Privacy Policy
Last updated: 19 August 2026
1. Who We Are
EAS Technology Consulting Ltd trading as Blankitt ("we", "us", "our") operates the following services:
- blankitt.com — marketing website
- draw.blankitt.com — IT infrastructure diagram editor
- portal.blankitt.com — account, billing, and endpoint/agent management
- dmarc.blankitt.com — DMARC email-authentication monitoring
- finance.blankitt.com — personal and business finance, with Open Banking
- hr.blankitt.com — HR, UK payroll, and hiring (applicant tracking)
- edge.blankitt.com — e-commerce storefront traffic security and bot detection
- privacy.blankitt.com — data-subject request (DSAR) management for businesses
Several of these are business products we operate on behalf of a business customer. Where a customer uses Blankitt to process data about their own people (for example DMARC report data, HR employee and candidate records, Edge storefront visitors, or the data subjects handled in Blankitt Privacy), that customer is the data controller and Blankitt acts as their processor. Sections 9 to 13 cover these products in detail.
We are also rolling out an additional application, GRC (governance, risk, and compliance). This policy is updated as each product becomes generally available, and explains how we collect, use, and protect your data across our services.
2. What Data We Collect
Analytics Data
When you consent, we use Google Analytics 4 (GA4) to collect anonymised usage data including page views, device type, browser, and approximate geographic region. We also use Cloudflare Web Analytics, which is entirely cookie-free and does not collect personal data.
We additionally send a small set of high-level account events — account creation, first bank connected, subscription start/cancel, account deletion, and data export — from our servers to GA4 so we can understand the customer journey end-to-end. Server-side events use your account ID as the GA4 client identifier and contain no transaction data, bank balances, or personal information beyond what's named here.
Account Data
When you create an account on any Blankitt app (Draw, Portal, DMARC, or Finance), we collect your email address, name, and password (stored as a salted hash). We never store passwords in plain text.
Financial Data
If you connect a bank account on finance.blankitt.com, we receive account identifiers (sort code, account number, IBAN where applicable, masked card numbers), bank and account metadata (bank name, account type, currency, nickname), real-time balances, and transaction history (typically the most recent 90 days, refreshed daily). Access tokens issued by your bank are encrypted at rest using AES-256-GCM. We never receive your bank login credentials, password, or PIN. See section 9 for the full Open Banking disclosure.
DMARC Monitoring Data
If you use Blankitt DMARC, we process DMARC reports about email sent using your domains. Aggregate (RUA) reports contain sending IP addresses, the domains and mail servers involved, SPF/DKIM authentication and alignment results, message volumes, and the policy applied. Forensic (failure) reports, where you enable them, can additionally contain message-level metadata such as the From/To headers and subject of individual failing messages. Because these reports describe mail sent (or spoofed) as your domains, they can include the IP addresses and domains of third parties. See section 10 for the full DMARC disclosure, including mailbox connections.
Payment Data
If you upgrade to a paid plan, we use Stripe to process payments. We do not store full card numbers — Stripe handles card data directly. We retain a Stripe customer ID, the last four digits of your card, the card brand, and your billing country in order to display your subscription, manage renewals, and meet UK tax record-keeping requirements.
Diagrams & Projects
Diagrams created in Blankitt Draw are stored locally in your browser by default. If you choose to save to the cloud, diagram data is stored on our servers (Cloudflare D1). Diagrams may contain device names, IP addresses, and network topology that you enter.
Free Tools & Enquiries
When you use a free tool such as our DMARC checker, or submit an enquiry or assessment form, we collect the information you provide — for example the domain you ask us to check and, if you choose to share it, your email address — so we can return your result and, with your consent, follow up about it. These forms are handled by our own marketing systems and protected with Cloudflare Turnstile, a privacy-preserving, cookie-free bot check.
Attribution Data
When you consent to analytics, we capture UTM campaign parameters and referrer information to understand how you found us.
Business Finance Data
If you use Blankitt Finance for a business, we process your company profile and bank details, bank connections made through Open Banking (via TrueLayer or Yapily), transactions, invoices, expenses, VAT data, and the salary and compensation records of employees you enter. See section 9 for the Open Banking disclosure.
