01Data Controller
The "Data Controller" responsible for your personal data under the GDPR and other applicable privacy laws is:
Filip Mihálik, sole trader (živnostník)
Trading as Vantage Strategic Systems via exitblueprint.io
Registered seat: Karpatské námestie 7770/10A, 831 06 Bratislava-Rača, Slovak Republic
Company ID (IČO): 57 556 199
Privacy contact: vantage@exitblueprint.io
I am registered as a sole trader in the Slovak Trade Register and act as the controller within the meaning of Article 4(7) of the GDPR. A Data Protection Officer (DPO) is not required under Article 37 GDPR, for any privacy matter, contact me directly at the email above.
02Scope & Definitions
This Privacy Policy applies to personal data collected through:
- The website exitblueprint.io and any subdomain we operate, hosted on Netlify, Inc.
- Email subscriptions, lead-magnet downloads (free PDF e-book and Notion template), and other forms hosted on the website, managed via MailerLite
- Purchases of our digital products and Top-Up Packs processed through Lemon Squeezy (our Merchant of Record) checkout
- The Vantage Suite at vantagesuite.xyz, our AI-powered web application, including account creation, passwordless magic-link sign-in, Credits and Product Runs, and Fair-Use Tools, with authentication and application data managed via Supabase (database hosted in West US (Oregon), United States, AWS region
us-west-2), application servers hosted on Fly.io in Frankfurt, Germany, and AI processing performed by Anthropic - Automated product and access delivery after purchase, handled via MailerLite
- Invoice creation and accounting records managed via SuperFaktúra
- Email correspondence sent to or from vantage@exitblueprint.io (hosted on Hostinger hMail).
Key terms
- Personal data → any information relating to an identified or identifiable natural person (e.g., name, email, IP address).
- Processing → any operation performed on personal data (collection, storage, use, disclosure, deletion).
- Controller → the entity that determines the purposes and means of processing (us).
- Processor → a third party that processes personal data on our behalf and under our documented instructions (e.g., MailerLite, Supabase, Netlify).
- DPA → Data Processing Agreement, a written contract between us and a processor specifying responsibilities, security measures, and sub-processor rules, required by Art. 28 GDPR.
- SCC → Standard Contractual Clauses, standard clauses adopted by the European Commission (Decision 2021/914) used to lawfully transfer personal data to non-EEA countries.
- DPF → EU-US Data Privacy Framework, an adequacy decision adopted by the European Commission on 10 July 2023 (Decision C(2023) 4745) that allows transfers to certified US organisations without additional safeguards.
- You → any visitor, subscriber, or customer interacting with our website or services.
03Data We Collect
We collect only the data we need to operate the website, deliver our products, and communicate with you. We do not buy email lists, scrape data, or process special categories of personal data (e.g., health, religion, biometrics).
| Category | Examples | Source |
|---|---|---|
| Identification & contact | First name (optional), email address | You, via newsletter / lead-magnet form or checkout |
| Transaction data | Email, billing name, billing country, last 4 digits of card, transaction ID, products and Top-Up Packs purchased, amount, currency, VAT/tax info | You, via Lemon Squeezy checkout, our Merchant of Record (we do not see or store full card numbers) |
| Invoicing data | Name, billing address, company details (optional), purchase amount, VAT number (optional) | You, transferred to SuperFaktúra for invoice generation |
| Vantage Suite account data | Email address, Account identifier, Tier (FREE / CORE / MASTER), magic-link sign-in tokens and timestamps, Credit balance, Product Run history and counts, Fair-Use Tool usage counters | You and the Suite, via Supabase authentication and application database |
| Suite content & AI inputs | Text, business descriptions, ideas, briefs, drafts, and other inputs you type into Suite fields, your optional Brand Kit (brand name, logo, colours, fonts), and the AI-generated Output returned to you | You, when you use AI-powered features. The text you submit is sent to Anthropic to generate the Output. See Section 3.1. |
| Consent records | Your email address, the timestamp of your agreement, the version identifier of the Terms and Privacy Policy you agreed to, what you agreed to, and your browser user-agent string | You, when you accept our Terms and this Policy in the Suite. Stored as our legal audit trail under Art. 7(1) GDPR. |
| Sign-up consent evidence | Whether you gave marketing consent (yes / no), the version identifier of the consent wording you were shown, and which page you signed up from. For marketing sign-ups, MailerLite additionally records the double opt-in timestamp and the IP address used to confirm. | You, when you submit the sign-up form. Stored so we can prove not only that you consented but exactly what wording you agreed to, as required by Art. 7(1) GDPR. |
| Payment webhook events | Purchase event identifiers received from Lemon Squeezy | Lemon Squeezy, automatically, so we can grant your Tier and Credits without granting the same purchase twice |
| Marketing engagement | Which links you clicked in our marketing emails, subscriber tags, unsubscribe status, time of subscription. We do not track whether you opened an email. | MailerLite, when you interact with our emails |
| Technical & usage data | IP address (truncated / anonymised), browser type, device type, operating system, referring URL, pages viewed, time on page, country / region (approx.) | Automatically, via Netlify server logs and Google Analytics 4 (analytics only after consent) |
| Email correspondence | Content of emails you send us, support requests, replies | You, when you contact us at vantage@exitblueprint.io (stored on Hostinger hMail servers) |
| Cookies & web storage | Cookie IDs, consent preferences (localStorage), session identifiers, analytics identifiers | Your device, see Section 10 for full details |
Government IDs, passport numbers, social security numbers, full payment-card numbers, passwords (the Suite is passwordless), health data, biometric data, precise GPS location, or any data we do not need for the purposes described in this policy. We do not store your IP address in the Vantage Suite application database.
