Preamble
This Privacy Policy (the "Policy") is issued by Black Swan Ventures Group LLC, a limited liability company organised under the laws of the State of Wyoming, United States of America (the "Company", "we", "us", "our"), being the operator of the website located at cashflowpositive.ai and the publisher of the Cashflow Positive AI brand.
The Policy governs the collection, use, disclosure, retention, and protection of personal data by the Company in connection with: (a) the aforesaid website and any subdomain thereof; (b) our publications, whether in printed or electronic form; (c) our business development correspondence, whether conducted by electronic mail or by telephone; and (d) the delivery of any service supplied under the Cash Flow Positive brand or by the Company (together, the "Services").
The Policy is framed so as to satisfy the requirements of Regulation (EU) 2016/679 (the "GDPR"), the United Kingdom General Data Protection Regulation, the German Bundesdatenschutzgesetz, the California Consumer Privacy Act as amended by the California Privacy Rights Act, and the several further State privacy statutes of the United States now in force.
This Policy is to be read together with, and forms a single instrument with, the Cookie Policy, the Cold Outreach & Communications Policy, the Do Not Sell or Share My Personal Information notice, the Sub-processor Register, the Data Processing Addendum, and the Cybersecurity Disclosure. Where any provision of this Policy conflicts with a provision of any of the foregoing, the more specific instrument shall prevail in respect of the subject-matter it governs.
1. Identity of the Controller and Manner of Correspondence
1.1 The controller in respect of the processing described herein is:
Black Swan Ventures Group LLC
30 N Gould Street, Ste N
Sheridan, Wyoming 82801
United States of America
Electronic mail: mgmt@blackswanventuresgroup.com
Telephone: +1 872-375-3144
1.2 The Company operates a single point of correspondence. All communications concerning this Policy, all requests for the exercise of rights, all complaints, and all notices of whatever nature are to be addressed to mgmt@blackswanventuresgroup.com. No other electronic mail address is maintained for such purposes, and correspondence sent to any other address should not be assumed to have been received.
1.3 In order that correspondence may be routed and answered expeditiously, the data subject is respectfully invited, though not required, to prefix the subject line of any communication with the word PRIVACY. Failure to do so shall not prejudice the request nor extend any period prescribed by law.
1.4 The Company has not appointed a Data Protection Officer, the thresholds prescribed by Article 37 GDPR not being met. Matters arising under this Policy are determined by the Managing Member.
1.5 Where the Company is required by Article 27 GDPR to designate a representative within the Union, the identity and address of that representative shall be published at this clause. [To be completed upon appointment, or this clause deleted in the event that processing of Union personal data is discontinued.]
2. Categories of Personal Data Processed
2.1 Data furnished by the data subject
| Occasion of collection | Categories of data |
|---|---|
| Application to the AI Concierge programme | Name; business name; office held; website; business electronic mail address; business telephone number; revenue band; description of operations voluntarily supplied |
| Booking of a consultation | Name; business electronic mail address; calendar availability; such context as is volunteered upon scheduling |
| Registration for a workshop or course | Name; business electronic mail address; company; billing particulars; record of attendance |
| Subscription to publications | Electronic mail address; delivery and language preferences |
| Performance of an engagement | Such information as the client or its personnel elect to furnish for the purpose of delivery, including any credentials voluntarily provided |
| General correspondence | The content of electronic mail, telephone calls, and messages |
2.2 Data collected by automated means
Internet Protocol address; browser and device characteristics; operating system; language preference; referring uniform resource locator; pages accessed; duration of session; and interaction events. Such data are collected by means of cookies and analogous technologies, as to which see the Cookie Policy.
2.3 Business contact data obtained from third parties
2.3.1 The Company conducts business-to-business correspondence. For that purpose it compiles and enriches records comprising: full name; office held; employer; business electronic mail address; business telephone number; publicly available professional profile; and publicly reported firmographic indicators including headcount, funding events, recruitment activity, and technology in use.
2.3.2 Such records are derived from publicly accessible corporate websites, publicly accessible professional networks, public registers, and licensed business-to-business data vendors, the identity of which is disclosed in the Sub-processor Register.
2.3.3 For the avoidance of doubt, the Company does not knowingly compile personal data concerning natural persons acting in a private capacity; does not process special categories of personal data within the meaning of Article 9 GDPR; and does not process sensitive personal information within the meaning of the California Consumer Privacy Act.
2.4 Recordings of telephone communications
Where telephone communications are recorded, recording commences only following an audible announcement given at the outset of the call. The regime governing such recordings is set out at clause 8 hereof and, more fully, in the Cold Outreach & Communications Policy.
