BlackEyes LogoBLACKEYES
Security & Privacy

Security, privacy & GDPR

How BLACKEYES protects your exposure data, acts as your authorised agent under UK GDPR, and keeps every report private to your account.

Six operating principles

These govern how the platform is built and how data flows through it.

We were never a data broker

We only ever act on data that's already exposed about you. Your information is used solely for your own exposure report and removals — never sold, shared, traded, or seeded to brokers who didn't already hold it.

Your report stays yours

Your exposure report and removal data are tied to your authenticated account and are never visible to other customers. BLACKEYES staff do not read your report contents except when strictly required for support, and only at your request.

Encryption in transit and at rest

Modern transport-layer encryption between your browser and our infrastructure. Report data is stored encrypted. Regular encrypted backups.

Public-domain sourcing

We never access accounts without authorisation, scrape private data, or purchase data from illicit marketplaces. We find your exposure in historical breach aggregators, public directories, data brokers, and open web records — then request its removal.

Scoped, least-privilege access

Every request to read your data is scoped to your authenticated account and enforced server-side. Cross-tenant data access is not possible by design, and staff-level access to customer data requires explicit break-glass procedures.

Retention in your control

Your exposure reports can be deleted at any time from your dashboard. Account deletion removes associated reports and personal data, subject to any statutory retention obligations. No silent retention of deleted material.

UK GDPR & Data Protection Act 2018

Clear roles and responsibilities between you and BLACKEYES as data handling parties.

It's your data — your rights

BLACKEYES only ever processes your own personal data, on your own account. Removal runs exclusively on your signed-in, verified email — there is no way to run it against anyone else.

We act as your authorised agent

When you authorise removal, BLACKEYES sends erasure and opt-out requests to data brokers on your behalf under UK GDPR and the CCPA — as your agent, with your consent recorded.

Your rights, fully supported

Access, rectification, erasure, export — exercise any of them against BLACKEYES at any time from your dashboard or by contacting support. We help you act on your data, we don’t hold it hostage.

How data is handled

Authentication

Strong password requirements (minimum 12 characters), disposable-email blocking, and session-based authentication. Standard industry practice for a security-sensitive platform.

Transport and storage

Modern transport-layer encryption for every request. Report data is stored encrypted at rest. No plaintext customer data transits the public internet.

Backups and recovery

Regular encrypted backups with recovery procedures in place. Retention is limited to what is needed for reliable recovery.

Payment data

Payments are processed by a PCI-DSS compliant payment provider. BLACKEYES does not store card numbers, CVV codes, or full banking details on our side. Only a customer reference is retained to manage subscriptions.

Email authentication

Email authentication (SPF, DKIM, DMARC) configured on all outbound sending domains to prevent spoofing. Transactional mail is sent through an authenticated service; we never expose customer data in email bodies beyond what is strictly necessary for the transaction.

Detailed infrastructure information (specific vendors, region, retention windows) is available to enterprise customers under NDA. Please contact us if you require it for a procurement or risk-review process.

Reporting a security issue

If you believe you've found a vulnerability or a data handling issue, let us know directly. We take every report seriously and respond quickly.