← brainiall.com

Privacy Policy (EU / GDPR)

Last updated: 19 April 2026 · Applicable to: European Economic Area residents under the General Data Protection Regulation (EU 2016/679).

1. Data Controller

Brainiall Inc., a Brazilian company, acts as data controller for the information you provide through this platform. Contact: privacy@brainiall.com.

We are not established in the EU but offer services to EU residents, so GDPR art. 3(2) applies to us.

2. What we collect

3. Legal basis (GDPR art. 6)

4. Your rights (GDPR art. 15-22)

You can, at any time:

To exercise any right: privacy@brainiall.com. We respond within 30 days.

4.5 UK residents — UK GDPR

For data subjects in the United Kingdom, the UK General Data Protection Regulation (UK GDPR) applies alongside the Data Protection Act 2018. Your rights mirror those listed above (access, rectification, erasure, restriction, portability, objection). The UK supervisory authority is the Information Commissioner's Office (ICO). To lodge a complaint, visit ico.org.uk/make-a-complaint or write to Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. UK-EU data transfers rely on the UK Addendum to the EU Standard Contractual Clauses (UK IDTA).

4.6 Germany residents — DSGVO (EU GDPR as enacted in Germany)

For data subjects in Germany, the Datenschutz-Grundverordnung (DSGVO) applies as the direct implementation of EU Regulation 2016/679, alongside the Bundesdatenschutzgesetz (BDSG) for national-specific provisions. Your rights under Art. 15-21 DSGVO mirror those listed above (Auskunft, Berichtigung, Löschung, Einschränkung, Datenübertragbarkeit, Widerspruch). Legal basis for processing is primarily Art. 6 Abs. 1 lit. b DSGVO (contract performance) and Art. 6 Abs. 1 lit. f DSGVO (legitimate interest). A Data Processing Agreement (Auftragsverarbeitungsvertrag, AVV) per Art. 28 DSGVO is available on request at privacy@brainiall.com or via /de/dpa. German supervisory authorities vary by state (Länder); complaints can be lodged with the authority in your federal state (list at bfdi.bund.de) or with the Federal Commissioner for Data Protection (BfDI). For company information per §5 TMG and §55 RStV, see our Impressum.

4.7 Rest of world — Other jurisdictions

We apply the following frameworks for users outside EU/UK/Germany:

Users in other jurisdictions should refer to their applicable local law. Core data subject rights (access, correction, deletion, portability, objection) are honored globally via privacy@brainiall.com, regardless of jurisdiction.

4.8 Other EU member states — National GDPR implementations

The EU GDPR (Regulation 2016/679) applies directly to all member states but is complemented by national laws. Below we list the applicable national framework + national supervisory authority (DPA) per market where we have users. Data subject rights (access, rectification, erasure, restriction, portability, objection) apply uniformly via privacy@brainiall.com regardless of member state.

5. Data retention

6. International transfers

Data is processed in Brazil. EU-Brazil transfers use Standard Contractual Clauses (GDPR art. 46) and Brazil's LGPD is considered equivalent protection by several EU national DPAs. Infrastructure subprocessors: leading cloud hosting providers (USA + EU), Stripe (payments, global), AI infrastructure partners (each with their own SCCs; specific disclosures under NDA via /subprocessors + compliance@brainiall.com).

7. Cookies

We use essential cookies (session, CSRF) — no tracking cookies without consent. Cookie banner appears on first visit from EU IPs.

8. AI-specific notes

Prompts and generated outputs are not used to train upstream models (contractually enforced with our providers). Internal improvement uses only aggregated, anonymized signals.

9. Children

Service is not intended for users under 16 in the EU (GDPR art. 8). We do not knowingly collect data from minors.

10. Changes

Material changes trigger in-app notice + email 30 days before effective date.

For Brazilian users: see LGPD notice. For US users: see CCPA notice.