Privacy Policy

Your data, your control.

Effective / Last updated: 2026-05-31 Ley 1581 (CO) · GDPR (EU/EEA) · UK GDPR · CCPA/CPRA (CA)

Legal draft: this policy is prepared for alignment with Colombia's Law 1581 of 2012 and applicable rules, but remains subject to legal review before being treated as legal advice or a legal guarantee.

Ready to choose a plan? View pricing →

Summary: Blackrack is a self-hosting infrastructure platform. We only collect data strictly necessary to operate the service. We never sell, share, or use your data to train AI models. You have full control and may exercise your rights at any time.

🌍 Your rights depend on where you live

This policy applies to everyone. Some regions grant you additional rights, so we've added jurisdiction-specific supplements. Jump straight to the one that applies to you:

No matter where you are, we never sell or share your personal data and never use it to train AI models. The supplements below only expand your rights; they never reduce them.

🏢 Who are we?

Blackrack is a self-hosting infrastructure service operated by USER TODO, based in Colombia.

We offer personal AI assistants, file storage, photo backup, password management, and media streaming: all hosted on your own infrastructure, under your control.

Responsible entity / Data Controller: USER TODO (sole proprietor / persona natural), based in Colombia. For purposes of the GDPR (EU 2016/679), the UK GDPR, and Colombian Law 1581 of 2012 (with Decree 1377 of 2013), Blackrack acts as the Data Controller for personal data collected during our commercial and onboarding processes.

📋 Data we collect

We collect data at two distinct moments: during the sales process and during active client onboarding.

Category Specific data Purpose
Prospect data Name, phone number (WhatsApp), conversation history, technology stack, budget signals Sales pipeline management and lead qualification
Client data Name, phone, email address, Discord/Element username, chosen assistant name Service delivery and technical support
Integration tokens OAuth tokens for Gmail, Google Calendar, Google Drive, Spotify or other voluntarily connected services Personal assistant operation (stored only in client's PVC, never copied)
Usage data Aggregated, anonymous usage metrics (system statistics, no PII) Service improvement
IP geolocation Country only, derived from your IP address via ipinfo.io. The IP is not stored. Personalize website language and currency

Important note on OAuth tokens: Access tokens for third-party services (Google, Spotify, etc.) are stored within the persistent volume (PVC) for the client's assigned gateway. Blackrack does not claim volume-level encryption unless that control has been verified for the specific deployment, and does not copy or share those tokens outside the operational scope needed to support and run the service.

Website geolocation: When you visit blackrack.app, our locale code queries ipinfo.io to detect your country only, so we can pre-select the right language (EN/ES) and currency. Your IP address is not stored on our servers; ipinfo.io acts as a processor. Your preference is saved locally in your browser (localStorage) and you can change it at any time via the language/currency selector.

⚙️ How we use your data

We use your data exclusively for the following purposes:

PurposeDescription
Service deliveryConfigure and operate your AI gateway and selected agent stack with agreed integrations.
Technical supportDiagnose and resolve issues with your infrastructure.
Service communicationsSend service updates, renewals, and contract-related communications.
Service improvementAnalyze aggregated, anonymous metrics to improve the platform.
Legal complianceHandle data rights requests and fulfill obligations under Law 1581 of 2012.

We do NOT use your data for: training AI models, advertising, selling to third parties, commercial profiling, or any purpose beyond those listed above.

🔗 Who we share data with

Blackrack does not sell or commercialize your personal data to third parties.

We may share data only in the following limited cases:

RecipientData sharedReason
Infrastructure providers
AWS (compute, storage, and encrypted S3 backups)
System data (encrypted, no PII) Infrastructure operation
Competent authorities
SIC, judicial authorities
Data required by law Compliance with legal requirements

Telnyx may process your phone number to route voice calls, subject to their own privacy policies.

🧩 Sub-processors

The following providers process data on our behalf, under contract and only per our instructions. We keep this list current and will give advance notice of material changes.

Sub-processorRoleProcessing region
Amazon Web Services (AWS)Compute, persistent storage, and encrypted S3 / Glacier backups. Kubernetes control plane and client gateways.US (us-east-1)
OpenAI / Gemini / Xiaomi / MiniMax / DeepSeekSupported AI model providers for inferenceDepends on configured provider
CloudflareCDN, DNS and DDoS mitigationGlobal (edge network)
Discord / ElementClient support and messaging channelUS
ipinfo.ioIP geolocation (country only; IP not stored)US

No sub-processor is permitted to use your data for its own purposes, sell it, or train models on it. AI model providers are used under enterprise/API plans that exclude training on your data.

