Privacy Policy
Version 1.1. In force from 16 September 2026.
At a glance
- We never sell your data. There are no advertisers, no trackers and no analytics. The one outside company involved is our identity provider, which handles sign-in for us under a contract.
- There are no passwords, so there is none of yours to lose. You sign in with a passkey or a one-time code sent to your email address. The credential itself is held by our identity provider and never reaches us.
- A member searching cannot see who you are. A search shows a role, a sector and how far away you are, never a name, until both sides have said yes to an introduction. Members you are already connected to see your name and your firm.
A summary, not the policy. Everything below is the document itself, and it is what binds us.
Who we are
Blackbook London is operated by Wadi Hussain. Upon incorporation of a private limited company in England and Wales, this policy will name it, with its registered office. We are the data controller. For anything in this policy, contact privacy@blackbook.london. Registration with the Information Commissioner's Office is pending.
What Blackbook does, in one paragraph
Blackbook is a private, referral-only network. Members say what they can open for someone else and what they need. When there is a match, we ask both people privately whether they want to be introduced, and only if both say yes do we put them in touch. Nobody's identity is revealed to anyone without their agreement.
If you are a member
What we hold
| What | Where it comes from |
|---|---|
| Name, email, city, and if you give it, your LinkedIn address | You |
| Firm, role, sector, seniority | You, confirmed with you on a call |
| What you can open, and what you need | You |
| How strongly you vouch for other members, on a 1–7 scale | You |
| Your close circle: invitations you send, and the ones you accept | You |
| Your answers to our joining questions, and who referred you | You and the person who referred you |
| Our own assessment of your application | Us, after the call |
| A record of introductions requested, agreed or declined | Automatic |
| A record of your sign-in sessions. There is no password: you sign in with a passkey or a one-time code sent to your email address, and the credential itself is held by our identity provider, never by us | You, through the identity provider |
| A report that you broke the membership rules, and what it said | Another member |
| Your membership fee payments: the amount, the date and the invoice. We never hold your card or bank details | You |
| If you asked to be considered before you were invited: the six things you gave us on the form (name, professional email, firm, role, sector, LinkedIn address), until the form's own ninety days are up | You |
We do not hold special category data (health, beliefs, politics, and so on), criminal records, payment card details, or the content of conversations between members. There is no member-to-member messaging.
Why we hold it, and our legal basis
| Purpose | Basis |
|---|---|
| Running your membership | Contract: we cannot provide the service without it |
| Taking payment of your membership fee | Contract |
| Deciding whether to admit you | Legitimate interests: keeping the network trustworthy is the whole point of it, and applicants expect to be assessed |
| Matching what you need to what others can offer | Contract |
| Confirming you are who you say you are | Legitimate interests: every member relies on it being true of everyone else |
| Security, audit logs, fraud prevention | Legitimate interests |
| Keeping the referral chain intact after a member leaves | Legitimate interests: fraud prevention, and the integrity of a closed, referral-only network. What is kept does not name you |
| Keeping our assessment of you while you are a member | Legitimate interests: a vetted network has to stay vetted, and the assessment is what we read when a question about a member arises |
| Acting on a report that a member broke the rules | Legitimate interests: the rules protect every other member, and they are unenforceable if nobody can tell us |
| Considering whether to invite someone who asked to be considered | Legitimate interests: inviting is the step before any membership, and a person who asks expects us to consider it |
Where we rely on legitimate interests, we have weighed our interest against your rights. You can ask us for that assessment and we will send it to you.
If someone reports you
Members can tell us that another member sold to them, pushed after a no, misrepresented themselves, or repeated something from here outside. We keep the report for 24 months.
You are not told, and we do not act on a single report. Both are deliberate, and both cut against you if you are the one reported, so they are worth saying plainly. We never see the conversation a report describes, so one report is one member's account and we have no way to test it. Telling you would identify the person who filed it, which would stop anyone filing.
What that means in practice: nothing happens on one report. If a second member raises the same thing separately, a founder looks at both and speaks to you before any decision, and you are told what has been said about you at that point. Nothing about your membership changes without that conversation.
Your access rights still apply, with one limit. Ask us and we will tell you what has been alleged. We will not identify who said it, because their identity is their personal data and releasing it would harm them.
Decisions about you
A person always makes the decision. Admission and rejection are decided by a founder after a conversation. We score applications to structure our thinking, but nothing is decided solely by a machine. If we turn you down you can ask us why, and a different person will look at it again.
Who sees what
- Other members see your name, firm, role, sector, what you can open and what you need.
- Other members never see how strongly you vouch for anyone. That is yours alone, and we do not show it to the person you rated.
- Search results are anonymised. Another member searching sees a role, a sector and how far away you are, never your name, until you have agreed to an introduction.
- Blocks are silent. If you block someone, they are never told.
- Our staff, meaning the founder and the brokers who run introductions, see your application, our assessment of it, and who referred you.
- Nobody outside the company sees any of it. We do not sell data, we do not share it with advertisers, and we have no advertisers.
