Privacy Policy
Blueprints Market
A Trading Brand of
Alpha & Omega Limited
Effective Date: 3 August 2026
Last Updated: 3 August 2026
Version: 2.0
Important Privacy Notice
This Privacy Policy explains how Alpha & Omega Limited, trading through Blueprints Market, collects, holds, uses, discloses, protects, retains, and otherwise processes personal information in connection with blueprintsmarket.com, customer accounts, purchases, licensing, enquiries, downloads, support, compliance, security, and enforcement.
By using the Website, submitting information, creating an account, purchasing a Product, requesting a licence, contacting us, or otherwise interacting with Blueprints Market, you acknowledge the practices described in this Policy. Where consent is legally required, we will request it separately.
This Policy should be read with the Blueprints Market Terms & Conditions, Cookie Policy, Acceptable Use Policy, Product Licence Agreements, and any signed commercial agreement.
1. Identity of the Agency
Blueprints Market is a trading brand operated by Alpha & Omega Limited, a New Zealand company. For the purposes of the New Zealand Privacy Act 2020, Alpha & Omega Limited is the agency responsible for personal information processed through Blueprints Market unless another notice expressly identifies a different controller or agency.
References to “Blueprints Market”, “Alpha & Omega Limited”, “we”, “us”, and “our” have the same meaning throughout this Policy.
2. Scope of This Policy
This Policy applies to personal information collected through the Website, customer accounts, payment and order processes, licensing systems, restricted download areas, contact forms, email, support communications, security systems, compliance processes, and related business activities.
It does not govern independent third-party websites, payment providers, hosting providers, social networks, professional advisers, or services that operate under their own privacy notices, except to the extent we control or instruct their processing.
3. Definitions
“Personal information” means information about an identifiable individual.
“Processing” includes collecting, recording, organising, storing, accessing, using, analysing, matching, disclosing, transferring, retaining, deleting, or otherwise handling personal information.
“Restricted Materials” means Products, downloads, source files, confidential documents, or other materials supplied under authentication, purchase, licence, NDA, or controlled access.
“Service Provider” means a person or organisation that processes information to provide hosting, payments, email, security, analytics, file delivery, legal, accounting, customer support, or other services.
4. Privacy Principles
We aim to collect only information reasonably necessary for lawful business purposes, explain why information is collected, use it consistently with those purposes, protect it against loss and misuse, retain it only as long as reasonably required, and provide access and correction rights where applicable.
We process personal information in accordance with the New Zealand Privacy Act 2020 and applicable Information Privacy Principles.
5. Information You Provide Directly
We may collect your name, organisation, position, postal address, email address, telephone number, billing information, tax information, country, account credentials, order details, licence selections, intended-use information, project information, support requests, communications, uploaded documents, identity-verification information, and information supplied in legal or compliance processes.
Where you act for an organisation, we may also collect information about your authority to bind or represent that organisation.
6. Information Collected Automatically
When you use the Website, systems and Service Providers may collect IP address, browser type, device type, operating system, language, referring page, requested pages, timestamps, approximate location, session information, error logs, security events, download activity, acceptance records, and technical identifiers.
We may use cookies, local storage, server logs, security tools, and similar technologies as described in our Cookie Policy.
7. Information Collected from Other Sources
We may receive information from payment processors, fraud-prevention providers, identity-verification providers, business directories, professional advisers, authorised representatives, distributors, corporate customers, public registers, sanctions or restricted-party sources, and publicly available information.
Where personal information is collected from someone other than the individual concerned, we will provide the notifications required by applicable law, including the indirect-collection requirements of Information Privacy Principle 3A where they apply.
8. Purposes of Collection and Use
We may process personal information to operate and secure the Website; create and administer accounts; process payments and orders; deliver Products; issue licence certificates; maintain acceptance records; provide support; respond to enquiries; negotiate and manage commercial agreements; verify identity, authority, sanctions status, and intended use; prevent fraud; investigate misuse; enforce rights; comply with law; maintain records; improve services; and communicate service, security, product, and legal notices.
