Blackout Intelligence Home

Data Processing Agreement

Last updated: 2 September 2026

This Agreement applies where you use Blackout Intelligence OS (the "Service") to process personal data for which you are the controller. It forms part of the Terms of Service. Where this Agreement and the Terms conflict on data protection, this Agreement governs.

1. Roles

You are the controller. Blackout Intelligence is the processor, acting only on your documented instructions. Your use of the Service is itself an instruction to process the data you submit for the purpose of producing the intelligence output you have requested.

For your own account and billing data we are a controller in our own right, and the Privacy Policy governs that instead.

2. Subject matter and duration

  • Subject matter: provision of open-source intelligence collection and reporting.
  • Duration: for as long as your subscription is active, plus the retention period in section 7.
  • Nature and purpose: collecting, correlating and reporting information about subjects you nominate.
  • Categories of data subject: the individuals and organisations you choose to investigate, and your own authorised users.
  • Categories of personal data: identifiers you submit (names, email addresses, usernames, telephone numbers, domains, addresses, company names) and whatever the open sources return about them.

3. Special category data

The Service is not designed for, and must not be used to build, profiles based on special category data under Article 9 UK GDPR — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation. Open sources may nonetheless return such information incidentally. You are responsible for ensuring your own lawful basis and for not using the Service for a purpose the Acceptable Use Policy prohibits.

4. Our obligations

  • Process personal data only on your documented instructions, including on international transfers, unless required otherwise by law — in which case we will tell you before processing unless that law forbids it.
  • Ensure people authorised to process the data are bound by confidentiality.
  • Apply the technical and organisational measures in section 6.
  • Engage sub-processors only on the terms in section 5.
  • Assist you, so far as is reasonable, with data subject requests and with your obligations under Articles 32 to 36.
  • Notify you without undue delay on becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties.
  • Delete or return the data at the end of the engagement, as set out in section 7.
  • Make available the information reasonably necessary to demonstrate compliance, and allow audits as described in section 9.

5. Sub-processors

You give general authorisation for the sub-processors below. We will give at least 30 days' notice before adding or replacing one, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected part of the Service.

Sub-processorPurposeLocation
Vercel Inc.Application hosting and deliveryEU / US
Supabase Inc.Database, authentication and file storageEU
Stripe Inc.Subscription billing and payment processingEU / US
Resend Inc.Transactional and notification emailEU / US
Anthropic PBCLanguage model assessment, where enabledUS

Language model providers are engaged only where a key is configured for your deployment or account. With no key configured, no data is sent to any model provider and the Service reports the assessment as unavailable rather than producing one.

The open sources the Service queries are not sub-processors. They are independent third parties from whom information is retrieved; we do not disclose your subjects to them beyond the identifier necessary to perform the lookup you requested.

6. Security measures

  • Encryption in transit (TLS) for all traffic, and encryption at rest for stored data.
  • Third-party credentials you supply are encrypted at rest with a separate application secret and are never returned to the browser.
  • Row-level security at the database, so tenant separation is enforced by the database rather than by application code that could forget.
  • Role-based access, with administrative surfaces restricted to named administrators.
  • Audit logging of account, billing and administrative events.
  • Least-privilege access for staff, granted only where operationally necessary.

7. Retention and deletion

Investigation data is retained while your subscription is active. On termination you may export it; after 30 days we delete or irreversibly anonymise it, except where we must retain records to meet a legal obligation — billing records being the usual case. Backups are cycled out on their own schedule and are not restored for the purpose of recovering deleted data.

8. International transfers

Where a sub-processor processes data outside the UK, transfers rely on UK adequacy regulations or on the International Data Transfer Addendum to the EU Standard Contractual Clauses. Application hosting is configured to the London region.

9. Audit

On reasonable written notice, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this Agreement. Where a sub-processor publishes an independent certification or report, we may provide that instead of an on-site audit.

10. Your responsibilities

You warrant that you have a lawful basis for the processing you instruct, that your own privacy information covers it, and that your use complies with the Acceptable Use Policy. The Service produces intelligence assessments from open sources; it does not make decisions about people. Any decision taken on the basis of a report is yours, and you are responsible for the fairness and lawfulness of that decision — including where it produces a legal or similarly significant effect on an individual.

11. Contact

Data protection enquiries, data subject requests and breach notifications: privacy@blackoutintelligence.co.uk.

This document describes how the Service actually operates and is provided in good faith. It is not legal advice. If you are relying on it commercially, have your own adviser review it against your circumstances.

Terms of ServicePrivacy PolicyAcceptable UseData Processing Agreement