3. Purposes of Processing and Lawful Bases
3.1 The Company processes personal data for the purposes, and upon the lawful bases, set out in the table below.
| Purpose | Lawful basis (GDPR) |
|---|---|
| Responding to applications, enquiries, and requests | Article 6(1)(b), steps preparatory to contract |
| Delivery of the AI Concierge programme and of paid engagements | Article 6(1)(b), performance of contract |
| Despatch of publications and marketing correspondence to subscribers | Article 6(1)(a), consent |
| Deployment of cookies beyond those strictly necessary | Article 6(1)(a), consent |
| Compilation and use of business contact data for correspondence outside the Union and the United Kingdom | Article 6(1)(f), legitimate interests |
| Correspondence directed to recipients within Germany, the Union, or the United Kingdom | Article 6(1)(a), prior consent only; see clause 4 |
| Security of systems, prevention of fraud, and improvement of the Services | Article 6(1)(f), legitimate interests |
| Maintenance of statutory accounting and tax records | Article 6(1)(c), legal obligation |
| Publication of case studies and testimonials | Article 6(1)(a), consent, supported by written release |
3.2 Where the Company relies upon legitimate interests, it has conducted the balancing exercise required by Article 6(1)(f) and has concluded that its interest in identifying and corresponding with businesses to which its Services may be material is not overridden by the interests or fundamental rights and freedoms of the data subjects concerned, regard being had to the limited and exclusively professional character of the data processed and to the immediate and unconditional facility of objection afforded in every communication. A summary of that assessment shall be furnished upon written request.
4. Direct Marketing and Unsolicited Correspondence
4.1 Territories outside the Union and the United Kingdom. The Company despatches business-to-business electronic mail in reliance upon legitimate interests and in conformity with the Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003 (15 U.S.C. § 7701 et seq.). Every such communication identifies the Company, states its registered postal address, employs accurate transmission and header information and a non-deceptive subject line, and affords a functioning facility of objection honoured within the period prescribed by that Act.
4.2 Germany, the Union, and the United Kingdom. The Company acknowledges that, by operation of § 7(2) No. 2 of the Gesetz gegen den unlauteren Wettbewerb and of Directive 2002/58/EC, advertising by electronic mail requires the prior express consent of the recipient, and that this requirement admits of no exception in favour of business recipients. The Company accordingly does not despatch unsolicited commercial electronic mail into those territories. Correspondence into those territories is undertaken solely where the recipient has consented, has requested contact, or falls within the narrow exception prescribed by § 7(3) of the aforesaid Act in respect of existing customers.
4.3 Telephone. Outbound telephone activity within the United States is screened against the National Do Not Call Registry and against the applicable State registries. The Company does not solicit consumers. Telephone contact with numbers within Germany or the Union is undertaken solely upon prior consent.
4.4 Objection. A data subject may at any time and without giving reasons require that the Company cease all contact. It suffices to reply to any communication with the word "unsubscribe", to employ the facility provided in any electronic communication, to write to mgmt@blackswanventuresgroup.com (prefixing the subject line with the word OPT-OUT being helpful but not required), or to telephone +1 872-375-3144. The Company maintains a permanent suppression register. The minimum data necessary to give effect to such objection are retained indefinitely and exclusively for that purpose, the deletion of such data being incompatible with the objection itself.
5. Recipients and Processors
5.1 Personal data are disclosed to service providers who act upon the Company's documented instructions and pursuant to a written data processing agreement. The identity of such providers is maintained in the Sub-processor Register, which forms part of this Policy.
5.2 Personal data may further be disclosed: (a) to professional advisers under duties of confidence; (b) to public authorities where the Company is compelled by law to do so; and (c) to an acquirer or successor in connection with a merger, financing, or disposal of assets, subject to the protections afforded by this Policy.
5.3 The Company does not sell personal data for monetary consideration. Certain advertising and analytics technologies may nonetheless constitute a "sale" or a "sharing" for the purposes of the California Consumer Privacy Act and analogous State statutes. The facility of objection is set out in the Do Not Sell or Share My Personal Information notice.
6. Transfers to Third Countries
6.1 The Company is established in the United States and conducts its operations from the United States and from Taiwan. Personal data concerning data subjects within the European Economic Area, the United Kingdom, and Switzerland are transferred to and processed within those territories.
6.2 Where such transfers require it, the Company relies upon the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, upon the International Data Transfer Addendum issued by the United Kingdom Information Commissioner, and, where the recipient participates, upon the EU, US Data Privacy Framework. Transfer impact assessments are conducted in respect of onward transfers to jurisdictions in respect of which no adequacy decision subsists. Copies of the relevant safeguards shall be furnished upon written request.
