Privacy Policy

Last updated: 1 August 2026

Brightside Technologies SA, doing business as Brightside AI ("Brightside", "we", "us" or "our"), provides an AI-powered security-awareness platform that helps organisations prepare their workforce for phishing, voice-phishing (vishing) and deepfake attacks (the "Platform").

This Privacy Policy describes how we process personal information collected through our website at brside.com and any other site of ours that links to this policy, through our sales, marketing, events and partner activities, and when you otherwise contact us (together, the "Services").

Important: what this policy does and does not cover

This policy does not apply to personal information that we process on behalf of our business customers. Where an organisation (an "Employer") uses the Platform to run security-awareness programmes for its workforce, that organisation decides why and how the personal information of its people is processed. In data-protection terms, the Employer is the controller and Brightside acts only as a processor, on that Employer's documented instructions and under a data processing agreement.

That covers, among other things, simulated phishing emails and their results, simulated voice calls and their transcripts and analysis results, training assignments and scores, and risk indicators derived from them. Simulated calls are not recorded — the audio is analysed as the call happens and is not stored.

If you received a simulated phishing email or a simulated phone call from us, or you use the Platform because your employer invited you to, then our handling of your personal information is governed by our agreement with your employer and by your employer's own privacy notice. Please direct questions about that data to your employer in the first instance. If you contact us directly, we will refer your request to your employer and support them in responding to it.

European, UK and Swiss users: see Section 11, Section 12 and Section 13 for information that applies specifically to you.

SUMMARY OF KEY POINTS

What personal information do we process? Contact and business details you give us, information collected automatically when you use our website, and business contact information from public and commercial sources. See Section 1.

Do we process sensitive personal information? No. We do not collect special-category data through the Services, and we ask that you do not send it to us. Voice recordings and any voice-clone material used in the Platform are handled for our customers under contract, not under this policy.

Do we sell your personal information? No — we do not sell personal information for money, and we do not disclose it to third parties or affiliates for those parties' own independent marketing. We do use advertising technologies on our website that share online identifiers with Google, Microsoft, Meta, Reddit and LinkedIn to measure our campaigns and show you our advertising, and that tell G2 which pages of our website you visit, so that visits arriving from our listing there can be attributed to it. This happens only if you accept advertising cookies, and you can withdraw that at any time. See Section 4.

Do we use your data to train AI models? No. We do not use your personal information, inputs or outputs to train, fine-tune or improve any AI model, whether ours or a provider's. See Section 6.

Who do we share it with? Vetted service providers under contract, professional advisers, authorities where legally required, and counterparties in a corporate transaction. See Section 7.

What are your rights? Depending on where you live, you may have rights of access, correction, deletion, portability, restriction and objection. See Sections 11–14.

How do you contact us? Email support@brside.com. Individuals in the EEA and UK may also contact our appointed representative, DataRep — see Section 12.

TABLE OF CONTENTS

1. WHAT INFORMATION DO WE COLLECT?

Information you provide to us

  • Contact data — your name, business email address, phone number, employer, and job title.
  • Account data — the username and credentials you set to access a Brightside account, together with your organisation and role. (Where your account exists because your employer bought the Platform, see the carve-out above.)
  • Communications data — the content of your exchanges with us, including sales enquiries, support requests, security-questionnaire responses, and messages sent through our website, by email, or over social media.
  • Event and marketing data — details you give us at conferences, webinars and trade shows, your marketing preferences, and how you engage with our communications.
  • Procurement and contract data — the business, billing and signatory details needed to enter into and administer a contract with your organisation.
  • Recruitment data — where you apply for a role with us, your CV, work history and qualifications.
  • Meeting data — where you join a sales, onboarding or support call with us, we may transcribe that meeting using an AI notetaking tool, and generate a written summary and action points from it. The audio is transcribed as the meeting happens and no recording is kept — what we store is the written transcript and summary, not a recording of your voice. We will tell you before transcription begins, and you can ask us not to — the meeting will go ahead either way. We use these notes only to capture what was discussed and to follow up accurately. We do not use them to evaluate you, and we do not use them to train AI models.

Sensitive information. We do not seek or knowingly collect special categories of personal data (such as data revealing health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or biometric data used to identify you) through the Services. Please do not send such information to us.

