BlackDogs Security · Legal
Privacy Policy
BlackDogs Security is a cybersecurity company. Handling other people's data carefully is the service we sell, so this policy is written to be read rather than to be scrolled past. It explains what personal data we process, why, for how long, and what you can require of us.
- Legal name
- BlackDogs Security Andorra, S.L.
- NRT
L-716619-A- Registered office
- Carrer Bonaventura Riberaygua, núm. 36, 6è pis, 3a porta, AD500 Andorra la Vella, Principality of Andorra
- Contact
- [email protected]
- Last updated
- 11 September 2026
- Supervisory authority
- Agència Andorrana de Protecció de Dades (APDA)
- Cookies
- None. This site sets no cookies and runs no analytics.
1. Who is responsible for your data
The data controller is BlackDogs Security Andorra, S.L., NRT L-716619-A, with registered office at Carrer Bonaventura Riberaygua, núm. 36, 6è pis, 3a porta, AD500 Andorra la Vella, Principality of Andorra.
For any question about this policy or to exercise the rights described in section 10, write to [email protected].
The processing described here is governed by Llei 29/2021, del 28 d'octubre, qualificada de protecció de dades personals (LQPD) and its implementing rules, under the supervision of the Agència Andorrana de Protecció de Dades (APDA). Where we process personal data on behalf of a client established in the European Union, we act as a processor and the General Data Protection Regulation applies to that processing through the contract signed with that client.
2. What personal data we process
We do not collect personal data through this website. There is no form, no account, no login and no tracker on any page. The only personal data we hold about you is data you send us, or data that reaches us in the course of providing a service:
- Correspondence. If you write to [email protected], we process your name, your email address, any details you include about your organization, and the content of your message.
- Reports sent to BlackDogs CSIRT. If you write to [email protected], we process your contact details and whatever the report contains. Incident and vulnerability reports often include personal data of third parties — logs, IP addresses, email headers, user identifiers. Section 8 explains how we handle that.
- Client and supplier records. Contact details of the people who represent the organizations we work with, and the billing information required by law.
- Service delivery data. Where a contract puts us inside a client's systems — monitoring, backup, incident response — we may encounter personal data belonging to that client's users. In that case the client is the controller and we act only on their documented instructions.
- Technical request data. Our infrastructure and content delivery provider record connection data such as IP address, user agent and requested URL, as any web server does. This is aggregate operational and anti-abuse data; it is not used to build a profile of you, and it is not joined to any of the above.
We do not buy contact lists, we do not enrich your data from third-party sources, and we do not carry out automated decision-making or profiling with legal or similarly significant effects.
3. Why we process it, and on what legal basis
- To answer you and prepare a proposal — steps taken at your request prior to entering into a contract, and our legitimate interest in responding to enquiries addressed to us.
- To deliver contracted services — performance of the contract with your organization.
- To receive and handle security incident and vulnerability reports — our legitimate interest, and that of the wider community, in ensuring the security of networks and information systems. This is the core function of a CSIRT.
- To meet accounting, tax and other legal obligations — compliance with a legal obligation.
- To keep our own infrastructure secure and available — our legitimate interest in preventing abuse, fraud and attack.
Where we rely on legitimate interest, we have weighed it against your rights and freedoms and concluded that the processing is limited to what you would reasonably expect from a company you contacted or reported an issue to. You can object to that processing, as described in section 10.
We send no marketing email. If that ever changes, it will be on the basis of consent you have given, and every message will carry a working unsubscribe route.
4. How long we keep it
- Enquiries that do not lead to a contract — two years from the last contact, then deleted.
- Client records — for the duration of the relationship and thereafter for as long as liability arising from it can still be claimed.
- Accounting and tax records — for the period required by Andorran law.
- Incident and vulnerability reports — three years from the closure of the case, so that recurring activity can be recognised and coordination history can be reconstructed. Reports are minimised before archiving: material not needed to understand the case is removed.
- Technical request data — as retained by our infrastructure providers for operational and anti-abuse purposes, a short rolling window.
When a retention period ends, data is deleted or irreversibly anonymised.
5. Who your data is shared with
We do not sell personal data and we do not share it for anybody else's marketing.