✈️ International data transfers

Because our infrastructure and several sub-processors operate mainly in the United States, your data may be transferred outside your country. We rely on the following recognized transfer mechanisms:

Transfer routeLegal mechanism
EU/EEA → USEU–US Data Privacy Framework adequacy decision (2023) where the recipient is certified; otherwise EU Standard Contractual Clauses (SCCs) plus supplementary measures.
EU/EEA → ColombiaEU Standard Contractual Clauses (SCCs).
UK → US / othersUK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.
Colombia → USSIC model clauses and the technical and organizational measures described in the Security section, including TLS in transit, access control, monitoring, backups where applicable, and operational isolation by deployment/client.

You may request a copy of the applicable transfer mechanism by writing to privacy@blackrack.app.

🗓️ Retention & anonymization

We retain your data for as long as necessary to fulfill the purposes described in this policy.

Data typeRetention periodPost-retention treatment
Prospect data 24 months from last activity Anonymization: name and phone replaced with irreversible SHA-256 hash; conversation notes deleted
Active client data Contract duration + 12 months Deletion upon data subject request or after retention period
OAuth tokens Until service disconnection Deleted from PVC when gateway is cancelled
Aggregate metrics Indefinite Never contain PII; retained for business analytics

🇨🇴 Colombia: Your rights (ARCO)

Under Articles 8 and 12–15 of Colombian Law 1581 of 2012, you have the following rights over your personal data:

🔍
Access
10 business days

Request to know what personal data we hold about you and how we use it.

✏️
Rectification
15 business days

Request correction of inaccurate, incomplete or outdated data.

🗑️
Erasure
15 business days

Request deletion of your data when it is no longer necessary or consent has been withdrawn.

🚫
Objection
15 business days

Object to your data being used for a specific purpose, including commercial communications.

If we need more time, we will notify you within the initial deadline. We have an additional 8 business days with prior notice, as per Article 14 of Law 1581.

To exercise any right, contact us at privacy@blackrack.app or WhatsApp +57 310 413 1691, stating the right you wish to exercise, your full name, and associated phone number.

If you believe we have violated your data protection rights, you may file a complaint with the Superintendencia de Industria y Comercio (SIC): www.sic.gov.co.

🇪🇺 EU / EEA: GDPR supplement

If you are in the European Union or European Economic Area, the General Data Protection Regulation (GDPR, EU 2016/679) grants you the rights described below. The Data Controller is USER TODO (sole proprietor / persona natural), based in Colombia.

Lawful basis for processing (Art. 6)

ActivityLawful basis (Art. 6 GDPR)
Contact form / sales enquiriesLegitimate interest (Art. 6(1)(f)): to respond to and manage your request
Service delivery to clientsPerformance of a contract (Art. 6(1)(b))
AnalyticsConsent (Art. 6(1)(a)): optional self-hosted Umami analytics; off until you accept it
localStorage preferences (language/currency/consent)Strictly necessary / functional: no prior consent required
Country-level geolocation (ipinfo.io)Legitimate interest (Art. 6(1)(f)): locale personalization; country only, IP not stored
Legal / tax obligationsLegal obligation (Art. 6(1)(c))

Your 8 data-subject rights

  • Access (Art. 15): obtain a copy of your data.
  • Rectification (Art. 16): correct inaccurate data.
  • Erasure / "right to be forgotten" (Art. 17).
  • Restriction of processing (Art. 18).
  • Data portability (Art. 20): receive your data in a structured, machine-readable format.
  • Objection (Art. 21): including to legitimate-interest processing and direct marketing.
  • Not to be subject to automated decision-making (Art. 22): we do no profiling with legal effects.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.

To exercise any right, email privacy@blackrack.app. We respond without undue delay and within one month at the latest (Art. 12). In the event of a data breach posing a risk to your rights, we will notify the competent supervisory authority within 72 hours (Art. 33) and notify you without undue delay where the risk is high (Art. 34).

You have the right to lodge a complaint with your national Data Protection Authority (DPA) in the member state of your residence, place of work, or where the alleged infringement occurred. The directory of authorities is available from the European Data Protection Board (EDPB).

EU Representative (Art. 27): Blackrack does not currently maintain a formal Article 27 representative in the EU. EU/EEA residents may exercise their rights or raise concerns by contacting us directly at privacy@blackrack.app, and may lodge a complaint with their national data protection authority. We will appoint an EU representative as our EU customer base grows.