Note on voice and likeness data. The Platform's vishing feature can use a voice clone generated from a short recording of a consenting individual. That material is supplied and controlled by our customer, is subject to documented consent obtained by the customer, and is processed by us solely as a processor under the customer's contract. It is not collected through the Services and is not governed by this policy.

Information collected automatically

When you visit our website we and our service providers automatically log:

  • Device data — IP address, browser type and version, operating system, device type, screen resolution, language settings, and approximate location derived from IP address (city or region level, not precise geolocation).
  • Log and usage data — pages viewed, time spent, referring URL, navigation paths, access times, and diagnostic information such as error reports.
  • Communication interaction data — whether you opened our emails or clicked links in them, collected using pixel tags.

This information is used primarily to keep the Services secure and operational and for aggregate analytics. See Section 4.

Information from other sources

  • Business contact data providers and public sources — we obtain business contact details (name, work email, job title, employer, company data) from commercial data providers, professional networks and publicly available sources, to identify and contact organisations that may benefit from our Services.
  • Partners and resellers — MSSPs and channel partners who refer your organisation to us.
  • Our customers — where a customer supplies the details of the person who will administer their account.
  • Business transaction counterparties — in connection with an actual or prospective merger, acquisition, financing or similar transaction.

2. HOW DO WE PROCESS YOUR INFORMATION?

We process personal information to:

  • Deliver and operate the Services — create and administer accounts, provide the Platform to the organisation you represent, and keep it running.
  • Provide support — respond to your enquiries, questions, security questionnaires and feedback.
  • Transcribe and summarise meetings — where you have agreed, capture a transcript and summary of a call so we have an accurate record of what was discussed and agreed. No audio recording is kept.
  • Communicate about the Services — send service announcements, security alerts, and changes to our terms or policies.
  • Secure the Services — monitor for, detect, investigate and prevent fraud, abuse, unauthorised access and other security incidents.
  • Improve the Services — understand how our website and Platform are used, diagnose problems, and develop new features.
  • Market to business audiences — send information about our products, events and webinars to business contacts, and measure how those communications perform.
  • Run events and webinars — register attendees and follow up afterwards.
  • Administer contracts and billing — process orders, issue invoices, collect payment, and meet accounting and tax obligations.
  • Comply with law and protect rights — meet legal obligations, respond to lawful requests from authorities, establish, exercise or defend legal claims, and enforce our terms.
  • Manage corporate transactions — evaluate, negotiate and complete a merger, acquisition, financing, or sale of assets.
  • Create aggregated and anonymised data — produce statistics and benchmarks that no longer identify any individual. Once data is anonymised we may use it indefinitely.

We do not use your personal information for automated decisions that produce legal or similarly significant effects. See Section 5.

This section applies if you are located in the EEA or the UK. The GDPR and UK GDPR require us to have a legal basis for each purpose for which we use your personal information. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests, rights and freedoms. You may object to that processing — see Section 11.

PurposeCategories of personal informationLegal basis
Service delivery and account administrationContact, Account, CommunicationsContractual necessity — to perform our contract with you or with the organisation you represent, or to take steps at your request before entering into one.
Support and responding to enquiriesContact, Communications, AccountContractual necessity, where you are an existing customer. Legitimate interests — to answer enquiries from prospective customers and other parties who contact us.
Transcribing and summarising meetingsMeeting, ContactConsent — we tell you before transcription starts and proceed only if you agree; you may decline and still take the meeting, and you may ask us to delete the transcript and summary afterwards.
Security, abuse prevention and platform integrityDevice, Log and usage, AccountLegitimate interests — to keep our Services, our business and our customers' data secure. Compliance with law, where a security obligation applies.
Service improvement and analyticsDevice, Log and usage, Communication interactionConsent, in respect of optional analytics cookies and similar technologies. Legitimate interests — to understand and improve how our Services are used, where no consent is required.
Business marketing and eventsContact, Event and marketing, data from third-party sourcesLegitimate interests — to promote our Services to business audiences in a proportionate way. Consent, where required by applicable law (including electronic marketing rules) for a given communication.
Online advertising, campaign measurement and remarketingDevice, Log and usage, online identifiersConsent — given through our cookie banner. You may withdraw it at any time through the cookie settings on our site.
Session replay and website usability analysisDevice, Log and usage, Communication interactionConsent — given through our cookie banner.
Contract administration, billing, accounting and taxContact, Procurement and contractContractual necessity. Compliance with law, for statutory retention of accounting records.
RecruitmentRecruitment, ContactLegitimate interests and steps prior to entering an employment contract at your request.
Legal compliance, claims and enforcementAny category relevant in the circumstancesCompliance with law. Legitimate interests — to establish, exercise or defend legal claims and enforce our terms.
Corporate transactionsAny category relevant in the circumstancesLegitimate interests — to evaluate, negotiate and complete a corporate transaction, and to allow counterparties to conduct due diligence.
Creating aggregated and anonymised dataAny category relevant in the circumstancesLegitimate interests — to analyse and improve our Services and produce industry benchmarks while reducing privacy impact.

