Blacklink Privacy Policy

Version 1.2 — effective 24 September 2026

This policy explains what personal data Blacklink collects, why, who it is shared with, how long it is kept, and what rights you have. It covers the Blacklink app and the website at joinblacklink.com. We have written it in plain English on purpose. If anything is unclear, email us.

1. Who we are

Blacklink is operated by Kai O'Donnell, trading as Blacklink, based in the United Kingdom.

Contact address: 28 Cottesbrook Gardens, Northampton, NN4 0DE
Email: hello@joinblacklink.com

For data protection law, Kai O'Donnell is the "controller" of your personal data.

2. Who can use Blacklink

Blacklink is for people aged 16 and over. We ask for your date of birth when you create a profile and do not allow accounts for anyone under 16. If we learn that an account belongs to someone under 16, we will delete it. If you believe a user is under 16, email us.

3. What we collect

When you create an account

Your profile

What you do in Blacklink

Voice

Technical data

Website (joinblacklink.com)

Support

4. Why we use your data, and our legal basis

PurposeData usedLegal basis
Creating and running your account and delivering the service (groups, rooms, messaging, wins)Account, profile, activity, technical dataPerformance of our contract with you (the Terms)
Keeping members safe: moderation, handling reports and blocks, removing rule-breaking content, banning accountsActivity data, reports, messages when reportedLegitimate interests (safety of members) and legal obligations, including UK online safety law
Security, fraud prevention, and keeping the service workingTechnical data, logsLegitimate interests
The rank system (calculating your rank from your activity)Rank and activity metricsLegitimate interests (running a feature of the service); you can object, see section 8
Sending push notifications about messages, seat activity, and winsPush tokenYour consent via your device settings; you can turn them off at any time
Emailing the waiting list about early access to Blacklink and its launchWaiting-list emailConsent; every email includes an unsubscribe link
Responding to your requests and legal obligationsSupport correspondence, relevant recordsLegal obligation and legitimate interests

We do not sell your data. We do not show advertising. We do not use your data to make automated decisions with legal or similarly significant effects on you.

5. Who we share your data with

We use a small number of service providers ("processors") to run Blacklink. They act on our instructions and are contractually bound to protect your data.

Other members see your profile, your presence at war-room tables, your room chat messages, your wins, and, if they message you, your direct messages.

Authorities: we may share data where the law requires it, for example to comply with a court order or a request from a regulator such as Ofcom or the Information Commissioner's Office, or where necessary to protect someone from serious harm.

We may transfer the business, including this data, if Blacklink is sold or restructured. We would tell you first.

6. International transfers

Your data is stored in the United Kingdom. Some of our providers (Apple, Expo, LiveKit) may process limited technical data in the United States or elsewhere. Where that happens we rely on the safeguards recognised under UK and EU law, such as adequacy decisions, the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses.

7. How long we keep your data

8. Your rights

Under UK GDPR and, for EU residents, the EU GDPR, you have the right to:

To exercise any right, email hello@joinblacklink.com from the address linked to your account. We will respond within one month. We may ask you to confirm your identity.

If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office at ico.org.uk or, if you live in the EU, to your national data protection authority. We would appreciate the chance to resolve any concern first.

9. Security

Your data is stored in encrypted form at rest and in transit. Access to Blacklink's systems is limited to the operator and protected by two-factor authentication. Database access rules mean members can only read and write what they are entitled to; for example, direct messages are only readable by their two participants, and room passwords are stored as one-way hashes. No online service can promise perfect security. If we discover a breach that puts your data at risk, we will inform the ICO within 72 hours as the law requires and tell affected members without undue delay.

10. Changes to this policy

If we make significant changes, we will tell you in the app or by email before they take effect, and we will keep the previous version available on request. The version number and effective date at the top of this policy tell you which version applies.

11. Contact

Kai O'Donnell, trading as Blacklink
28 Cottesbrook Gardens, Northampton, NN4 0DE
hello@joinblacklink.com