Last updated: October 1st, 2026
ProWebCraft LTD ("Brizy," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and share your personal information ("Personal Data"), as well as your rights regarding that information. It applies to all users of our services, including individuals and agencies/companies using Brizy’s website-building platform for their clients (collectively, "Users," "you," or "your").
It applies to Brizy Cloud, Brizy for WordPress, the Brizy AI Website Builder, the Brizy AI Assistant, Brizy Shops, Brizy APIs, white-label and reseller services, support services, our websites and other products or features that refer to this Privacy Policy.
This Privacy Policy explains the processing activities for which Brizy acts as a data controller. It also provides general information about processing carried out by Brizy on behalf of business customers. Where Brizy processes Personal Data on behalf of a customer, the customer acts as the data controller and Brizy acts as the data processor in accordance with our Data Processing Addendum.
This Privacy Policy is provided for transparency and does not itself constitute a request for consent. Your use of the Services is governed by our Terms of Service.
If you access Brizy through an agency, reseller or white-label partner, that partner’s privacy notice may also apply to the information it collects from you.
By accessing or using our Services, you confirm that you have read, understood, and agreed to this Privacy Policy and our Terms of Service. If you do not agree with our practices, you must immediately discontinue using our Services. If you have any questions or concerns, please contact us at dpo@brizy.io.
Brizy is committed to ensuring the protection of your rights and freedoms in relation to the processing of your Personal Data. We process your data securely and in accordance with all applicable legal obligations. Our Privacy Policy is designed to comply with the highest standards, including the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR.
This Privacy Policy outlines the information we collect about you through our Website and Services. It also explains your choices regarding the processing of your data, including how you can access, update, and object to certain uses of your Personal Data.
We may update this Privacy Policy periodically to reflect changes in our data processing practices or legal requirements. Any updates will be posted on this page, and we encourage you to review the policy regularly.
We encourage you to read this Privacy Policy in full to understand how we handle your Personal Data. However, for your convenience, here are key points:
If you have any questions about this Privacy Policy, your rights, or how we handle your data, please contact us at dpo@brizy.io
Brizy is the commercial name of ProWebCraft LTD, a company registered in the United Kingdom under company number 14303873. Our registered office is located at 71–75 Shelton Street, Covent Garden, London, England, WC2H 9JQ.
Brizy is a digital technology company that provides a visual website builder and design platform. Our services empower individuals, agencies, and businesses to create professional websites without writing code. We operate globally and offer both cloud-based and self-hosted solutions to accommodate diverse user needs.
In this Privacy Policy, references to “Brizy”, “we”, “us”, or “our” refer to ProWebCraft LTD, acting as the data controller or data processor depending on the context of data collection and processing.
Brizy acts in different capacities depending on the nature of the data processing activities involved:
1. Brizy as a Data Controller:
Brizy functions as a data controller when we directly collect and process personal data from Users who create accounts, access workspaces, manage projects, subscribe to newsletters, participate in webinars, engage in affiliate marketing, or otherwise communicate through our platform. This category includes data processed for the purposes of account creation, user authentication, platform analytics, marketing and promotional activities, customer support, and any cookies set by Brizy on our website to enhance User experience and service functionality.
Examples of data collected as a data controller include:
2. Brizy as a Data Controller:
Brizy acts as a data processor when a customer uses the Services to process Personal Data concerning its clients, website visitors, end users or shoppers.
Depending on the features used, this may include:
In these circumstances, the customer is responsible for determining an appropriate legal basis, providing privacy notices, obtaining any required consents, responding to data-subject requests and issuing lawful instructions to Brizy. The processing is governed by our Data Processing Addendum.
Certain third parties, such as payment providers, social login providers, advertising platforms or other service providers selected by a customer, may determine their own purposes and means of processing and may act as independent data controllers. Their own privacy notices apply to those activities.
Brizy may be made available through an agency, reseller, SaaS provider, hosting provider or other white-label partner.
