This Policy explains what personal information Brightmesh handles, why, and the choices you have. It distinguishes the data we control from the policyholder data we process on behalf of our Customers.
Overview & Scope
This Privacy Policy explains how Brightmesh Studio (“Brightmesh”, “we”, “us”) handles personal information when you visit our website, create an account, or use the Brightmesh platform (the “Service”).
It applies to operators, agents, and administrators who use the Platform, and to visitors to our website. It does not change any separate agreement between Brightmesh and a Customer organisation.
Our Role: Controller & Processor
Brightmesh acts in two capacities, depending on the data:
- As a processor: For policyholder and claims records that a Customer uploads to its Tenant, the Customer is the controller and decides how that data is used. Brightmesh processes it on the Customer’s behalf and under its instructions.
- As a controller: For account details, billing information, website usage, and direct communications with us, Brightmesh determines the purposes of processing and is the controller.
Information We Collect
Information you provide
- Account and profile details, such as name, work email, company, and role.
- Billing and Subscription information.
- Content you submit when contacting us or requesting a demo.
Information collected automatically
- Usage and log data, such as pages viewed, actions taken, and timestamps.
- Device and connection data, such as browser type, operating system, and IP address.
- Cookies and similar technologies, as described below.
Customer Data
When a Customer uses the Platform, it may submit personal information about its policyholders and staff. Brightmesh processes this Customer Data only to provide the Service, as described in “Our Role” above.
How We Use Information
Where Brightmesh is the controller, it uses personal information to:
- Provide, maintain, and secure the Service and the website.
- Authenticate users and manage accounts and Subscriptions.
- Respond to enquiries and provide support.
- Send service messages and, where permitted, relevant product updates.
- Detect, prevent, and investigate fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
Brightmesh does not sell personal information, and does not use Customer Data to build advertising profiles.
Legal Bases for Processing
Where applicable law requires a legal basis, Brightmesh relies on one or more of the following:
- Contract: to provide the Service the Customer has requested.
- Legitimate interests: to secure, operate, and improve the Service, balanced against your rights.
- Consent: for optional communications and certain cookies, which you may withdraw at any time.
- Legal obligation: to comply with laws that apply to us.
Data Retention
Brightmesh retains personal information for as long as needed to provide the Service and for legitimate business or legal purposes. Account data is kept for the life of the account.
When a Customer’s Subscription ends, Customer Data is available for export for 30 days, after which it is deleted or anonymised, unless retention is required by law.
Security
Brightmesh maintains technical and organisational measures appropriate to the risk, including encryption in transit, tenant isolation, role-based access controls, audit logging, and monitoring.
No system is completely secure. The Customer is responsible for safeguarding its credentials and for configuring access within its Tenant appropriately.
International Transfers
Brightmesh may process and store information in locations outside the country where it was collected. Where personal information is transferred across borders, Brightmesh applies appropriate safeguards consistent with applicable data-protection law.
Your Rights
Subject to applicable law, you may have the right to access, correct, delete, or restrict the processing of your personal information, to object to certain processing, and to request a copy in a portable format.
To exercise these rights where Brightmesh is the controller, contact privacy@brightmesh.studio. Where Brightmesh acts as a processor on a Customer’s behalf, requests will be referred to the relevant Customer.
Children’s Privacy
The Service is intended for businesses and their staff. It is not directed to children, and Brightmesh does not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Policy
Brightmesh may update this Policy from time to time. The effective date at the top reflects the latest version. For material changes, Brightmesh will provide reasonable notice through the website or an in-product notice.
Contact & Complaints
For questions or requests about this Policy or your personal information, contact privacy@brightmesh.studio. If you believe your rights have not been respected, you may also lodge a complaint with the relevant data-protection authority.
Need clarification?
For any questions about this Policy, contact privacy@brightmesh.studio. The team responds within two business days.