Christopher Justice
privacy@bl.ink
6302 Royal Birkdale Overlook Austin, TX 78746
As part of our ongoing efforts to protect the security and privacy of our users, we are working to meet or exceed the GDPR (General Data Protection Regulation). This site contains information on what steps we are taking, their progress, and who to contact for any security concerns. Please see our FAQ for more information.
If you need a signed DPA, please use the button below to cross sign and download your copy of our DPA.
We respect the rights of individuals to know how their data is being used, export it or request that it be deleted.
We rely on a number of trusted 3rd parties to assist with our operations. Depending on the exact nature of your account and what you've requested we do, your data may be shared with one of these partners. We carefully evaluate each to make sure they're handling your personal data with the utmost of respect, security, and privacy.
Services | ||||
---|---|---|---|---|
Partner | Locale | Data Shared | Purpose | |
Amazon | ![]() |
All stored data | This site is hosted on Amazon AWS EC2 Infrastructure. |
|
Auth0 | ![]() |
IP Address First Name Last Name Email Authentication Token | Authentication and login system. |
|
Chargebee | ![]() |
First name Last Name Email Phone Number Address Billing Authorization Subscription ID | Finance and Billing Management |
|
Freshchat | ![]() |
IP Address First Name Last Name Email Account Plan Page Views | Live chat software from FreshWorks. |
|
Freshdesk | ![]() |
First name Last Name Email | An online help desk software that allows you to support customers over email |
|
Gaug.es | ![]() |
IP Address | Gauges collects and analyzes your web traffic in real-time. |
|
Global Site Tag | ![]() |
IP Address | Google's primary tag for Google Measurement/Conversion Tracking, Adwords and DoubleClick. |
|
Google Analytics | ![]() |
IP Address | Google Analytics offers a host of compelling features and benefits for everyone from senior executives and advertising and marketing professionals to site owners and content developers. |
|
Google Apps for Business | ![]() |
IP Address | Web-based email, calendar, and documents for teams. Renamed to Google Apps for Work, but now known as G Suite from Google Cloud. |
|
Google Font API | ![]() |
IP Address | The Google Font API helps you add web fonts to any web page. |
|
Google Tag Manager | ![]() |
IP Address | Tag management that lets you add and update website tags without changes to underlying website code. |
|
Gravatar Profiles | ![]() |
IP Address | Creates Gravatar Profiles on the site. |
|
Hubspot | ![]() |
First name Last Name Email Phone Number Address Billing Authorization Subscription ID Page Views Emails Plan Details | Hubspot provides marketing information and leads via inbounding marketing software. |
|
ProfitWell | ![]() |
First name Last Name Email Phone Number Address Subscription ID Subscription Date Plan Details | Subscription and financial metrics in one place. |
|
Sendinblue | ![]() |
First name Last Name Email Plan Type Registration Date | Email communications |
GDPR Compliance requires maintenance and ongoing work. We are tracking our efforts here.
Application Site Security | |
---|---|
Status | Name |
Completed | Restrict Personal Data at Signup to the Minimum Necessary |
Completed | Ensure Backups are Stored in on Encrypted File Storage |
Completed | Personal Data in File Storage is Encrypted |
Completed | Personal Data in Databases is Encrypted |
Completed | Ensure Access to Backups is Restricted |
Completed | Redact Logs from Writing Unneeded Personal or Sensitive Data |
Completed | Ensure Intrusion Detection Systems are in Place |
Completed | Ensure Web Application Firewall enabled and blocking common attacks |
Completed | Ensure Database Backups of Personal Data are working |
Completed | SSL (TLS) Deployed on App Site |
Completed | HSTS (HTTP Strict Transport Security) added to SSL/TLS of App Site |
Completed | Establish Development Environment Data Handling Guidelines |
Completed | Inform Users about the GDPR Page |
Data Mapping | |
---|---|
Status | Name |
Completed | Add Database Provider to Data Partner |
Completed | Add Hosting Provider to Data Partners |
Completed | Add Customer Support (Helpdesk) Service to Partners |
Completed | Add Web Analytics Service to Data Partners |
Completed | Add Internal Email Service to Data Partners |
Completed | Add File Collaboration Service to Data Partners |
Completed | Add Transactional Email Service to Partners |
Completed | Add Email Newsletter Service to Partners |
Completed | Add Exception/Error Reporting Services to Data Partners |
Completed | Add Performance Monitoring Applications to Data Providers |
Completed | Add Third Party Web Font Services to Data Partners |
Completed | Add CDN Provider to Data Partners |
Completed | Add Social Embeds to Data Partners |
Marketing Site Security | |
---|---|
Status | Name |
Completed | Reviewed list of users with access to site |
Completed | HSTS (HTTP Strict Transport Security) added to SSL/TLS of Marketing Site |
Completed | SSL (TLS) Deployed on Marketing Site |
Privacy Procedures | |
---|---|
Status | Name |
Completed | Process established for subject data requests |
Completed | Get Management Approval for GDPR Efforts |
Completed | Developed a Data Processing Agreement |
Completed | Data Protection Policy Created |
Completed | Nominate a Data Protection Lead or Data Protection |
Completed | Procedure established to allow for people to request that inaccuracies in their data are fixed. |
Completed | Privacy Policy Updates |
Completed | Informed all Employees and Contractors about GDPR Compliance |
Completed | Briefed all Staff on GDPR Impact to the organization |
Security Procedures | |
---|---|
Status | Name |
Completed | Publish statement on public website on how to report security and data issues. |
Completed | Data Breach Notification Policy has been established |
If you have any concerns not answered here, please reach out to our contact (listed above) and we'll be happy to assist.
While it remains to be seen if the EU has the legislative power to levy fines and enforcement against organizations around the globe, GDPR compliance is being sought by non EU companies for a variety of reasons.
We take all security reports seriously. Please email our security contact (information listed above) with any information you have regarding any potential data breaches, vulnerabilities or concerns.
The General Data Protection Regulation (GDPR) is a new piece of privacy legislation enacted by the European Union. It represents a significant change in how personal (IP Addresses, Emails, Names) and sensitive (religion, ethnic origin, health, orientation) data is handled by companies.