Your data, your control.
Legal draft: this policy is prepared for alignment with Colombia's Law 1581 of 2012 and applicable rules, but remains subject to legal review before being treated as legal advice or a legal guarantee.
Ready to choose a plan? View pricing →
Summary: Blackrack is a self-hosting infrastructure platform. We only collect data strictly necessary to operate the service. We never sell, share, or use your data to train AI models. You have full control and may exercise your rights at any time.
Your rights depend on where you live
This policy applies to everyone. Some regions grant you additional rights, so we've added jurisdiction-specific supplements. Jump straight to the one that applies to you:
Habeas Data rights: access, rectification, erasure and objection.
8 data-subject rights, Art. 6 lawful basis, complaint to your national DPA.
Same rights as GDPR; complaint to the ICO.
Know, delete, correct, opt-out. We do not sell your data.
No matter where you are, we never sell or share your personal data and never use it to train AI models. The supplements below only expand your rights; they never reduce them.
Who are we?
Blackrack is a self-hosting infrastructure service operated by USER TODO, based in Colombia.
We offer personal AI assistants, file storage, photo backup, password management, and media streaming: all hosted on your own infrastructure, under your control.
Responsible entity / Data Controller: USER TODO (sole proprietor / persona natural), based in Colombia. For purposes of the GDPR (EU 2016/679), the UK GDPR, and Colombian Law 1581 of 2012 (with Decree 1377 of 2013), Blackrack acts as the Data Controller for personal data collected during our commercial and onboarding processes.
Legal framework
Blackrack is operated by USER TODO as a sole proprietor (persona natural), based in Colombia. This section summarizes the legal framework applicable to our processing of personal data and the scope of our obligations before the Superintendencia de Industria y Comercio (SIC).
Law 1581 of 2012 and Decree 1074 of 2015 (which compiled Decree 1377 of 2013): Blackrack acts as the Data Controller for personal data collected during commercial and onboarding processes. We comply with all operational duties of Law 1581, including:
- Free, prior, express and informed consent for prospect data processing.
- A public and accessible Information Treatment Policy (this page).
- Procedures to handle ARCO data-subject requests within statutory deadlines (10/15 business days).
- Database and sub-processor inventory.
- Adequate technical and organizational security measures.
- Notice to the SIC and to data subjects in the event of security incidents with material impact, in accordance with applicable law.
Registro Nacional de Bases de Datos (RNBD): Per the SIC bulletin on obligated persons, RNBD registration applies to (i) companies and non-profit entities with total assets above 100,000 UVT (COP $5,237,400,000 in 2026) and (ii) public legal entities. Sole proprietors (personas naturales comerciantes) are not obligated to register. Blackrack, as a sole proprietor, is not required to inscribe in the RNBD, without prejudice to the full application of the other Law 1581 obligations.
Internal decision record: the full rationale and the trigger conditions that could change this decision are recorded in our internal compliance file (`Ops/compliance/rnbd-applicability.md`).
Data we collect
We collect data at two distinct moments: during the sales process and during active client onboarding.
| Category | Specific data | Purpose |
|---|---|---|
| Prospect data | Name, phone number (WhatsApp), conversation history, technology stack, budget signals | Sales pipeline management and lead qualification |
| Client data | Name, phone, email address, Discord/Element username, chosen assistant name | Service delivery and technical support |
| Integration tokens | OAuth tokens for Gmail, Google Calendar, Google Drive, Spotify or other voluntarily connected services | Personal assistant operation (stored only in client's PVC, never copied) |
| Usage data | Aggregated, anonymous usage metrics (system statistics, no PII) | Service improvement |
| IP geolocation | Country only, derived from your IP address via ipinfo.io. The IP is not stored. | Personalize website language and currency |
Important note on OAuth tokens: Access tokens for third-party services (Google, Spotify, etc.) are stored within the persistent volume (PVC) for the client's assigned gateway. Blackrack does not claim volume-level encryption unless that control has been verified for the specific deployment, and does not copy or share those tokens outside the operational scope needed to support and run the service.
Website geolocation: When you visit blackrack.app, our locale code queries ipinfo.io to detect your country only, so we can pre-select the right language (EN/ES) and currency. Your IP address is not stored on our servers; ipinfo.io acts as a processor. Your preference is saved locally in your browser (localStorage) and you can change it at any time via the language/currency selector.
How we use your data
We use your data exclusively for the following purposes:
| Purpose | Description |
|---|---|
| Service delivery | Configure and operate your AI gateway and selected agent stack with agreed integrations. |
| Technical support | Diagnose and resolve issues with your infrastructure. |
| Service communications | Send service updates, renewals, and contract-related communications. |
| Service improvement | Analyze aggregated, anonymous metrics to improve the platform. |
| Legal compliance | Handle data rights requests and fulfill obligations under Law 1581 of 2012. |
We do NOT use your data for: training AI models, advertising, selling to third parties, commercial profiling, or any purpose beyond those listed above.
