Skip to content
Legal · Privacy

Privacy Policy & Data Processing Notice

Effective July 2026 · Blacklight AI

Privacy Policy and Data Processing Notice

Blacklight AI (“we”, “us”, “our”) is committed to protecting and respecting your privacy. This notice explains what personal data we collect, how we use it, and the rights you have. It applies to this website and our interactions with you.

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Who we are and what we do

Blacklight AI is a cybersecurity software company. We provide an AI-native security platform and managed security services. We collect personal data about:

  • prospective and current customer contacts;
  • supplier and partner contacts;
  • our team members and contractors.

Information you give to us, or we collect about you

Information you provide. When you fill in a form on our site, request a demo, subscribe to our Cybersecurity Intel Report, or otherwise contact us, you may give us your name, work email, company, role, sector, and any message you send. Providing this is your choice.

Information collected automatically. When you use our site we may collect device and usage data such as IP address, browser and operating system, and pages viewed, through cookies and similar technologies (see our Cookie Policy). Where this identifies you, we treat it as personal data.

Sensitive personal data

We do not seek to collect special-category (sensitive) personal data through this site. If you choose to provide it unsolicited, you consent to our using it subject to applicable law.

How we use personal data

Our lawful bases for processing are: performance of a contract, our legitimate business interests, compliance with legal obligations, and, where required, your consent.

We use personal data to:

  • respond to your enquiries and provide demos, information, products and services you request;
  • provide, operate, secure and improve our platform and services, and customer support;
  • send you communications you have asked for, such as the Cybersecurity Intel Report (you can unsubscribe at any time);
  • protect the security and safety of our customers and systems, and prevent fraud and abuse;
  • run aggregate analysis and business operations, and meet our legal and regulatory obligations.

We do not sell your personal data, and we do not use the contents of your communications to target advertising to you.

Cookies

We use cookies and similar technologies for essential functionality and, only with your consent, for anonymous analytics. See our Cookie Policy for details and how to manage your choice.

Disclosure of your information

We may share your personal data with: service providers and sub-processors who help us operate (under contract and appropriate safeguards); our professional advisers and auditors; and authorities where we are legally required to. If our business or its assets are acquired by a third party, personal data held by us may be one of the transferred assets. We require our processors to protect personal data to at least the standard set out in this notice.

Where we store and process your personal data

We store and process personal data on secure servers in the UK and the European Economic Area. Where personal data is transferred outside the UK/EEA, we rely on an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Agreement or Standard Contractual Clauses). Transmission over the internet is never completely secure; we use strict procedures and security features to protect your data once we receive it.

How we protect your information

We adopt appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure or destruction. Our information-security management system is independently certified to ISO/IEC 27001:2022. Data in transit is protected over encrypted channels.

Retention

We retain personal data only for as long as we need it for the purposes described in this notice or to meet our legal obligations, generally up to 6 years, after which it is deleted or pseudonymised. The criteria we use include the nature of the data, our legal obligations, and whether a contractual relationship is in place.

Children

Our services are not directed at children. We do not knowingly collect personal data from anyone under 16.

Your rights

Under the UK GDPR you have the right to be informed, the right of access, and the rights to rectification, erasure, restriction of processing, data portability, and to object to processing. You also have the right to withdraw consent where processing is based on consent.

To exercise any of these rights, email info@blacklightai.com. We will respond without undue delay and within one month, extendable by two further months for complex or numerous requests (we will tell you if so). You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk.

If we process your personal data on behalf of one of our customers (as a processor), we will forward your request to the relevant customer.

Changes to this notice

We may update this notice from time to time. The current version is always published on this page and, where appropriate, we will notify you. Please check this page periodically.

How to contact us

Questions, comments and requests regarding this notice are welcome and should be addressed to info@blacklightai.com. Blacklight AI is the data controller for personal data collected through the services subject to this notice. Our address is 111 Park Street, London W1K 7JF, United Kingdom.

Questions about this notice or to exercise your rights: email info@blacklightai.com.