Skip to main content
Bloomder
  • Home
  • 035 Shield ProgramAudit-ready NOM-035 file in 30 days NOM-035 & ISO 45003Always-ready compliance file All FeaturesHow the three pieces fit together Pulse SurveysShort surveys on a schedule AI InsightsPlain-language actions per team Burnout DetectionTrend breaks before resignations Product TourLive dashboard, no account needed
  • ManufacturingOur focus — shift work and deskless teams TechnologyOn-call fatigue and quiet disengagement Retail & HospitalityHourly staff across many sites Professional ServicesUtilization pressure and billable hours
  • Pricing
  • BlogGuides on engagement and compliance GlossaryeNPS, NOM-035, burnout, defined FAQSetup, anonymity, pricing SecurityEncryption, access control, sub-processors API docsRead-only REST API for your own tools
  • About Us
  • Contact
Log in Start Free → Español
Home
035 Shield Program NOM-035 & ISO 45003 All Features Pulse Surveys AI Insights Burnout Detection Product Tour
Manufacturing Technology Retail & Hospitality Professional Services
Pricing
Blog Glossary FAQ Security API docs
About Us Contact Log in Start Free → Español
Home  /  Privacy Policy

Privacy Policy

How Bloomder (Zafiro Technology, S.A. DE C.V.) collects, uses, and protects personal data — the visitor’s, the customer’s, and the employee’s.

Last updated: August 15, 2026 Governed by Mexican federal law

This Privacy Policy is also available in Spanish for your convenience. In the event of any conflict or discrepancy between the English and Spanish versions, the English version shall govern and prevail.

1. Who we are, and how to reach us

Zafiro Technology, S.A. DE C.V., trading as Bloomder, with address at Calle Ricardo Margáin 335, Torre 1, Piso 4, Col. Valle del Campestre, San Pedro Garza García, Nuevo León, México, C.P. 66265, is responsible for the personal data described in this policy.

This policy covers the marketing website at bloomder.io and the Bloomder application. It describes what is actually collected, by whom, and for how long. Where a statement applies only to the website or only to the application, it says so.

Reason to writeAddress
Privacy requests, data subject rights, deletion evidence[email protected]
Security reports and vulnerability disclosure[email protected]
Anything else[email protected]

We have not appointed a Data Protection Officer, because we are not required to appoint one. Privacy requests are handled by the team behind the addresses above.

2. Two different roles, and why the difference matters

Bloomder handles personal data in two capacities, and your rights depend on which one applies.

As a controller (in Mexican terms, the responsable) for the data of website visitors and of the people who hold a Bloomder account. We decide why and how that data is processed: to run the site, to create and secure accounts, to bill, and to provide support.

As a processor (in Mexican terms, the encargado) for the employee data a customer uploads and for the survey answers their employees give. The employer is the controller of that data. We process it only on the employer’s documented instructions, we do not sell it, we do not use it to train any model, and we do not use it for our own purposes — including product analytics.

If you are an employee answering a survey and you want your data corrected or erased, your employer is the party who decides. Write to them first; if you write to us, we will forward the request and tell you we have done so. If you are the employer, a Data Processing Addendum is available at [email protected].

3. What we collect in each role

Website visitors (we are the controller)

  • Analytics events: pages viewed, referrer, approximate location derived from your IP address, device and browser type, and — if you accept the cookie banner — a recording of your session. See section 5.
  • Anything you type into a form on the site: name, work email, company, company size, and the message itself. This is used to answer you and, where you asked for one, to arrange a demo.
  • Server request data such as your IP address, held briefly by our hosting provider for delivery, abuse prevention and diagnostics.

Account holders (we are the controller)

  • Name, work email address, password hash (bcrypt — we never store the password itself), profile image if you set one, and the identity provider you used if you signed in with Google or Microsoft.
  • Organization name, plan, and billing contact. Card numbers go directly to our payment processor; we never receive or store them.
  • Security and audit records: sign-in times, IP address and user agent for administrative actions, and failed sign-in counters used for lockout.

Employee data uploaded by a customer (we are the processor)

  • Employee records the customer imports: name, work email, department, position, hire date, and manager relationship.
  • Survey answers, including free-text comments, and the technical record that a survey token was used — never a link, visible to anyone, between a person and the answers they gave. See section 7.

Bloomder is not intended for special-category or sensitive data as defined in Article 3, Section VI of the Federal Law on Protection of Personal Data Held by Private Parties, and it must not be used to collect protected health information. Survey questions are written by the customer, so the customer is responsible for not asking for such data.