3.1 What the Vantage Suite stores, table by table
So you can see exactly what exists about you, this is the complete inventory of the Vantage Suite application database (hosted on Supabase, in the West US (Oregon) region of the United States, AWS us-west-2):
| Table | What it holds | Why |
|---|---|---|
users | Your email address, Tier (FREE / CORE / MASTER), Credit balance, your plan version (which recorded your allowances at the time of purchase), and a suspension flag and reason if your Account has ever been restricted | To identify your Account, grant the right level of access, track your Credit balance, and apply the limits that were in force when you bought |
projects | The finished products you save, including the title, all generated text, the export formats you chose, and your Brand Kit (your uploaded logo stored as an embedded image, your colours and fonts) | So your work persists between sessions and you can return to it, this is your library |
ideas | The ideas you save, including the niche, the pain point, the generated product proposals, niche scores, and buyer personas | So your saved ideas remain available in your Vault |
usage_counters | Per-Account counts of metered actions, with timestamps. No content is stored here, only counts. | To enforce your Credit balance and fair-use limits accurately and to detect abuse |
consent_records | Your email address, the timestamp you agreed, the version of the Terms and Privacy Policy in force at that moment, what you agreed to, and your browser user-agent string | Our legal audit trail proving valid consent and acceptance, required under Art. 7(1) GDPR |
webhook_events | Purchase event identifiers received from Lemon Squeezy | De-duplication only, so a single purchase cannot accidentally grant your Tier or Credits twice |
We do not store payment-card data, passwords, or IP addresses in this database. Authentication is passwordless, based on one-time magic links sent to your email address.
3.2 What is sent to our AI provider, and what is not
When you run a generation, the text you typed into the input fields is transmitted to Anthropic so the AI model can produce your Output. To keep this minimal:
- Your account email address is not sent to Anthropic. Neither is your Account identifier, your Tier, your Credit balance, your billing data, or your payment information. The AI provider receives the content of your brief, not your identity.
- Only the specific fields relevant to the generation you requested are transmitted, together with our own system instructions.
- Input fields are length-limited, ranging from roughly 600 to 30,000 characters depending on the field, which caps how much text can ever leave our systems in a single request.
- Anthropic processes this data as our processor under its commercial terms and does not use it to train its models.
Because your inputs are transmitted to a third-party AI provider, you must not type into any Suite field: personal data about other people (customer lists, client names, subscriber emails, contact details, exported CRM data), special categories of data under Art. 9 GDPR (health, biometric, genetic, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation), third-party confidential or trade-secret information, or any credentials, API keys, or payment-card data.
The Suite is designed for your own business ideas, topics, and briefs. If you enter third-party personal data anyway, you become the controller of that data and are responsible for having a lawful basis for it. See Section 9.3 of our Terms & Conditions.
04How We Use Your Data
We use your personal data only for the specific purposes listed below. We do not sell your data, and we do not use it for purposes incompatible with the original purpose of collection.
4.1 Delivering the lead magnet
When you submit your email to receive the free PDF e-book, the Notion template or MODULE ZERO, we use your email address for one thing: to send you the file you asked for, via a MailerLite automation.
Our sign-up form carries two separate tick boxes and they do different jobs:
- The required box is your acceptance of our Terms and your confirmation that you have read this Policy. It is not consent to anything, it is the contract under which we supply you the file.
- The optional box is your consent to marketing email. Leaving it unticked still gets you the file. Nothing is withheld, delayed or degraded because you declined.
Neither box is pre-ticked. We keep them separate deliberately, because bundling consent together with other matters would not satisfy Art. 7(2) GDPR, and making the free file conditional on marketing consent would call into question whether that consent was freely given at all under Art. 7(4) GDPR.
What happens next depends on that second box:
- If you did not tick it, we simply send the file. There is no confirmation step, because there is no subscription to confirm, and we add you to no marketing audience.
- If you ticked it, we first send a double opt-in confirmation message. Only after you click the link in it do we send the file and add you to the newsletter audience.
4.2 Email marketing & product education
If you gave marketing consent and confirmed it via double opt-in, we send you:
- Educational and onboarding emails about our digital products and the topics they cover.
- Promotional offers, discounts, launches, and announcements.
- Occasional newsletter content related to faceless digital business, content systems, and product creation.
Every marketing email contains a one-click unsubscribe link. You can withdraw consent at any time, free of charge, with no negative consequences. Withdrawing marketing consent does not take away any file you already received, and it does not affect your Vantage Suite Account, your Tier, or your Credits.
