1. Who we are and our role
Braigest ("Braigest", "we", "us") provides a platform that lets organisations build and run customer onboarding and compliance workflows — forms, document collection, AI document intelligence, identity verification (KYC), anti-money-laundering screening (AML), business verification (KYB), e-signatures, risk scoring and delivery of results to their systems.
Controller vs. processor
Our role under data-protection law depends on whose data it is:
- When we handle personal data about our own account holders, website visitors and prospects, we act as a data controller.
- When our customers use Braigest to onboard, verify or screen their own applicants and end users, our customer is the controller and Braigest acts as a data processor, handling that data on the customer's documented instructions.
2. Personal data we collect
Account & website data (we are the controller)
- Account details: name, work email, organisation, role, and authentication data (including Google or Apple sign-in identifiers if you use single sign-on).
- Billing details: plan, invoices and payment status (card data is handled by our payment providers, not stored by us).
- Usage and device data: log data, IP address, browser type, pages viewed and actions taken, collected to run and secure the service.
- Communications: messages you send us and meeting/booking details.
Onboarding & compliance data (usually processed on behalf of a customer)
When a customer runs a workflow, the platform may process personal data about their applicants and end users, including:
- Identity data: name, date of birth, nationality, address, contact details and government identity-document images.
- Biometric and verification data: facial images / liveness data used by identity providers to confirm a document belongs to the person (special-category data — see section 4).
- Screening data: names and identifiers checked against sanctions, politically-exposed-person (PEP) and watch-lists, and the resulting matches.
- Business (KYB) data: company registry records and details of directors and beneficial owners.
- Documents and form responses: files uploaded and information entered into a workflow, plus e-signatures and the signed, sealed documents produced.
- Audit data: a record of the steps taken, decisions made and who reviewed them.
3. How and why we use personal data
Where we are the controller, we rely on one or more of these legal bases under the UK/EU GDPR:
- Contract — to create and manage your account and provide the service you signed up for.
- Legitimate interests — to secure, operate, improve and support the platform, and to prevent fraud and abuse, balanced against your rights.
- Legal obligation — to meet our own tax, accounting and regulatory duties.
- Consent — for optional communications; you can withdraw consent at any time.
Where we act as a processor for onboarding and compliance data, we only use that data to provide the service on the customer's instructions — for example running a verification, performing a screening check, generating a signed document or delivering results — and not for our own purposes.
We do not sell personal data, and we do not use applicants' onboarding or verification data to train our own general-purpose AI models.
4. Biometric & special-category data
Identity verification can involve biometric data (such as a facial image compared against an ID document) and other special-category data. On the platform this is processed by specialist identity providers on behalf of our customer, to confirm identity and help the customer meet its own legal and regulatory obligations (for example, anti-money-laundering rules).
The customer is responsible for having a valid lawful basis and, where required, explicit consent or a substantial-public-interest / legal-obligation basis for this processing. Braigest processes it only as instructed and applies additional safeguards described in section 8.
6. International data transfers
We aim to host and process personal data in the EU/EEA. Some sub-processors may process data outside your country. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards — such as an adequacy decision or the European Commission's Standard Contractual Clauses (and the UK Addendum) — and take additional measures where needed.
7. How long we keep personal data
Where we are the controller, we keep account and billing data for as long as your account is active and afterwards only as long as needed for legitimate business, legal, tax and security purposes.
Where we are a processor, retention of onboarding and compliance data is set by our customer's configuration and instructions and by the record-keeping obligations that apply to them (anti-money-laundering retention periods, for example). When a customer's contract ends, we delete or return the data in line with our agreement, except where law requires us to keep it.
8. How we protect personal data
Security is built into the platform's architecture. Measures include:
- Tenant isolation — each customer's data lives in a separate, logically-isolated database schema.
- Encryption of data in transit (TLS) and encryption of sensitive material at rest, including cryptographic signing keys.
- Access controls, authentication (including single sign-on) and least-privilege internal access.
- Audit logging of compliance and workflow actions so activity can be reviewed.
- A coding standard that prohibits logging secrets or personal data and forbids hard-coded credentials.
No system can be guaranteed perfectly secure, but we work to protect personal data using measures appropriate to its sensitivity.
9. Your privacy rights
Subject to applicable law, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. You also have the right to complain to a data-protection authority.
Where we are the controller, contact us at grig@braigest.app to exercise these rights. Where your data relates to an onboarding or verification flow you completed, the organisation that ran the flow is the controller — please contact them, and we will assist them as their processor.
11. Children
The platform is a business tool and is not directed to children. We do not knowingly collect personal data from children except where an onboarding flow operated by a customer lawfully requires it (for example, verifying a minor with appropriate consent), in which case the customer is the controller.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version here and change the "last updated" date; material changes will be communicated as appropriate.
13. How to contact us
For any privacy question or request, contact Braigest at grig@braigest.app. Registered entity: [Braigest legal entity name], [Registered company address].
This page describes Braigest’s practices for the braigest.io website and the braigest.app platform.