BlackSplit

GDPR Data Protection Notice

This GDPR Data Protection Notice is intended to explain the principles governing the processing of personal data, the applicable legal bases, and the rights available to individuals when BlackSplit provides platform functions and conducts related operational activities. This Notice is formulated in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applies to the BlackSplit platform and its related features and services.

I. General Principles of Personal Data Processing

In the course of operating the BlackSplit platform and providing related functionalities to users, we may process personal data relating to users within a reasonable and necessary scope.

Such processing activities are primarily carried out to support platform account management, the establishment and maintenance of collaborative relationships, the display of participation status and related records, the operation of platform functionalities, user communications, system maintenance, security protection, and the fulfillment of applicable legal and regulatory obligations.

We consistently adhere to the fundamental principles of lawfulness, fairness, transparency, purpose limitation, data minimization, and security, and process personal data only to the extent necessary to achieve clear and legitimate platform functionalities and operational purposes, taking into account users' reasonable expectations arising from their use of the platform.

As the platform operator, BlackSplit provides technical platform services to support subscription cost sharing, collaborative relationship management, and the implementation of related functionalities. BlackSplit is not a provider of third-party subscription services or content, nor does it directly determine or control the specific content of such third-party services or their independent data processing activities.

During the use of the platform, certain processing activities related to subscription services may be carried out directly between users and third-party service providers, based on users' own decisions. BlackSplit processes personal data only within the scope of platform functionalities, and solely insofar as such data is directly related to the operation of its own platform services.

On the basis of the above-defined platform role and processing boundaries, BlackSplit processes the following categories of personal data only to the extent necessary to provide platform functionalities and fulfill related obligations, and in accordance with users' specific usage scenarios and functional requirements:

  • Account and identity-related information (platform-level only), such as email addresses, usernames, internal account identifiers, or other information used solely for platform account management and login authentication purposes.
  • Device and technical information, such as IP addresses, device identifiers, browser types, operating system information, as well as cookies or similar technical identifiers used to ensure the normal operation and security of the platform.
  • Platform usage and operational information, such as collaborative relationships, participation status, operation records, log information, and behavioral data associated with the use of platform functionalities.
  • Communication and support-related information, such as records of communications between users and the platform, feedback content, enquiries, or customer support request information.
  • Compliance and security-related information, strictly limited to necessity, where required by law or platform security management needs.

II. Legal Bases for Personal Data Processing

All personal data processing activities are conducted in accordance with the principles of lawfulness, fairness, transparency, and necessity, and are carried out strictly on the basis of clear and legitimate legal grounds.

In the course of actual platform operations, BlackSplit's processing of personal data is typically based on one or more of the following legal bases:

  • Legal obligation, where processing is necessary for compliance with applicable laws and regulations, supervisory requirements, or tax and accounting obligations.
  • Legitimate interests, where processing is necessary to safeguard the security of the platform and its users, prevent fraud or abuse, and implement necessary risk management and system maintenance measures.
  • Contractual necessity, where processing is necessary for the performance of a service agreement between the user and the platform, or for taking steps at the user's request prior to entering into such an agreement.
  • Consent, where explicitly required by applicable laws and regulations, or where the relevant processing activity does not fall within the legal bases set out above.

BlackSplit consistently applies the appropriate and most suitable legal basis to each category of personal data processing activity in accordance with applicable data protection laws, and adopts reasonable measures to ensure the compliance and necessity of such processing activities.

III. Use, Access, and Sharing of Personal Data

Personal data is used and accessed only to the extent necessary to achieve the purposes described above.

In the course of platform operations, personal data may be processed within BlackSplit's system environment. Where necessary, certain personal data may also be processed by entrusted service providers that support the operation of the platform, strictly in accordance with BlackSplit's instructions and solely within the scope of their entrusted responsibilities.

Such entrusted service providers may include the following categories of technical or operational support providers:

  • Payment-related technical or settlement support service providers.
  • Cloud service or system hosting providers.
  • Customer support or communication tool service providers.
  • Compliance, audit, or risk support service providers, where applicable.

All such entrusted service providers process personal data only to the extent necessary to perform their entrusted duties and achieve the relevant support purposes, and are required, pursuant to applicable data protection laws and contractual arrangements, to implement appropriate technical and organizational measures.

IV. Cross-Border Data Processing and Protection

Due to the platform's technical architecture, service coverage, and operational characteristics, personal data may be processed or stored in different countries or regions.

Where the transfer of personal data from the European Union to locations outside the EU is involved, BlackSplit will, in accordance with applicable data protection laws and subject to the requirements of such laws, implement appropriate lawful transfer mechanisms as well as necessary technical and organizational safeguards to ensure that the relevant personal data continues to receive the level of protection required by law during processing.

V. Data Retention and Lifecycle Management

Personal data will be retained only for the period necessary to fulfill the relevant processing purposes. Once such purposes no longer exist, related disputes or investigations have concluded, or the applicable statutory retention period has expired, personal data will be handled through deletion, anonymization, or other legally compliant measures, in accordance with applicable laws and regulations.

VI. Users' Data Protection Rights

In accordance with applicable data protection laws, eligible users are entitled to exercise rights in relation to their personal data, including but not limited to:

  • The right to confirm whether their personal data is being processed and to request access.
  • The right to request rectification of inaccurate or incomplete personal data.
  • The right to request erasure of personal data under legally applicable conditions.
  • The right to request restriction of or to object to certain processing activities.
  • The right to receive their personal data in a structured, commonly used, and machine-readable format and to exercise data portability.
  • The right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing prior to withdrawal.

Users may submit relevant requests via the contact details published by BlackSplit. BlackSplit will respond within a reasonable period in accordance with applicable law, generally within 30 days. Where requests are complex or require an extension, users will be informed as required by law.

VII. Data Controller Contact Information

Users may contact BlackSplit regarding matters related to the personal data processing described in this Notice via the following email address: team@BlackSplit.com.

BlackSplit has designated personnel responsible for personal data protection matters, appropriate to its business scale and risk profile, to handle personal data-related requests through the above contact details.

Where applicable and where the conditions set out in Article 27 of the GDPR are met, BlackSplit will appoint a designated EU Representative and provide the relevant contact details to users.

VIII. Automated Processing and Risk Management

In the course of platform operation and security management, BlackSplit uses system-based mechanisms to support platform maintenance and basic security management.

Any automated processing is used solely as an auxiliary measure and is not used, in the absence of appropriate safeguards or meaningful human intervention, as the sole basis for decisions that produce legal effects or similarly significant impacts on users.

IX. Data Security Measures

We have implemented technical and organizational measures proportionate to our business scale, technological capabilities, and risk profile to safeguard personal data against unauthorized access, disclosure, alteration, or misuse, and we continuously evaluate and improve such measures.

X. Complaints, Communication, and Regulatory Remedies

Where users believe that the processing of their personal data does not comply with applicable data protection laws, they have the right to lodge a complaint with the competent data protection supervisory authority.

We also encourage users to contact BlackSplit via the published contact details prior to seeking regulatory remedies, so that we may address concerns directly where possible.

XI. Updates to This Notice

We may update this Notice from time to time in response to changes in laws, regulatory requirements, or platform operations.

Updated versions will be published on the platform and will take effect from the date of publication.

XII. Cookies and Similar Technologies

BlackSplit may use cookies or similar technologies during platform operations solely to the extent necessary to enable core platform functionalities, ensure system security, and maintain service stability.

Where the use of non-essential cookies or similar technologies is involved in the future, BlackSplit will, in accordance with applicable data protection and electronic privacy laws, provide users with clear information in advance and obtain their valid consent prior to such use.