Privacy Policy
1. Who We Are
This Privacy Policy explains how BlitzAPI processes personal data in connection with its website and Services.
-
Company: BlitzAPI, a Société par Actions Simplifiée (SAS) registered in France
-
SIREN: 101 473 775
-
Registered address: 1 rue Marguerin, 75014 Paris, France
-
Privacy contact: antoine@blitz-api.ai
BlitzAPI acts as:
-
Data controller for website usage, account creation, billing, support, analytics, and for the professional B2B data we compile and make available through the Services;
-
Data processor when we process data that you submit to us strictly on your instructions and for your purposes (for example, a list of professional email addresses you upload for validation).
2. Scope of This Policy
This Policy applies to: the BlitzAPI website (blitz-api.ai); all BlitzAPI API endpoints (Search, Enrichment, Validation); customer accounts, billing, logs and API-usage data; and support and customer-success interactions.
It does not apply to: data you process outside BlitzAPI; or your CRM or third-party platforms connected to BlitzAPI.
3. B2B Only
BlitzAPI processes B2B professional data only. We do not process B2C data, personal (non-professional) email addresses, or consumer profiles.
4. Data We Process
4.1 Website & account data
-
Identifiers (IP address, browser, device)
-
Aggregated, cookieless website usage data (Vercel Web Analytics), where enabled
-
Contact-form entries (name, work email, company, topic, message), routed to our self-hosted form-processing tool to answer your request
-
Account information (email, password hash, billing information)
4.2 Professional B2B data made available through the Services
When you call our endpoints, we make available professional B2B data such as: professional email addresses; professional phone numbers; professional / LinkedIn URLs; job titles; and company information (domain name, company page, sector, size, location). We compile this data from publicly available and third-party professional sources, for legitimate B2B purposes.
4.3 Technical logs
-
Timestamp
-
IP address
-
Endpoint used
-
Error logs
Technical logs are stored for 30 days for security and operational integrity.
5. Data We Do NOT Process
BlitzAPI explicitly does not accept, process or store:
-
Personal / consumer data
-
Personal email addresses (Gmail, Yahoo, Proton, etc.)
-
Special categories of data (health, religion, political opinions, etc.)
-
Private or non-public information
-
Any data collected in violation of a third party’s terms of service
If such data is submitted by mistake, it is automatically rejected or deleted.
6. How We Use Data: Legal Bases
-
Performance of a contract: executing API calls; returning search, enrichment or validation results; managing accounts and billing; securing the Services.
-
Legitimate interests (B2B): improving API performance; preventing abuse and fraud; providing support and customer success; internal analytics and service optimisation. For the processing of professional B2B data, we rely on our legitimate interest in providing B2B business-information services and conduct a balancing test to ensure this interest does not override the rights and freedoms of data subjects.
-
Consent: optional marketing communications. Website usage measurement, where enabled, is aggregated and cookieless (see Section 14) and relies on our legitimate interest.
7. No Resale, No Sharing, No Enrichment from Customer Data
-
We do not resell data, datasets or enrichments, and we do not allow customers to do so (see our Terms & Conditions).
-
We do not use customer-provided data to enrich our own database.
-
We do not sell customer data to third parties.
-
During API operations, we do not transmit personal data to third-party services; all API operations are processed on BlitzAPI-controlled servers.
8. Data Subjects in Our B2B Data: Your Rights & Opt-Out
If your professional information is included in the data we make available, you have the right to object to our processing and to request access, rectification or deletion at any time.
-
We rely on legitimate interest for B2B prospecting data, and we honour objections.
-
On a valid request, we add your information to a suppression list so that it is not returned again through the Services.
-
To exercise these rights, or to opt out, contact us at antoine@blitz-api.ai.
9. Subprocessors & Third Parties
We use a limited set of subprocessors to operate the website, billing and analytics. We do not share personal data with third parties during API operations. The current categories are:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner | Hosting & encrypted storage | EU (Germany) |
| Vercel | Website hosting; aggregated, cookieless website analytics where enabled | EU / US (SCCs) |
| Hostinger | Hosting of our self-hosted contact-form processing tool (n8n) | EU |
| Stripe | Payment processing | EU / US (SCCs) |
| AWS | Certain infrastructure services | EU / US (SCCs) |
We may update this list as our providers evolve; material changes will be reflected in this Policy.
10. International Transfers
Our core infrastructure operates within the European Union. Some tools (e.g., Stripe, AWS) may involve transfers to the United States under Standard Contractual Clauses (SCCs) and appropriate safeguards under the GDPR. No personal data returned by the API is transferred outside the EU.
11. Data Security
We implement industry-standard measures, including:
-
Encryption in transit (HTTPS / TLS 1.2+)
-
Encrypted storage within Hetzner EU data centres
-
Network segregation
-
Access control and least-privilege internal policies
-
Regular auditing and monitoring
No raw API personal data is transmitted to any third-party provider.
12. Data Retention
-
Technical logs: 30 days.
-
Account & billing data: for the duration of the contractual relationship and as required by applicable law thereafter.
-
Professional B2B data: for as long as it remains accurate and useful for the Services; deleted or suppressed following a valid objection or erasure request.
13. Your Rights (GDPR)
You have the right to: access your personal data; rectify inaccurate information; request deletion; object to processing; restrict processing; export your data (portability); and, where processing relies on consent, withdraw that consent at any time.
Requests can be sent to antoine@blitz-api.ai. We will respond within 30 days. You also have the right to lodge a complaint with the French supervisory authority, the CNIL (https://www.cnil.fr).
14. Cookies
The public website (blitz-api.ai) sets no advertising or analytics cookies, and therefore shows no cookie banner. Where website usage measurement is enabled, it is cookieless and aggregated (Vercel Web Analytics): it does not identify individual visitors and stores nothing on your device.
Essential cookies (authentication, session) are used in the application (app.blitz-api.ai) after sign-in, strictly to operate your Account.
15. Children
The Services are not intended for minors. We do not knowingly process personal data of individuals under 16.
16. Customer Responsibilities
Users of BlitzAPI must: use the API only for lawful B2B purposes; not submit consumer data; not violate any third-party platform terms of service (including LinkedIn’s); not attempt to scrape private or restricted resources; and not build datasets, products or enrichment platforms using BlitzAPI outputs. BlitzAPI reserves the right to suspend accounts violating these principles.
17. Changes to This Policy
This Privacy Policy may be modified from time to time as our practices and legal requirements evolve. We will post the updated Policy with a new effective date and, for material changes, provide notice.
18. How to Contact Us
For any privacy question or request, contact us at antoine@blitz-api.ai.
Data controller: BlitzAPI SAS, 1 rue Marguerin, 75014 Paris, France.