7. Retention
7.1 Personal data are retained for no longer than is necessary for the purposes for which they were collected, subject to the periods set out below.
| Category | Period of retention |
|---|---|
| Business contact records employed in correspondence | 24 months from the last meaningful interaction, whereupon the record is deleted or re-verified |
| Applications not selected | 24 months from submission |
| Records of client engagements | The term of the engagement and 6 years thereafter |
| Accounting and tax records | 7 years, or such longer period as fiscal law may require |
| Subscriptions to publications | Until objection, and 12 months thereafter |
| Recordings and transcripts of calls | 24 months, save where forming part of a client deliverable |
| Suppression register | Indefinitely, and exclusively for the purpose of giving effect to objection |
| Server and security logs | 12 months |
7.2 Earlier erasure may be requested at any time in accordance with clause 9.
8. Recording and Monitoring of Telephone Communications
8.1 The Company records and transcribes sales and delivery calls for the purposes of producing intelligence deliverables, of quality assurance, and of maintaining an accurate record.
8.2 Recording commences only following an audible announcement given at the outset of the call.
8.3 Where any participant is situate within a jurisdiction requiring the consent of all parties, including, without limitation, California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, and Washington within the United States, and Germany by operation of § 201 of the Strafgesetzbuch, recording proceeds solely upon the affirmative consent of every participant, and ceases immediately upon request.
8.4 Refusal to be recorded shall not prejudice any person's dealings with the Company in any respect whatsoever.
8.5 A copy of any recording of a data subject's own call, or the erasure thereof, may be requested in accordance with clause 9.
9. Rights of the Data Subject
9.1 Rights under the GDPR and cognate laws. The data subject enjoys the rights: of access (Article 15); of rectification (Article 16); of erasure (Article 17); of restriction of processing (Article 18); of notification (Article 19); of portability (Article 20); of objection (Article 21), including an unqualified right to object to direct marketing; and not to be subject to a decision based solely upon automated processing (Article 22). Consent, where given, may be withdrawn at any time without prejudice to the lawfulness of processing effected prior to withdrawal.
9.2 Right of complaint. A data subject may lodge a complaint with a supervisory authority. In Germany, the competent authority is that of the federal state of residence, a register of which is maintained at bfdi.bund.de. In the United Kingdom, the competent authority is the Information Commissioner's Office.
9.3 Rights under the privacy statutes of the United States. Residents of States having enacted a comprehensive privacy statute, including California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, Utah, and Florida, in each case as applicable, enjoy the rights to know, to access, to delete, to correct, to obtain a portable copy, to opt out of sale, sharing, and targeted advertising, to limit the use of sensitive personal information, to appeal a refusal where the relevant statute so provides, and to be free from discrimination on account of the exercise of any such right.
9.4 Automated decision-making. The Company does not take decisions producing legal effects, or effects of similar significance, concerning any data subject by automated means alone. Where artificial intelligence systems assist in the scoring or prioritisation of business accounts, the determinative decision is in every case taken by a natural person.
9.5 Manner of exercise. Requests are to be addressed to mgmt@blackswanventuresgroup.com, or by post to the address at clause 1.1. The Company shall respond within one month of receipt in the case of a request under the GDPR, and within forty-five days in the case of a request under the privacy statutes of the United States, in each case extensible once where the law so permits and upon notice being given. Identity shall be verified by means proportionate to the sensitivity of the request. An authorised agent may submit a request upon production of written authority.
9.6 Universal opt-out signals. The Company honours the Global Privacy Control signal as a valid exercise of the right to opt out of sale and sharing.
10. Security
The Company applies technical and organisational measures appropriate to the risk, including transport-layer encryption, encryption at rest as afforded by its hosting and storage providers, role-based access control, mandatory multi-factor authentication upon all administrative accounts, least-privilege vendor access, and periodic review of access rights. Those measures are described at length in the Cybersecurity Disclosure. No system of information security is impregnable, and the Company gives no warranty of absolute security.
11. Minors
The Services are directed exclusively to businesses and to persons acting in a professional capacity. The Company does not knowingly collect personal data concerning any person under the age of eighteen years. Should the Company become aware that it has done so, it shall erase such data without delay.
12. Amendment
The Company may amend this Policy from time to time. Material amendment shall be denoted by revision of the version number and date of issue appearing at the head hereof and, where the amendment is of significance, by direct notice to subscribers and to clients then engaged. Continued use of the Services following the date of effect constitutes acceptance.
13. Correspondence
The Company operates a single point of correspondence for all matters arising under this Policy. Communications should carry the subject-line prefix [PRIVACY], or, where the object of the communication is objection to further contact, [OPT-OUT].
Correspondence
Black Swan Ventures Group LLC30 N Gould Street, Ste N
Sheridan, Wyoming 82801
United States of America
mgmt@blackswanventuresgroup.com
+1 872-375-3144
Related notices