We may also use aggregated or de-identified information for statistics, planning, security, and service improvement where it no longer identifies an individual.
9. Legal and Operational Bases
Our processing may be based on performance of a contract, steps requested before entering a contract, legal obligations, protection of legal rights, legitimate business purposes, consent where required, and other grounds permitted by applicable law.
Where processing depends on consent, you may withdraw consent for future processing, but withdrawal does not affect prior lawful processing or processing required for contracts, security, compliance, or legal obligations.
10. Accounts and Authentication
We process account identifiers, login information, password hashes, multi-factor authentication data, role assignments, access rights, session records, and security events to administer and protect accounts.
You are responsible for keeping credentials confidential and notifying us promptly of suspected compromise, unauthorised access, or misuse.
11. Orders, Payments, and Billing
Payments may be processed by independent payment providers. We may receive transaction identifiers, payment status, billing name and address, card type and last digits, fraud indicators, refunds, disputes, and related records, but we do not necessarily receive or store complete payment-card numbers.
Payment providers process information under their own terms and privacy policies. Information may also be shared with banks, tax authorities, accountants, auditors, and professional advisers where reasonably necessary.
12. Licensing and Commercial Due Diligence
For licences involving Restricted Materials, manufacturing, OEM, enterprise, distributor, government, research, or strategic-partner rights, we may collect identity, ownership, corporate structure, beneficial-owner, location, project, site, territory, personnel, financial, compliance, export-control, certification, and intended-use information.
We may retain licence applications, approval decisions, signed agreements, authorised-user records, royalty reports, audit records, manufacturing records, and compliance communications for contract administration and enforcement.
13. Downloads, Watermarks, and Product Security
Restricted downloads may be associated with purchaser names, account IDs, order IDs, licence IDs, timestamps, IP addresses, file hashes, digital fingerprints, watermarks, or other identifiers used for delivery, support, integrity, fraud prevention, and enforcement.
We do not use hidden identifiers to collect unrelated personal information. We may compare identifiers and access records when investigating suspected unauthorised distribution, leakage, or licence breach.
14. Customer Support and Communications
We may retain emails, messages, contact forms, call notes, support tickets, attachments, diagnostic information, and related correspondence to respond, maintain service history, resolve disputes, improve support, and protect legal rights.
Do not send sensitive personal information that is not necessary for your request.
15. Marketing Communications
We may send marketing communications where permitted by law. You may unsubscribe using the link in the message or by contacting us.
Unsubscribing from marketing does not prevent necessary transactional, account, licence, safety, security, legal, or service communications.
16. Cookies and Similar Technologies
We may use strictly necessary cookies and storage for security, session management, preferences, account functions, checkout, and delivery. With appropriate consent where required, we may also use analytics, performance, or marketing technologies.
Detailed information about cookie categories, providers, duration, controls, and consent is provided in our Cookie Policy.
17. Analytics
Analytics may help us understand page usage, errors, devices, traffic sources, performance, and general interaction patterns.
Where practicable, analytics settings should minimise collection, shorten retention, mask identifiers, and avoid collecting Product contents, passwords, payment data, or Restricted Materials.
18. Fraud, Security, and Abuse Prevention
We may analyse account, access, payment, download, device, network, and communication information to identify fraud, credential abuse, scraping, automated extraction, unauthorised sharing, sanctions concerns, malware, infringement, security threats, and breaches of applicable agreements.
Security decisions may involve automated indicators, but material adverse decisions should be subject to appropriate human review where reasonably practicable.
19. Intellectual-Property and Licence Enforcement
Where reasonably necessary, we may process identity, order, licence, download, access, watermark, marketplace, public-posting, manufacturing, audit, and communication records to investigate and enforce copyright, contractual, confidentiality, trade-secret, royalty, patent-filing, and other rights.