You may ask us for more information about any legitimate-interests assessment by writing to support@brside.com.

4. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies (including pixels and web beacons) on our website. We group them into four categories:

  • Strictly necessary — to keep the site secure, maintain your session, remember your cookie preferences, and enable core functions. These do not require your consent.
  • Preferences and functionality — to remember choices you make, such as your language.
  • Analytics and performance — to understand how visitors use the site so we can improve it, including session replay.
  • Advertising and marketing — to measure our campaigns and show our advertising to people who have visited the site.

Apart from the strictly necessary category, these are set only with your consent, which you give through our cookie banner and may withdraw at any time.

Analytics. We use Google Analytics and Amplitude to understand how our website and services are used. Amplitude also provides session replay, which reconstructs a visit — the pages seen, scrolling and clicks — so we can find parts of the site that confuse people or fail on particular devices. We use Microsoft Clarity for the same purpose. These tools are configured to mask text entered into form fields. Clarity is connected to our Microsoft Advertising account, which means what it records is also available to Microsoft for advertising measurement.

Advertising and marketing. We advertise our Services online, and we use technologies from Google Ads, Microsoft Advertising, Meta, Reddit and LinkedIn to measure how those campaigns perform and to show our advertising to people who have previously visited our website. These providers may use the identifiers they collect to build a profile of your interests across other websites. They act as independent or joint controllers for that processing, and their own privacy notices describe it; for the LinkedIn Insight Tag, LinkedIn and Brightside are joint controllers.

We also run a tag from G2, the software review site. It runs on every page of our website and tells G2 the address of the page you are viewing, so that visits which arrive from our G2 listing can be attributed to it. It stores nothing on your device, but it does transmit that page address and your IP address to G2 on each page you view, whether or not you reached us from G2.

Neither analytics nor advertising technologies are loaded until you accept the relevant category. You can change your choice at any time through the cookie settings on our site.

A full list of the technologies we use, the provider of each, and how long each lasts, is in our Cookie Policy. You can additionally opt out of Google Analytics across all sites using Google's browser add-on, and out of interest-based advertising generally through Your Online Choices.

We do not sell your personal information for money. We do share online identifiers with the advertising providers named above for campaign measurement and remarketing, and only where you have accepted advertising cookies.

Most browsers accept cookies by default and can be set to reject or delete them. Blocking cookies may affect how parts of our site work.

Do Not Track. There is no finalised industry standard for responding to browser "Do Not Track" signals, and we do not currently respond to them. Where your browser sends a Global Privacy Control signal, we treat it as an objection to analytics and advertising cookies.

5. DO WE USE AUTOMATED DECISION-MAKING?

We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, in the context of the Services covered by this policy.

The Platform does generate risk indicators and training recommendations about individuals for our customers. Where it does so, it operates on our customer's instructions and under their control, and Platform reporting is designed to surface results in aggregate. Any questions about how your employer uses those results should be directed to your employer.

6. ARTIFICIAL INTELLIGENCE

Parts of our Services are powered by artificial intelligence and machine learning ("AI Products"), including AI-generated simulation content and AI-driven voice calls within the Platform.

AI service providers. We provide these features using third-party AI providers, currently Amazon Web Services (AWS), Mistral AI and ElevenLabs. Simulated calls are placed over a specialist telephony provider, currently Infobip. Where personal information is involved, it is shared with these providers only as needed to produce the requested output, under contracts that bind them to process it solely on our instructions.