Legal basis
The processing of your personal data is based on the following legal grounds under Colombian Law 1581 of 2012:
| Legal basis | Application |
|---|---|
| Free, prior, express and informed consent | Prospect data: granted when initiating the commercial conversation and accepting the Habeas Data notice. |
| Contract performance | Active client data: necessary to deliver the contracted service. |
| Legal obligation | Data retention to process rights requests and applicable tax obligations. |
| Legitimate interests | Aggregated, anonymous metrics for service improvement. |
For Colombian prospects, the Habeas Data notice is delivered in the first message of every new conversation, in accordance with Article 12 of Law 1581 and Article 7 of Decree 1377 of 2013.
Who we share data with
Blackrack does not sell or commercialize your personal data to third parties.
We may share data only in the following limited cases:
| Recipient | Data shared | Reason |
|---|---|---|
| Infrastructure providers AWS (compute, storage, and encrypted S3 backups) |
System data (encrypted, no PII) | Infrastructure operation |
| Competent authorities SIC, judicial authorities |
Data required by law | Compliance with legal requirements |
Telnyx may process your phone number to route voice calls, subject to their own privacy policies.
Sub-processors
The following providers process data on our behalf, under contract and only per our instructions. We keep this list current and will give advance notice of material changes.
| Sub-processor | Role | Processing region |
|---|---|---|
| Amazon Web Services (AWS) | Compute, persistent storage, and encrypted S3 / Glacier backups. Kubernetes control plane and client gateways. | US (us-east-1) |
| OpenAI / Gemini / Xiaomi / MiniMax / DeepSeek | Supported AI model providers for inference | Depends on configured provider |
| Cloudflare | CDN, DNS and DDoS mitigation | Global (edge network) |
| Discord / Element | Client support and messaging channel | US |
| ipinfo.io | IP geolocation (country only; IP not stored) | US |
No sub-processor is permitted to use your data for its own purposes, sell it, or train models on it. AI model providers are used under enterprise/API plans that exclude training on your data.
International data transfers
Because our infrastructure and several sub-processors operate mainly in the United States, your data may be transferred outside your country. We rely on the following recognized transfer mechanisms:
| Transfer route | Legal mechanism |
|---|---|
| EU/EEA → US | EU–US Data Privacy Framework adequacy decision (2023) where the recipient is certified; otherwise EU Standard Contractual Clauses (SCCs) plus supplementary measures. |
| EU/EEA → Colombia | EU Standard Contractual Clauses (SCCs). |
| UK → US / others | UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs. |
| Colombia → US | SIC model clauses and the technical and organizational measures described in the Security section, including TLS in transit, access control, monitoring, backups where applicable, and operational isolation by deployment/client. |
You may request a copy of the applicable transfer mechanism by writing to privacy@blackrack.app.
Retention & anonymization
We retain your data for as long as necessary to fulfill the purposes described in this policy.
| Data type | Retention period | Post-retention treatment |
|---|---|---|
| Prospect data | 24 months from last activity | Anonymization: name and phone replaced with irreversible SHA-256 hash; conversation notes deleted |
| Active client data | Contract duration + 12 months | Deletion upon data subject request or after retention period |
| OAuth tokens | Until service disconnection | Deleted from PVC when gateway is cancelled |
| Aggregate metrics | Indefinite | Never contain PII; retained for business analytics |
Colombia: Your rights (ARCO)
Under Articles 8 and 12–15 of Colombian Law 1581 of 2012, you have the following rights over your personal data:
Request to know what personal data we hold about you and how we use it.
Request correction of inaccurate, incomplete or outdated data.
Request deletion of your data when it is no longer necessary or consent has been withdrawn.
Object to your data being used for a specific purpose, including commercial communications.
If we need more time, we will notify you within the initial deadline. We have an additional 8 business days with prior notice, as per Article 14 of Law 1581.
To exercise any right, contact us at privacy@blackrack.app or WhatsApp +57 310 413 1691, stating the right you wish to exercise, your full name, and associated phone number.
If you believe we have violated your data protection rights, you may file a complaint with the Superintendencia de Industria y Comercio (SIC): www.sic.gov.co.
EU / EEA: GDPR supplement
If you are in the European Union or European Economic Area, the General Data Protection Regulation (GDPR, EU 2016/679) grants you the rights described below. The Data Controller is USER TODO (sole proprietor / persona natural), based in Colombia.
Lawful basis for processing (Art. 6)
| Activity | Lawful basis (Art. 6 GDPR) |
|---|---|
| Contact form / sales enquiries | Legitimate interest (Art. 6(1)(f)): to respond to and manage your request |
| Service delivery to clients | Performance of a contract (Art. 6(1)(b)) |
| Analytics | Consent (Art. 6(1)(a)): optional self-hosted Umami analytics; off until you accept it |
| localStorage preferences (language/currency/consent) | Strictly necessary / functional: no prior consent required |
| Country-level geolocation (ipinfo.io) | Legitimate interest (Art. 6(1)(f)): locale personalization; country only, IP not stored |
| Legal / tax obligations | Legal obligation (Art. 6(1)(c)) |
Your 8 data-subject rights
- Access (Art. 15): obtain a copy of your data.
- Rectification (Art. 16): correct inaccurate data.
