Account data (controller).
When an advisor or firm administrator creates an account, we collect: full name, work email, hashed password, optional two-factor secret (encrypted at rest), firm name, and the IP address of authentication events. We collect this to deliver the service and protect the account.
Billing data (controller).
For paid subscriptions, we collect: billing contact name, billing email, company name, subscription tier, and payment status. Card details are handled by Stripe and never seen or stored by blankit. We also collect AI usage records for billing: each AI-powered action records its computational usage (tokens, cost, and credits) attributed to the advisor who performed it. These records power the firm's own usage dashboard and metered billing; only the firm's aggregate usage quantity is sent to Stripe — never per-advisor detail, and never document or message content. Raw usage records are retained for 24 months (the billing-dispute window); invoices and audit records remain the durable trail after that.
Client data (processor).
Subscribing firms upload data about their plan-sponsor clients (employer names and contact details), coverage booklets, claims-experience documents, carrier quotes, and renewal analyses. We process this strictly on the firm's documented instructions, under our Data Processing Agreement. The firm — not blankit — is the controller of this data.
Plan-member data (processor).
When a firm enables the plan-member assistant, plan members may submit messages and (in optional Critical Illness enrolment flows) contact details. The firm is the controller. The assistant can be used without identifying yourself, we ask for no personal information to start a conversation, and message content is not retained once an answer has been produced. Where a plan member does choose to identify themselves — asking for an advisor to follow up, or starting a Critical Illness enrolment — we record their explicit consent at that point, along with the version of the notice they were shown, and it can be withdrawn at any time.
A firm may also offer the same assistant inside a plan sponsor's own Slack workspace. Nothing we retain changes there — still no message content — but the surface itself is not ours: the workspace belongs to the plan member's employer, and what an employer can see or export from it is governed by Slack's own administrator controls and by that employer's Slack plan, not by us. Plan members are told this before their first question, and the web assistant remains available to anyone who would rather ask outside their employer's workspace. See the assistant privacy notice.
Operational and security telemetry.
We log application events (audit log entries, error traces, access patterns) for security and incident response. These may include IP address, user ID, and the action performed.