Simulated calls are not recorded. The audio of a simulated call is analysed as the call happens and is not stored — not by us and not at the telephony provider. Depending on the mode a customer selects, either a written transcript of the call is retained for a limited period, or nothing but the analysis result is retained.

We do not train models on your data. We do not use your personal information, inputs, outputs or any other content you submit to train, fine-tune or otherwise improve any AI or machine-learning model, whether our own or our providers'. Our agreements with AWS, Mistral AI and ElevenLabs require that data processed on our behalf is used exclusively to deliver the requested output and is not used for general model training or improvement.

Synthetic voice and likeness. Where the Platform generates synthetic speech, including from a voice clone, that material is created for a customer's security-awareness programme only. Voice samples are supplied by the customer, who is responsible for obtaining and evidencing the consent of the individual concerned. We do not use voice or likeness material for marketing, identification, or any purpose beyond delivering the customer's programme.

7. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

We share personal information with:

  • Service providers — vendors that support our business under written contract, including cloud hosting and infrastructure, data storage, AI providers, telephony providers for simulated calls, bot protection and traffic filtering, AI meeting-notetaking tools, customer support tooling, email delivery, CRM, and website analytics. They may use personal information only to provide services to us.
  • Professional advisers — lawyers, auditors, accountants, insurers and bankers, where necessary for the services they provide to us.
  • Partners and resellers — where an MSSP or channel partner is involved in your organisation's relationship with us, limited to what that relationship requires.
  • Authorities and other parties — law enforcement, regulators, courts and other parties, where we believe in good faith it is necessary to comply with law, respond to lawful requests, or protect the rights, property or safety of Brightside, our customers or others.
  • Corporate transaction counterparties — prospective and actual acquirers, investors, successors and their advisers, in connection with a merger, acquisition, financing, sale of assets, insolvency or similar transaction.
  • Advertising and analytics providers — Google, Microsoft, Meta, Reddit, LinkedIn and Amplitude receive online identifiers and information about your interaction with our website, and G2 receives the address of each page you view together with your IP address, in each case where you have accepted the relevant cookie category. This is described in Section 4 and in our Cookie Policy.

We do not sell personal information for money, and we do not disclose it to third parties or affiliates so that they can market their own products to you. The advertising providers above use what they receive to measure and deliver our advertising, subject to their own terms.

A current list of our subprocessors is published at trust.brside.com/subprocessors, and is also available on request from support@brside.com.

8. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION

Brightside is established in Switzerland. If you are in the EEA or the UK, your personal information will be transferred to Switzerland, and may be transferred onward to service providers located in other countries, including the United States.

Transfers to Switzerland. The European Commission and the UK Government have each determined that Switzerland provides an adequate level of protection for personal data. Transfers from the EEA and the UK to Brightside in Switzerland therefore take place on the basis of that adequacy decision and require no additional safeguard.

Where your data is stored. We select our service providers so that personal information is stored in the European Union, the European Economic Area or Switzerland. This includes our cloud infrastructure, our AI providers, and our analytics and business tooling. Your personal information is not routinely stored outside these regions.

Two exceptions. Two categories of provider fall outside that commitment, and we set them out rather than leave the sentence above to imply otherwise.

  • Advertising and review platforms. The advertising technologies described in Section 4 — and the G2 tag — are operated by global platforms that process the data they collect on their own infrastructure, including in the United States. We do not control where they host it. Those providers act as independent or joint controllers, each relies on its own transfer mechanism, and their privacy notices are linked in our Cookie Policy. These technologies load only if you accept the advertising category — declining it means no data reaches them.
  • Our bot-protection and traffic-filtering layer. Requests to our simulation infrastructure pass through Cloudflare, which screens out automated traffic and may present a challenge before a request reaches us. Cloudflare runs a global edge network, so each request — including your IP address, browser user agent and the address you requested, which can indicate that you interacted with a simulation — is handled at whichever of its locations is nearest, and that may be outside the EEA. Unlike the advertising platforms above, Cloudflare acts as our processor here: it is engaged under a contract incorporating the Standard Contractual Clauses and is certified under the EU–US Data Privacy Framework. This affects data in transit and in Cloudflare's short-term request logs; the records the Platform keeps afterwards are stored in the EU or Switzerland as described above.

