Applications close 15 August, or sooner when all 30 places are filled.

Data protection and privacy

Privacy Policy for Black Founders Studio CIC

This Privacy Policy explains how Black Founders Studio CIC collects, uses, shares, stores and protects your personal data when you interact with our website, programmes and services.

UK data protection

How we handle your personal information.

We collect personal information only where it is needed to operate our services, process programme applications, communicate with you, improve our website and meet our legal obligations.

1

Who We Are

Black Founders Studio CIC, referred to in this Privacy Policy as “we”, “our” or “us”, is a UK-based Community Interest Company.

Our organisation is dedicated to supporting early-stage Black entrepreneurs.

2

Data We Collect

We collect different types of personal data to provide our services, operate our programmes and communicate with you.

Identity Data

Your name, title and date of birth.

Contact Data

Your email address, telephone number and postal address.

Business Data

Your company name, business stage, industry, business ideas, product details and relevant financial information.

Technical Data

Your IP address, browser information, operating system, device information, location and time zone settings.

Usage Data

Information about how you use our website, products, programmes and services.

Marketing Data

Your preferences for receiving marketing communications and how you prefer us to contact you.

Special Category Data

We do not explicitly request ethnicity through our general contact forms. However, our mission involves supporting Black founders, so information indicating racial or ethnic origin may be inferred or voluntarily provided during programme applications or other interactions.

Where special category data is processed, we will process it with explicit consent and in accordance with applicable data protection law, including Article 9 of the UK GDPR.

3

How We Collect Your Data

We collect personal data through several methods.

Direct Interactions

You may provide Identity, Contact and Business Data by completing forms or corresponding with us by email, telephone, post or other communication methods.

This includes personal data you provide when you:

  • Apply for an incubator, scale-up programme or another service.
  • Subscribe to our newsletter.
  • Ask to receive marketing communications.
  • Enter a competition, promotion or survey.
  • Give us feedback or contact us.

Automated Technologies

As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and usage patterns.

We may collect this information through cookies, server logs and similar technologies.

Third Parties and Public Sources

We may receive personal data about you from third parties or publicly available sources where permitted by law.

4

How We Use Your Data

We will only use your personal data where the law allows us to do so.

We most commonly use your personal data:

  • Where we need to perform a contract we are about to enter into or have entered into with you.
  • Where processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests.
  • Where we need to comply with a legal or regulatory obligation.
  • Where you have given consent or explicit consent.

Purposes for Using Your Data

  • Processing applications for our programmes and services.
  • Administering your programme enrolment.
  • Sending newsletters and marketing communications where you have consented.
  • Responding to enquiries, feedback and support requests.
  • Improving our website, programmes, products and services.
  • Complying with legal, accounting and regulatory requirements.
5

Disclosure of Your Data

We may share your personal data with the following categories of recipient where it is necessary and lawful to do so.

  • Internal third parties: Other companies within our group acting as processors or joint controllers.
  • External service providers: Organisations providing services such as website hosting, information technology, system administration, payment processing and communications.
  • Professional advisers: Lawyers, bankers, auditors, insurers and other professional advisers.
  • Public authorities: Regulators, government bodies and other authorities where disclosure is required by law.
  • Business transactions: Third parties to whom we may sell, transfer or merge parts of our business or assets.

We require third parties to respect the security of your personal data and process it in accordance with the law and our instructions. We do not permit service providers to use your personal data for their own purposes.

6

International Transfers

We do not currently transfer your personal data outside the European Economic Area.

If we transfer personal data internationally in the future, we will ensure that an appropriate degree of protection is provided by using suitable legal safeguards.

These safeguards may include:

  • Transferring personal data to countries that have been recognised as providing an adequate level of data protection.
  • Using approved contractual protections with service providers.
  • Applying other legally recognised safeguards required under applicable data protection law.
7

Data Security

We have put appropriate security measures in place to help prevent your personal data from being accidentally lost, used, accessed, altered or disclosed without authorisation.

Access to your personal data is limited to employees, agents, contractors and other third parties who have a genuine business need to access it.

Those individuals and organisations may only process your personal data on our instructions and are subject to confidentiality obligations.

We have procedures for dealing with suspected personal data breaches. Where legally required, we will notify affected individuals and the relevant regulator.

8

Data Retention

We will retain your personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected.

This includes retaining information where necessary to meet legal, accounting, regulatory or reporting requirements.

When deciding the appropriate retention period, we consider:

  • The amount, nature and sensitivity of the data.
  • The potential risk of harm from unauthorised use or disclosure.
  • The purposes for which the data is processed.
  • Whether those purposes can be achieved through other means.
  • Applicable legal, accounting and regulatory requirements.
9

Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data.

Access Request a copy of the personal data we hold about you.
Correction Ask us to correct inaccurate or incomplete personal data.
Erasure Ask us to delete your personal data in qualifying circumstances.
Object Object to certain types of personal data processing.
Restriction Ask us to restrict how your personal data is processed.
Data transfer Request the transfer of your personal data where applicable.
Withdraw consent Withdraw consent at any time where consent is the basis for processing.

To exercise any of these rights, email info@blackfoundersstudio.com .

10

Changes to This Privacy Policy

We keep this Privacy Policy under regular review and may update it from time to time.

Any changes will be published on this page.

This version was last updated on 15 July 2026.

11

Contact Us

If you have any questions about this Privacy Policy, our use of your personal data or our data protection practices, please contact us.

Privacy question or data request?

Contact Black Founders Studio.

Contact us to ask a question, exercise a legal right or raise a concern about how your personal data is being handled.