Blackstone Interactive
  • Home
  • About Us
  • Services
  • Contact Us
  • Blog
Get Started

Legal

Privacy policy

Last updated: 8 September 2026

This policy explains how Blackstone Interactive Ltd handles personal data when you visit this website, enquire about our services, or work with us as a client. It also explains the separate situation where we handle personal data inside your own advertising and analytics accounts on your instructions. We follow the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR).

Contents

  1. Who we are
  2. Data we collect
  3. Client accounts: our processor role
  4. Purposes and legal bases
  5. Marketing and PECR
  6. Sharing with third parties
  7. International transfers
  8. How long we keep data
  9. Security
  10. Cookies
  11. Your rights
  12. Withdrawing consent
  13. Complaints to the ICO
  14. Age limit
  15. Changes to this policy
  16. Contact us

1. Who we are

Blackstone Interactive Ltd is a full-cycle marketing agency working with small and medium businesses across the United Kingdom. For the personal data described in section 2 of this policy, Blackstone Interactive Ltd is the data controller.

  • Company: BLACKSTONE INTERACTIVE LTD, registered in England and Wales
  • Company number: 17371969
  • Registered office: Dept 6974, 196 High Road, Wood Green, London, United Kingdom, N22 8HH
  • Email for privacy matters and general enquiries: ceo@blackstoneinteractive.uk
  • Telephone: +44 7911 242261

We are not required to appoint a Data Protection Officer. Privacy questions are handled by our director, who can be reached at the email address above.

2. Data we collect

When you enquire

This website has no server-side contact form. Every contact button opens your own email application, so the information you send us is the information you choose to put in that email. In practice an enquiry usually contains your name, email address, telephone number, company name, website address and a description of what you want to achieve.

When you become a client

To run a project we collect and hold contact details for the people we deal with at your company, billing details and company registration information, the brief and any materials you send us, correspondence, meeting notes, proposals, contracts and invoices.

When you visit this website

Our hosting provider records standard server log data, including IP address, browser type, referring page, requested pages and the time of the request. This happens for every website and is needed to serve pages and to keep the site secure.

When you subscribe to our emails

If you opt in to marketing emails we hold your email address, your name if you give it, and records of consent, sends, opens and unsubscribes.

Data we do not collect

We do not ask for and do not want special category data — health, ethnicity, religious or philosophical beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation — or criminal offence data. Please do not send this kind of information to us. We also do not take card details on this website.

3. Client accounts: our processor role

This section is separate from everything else in this policy and matters most to our clients.

When we manage advertising, analytics or CRM accounts for a client, we are usually given access to accounts owned by that client — for example Google Ads, Google Analytics, Meta Business Manager, an email platform or a website back end. Those accounts can contain personal data about the client's own customers and enquirers: contact details in lead forms, customer lists uploaded for audience matching, online identifiers, and conversion or enquiry records.

In that situation the client is the data controller and Blackstone Interactive Ltd acts as a processor. We only act on the client's documented instructions, and the arrangement is governed by a written data processing agreement that meets Article 28 of the UK GDPR. That agreement is signed before we are given access to any account, and it covers:

  • the subject matter, duration, nature and purpose of the processing, and the categories of data subject
  • our duty to act only on the client's documented instructions
  • confidentiality obligations for everyone we allow to access the data
  • the security measures we apply
  • the rules for engaging any sub-processor, and prior written authorisation for each one
  • our help with data subject requests, breach notification, and data protection impact assessments
  • deletion or return of the data at the end of the engagement, and our duty to make available the information needed to demonstrate compliance

If you are a member of the public and you believe a company has your data in an advertising account that we manage, the controller is that company, not us. Contact them first; if you contact us, we will pass your request on to them without delay and support them in answering it.

We never take a client's customer list and use it for our own marketing, and we never move data between client accounts.

4. Purposes and legal bases

We only use personal data where the law gives us a basis to do so. The table below sets out what we do and why.

What we doLegal basis
Reply to your enquiry, prepare a proposal and quote a priceSteps taken at your request before entering a contract (Article 6(1)(b))
Deliver the services, manage the project and communicate with youPerformance of a contract (Article 6(1)(b))
Send marketing emails to individual subscribersConsent (Article 6(1)(a)) with PECR
Send service updates to existing clients about similar servicesLegitimate interests (Article 6(1)(f)) and the PECR soft opt-in, with an unsubscribe link in every message
Keep the website secure, prevent abuse and diagnose faultsLegitimate interests (Article 6(1)(f)) in running a safe, working website
Keep records of work, quotes and correspondence to handle disputesLegitimate interests (Article 6(1)(f)) in defending legal claims
Issue invoices, keep accounts and file tax returnsLegal obligation (Article 6(1)(c))

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and we have concluded that it is not, because the processing is limited to what is needed and is what you would reasonably expect. You can object to it at any time — see section 11.

5. Marketing and PECR

We send marketing emails to individuals only with clear, specific opt-in consent. We do not buy or rent marketing lists, we do not use pre-ticked boxes, and consent to marketing is never a condition of getting a quote or being a client.

Existing clients may receive occasional emails about services similar to the ones they have already bought, under the PECR soft opt-in. Every marketing email we send includes a working unsubscribe link, and we act on unsubscribes promptly. We do not make automated marketing calls and we do not use automated decision-making or profiling that produces legal or similarly significant effects for anyone.

