Privacy Policy for Blendspace

Effective date: 22 April 2026
Last updated: 22 April 2026

This Privacy Policy describes how Blendlens s.r.o. ("Blendlens", "we", "us", or "our") collects, uses, stores, and protects personal data when you use Blendspace, including the Blendspace web application at app.blendspace.io, the Blendspace website at blendspace.io, our e-commerce plugins (for Shopify, Shoptet, WordPress, and similar platforms), and related services (together, the "Service").

Blendspace is offered worldwide. This Privacy Policy is primarily based on Regulation (EU) 2016/679 (the "GDPR") and Czech Act No. 110/2019 Coll., on the processing of personal data, which we apply as a baseline standard to all users regardless of location. Users in specific jurisdictions (including the United Kingdom, the European Economic Area, Switzerland, California, and other U.S. states) have additional rights described in Section 16 below.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for your personal data is:

We have not designated a Data Protection Officer. All privacy-related requests and questions, including requests to exercise your rights under Section 10, should be addressed to info@blendspace.io.

2. Scope of this Policy

This Privacy Policy applies to personal data we process as data controller, including:

When you embed Blendspace 3D previews or AR experiences on a third-party website (for example your e-shop), end-customer analytics events (impressions, AR views, viewer interactions) are collected. For these events Blendlens acts as a data processor on behalf of the business operating the embedding website, under a separate Data Processing Agreement (DPA). The operator of the embedding website remains the data controller for its end-customers.

3. Categories of Personal Data We Process

3.1 Account and contact data

3.2 Billing and subscription data

We do not store full payment card numbers or payment credentials. Card data is collected and processed directly by Stripe Payments Europe, Ltd., or by the Apple App Store / Google Play when you subscribe through those channels.

3.3 Technical and usage data

3.4 Content you upload or generate

Please do not upload images of identifiable individuals without their consent. Blendspace is intended for products and objects, not for images of people.

3.5 Embed analytics (as processor on behalf of our business customers)

When a visitor to an embedding website loads a Blendspace 3D preview or opens an AR view, we record events of the following types: Impression, AR View, and Viewer Interaction. Each event includes the model identifier, snippet identifier (if any), platform detected from the user-agent string, and timestamp. We do not collect IP addresses, cookies, or direct identifiers of end-customers for these events.

3.6 Plugin data (Shopify, Shoptet, WordPress)

When you install one of our e-commerce plugins, we collect the shop domain, the contact email of the shop owner, OAuth tokens issued by the platform, and product-to-model mapping. We use this data strictly to deliver the plugin's functionality.

3.7 Communications

If you contact us by email or through support channels, we retain the content of the correspondence and any attachments.

4. Sources of Personal Data

We obtain personal data:

5. Purposes and Legal Bases for Processing

Purpose Legal basis (GDPR Art. 6)
Providing the Service (account, hosting, 3D/AR previews, embeds, AI generation, format conversion) Performance of a contract — Art. 6(1)(b)
Processing payments, invoicing, subscription management Performance of a contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c)
Security, abuse prevention, audit logging, backups Legitimate interest — Art. 6(1)(f)
Product improvement and analytics on aggregated / anonymized data Legitimate interest — Art. 6(1)(f)
Service-related communications (transactional emails, system notifications) Performance of a contract — Art. 6(1)(b)
Marketing communications, newsletters, feature announcements Consent — Art. 6(1)(a); withdrawable at any time
Showcasing user-created content as Blendspace customer reference or in marketing Consent — Art. 6(1)(a) (opt-out in account settings)
Compliance with tax, accounting, and other legal obligations Legal obligation — Art. 6(1)(c)
Establishment, exercise, or defence of legal claims Legitimate interest — Art. 6(1)(f)

We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

6. Artificial Intelligence and Automated Processing

Blendspace uses AI and automated tooling to transform your uploaded images into 3D models and to convert between 3D formats. Specifically:

Input files and generated outputs are stored on our infrastructure only for as long as necessary to complete the job and to provide the resulting asset back to you. We do not use your content to train AI models.

6.1 AI Act transparency (EU Regulation 2024/1689)

Where Blendspace offers generative AI features, we act as a deployer of a general-purpose AI model within the meaning of the EU AI Act. The following disclosures are provided in compliance with Article 50 of the AI Act:

You must not submit photographs of identifiable individuals to our AI features without their explicit consent. Blendspace's generative AI is intended for products and objects, not for people.

7. Recipients and Processors

We share personal data only with carefully selected processors and recipients:

7.1 Infrastructure and hosting

7.2 Authentication

7.3 Payments and billing

7.4 Analytics, consent and communications

7.5 E-commerce platforms (upon your install)

7.6 Professional advisors, legal, and acquirers

We may disclose personal data to our accountants, auditors and lawyers under obligations of confidentiality, to public authorities when required by law, and to an acquirer in the event of a corporate reorganisation, merger or sale of assets (in each case with appropriate safeguards).

We do not sell your personal data.