Because these are two different audiences held separately in MailerLite, unsubscribing from marketing does not delete your record where we still need it for something else (for example your Tier entitlement). If you want your data erased outright rather than just unsubscribed, use your Art. 17 right in Section 11.
4.3 Selling and delivering digital products
When you purchase a product or Top-Up Pack, we use your data to process the payment via Lemon Squeezy (our Merchant of Record), trigger the automated product and access delivery email via MailerLite, provide customer support, generate invoices via SuperFaktúra, and meet our tax and accounting obligations under Slovak and EU law.
4.4 Operating the Vantage Suite
When you use the Vantage Suite, we process your Account data to (a) create and authenticate your Account via passwordless magic-link sign-in (Supabase), (b) determine your Tier and the features available to you, (c) track and enforce your Credit balance, Product Runs, and Fair-Use Tool limits, (d) store and return the work you save, and (e) provide customer support. This processing is necessary to perform our contract with you (Art. 6(1)(b) GDPR).
Your entitlement Tier is determined by your record in MailerLite, which is our source of truth for what you purchased. When you sign in, the Suite checks your email address against that record to establish whether you hold FREE, CORE, or MASTER access. This is why your Suite email address must be the same address you purchased with.
Creating a Vantage Suite Account does not by itself subscribe you to our marketing emails. Suite users and newsletter subscribers are kept as separate audiences in MailerLite. We will only send you marketing emails if you give a separate, double opt-in marketing consent, and you can withdraw it at any time via the unsubscribe link.
4.5 AI-powered features
When you use an AI-powered feature, the text you submit is sent to Anthropic, which processes it on our behalf to generate the requested Output and return it to you. We use this data only to provide the feature to you. We do not use your inputs or Output to train or fine-tune AI models, and Anthropic processes the data as our processor under its commercial terms, which do not use submitted data to train its models. Your account email address is not sent to Anthropic. The legal basis is performance of our contract with you (Art. 6(1)(b) GDPR). See Section 3.2 for the full detail of what is and is not transmitted.
4.5a AI-generation marking
Assets generated by the Suite carry a machine-readable marking in their file metadata identifying them as artificially generated, in line with Article 50(2) of Regulation (EU) 2024/1689 (the EU AI Act). This marking describes the file, not you. It does not contain your email address, your Account identifier, or any other personal data about you.
4.6 Operating, securing, and improving the website
We use technical data from Netlify server logs, our security and delivery layer (Cloudflare), and, where you consent, Google Analytics 4 to keep the site running, prevent fraud and abuse, mitigate attacks, fix bugs, and understand which content is most useful so we can improve it.
4.7 Legal compliance
We process and retain certain data to comply with applicable Slovak and EU laws, including the Accounting Act, VAT Act (EU OSS for cross-border digital sales), and consumer-protection rules.
05Legal Basis for Processing (GDPR)
Under Article 6 of the GDPR, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Delivering the lead magnet you asked for (the free e-book, Notion template and MODULE ZERO) | Performance of a contract, Art. 6(1)(b) GDPR. You requested the file and we supply it. This is a contract for the supply of digital content free of charge in exchange for personal data, within the meaning of Art. 3(1) of Directive (EU) 2019/770. It does not require your marketing consent and we do not withhold the file if you decline marketing. |
| Sending you marketing emails (THE [ SIGNAL ] newsletter, offers, launches) | Consent, Art. 6(1)(a) GDPR. A separate, freely given, specific, informed and unambiguous opt-in, given via its own tick box that is never pre-ticked and never a condition of receiving anything else, and confirmed by double opt-in. |
| Processing your purchase and delivering the product | Performance of a contract, Art. 6(1)(b) GDPR. |
| Operating the Vantage Suite (account, magic-link sign-in, Credits, Product Runs, Fair-Use Tools) and processing your prompts via Anthropic to generate AI output | Performance of a contract, Art. 6(1)(b) GDPR. We process your inputs only to provide the feature; we do not use them to train AI models. |
| Hosting the Vantage Suite application backend on Fly.io (Frankfurt, Germany) | Performance of a contract, Art. 6(1)(b) GDPR. Necessary to run the application you purchased access to. |
Keeping consent_records (email, timestamp, policy version, agreement, user-agent) | Legal obligation, Art. 6(1)(c) GDPR read with Art. 7(1) GDPR, we must be able to demonstrate that you consented and what you agreed to. Also our legitimate interest, Art. 6(1)(f), in establishing and defending legal claims. |
Keeping webhook_events from Lemon Squeezy | Performance of a contract, Art. 6(1)(b) GDPR (granting the Tier and Credits you paid for), and legitimate interest, Art. 6(1)(f), in preventing duplicate or fraudulent grants. |
| Security, abuse prevention, and attack mitigation via Cloudflare | Legitimate interest, Art. 6(1)(f) GDPR. Necessary to keep the Service secure and available. |
| Issuing invoices (via SuperFaktúra), keeping accounting records, fulfilling tax and VAT obligations | Legal obligation, Art. 6(1)(c) GDPR (Slovak Accounting Act, VAT Act, EU OSS rules). |
| Sending follow-up emails to existing customers about similar digital products | Legitimate interest, Art. 6(1)(f) GDPR (soft opt-in for direct marketing to existing customers, balanced against your rights). You can object at any time. |
| Netlify infrastructure logging (server logs for security and operation) | Legitimate interest, Art. 6(1)(f) GDPR. Necessary for secure, reliable hosting, logs are minimised and retained for a limited period. |
| Essential cookies / web storage, fraud prevention, website security | Legitimate interest, Art. 6(1)(f) GDPR. |
| Analytics cookies (Google Analytics 4) | Consent, Art. 6(1)(a) GDPR + ePrivacy Directive. Loaded only after you opt in via the cookie banner. |
Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. To withdraw, click "unsubscribe" in any email, change your cookie preferences via the cookie banner or the "Cookie Settings" link in the footer, or email vantage@exitblueprint.io.