HR, Payroll & Hiring Data (Blankitt HR)
If your employer uses Blankitt HR, we process, on their behalf, employee records (name, date of birth, National Insurance number, home address, and emergency contacts), payroll and pay data, tax codes and Real Time Information (RTI) submissions to HMRC, right-to-work and DBS check documents, and, where applicable, US employment records such as Form I-9. For hiring, we process candidate applications, including CVs and, where a candidate chooses to provide it, diversity information. Some of this is special-category or immigration data. Your employer is the controller; Blankitt is the processor. See section 11.
E-commerce Storefront Security Data (Blankitt Edge)
If you use Blankitt Edge, we process request logs from your storefront's content-delivery network in order to detect bots, scrapers, and abusive traffic. These logs include visitor IP addresses, network (ASN) and country, user-agent, requested paths, HTTP method and status, and timing. We process full IP addresses (we do not mask them), because blocking and rate-limiting decisions require the exact address. The merchant is the controller; Blankitt is the processor. See section 12.
Data-Subject Request Data (Blankitt Privacy)
If a business uses Blankitt Privacy to manage data-subject requests (DSARs), we process, on their behalf, the personal data of the individuals who make those requests: their name and contact details, the request itself, identity-verification documents (such as a passport or driving-licence image) where the business requires them, and the personal data gathered from the business's own systems to fulfil the request. The business is the controller; Blankitt is the processor. See section 13.
3. Cookies & Similar Technologies
| Name | Purpose | Category | Duration |
|---|---|---|---|
| _ga | Google Analytics visitor ID | Analytics | 2 years |
| _ga_* | GA4 session state | Analytics | 2 years |
| _gid | GA4 session ID | Analytics | 24 hours |
| blankitt-consent | Your cookie preferences | Essential | Persistent |
| draw-auth-token | Authentication (Draw) | Essential | Session |
| token | Authentication (Portal, DMARC, and other Blankitt apps) | Essential | Session |
| blankitt-draw-projects | Crash recovery | Essential | Persistent |
| draw-sidebar-width, draw-landing-theme, blankitt-theme | UI preferences | Functional | Persistent |
| utm_source, utm_medium, utm_campaign (sessionStorage) | Campaign attribution | Analytics | Session |
Cloudflare Web Analytics does not use cookies or collect personal data. It is loaded on all pages regardless of your cookie preferences. Cloudflare Turnstile (used on free tools and contact forms) is a cookie-free bot check and is not used for tracking or advertising.
4. How We Use Your Data
- Improve our products and user experience
- Understand aggregate usage patterns
- Provide and secure your account
- Communicate about your account or service changes
We do not sell your personal data to third parties.
5. Legal Basis for Processing (GDPR)
- Consent — Analytics cookies are only set after you actively consent; marketing follow-up to a free-tool enquiry is sent only with your consent
- Contract — Account data, and the monitoring/processing you sign up for (e.g. DMARC), are processed to provide the service
- Legitimate interest — Essential cookies and bot protection for security and functionality
6. Your Rights (GDPR)
If you are in the EU, EEA, or UK, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Request erasure of your data
- Data portability (receive your data in a structured format)
- Restrict processing
- Object to processing
- Withdraw consent at any time via the "Cookie Settings" link in the footer
Where Blankitt processes data on behalf of a business customer (for example DMARC report data, HR employee and candidate records, Edge storefront visitor data, business Finance data, or the data subjects handled in Blankitt Privacy), that customer is the data controller; please direct such requests to them and we will assist as their processor.
7. Your Rights (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the "sale" or "sharing" of personal information (we do not sell data)
- Non-discrimination for exercising your rights
8. Global Privacy Control
We honour the Global Privacy Control (GPC) browser signal. If your browser sends a GPC signal, analytics cookies will be automatically disabled without requiring further action from you.
9. Open Banking Data
If you connect a bank account to Blankitt's personal finance product, we use the UK's Open Banking framework to fetch your account data. The Open Banking framework is regulated by the Financial Conduct Authority (FCA) and underpinned by the Payment Services Regulations 2017 (PSR 2017).
Who acts as your Account Information Service Provider (AISP)?
Yapily Ltd ("Yapily") is the FCA-authorised AISP. Yapily is registered with the FCA under firm reference number (to be confirmed once Yapily's agent agreement is signed). Blankitt operates as Yapily's appointed representative under PSR 36(1), which means Blankitt arranges the connection on your behalf and Yapily is the regulated party performing the account-information service.
