Trust & Security — Data Handling | Bluestar

How Bluestar handles personal data, hosting, subprocessors, cookies and GDPR requests. Honest, no third-party certifications.

Trust & Security

How Bluestar handles data & security

This page is maintained by Bluestar N.V. to answer common security, privacy and data-handling questions from our B2B partners. It describes the controls actually in place on this website and in our commercial process — not third-party certifications.

Last updated: July 2026

What this site does

bluestar.be is a public marketing and lead-generation website for our leather production house. It has no customer login, no e-commerce checkout, no customer accounts and no payment processing. The only personal data we receive is what B2B prospects voluntarily send us through the contact form or by email.

Data we collect and why

Contact form submissions (name, company, email, phone, project details) — used only to reply to your enquiry and prepare a quote. Anonymised website analytics (page views, referrer, country) — used to improve the site. No profiling, no ad retargeting, no data brokering.

Hosting & infrastructure

The website is hosted on Lovable, which runs on EU/US-based cloud infrastructure with TLS encryption in transit. The database and file storage are provided by Lovable Cloud (Supabase-based, EU region where applicable). Access to production infrastructure is limited to Bluestar staff and required platform administrators.

Subprocessors

Lovable — website hosting and backend. Google Analytics 4 — anonymised traffic statistics, consent-gated, IP anonymisation on. A current subprocessor list is available on request at sales@bluestar.be.

Cookies & analytics

Analytics and marketing cookies are denied by default and only load after you give explicit consent via our banner. You can change your choices at any time through the cookie preferences panel.

Retention & deletion

Enquiry data is kept for the duration of our commercial relationship and up to 5 years afterwards for legal and accounting obligations. Analytics data is retained for 14 months at most. You can request deletion at any time at sales@bluestar.be.

Privacy requests

GDPR requests (access, rectification, deletion, restriction, portability, objection) are handled by email at sales@bluestar.be. We respond within 30 days as required by GDPR Art. 12.

Security & vulnerability reporting

If you discover a security issue on this website, please email sales@bluestar.be with the details. We investigate every report in good faith and aim to acknowledge within 5 business days.

Compliance scope

We comply with the EU General Data Protection Regulation (GDPR) as a Belgian data controller. We are not SOC 2, ISO 27001 or HIPAA certified — as a B2B leather manufacturer we do not process healthcare data or operate a SaaS platform where those frameworks would apply. If your procurement process requires additional documentation (DPA, subprocessor list, security questionnaire), contact sales@bluestar.be.

Shared responsibility

Bluestar is responsible for the website content, the data we collect through it, and our commercial process. Our platform provider (Lovable) is responsible for the underlying hosting infrastructure and its own security controls. You remain responsible for the accuracy of the information you send us and for keeping your own credentials safe.

Contact us about data or security