Skip to main content

Privacy Policy

Last updated: 2026-05-10

PrintingPay (operated by Black Asterisk LLC, “we,” “us”) provides a B2B operator portal for printing brokers and their authorized staff. This policy explains what personal data we collect through the PrintingPay service and how we handle it.

1. What we collect

  • Authentication data. Email address, hashed password, multi-factor secrets, session tokens, IP address, browser user-agent, and the timestamp of every login attempt. We retain login records for security investigation and compliance.
  • Operator profile. Display name, role assignment, per-tenant access scope, and permissions configured by the account administrator.
  • Audit logs. Every state-changing API call records actor, action, target object, request identifier, and timestamp. Retained for security and dispute investigation.
  • Order and customer data submitted by your tenant. PrintingPay processes order metadata (SKUs, quantities, ship-to addresses, payment receipts) on behalf of the broker tenant. The broker is the data controller for that information; we are the processor.
  • Billing data. Card payment data is collected and stored by our payment processors (Stripe, Square, PayPal). We retain only the last four digits, brand, and the processor’s opaque transaction identifier — never full card numbers, expiration dates, or CVVs.
  • Operational telemetry. Aggregated request rates, latency, and error counts. Not linked to an individual operator where avoidable.

2. Lawful basis (GDPR Article 6)

We process operator account data under contract performance (the operator agreement with their broker tenant) and legitimate interest (preventing fraud and abuse against the platform). We process tenant order data on the broker’s instructions under a data processing agreement in line with Article 28.

3. How long we keep data

  • Active operator profiles: for the life of the account.
  • Audit logs and login records: 24 months from the event, then purged.
  • Closed accounts: deleted within 90 days of account closure unless a longer period is required to satisfy a legal hold or open financial-record retention obligation.
  • Billing records: retained as required by tax law in the relevant jurisdiction (typically 7 years in the United States).

4. Who we share data with

PrintingPay does not sell personal data to anyone. We share limited operational data with the sub-processors listed at /sub-processors. Each sub-processor is contractually bound to confidentiality, security, and use-restriction terms equivalent to or stricter than this policy.

5. Your rights

Depending on your jurisdiction, you may have the right to:

  • Request a copy of the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request erasure of personal data that is no longer necessary for the purpose for which it was collected.
  • Object to or restrict processing.
  • Request portability of data you supplied directly.
  • Withdraw consent for any processing that relied on your consent.

To exercise any of these rights, email [email protected]. We respond within 30 days.

6. California residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete personal information we hold, and the right to opt out of the sale or sharing of personal information. PrintingPay does not sell or share personal information for cross-context behavioral advertising. To submit a verifiable consumer request, email [email protected] or use the link below.

Do Not Sell or Share My Personal Information

7. International data transfers

7.1 Where your data goes

PrintingPay is operated from the United States by Black Asterisk LLC. When you use the service from the European Economic Area (EEA), the United Kingdom (UK), or Switzerland, your personal data is transferred to and processed in the United States and, in limited cases, in other countries where our sub-processors operate. A current list of these sub-processors and their country of operation is published at /sub-processors.

7.2 Lawful basis for the transfer

Our lawful basis for transferring personal data outside the EEA, UK, or Switzerland is one of the following, applied on a transfer-by-transfer basis: (a) performance of a contract with you or with the broker organization you act for (GDPR Article 49(1)(b) / UK GDPR Article 49(1)(b)); (b) your explicit consent where requested (GDPR Article 49(1)(a)); (c) compliance with a legal obligation; or (d) where the transfer is covered by an Article 46 safeguard, the safeguard itself (Standard Contractual Clauses, the EU–US Data Privacy Framework, or the UK International Data Transfer Addendum) provides the lawful basis.

7.3 Transfer mechanism per recipient

Where personal data leaves the EEA, UK, or Switzerland, we rely on a recognized transfer mechanism under GDPR Article 46. The specific mechanism depends on the recipient's role:

  • Controller-to-processor transfers (PrintingPay or Black Asterisk LLC acting as controller, transferring data to a sub-processor such as our payment, shipping, hosting, or email vendor): the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor), are executed with the recipient. Where the recipient is also self-certified to the EU–US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), the Framework provides the primary safeguard and the SCCs operate as a fallback.
  • Processor-to-sub-processor transfers (where we act as processor for a broker organization and onward-transfer data to a sub-processor): the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Three (Processor to Processor), are executed with the recipient.
  • UK transfers: the UK International Data Transfer Addendum to the EU Commission SCCs (issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, in force 21 March 2022) is executed alongside the EU SCCs.
  • Swiss transfers: the EU SCCs are executed with the Swiss-specific amendments published by the Federal Data Protection and Information Commissioner (FDPIC) on 27 August 2021, applying Swiss FADP terminology and FDPIC supervisory authority.