Our AI providers all sit inside the commitment. Mistral AI is established and hosted in France; our AWS infrastructure runs in EU regions; and ElevenLabs operates on its European Union data residency environment, so the voice data used to generate synthetic speech is stored in the EU. The transcripts and results the Platform keeps afterwards are stored in Switzerland, and retention on the ElevenLabs side is configured to zero.

One point of detail we would rather state than gloss. ElevenLabs, Inc. is a company established in the United States. Although your data is stored in its EU environment, the company remains subject to US law, so we keep Standard Contractual Clauses in place as a safeguard, supported by its certification under the EU–US Data Privacy Framework. Data residency also governs where data is stored rather than every place it might be handled: a provider may involve staff or subcontractors outside the EEA for limited support and content-moderation purposes, and those clauses cover that too.

Our telephony provider, Infobip, serves EU customers from data centres in Germany and is contractually restricted to processing within the EU/EEA, so it sits inside the commitment above. It is a UK-established company; any access from the United Kingdom relies on the mechanisms described next.

Onward transfers. Some of our providers are part of corporate groups headquartered outside Europe. Where that means personal information may be accessed from a third country — for example for technical support — we rely on one of the following:

  • an adequacy decision by the European Commission, the UK Government, or the Swiss Federal Council covering the destination country or framework;
  • Standard Contractual Clauses approved by the European Commission, together with the UK International Data Transfer Addendum and the recognition of those clauses under Swiss law, in each case supported by a transfer risk assessment and any additional technical and organisational measures we judge necessary; or
  • in limited cases, a derogation permitted by applicable law, such as where the transfer is necessary to perform a contract with you or you have given your explicit consent.

You may request further information about the specific mechanism we use for a given transfer, and a copy of the relevant safeguards, by writing to support@brside.com.

9. HOW LONG DO WE KEEP YOUR INFORMATION?

We keep personal information only as long as necessary for the purposes set out in this policy, unless a longer period is required or permitted by law.

To decide how long to keep information, we consider its amount, nature and sensitivity, the potential risk of harm from unauthorised use or disclosure, whether we can achieve our purpose by other means, and any applicable legal, accounting, tax or reporting requirement.

As a general guide:

InformationRetention
Account data for customer administratorsDeleted within 60 days of the end of the customer contract
Contract, billing and accounting records10 years, as required by Swiss company law
Sales and marketing contact data24 months from your last meaningful engagement with us
Website and product analytics data14 months
Support and communications records24 months after the enquiry or case is closed
Meeting transcripts and summaries12 months
Recruitment dataFor the duration of the process, and afterwards only with your consent

When we no longer need personal information we delete or anonymise it. Where deletion is not immediately possible — for example because data sits in backup archives — we isolate it from further processing until deletion can occur.

10. HOW DO WE KEEP YOUR INFORMATION SAFE?

We maintain technical, organisational and physical measures designed to protect personal information, including encryption in transit and at rest, access controls and least-privilege provisioning, logging and monitoring, vendor security review, and staff security training.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Security incidents. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within the time limits set by applicable law, and will inform affected individuals without undue delay where the law requires it. Where we act as a processor for a customer, we notify that customer without undue delay so they can meet their own obligations.

11. YOUR RIGHTS IN THE EEA/UK

This section applies if you are located in the European Economic Area or the United Kingdom. References to "personal information" throughout this policy mean "personal data" as defined in the EU GDPR (Regulation (EU) 2016/679) and in the UK GDPR — that is, information from which you are directly identified or can be identified.

Controller. For the processing described in this policy, Brightside Technologies SA is the controller. Our contact details are in Section 19.