In these arrangements, the partner may control the branding, onboarding flow, information requested from end users, customer relationship, billing and customer-facing privacy notices.
The partner generally acts as the data controller for the Personal Data it collects from its end users and for its commercial relationship with them. Brizy processes data through the underlying platform on the partner’s instructions and in accordance with our Data Processing Addendum.
Data processed through a white-label or API implementation may include:
Brizy may separately act as controller for limited security, fraud-prevention, infrastructure, legal-compliance and direct-support activities.
End users accessing Brizy through a white-label partner should review the partner’s privacy notice and contact that partner in the first instance regarding their Personal Data.
AI Services are not included in standard Brizy for WordPress or white-label offerings unless expressly enabled for the relevant product or integration. Where a partner enables an AI feature through an interface it controls, the partner must provide appropriate privacy and AI transparency information to its users.
Personal Data You Provide Us
We collect the following data directly and through the use of third parties. We collect this data by using certain technologies, such as cookies. Please refer to our Cookies Policy to learn more about your rights and responsibilities with respect to cookies and other technologies. If you have any questions about your rights under our Cookies Policy, we encourage you to contact us at dpo@brizy.io
When you use the Brizy AI Website Builder, the AI Assistant or another AI-enabled feature, we may process:
We use this information to:
Where you are the contracting customer, this processing is generally necessary to provide the AI feature you request. Where you use Brizy on behalf of an organisation, we may also rely on our legitimate interests and those of the organisation in providing, administering and securing the Services.
Where you submit Personal Data concerning your clients, personnel or other individuals, Brizy processes that information on your behalf under our Data Processing Addendum. You are responsible for ensuring that you are authorised to submit the information and that you have provided any required privacy information.
The AI Services are not designed for the processing of special-category Personal Data, highly confidential information or data concerning children. You should not submit such information unless you have determined that the processing is lawful, necessary and appropriate for the relevant feature.
At your request, the AI Services may retrieve information from publicly available webpages, URLs or search results. This information may include public business information, business descriptions, publicly displayed contact information and names appearing on the relevant source. The source of such information is the relevant public webpage, URL or search result.
Brizy does not use your prompts, uploaded documents, images, website content, AI conversations or AI-generated output to train general-purpose artificial intelligence models, and we require our AI providers not to use this information for such training, unless you expressly opt in to a separate optional programme.
We may use aggregated or de-identified usage and performance information to evaluate and improve the reliability, safety and functionality of the AI Services.
Brizy AI does not currently generate images. Where the AI Services suggest or insert stock images, search terms derived from your prompt or website context and relevant API request information may be sent to a stock-image provider, such as Unsplash.
If you submit information about a real customer, employee or other person for use in a testimonial, review or endorsement, Brizy processes that information as User Content on your behalf. You are responsible for having an appropriate legal basis and any required permissions for the use of the person’s name, photograph, quotation or other Personal Data.
AI-generated sample testimonials and stock images are intended as demonstration content and should not be treated as statements or photographs of actual customers unless you replace and verify them
Brizy Shops is an optional e-commerce feature that allows Brizy customers to create and manage online shops. Brizy Shops uses commerce technology provided by Ecwid by Lightspeed.
When a customer activates Brizy Shops, we may process:
Merchant and shop administration data
Shopper and order data
The operator of the Shop determines why and how Shopper and Order Data is collected and acts as the data controller. Brizy processes that data on behalf of the Shop operator under our Data Processing Addendum.
Brizy acts as a separate data controller for the merchant’s Brizy account, subscription, billing, direct support, platform security and legal compliance.
Payment information for purchases made through a Shop is normally collected directly by the payment provider selected by the merchant. Unless expressly stated otherwise, Brizy does not receive or store full payment-card numbers. We may receive limited transaction information, such as the payment status, amount, currency, provider reference or token, and information required to manage refunds or disputes.