How long we keep it
| What | How long |
|---|---|
| Your record: your name, contact details, firm, role, city, your joining answers, and what you asked for and offered | While you are a member. When you leave, or are removed, it is erased within 12 months, or sooner if you ask. While you are a member you can erase it yourself from your account |
| Our assessment of your application | While you are a member, then erased at the same time as the rest of your record |
| How strongly you vouch for another member | While you are both members, then erased with whichever record goes first |
| Your place in the referral chain: a record that does not name you, holding an internal identifier, the dates you joined and were approved, whether you left or were removed, who invited you and whom you invited | Indefinitely |
| Invitation codes you send | 24 hours to use, then a record that the code was used for 90 days |
| Records of an introduction | 30 days after it ends, whether it went ahead, was declined or was withdrawn |
| An unsuccessful application | 90 days |
| A request to be considered, from someone we have not yet invited | 90 days from the day it was sent, or sooner if they ask. Sending it again restarts the 90 days. The form is deleted at 90 days whether or not we invited them; an invitation and the application that follows are separate records, and the rows above apply to those |
| Security and audit logs | 12 months |
| A conduct report | 24 months from when it was filed |
| Backups | Rolling, overwritten within 90 days |
We delete introduction records quickly on purpose. In this industry the fact that two people spoke can matter as much as what they said.
We keep the referral chain on purpose too, and for the opposite reason. Every member's standing rests on who vouched for whom. If we cut that link when a member left, we would either lose sight of everyone they had introduced, or of who admitted them, and both are how a bad actor's route in gets lost. What remains is an identifier, dates and links, readable only by our staff. On its own it does not name you.
If you are not a member
Unless you have asked us to consider you, we hold nothing about you. Not a name, not a firm, not a note.
This is worth stating plainly, because a network like this one could easily work the other way. Our members know a great many people who are not members, and it would be useful to us to keep a record of them. We decided not to.
Why it matters to you. If a member of Blackbook knows you, that stays on their own phone, in their own contacts, exactly as it already does. It does not reach us. Unless you sent us the form described below, you are not in a database here, you are not rated, and there is no entry with your name on it for anyone to leak, subpoena or sell.
Unless you ask us yourself, the only way your name reaches us is if a member asks to be introduced to you and you say yes first. We ask you before anything is shared, you can decline without giving a reason, and the person who asked is not told why. If you decline, we keep nothing.
What we will never do: contact you out of the blue on someone else's behalf, or hold a record about you that you did not agree to.
If you think we hold something about you anyway, ask. Email privacy@blackbook.london and we will tell you, and delete it if we do.
If you ask to be considered
There is a form on our site for people who would like to be considered for membership without having been referred. This section applies only if you chose to send it.
What we take. Six things: your name, your professional email address, your current firm, your role or title, your sector, and the address of your LinkedIn profile. That is all. There is no box for anything else, so you cannot tell us more even if you wanted to, and we do not go looking.
Why. To consider whether to invite you. Our legal basis is legitimate interests: inviting someone is the step before any membership, and a person who asks to be considered expects us to consider it. We have weighed our interest against your rights, and you can ask us for that assessment.
Who sees it. Our staff, in the same tool we use to review applications. Nobody else. Members do not see it and it does not leave the company.
How long we keep it. Ninety days from the day you sent it, then it is deleted, or at once if you ask. If you send the form again, the ninety days start again from the new submission.
If we invite you, the invitation and the application that follows are separate records, handled under the membership sections above. The form itself is still deleted at ninety days, whether or not we invited you. If we do not, the form was all we ever held, and after ninety days we keep nothing.
What it does not do. Sending the form does not guarantee admission. A person reads every submission and decides against our criteria for membership. Nothing is decided by a machine.
Your rights under Your rights below apply to it in full, including the right to have it deleted before the ninety days are up.
Your rights
Whether or not you are a member, you can ask us to:
- Show you everything we hold about you, including our own assessment of you if there is one. The download in the app gives you what you gave us; ask us by email for the full answer, which a person prepares.
- Correct anything wrong.
- Delete it. We erase your name, contact details, firm, role, what you asked for and offered, and our assessment of you. What remains afterwards: the record of your place in the referral chain described under How long we keep it; any conduct report about you, until its 24 months are up; the log of staff who looked at your record, for its 12 months; and records of introductions and invitations until their own short periods end. None of these names you to another member.
- Restrict what we do with it, or object to it.
- Send you a copy in a portable format.
We will respond within one month. There is no charge.
If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would rather you came to us first, but it is your right either way.
Security
- There are no passwords. Sign-in is by passkey, or by a one-time code sent to your email address, and both are handled by our identity provider. We never receive, process or store a password, so there is none to lose.
- Data is encrypted in transit and at rest.
- Access is limited to what each role needs, and access is logged.
- Backups are encrypted and the restore process is tested rather than assumed.
- If there is a breach that puts you at risk, we will tell the ICO within 72 hours and tell you without undue delay.
Where your data is
Your membership data is held in the United Kingdom: the database and the application both run in London.
Your sign-in data (your email address, the public half of your passkey, and when you signed in) is processed by our identity provider, Clerk, under a data processing agreement. Where this data is processed outside the UK, it is executed strictly under compliant UK International Data Transfer mechanisms.
Cookies, and what we keep on your device
Essential authentication cookies (such as __session) to keep you signed in, set by our identity provider on our own domain. They are not used for tracking or advertising, and there is no analytics on the member application.
Two small settings stored in your browser, not on our servers: whether you prefer the light, dark or automatic appearance, and whether you prefer the comfortable or compact layout. They contain no personal data, they never leave your device, and clearing your browser storage removes them. We mention them because storing anything on your device should be disclosed even when it is harmless, and these are the only things we put there.
Changes
If we change anything that affects you materially, we will tell you directly rather than quietly updating this page. The date of each change is recorded with the policy, and we will state it here.
Changes so far. Version 1.1, 16 September 2026: added the section If you ask to be considered, with the matching row in What we hold, the legal basis for considering a request, and its ninety-day row in How long we keep it; the section If you are not a member now says that it applies unless you sent us that form. Nothing else changed. Version 1.0, 13 September 2026: first version in force.