Home / Privacy Policy
Privacy Policy
This policy explains how Blackbourne Worldwide handles information when you visit our website, contact us, engage us for security services, or enrol in a training course. It also describes how we handle data encountered during an engagement, which is governed additionally by the written agreement for that engagement.
Information we collect
- Contact and enquiry details. Name, organisation, role, email address and the content of your message.
- Client and engagement information. Scope documents, authorisations, findings, reports and correspondence.
- Technical information. IP address, browser and device type, and pages visited, collected to operate and secure the website.
- Training information. Enrolment details, assessment results and certification records.
Information encountered during an engagement
Security testing and incident response necessarily involve observing systems and, in some cases, data held on them. We handle that information under the following rules:
- Minimum necessary. We access only what the agreed scope requires to demonstrate the finding.
- No unnecessary copies. We do not retain client data beyond what the engagement requires and the agreement permits.
- Personal data minimisation. Where testing may expose personal data — as social engineering campaigns often do — collection, storage location, retention and deletion are agreed in writing beforehand.
- Confidentiality. Findings, artefacts and samples are confidential to the client and are not disclosed to third parties except as the law requires or the client instructs.
- Deletion. Engagement data is deleted or returned at the end of the agreed retention period.
Malware and artefacts
Samples recovered during testing or response are analysed in an isolated environment by our research team. Analysis may involve submitting a sample to a third-party analysis service; where that would disclose client-identifying information or the existence of an incident, the client is asked first.
How we use information
- To deliver the services and training you have engaged us for.
- To respond to enquiries and provide support, including emergency response.
- To meet legal, contractual and accounting obligations.
- To maintain and improve the security of our own systems.
Sharing
We share information only with personnel working on the engagement, with service providers who support our operations under written agreements, and with authorities where the law requires it. We do not sell personal information.
Retention
Engagement records are retained for the period agreed in the engagement contract, or as required for legal and insurance purposes. Website enquiry data is retained only as long as needed to handle the enquiry and any resulting relationship. Training records are retained to support certification verification.
Security
We are a security company and hold ourselves to the practices we test in others: access control, encryption, least privilege, logging and independent review of our own environment.
Your rights
Subject to your jurisdiction, you may request access to, correction of, or deletion of your personal information, and object to certain processing. Write to privacy@blackbourneco.com. Where your information was encountered during an engagement as part of a client's data, direct the request to that client — we act on their instructions.
Cookies
Our website uses only the cookies necessary to operate it. We do not use advertising cookies or third-party advertising trackers.
Changes and contact
We will post any change to this policy on this page with a new effective date. Questions: privacy@blackbourneco.com, or through the contact page.