Translation provided for information only — the French version prevails. Read the French version (which prevails)

Privacy Policy

Last updated: 29 July 2026

This privacy policy describes how BL NEXT, publisher of the BL Next service, processes personal data in connection with the service, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the “GDPR”) and with French law no. 78-17 of 6 January 1978 on information technology, data files and civil liberties, as amended (the “French Data Protection Act”, loi Informatique et Libertés).

1. Who we are and scope

The BL Next service is a business management platform for professionals (SMEs in the construction and telecoms sectors), available at https://blnext.eu. It is published by BL NEXT, Société par actions simplifiée (SAS) with a share capital of 3 000 €, registered under RCS Avignon 999 963 382 (SIREN 999 963 382), whose registered office is located at 2 place Alexandre Farnèse, 84000 Avignon, France (hereinafter “the Provider” or “we”). Full identification details appear on the Legal Notice page.

This policy applies to the entire service: the https://blnext.eu website, the management web application, the technician application (PWA) available at tec.blnext.eu, and the public API v1 (read access and, where this option is enabled on an access key, write access). For any question regarding personal data, you can contact our data protection contact at contact@blnext.eu.

2. Our dual role under the GDPR

BL Next is a multi-company professional service: each client company has its own segregated workspace in which it enters its own data. This architecture entails an allocation of responsibilities that it is essential to understand properly.

The Provider acts as data controller

We determine the purposes and means of the following processing operations, for which we act as data controller within the meaning of Article 4 of the GDPR:

  • the creation and management of our clients’ user accounts;
  • subscription billing and management of the contractual relationship;
  • sales prospecting aimed at professionals (B2B);
  • user support and assistance;
  • the security of the service (login logs, audit log).

The Provider acts as processor (Article 28 GDPR)

For all data that client companies enter into the platform — data relating to their employees (HR files, time tracking, leave, HR documents), to their own end customers (quotes, invoices, client portal), worksite photos, operational and financial data —, the client company is the data controller. The Provider then acts as a processor, exclusively on that company’s documented instructions and on its behalf, under the conditions provided for in Article 28 of the GDPR.

Consequently, if you are an employee, end customer or partner of a company using BL Next, you should first exercise your rights over the data concerning you with that company (see Section 8). We will forward without delay to the company concerned any request that reaches us directly and will assist it, insofar as possible, in responding to it.

3. Data collected

Data processed as data controller

  • Identification and account data: surname, first name, business e-mail address, telephone, employing company, role in the application, profile photo (optional), login credentials (the password is stored in hashed form) and, where applicable, two-factor authentication settings (2FA TOTP). Proof of acceptance of the terms of service (timestamp, IP address, browser) is kept for evidential purposes.
  • Subscription billing data: billing details of the client company, history of subscriptions, options and AI credit packs. Bank card data is collected and processed directly by our payment provider Stripe; we have no access to it and do not store it.
  • Support data: content of exchanges with our support team and information necessary to handle the request.
  • Technical and security data: login logs (IP address, timestamp, user agent), audit log of sensitive actions in the application.
  • B2B prospecting data: business contact details of contacts and prospects (name, position, business e-mail and telephone, company). This data is collected directly from you or, where applicable, from publicly accessible professional sources (company websites, directories and professional networks).

Data processed as processor

This is the data entered, imported or generated by client companies in their workspace; its nature depends on the modules used:

  • Operations: work orders and field interventions, schedule, geolocated technical points, worksite photos. Photos taken from the field application may be time-stamped and geolocated (if the technician refuses the location permission, only the time is applied);
  • Sales: quotes, customer invoices, data of the company’s end customers, read-only access to the client portal via a tokenised link;
  • Human resources: employee files — full identity (including date and place of birth), social security number (French NIR, solely for payroll and social administration purposes), bank details (IBAN/BIC), remuneration items, emergency contacts —, leave, time tracking and absences. Clocking in and out may record GPS coordinates at the time of clocking; the employer, as data controller, must inform its employees (Article L. 1222-4 of the French Labour Code). Some HR documents (sick-leave certificates, medical check-ups) may contain health data (Article 9 GDPR): access to them is restricted to the client company’s administrators;
  • Electronic signatures: handwritten stroke captured on screen (signature of HR documents by employees, of intervention slips and quotes by end customers), together with the signatory’s IP address and browser for evidential purposes;
  • Logistics: vehicle fleet, expenses and expense reports;
  • Finance: supplier invoices, imported bank statements, production statements (PPD), reconciliations;
  • Documents submitted to the AI features: documents and content that the client company chooses to have analysed by the assistance features described in Section 10.

