Skip to main content
BLINCKE

Privacy & Cookie Policy

Last updated 2 September 2026. This page explains what data Blincke collects, why, and what cookies this site uses.

Who we are

Blincke is the operations platform used to run 9 Millbank — staff, front of house, compliance, and the owner/tenant portal. This policy covers both the public marketing site and the platform itself.

Cookies this site uses

We keep this deliberately simple: this site sets only the cookies strictly necessary to make it work — keeping you signed in, protecting forms against cross-site request forgery, and remembering basic display preferences such as a collapsed sidebar. We don't run analytics, advertising, or third-party tracking cookies of any kind.

  • Session & login — keeps you signed in between pages, and protects account security.
  • CSRF protection — a security token confirming a form submission genuinely came from this site.
  • Display preferences — stored locally in your browser (not sent to our servers), such as whether the dashboard sidebar is collapsed, or that you've dismissed this notice.

Because these are all strictly necessary to the service, they aren't the kind of cookie that requires opt-in consent under UK PECR — but we still tell you about them, and we'll update this section if that ever changes.

What personal data we collect

For staff, owners, and tenants with an account: the details needed to run the building day to day — name, contact details, unit/role, and the records your role generates (shift and handover entries, maintenance and incident logs, invoices, visitor and parcel logs, and similar). For a visitor to this marketing site: only what you submit yourself through the Contact or Get started forms.

We collect only what a given workflow actually needs, and every account is invite-only and provisioned by your building's team — there's no public self-serve signup collecting data we don't need.

Why we process it

Staff data is processed under contract and legitimate interest in running the building. Resident data is processed under the tenancy or ownership relationship, or legitimate interest in estate operations and security. Where we send anything beyond operational necessity — a general announcement rather than "your parcel has arrived" — we treat that as needing its own, trackable basis rather than assuming it's covered.

How your data is protected

  • Every account is role-scoped server-side — staff, owners, and tenants each see only what their role and building are meant to see.
  • Manager-and-above accounts carry two-factor authentication as standard.
  • Every mutating action is attributed to a named, timestamped user in the audit trail — nothing anonymous.
  • Passwords are hashed, never stored or logged in plain text.

Retention

We keep personal data only as long as it's needed for the purpose it was collected for — operational logs for the period they remain operationally useful, financial and HR records for as long as statutory record-keeping requires, and the audit trail itself for longer, as the accountability record. Data is not kept indefinitely by default.

Your rights

Under UK GDPR, you can ask us what personal data we hold about you, ask us to correct it, or ask us to erase it where it's no longer needed. To make a request, or if you have any question about this policy, get in touch through our Contact page.

We use only the essential cookies needed to keep you signed in and the site working correctly — no tracking or advertising cookies. See our Privacy & Cookie Policy for details.