07Data Processing Agreements, SCCs & DPF
Under Article 28 of the GDPR, every processor we engage must sign a Data Processing Agreement (DPA) that obliges them to process data only on our documented instructions, maintain appropriate technical and organisational security measures, assist us in fulfilling data-subject rights, delete or return data upon termination, and make available all information necessary to demonstrate compliance.
For transfers of personal data to countries outside the European Economic Area (EEA), we rely on one or more of the following legally recognised transfer mechanisms:
- EU-US Data Privacy Framework (DPF) → adequacy decision adopted by the European Commission on 10 July 2023 (C(2023) 4745), allowing transfers to certified US organisations without further safeguards. The DPF list is maintained by the US Department of Commerce at dataprivacyframework.gov.
- Standard Contractual Clauses (SCCs) → module-specific clauses adopted by the European Commission via Implementing Decision (EU) 2021/914 of 4 June 2021. We use Controller-to-Processor (Module 2) SCCs with all non-EEA processors.
- Adequacy decision → where the European Commission has determined that a third country provides an essentially equivalent level of protection (e.g., UK under the adequacy decision of 28 June 2021).
7.1 DPA and transfer mechanism per processor
| Processor | DPA in place | Transfer mechanism | Reference / DPA location |
|---|---|---|---|
| MailerLite UAB MailerLite, EU |
Yes, signed automatically upon account creation and available in account settings | Intra-EU primary processing (Lithuania). US sub-processors covered by SCCs (Module 2, Decision 2021/914) incorporated into MailerLite's DPA. | mailerlite.com/legal/data-processing-agreement |
| Lemon Squeezy Lemon Squeezy, LLC, US (Merchant of Record) |
Yes, Lemon Squeezy's Data Processing Addendum is part of their standard terms | As Merchant of Record, Lemon Squeezy is the reseller of record. For personal data processed on our behalf, transfers to the US rely on SCCs (Module 2) and/or DPF where certified, incorporated into Lemon Squeezy's DPA. | lemonsqueezy.com/legal |
| Supabase, Inc. US company, US region (Oregon) |
Yes, Supabase's Data Processing Addendum is available and incorporated into its terms | Suite authentication and database. Our Supabase project is hosted in the West US (Oregon) region of the United States (AWS us-west-2), so your Account and application data is stored at rest in the United States. This transfer relies on SCCs (Module 2) and/or DPF where certified, incorporated into Supabase's DPA. We will notify you if we change this region. |
supabase.com/legal/dpa |
| Fly.io, Inc. US company, EU region (Frankfurt) |
Yes, Fly.io's Data Processing Addendum is incorporated into its terms of service | Our Suite application servers are pinned to the Frankfurt (fra) region in Germany, so this processing takes place inside the EEA. Fly.io is a US-incorporated company, so SCCs (Module 2) incorporated into its DPA cover any administrative or support access from the US. | fly.io/legal/dpa |
| Anthropic, PBC US |
Yes, Anthropic's Data Processing Addendum applies to commercial API use | AI processing of submitted prompts and content. Transfers to the US rely on SCCs (Module 2) and/or DPF where certified. Anthropic does not train on data submitted via its commercial terms. | anthropic.com/legal |
| Cloudflare, Inc. US |
Yes, Cloudflare's Data Processing Addendum is part of its self-serve subscription agreement | DPF-certified + SCCs (Module 2) incorporated into Cloudflare's DPA for EEA-originating traffic. Cloudflare acts as a processor for security and CDN log data. | cloudflare.com, customer DPA |
| Google LLC Google Analytics 4, US |
Yes, Google Measurement Controller-Controller Data Protection Terms / Google Analytics Data Processing Terms | DPF-certified (Google LLC listed on dataprivacyframework.gov) + SCCs (Module 2) incorporated into Google's Data Processing Amendment. IP anonymisation enabled in our GA4 configuration, advertising features disabled. | Google Ads / Analytics DPA |
| Netlify, Inc. US |
Yes, Netlify's Data Processing Agreement (DPA) is available and accepted as part of the Netlify Terms of Service | DPF-certified (Netlify, Inc. listed on dataprivacyframework.gov) + SCCs (Module 2) incorporated into Netlify's DPA for EEA-originating data. Netlify acts as a data processor for server-level log data. | netlify.com/legal/data-processing-agreement |
| Hostinger International Ltd hMail, EU (Lithuania) |
Yes, Hostinger's DPA is incorporated into their Terms of Service and Privacy Policy | Primarily intra-EU processing. No third-country transfer for standard email hosting under Hostinger's EU infrastructure. SCCs apply where sub-processors outside EEA are involved. | hostinger.com/privacy-policy |
| SuperFaktúra, s.r.o. EU, Slovak Republic |
Yes, DPA available as part of SuperFaktúra's Terms of Service for business accounts | EU-based company and infrastructure, no third-country transfer. Processing stays within the EEA. | superfaktura.sk, Privacy |
You have the right to receive a copy of the relevant transfer safeguards (SCCs, DPF certification references, or DPA excerpts) for any processor. Send your request to vantage@exitblueprint.io with the subject line "Transfer safeguards request". We will respond within 30 days.
