GDPR Statement

We built the product to collect as little as possible.

BlackFog products are designed to be GDPR compliant and to limit the collection of personally identifiable information wherever possible. Here is exactly what the agent sends, and how long we keep it.

at a glance

Console data retention

90 days

Records purged after account ends

90 days

Credit card data stored

never

In force since

25 May 2018

What the regulation is

The EU General Data Protection Regulation came into force on May 25, 2018. It builds on existing data protection law, strengthens the rights EU individuals hold over their personal data, and creates a single data protection approach across Europe.

data collection

What leaves the device.

BlackFog was specifically designed to limit data collection by third parties. That principle applies to us too.

Outbound data, in full

nothing else leaves

Analysis happens on the device. The only data sent to BlackFog is:

  • License verification.

  • Lookup of unknown IP addresses, for threat detection and blocking.

  • Alerts to the centralized cloud console, so attacks can be monitored across devices.

Console alerts contain:

  • Device name and specifications.

  • Alerts to the centralized cloud console, so attacks can be monitored across devices.

  • Stored for 90 days, then purged, unless the customer extends it.

retention

Nothing is kept longer than it is needed.

90 days

Console data

Stored for 90 days then purged, unless the customer extends the period.

90 days

Customer records

Retained while the account is active, purged within 90 days of it closing.

Never

Credit card details

No card information is ever stored with BlackFog. Our payment provider handles it directly.

your rights

Processors and data requests.

Third-party processors

Our Data Processing Agreement lists every third-party processor we use and the controls applied to each.

Data export request

GDPR gives you the right to see what has been collected. Submit a request through our contact form.

Questions about how we handle data?

Certifications, subprocessors and every agreement we publish are in the Trust Center.