format, or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent for the future. GDPR rights are subject to their statutory conditions and exceptions. BlueMarke may need to verify your identity before responding to a request.
For questions about a particular appointment or a participating business's services, contact that business through the details on its public profile. Requests concerning BlueMarke's own processing should be sent.
You may raise a concern with the Office of the Privacy Commissioner of Canada. If the GDPR applies, you may also lodge a complaint with a supervisory authority, particularly in the EU or EEA country where you live, work, or believe an infringement occurred. These complaint rights do not prevent you from using other administrative or judicial remedies.
BlueMarke may update this notice when its service, providers, or legal obligations change. The current version and its update date will be published on this page. Material changes will be communicated through an appropriate channel where required.