🇬🇧 United Kingdom: UK GDPR supplement

If you are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 grant you the same rights and lawful bases set out in the EU/EEA supplement above (access, rectification, erasure, restriction, portability, objection, automated decisions, and consent withdrawal), as well as the one-month response window and 72-hour breach notification.

You have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk.

UK Representative: Blackrack does not currently maintain a formal UK representative. UK residents may contact us at privacy@blackrack.app and may lodge a complaint with the UK Information Commissioner's Office (ICO, ico.org.uk). We will appoint a UK representative as our UK customer base grows.

🇺🇸 California: CCPA / CPRA

If you are a California resident, the CCPA (as amended by the CPRA) grants you the rights described below.

Categories of personal information we collect

Category (Cal. Civ. Code §1798.140)Examples
IdentifiersName, email, phone, Discord/Element username
Commercial informationContracted service, support history
Internet / network activityAggregated usage metrics; country derived from IP (IP not stored)
GeolocationApproximate country (country-level, not precise)

We do not sell or share ("Do Not Sell or Share") your personal information as defined by the CCPA/CPRA, and have not sold or shared it in the past 12 months. We also do not collect sensitive personal information categories for inference purposes.

Your rights

  • Know what personal information we collect, use, and disclose.
  • Delete the personal information we hold about you.
  • Correct inaccurate personal information.
  • Opt out of sale or sharing (not applicable: we do not sell or share).
  • Non-discrimination for exercising your rights: we will not deny service or change pricing.

To exercise these rights, email privacy@blackrack.app. We will verify your identity and respond within 45 days (extendable by a further 45 days with notice). You may designate an authorized agent to submit the request on your behalf.

🌎 Server location

By default, Blackrack infrastructure runs on servers located in the United States (AWS us-east-1). This includes client gateways, persistent storage, backups where applicable, and the Kubernetes control plane.

Clients with Colombian data residency requirements: If your organization requires data to remain within Colombian territory for legal, regulatory, or contractual compliance, Blackrack can deploy your infrastructure on servers located in Colombia. This option is available upon request: contact us at privacy@blackrack.app before onboarding.

OptionLocationAvailability
Standard United States (AWS us-east-1) Default for all clients
Colombia residency Colombia Available upon request before onboarding

International data transfers from Colombia to the United States are handled with applicable contractual mechanisms and the technical and organizational measures described in the Security section, including TLS in transit, access control, monitoring, backups where applicable, and operational isolation by deployment/client.

🔒 Security

We implement appropriate technical and organizational measures to protect your personal data:

MeasureDescription
TLS in transitCommunications between clients, the website, and infrastructure use TLS 1.2 or higher when traveling over public networks.
Persistent storageOperational data is stored in replicated Kubernetes/Longhorn persistent volumes. Encryption at rest: AWS S3 backups use SSE-S3 (AES-256) by default; Longhorn volumes for gateways do NOT have volume-level encryption enabled (the underlying AWS EBS disks may be encrypted depending on cluster configuration). We do not claim Longhorn volume encryption unless specifically verified for the deployment.
Operational client isolationEach client operates with its own gateway/deployment and associated persistent state. We apply operational separation by deployment/client without claiming a dedicated namespace unless specifically verified.
Restricted accessOnly authorized Blackrack personnel can access production systems, via multi-factor authentication.
Backups and monitoringWe operate backup/restore routines and service monitoring where applicable; scope and retention may vary by deployment or contract.

In the event of a security breach affecting your rights, we will notify you without undue delay and report to the competent authority as required by applicable law: to the SIC in Colombia, and to the relevant EU supervisory authority or the UK ICO within 72 hours under the GDPR / UK GDPR (Art. 33).

📝 Changes to this policy

We may update this Privacy Policy occasionally to reflect changes in our practices or applicable law. When we make material changes:

  • We will update the "Last updated" date at the top of this page.
  • We will notify you by email or WhatsApp if the change materially affects your rights.

Continued use of the service after notification implies acceptance of the updated version.

✉️ Contact

For questions about this policy, to exercise your rights, or to report a privacy incident:

10 active clients 100% uptime this month <48h setup
🏢
Controller / Legal entity
Blackrack: operated by USER TODO (persona natural), Colombia
📧
Privacy email
💬
WhatsApp
🇪🇺
EU Representative (Art. 27)
Not currently appointed. EU/EEA residents may contact us at privacy@blackrack.app and may lodge a complaint with their national data protection authority.
🇬🇧
UK Representative
Not currently appointed. UK residents may contact us at privacy@blackrack.app and may lodge a complaint with the ICO (ico.org.uk).
🌐
Supervisory authorities

See also our Cookie Policy and our Terms of Service.