6. Sharing with third parties

We do not sell personal data. We share it only where it is needed to run the business or deliver the work, and only with the following categories of recipient:

  • Advertising and analytics platforms — such as Google and Meta, where campaigns are run or measured. Where the account belongs to the client, this happens under section 3.
  • Hosting, email and file storage providers — for the website, our mailboxes and our project files.
  • Email marketing platforms — to send newsletters to subscribers who have opted in.
  • Print partners — printers and finishing houses that produce leaflets, brochures, cards and signage. They receive delivery contact details and artwork, nothing more.
  • Accountants, auditors and payment providers — for invoicing, bookkeeping and statutory accounts.
  • Professional advisers — lawyers and insurers, where we need advice or have to defend a claim.
  • Public authorities — where we are legally required to disclose information.

Every supplier acting as our processor is bound by a written contract that restricts them to our instructions and requires appropriate security.

7. International transfers

We prefer suppliers who store data in the United Kingdom or the European Economic Area. Some of the platforms we use are based in the United States or process data there.

Where personal data leaves the UK, we rely on one of the safeguards allowed by UK data protection law: an adequacy decision made by the UK government, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where one is required. You can ask us which safeguard applies to a particular supplier by emailing ceo@blackstoneinteractive.uk.

8. How long we keep data

  • Enquiries that do not become projects — up to 24 months from the last contact, then deleted.
  • Client project records, briefs and correspondence — for the duration of the engagement and 6 years afterwards, to cover the limitation period for contract claims.
  • Invoices and accounting records — 6 years from the end of the relevant accounting period, as required by tax law.
  • Marketing subscribers — until you unsubscribe, plus a suppression record so we do not email you again by mistake.
  • Website server logs — normally up to 12 months.
  • Data inside a client's own accounts — governed by the client's own retention rules; on the client's instruction we delete or return what we hold and remove our access when the engagement ends.

9. Security

The site is served over HTTPS. Access to mailboxes, project files and client advertising accounts is protected by strong unique passwords in a password manager and by multi-factor authentication wherever the platform supports it. Access is granted on a need-to-know basis and removed when an engagement ends or a person's role changes. We do not store client credentials in plain text and we ask for delegated access rather than shared passwords.

No system is completely secure. If a personal data breach is likely to result in a risk to people's rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours of becoming aware, and tell the people affected without undue delay where the risk is high. Where we act as processor, we notify the client controller without undue delay.

10. Cookies

This website does not set analytics, advertising or tracking cookies, and it does not use local storage in your browser. Because we set no non-essential cookies, there is no cookie banner to accept or reject.

The site loads fonts from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address in order to serve the font files. If you would rather avoid this, most browsers and privacy extensions can block third-party font requests.

If we add analytics in future, we will ask for your consent before any non-essential cookie is set and update this section first.

11. Your rights

Under the UK GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate data corrected and incomplete data completed.
  • Erasure — ask us to delete data where there is no good reason for us to keep it.
  • Restriction — ask us to pause our use of your data while a dispute about it is resolved.
  • Portability — receive data you gave us, in a structured, commonly used, machine-readable format, where processing is based on consent or a contract and carried out by automated means.
  • Object — object to processing based on legitimate interests, and object to direct marketing at any time, which we will always honour.
  • Withdraw consent — where our processing relies on consent.

To exercise any of these rights, email ceo@blackstoneinteractive.uk. We respond within one month, and will tell you if we need to extend that period by up to two further months because the request is complex. There is no charge unless a request is manifestly unfounded or excessive. We may ask for information to confirm your identity before we act.

12. Withdrawing consent

Where we rely on consent, you can withdraw it at any time — by clicking unsubscribe in any marketing email, or by emailing ceo@blackstoneinteractive.uk. Withdrawing consent does not affect the lawfulness of anything we did before you withdrew it, and it will not affect processing that rests on a different legal basis, such as the records we must keep for tax purposes.

13. Complaints to the ICO

If you are unhappy with how we have handled your personal data, please tell us first at ceo@blackstoneinteractive.uk so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office, the UK supervisory authority for data protection:

  • Website: ico.org.uk
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

14. Age limit

Our services are sold to businesses and this website is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, email ceo@blackstoneinteractive.uk and we will delete it.

15. Changes to this policy

We update this policy when our services, our suppliers or the law change. The date at the top shows when it was last revised. If a change materially affects how we use your personal data, we will tell affected clients and subscribers directly rather than relying on this page alone.

16. Contact us

Blackstone Interactive Ltd, Dept 6974, 196 High Road, Wood Green, London, United Kingdom, N22 8HH. Email ceo@blackstoneinteractive.uk or call +44 7911 242261.

Blackstone Interactive

Good marketing should be easy to check.

Blackstone Interactive Ltd, a full-cycle marketing agency working with small and medium businesses across the United Kingdom.

Get in touch

Company

  • Home
  • About us
  • Blog & news
  • Privacy policy

Services

  • Paid advertising
  • SEO & local search
  • Content & copy
  • Design & print

Contact us

  • ceo@blackstoneinteractive.uk
  • +44 7911 242261
  • Dept 6974, 196 High Road,
    Wood Green, London N22 8HH

Copyright © 2026 Blackstone Interactive Ltd · Registered in England and Wales, company number 17371969

Privacy policy