Privacy Policy
Last updated: 2026-02-27
This Privacy Policy explains how Black Belt Digital Ltd (we, us, our, BBD) collects, uses, stores, shares, and protects personal data when you use our websites, platform, website builder, templates, hosting services, video library, support channels, and related services (together, the Service). It applies globally and is written to meet the requirements of UK GDPR, EU GDPR, and other applicable data protection laws, subject to local mandatory rights. By using the Service, you acknowledge and understand this Privacy Policy.
1. Who is responsible for your data
Black Belt Digital Ltd is the data controller for personal data we collect directly from you when you create an account, use the Service, contact us, or interact with our marketing. If you use the Service to collect personal data from your own customers, patients, leads, or site visitors, you are the data controller for that data and we act as a service provider or processor where applicable. This distinction is critical. We do not take responsibility for your compliance failures, your privacy notices, or your consent mechanisms.
2. Personal data we collect
We collect different categories of personal data depending on how you interact with us. This includes account data such as your name, business name, email address, phone number, billing address, and login credentials. It includes billing and payment data such as payment method details and transaction history, which are typically processed by our payment providers rather than stored directly by us. It includes usage data such as IP address, device type, browser type, pages accessed, timestamps, feature usage, and diagnostic logs. It includes support and communications data when you contact us by email, chat, forms, or calls. If you upload personal data into the Service as part of your Content, including patient images, contact forms, or lead data, that data is controlled by you, not us.
3. Special category data and health-related data
The Service may be used by aesthetics and dental practices. If you upload health-related data, patient images, or other special category data, you confirm you have a lawful basis to do so, including explicit consent where required. We do not request this data from you, we do not verify consent, and we do not determine how it is used. You carry full responsibility for compliance, record keeping, and responding to data subject requests.
4. How we use personal data
We use personal data to provide and operate the Service, create and manage accounts, process payments, deliver support, communicate about the Service, improve features, maintain security, prevent fraud, comply with legal obligations, and enforce our Terms. Where permitted, we may also use contact data to send product updates, service notices, and relevant marketing communications. You can opt out of marketing communications at any time, but you will still receive essential service messages.
5. Legal bases for processing
Depending on the context, we process personal data based on one or more of the following legal bases: performance of a contract where processing is necessary to provide the Service, legitimate interests where processing is necessary to operate, secure, and improve the platform and does not override your rights, consent where required for specific activities such as marketing, and legal obligation where processing is required by law.
6. Data sharing and disclosure
We share personal data only where necessary. This includes sharing with trusted service providers such as hosting providers, cloud infrastructure providers, payment processors, analytics providers, customer support tools, and security services, all of whom are bound by contractual obligations to protect data. We may disclose data to regulators, law enforcement, courts, or other authorities if required by law or where reasonably necessary to protect rights, safety, or prevent harm. We may also share data as part of a merger, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
7. International data transfers
The Service is global. Personal data may be transferred to and processed in countries outside your own, including countries that may not offer the same level of data protection. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms to protect personal data.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this Policy, including providing the Service, meeting legal and accounting obligations, resolving disputes, and enforcing agreements. When accounts are closed, data may be deleted or anonymised, subject to backup retention and legal requirements. Backups are rotated periodically and are not intended for long term storage.
9. Security
We use reasonable technical and organisational measures to protect personal data, including access controls, encryption where appropriate, monitoring, and secure infrastructure. No system is completely secure. You acknowledge that online services carry inherent risk, and we cannot guarantee absolute security.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to request data portability. You may also have the right to withdraw consent where processing is based on consent. Requests should be sent to [email protected] We may need to verify your identity before responding. If you are an end user of a site built on BBD, you must contact the site owner directly, as they control your data.
11. Children
The Service is not intended for children and we do not knowingly collect personal data from children.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published on our website. Continued use of the Service after publication means you accept the updated Policy.
13. Contact
If you have questions about this Privacy Policy or how we handle data, contact us at [email protected] or at our registered office address.