- Erasure / "right to be forgotten" (Art. 17).
- Restriction of processing (Art. 18).
- Data portability (Art. 20): receive your data in a structured, machine-readable format.
- Objection (Art. 21): including to legitimate-interest processing and direct marketing.
- Not to be subject to automated decision-making (Art. 22): we do no profiling with legal effects.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any right, email privacy@blackrack.app. We respond without undue delay and within one month at the latest (Art. 12). In the event of a data breach posing a risk to your rights, we will notify the competent supervisory authority within 72 hours (Art. 33) and notify you without undue delay where the risk is high (Art. 34).
You have the right to lodge a complaint with your national Data Protection Authority (DPA) in the member state of your residence, place of work, or where the alleged infringement occurred. The directory of authorities is available from the European Data Protection Board (EDPB).
EU Representative (Art. 27): Blackrack does not currently maintain a formal Article 27 representative in the EU. EU/EEA residents may exercise their rights or raise concerns by contacting us directly at privacy@blackrack.app, and may lodge a complaint with their national data protection authority. We will appoint an EU representative as our EU customer base grows.
United Kingdom: UK GDPR supplement
If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 grant you the same rights and lawful bases set out in the EU/EEA supplement above (access, rectification, erasure, restriction, portability, objection, automated decisions, and consent withdrawal), as well as the one-month response window and 72-hour breach notification.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk.
UK Representative: Blackrack does not currently maintain a formal UK representative. UK residents may contact us at privacy@blackrack.app and may lodge a complaint with the UK Information Commissioner's Office (ICO, ico.org.uk). We will appoint a UK representative as our UK customer base grows.
California: CCPA / CPRA
If you are a California resident, the CCPA (as amended by the CPRA) grants you the rights described below.
Categories of personal information we collect
| Category (Cal. Civ. Code §1798.140) | Examples |
|---|---|
| Identifiers | Name, email, phone, Discord/Element username |
| Commercial information | Contracted service, support history |
| Internet / network activity | Aggregated usage metrics; country derived from IP (IP not stored) |
| Geolocation | Approximate country (country-level, not precise) |
We do not sell or share ("Do Not Sell or Share") your personal information as defined by the CCPA/CPRA, and have not sold or shared it in the past 12 months. We also do not collect sensitive personal information categories for inference purposes.
Your rights
- Know what personal information we collect, use, and disclose.
- Delete the personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of sale or sharing (not applicable: we do not sell or share).
- Non-discrimination for exercising your rights: we will not deny service or change pricing.
To exercise these rights, email privacy@blackrack.app. We will verify your identity and respond within 45 days (extendable by a further 45 days with notice). You may designate an authorized agent to submit the request on your behalf.
Server location
By default, Blackrack infrastructure runs on servers located in the United States (AWS us-east-1). This includes client gateways, persistent storage, backups where applicable, and the Kubernetes control plane.
Clients with Colombian data residency requirements: If your organization requires data to remain within Colombian territory for legal, regulatory, or contractual compliance, Blackrack can deploy your infrastructure on servers located in Colombia. This option is available upon request: contact us at privacy@blackrack.app before onboarding.
| Option | Location | Availability |
|---|---|---|
| Standard | United States (AWS us-east-1) | Default for all clients |
| Colombia residency | Colombia | Available upon request before onboarding |
International data transfers from Colombia to the United States are handled with applicable contractual mechanisms and the technical and organizational measures described in the Security section, including TLS in transit, access control, monitoring, backups where applicable, and operational isolation by deployment/client.
Security
We implement appropriate technical and organizational measures to protect your personal data:
| Measure | Description |
|---|---|
| TLS in transit | Communications between clients, the website, and infrastructure use TLS 1.2 or higher when traveling over public networks. |
| Persistent storage | Operational data is stored in replicated Kubernetes/Longhorn persistent volumes. Encryption at rest: AWS S3 backups use SSE-S3 (AES-256) by default; Longhorn volumes for gateways do NOT have volume-level encryption enabled (the underlying AWS EBS disks may be encrypted depending on cluster configuration). We do not claim Longhorn volume encryption unless specifically verified for the deployment. |
| Operational client isolation | Each client operates with its own gateway/deployment and associated persistent state. We apply operational separation by deployment/client without claiming a dedicated namespace unless specifically verified. |
| Restricted access | Only authorized Blackrack personnel can access production systems, via multi-factor authentication. |
| Backups and monitoring | We operate backup/restore routines and service monitoring where applicable; scope and retention may vary by deployment or contract. |
In the event of a security breach affecting your rights, we will notify you without undue delay and report to the competent authority as required by applicable law: to the SIC in Colombia, and to the relevant EU supervisory authority or the UK ICO within 72 hours under the GDPR / UK GDPR (Art. 33).
Changes to this policy
We may update this Privacy Policy occasionally to reflect changes in our practices or applicable law. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify you by email or WhatsApp if the change materially affects your rights.
Continued use of the service after notification implies acceptance of the updated version.
Contact
For questions about this policy, to exercise your rights, or to report a privacy incident:
See also our Cookie Policy and our Terms of Service.