Legal
Privacy & Data Protection Notice
This notice explains how Blackstone Intelligence Group collects, uses, discloses, transfers, secures and retains personal data, and the rights available to you. Version [VERSION NUMBER]. Effective date: [DATE]. Last reviewed: [DATE].
1. Purpose and scope of this notice
Blackstone Intelligence Group ("Blackstone", "we", "us", "our") provides confidential investigative, cyber intelligence, digital forensics, cryptocurrency tracing and asset-tracing support services. This notice describes our processing of personal data in connection with:
- this website, including the enquiry form, and any subdomain or successor site;
- enquiries, correspondence and pre-engagement assessments;
- client engagements, insofar as not superseded by an engagement agreement or data processing agreement;
- supplier, subcontractor, associate and recruitment relationships; and
- marketing communications you have expressly requested.
Where we act as a processor or service provider on a client's instructions, the client's own privacy notice and our data processing agreement govern that processing, and this notice describes only our independent controller activities.
2. Identity and contact details of the controller
The controller (and, where Australian or Canadian law applies, the entity accountable for the personal information) is Blackstone Intelligence Group, registered as [LEGAL ENTITY NAME], company registration number [REGISTRATION NUMBER], registered office [REGISTERED OFFICE ADDRESS].
- Privacy contact: [EMAIL ADDRESS]
- Telephone: [PHONE NUMBER]
- Postal: Dronning Eufemias gate 8, Bjørvika, 0191 Oslo
- Data Protection Officer / privacy officer: [DPO NAME AND CONTACT], appointed under Article 37 GDPR where required.
- EU representative under Article 27 GDPR (if established outside the EU): [EU REPRESENTATIVE DETAILS].
- UK representative under Article 27 UK GDPR (if applicable): [UK REPRESENTATIVE DETAILS].
3. Laws we apply
Depending on your location and the matter concerned, we process personal data in accordance with:
- Regulation (EU) 2016/679 (the GDPR) and national implementing laws;
- the Norwegian Personal Data Act (personopplysningsloven) and applicable guidance of Datatilsynet;
- the UK GDPR and the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR);
- the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme, and the Spam Act 2003 (Cth);
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), substantially similar provincial legislation, and Canada's Anti-Spam Legislation (CASL); and
- Directive 2002/58/EC as implemented locally in respect of cookies and similar technologies.
4. Categories of personal data we collect
4.1 Data you provide directly
- Identity and contact data: name, email address, optional telephone number, organization, role and country.
- Enquiry data: matter type and the free-text outline you choose to submit, together with your consent record.
- Engagement data: where we are instructed, information required for client onboarding, conflict checks, anti-money-laundering and know-your-client checks, billing and correspondence.
4.2 Data generated automatically
- Technical data: IP address, user-agent string, referring URL, approximate location derived from IP, request timestamps and security logs, processed by our hosting and security providers.
- Anti-abuse data: signals used to detect automated submissions, including a hidden form field and the elapsed time before submission.
4.3 Data obtained from third parties
- publicly available registers, court and insolvency records, corporate filings, sanctions and adverse-media sources, and lawfully accessible open-source information;
- blockchain and distributed-ledger data, which is public by design;
- information provided by clients, their advisers, insurers or law-enforcement contacts in the course of an instruction.
4.4 Special category and sensitive data
Investigative work can incidentally involve special category data under Article 9 GDPR (such as data revealing alleged criminal conduct under Article 10, health, or political opinions) or "sensitive information" under APP 3. We minimise such processing, restrict it to what is strictly necessary for the establishment, exercise or defence of legal claims, and apply the additional safeguards recorded in our appropriate-policy document: [APPROPRIATE POLICY DOCUMENT REFERENCE].
Please do not submit credentials, private keys, seed phrases, wallet recovery data, government identifiers, payment card numbers, health information, or confidential case material through this website. Where such material reaches us unnecessarily we delete it and record the deletion.
5. Purposes and lawful bases
Where the GDPR or UK GDPR applies, we rely on the following bases:
- Responding to your enquiry and assessing whether we can assist — Article 6(1)(b) (steps prior to a contract) and Article 6(1)(f) (legitimate interests in responding to business enquiries).
- Performing an engagement — Article 6(1)(b), and Article 6(1)(f) where the data subject is not our client.
- Conducting investigations lawfully instructed by a client — Article 6(1)(f), balanced against the rights of the individuals concerned and documented in a legitimate interests assessment; Article 9(2)(f) and Article 10 conditions where relevant.
- Legal, regulatory and professional obligations — Article 6(1)(c), including anti-money-laundering, tax and record-keeping duties.
- Site security, fraud prevention and abuse mitigation — Article 6(1)(f).
- Optional communications you request — Article 6(1)(a) consent, withdrawable at any time without affecting prior lawful processing.
Under the APPs we collect only information reasonably necessary for our functions or activities (APP 3) and notify collection as required (APP 5). Under PIPEDA we rely on your knowledge and consent, or on an applicable exception in section 7 — including investigations of a breach of an agreement or contravention of law, and disclosures to an investigative body — and we identify purposes before or at collection.
6. Recipients and disclosures
We do not sell personal data and we do not engage in behavioural advertising. We disclose personal data only to:
- processors that host this website, deliver email, or provide secure file transfer and case-management tooling, each under a written contract meeting Article 28 GDPR and equivalent APP 8 / PIPEDA accountability requirements. Current processors: [PROCESSOR LIST WITH LOCATIONS AND PURPOSES];
- our clients and, where they direct, their legal advisers, insurers or the courts;
- professional advisers, auditors and insurers bound by confidentiality;
- law enforcement, regulators or courts where disclosure is legally required or permitted, subject to our policy of requiring lawful process and recording each request; and
- a successor entity in a corporate transaction, subject to equivalent protection.