You can verify Yapily's authorisation on the FCA Financial Services Register.
Business accounts
Blankitt Finance for business uses the same Open Banking framework. Business bank connections are provided by TrueLayer Limited or Yapily Ltd, both FCA-authorised Account Information Service Providers whose authorisation you can verify on the FCA Financial Services Register. The data categories, storage, and rights described in this section apply equally to business connections.
What data we receive from your bank
When you authorise the connection at your bank, your bank shares the following with Yapily, who then makes it available to Blankitt:
- Account identifiers (account number, sort code, IBAN where applicable, masked card numbers).
- Account metadata: bank name, account type, currency, nickname.
- Real-time account balances.
- Transaction history (typically the most recent 90 days, refreshed daily).
We do not receive your bank login credentials or PIN. Authentication happens directly between you and your bank during the consent flow.
Lawful basis: consent
We process this data on the basis of your explicit consent under UK GDPR Article 6(1)(a). You consent during your bank's authorisation flow before any data is shared. Open Banking consents last for 90 days under PSR rules; after that, data sync stops automatically until you reconnect.
Withdrawing consent
You can revoke a connection at any time from the Bank Feeds page in your Blankitt account. We will:
- Tell Yapily to revoke the consent at your bank (so your bank stops sharing data).
- Mark the connection as disconnected within Blankitt.
- On request, permanently delete the imported transactions and account metadata. (Permanent delete is a separate action — by default we retain history so you can browse it post-disconnect.)
You can also withdraw consent directly with your bank.
Where the data is stored
Imported account data is stored in encrypted form in the United Kingdom and Republic of Ireland regions of Cloudflare, Inc.'s D1 SQLite-compatible database. Sensitive fields (access tokens issued by your bank, sort codes, account numbers) are encrypted at the application level using AES-256-GCM, keyed separately from the rest of our infrastructure secrets.
Third-party data processors
The chain of processors for your bank data is:
| Processor | Role | Jurisdiction |
|---|---|---|
| Your bank | Data controller (the source) | UK / your bank's home country |
| Yapily Ltd | AISP — fetches data from bank, hands to Blankitt | United Kingdom |
| TrueLayer Limited | AISP — business Open Banking connections | United Kingdom |
| Blankitt | Application — displays and categorises data for you | United Kingdom |
| Cloudflare, Inc. | Storage and edge compute infrastructure | UK + Republic of Ireland |
Each processor in this chain has its own privacy policy. Yapily's is at yapily.com/legal/privacy. Cloudflare's is at cloudflare.com/privacypolicy.
How long we keep the data
For as long as you keep the connection active or the imported transactions in your account. If you disconnect a bank, the consent is revoked but transaction history is retained until you choose "Delete" (a separate, irreversible action) or close your Blankitt account.
Your rights
UK GDPR gives you the right to access, correct, and delete the data we hold on you. Email [email protected] and we'll respond within 30 days. You can also complain to the Information Commissioner's Office (ICO) at ico.org.uk.
10. DMARC Email Authentication Data
Blankitt DMARC helps you monitor and improve the email authentication (DMARC, SPF, and DKIM) of domains you own. This section explains the data involved and how mailbox connections work.
Controller and processor
For business customers, you are the data controller of the DMARC report data relating to your domains, and Blankitt acts as your processor, processing it only to provide the monitoring service and on your instructions. A Data Processing Agreement is available to business customers on request ([email protected]); our sub-processors are listed at blankitt.com/subprocessors.
How we receive reports
There are two ways DMARC reports reach Blankitt, and you choose which to use:
- Blankitt report address. We give you a unique address of the form
<id>@rua.blankitt.comto publish in your domain's DMARC DNS record. Mailbox providers (Google, Microsoft, Yahoo and others) then email aggregate reports to that address, where we ingest them. The address is specific to your account. - Connected mailbox. Alternatively, you can connect a Microsoft 365 or Google Workspace mailbox so we collect reports that already arrive there.
Mailbox connections (Microsoft 365 / Google Workspace)
If you connect a mailbox, you authorise Blankitt — through Microsoft's or Google's standard OAuth consent — to access that mailbox to read and extract DMARC report attachments. We:
- request the narrowest access the provider offers for this purpose;
- process only DMARC report messages and their attachments — we do not read, store, or use your other email for any purpose;
- store the resulting access credentials encrypted at rest (AES-256-GCM); and
- let you disconnect at any time from the DMARC app's settings, which stops collection and deletes the stored credentials.
DNS lookups and the free checker
To assess a domain, we perform DNS lookups of its public email-authentication records (DMARC, SPF, DKIM, BIMI, MTA-STS, TLSRPT). Our free DMARC checker does a live lookup of the domain you enter and returns an assessment; if you provide an email address to receive your result, we handle it as described in section 2. You may only check domains you own or are authorised to assess — see our Acceptable Use Policy.
Storage, sub-processors, and retention
DMARC data is stored in Cloudflare's D1 database, scoped to your account, in Cloudflare's UK/EU regions (see section 15). The sub-processors used for DMARC are Cloudflare (hosting, storage, report-email routing, and Turnstile bot protection), Microsoft and/or Google (only if you connect their mailbox), Resend (notification emails), and Stripe (billing) — the full list is at blankitt.com/subprocessors. Reports are retained for your plan's retention window (from 30 days up to 2 years) and older data is then deleted automatically; you can also request deletion at any time. Lawful basis: contract (to provide the monitoring you signed up for) and, for a mailbox connection, your authorisation.
11. Blankitt HR Data
Blankitt HR is a human-resources, payroll, and hiring platform that a business (your employer) uses to manage its people. For this data your employer is the data controller and Blankitt is the processor, acting on their instructions and under a Data Processing Agreement available on request ([email protected]). Our sub-processors are listed at blankitt.com/subprocessors.
What we process
Employee records (name, date of birth, National Insurance number, address, and emergency contacts), payroll and pay data, tax codes, pensions, and year-end forms (P60, P11D). For UK payroll we submit Real Time Information (RTI) to HMRC on your employer's behalf. We store right-to-work and DBS check documents and, for US employees, records such as Form I-9. For hiring, we process candidate applications, CVs, interview records, and any diversity information a candidate provides.
Special-category and immigration data
Some HR data is special-category data (for example diversity information, or health-related absence) or immigration data (right-to-work evidence). We process it only to provide the HR service and on your employer's instructions.
Third parties
Depending on the features your employer enables, HR data may be shared with HMRC (payroll RTI), background-check and right-to-work providers, job boards, video-interview providers, and calendar or email providers for scheduling. Each is listed at blankitt.com/subprocessors. Retention is described in section 14.
12. Blankitt Edge Data
Blankitt Edge helps an online retailer detect and respond to bots, scrapers, and abusive traffic on their storefront. Edge reads the storefront's content-delivery-network logs out of band; it is never in the path of a shopper's request. For this data the retailer is the data controller and Blankitt is the processor.
What we process
Storefront request logs containing visitor IP addresses, network (ASN) and country, user-agent, requested paths, HTTP method and status, and timing. We process full IP addresses because blocking and rate-limiting decisions require the exact address; IP addresses are not masked or hashed. We do not receive shopper names, payment details, or the contents of orders.
AI-generated explanations
Where enabled, Edge uses AI to write plain-English explanations of an alert. Only aggregated evidence (such as the network operator, country, and a normalised path with counts) is sent to the AI provider; raw logs and raw IP addresses are not. When a customer's own external AI provider is not enabled, this runs inside Cloudflare and no data leaves Cloudflare.
Alerts
Alerts can be delivered to destinations the customer configures (email, webhook, Microsoft Teams, or Slack). These carry the network, country, and normalised path involved, not shopper IP addresses. Retention is described in section 14.
13. Blankitt Privacy (DSAR) Data
Blankitt Privacy lets a business receive and fulfil data-subject requests (for access, erasure, and similar rights). The business is the data controller of the request data and Blankitt is the processor. Each business's data is isolated in its own database.
What we process
On the business's behalf, we process the personal data of the individuals making a request: their name and contact details, the request and correspondence, identity-verification documents (such as a passport or driving-licence image) where the business requires them, and the personal data gathered from the business's systems to fulfil the request.
Identity documents and deletion
Identity-verification documents are deleted automatically as soon as identity is verified. Closed or rejected requests are automatically anonymised after the business's chosen retention period (12 months by default), and secure delivery links expire (14 days by default). A tamper-evident audit record of the request is retained. See section 14.
14. Data Retention
We keep personal data only as long as we need it for the purpose it was collected, or as the law requires. Where a business customer is the controller (DMARC, HR, Edge, Privacy, and business Finance), we also retain and delete data on their instructions. Where a product does not delete data on an automatic schedule, we retain it until you, or the controlling business, request deletion or close the account.
- Analytics (GA4): retained for 14 months (Google default).
- Account data: retained while your account is active; deleted on request or on account closure.
- Draw cloud projects: retained while your account is active; deleted on request.
- Bank connections & transactions (personal and business Finance): retained while the connection is active. After you disconnect, transaction history is retained until you delete it or close your account; encrypted bank access tokens are deleted immediately on disconnect.
- DMARC reports & monitoring data: retained for your plan's retention window (30 days to 2 years); older reports are deleted automatically. Deleted on request and on account closure.
- Edge storefront security data: raw request logs (which include visitor IP addresses) are automatically deleted after 30 days; aggregated traffic analytics age out after about 90 days; short-lived forensic IP-capture windows expire within 24 hours; alerts and operational records are retained until deleted by the customer or on account closure.
- HR candidate (applicant) data: for unsuccessful applicants, automatically anonymised or deleted after a retention period set by your employer (defaulting to a few months). Candidates can request access to, or erasure of, their data.
- HR employee, payroll and compliance data: retained for the life of the employer's account and, where longer, for the periods UK employment and tax law require; deleted on the employer's instruction. This includes payroll, RTI, right-to-work and DBS documents, and year-end forms.
- Business Finance records: company, bank, invoice, expense, and employee-salary records are retained while the account is active and deleted on request or on account closure.
- Blankitt Privacy (DSAR) data: identity-verification documents are deleted as soon as identity is verified; closed or rejected requests are anonymised after the controller's retention period (12 months by default); secure delivery links expire (14 days by default). A tamper-evident audit record is retained.
- Free-tool enquiry and marketing-contact data: retained until you ask us to delete it or unsubscribe. If you opt out, we keep a minimal suppression record so we can honour your choice.
- Payment records: retained for 7 years to meet UK tax and accounting record-keeping requirements (Companies Act 2006).
- Transactional email logs: retained for 30 days by Resend (our email provider) for delivery diagnostics, then deleted.
- Server-side analytics: IP addresses are hashed with SHA-256; raw events are retained for 90 days.
15. International Transfers
Depending on the products you use, your data may be processed by providers located outside the UK and EEA:
- Google LLC (United States) — analytics, and access to a connected Google Workspace mailbox for DMARC, or Google calendar and email features in HR
- Microsoft Corporation / Microsoft Ireland Operations Ltd — access to a connected Microsoft 365 mailbox for DMARC, or Microsoft 365 calendar and email features in HR
- Cloudflare Inc. (United Kingdom + Republic of Ireland regions) — hosting, storage, CDN, DMARC report-email routing, and Turnstile bot protection
- Anthropic, PBC (United States) — AI features: candidate-CV parsing in HR, document and receipt processing in Finance, and alert explanations in Edge and our marketing tooling
- Yapily Ltd and TrueLayer Limited (United Kingdom) — FCA-authorised AISPs for Open Banking (personal and business Finance)
- Stripe Payments Europe Ltd (Republic of Ireland) and Stripe, Inc. (United States) — subscription payments
- Resend Inc. (United States) — transactional and notification emails
Blankitt HR and Edge use further sub-processors depending on the features you enable (for example background-check, right-to-work, job-board, and video-interview providers). Providers outside the UK and EEA maintain appropriate safeguards for international data transfers, including UK International Data Transfer Agreements (IDTA) or EU Standard Contractual Clauses (SCCs). The complete, current sub-processor list with locations and safeguards is published at blankitt.com/subprocessors.
16. Children's Privacy
Our services are not directed at individuals under 16. We do not knowingly collect data from children.
17. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the website. The "last updated" date at the top reflects the most recent revision.
18. Contact Us
For privacy-related questions or to exercise your rights:
- Email: [email protected]
- General enquiries: [email protected]