We may disclose relevant information to legal advisers, investigators, courts, regulators, online platforms, hosting providers, payment providers, customs authorities, or law-enforcement agencies where lawful and proportionate.
20. Service Providers
We may use Service Providers for hosting, cloud storage, cybersecurity, authentication, email, communications, analytics, payment processing, digital delivery, customer support, document signing, accounting, legal services, and business administration.
We seek to use providers that offer appropriate privacy and security safeguards and limit their access to what is reasonably required for the service.
21. Overseas Processing and Disclosure
Some Service Providers or recipients may be located outside New Zealand. Where personal information is disclosed to an overseas person or entity, we will take steps required by Information Privacy Principle 12, which may include assessing comparable legal safeguards, using contractual protections, relying on an applicable statutory basis, or obtaining informed authorisation.
Where an overseas organisation merely stores or processes information on our behalf and is treated as our agent under applicable law, different legal rules may apply, but we still seek appropriate contractual and security protections.
Internet services may route or store information in multiple countries, and we cannot guarantee that all processing occurs exclusively in New Zealand.
22. When We May Disclose Information
We may disclose personal information to the individual concerned or authorised representative; Service Providers; payment and banking providers; professional advisers; corporate transaction parties; licence partners where authorised; regulators; courts; law enforcement; tax authorities; customs or export-control authorities; and other persons where disclosure is authorised or required by law.
We do not sell personal information as a standalone commodity.
23. Public Areas and User Submissions
Information voluntarily posted in public areas, reviews, social media, testimonials, public forums, or public submissions may become visible to others and may be copied or indexed beyond our control.
Do not publish personal information, confidential information, credentials, or Restricted Materials in public areas. Where testimonials or identifying submissions are used for marketing, we will seek appropriate authority where required.
24. Information About Other People
If you provide personal information about another person, you represent that you are authorised to do so and that any required notice or consent has been provided.
Corporate customers are responsible for ensuring that employee, contractor, adviser, and authorised-user information supplied to us is accurate and lawfully disclosed.
25. Children and Minors
The Website and Products are intended primarily for adults, businesses, professionals, researchers, and organisations. We do not knowingly seek to collect personal information from children without appropriate authority.
If you believe a child has supplied personal information without proper authority, contact us so we can assess and respond.
26. Security Safeguards
We use administrative, technical, and physical safeguards appropriate to the nature of the information, which may include access controls, password hashing, encryption, secure transfer, network protection, backups, monitoring, logging, least-privilege access, staff controls, and incident-response procedures.
No system is completely secure. You should use strong unique passwords, secure devices, current software, and appropriate protections for files you download.
27. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including account administration, delivery, support, security, legal compliance, taxation, accounting, licensing, royalty verification, dispute resolution, and enforcement.
Retention periods vary by record type. We may retain transaction, agreement, acceptance, licence, audit, enforcement, and legal records after account closure where reasonably required.
When information is no longer required, we may securely delete, anonymise, archive, or otherwise dispose of it in accordance with lawful retention requirements.
28. Access to Personal Information
Subject to the Privacy Act 2020 and applicable exceptions, you may request confirmation of whether we hold personal information about you and request access to it.
We may need to verify your identity and authority before responding. Some information may be withheld or redacted where authorised by law, including to protect another person, legal privilege, security, confidential evaluative material, or trade secrets.
29. Correction of Personal Information
You may request correction of personal information you believe is inaccurate, incomplete, or misleading.
If we do not make the requested correction, you may be entitled to request that a statement of correction be attached to the information, subject to applicable law.
30. Account Information and Self-Service Updates
Where account tools are available, you should keep your contact, organisation, billing, and authorised-user information current.
Some records, including completed transaction, legal, licence, audit, and acceptance records, may be preserved as historical records rather than overwritten.
31. Privacy Requests
Privacy requests should identify the requester, the information or action sought, relevant dates or accounts, and any authorised-representative details.
We may request identification information to prevent unauthorised access. We will respond within the time required by applicable law, subject to permitted extensions or transfers.