7.2 UK residents
For residents of the United Kingdom, the UK adequacy regulations recognise the EU as providing adequate protection (and vice versa under the EU-UK adequacy decisions of 28 June 2021). Transfers from the UK to processors in the US are covered by the UK International Data Transfer Agreement (IDTA) and/or UK Addendum to EU SCCs, incorporated into the relevant processor DPAs. The UK's equivalent of the DPF is the UK Extension to the DPF, for certified US organisations.
7.3 Swiss residents
Switzerland is recognised as providing adequate protection under EU Commission adequacy decisions. For transfers from Switzerland to the US, we rely on SCCs adapted for Switzerland per the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the Swiss-US Data Privacy Framework.
08International Transfers, Summary
The following processors involve transfers of personal data outside the EEA:
| Processor | Transfer destination | Mechanism | Conditions |
|---|---|---|---|
| Google LLC (GA4) | United States | DPF + SCCs (Module 2) | Only triggered after explicit cookie consent. IP anonymisation active. Advertising features disabled. |
| Netlify, Inc. | United States (CDN nodes worldwide) | DPF + SCCs (Module 2) | Automatic for all site visitors, server log data only. No content-level user data stored by Netlify beyond standard infrastructure logs. |
| Lemon Squeezy, LLC (Merchant of Record) | United States | SCCs (Module 2) + DPF where certified | Only triggered upon purchase. Acts as reseller of record and handles tax collection and remittance. |
| Supabase, Inc. | United States → West US (Oregon), AWS us-west-2 | SCCs (Module 2) + DPF where certified | Triggered when you create or use a Vantage Suite Account. Stores authentication and application data at rest in the United States. |
| Anthropic, PBC | United States | SCCs (Module 2) + DPF where certified | Triggered when you use an AI-powered feature. The text you typed is transmitted, your email address is not. No training on submitted data under commercial terms. |
| Cloudflare, Inc. | United States (global edge network) | DPF + SCCs (Module 2) | Automatic for traffic passing through Cloudflare. Security and CDN log data only. |
| MailerLite (US sub-processors) | United States (via sub-processors) | SCCs (Module 2) per MailerLite's DPA | Primary processing in EU (Lithuania). Sub-processors listed in MailerLite's sub-processor register. |
Hostinger (hMail) and SuperFaktúra process data within the EU only. Our Vantage Suite application servers on Fly.io are pinned to Frankfurt, Germany, so that processing takes place inside the EEA, although Fly.io is a US-incorporated company and SCCs cover any US administrative access.
The Vantage Suite is split between two regions, and we would rather state it precisely than let the Frankfurt reference above imply more than it should:
- Compute, in the EEA. The server processes that receive your request and run your generation are pinned to Frankfurt, Germany on Fly.io. Your data passes through memory there during processing, it is not our persistent store.
- Storage, in the United States. Our Supabase database, which holds your Account, your saved projects and ideas, your usage counters, and your consent record, is hosted in the West US (Oregon) region (AWS
us-west-2). This is where your Suite data is stored at rest. - AI processing, in the United States. The text you submit is sent to Anthropic in the US, without your email address or Account identifier.
In short, EEA compute does not mean EEA storage. Your Suite data rests in the United States under SCCs (Module 2) and, where the provider is certified, the EU-US Data Privacy Framework.
We want to be plain about this rather than imply otherwise. We do not claim that your data never leaves the European Union. It does. In particular, the text you enter into the Vantage Suite is transmitted to Anthropic in the United States for AI processing, your purchase data is processed by Lemon Squeezy in the United States, and your Account and application data sit in a database operated by Supabase, a US-incorporated company, which we host in the West US (Oregon) region of the United States. These transfers are lawful and are protected by the mechanisms described above (SCCs and, where the provider is certified, the EU-US Data Privacy Framework), but they are real transfers to a third country and you should understand that before using the Suite.
We continuously monitor changes to transfer mechanisms and update our arrangements as required. If the legal basis for any transfer is invalidated by a court or supervisory authority, we will suspend the transfer and notify you.
