Governance & compliance

What we build against.

The group operates across privacy, child-safety, gaming and adult-content regimes simultaneously. These are the frameworks the compliance gate tests every release against.

Corporate

The entity
  • EntityBlackhold Group Pty LtdAustralian proprietary company, limited by shares. ACN 702 584 790. Incorporated in New South Wales, 2026.
  • Registered officeSuite 17, 89–97 Jones Street, Ultimo NSW 2007All formal correspondence and service of documents.
  • TaxRegistered for GST and PAYGABN registration in progress; this page is updated when issued.
  • Division separationEach division operates independentlyBrands, compliance obligations and distribution are held at division level, not pooled at the parent.

Regulatory frameworks

Build-time obligations

Applicability varies by division and territory. Every release is assessed against the regimes that apply to it before distribution.

  • Privacy — AustraliaPrivacy Act 1988 and the Australian Privacy PrinciplesCollection limitation, notification, access and correction, and cross-border disclosure obligations.
  • Privacy — internationalGDPR, UK GDPR and the US state patchworkLawful basis, data subject rights, breach notification, and CCPA/CPRA-equivalent obligations where a division distributes into those markets.
  • ChildrenCOPPA, the Online Safety Act 2021 (Cth) and age-appropriate design codesApplied to any product reachable by minors, including the group's child-safety software.
  • GamingInteractive Gambling Act 2001 (Cth) and the terms of the operating licenceBlackSpire operates only where licensed, with hard geo-restriction elsewhere, including Australia.
  • Adult contentAge verification and creator identity requirementsVyce Studios operates age-verified access and verifies the identity and age of creators on its platforms.
  • Platform policyGoogle Play and Apple App Store developer policyData safety declarations, content rating, permissions justification, account deletion and payment rules.

Security

Group practice

The group runs a security product line, and what it proves there becomes the internal standard.

Products are assigned a security class at build time, and the class sets the floor for encryption, key handling, update control and data retention. Products that hold money or handle sensitive personal data sit in the highest class and carry additional controls.

Group infrastructure runs encrypted off-site backups on a fixed retention schedule, private networking between systems, and monitored access. Incident response, including breach notification obligations under the Privacy Act, is handled at group level.

A note on claims. This page describes the obligations the group builds against and the controls it applies. It is not a statement of certification or accreditation, and nothing on this page is legal advice. Formal compliance documentation is available to counterparties on request through Contact.