32. Privacy Breaches
A privacy breach may involve unauthorised or accidental access, disclosure, alteration, loss, destruction, or temporary loss of access to personal information.
We maintain processes to assess, contain, investigate, document, and respond to suspected breaches. Where a breach has caused or is likely to cause serious harm, we will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, unless an exception applies.
We may also notify Service Providers, insurers, advisers, regulators, platforms, law enforcement, or other parties where reasonably necessary to contain harm or comply with law.
33. Complaints
If you have a privacy concern, contact us first so we can investigate and attempt to resolve it.
You may also complain to the New Zealand Office of the Privacy Commissioner. Information about privacy rights and complaints is available from that Office.
34. Automated Decisions and Profiling
We may use automated tools to prioritise security alerts, detect suspicious transactions, identify likely scraping or account abuse, and assist fraud or compliance reviews.
We do not intend to make solely automated decisions producing significant legal or similarly serious effects without appropriate safeguards and human review where required by law.
35. Do Not Track and Browser Controls
Browser signals such as “Do Not Track” are not consistently standardised. We respond through the cookie and consent controls described in our Cookie Policy and through available browser or device settings.
Blocking necessary cookies may prevent account, security, checkout, or download functions from working correctly.
36. Third-Party Links and Social Media
The Website may link to third-party websites or social platforms. Those services control their own collection and processing, and you should review their privacy policies before use.
Interaction with social media buttons, embedded media, external review links, or third-party content may transmit information to the relevant provider.
37. Business Transfers
If Alpha & Omega Limited undergoes a merger, restructuring, financing, sale, acquisition, insolvency process, or transfer of assets, personal information may be disclosed to professional advisers and prospective or actual transaction parties subject to appropriate confidentiality and legal safeguards.
Any successor handling personal information remains subject to applicable privacy law and the commitments that continue to apply.
38. Legal Claims and Regulatory Matters
We may preserve and use personal information where reasonably necessary to establish, exercise, defend, investigate, settle, or enforce legal claims, contracts, intellectual-property rights, security obligations, or regulatory requirements.
Legal holds may temporarily override ordinary deletion schedules.
39. Changes to This Policy
We may update this Policy to reflect changes in law, technology, services, providers, security practices, or business operations.
The updated version will state its effective date, last-updated date, and version number. Material changes may be communicated through the Website, account, or email where appropriate.
Changes apply prospectively and do not remove rights that cannot lawfully be excluded.
40. Privacy Officer and Contact
Privacy enquiries, access requests, correction requests, complaints, and breach reports should be submitted through the contact details published on the Website and marked for the Privacy Officer.
Blueprints Market
A Trading Brand of Alpha & Omega Limited
New Zealand
Do not send passwords, complete payment-card details, or unnecessary sensitive information through ordinary email.
41. Related Legal Documents
This Policy should be read with the following documents where applicable: Blueprints Market Terms & Conditions, Cookie Policy, Acceptable Use Policy, Product Licence Agreements, Engineering Disclaimer, Export Control Policy, Copyright Policy, Patent Policy, and Enforcement Policy.
If a signed agreement contains specific privacy or security obligations, that agreement prevails to the extent of an express conflict.
42. Final Privacy Statement
Alpha & Omega Limited is committed to handling personal information lawfully, fairly, transparently, and securely while protecting customers, users, Product IP, Restricted Materials, and the integrity of the Blueprints Market licensing system.
Nothing in this Policy limits any privacy right or remedy that cannot lawfully be excluded.
Implementation Notice
This Policy must accurately reflect the technologies and Service Providers actually used by the Website. Before publication, verify payment processors, analytics tools, hosting locations, cookie providers, email platforms, account systems, download systems, retention periods, privacy-contact details, and overseas processing arrangements. Remove any description that does not match actual practice and add any material processing not currently described.
Contact
For privacy questions or data inquiries, contact us at:
Email: support@BluePrintsMarket.com & BluePrintsMarket.com
Last Updated: