Privacy Policy

Effective date: July 11, 2026

Blackbird IT Solutions ("Blackbird," "we," "us," or "our") provides managed IT and cybersecurity services to businesses. This policy explains what information we collect, why we collect it, and how we protect it — whether you're browsing our website, requesting an assessment, or working with us as a client.

We wrote this in plain English on purpose. If anything here is unclear, email us — we'd rather explain it than have you guess.

1. What we collect

Information you give us directly. Your name, company name, email address, and phone number when you contact us, request an M365 assessment, or fill out a form on this site.

Information we collect automatically. When you visit our website, we collect standard analytics data — pages viewed, general location, browser and device type, and how you found us — through Google Analytics (GA4) and Google Search Console. This data is aggregated and isn't used to identify you personally.

Information we process on behalf of clients. If you're a managed services client, we process data as part of delivering IT and security services — device and system information, security logs, backup data, and similar operational data. This is processed under the terms of your service agreement, not this public policy, and only for the purpose of delivering and securing your environment.

M365 assessment data. If you run our automated Microsoft 365 security assessment, we access your tenant read-only through a Microsoft App Registration you control. We don't store your credentials, and the data we pull is used solely to generate your report.

2. How we use it

We use the information above to:

We do not sell your personal information. We never have, and we're not planning to start.

3. Who we share it with

We don't share your information for marketing purposes. We do work with a small number of vendors to run our business and deliver our services — each one only gets the access it needs to do its job:

VendorWhat it's for
Microsoft 365Email, identity, and device management for our own operations, and for clients on managed services
StripePayment processing. Card and bank details go straight to Stripe — we never see or store them
XeroAccounting and invoicing
NinjaOneRemote monitoring and management for client devices under a service agreement
Perception Point (FortiMail)Email security filtering
HuntressManaged endpoint detection and response for client devices
Keeper SecurityEncrypted credential storage
DigitalOceanHosting for our web and application infrastructure
Google (Analytics / Search Console)Website traffic and search performance analytics

Every vendor we use is bound by its own security and confidentiality obligations, and we review our vendor list regularly as part of our security program. We may also disclose information if required by law, to protect our rights or safety, or in connection with a legal process.

4. How we protect it

Security isn't an afterthought here — it's the business. Concretely, that means:

No system is 100% secure, and we won't pretend otherwise — but we take real, documented steps to protect what you share with us, and we hold ourselves to the same standard we sell to our clients.

Blackbird is actively pursuing SOC 2 Type II compliance. We operate under a documented, SOC 2-aligned control framework covering access management, change management, system monitoring, and vendor oversight — and we review it continuously as we build toward a formal audit. We're not there yet, and we won't tell you we are until an independent auditor says so.

5. How long we keep it

Data is kept only as long as needed to deliver services, meet legal obligations, or support the reason it was collected. Some examples: M365 assessment reports are automatically deleted 90 days after delivery. Client data processed under a managed services agreement is retained and deleted according to the terms of that agreement.

We're still formalizing a company-wide retention schedule for general website and inquiry data (contact form submissions, analytics). Until that's published, we retain that data only as long as reasonably necessary for the purpose it was collected, and delete it on request (see Section 6).

6. Your rights and choices

You can ask us to access, correct, or delete the personal information we hold about you by emailing info@blackbirditsolutions.com. We'll respond promptly — we don't have a large enough team yet to promise a formal SLA on this, but we take these requests seriously and will handle them directly, not through a form-letter process.

If you're a client, data processed on your behalf under a service agreement is governed by that agreement, and requests related to it should go through your normal Blackbird contact.

7. Cookies and analytics

This site uses cookies and similar technologies through Google Analytics (GA4) and Google Search Console to understand how visitors use the site. This helps us improve the site and doesn't identify you personally. You can control cookies through your browser settings; blocking them won't affect your ability to use this site, but may limit some analytics features.

8. If something goes wrong

If we experience a security incident affecting your personal information, we will notify affected individuals without unreasonable delay, consistent with applicable law. Clients under a Blackbird service agreement have specific incident notification commitments defined in that agreement.

9. Changes to this policy

We may update this policy as our services, vendors, or legal obligations change. We'll update the effective date at the top when we do. Material changes will be noted here.

10. Contact us

Questions about this policy or how we handle your information?

Blackbird IT Solutions
Email: info@blackbirditsolutions.com