top of page

Privacy Policy

PRIVACY POLICY

 

1. Who we are

 

Brind OÜ (“Brind”, the “Company”, “we”) has established this privacy policy to ensure the lawfulness of its data processing, to protect the rights of data subjects, and to provide them with the necessary information.

– Data Controller: Brind OÜ, registry code 16849393

– Registered office: Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, 15551, Harju maakond, Estonia

– E-mail: info@brind.io

– Phone: +36 20 549 0816

– Representative: Dr. Dániel Váczi, CEO

– Websites: www.brind.io and www.brind.hu (together, the “Website”)

 

Brind OÜ is a wholly-owned subsidiary of Brind B.V., a private limited liability company incorporated in the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 99920069, the parent company of the Brind group. Brind OÜ operates the platform and is the controller for the processing described in this policy; limited business contact data may be shared within the group (see Section 7).

 

We process personal data in compliance with applicable legislation, in particular Regulation (EU) 2016/679 (the “GDPR”). We treat personal data confidentially and take the information-technology, technical and organisational measures necessary to ensure secure data management. In the event of any discrepancy between language versions of this policy, the English version prevails.

 

2. What this policy covers — our two roles

 

Brind acts in two different capacities, and your rights are exercised differently in each:

– As a controller — for the personal data described in Sections 3 and 4 (website visitors, enquiries, prospects, account registration, billing and support). For this processing, this policy is the primary source of information and you can exercise your rights directly against Brind (Section 10).

– As a processor — for personal data contained in the content our customers and their auditors upload to the Brind platform (“User Data”, e.g. compliance documents and audit evidence). The customer (or the auditor’s client) is the controller of that data; Brind processes it only on the customer’s instructions under our Terms & Conditions and, where concluded, a data processing agreement (“DPA”). If your personal data appears in a customer’s User Data, please address requests to that customer; we will assist them in responding, as required by Article 28 GDPR.

 

3. Communication via the Website, e-mail and phone

 

We primarily maintain contact with partners and clients electronically (and by telephone where justified). You may contact us via e-mail, through the forms on the Website, or via https://www.linkedin.com/company/brind. During any electronic communication with you, we process your personal data as described in this section.

 

Purposes

To perform an already concluded contract; to take pre-contractual steps; to respond to enquiries and expressions of interest; and to operate the Website and manage relationships and online administration through it.

​

Categories of data

First and last name; e-mail address; phone number; LinkedIn profile; employer name and address; employer tax number; job position; educational institution and name of training/course; uploaded CV; country of residence; IP address.

​

Legal bases

Where a contract is concluded or being prepared: Article 6(1)(b) GDPR (performance of a contract or pre-contractual steps). For enquiries: Article 6(1)(a) GDPR (consent). For maintaining business relationships with representatives of our corporate partners: Article 6(1)(f) GDPR (legitimate interest in business communication).

​

Other information

Special categories of personal data: none. Source: directly from you. Retention: for the duration of the contract or the existence of the consent; if a contract is concluded, until the expiry of the applicable limitation period; if no contract is concluded, messages are deleted after the communication is closed. Automated decision-making or profiling: none.

 

4. Account registration, billing and support

 

Account and trial registration

When you register an account or start a trial, we process the account holder’s and authorised users’ name, business e-mail address, role/permissions, organisation, log-in and usage log data. Legal basis: Article 6(1)(b) GDPR (contract) and, for personnel of corporate customers, Article 6(1)(f) GDPR (legitimate interest in administering the customer relationship). Retention: for the duration of the subscription and until expiry of the applicable limitation period; trial data is permanently deleted at the end of the trial if no subscription is concluded (see the Terms & Conditions).

 

Billing

For invoicing we process the billing contact’s name, e-mail and the invoicing details of the customer. Legal basis: Article 6(1)(c) GDPR (statutory accounting obligations). Retention: seven (7) years in accordance with applicable accounting legislation.

​

Support

When you contact support (support@brind.io or in-platform tickets), we process your contact details and the content of your request. Legal basis: Article 6(1)(b) GDPR. Retention: duration of the customer relationship plus the applicable limitation period.

 

5. The Brind platform — processing on behalf of our customers

 

Content uploaded to the platform (including compliance documentation and audit evidence relating to NIS2, ISO/IEC 27001, CRA and other frameworks) may contain personal data. For this User Data, Brind acts as a processor for the customer. Key practices:

– All User Data is hosted on servers located entirely within the European Union; backups are likewise stored in the EU on independent infrastructure. We do not transfer User Data outside the EU unless specifically agreed in writing and subject to appropriate safeguards.

– Customer environments are logically separated; data is encrypted in transit and at rest; access is role-based, logged and monitored; the platform undergoes regular vulnerability scanning and penetration testing.

– Backups are retained for a minimum of 30 days for disaster-recovery purposes. After termination of a subscription, User Data is retained for a 30-day grace period to allow export, and is then securely and permanently deleted from systems and backups.

– Auditor Module: documents made available to an auditor are accessible for review only; unless downloaded by the auditor, they are automatically deleted when the audit is closed. Data of an auditor’s client using the free audit period is permanently deleted within 30 days after the end of that period unless the client subscribes.

