Privacy policy

Last updated: 14 September 2026

1. Controller

Bliq GmbH
Lohmühlenstraße 65
12435 Berlin
Germany
Email: hello@bliq.ai
Data Protection Officer (DPO):
Email: dpo@bliq.ai

Bliq GmbH
Lohmühlenstraße 65
12435 Berlin
Germany
Email: hello@bliq.ai
Data Protection Officer (DPO):
Email: dpo@bliq.ai

2. General Information

We take the protection of personal data seriously. This Privacy Policy explains how Bliq GmbH (“we”, “us”) processes personal data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.
Personal data means any information relating to an identified or identifiable natural person.

We take the protection of personal data seriously. This Privacy Policy explains how Bliq GmbH (“we”, “us”) processes personal data in accordance with the General Data Protection Regulation (GDPR) and applicable German data protection laws.
Personal data means any information relating to an identified or identifiable natural person.

3. Categories of Data We Process

Depending on usage of our website and driverless vehicle services, we may process:
Website data
IP address
Date and time of access
Browser and device information
Referrer URL
Log files
Communication data
Name
Email address
Message content
Vehicle and mobility data (if using our driverless vehicle services)
Trip metadata (start/end location, timestamps, route)
Vehicle telemetry (speed, braking, system status)
Sensor data (camera, lidar, radar)
Interior safety data (e.g. seat occupancy)
Safety and incident data
Video recordings in and around the vehicle
Event data related to accidents or system faults

Depending on usage of our website and driverless vehicle services, we may process:
Website data
IP address
Date and time of access
Browser and device information
Referrer URL
Log files
Communication data
Name
Email address
Message content
Vehicle and mobility data (if using our driverless vehicle services)
Trip metadata (start/end location, timestamps, route)
Vehicle telemetry (speed, braking, system status)
Sensor data (camera, lidar, radar)
Interior safety data (e.g. seat occupancy)
Safety and incident data
Video recordings in and around the vehicle
Event data related to accidents or system faults

4. Purposes of Processing

We process personal data for the following purposes:
Operation and safety of driverless vehicles
Navigation and ride execution
System monitoring and improvement
Legal compliance and accident investigation
Customer support and communication
Website operation and security

We process personal data for the following purposes:
Operation and safety of driverless vehicles
Navigation and ride execution
System monitoring and improvement
Legal compliance and accident investigation
Customer support and communication
Website operation and security

5. Legal Bases

Processing is based on:
Art. 6(1)(b) GDPR – performance of a contract
Art. 6(1)(c) GDPR – legal obligations
Art. 6(1)(f) GDPR – legitimate interests (e.g. system security, fraud prevention, service improvement)
Art. 6(1)(a) GDPR – consent, where applicable
Our legitimate interests include operating safe driverless vehicles and maintaining reliable digital services.

Processing is based on:
Art. 6(1)(b) GDPR – performance of a contract
Art. 6(1)(c) GDPR – legal obligations
Art. 6(1)(f) GDPR – legitimate interests (e.g. system security, fraud prevention, service improvement)
Art. 6(1)(a) GDPR – consent, where applicable
Our legitimate interests include operating safe driverless vehicles and maintaining reliable digital services.

6. Recipients of Data

Personal data may be shared with:
Technical service providers (hosting, cloud, analytics)
Mobility partners
Insurance providers
Authorities where legally required
All processors act under GDPR-compliant data processing agreements.

Personal data may be shared with:
Technical service providers (hosting, cloud, analytics)
Mobility partners
Insurance providers
Authorities where legally required
All processors act under GDPR-compliant data processing agreements.

7. International Transfers

If data is transferred outside the EU/EEA, we ensure appropriate safeguards such as EU Standard Contractual Clauses.

If data is transferred outside the EU/EEA, we ensure appropriate safeguards such as EU Standard Contractual Clauses.

8. Storage Period

We store personal data only as long as necessary for the stated purposes or legal retention requirements.
Typical retention periods:
Website logs: up to 30 days
Communication data: up to 3 years
Vehicle and safety data: according to operational necessity and statutory requirements

We store personal data only as long as necessary for the stated purposes or legal retention requirements.
Typical retention periods:
Website logs: up to 30 days
Communication data: up to 3 years
Vehicle and safety data: according to operational necessity and statutory requirements

9. Your Rights

You have the right to:
Access your data (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object to processing (Art. 21 GDPR)
Withdraw consent at any time
Requests can be sent to: dpo@bliq.ai
You also have the right to lodge a complaint with a supervisory authority.

You have the right to:
Access your data (Art. 15 GDPR)
Rectification (Art. 16 GDPR)
Erasure (Art. 17 GDPR)
Restriction of processing (Art. 18 GDPR)
Data portability (Art. 20 GDPR)
Object to processing (Art. 21 GDPR)
Withdraw consent at any time
Requests can be sent to: dpo@bliq.ai
You also have the right to lodge a complaint with a supervisory authority.

10. Automated Decision-Making

Our systems may perform automated processing for driverless vehicle operation and safety. No decisions producing legal effects concerning individuals are made without human oversight.

Our systems may perform automated processing for driverless vehicle operation and safety. No decisions producing legal effects concerning individuals are made without human oversight.

11. Analytics and website technologies

We use Google Analytics 4 and Hotjar to understand website usage and improve performance and content. These optional analytics technologies should be activated only after you give consent. The legal basis is your consent under Article 6(1)(a) GDPR and Section 25(1) TDDDG. You may withdraw or change your consent at any time with effect for the future through the website’s cookie settings. Google Analytics 4 is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. It may process online and cookie identifiers, IP-derived location, device and browser information, referrer information, pages viewed, interactions, session information and timestamps. Google Ireland may use Google LLC and other processors, which can involve transfers outside the EU/EEA. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses and supplementary safeguards. Google Analytics cookies commonly include _ga and _ga_<container-id>; their duration and event-data retention depend on our configuration. Hotjar is provided by Hotjar Limited, Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian’s STJ 3141, Malta. Hotjar may process technical device and browser information, IP-derived location, pages visited, clicks, scrolling, pointer movements, screen size, timestamps and technical identifiers to provide heatmaps, interaction analytics and, where enabled, privacy-configured session recordings or feedback tools. Form fields and sensitive content should be masked or suppressed. Hotjar may engage processors outside the EU/EEA subject to appropriate safeguards; cookie and identifier duration depends on purpose and configuration. Further information is available in Google’s and Hotjar’s privacy documentation. INFORMATION TO CONFIRM BEFORE PUBLISHING: the GA4 event-data retention period and whether Google Signals or advertising features are enabled; the enabled Hotjar features, masking configuration and retention periods; and the final cookie-settings mechanism.

12. Data Security

We apply appropriate technical and organizational measures, including encryption, access controls, and secure infrastructure.

We apply appropriate technical and organizational measures, including encryption, access controls, and secure infrastructure.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The current version is always available on our website.

We may update this Privacy Policy from time to time. The current version is always available on our website.