7. International transfers
We operate across Europe, Canada and Australia. Where personal data leaves the EEA, the UK, Australia or Canada, we rely on an adequacy decision where one exists, or otherwise on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK transfers, the ICO International Data Transfer Agreement or Addendum, supported by a transfer risk assessment. For APP 8 purposes we take reasonable steps to ensure overseas recipients handle information consistently with the APPs. Copies of the safeguards, and the countries involved, are available on request from [EMAIL ADDRESS]. Current transfer destinations: [TRANSFER DESTINATIONS].
8. Retention
We keep personal data only as long as necessary for the purpose for which it was collected, and then delete, destroy or irreversibly anonymise it:
- Unsuccessful or declined enquiries: [RETENTION PERIOD — e.g. 12 months].
- Client engagement files and reports: [RETENTION PERIOD], reflecting limitation periods and professional-indemnity requirements.
- Anti-money-laundering and identification records: the minimum statutory period applicable in the relevant jurisdiction, currently [AML RETENTION PERIOD].
- Financial and tax records: [FINANCE RETENTION PERIOD].
- Website security logs: [LOG RETENTION PERIOD].
Our full retention schedule is available on request.
9. Cookies and similar technologies
This website sets only cookies and local storage strictly necessary for its operation and security; no analytics, profiling or advertising technologies are used at the date of this notice. Consequently no consent banner is presented, consistent with the strictly-necessary exemption in Article 5(3) of Directive 2002/58/EC and PECR regulation 6(4). If measurement or marketing technologies are introduced, we will first implement a compliant consent mechanism providing granular, freely given, revocable choice, publish a cookie table identifying each cookie, its purpose, provider and duration, and update this notice.
10. Electronic marketing
We send commercial electronic messages only with the consent required by PECR, the Australian Spam Act 2003 and CASL, or where a narrow soft-opt-in applies. Every message identifies the sender, provides accurate contact details and includes a functioning unsubscribe facility honoured promptly. You may object at any time by contacting [EMAIL ADDRESS].
11. Automated decision-making and profiling
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. Analytical tooling used in investigations always informs, and never replaces, human assessment by a qualified investigator.
12. Your rights
Subject to conditions and exemptions in applicable law, you may request:
- confirmation of processing and access to a copy of your personal data;
- rectification of inaccurate or incomplete data;
- erasure where no overriding legal ground or obligation applies;
- restriction of processing, including while accuracy is verified;
- portability of data you provided under consent or contract, in a structured, commonly used, machine-readable format;
- objection to processing based on legitimate interests, and to direct marketing at any time;
- withdrawal of consent where consent is the basis; and
- not to be subject to unlawful automated decision-making.
We respond within one month under the GDPR and UK GDPR (extendable by two further months for complex requests, with notice), within 30 days under PIPEDA, and within a reasonable period — generally 30 days — under the APPs. Verification of identity may be required and is used solely for that purpose.
Investigative exemptions. Certain rights may be lawfully restricted where compliance would prejudice the prevention or detection of crime, the assessment or collection of a tax, legal professional privilege, or the establishment, exercise or defence of legal claims — for example under Schedule 2 of the UK Data Protection Act 2018, equivalent national derogations under Article 23 GDPR, APP 12.3, or sections 9 and 12 of PIPEDA. Where we rely on such a restriction we tell you so far as we lawfully can, record the reasons, and inform you of your right to complain.
13. Complaints
Please raise concerns with us first at [EMAIL ADDRESS]; we investigate and respond in writing. You may also complain to a supervisory authority, including:
- Norway: Datatilsynet (the Norwegian Data Protection Authority);
- United Kingdom: the Information Commissioner's Office;
- Australia: the Office of the Australian Information Commissioner;
- Canada: the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner; and
- elsewhere in the EEA, the authority of your habitual residence, place of work or the place of the alleged infringement.
14. Security
We implement technical and organisational measures appropriate to the risk under Article 32 GDPR and APP 11, including encryption in transit and at rest, least-privilege access controls, multi-factor authentication, segregated case storage, vetting and confidentiality undertakings for personnel, secure destruction procedures, logging and monitoring, and periodic review. No transmission or storage method is entirely secure, and we cannot guarantee absolute security.
15. Personal data breaches
We maintain an incident-response procedure. Where a breach is likely to result in a risk to individuals' rights and freedoms we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours, and notify affected individuals where the risk is high. Eligible data breaches are notified to the Office of the Australian Information Commissioner and affected individuals under the Notifiable Data Breaches scheme, and reports of breaches creating a real risk of significant harm are made under PIPEDA.
16. Children
This website is directed to businesses and professional advisers. We do not knowingly collect personal data from children, and where a matter necessarily concerns a minor we process only with appropriate legal authority and heightened safeguards.
17. Changes to this notice
We may update this notice to reflect legal, technical or operational developments. Material changes are notified on this page with a revised effective date and, where required, by direct communication. Superseded versions are archived and available on request.
18. How to contact us
Privacy enquiries and rights requests: [EMAIL ADDRESS], marked "Data protection request". Postal: Dronning Eufemias gate 8, Bjørvika, 0191 Oslo. Controller, DPO and representative details: [CONTROLLER / DPO / REPRESENTATIVE DETAILS].
Template drafting for review by qualified counsel in Norway, the United Kingdom, Australia and Canada before publication. Every bracketed value must be completed with verified information, and the processor list, retention schedule and transfer safeguards must reflect actual practice.