 

6. Brind AI

 

The platform may include optional AI functionality (“Brind AI”) that analyses uploaded evidence, groups related materials and maps them to compliance requirements, and provides preliminary assessments for professional review.

– Brind AI runs on dedicated infrastructure located within the European Union; content submitted to it is processed in isolated, encrypted environments.

– We do not use one customer’s content to train or improve models made available to any other customer; there is no cross-customer data sharing or learning.

– Personal data contained in content submitted to Brind AI is processed by Brind as a processor on behalf of the customer (Section 5 applies).

– Brind AI does not make automated decisions producing legal or similarly significant effects on individuals (Article 22 GDPR): its outputs are decision support, reviewed and validated by qualified people at the customer or auditor. Users are informed within the platform when they interact with AI, and AI-generated content is identified as such.

 

7. Recipients and processors

 

We use the following processors and service providers. All platform-related processing takes place within the EU/EEA.

 

Website, marketing and administration

– Wix.com Ltd. — website hosting, contact, e-mail and chat functions (https://www.wix.com/about/privacy)

– Google Analytics — website traffic measurement and analytics, used subject to your cookie consent (https://support.google.com/analytics/answer/3379636)

– Pipedrive OÜ — contact and customer-relationship management (https://www.pipedrive.com/en/privacy)

​

Platform subprocessors

– Hetzner Online GmbH (Germany) — production hosting of the platform

– Amazon Web Services EMEA SARL (EU regions) — encrypted backup infrastructure

– Rackhost Zrt. (Hungary) — dedicated infrastructure for Brind AI

– 7Hills IT Kft. (Hungary, company registration no. 13-09-173849) — software development, platform operation and infrastructure management under a written development and services agreement containing data-processing terms

​

Group

– Brind B.V. (the Netherlands, KvK 99920069) — parent company of the Brind group; group administration; limited business contact data only.

An up-to-date list of subprocessors for the platform is available on request at info@brind.io. We will inform customers of intended changes to platform subprocessors in accordance with the applicable DPA.

 

8. Transfers and automated decision-making

 

We do not transfer your personal data to third countries or international organisations. No automated decision-making producing legal effects, and no profiling, takes place in the processing described in this policy (see Section 6 regarding Brind AI).

 

9. Cookies

 

The Website uses cookies and similar technologies. Strictly necessary cookies are used on the basis of our legitimate interest in operating the Website; analytics cookies (Google Analytics) are used only with your consent, which you can give and withdraw via the cookie banner. [Align this section with the actual cookie banner configuration and cookie list before publication.]

 

10. Your rights

 

Right to information — you have the right to receive information about data processing, which we fulfil by providing this notice.

​

Right to withdraw consent — where the legal basis is consent (Article 6(1)(a) GDPR), you may withdraw it at any time. Withdrawal only affects data for which there is no other legal basis, and does not affect the lawfulness of processing carried out before the withdrawal.

​

Right of access — upon request, we will confirm whether your data is being processed and provide access to the purposes and categories of data, the recipients, the planned retention period, information on your rights (rectification, erasure, restriction, objection), the right to lodge a complaint with a supervisory authority, the source of the data (if not collected from you), and the existence of any automated decision-making or profiling.

​

Right to rectification — you may request the correction of inaccurate data or the completion of incomplete data without undue delay. Please report any changes in your data to us as soon as possible.

​

Right to erasure (“right to be forgotten”) — you may request erasure if the data is no longer necessary; consent is withdrawn and there is no other legal basis; you object to processing and there are no overriding legitimate grounds; the processing is unlawful; erasure is required by EU or Member State law; or the data was collected in relation to information society services. Erasure will not be performed where processing is necessary for exercising freedom of expression, legal compliance, public interest in health or archiving, or for legal claims.

​

Right to restriction of processing — you may request restriction if you contest the accuracy of the data; the processing is unlawful but you oppose erasure; we no longer need the data but you need it for legal claims; or you have objected to processing (pending verification of legitimate grounds).

​

Right to object — where the legal basis is legitimate interest, you may object to processing on grounds relating to your particular situation. We will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms.

​

Right to data portability — you have the right to receive the personal data concerning you in a structured, commonly used, machine-readable format and to request its transfer directly to another controller.

 

11. Exercising your rights and redress

 

You may exercise these rights via e-mail at info@brind.io or via the telephone number above. We will begin investigating your request without undue delay and inform you of the actions taken within 30 days. If we refuse a request, we will provide the reasons and information on your rights to redress within the same 30-day period.

 

Supervisory authority: you may lodge a complaint with the supervisory authority of the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. The supervisory authority for Brind OÜ is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, www.aki.ee).

 

Court proceedings: you may bring a legal action against Brind if you believe your personal data has been processed in violation of the GDPR. You may bring the action before the courts of Estonia or before the courts of the Member State of your habitual residence.

 

12. Changes to this policy

 

We may update this policy from time to time. Material changes will be announced on the Website or, for platform customers, by e-mail or in-platform notice. The date of the current version is indicated at the top of this policy.

bottom of page