Legal

Privacy notice

This notice explains how we handle personal data on this website and in the course of our work, in line with Regulation (EU) 2016/679 (GDPR).

Last updated: September 2026

1. Controller and contact

The four partners of Black Sea Risk Advisory Group act as joint controllers for data submitted through this site and for engagement records. Data protection queries and requests should be sent to blacksearisk.eu@gmail.com; we answer within one month.

2. What we collect and why

We keep data collection deliberately narrow.

  • Enquiry form: your name, email, organisation and message, used solely to respond to your enquiry and to scope possible work. Legal basis: steps taken at your request prior to a contract, and our legitimate interest in responding to business enquiries.
  • Engagement records: contact details of your representatives, correspondence, invoices and the deliverable. Legal basis: performance of the contract and compliance with legal obligations such as accounting and anti-money-laundering rules.
  • Research data: our work may involve personal data about third parties — company officers, beneficial owners, public officials — drawn from public registers, court and procurement records, and published reporting. Legal basis: our and our client's legitimate interest in integrity and risk assessment, balanced against the rights of the individuals concerned.

3. What we do not do

We do not sell or rent personal data, we do not use it for advertising or profiling, we do not run behavioural advertising trackers on this site, and we do not use enquiry details to build a marketing list.

4. Sharing and processors

Data is shared only with the four partners, with infrastructure providers hosting the site and the enquiry database under a data-processing agreement, and where disclosure is required by law. Where a provider processes data outside the EEA, transfers rely on adequacy decisions or standard contractual clauses.

5. Retention

Enquiries that do not become engagements are deleted within 12 months. Engagement records and deliverables are retained for the period required by accounting and limitation rules, normally up to 10 years, and then deleted. Research working material is deleted at the end of the retention period agreed with the client.

6. Your rights

You may request access to your personal data, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. You may also lodge a complaint with your national supervisory authority — in our case the Bulgarian CPDP, the Moldovan NCPDP or the Romanian ANSPDCP.

7. Cookies and analytics

This site uses only what is strictly necessary to serve the pages. It sets no advertising cookies and runs no cross-site tracking. If we ever add analytics, this notice will be updated first and consent requested where the law requires it.

8. Security

Enquiry data is stored in an access-controlled database with row-level restrictions; client material is held in encrypted storage and shared with clients over protected channels. Access is limited to the partner working on the mandate.