Legal Information

Privacy Policy

How BLACKFILE collects, uses, stores, and discloses personal data when you visit blackfile.io, contact us, or receive our services.

Вступает в силу: 30 July 2026Обновлено: 30 July 2026
Читать документ
Legal Document / 01

This policy applies with regard to the Swiss Federal Act on Data Protection (FADP/DSG). The EU General Data Protection Regulation (GDPR) applies where the relevant processing falls within its scope.

01

Data controller

BLACKFILE Intelligence AG

Address

Bahnhofstrasse 11

8001 Zurich, Switzerland

Registration number

CHE-421.028.751

General enquiriesinfo@blackfile.io

Confidentialityprivacy@blackfile.io

Legal noticeslegal@blackfile.io

The telephone number is not published. You may contact us using the e-mail addresses provided.

02

Scope of application

BLACKFILE processes data in two principal situations.

  1. 1When a person interacts with BLACKFILE directly: visits the site, submits an enquiry, discusses a project, or enters into an agreement.
  2. 2When BLACKFILE processes data in carrying out a client's lawful instruction. In such a situation, the roles of the parties, the purposes of processing, and the protective measures are further defined by the agreement.
03

What data we process

  • Contact detailsName, position, organization, professional contacts.
  • Information from the enquiryThe content of the request, project requirements, and attached materials.
  • Technical device dataIP address, device and browser type, operating system.
  • Website usage dataTime of access, referral source, security logs, cookies.
  • Professional and corporate informationContractual, payment, and accounting data.
  • Materials within the scope of an instructionInformation about persons and organizations obtained from lawful sources.

We adhere to the principle of data minimization and collect only the data reasonably necessary for the stated purpose.

04

Special categories of data

We do not ask website visitors to provide particularly sensitive personal data without necessity.

In the course of individual lawful engagements, such data may be contained in client materials or become known from lawful sources. It is processed only where an applicable legal basis exists, within the scope of the engagement, subject to enhanced access limitations and retention periods.

Data concerning alleged offenses and criminal records is processed only in cases permitted by law.

05

Purposes and legal bases

Responses to enquiries and preliminary discussion of a matter
Actions prior to entering into an agreement
Conclusion and performance of agreements, provision of services and settlements
Performance of the agreement
Verification of clients and admissibility of engagements
Legal obligation and legitimate interest
Prevention of fraud, abuse and security threats
Legitimate interest
Compliance with legal, tax and accounting obligations
Legal obligation
Establishment, exercise and defense of legal claims
Defense of legal claims
Operation, protection and improvement of the website
Legitimate interest
Analytics and informational materials
Consent or other applicable basis

If processing is based on consent, it may be withdrawn at any time by writing to privacy@blackfile.io. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

06

Data sources

  • directly from you;
  • from the client, an authorized representative or a partner;
  • from state, judicial, arbitration and corporate registers;
  • from public sources, archives, professional databases and other lawfully accessible sources;
  • from providers that help us verify clients and comply with the law;
  • automatically when using the website.

Where data is obtained other than from you, we provide information within the periods and to the extent required by applicable law, except where a legal exception applies.

07

Cookies and technologies

The website may use strictly necessary cookies, as well as functional and analytical technologies.

The list of cookies used, their purpose, duration and available settings are set out in a separate Cookie Policy. Non-essential cookies are activated only where a legally required basis exists.

The website is hosted using the cloud infrastructure of a hosting and technical services provider. When processing requests to the website, the infrastructure provider may receive technical data necessary for content delivery, security, error diagnostics and abuse prevention. Such processing is carried out in accordance with contractual data protection obligations and applicable international transfer mechanisms.

We may use aggregated web analytics to assess the website's performance. It helps us understand page traffic, device type, browser, approximate region and referral source. We do not transmit the content of enquiries, contact details or other sensitive information to analytics events.

08

Recipients of data

  • providers of hosting, secure communications, corporate e-mail, IT support and security;
  • professional advisers, including lawyers, auditors and tax specialists;
  • specialists and contractors engaged for a specific matter and bound by a duty of confidentiality;
  • state authorities and courts, where disclosure is required by law or by a binding legal request;
  • the client for whose benefit the engagement is carried out, in respect of the results of that engagement.

We do not sell personal data. Providers processing data on our behalf are granted access only to the extent necessary and on contractual data protection terms.

09International transfers

Our activities may require the transfer of data outside Switzerland and, where applicable, the European Economic Area.

Each transfer is subject to a mechanism provided for by law: a recognized adequate level of protection, approved standard contractual clauses with the necessary supplementary measures, or an applicable legal exception.

10

Retention periods

Enquiries without a contractual relationship
Until completion of correspondence and a reasonable subsequent period
Client and project materials
For the duration of the project and the retention period thereafter as set out in the agreement
Contractual, tax and accounting documents
For the period established by law
Security logs and technical data
The minimum period necessary for security and diagnostics
Data based on consent
Until consent is withdrawn or the purpose of processing is achieved

At the end of the retention period, data is deleted, anonymised or securely archived, unless further retention is required by law.

11

Security

01Access limitationAccess is limited to the team working on the task.
02Encryption in transitHTTPS on all routes and secure communication channels.
03Change controlLogging, environment separation and change review.
04Response proceduresIncident response protocol and backup procedures.

Measures are reviewed regularly. No method of data transmission or storage provides absolute security.

12

Security breaches

We assess incidents, take steps to limit their consequences and document the decisions taken.

Where applicable law requires notification of a supervisory authority or affected individuals, we provide such notification in the manner prescribed and without undue delay.

13

User rights

  1. 01AccessFind out whether we process your data and obtain access to it.
  2. 02CorrectionRequest correction of inaccurate or incomplete data.
  3. 03DeletionRequest deletion of data where grounds for it exist.
  4. 04LimitationRequest restriction of processing in the cases provided for.
  5. 05ObjectionObject to certain types of processing.
  6. 06PortabilityReceive the data you provided in a portable format.
  7. 07Withdrawal of consentWithdraw consent where processing is based on it.
  8. 08Review of a decisionRequest human involvement in an automated decision.
  9. 09ComplaintContact the competent supervisory authority.

To exercise these rights, write to privacy@blackfile.io. We may request information necessary to verify identity. Rights may be limited in cases provided for by law, including the protection of the rights of others, professional secrecy and mandatory retention periods. In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).

Направить запрос о данных
14

Automated decisions

BLACKFILE does not make purely automated decisions that produce legal or similarly significant effects for an individual, unless expressly notified in advance otherwise.

Automated tools may be used as an aid to analysis. Material conclusions are subject to review by an authorised specialist.

15

Third-party sites

The site may contain links to third-party resources. Their owners are independently responsible for processing data. Before providing them with personal data, you should review their privacy policies.

16

Changes to the Policy

We may update this Policy when legislation, technology or our processes change. The current version is published on blackfile.io with a new update date. We notify of material changes by an additional means where required by law.

17

Question about personal data?

Write to us, and we will respond within the time limits set by applicable law. For a data subject request, a letter describing the request is sufficient.

Направить запрос
Legal Document / 01Обновлено: 30 July 2026