privacyVersion 1SOC2GDPRCCPAISO27001
Privacy Policy (Internal)
How Rex Black personnel handle personal data on behalf of employees, prospects, and clients.
Privacy Policy (Internal)
This document governs how Rex Black personnel handle personal data on
behalf of employees, prospects, and clients. The public-facing
privacy notice lives at https://rexblack.com/privacy and is derived
from this policy.
1. Principles
We apply GDPR Article 5 as our operating baseline for all personal data, regardless of the data subject's jurisdiction:
- Lawfulness, fairness, transparency.
- Purpose limitation: collect for a specific, explicit purpose.
- Data minimization: collect only what we need.
- Accuracy: keep it correct and up to date.
- Storage limitation: retain only as long as needed
(
010-data-retention-and-disposal-policy.md). - Integrity and confidentiality: encrypt, access-control, log.
- Accountability: demonstrate compliance; keep records.
2. Roles
Under GDPR:
- Rex Black is a controller for HR and prospect data.
- Rex Black is a processor for client-provided personal data.
- Clients are the controllers of that data.
3. Legal bases
Rex Black relies on the following lawful bases (GDPR Art. 6):
| Processing | Lawful basis |
|---|---|
| Serving clients under contract | Art. 6(1)(b) contract |
| Sending invoices, enforcing agreements | Art. 6(1)(b) + (c) |
| Prospect outreach | Art. 6(1)(f) legitimate interests (after balancing test) |
| Marketing email to subscribed contacts | Art. 6(1)(a) consent |
| Security monitoring, audit logs | Art. 6(1)(c) + (f) |
| Employment and HR | Art. 6(1)(b) + (c) + (f) |
4. Data subject rights
We honor rights enumerated in GDPR and, where applicable, CCPA:
access, correction, deletion, portability, restriction, objection,
and the right to not be subject to solely automated decisions with
significant effect. Process is in
028-data-subject-rights-policy.md.
5. International transfers
- Rex Black processes data in AWS
us-east-1by default. - Transfers of EU/UK personal data to the United States rely on Standard Contractual Clauses (2021/914) and UK IDTA as applicable, supplemented by encryption at rest (SSE-KMS), encryption in transit (TLS 1.2+), and access restrictions.
- We do not transfer personal data to jurisdictions without an adequacy decision or equivalent safeguard.
6. Third parties
Subprocessors are listed at registers/subprocessors.md and on the
public trust page. DPAs with SCCs where applicable are in place.
7. DPIA
A Data Protection Impact Assessment is performed when:
- Introducing systematic monitoring.
- Processing special-category data (health, biometrics, etc.).
- Large-scale profiling or automated decision-making.
- Any new processing flagged "high risk" by the Privacy Officer.
DPIAs are stored at compliance/dpias/YYYY-slug.md.
8. Breach response
Personal data breaches follow the Incident Response Plan and the notification thresholds in §4 of that plan, including the GDPR 72- hour notification obligation.
9. Children
Rex Black's products are B2B and are not directed at children under 16. We do not knowingly process data of children under 16. Reports to that effect trigger immediate deletion.
10. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Privacy Officer | Policy maintenance; DPIAs; rights-request triage. |
| Security Officer | Technical safeguards; breach response. |
| CEO | Final approver of policy changes and breach disclosure. |
11. References
009-data-classification-and-handling-policy.md010-data-retention-and-disposal-policy.md028-data-subject-rights-policy.md017-vendor-subprocessor-management-policy.md
12. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | P.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.