BLACKFLAG ALERT takes the privacy of its users seriously. This policy explains what personal data we collect, why we collect it, the legal basis on which we process it, and the rights you have under UK data protection law.
Who we are
The data controller responsible for your personal data is Plainview Ventures Limited trading as Black Flag Alert, a company registered in England and Wales (company number 09687391) with its registered office at 15-17 Westmill Road, Ware, England, SG12 0EF.
We are registered with the Information Commissioner's Office (ICO) under registration number ZB628194. Where this policy refers to "we", "us" or "our", it means Plainview Ventures Limited trading as Black Flag Alert.
If you need to contact our Data Protection point of contact, please write to [email protected].
Personal data we collect
We collect and process the following categories of personal data:
Information you provide to us
- Account data: name, work email address, employer, job title.
- Enquiry data: any information you submit through our contact form, including the body of your message and an optional phone number.
- Communications: records of correspondence with our team.
Information we collect automatically
- Technical data: IP address, browser type and version, operating system, device identifiers, and access timestamps.
- Usage data: pages viewed, search queries within our platform, time spent on each page, and referring URLs.
- Cookies and similar technologies: see our Cookies Policy.
Information about England & Wales companies (not personal data)
The credit intelligence we publish about England & Wales limited companies, including financial accounts, director histories, and risk scores, is derived from public records held by Companies House and other authoritative sources. Information about a natural person acting in their capacity as a company director is processed only as it appears on the public register.
How and why we use your data
We process personal data only when we have a lawful basis to do so under Article 6 of the UK GDPR. The table below summarises our processing activities and the corresponding lawful basis.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Providing access to the platform | Account, technical | Performance of a contract |
| Responding to your enquiries | Enquiry, communications | Legitimate interests |
| Securing the platform & detecting abuse | Technical, usage | Legitimate interests |
| Sending product updates (where opted in) | Account | Consent |
| Complying with legal obligations | All categories, as required | Legal obligation |
| Aggregated analytics & service improvement | Technical, usage (anonymised) | Legitimate interests |
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure that our interests do not override your rights and freedoms. You may object to processing on this basis at any time (see Your rights).
Who we share data with
We do not sell your personal data. We share it only with the following categories of recipient:
- Service providers who help us operate the platform, including cloud hosting, email delivery, error monitoring, and customer support tooling. Each is bound by a written data processing agreement under Article 28 UK GDPR.
- Professional advisers including lawyers, accountants, and auditors, where necessary.
- Regulators and law enforcement where we are required by law, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, protect our rights, or protect the safety of others.
- Successors in a corporate transaction (such as a merger, acquisition, or restructuring), in which case data will be transferred on terms consistent with this policy.
International transfers
Our primary infrastructure is located in the United Kingdom and the European Economic Area. Where personal data is transferred outside the UK, we ensure that an appropriate safeguard under Article 46 UK GDPR is in place. This will usually be the International Data Transfer Agreement issued by the ICO, or the UK Addendum to the EU Standard Contractual Clauses. A list of relevant safeguards is available on request from [email protected].
How long we keep data
- Account data: for the duration of your account and 24 months after closure.
- Enquiry submissions: 24 months after the matter is closed.
- Server logs and security events: 12 months.
- Records required for legal or tax purposes: 6 years from the end of the relevant accounting period.
Where data is retained for security or legal reasons, we restrict access to it and use it only for those purposes.
Your rights
Under the UK GDPR, you have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — to ask us to delete your data, subject to certain exemptions.
- Right to restrict processing — to ask us to pause processing while a dispute is resolved.
- Right to data portability — to receive your data in a structured, machine-readable format.
- Right to object — to processing based on legitimate interests, or for direct marketing.
- Rights related to automated decision-making — we do not make decisions that produce legal effects concerning you based solely on automated processing.
- Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact [email protected]. We will respond within one calendar month of receiving a valid request. We may need to verify your identity before acting on a request.
Security
We use a combination of technical and organisational measures to protect personal data, including: encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, multi-factor authentication for staff, audit logging, regular penetration testing, and a documented incident response procedure. Despite these measures, no system is fully secure, and you transmit information to us at your own risk.
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify the ICO within 72 hours where required by law, and inform affected individuals without undue delay.
Cookies and tracking
We use a small number of cookies and similar technologies that are strictly necessary for the platform to function, together with optional analytics cookies that we will only set with your consent. For a full breakdown and the controls available to you, please see our Cookies Policy.
Children
Our service is aimed at business users and not at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe that a child has provided us with personal data, please contact us and we will delete it.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, or legal requirements. The "Last updated" date at the top of this page indicates when the policy was last revised. Where changes are material, we will give you reasonable notice through the platform or by email before the changes take effect.
Complaints to the ICO
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
Web: ico.org.uk/make-a-complaint
We would, however, appreciate the chance to address your concerns directly before you approach the ICO.
Contact us
For privacy-related questions, requests to exercise your rights, or concerns about how we handle your data, please contact:
- Email: [email protected]
- Post: Data Protection, Plainview Ventures Limited t/a Black Flag Alert, 15-17 Westmill Road, Ware, England, SG12 0EF
- General enquiries: contact form