4. Sub-processors — the platform

These vendors process data on our behalf to run the product. Each one is bound by a data processing agreement and receives only what its purpose requires.

Sub-processorPurposeWhat it can seeLocation
Anthropic PBC (Claude) Generating AI insights, themes and recommendations from a completed survey run The survey and organization name, the question text, aggregate answer counts, and the employees’ free-text answers themselves. It never receives employee names, email addresses, departments, or anything that ties an answer to a person. Under Anthropic’s commercial terms these inputs are not used to train models and are deleted within 30 days. United States
Resend Delivery of survey invitations, reminders, verification emails, risk alerts and account notifications Recipient name and email address, and the content of the message United States
Stripe Subscription billing and checkout Billing contact and payment details, which are collected by Stripe directly and never pass through our systems United States, with global processing
Amazon Web Services Application hosting, database and automated backups today Request metadata, the production database in full, and in transit everything the application sends or receives United States
Upstash Rate limiting and sign-in lockout counters IP addresses and the email address of a sign-in attempt, held as short-lived counters. No survey content and no employee records. United States

Customers on an executed data processing agreement receive 30 days’ notice of a material sub-processor change, with the right to object.

5. Sub-processors — website analytics

This section is about bloomder.io, the marketing website — not about the application, and not about any employee survey answer. Two of the four providers below run only after you accept the cookie banner; the other two run on every page.

ProviderWhat it doesConsentLocation
Google Analytics 4
Google LLC — measurement ID G-DP52ZBQ572
Traffic and conversion measurement: pages viewed, referrer, device, approximate location from IP, and two events we raise ourselves — clicking a trial link and submitting a form. Runs on every page, under Google Consent Mode v2. Advertising storage is denied everywhere, always. Analytics storage starts denied for visitors in the EEA, the United Kingdom and Switzerland, and is granted only if you accept the banner; elsewhere it starts granted. United States
Microsoft Clarity
Microsoft Corporation — project xt5v9ttw3n
Records your session. Pointer movement, scrolling, clicks, rage clicks and the sequence of pages you view are replayed to us as a video-like reconstruction, and aggregated into heatmaps. Clarity masks text input by default. Only after you accept the cookie banner. It is never loaded otherwise. United States
PostHog
PostHog Inc. — project key beginning phc_nTj3dRXy
Product analytics: which pages and features a visitor moves through. It writes a cookie and browser storage entries to recognise a returning visitor. Only after you accept the cookie banner. United States
Plausible Analytics Aggregate page-view counts. Cookieless: it stores nothing on your device and builds no cross-site or cross-visit profile. Runs on every page. No consent is required, because nothing is stored on your device and no individual is identified. European Union
Google Fonts
Google LLC
Serves the typefaces the pages are set in. Your browser requests them directly, so Google receives your IP address and user agent as part of that request. No cookie is set. Required to render the page; not gated behind the banner. United States

We do not run advertising or remarketing tags, we do not sell or share personal data with advertisers, and we do not send marketing emails to people who merely visited the website.

6. Cookies and similar technologies

A cookie is a small file a site asks your browser to store; browser storage such as localStorage works the same way for this purpose. Here is what this site actually stores.

  • Your consent choice. Accepting or declining the banner writes a single entry, bloomder_consent, in your browser’s local storage. It holds one word — granted or denied — and it is what stops the banner from asking again.
  • Analytics cookies, set by Google Analytics and PostHog as described in section 5. Microsoft Clarity also stores an identifier for the session it records.
  • Application cookies, set only once you sign in to Bloomder: a session cookie that keeps you signed in and is revoked server-side when you change your password or leave an organization. It is strictly necessary — sign-in does not work without it — and carries no analytics purpose.

Declining the banner means Clarity and PostHog are never loaded, and Google Analytics keeps analytics storage denied where Consent Mode applies. You can also delete cookies and local storage at any time in your browser, or block them entirely; the site works either way, apart from staying signed in.

7. How employee answers stay anonymous

This is the part employees care about most, so it is written as a mechanism rather than a promise.

  • A result is shown only when at least 5 distinct people answered. That floor — k-anonymity with k = 5 — is enforced once, at the data layer, so it applies to the results dashboard, to the department × dimension matrix, to CSV exports and to the API alike. Below it, the product shows “Insufficient data to protect anonymity” instead of a score.
  • It is not a setting. No administrator, manager or owner can lower it for a survey, a department or an account. Neither can we.
  • Nobody sees who answered what. Administrators and managers see aggregates. The record that a given invitation was used is kept so the same person is not counted twice and reminders are not sent to someone who already answered; it is not joined to their answers anywhere in the product, in an export, or in a report.
  • AI insights obey the same floor. A survey run with fewer than 5 responses is never sent for analysis at all, so free-text answers from a group too small to be anonymous never leave our systems.