4. Purposes, legal bases and retention periods

The table below summarises the processing operations for which we are the data controller, as well as the regime applicable to the data processed on behalf of our clients.

PurposeLegal basis (Art. 6 GDPR)Retention period
Creation, management and security of user accounts; provision of the servicePerformance of the contract (Art. 6(1)(b))Term of the contract, then intermediate archiving for evidential purposes for the duration of the applicable statutory limitation periods (5 years as a rule)
Subscription billing and accounting obligationsLegal obligation (Art. 6(1)(c))10 years from the close of the financial year (Article L. 123-22 of the French Commercial Code)
User support and assistancePerformance of the contract (Art. 6(1)(b))Time needed to handle the request, then term of the contract
Security of the service: application audit log of sensitive actionsLegitimate interest (Art. 6(1)(f)) — security and prevention of unauthorised access12 months, except for records relating to billing and the life of the contract, kept for 10 years under accounting obligations
Sales prospecting aimed at professionals (B2B)Legitimate interest (Art. 6(1)(f)) — business development3 years after the last contact from the prospect
Data entered by client companies in their workspace (processing on behalf of the client — Art. 28 GDPR)Legal bases determined by the client company, as data controllerTerm of the contract; upon termination or expiry of the subscription, thirty (30) day reversibility window (Article 8 of the Terms of Service) then deletion of data and files, subject to the technical backup purge period

Login logs (IP address, timestamp, user agent) are kept by our authentication processor (Supabase) as part of account security, according to its own technical retention periods.

We only collect the data necessary for these purposes (data minimisation principle) and do not use it for other incompatible purposes.

The provision of account and billing data is of a contractual nature: it is necessary for the conclusion and performance of the contract. Without it, we are unable to create your account or provide the service. The provision of the other data is optional.

5. Recipients and processors

The data is accessible to our authorised staff, within the strict limits of their duties, and to the providers listed below. Providers acting as processors (or sub-processors) on our behalf or on behalf of our clients — in particular Supabase Inc., Hostinger International Ltd., Resend and Anthropic — are bound by contractual commitments compliant with Article 28 of the GDPR. Some providers — Stripe, for fraud prevention and compliance with its own regulatory obligations, Google Maps Platform and the browsers’ push notification services — additionally act, in whole or in part, as independent data controllers for their own purposes, under the conditions set out in their respective privacy policies.

ProviderRoleLocation
Supabase Inc.Database, authentication, file storageUnion européenne — Suède (AWS eu-north-1, Stockholm)
Hostinger International Ltd.Application hosting (VPS server)France (datacenter situé à Paris)
Stripe Payments Europe LtdSubscription paymentsIreland (EU)
ResendTransactional e-mail deliveryUnited States
AnthropicArtificial-intelligence features (Claude API). In accordance with Anthropic’s commercial terms, data submitted to the API is not used to train the modelsUnited States
Google Ireland Ltd — Google Maps PlatformMaps and geocoding of intervention addressesIreland (EU)
OpenStreetMap Foundation — Nominatim serviceGeocoding of worksite addresses and reverse geocoding of coordinates, in addition to Google Maps PlatformUnited Kingdom (European Commission adequacy decision)
Browser push notification services (Google, Mozilla, Apple)Delivery of web push notifications, if you have enabled themDepending on the browser used

We neither sell nor rent your personal data. Data may also be disclosed to the competent authorities where required by law.

6. Transfers outside the European Union

Some of the providers listed above are established, in whole or in part, outside the European Union, notably in the United States: Resend, Anthropic and the push services of some browsers. The platform’s data is itself hosted in the European Union (Union européenne — Suède (AWS eu-north-1, Stockholm)); as Supabase Inc. is a US company, remote access from a third country for support or maintenance purposes cannot however be ruled out. These transfers are governed, in accordance with Articles 44 et seq. of the GDPR, by the standard contractual clauses adopted by the European Commission and, where applicable, by the provider’s certification under the EU–U.S. Data Privacy Framework, supplemented where necessary by additional measures. You can obtain information about these safeguards, or a copy of the relevant documents, by writing to contact@blnext.eu.