09Retention Periods
We keep personal data only as long as necessary for the purposes described in this policy, and then either delete it or anonymise it.
| Data type | Retention period |
|---|---|
| Newsletter subscribers (email + engagement data in MailerLite) | Until you unsubscribe. We review the list periodically and remove subscribers who have been completely inactive for 24 months. You can leave at any time using the unsubscribe link, or ask us to erase your record under Section 11. |
| Unconfirmed double-opt-in signups | Retained only while the signup could still be confirmed. We review and remove unconfirmed records periodically, and in any event they are never sent marketing email, because an unconfirmed record has not given consent. |
| Lead-magnet recipients who declined marketing | Kept only as long as needed to deliver the file and to evidence that we were entitled to send it, then reviewed and removed. These records sit in a separate audience and are never mailed marketing. In practice we remove them 12 months after delivery unless you have since become a customer or subscriber. |
| Sign-up consent evidence (marketing flag, consent wording version, double opt-in timestamp and IP) | Kept for as long as we rely on that consent, and for 3 years after it is withdrawn or lapses, so we can answer a challenge about whether we were entitled to email you. Art. 7(1) GDPR requires us to be able to demonstrate consent. |
| Customer / transaction records (Lemon Squeezy checkout) | 10 years from the end of the relevant accounting period (Slovak Accounting Act §35) |
| Invoices and tax records (SuperFaktúra) | 10 years (Slovak VAT Act and Accounting Act) |
Vantage Suite Account data (users, projects, ideas, usage_counters) | For as long as your Account exists, see the explanation below. Deleted immediately and irreversibly when you delete your Account. |
| Suite content & AI Output | Kept as long as your Account exists so your library remains available to you. Deleted when you delete your Account. Anthropic does not retain your submitted data to train its models. |
Consent records (consent_records) | Kept as our legal audit trail for the life of your Account. Deleted when you delete your Account. |
Payment webhook identifiers (webhook_events) | Kept while needed to prevent a purchase being granted twice |
| Database backups | None held at present. Our current plan includes no restorable snapshot backups or point-in-time recovery, so there is no secondary copy in which your deleted data survives. This will change when we move to a backed-up plan, and we will state the backup retention window here before that happens. See Section 9.3. |
Cookie consent record (localStorage → exitblueprint_consent) | Up to 12 months, re-prompt after expiry |
| Google Analytics 4 data (_ga, _ga_W8TXJLVNN9 cookies and associated reports) | Cookies → up to 13 months. User- and event-level data inside our GA4 property → 2 months, the shortest retention Google offers, after which Google deletes it automatically. Aggregated, anonymised reports may be kept indefinitely. |
| Netlify server / access logs | Up to 30 days per Netlify's standard infrastructure log retention policy |
| Email correspondence, support & business (Hostinger hMail) | Up to 3 years from last contact, unless required longer for legal claims |
9.1 Why Suite data is kept for as long as your Account exists
We deliberately do not auto-delete your Vantage Suite work after a fixed period. The reason is that your Account is your library. You paid a one-off price for access, your Credits never expire, and the guides, ideas, and assets you have generated are the thing you bought. Deleting them on a timer would destroy the value of the purchase and would surprise you in a way that is worse, not better, for your rights.
Retention is therefore tied to your decision, not to a clock. Your data stays for as long as you keep the Account, and goes the moment you delete it. This satisfies the storage-limitation principle in Art. 5(1)(e) GDPR, because the retention period is defined by the purpose (giving you continued access to what you purchased) and you can end it yourself at any time in one click.
9.2 Self-service export and deletion
You do not need to email us or wait 30 days to exercise these rights. Both are built into the Suite, under Account:
| Function | What it does |
|---|---|
| EXPORT VAULT | Downloads a single zip archive containing every product you have created as readable Markdown, the full structured copy of each one, all of your saved ideas, and a summary of your profile. Immediate and free of charge. This is your Art. 15 (access) and Art. 20 (portability) right, self-served in a structured, commonly used, machine-readable format. We recommend running an export before you delete anything. |
| DELETE ACCOUNT | Permanently deletes your Account, all your saved products and ideas, your usage counters, your consent log, and your record on our mailing list. To prevent accidents, you must retype your account email address to confirm. This is your Art. 17 (erasure) right, self-served. |
When you use DELETE ACCOUNT:
- Your Account, your saved projects, your ideas, your Vault, your Brand Kit, your usage counters, your consent log, and your record on our mailing list are permanently deleted. We cannot restore them, we do not keep a backup copy for you, and there is no grace period or recycle bin.
- Any remaining Credits are lost, along with your Tier access, and are not refunded, transferred, or reinstated. If you later purchase again, you start fresh.
- Files you have already downloaded to your own device are yours and are unaffected.
- Purchase, invoice, and transaction records held by Lemon Squeezy (our Merchant of Record) and in our accounting records are retained, even after you delete your Account. Deleting your Account does not and cannot delete them. We are legally required to keep them under the Slovak Accounting Act (§35) and VAT rules for 10 years, and Art. 17(3)(b) GDPR expressly permits this. This is the one category of data that deletion does not remove.
- You must retype your account email address to confirm, so this cannot happen by a misclick.
Export first, delete second. Once deletion completes, your work cannot be recovered by us or by you.
9.3 Backups, restoration, and the honest state of it
Article 32(1)(c) GDPR asks us to have "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident." Article 32(1) also says the measures we take must be appropriate to the risk, judged against the state of the art, the costs of implementation, and the nature and scope of what we process. This section sets out our position against that standard, plainly, including the part that is not flattering.