Where to find the rest of your GDPR information. The disclosures required by Articles 13 and 14 are set out across this policy:

What the GDPR requiresWhere it is
What we collect, and the sources it comes fromSection 1
The purposes we use it forSection 2
Our legal basis for each purposeSection 3
Cookies and similar technologiesSection 4
Automated decision-making and profilingSection 5
Recipients we share it withSection 7
Transfers outside Europe, and the safeguards usedSection 8
How long we keep it, and the criteria we applySection 9
Our EU/UK representative under Article 27Section 12

Subject to conditions and exceptions in applicable law, you may ask us to:

  • Access — confirm whether we process your personal information and give you a copy of it.
  • Correct — update or correct inaccurate or incomplete information.
  • Delete — erase your personal information where there is no overriding reason for us to keep it.
  • Transfer — provide a machine-readable copy of information you gave us, or send it to another provider where technically feasible.
  • Restrict — limit how we process your information, for example while we verify its accuracy.
  • Object — object to processing based on legitimate interests. You may object to direct marketing at any time, and we will stop.
  • Withdraw consent — where we rely on consent, withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

Do you have to give us your information? No. You are not obliged to provide personal information to us. But where we need it to enter into or perform a contract with you or with the organisation you represent, or to meet a legal obligation, and you choose not to provide it, we may be unable to provide some or all of our Services. We will tell you at the time if that is the case.

How to exercise your rights. Email support@brside.com, or contact our representative as set out in Section 12. We may ask for information to verify your identity. We respond within one month, and will tell you if we need longer because a request is complex or because you have made several. There is normally no fee, though we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.

Complaints. We would like the chance to resolve your concern first, so please contact us. You also have the right to complain to a supervisory authority:

12. OUR REPRESENTATIVES IN THE EU/EEA AND UK

As a company established outside the European Union and the United Kingdom, we have appointed a representative under Article 27 of the EU GDPR and Article 27 of the UK GDPR. Our appointed representative is:

Data Protection Representative Limited (trading as DataRep) Registered in Ireland, company number 616588

Individuals in the EEA and the UK, and supervisory authorities, may contact DataRep on any matter relating to our processing of personal data:

Important: when writing by post you must address your letter to "DataRep" and not to Brightside Technologies SA, or it may not reach us. Please refer to Brightside Technologies SA clearly in the body of your correspondence.

Please note: DataRep handles data-protection matters only. For questions about our products, your account, billing or support, contact us directly at support@brside.com.

DataRep contact locations

CountryAddress
AustriaDataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
BelgiumDataRep, Rue des Colonies 11, Brussels, 1000
BulgariaDataRep, 132 Mimi Balkanska Str., Sofia, 1540, Bulgaria
CroatiaDataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia
CyprusDataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus
Czech RepublicDataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic
DenmarkDataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark
EstoniaDataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia
FinlandDataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland
FranceDataRep, 72 rue de Lessard, Rouen, 76100, France
GermanyDataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany
GreeceDataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece
HungaryDataRep, President Centre, Kálmán Imre utca 1, Budapest, 1054, Hungary
IcelandDataRep, Laugavegur 13, 101 Reykjavik, Iceland
IrelandDataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland
ItalyDataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy
LatviaDataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia
LiechtensteinDataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
LithuaniaDataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania
LuxembourgDataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg
MaltaDataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta
NetherlandsDataRep, Cuserstraat 93, Floor 2 and 3, Amsterdam, 1081 CN, Netherlands
NorwayDataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway
PolandDataRep, Budynek Fronton, ul Kamienna 21, Krakow, 31-403, Poland
PortugalDataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal
RomaniaDataRep, 15 Piața Charles de Gaulle, nr. 1-T, București, Sectorul 1, 011857, Romania
SlovakiaDataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia
SloveniaDataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia
SpainDataRep, Calle de Manzanares 4, Madrid, 28005, Spain
SwedenDataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE-211 46, Sweden
United KingdomDataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom

13. SWITZERLAND (FADP)

Brightside Technologies SA is established in Switzerland and is subject to the Swiss Federal Act on Data Protection ("FADP"). References in this policy to "personal information" include "personal data" as defined in the FADP.

If you are in Switzerland, you may ask us to provide access to your personal data, correct inaccurate data, delete data, restrict or object to processing, and — where processing is automated and based on your consent or a contract — receive your data in a commonly used electronic format or have it transferred to another controller.

Because we are established in Switzerland, we are not required to appoint a Swiss representative under Article 14 FADP.

You may exercise these rights by writing to support@brside.com. If you believe our processing breaches the FADP, you may report the matter to the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland — edoeb.admin.ch.

Where we transfer personal data out of Switzerland, we do so to a country recognised by the Swiss Federal Council as providing adequate protection, or under contractual safeguards recognised by the FDPIC. See Section 8.

