Privacy Policy
How BLACKFILE collects, uses, stores, and discloses personal data when you visit blackfile.io, contact us, or receive our services.
This policy applies with regard to the Swiss Federal Act on Data Protection (FADP/DSG). The EU General Data Protection Regulation (GDPR) applies where the relevant processing falls within its scope.
Data controller
BLACKFILE Intelligence AG
Bahnhofstrasse 11
8001 Zurich, Switzerland
Registration numberCHE-421.028.751
General enquiriesinfo@blackfile.io
Confidentialityprivacy@blackfile.io
Legal noticeslegal@blackfile.io
The telephone number is not published. You may contact us using the e-mail addresses provided.
Scope of application
BLACKFILE processes data in two principal situations.
- 1When a person interacts with BLACKFILE directly: visits the site, submits an enquiry, discusses a project, or enters into an agreement.
- 2When BLACKFILE processes data in carrying out a client's lawful instruction. In such a situation, the roles of the parties, the purposes of processing, and the protective measures are further defined by the agreement.
What data we process
- Contact detailsName, position, organization, professional contacts.
- Information from the enquiryThe content of the request, project requirements, and attached materials.
- Technical device dataIP address, device and browser type, operating system.
- Website usage dataTime of access, referral source, security logs, cookies.
- Professional and corporate informationContractual, payment, and accounting data.
- Materials within the scope of an instructionInformation about persons and organizations obtained from lawful sources.
We adhere to the principle of data minimization and collect only the data reasonably necessary for the stated purpose.
Special categories of data
We do not ask website visitors to provide particularly sensitive personal data without necessity.
In the course of individual lawful engagements, such data may be contained in client materials or become known from lawful sources. It is processed only where an applicable legal basis exists, within the scope of the engagement, subject to enhanced access limitations and retention periods.
Data concerning alleged offenses and criminal records is processed only in cases permitted by law.
Purposes and legal bases
- Responses to enquiries and preliminary discussion of a matter
- Actions prior to entering into an agreement
- Conclusion and performance of agreements, provision of services and settlements
- Performance of the agreement
- Verification of clients and admissibility of engagements
- Legal obligation and legitimate interest
- Prevention of fraud, abuse and security threats
- Legitimate interest
- Compliance with legal, tax and accounting obligations
- Legal obligation
- Establishment, exercise and defense of legal claims
- Defense of legal claims
- Operation, protection and improvement of the website
- Legitimate interest
- Analytics and informational materials
- Consent or other applicable basis
If processing is based on consent, it may be withdrawn at any time by writing to privacy@blackfile.io. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Data sources
- directly from you;
- from the client, an authorized representative or a partner;
- from state, judicial, arbitration and corporate registers;
- from public sources, archives, professional databases and other lawfully accessible sources;
- from providers that help us verify clients and comply with the law;
- automatically when using the website.
Where data is obtained other than from you, we provide information within the periods and to the extent required by applicable law, except where a legal exception applies.
Cookies and technologies
The website may use strictly necessary cookies, as well as functional and analytical technologies.
The list of cookies used, their purpose, duration and available settings are set out in a separate Cookie Policy. Non-essential cookies are activated only where a legally required basis exists.
The website is hosted using the cloud infrastructure of a hosting and technical services provider. When processing requests to the website, the infrastructure provider may receive technical data necessary for content delivery, security, error diagnostics and abuse prevention. Such processing is carried out in accordance with contractual data protection obligations and applicable international transfer mechanisms.
We may use aggregated web analytics to assess the website's performance. It helps us understand page traffic, device type, browser, approximate region and referral source. We do not transmit the content of enquiries, contact details or other sensitive information to analytics events.
Recipients of data
- providers of hosting, secure communications, corporate e-mail, IT support and security;
- professional advisers, including lawyers, auditors and tax specialists;
- specialists and contractors engaged for a specific matter and bound by a duty of confidentiality;
- state authorities and courts, where disclosure is required by law or by a binding legal request;
- the client for whose benefit the engagement is carried out, in respect of the results of that engagement.
We do not sell personal data. Providers processing data on our behalf are granted access only to the extent necessary and on contractual data protection terms.
09International transfers
Our activities may require the transfer of data outside Switzerland and, where applicable, the European Economic Area.
Each transfer is subject to a mechanism provided for by law: a recognized adequate level of protection, approved standard contractual clauses with the necessary supplementary measures, or an applicable legal exception.
Retention periods
- Enquiries without a contractual relationship
- Until completion of correspondence and a reasonable subsequent period
- Client and project materials
- For the duration of the project and the retention period thereafter as set out in the agreement
- Contractual, tax and accounting documents
- For the period established by law
- Security logs and technical data
- The minimum period necessary for security and diagnostics
- Data based on consent
- Until consent is withdrawn or the purpose of processing is achieved
At the end of the retention period, data is deleted, anonymised or securely archived, unless further retention is required by law.
Security
Measures are reviewed regularly. No method of data transmission or storage provides absolute security.
Security breaches
We assess incidents, take steps to limit their consequences and document the decisions taken.
Where applicable law requires notification of a supervisory authority or affected individuals, we provide such notification in the manner prescribed and without undue delay.
User rights
- 01AccessFind out whether we process your data and obtain access to it.
- 02CorrectionRequest correction of inaccurate or incomplete data.
- 03DeletionRequest deletion of data where grounds for it exist.
- 04LimitationRequest restriction of processing in the cases provided for.
- 05ObjectionObject to certain types of processing.
- 06PortabilityReceive the data you provided in a portable format.
- 07Withdrawal of consentWithdraw consent where processing is based on it.
- 08Review of a decisionRequest human involvement in an automated decision.
- 09ComplaintContact the competent supervisory authority.
To exercise these rights, write to privacy@blackfile.io. We may request information necessary to verify identity. Rights may be limited in cases provided for by law, including the protection of the rights of others, professional secrecy and mandatory retention periods. In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC).
Направить запрос о данныхAutomated decisions
BLACKFILE does not make purely automated decisions that produce legal or similarly significant effects for an individual, unless expressly notified in advance otherwise.
Automated tools may be used as an aid to analysis. Material conclusions are subject to review by an authorised specialist.
Third-party sites
The site may contain links to third-party resources. Their owners are independently responsible for processing data. Before providing them with personal data, you should review their privacy policies.
Changes to the Policy
We may update this Policy when legislation, technology or our processes change. The current version is published on blackfile.io with a new update date. We notify of material changes by an additional means where required by law.
Question about personal data?
Write to us, and we will respond within the time limits set by applicable law. For a data subject request, a letter describing the request is sufficient.