What we currently do and do not have
Our Supabase project currently runs on a plan that does not include restorable snapshot backups or point-in-time recovery. The database itself runs on our provider's managed, redundant infrastructure, so it is not sitting on a single unprotected disk, but to be exact about the distinction that matters: we do not presently hold a backup we could restore your Account from if the database were destroyed or corrupted. We are a newly launched sole-trader business and this reflects what we can currently fund, not a view that backups are unnecessary.
The two consequences, one good and one not
- In your favour. When a record is deleted it is deleted from the only copy that exists. There is no nightly snapshot and no archive in which your data quietly survives for weeks after you asked us to erase it. Your Article 17 erasure is genuinely immediate and complete, which is more than many services can honestly say.
- Against you. We cannot restore your work if you delete it by mistake, and we could not reconstruct it after a catastrophic failure at our provider. There is no recycle bin and no support ticket that recovers it.
How we compensate for this in the meantime
- You hold the restorable copy. EXPORT VAULT gives you, at any time and free of charge, a complete zip of everything you have created in readable Markdown. Restoration capability exists, it simply sits with you rather than with us. Run an export periodically, not only before deleting, and keep it somewhere you control.
- There is very little to lose. We deliberately hold no passwords, no payment-card data and no IP addresses in this database, and your invoices, purchase records and Tier entitlement live outside it, with Lemon Squeezy, SuperFaktúra and MailerLite. A total loss of the Suite database would not expose or destroy your financial or identity records, and would not erase proof of what you purchased.
- Encryption and access control as described in Section 14 continue to apply to the live database.
- Availability of the Service itself is a separate commitment and is unaffected, see Section 11.7 of our Terms & Conditions.
We will move the Suite database onto a plan with automated daily backups as soon as the business can fund it, which we expect to be shortly after the first paying customers. When that happens we will update this section before the change takes effect and state the backup retention window, where those backups are stored, and how deleted data is purged from them, so that our Article 17 promise above stays accurate rather than quietly becoming untrue.
If this position is not acceptable to you, that is a legitimate reason not to create an Account, and we would rather you knew before you paid than after. If you have already purchased and this changes your mind, contact us at vantage@exitblueprint.io.
11Your Rights Under the GDPR
If the GDPR applies to you (e.g., you are in the EEA, UK, or Switzerland), you have the following rights:
- Right of access (Art. 15) → to know what personal data we hold about you and to receive a copy.
- Right to rectification (Art. 16) → to correct inaccurate or incomplete data.
- Right to erasure / "right to be forgotten" (Art. 17) → to request deletion of your data, subject to legal retention obligations (e.g., invoices must be kept 10 years).
- Right to restriction of processing (Art. 18) → to limit how we process your data in certain situations.
- Right to data portability (Art. 20) → to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) → including the absolute right to object to direct marketing at any time, without needing to give a reason.
- Right to withdraw consent (Art. 7(3)) → at any time, without affecting prior lawful processing.
- Right not to be subject to automated decision-making (Art. 22) → see Section 15.
- Right to lodge a complaint with a supervisory authority, see Section 17.
If you have a Vantage Suite Account, you do not have to email us and wait. Under Account in the Suite you will find EXPORT VAULT (your Art. 15 and Art. 20 rights, an instant zip download of everything you have created) and DELETE ACCOUNT (your Art. 17 right, immediate and irreversible). See Section 9.2 for exactly what deletion removes and what we are legally required to keep.
To exercise any other right, email vantage@exitblueprint.io with the subject line "GDPR request". We will respond within 30 days, free of charge in most cases (Art. 12 GDPR). We may ask for proof of identity to make sure the request is genuine and to protect your data.
12California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"):
- Right to know → what categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties we share it with.
- Right to delete → request deletion of personal information we hold about you, subject to legal exceptions.
- Right to correct → request correction of inaccurate personal information.
- Right to opt out of sale or sharing → we do not sell personal information and we do not share it for cross-context behavioural advertising. There is therefore nothing to opt out of. If this changes, you will be notified and provided with a "Do Not Sell or Share My Personal Information" link.
- Right to limit use of sensitive personal information → we do not collect sensitive personal information as defined under the CCPA.
- Right to non-discrimination → we will not deny services, charge different prices, or provide a lesser quality of service because you exercised your rights.
Categories collected in the last 12 months (CCPA disclosure)
- Identifiers (name, email, IP address)
- Commercial information (purchase history)
- Internet / network activity (browsing, page views, interactions, analytics only with consent)
- Geolocation (approximate, country/region only)
- Inferences drawn from the above (e.g., topic interests for email segmentation)
To exercise your California rights, email vantage@exitblueprint.io with the subject line "CCPA request". You may also designate an authorised agent to make a request on your behalf, subject to verification. We respond within 45 days (extendable by a further 45 days with notice).
13Children's Privacy
Our website and products are intended for adults pursuing entrepreneurial and professional goals. We do not knowingly collect personal data from children under 16 years of age (or the equivalent minimum age under your local law, e.g., 13 under COPPA in the US). If you believe a child has provided us with personal data, contact us at vantage@exitblueprint.io and we will delete it promptly.