14. UNITED STATES RESIDENTS

Brightside is a Swiss company selling to businesses, primarily in Switzerland and Europe. We do not currently meet the applicability thresholds of US state privacy laws such as the California Consumer Privacy Act, and this policy is therefore not written to those laws.

If that changes, we will update this policy and publish the disclosures those laws require before they begin to apply to us.

In the meantime, the rights described in Section 11 — access, correction, deletion, a copy of your information, and objection — are available to anyone who asks, wherever you live. Email support@brside.com. We will verify your identity before acting on a request.

If you want to stop the advertising and analytics technologies described in Section 4, decline or withdraw the relevant category in the cookie settings on our website. Where your browser sends a Global Privacy Control signal, we treat it as an objection to those technologies.

15. DIGITAL SERVICES ACT

To the extent that Regulation (EU) 2022/2065 (the Digital Services Act) applies to any service we offer in the European Union, the following applies.

Legal representative (Article 13). As a provider established outside the European Union, we have designated a legal representative in the Union:

Data Protection Representative Limited (trading as DataRep) DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland Email: digitalrequest@datarep.com — please quote "Brightside Technologies SA" Telephone: +353 (1) 919 8899

Our legal representative may be addressed by Member State authorities, the European Commission and the European Board for Digital Services on all matters necessary for the receipt of, compliance with and enforcement of decisions issued in relation to the Digital Services Act.

This designation has been notified to the Digital Services Coordinator in Ireland, Coimisiún na Meán, which has confirmed that our legal representative is recorded for the purposes of Article 13.

Contacting us. Member State authorities, the European Commission and the Board may also contact us directly by electronic means at support@brside.com. Communications may be conducted in English.

16. BRIGHTSIDE REPORT PHISHING ADD-ON FOR GMAIL — GOOGLE USER DATA

The Brightside Report Phishing add-on for Gmail allows employees of our customers to report suspicious emails to their organisation's security team. This section describes how the add-on accesses, uses, stores and shares Google user data.

Data we access. When a user clicks "Report Phishing" on an email, the add-on accesses: (a) the full content of that single email message (headers, body and attachments) using Google's contextual add-on scopes, which grant access only to the message the user is currently viewing and only at the moment of interaction; (b) the user's email address, used to identify the reporter within their organisation; (c) the user's display-language setting, used solely to render the add-on interface in the user's language and not stored. The add-on cannot read any other messages in the user's mailbox, cannot send email, and cannot modify mailbox content.

How we use it. The reported message is transmitted over an encrypted connection (TLS) to Brightside and used exclusively to: scan the message for malware; determine whether it is a simulated phishing email sent as part of the customer's security-awareness programme; extract message metadata (sender, subject, contained links) for security analysis; and make the report available to the security team of the reporter's own organisation. Reports of genuine (non-simulated) suspicious emails may also be forwarded to the customer's designated security contact.

Storage and protection. Reported messages are stored encrypted at rest within infrastructure operated by our hosting subprocessor (Amazon Web Services). Access is restricted to the reporter's own organisation; reports are never shared across customer organisations. Reported messages are retained for the duration of the customer contract or until the customer requests deletion.

Sharing. Google user data obtained through the add-on is shared only with the security team and designated security contacts of the reporter's own organisation. We do not sell Google user data, do not use it for advertising, and do not share it with third parties other than the hosting subprocessors required to operate the service.

Limited Use disclosure. Brightside's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

17. DO WE COLLECT INFORMATION FROM MINORS?

Our Services are intended for businesses and are not directed at anyone under 18. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child, contact us at support@brside.com and we will take appropriate steps to delete it.

18. DO WE MAKE UPDATES TO THIS NOTICE?

We may update this policy from time to time. The updated version is indicated by the "Last updated" date at the top. If we make material changes, we will post a prominent notice on our website or notify you directly. We encourage you to review this policy periodically.

19. HOW CAN YOU CONTACT US?

For any question about this policy or about how we handle personal information:

Email: support@brside.com

Post:

Brightside Technologies SA Route des Flumeaux 46 1008 Prilly Switzerland

Individuals in the EEA and the UK may also contact our appointed representative, DataRep — see Section 12.