Skip to main content

privacyVersion 1SOC2GDPRCCPAISO27001

Privacy Policy (Internal)

How Rex Black personnel handle personal data on behalf of employees, prospects, and clients.

Download PDFSHA-256 5bbb3479f505072c…

Privacy Policy (Internal)

This document governs how Rex Black personnel handle personal data on behalf of employees, prospects, and clients. The public-facing privacy notice lives at https://rexblack.com/privacy and is derived from this policy.

1. Principles

We apply GDPR Article 5 as our operating baseline for all personal data, regardless of the data subject's jurisdiction:

  1. Lawfulness, fairness, transparency.
  2. Purpose limitation: collect for a specific, explicit purpose.
  3. Data minimization: collect only what we need.
  4. Accuracy: keep it correct and up to date.
  5. Storage limitation: retain only as long as needed (010-data-retention-and-disposal-policy.md).
  6. Integrity and confidentiality: encrypt, access-control, log.
  7. Accountability: demonstrate compliance; keep records.

2. Roles

Under GDPR:

  • Rex Black is a controller for HR and prospect data.
  • Rex Black is a processor for client-provided personal data.
  • Clients are the controllers of that data.

3. Legal bases

Rex Black relies on the following lawful bases (GDPR Art. 6):

Processing Lawful basis
Serving clients under contract Art. 6(1)(b) contract
Sending invoices, enforcing agreements Art. 6(1)(b) + (c)
Prospect outreach Art. 6(1)(f) legitimate interests (after balancing test)
Marketing email to subscribed contacts Art. 6(1)(a) consent
Security monitoring, audit logs Art. 6(1)(c) + (f)
Employment and HR Art. 6(1)(b) + (c) + (f)

4. Data subject rights

We honor rights enumerated in GDPR and, where applicable, CCPA: access, correction, deletion, portability, restriction, objection, and the right to not be subject to solely automated decisions with significant effect. Process is in 028-data-subject-rights-policy.md.

5. International transfers

  1. Rex Black processes data in AWS us-east-1 by default.
  2. Transfers of EU/UK personal data to the United States rely on Standard Contractual Clauses (2021/914) and UK IDTA as applicable, supplemented by encryption at rest (SSE-KMS), encryption in transit (TLS 1.2+), and access restrictions.
  3. We do not transfer personal data to jurisdictions without an adequacy decision or equivalent safeguard.

6. Third parties

Subprocessors are listed at registers/subprocessors.md and on the public trust page. DPAs with SCCs where applicable are in place.

7. DPIA

A Data Protection Impact Assessment is performed when:

  • Introducing systematic monitoring.
  • Processing special-category data (health, biometrics, etc.).
  • Large-scale profiling or automated decision-making.
  • Any new processing flagged "high risk" by the Privacy Officer.

DPIAs are stored at compliance/dpias/YYYY-slug.md.

8. Breach response

Personal data breaches follow the Incident Response Plan and the notification thresholds in §4 of that plan, including the GDPR 72- hour notification obligation.

9. Children

Rex Black's products are B2B and are not directed at children under 16. We do not knowingly process data of children under 16. Reports to that effect trigger immediate deletion.

10. Roles & responsibilities

Role Responsibility
Privacy Officer Policy maintenance; DPIAs; rights-request triage.
Security Officer Technical safeguards; breach response.
CEO Final approver of policy changes and breach disclosure.

11. References

  • 009-data-classification-and-handling-policy.md
  • 010-data-retention-and-disposal-policy.md
  • 028-data-subject-rights-policy.md
  • 017-vendor-subprocessor-management-policy.md

12. Revision history

Version Date Author Approver Change
1.0 2026-04-17 P.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center