Work in progress · This site is still under construction
Legal · Privacy

Privacy Policy

How Brightmesh collects, uses, and protects personal information across the platform and website.

Effective
01 May 2026
Version
1.4
Jurisdiction
South Africa
Reading time
~7 min

This Policy explains what personal information Brightmesh handles, why, and the choices you have. It distinguishes the data we control from the policyholder data we process on behalf of our Customers.

01

Overview & Scope

This Privacy Policy explains how Brightmesh Studio (“Brightmesh”, “we”, “us”) handles personal information when you visit our website, create an account, or use the Brightmesh platform (the “Service”).

It applies to operators, agents, and administrators who use the Platform, and to visitors to our website. It does not change any separate agreement between Brightmesh and a Customer organisation.

02

Our Role: Controller & Processor

Brightmesh acts in two capacities, depending on the data:

  • As a processor: For policyholder and claims records that a Customer uploads to its Tenant, the Customer is the controller and decides how that data is used. Brightmesh processes it on the Customer’s behalf and under its instructions.
  • As a controller: For account details, billing information, website usage, and direct communications with us, Brightmesh determines the purposes of processing and is the controller.
Policyholder data
Where Brightmesh acts as a processor, the relevant Customer’s own privacy notice governs how policyholder data is used. Direct requests about that data to the Customer.
03

Information We Collect

Information you provide

  • Account and profile details, such as name, work email, company, and role.
  • Billing and Subscription information.
  • Content you submit when contacting us or requesting a demo.

Information collected automatically

  • Usage and log data, such as pages viewed, actions taken, and timestamps.
  • Device and connection data, such as browser type, operating system, and IP address.
  • Cookies and similar technologies, as described below.

Customer Data

When a Customer uses the Platform, it may submit personal information about its policyholders and staff. Brightmesh processes this Customer Data only to provide the Service, as described in “Our Role” above.

04

How We Use Information

Where Brightmesh is the controller, it uses personal information to:

  • Provide, maintain, and secure the Service and the website.
  • Authenticate users and manage accounts and Subscriptions.
  • Respond to enquiries and provide support.
  • Send service messages and, where permitted, relevant product updates.
  • Detect, prevent, and investigate fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our terms.

Brightmesh does not sell personal information, and does not use Customer Data to build advertising profiles.

06

Sharing & Sub-Processors

Brightmesh shares personal information only as needed to run the Service:

  • Sub-processors: vetted providers for hosting, infrastructure, and analytics, bound by data-protection terms.
  • Payment providers: such as PayFast, to process transactions the Customer initiates.
  • Professional advisers and authorities: where required by law or to protect our rights.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this Policy.

A current list of sub-processors is available on request at privacy@brightmesh.studio.

07

Data Retention

Brightmesh retains personal information for as long as needed to provide the Service and for legitimate business or legal purposes. Account data is kept for the life of the account.

When a Customer’s Subscription ends, Customer Data is available for export for 30 days, after which it is deleted or anonymised, unless retention is required by law.

08

Security

Brightmesh maintains technical and organisational measures appropriate to the risk, including encryption in transit, tenant isolation, role-based access controls, audit logging, and monitoring.

No system is completely secure. The Customer is responsible for safeguarding its credentials and for configuring access within its Tenant appropriately.

09

International Transfers

Brightmesh may process and store information in locations outside the country where it was collected. Where personal information is transferred across borders, Brightmesh applies appropriate safeguards consistent with applicable data-protection law.

10

Your Rights

Subject to applicable law, you may have the right to access, correct, delete, or restrict the processing of your personal information, to object to certain processing, and to request a copy in a portable format.

To exercise these rights where Brightmesh is the controller, contact privacy@brightmesh.studio. Where Brightmesh acts as a processor on a Customer’s behalf, requests will be referred to the relevant Customer.

11

Cookies & Tracking

The website and Platform use cookies and similar technologies to keep you signed in, remember preferences, and understand usage.

  • Essential: required for authentication and core functionality.
  • Analytics: help us understand how the Service is used, in aggregate.

Brightmesh does not use third-party advertising cookies. You can control non-essential cookies through your browser settings or any in-product controls provided.

12

Children’s Privacy

The Service is intended for businesses and their staff. It is not directed to children, and Brightmesh does not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact us and we will delete it.

13

Changes to This Policy

Brightmesh may update this Policy from time to time. The effective date at the top reflects the latest version. For material changes, Brightmesh will provide reasonable notice through the website or an in-product notice.

14

Contact & Complaints

For questions or requests about this Policy or your personal information, contact privacy@brightmesh.studio. If you believe your rights have not been respected, you may also lodge a complaint with the relevant data-protection authority.

Questions

Need clarification?

For any questions about this Policy, contact privacy@brightmesh.studio. The team responds within two business days.

↑ Back to top