14Data Security
We apply technical and organisational measures appropriate to the risk, including:
- HTTPS / TLS encryption for all data transmitted between your browser and our website (enforced by Netlify's infrastructure).
- Strong, unique passwords and two-factor authentication on all critical accounts (Netlify, Cloudflare, Supabase, MailerLite, Lemon Squeezy, SuperFaktúra, Google, Hostinger).
- Passwordless authentication for the Vantage Suite via Supabase magic-link sign-in, no passwords are created or stored.
- Reputable processors with industry-standard certifications, Lemon Squeezy (PCI-DSS compliant payment partners), Supabase (SOC 2 Type II), Cloudflare (SOC 2 Type II, ISO 27001), MailerLite (SOC 2 Type II), Netlify (SOC 2 Type II), Google (ISO 27001, SOC 2, SOC 3), Hostinger (ISO 27001), Anthropic (SOC 2 Type II), Fly.io (SOC 2 Type II).
- Pinned hosting regions → the Vantage Suite backend runs on Fly.io machines pinned to the Frankfurt, Germany region, and our Supabase database is pinned to the West US (Oregon) region (AWS
us-west-2). Neither floats between regions, so we can always tell you where your data is. See Section 08. - Encryption at rest → the Suite database is encrypted at rest by Supabase, and all traffic between your browser, our application servers, and the database travels over TLS.
- Data minimisation by design → we do not store passwords, payment-card data, or IP addresses in the Suite database, and your account email address is never transmitted to our AI provider.
- Input length limits → Suite input fields are capped at between roughly 600 and 30,000 characters, limiting how much data can ever be submitted in a single request.
- Access control → access to personal data is limited to the controller and authorised processors on a strict need-to-know basis.
- Regular review of access rights, software updates, dependency patches, and security practices.
Despite these measures, no method of transmission over the internet is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by Art. 33 GDPR, and notify you without undue delay where required by Art. 34 GDPR.
15Automated Decision-Making & Profiling
We do not make decisions that produce legal or similarly significant effects on you based solely on automated processing (Art. 22 GDPR). Basic automation used in our operations includes:
- Sending the lead-magnet email automatically when you confirm your subscription via double opt-in (MailerLite).
- Triggering the product delivery email automatically after a confirmed purchase (MailerLite).
- Segmenting subscribers by topic interest or purchase status in MailerLite to send relevant content.
- Generating AI Output in the Vantage Suite (via Anthropic) in response to inputs you submit. This produces content for you to review and use at your discretion, it does not make any decision about you, your rights, or your access.
- Granting your Tier and Credits automatically when a purchase webhook is received from Lemon Squeezy, and automatically deducting Credits when you run a generation. These are arithmetic entitlement calculations based on what you paid for, not an assessment of you as a person.
- Automatically applying fair-use and free-tier limits when a counter is reached.
These automations are used for operational efficiency and content relevance only. They do not evaluate, profile, or score you in any way that affects your legal rights, access to services, or price paid.
15.1 Decisions about your Account are reviewed by a human
Where we warn, throttle, suspend, or terminate an Account for suspected misuse, the decision is not made solely by automated means. Automated signals may flag unusual usage for review, but the decision to restrict an Account is taken by a person. You also have an express right to contest any such decision and obtain human re-review, set out in Section 16.4 of our Terms & Conditions.
15.2 You are interacting with an AI system
In accordance with Article 50(1) of Regulation (EU) 2024/1689 (the EU AI Act), we inform you clearly that the Vantage Suite is an artificial-intelligence system and that the assets it produces are generated by AI, without human review. Assets are also marked as artificially generated in their file metadata under Art. 50(2), see Section 4.5a.
16Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other reasons. The "Last updated" date at the top of this page indicates when the policy was last revised.
The current version of this policy is 2026-08-11. Each version carries a dated identifier, and the identifier of the version you accepted is stored in your consent record (consent_records) alongside the timestamp of your acceptance. This means you can always establish exactly which text you agreed to, and when.
If changes are material, we will notify you in advance, for example, by email to subscribers or via a prominent notice on the website, and, where required by GDPR, ask for fresh consent. Your continued use of the website after the effective date constitutes acceptance of the updated policy.
17Contact & Complaints
For any privacy-related question, request, or complaint, contact us first, we aim to resolve all concerns directly and will respond within 30 days:
Filip Mihálik, Data Controller
Karpatské námestie 7770/10A, 831 06 Bratislava-Rača, Slovak Republic
IČO: 57 556 199
vantage@exitblueprint.io
Right to lodge a complaint
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with a data protection supervisory authority at any time, you do not need to contact us first, though we encourage it. The competent authority for our establishment is:
Úrad na ochranu osobných údajov Slovenskej republiky
(Office for Personal Data Protection of the Slovak Republic)
Hraničná 12, 820 07 Bratislava 27, Slovak Republic
dataprotection.gov.sk
EEA residents may alternatively lodge a complaint with the supervisory authority in their country of habitual residence or place of work (Art. 77 GDPR).
UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.
Swiss residents may contact the Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch.
California residents may contact the California Privacy Protection Agency (CPPA) at cppa.ca.gov or the California Attorney General's Office.