7. Security

We implement technical and organisational measures appropriate to the risks, in accordance with Article 32 of the GDPR, and in particular:

  • encryption of communications in transit (TLS);
  • strict segregation of each client company’s data at database level (Row Level Security): a company can never access another company’s data;
  • AES-256-GCM encryption of the secrets entrusted to the password vault built into the application;
  • two-factor authentication (2FA TOTP) offered as an option to each user;
  • regular data backups;
  • logging of logins and sensitive actions (audit log), with role-based access management within each company.

In the event of a data breach likely to result in a risk to the rights and freedoms of individuals: where we act as data controller, we will notify the breach to the CNIL (the French data protection authority) and, where the GDPR so requires, to the data subjects (Articles 33 and 34 of the GDPR); where we act as processor, we will notify the breach to the client company concerned, as data controller, as soon as possible after becoming aware of it (Article 33(2) of the GDPR).

8. Your rights

In accordance with the GDPR and the French Data Protection Act, you have the following rights over the data concerning you:

  • right of access to your data and to obtain a copy of it;
  • right to rectification of inaccurate or incomplete data;
  • right to erasure, under the conditions of Article 17 of the GDPR;
  • right to restriction of processing;
  • right to object, on grounds relating to your particular situation, to processing based on our legitimate interest, and right to object without giving reasons to prospecting;
  • right to portability of the data you have provided to us;
  • right to withdraw your consent at any time, for the processing that depends on it, without such withdrawal affecting the lawfulness of prior processing;
  • right to set directives regarding the fate of your data after your death (Article 85 of the French Data Protection Act).

For the processing for which we are the controller (Section 2), you can exercise these rights by e-mail to contact@blnext.eu. In the event of reasonable doubt as to your identity, proof of identity may be requested. We will reply within one month of receiving the request, extendable by two months for complex or numerous requests (you would then be informed).

Some rights can also be exercised directly in the application: from the settings of the management web panel, you can rectify your first name, surname and e-mail address yourself; the administrator of each client company also has a global export of the data of its workspace as well as a register for tracking the GDPR requests received by its company. Users whose access is limited to the field application can ask their company’s administrator to rectify their file, or write to us at the address given above.

For data entered by a client company (data of its employees or of its end customers), the client company is the data controller: address your request to it first. Any request received directly will be forwarded to it.

If, after contacting us, you consider that your rights are not being respected, you can lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), the French data protection authority: www.cnil.fr.

9. Cookies and trackers

The service only uses trackers strictly necessary for its operation. We use no advertising cookies, no audience-measurement cookies and no third-party trackers for tracking purposes.

TrackerPurposeDuration
Authentication session cookies (“sb-” prefix)Keeping your session logged in and securing access to your account (strictly necessary)Duration of the session, renewed while the service is being used
Theme preference (light/dark)Remembering your display preference, stored locally in your browser (localStorage)Until deleted by you (data held in your browser)
Field application language preference (“blnext.terrain.lang”)Remembering the language chosen on the technician application (strictly necessary)12 months

As the sole purpose of these trackers is to enable or facilitate the provision of the service you request, they are exempt from prior consent pursuant to Article 82 of the French Data Protection Act and the doctrine of the CNIL. This is why no cookie consent banner is displayed to you. You can delete these cookies via your browser settings; deleting the session cookie has the effect of logging you out.

The technician application (PWA) also keeps, locally on the device, an offline operating cache: the day’s agenda, drafts and intervention reports awaiting upload. This local data is erased upon logout (except for intervention reports not yet synchronised, which are kept until they are sent, to avoid any loss of work).

10. Automated decisions and artificial intelligence

The service makes no decision based solely on automated processing producing legal effects concerning you or similarly significantly affecting you, within the meaning of Article 22 of the GDPR.

The service offers strictly assistive artificial-intelligence features — document analysis, consultation copilot, quote entry assistance — based on the Anthropic API (Claude). These features produce suggestions or pre-filled entries that are always subject to review and validation by a human user before producing any effect. In accordance with Anthropic’s commercial terms, data submitted to the API is not used to train the AI models.

11. Minors

BL Next is a service exclusively intended for professionals (B2B). It is not aimed at minors and we do not knowingly collect data concerning minors. If you believe that a minor has provided us with personal data, contact us at contact@blnext.eu so that we can delete it.

12. Changes to this policy

We may update this policy to reflect changes in the service, in our providers or in the regulations. The last-updated date shown at the top of the page is refreshed with each change. In the event of a substantial change, we will inform you by any appropriate means (in-app notification or e-mail). We invite you to consult this page regularly, together with our Terms of Service and our Legal Notice.