Data is disclosed only to:
- Service providers acting on our instructions — email, hosting, content delivery and professional advisers — each bound by a written processing agreement and by confidentiality.
- Parties necessary to resolve a security incident — the affected organization, the vendor of a vulnerable product, or another CSIRT, always under the rules in section 8.
- Public authorities, where we are legally required to do so.
6. Transfers outside Andorra
Some of our providers are established in the European Union or in other jurisdictions. Transfers take place only to countries recognised as providing an adequate level of protection, or under contractual safeguards that provide protection equivalent to that guaranteed by Andorran law.
Andorra itself is recognised by the European Commission as a jurisdiction ensuring an adequate level of protection for personal data, so a transfer from the European Economic Area to BlackDogs Security requires no additional safeguard on that ground alone.
7. No cookies, no analytics, no tracking
This website sets no cookies whatsoever — not technical ones, not preference ones, not analytics ones. It loads no Google Analytics, no Google Tag Manager, no Meta, LinkedIn, X or TikTok pixel, no session-recording or heatmap tool, and no third-party font or script of any kind.
That is not a promise you have to take on trust. Every page ships a Content Security Policy of default-src 'none' with resources permitted from this origin only, delivered both as a meta element in the page and as an HTTP response header. An external tracker cannot execute here even if one were added by mistake; you can verify this in your browser's developer tools.
Because nothing is stored on your device and nothing is shared with a third party, there is no consent to collect and therefore no cookie banner. Visitor numbers are measured server-side by our content delivery provider, from request logs that already exist, without identifying you.
If this ever changes, this section will be updated before the change goes live, and any processing that requires your consent will ask for it first.
8. Reports sent to BlackDogs CSIRT
A report of an incident or a vulnerability is treated as confidential by default and handled on a need-to-know basis. Information is classified and shared according to the Traffic Light Protocol, and we honour the classification a reporter applies to their own report.
If resolving an issue requires us to contact a third party — the affected organization, a vendor, another CSIRT — we share the minimum necessary. We do not disclose the identity of the reporter, or of an affected customer, without that party's consent, unless a legal obligation compels it.
You may report anonymously; we can act on a report without knowing who sent it, though we will then be unable to ask you for clarification or to credit you. You may encrypt your report with our published PGP key. The full terms are set out in the Coordinated Vulnerability Disclosure Policy and the RFC 2350 team description of BlackDogs CSIRT, or that of BlackDogs CSIRT Andorra where the Andorran team is the one handling the report.
9. How we protect your data
Access to personal data is restricted to the people who need it to do their work, under confidentiality obligations that survive the end of their engagement. Data is encrypted in transit and at rest, access is logged, and we apply the same controls internally that we recommend to clients.
Sensitive correspondence can be encrypted end-to-end: our PGP key is published at csirt-blackdogs.asc and referenced from /.well-known/security.txt.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the APDA and, where the law requires it, you, without undue delay.
10. Your rights
You may at any time ask us to:
- Access the personal data we hold about you, and obtain a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase data we no longer have a lawful reason to keep.
- Restrict processing while a dispute about accuracy or legitimacy is resolved.
- Object to processing based on legitimate interest, on grounds relating to your particular situation.
- Receive the data you provided in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.
Write to [email protected]. We answer within one month; if a request is complex we may extend that period and will tell you why. Exercising these rights is free, and we will ask you for proof of identity only where we cannot otherwise be confident who is asking.
If you believe we have not handled your data correctly, you are entitled to complain to the Agència Andorrana de Protecció de Dades (APDA), the supervisory authority of the Principality of Andorra. We would rather you told us first, so we can put it right.
Where BlackDogs Security acts as a processor for a client, rights requests should be addressed to that client as controller; if you write to us, we will forward your request to them and tell you that we have done so.
11. Changes and language versions
This is the version dated 11 September 2026. The current version is always the one published at https://blackdogs.io/privacy. Material changes will be reflected in the date above, and the change will be made before the new processing starts, not after.
Spanish and Catalan translations are available at /privacy/es and /privacy/ca. In case of discrepancy between versions, the English version prevails.
The identification details of the company and the terms governing this website are set out in the Legal Notice.