7.4 Sub-processor list and changes

The current list of sub-processors that may receive personal data, the category of data processed, the country of processing, and the transfer mechanism in force for each is published at /sub-processors and is updated when a sub-processor is added, replaced, or removed. Broker tenants who have signed our Data Processing Agreement receive the period of advance notice specified in that DPA (default: 30 days) before a new sub-processor begins processing the tenant's personal data. Tenants may object to a new sub-processor through the procedure in their executed DPA. A copy of the executed transfer mechanism for any named sub-processor is available on request from [email protected].

7.5 Your rights as an EEA, UK, or Swiss resident

Where the General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR, or the Swiss Federal Act on Data Protection (FADP) applies to you, you have the right to: (a) access the personal data we hold about you (GDPR Article 15); (b) request rectification of inaccurate data (Article 16); (c) request erasure where the conditions of Article 17 are met; (d) request restriction of processing (Article 18); (e) data portability for data you provided to us by automated means (Article 20); (f) object to processing carried out on the basis of legitimate interests (Article 21); (g) withdraw consent at any time where processing is based on consent (Article 7(3)); and (h) lodge a complaint with your member state's supervisory authority (Article 77), with the UK Information Commissioner's Office at ico.org.uk, or with the Swiss FDPIC at edoeb.admin.ch.

To exercise any of these rights, email [email protected]. We respond within one month of receipt of a verifiable request, as required by GDPR Article 12(3), and may extend the response period by up to two further months where Article 12(3) permits, in which case we will notify you of the extension and the reasons within the initial one-month window.

7.6 EU and UK representative; data protection contact

Black Asterisk LLC is not currently required to designate a Data Protection Officer under GDPR Article 37. The responsible party for data protection inquiries from EEA, UK, and Swiss residents is:

Responsible party: Black Asterisk LLC, Legal & Compliance Department
Email: [email protected]
Postal address: [Black Asterisk LLC registered address — insert per Donna's state-of-formation record before publication]

Where Black Asterisk LLC is required under GDPR Article 27 to designate an EU representative, or under UK GDPR Article 27 to designate a UK representative, the name and contact details of that representative will be published in this section. As of the “Last updated” date above, Black Asterisk LLC has assessed its EEA and UK processing under the Article 27(2) exemptions and determined that the exemption applies. This assessment is reviewed whenever processing scope materially changes.

7.7 Supplementary measures (post-Schrems II)

In line with the European Data Protection Board's Recommendations 01/2020 on supplementary measures (version 2.0, adopted 18 June 2021), we apply the following supplementary measures to transfers to the United States: (a) encryption in transit using TLS 1.2 or higher; (b) encryption at rest for production databases and object storage; (c) per-tenant access controls with audit logging; (d) a documented process for responding to law-enforcement requests, including challenging requests that exceed what is “necessary and proportionate in a democratic society” under EU Charter Articles 7, 8, and 47.

Legal authority (citations)
  • GDPR Articles 12(3), 15–21, 27, 37, 46, 49, 77 — Regulation (EU) 2016/679
  • UK GDPR + Data Protection Act 2018 (UK retained version of GDPR post-Brexit)
  • Swiss FADP (revised, in force 1 September 2023)
  • Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on SCCs (Modules 1–4)
  • Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 (EU–US Data Privacy Framework adequacy)
  • UK IDTA (issued under DPA 2018 § 119A, in force 21 March 2022)
  • FDPIC Statement of 27 August 2021 on Swiss SCC adaptations
  • EDPB Recommendations 01/2020 on supplementary measures, v2.0 (18 June 2021)
  • CJEU, Schrems II (Case C-311/18, 16 July 2020) — Privacy Shield invalidation, basis for supplementary-measures regime

8. Security

We protect operator passwords with industry-standard hashing, require TLS 1.2 or higher for all browser connections, scope every API call against per-tenant access controls, and store credentials in a hardened secrets manager. Report suspected vulnerabilities to [email protected] per our security.txt.

9. Children

PrintingPay is a B2B operator portal not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has supplied personal data, contact us so we can delete it.

10. Changes

We may update this policy as the service evolves. Material changes will be communicated to operators by email at least 30 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

11. Contact

Questions about this policy or any data we hold should be sent to [email protected].

Privacy Policy — PrintingPay