8. International Transfers

Blendspace infrastructure is primarily hosted in the European Union (Microsoft Azure, regions West Europe and Sweden Central). Because Blendspace is a global service, if you access it from outside the EU/EEA your personal data will be transferred to, stored and processed in the European Union. Some of our processors (notably Google LLC, Apple Inc., Stripe entities, Hugging Face Inc., Microsoft Corporation) may also transfer or access data from countries outside the European Economic Area, including the United States.

Where transfers of personal data of EU/EEA, UK or Swiss data subjects occur, they are protected by:

You may request a copy of the relevant safeguards by contacting us at info@blendspace.io.

9. Retention

We retain personal data only for the period necessary for the purposes for which it was collected:

Where required to enforce legal claims or comply with applicable law, we may retain specific data longer.

10. Your Rights

Subject to the conditions and exceptions of the GDPR, you have the right to:

To exercise your rights, please contact us at info@blendspace.io. We will respond within one month of receiving your request; this period may be extended by up to two further months where necessary, taking into account the complexity and number of requests. We may need to verify your identity before processing a request.

Right to lodge a complaint. If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. For Blendlens s.r.o. the competent authority is the Úřad pro ochranu osobních údajů (Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic — www.uoou.cz.

11. Data Security

We implement appropriate technical and organisational measures, including:

No system is fully secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and, where required, inform you directly, in accordance with GDPR Articles 33–34.

12. Cookies and Similar Technologies

Our websites and applications use cookies and similar technologies (local storage) for authentication, preferences, security, and (with your consent) analytics and marketing. Detailed information, including the list of cookies and their purposes, is available in our Cookie Policy. You can manage your consent at any time through the consent banner on our site.

13. Third-Party Websites and Embedded Content

Blendspace-generated embeds (HTML snippets, AR viewers) may be placed on third-party websites, including the online stores of our business customers. Those websites have their own privacy policies and cookie notices; we are not responsible for their content or practices. End-customers interacting with embedded Blendspace previews should consult the privacy notice of the website they are visiting.

14. Children

Blendspace is a B2B / prosumer service and is not directed at children. The minimum age for an independent account is 16 years. Younger users may use Blendspace only with the consent of a parent or legal guardian. We do not knowingly collect personal data from children under the age of 13 (the threshold under the U.S. Children's Online Privacy Protection Act — COPPA) and, in jurisdictions where a higher digital-consent threshold applies (for example under GDPR Article 8 and Czech Act No. 110/2019 Coll., which set the Czech threshold at 15 years), we do not knowingly collect personal data below that local threshold without the required parental consent. If you believe a child has provided us with personal data, please contact us and we will delete it.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Service, legal requirements, or operational practices. The updated policy will be posted at blendspace.io/privacy.html with a revised "Last updated" date. Material changes will be communicated by email or in-app notice with reasonable advance notice.

16. Additional Rights by Jurisdiction

Because Blendspace is offered worldwide, this section sets out additional or jurisdiction-specific rights that may apply to you depending on where you reside. These rights are in addition to the rights described in Section 10 above.

16.1 United Kingdom (UK GDPR and Data Protection Act 2018)

If you are located in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to the processing of your personal data. Your rights mirror those described in Section 10. The supervisory authority in the UK is the Information Commissioner's Office (ICO)ico.org.uk.

16.2 Switzerland (revised FADP)

If you are located in Switzerland, the revised Federal Act on Data Protection (FADP) applies. Your rights are broadly equivalent to those under the GDPR. The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC)edoeb.admin.ch.

16.3 California (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), grants you the following rights:

We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CCPA. The categories of personal information we collect and our purposes for collecting them are described in Sections 3 and 5 of this Privacy Policy. To exercise your CCPA rights, contact us at info@blendspace.io. You may designate an authorised agent to submit requests on your behalf. We will verify your identity before responding.

16.4 Other U.S. states

Residents of other U.S. states that have enacted comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) have rights generally comparable to those described above, including access, deletion, correction, portability, and opt-out of targeted advertising, sale, and certain profiling. To exercise these rights, contact us at info@blendspace.io.

16.5 Brazil (LGPD), Canada (PIPEDA), Australia (Privacy Act)

Residents of Brazil (under the Lei Geral de Proteção de Dados), Canada (under PIPEDA and applicable provincial laws), Australia (under the Privacy Act 1988), and other jurisdictions with comprehensive privacy laws have rights including access, correction, and deletion of their personal data, and may lodge complaints with their local supervisory authority. To exercise these rights, contact us at info@blendspace.io.

16.6 EU/EEA Representative and UK Representative

Blendlens s.r.o. is established within the European Union (Czech Republic) and therefore no Article 27 GDPR representative is required. We have not appointed a separate UK GDPR Article 27 representative; if this is required in the future in relation to our processing of UK personal data, we will update this Policy accordingly.

17. Contact

For any questions or requests relating to this Privacy Policy or your personal data, contact us at:

Blendlens s.r.o.
Tovární 1112, 537 01 Chrudim, Czech Republic
IČO: 19332351
Registered in the Commercial Register, Regional Court in Hradec Králové, Section C, File No. 51234
Privacy and product enquiries: info@blendspace.io
Corporate / formal correspondence: hello@blendlens.com