8. How long we keep data, and when it is destroyed

The schedule below is automated, and it matches section 9.1 of the Terms of Service exactly.

  • Days 0–30 after cancellation — export window. The account stays reachable and a complete export of everything in it can be downloaded from Settings or through the API, on every plan including the free one.
  • Within 90 days — production data deleted. The organization and everything belonging to it are permanently deleted: employee records, surveys, responses, AI insights, action items, API keys and the audit trail. Nothing is archived and nothing is retained for our own analytics. Resubscribing before day 90 cancels the deletion.
  • A further 35 days — backups. Deleted rows can still exist inside automated database backups until those age out, and that window is capped at 35 days. No copy survives beyond 125 days from cancellation.
  • The deletion record survives. It holds the organization name, the cancellation and deletion dates, and the number of rows removed per category — no personal data and no survey content — so that a deletion can be evidenced to you or to an auditor.

Outside cancellation: administrative audit records are retained for 400 days. Website analytics data is retained under each provider’s own schedule. Rate-limit and lockout counters expire in minutes. Where a law or a live legal proceeding requires longer retention of specific records, we retain only what is required, only for as long as it is required, and we say so.

9. International transfers and security

Bloomder is a Mexican company and most of the vendors in sections 4 and 5 process data in the United States. Where personal data of individuals in the European Economic Area or the United Kingdom is transferred, we rely on Standard Contractual Clauses with the vendor concerned.

Data is encrypted in transit with TLS 1.2 or better, and encrypted at rest by our infrastructure providers. Access is role-based and least-privilege, administrative actions are recorded in an append-only audit trail, and confirmed incidents affecting personal data are notified within 72 hours. The controls, and the ones still on the roadmap, are listed in detail on our security page. No system is completely secure, and we do not claim otherwise.

10. Your rights

Access, Rectification, Cancellation, Opposition or revocation of your consent for the use of your personal data

You have the right to access, rectify and cancel your personal data, as well as to oppose the treatment of these for those purposes that are not necessary, nor have they given rise to the legal relationship with Bloomder, or revoke the consent that you have given us for this purpose.

Just send your request by means of an electronic note to the email [email protected] in which we will attend and resolve your request in accordance with the Law.

All processing of personal data is subject to the consent of its owner, except for the exceptions established in the Law and its regulations. Under Article 8 of the Federal Law on the Protection of Personal Data Held by Private Parties, the owner tacitly consents to the processing of their personal data if they do not express opposition. We will not sell, assign or distribute personal data without consent, unless a competent authority orders it.

GDPR and UK GDPR

If you are in the European Economic Area or the United Kingdom, you have the right of access, rectification, erasure, restriction of processing, objection, and data portability, and the right to withdraw consent at any time without affecting processing already carried out. Where we act as a processor for an employer, we will pass your request to them rather than act on it ourselves, and we will tell you that we have.

Our legal bases are: performance of a contract, for running an account and billing it; legitimate interests, for securing the service, preventing abuse and measuring aggregate website traffic; consent, for the analytics described in section 5 that are gated behind the banner; and legal obligation, for tax and accounting records.

Requests go to [email protected] and we answer within 30 days. You also have the right to complain to your local supervisory authority.

California (CCPA / CPRA)

California residents may request access to, deletion of, and correction of their personal information, and may limit its use. We do not sell or share personal information as those terms are defined by the CCPA, and we do not offer financial incentives in exchange for it. Exercising a right never results in worse service.

11. Links to other sites

This website links to sites we do not control. Once you follow such a link, this policy no longer applies and the destination’s own policy does. Please review it before providing anything.

12. Changes to this policy

We may update this policy. The date at the top of the page is the date of the version you are reading, and a material change — a new sub-processor, a new purpose — is announced to account holders by email before it takes effect.

Bloomder

AI-powered pulse surveys that help HR leaders and educators truly understand their people — and act on it.

Product

Home 035 Shield Program Pricing All Features Pulse Surveys AI Insights Burnout Detection Product Tour

Industries

Manufacturing Technology Retail & Hospitality Professional Services

Resources

Blog Glossary Workplace climate survey NOM-035 questionnaire FAQ Compliance (ISO 45003 / NOM-035)

Compare

Bloomder vs 15Five Bloomder vs Culture Amp Bloomder vs Workleap Bloomder vs Lattice Bloomder vs Leapsome

Company

About Us Contact Book a Demo Security

© 2026 Bloomder. All rights reserved.

Privacy Terms Security