Ecwid by Lightspeed provides the underlying e-commerce technology and processes Merchant, Shopper and Order Data for the purpose of delivering Brizy Shops. Payment providers, shipping providers, marketplaces, tax providers and other services enabled by the merchant may process Personal Data under their own privacy notices.
If you are a shopper and wish to exercise a privacy right relating to a purchase, account or order, you should normally contact the operator of the relevant Shop. Brizy will assist the Shop operator where required under our Data Processing Addendum.
Brizy processes your personal data based on one or more of the following legal bases:
Below you will find details on how we use your personal data:
We process your personal data to deliver and manage the services you request from Brizy. This includes:
Platform Analytics and User Experience:
We use your personal data to communicate important information and provide support:
We may collect your personal data if you voluntarily participate in surveys, forums, research projects, contests, sweepstakes, or promotional activities. This information allows us to understand our customers better and continuously enhance our offerings. Processing in this context is typically based on your consent or our legitimate interest.
For potential enterprise customers, we collect and process data such as name, email address, phone number, job title, and company details. This processing is based on our legitimate interest in expanding our business and facilitating enterprise partnerships.
We use your personal data to detect, prevent, and investigate security incidents, fraud, and other illegal or unauthorized activities. This processing is necessary for our legitimate interest in maintaining the security and integrity of our services.
We process personal data to fulfill applicable legal requirements, such as tax obligations, regulatory compliance, reporting to authorities, and responding to legal inquiries or law enforcement requests. This processing is based on our compliance with relevant laws and regulations.
Processing activity | Main data | Brizy’s role | Purpose | Legal basis |
|---|---|---|---|---|
Providing AI generation and editing | Prompts, uploads, website context, conversations and output | Controller for direct account data; processor for customer-submitted third-party data | Generate and edit websites and text | Contract or legitimate interests, as applicable; customer’s lawful basis where Brizy is processor |
AI security and troubleshooting | Prompts, output, technical logs and security signals | Controller | Prevent abuse, investigate incidents and maintain reliability | Legitimate interests and, where applicable, legal obligation |
Optional use of identifiable content for model training | Content expressly included in an optional programme | Controller | Model improvement | Separate consent or another specifically assessed lawful basis |
Brizy Shops merchant administration | Merchant contact, shop settings and subscription data | Controller | Activate and administer Brizy Shops | Contract, legal obligation and legitimate interests |
Brizy Shops shopper and order processing | Shopper, order, shipping and transaction data | Primarily processor | Provide the platform to the partner | Determined by the partner; Brizy processes under the DPA |
Automated security screening | URLs, content, code, files, activity and security signals | Controller | Detect phishing, malware, fraud and abuse | Legitimate interests and legal obligation, where applicable |
Stock-image search | Search terms and contextual information | Controller or processor depending on the project context | Retrieve relevant stock images | Contract, legitimate interests or customer instructions |
White-label and API processing | End-user accounts, projects, content and technical data | Primarily processor | Provide the platform to the partner | Determined by the partner; Brizy processes under the DPA |
Brizy hosts websites created by our Clients (such as agencies, SaaS providers, and other Users). Any personal data processed by these websites, including data collected from end users, is solely controlled by the respective clients. Brizy does not independently collect or control this data, nor do we set cookies or tracking scripts on these sites. End users should refer to the specific privacy policy of the website they visit for information on their data processing practices.
For How Long Do We Keep Your Personal Data?
We retain your personal data only for as long as it is necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal, regulatory, or contractual obligations, or protect our legal rights.
In general, your personal data will be stored as follows:
After the expiry of the relevant retention period, we securely delete or anonymize your personal data to ensure that it cannot be associated with you.
If you have questions about our data retention practices or wish to request deletion or access to your personal data, please contact us at dpo@brizy.io.
Brizy may send you email communications for various purposes related to your use of the platform. These include, but are not limited to:
Each email includes a clear unsubscribe link, allowing you to opt out of promotional communications or adjust your preferences at any time.
We rely on the following legal bases under the General Data Protection Regulation (GDPR) and related laws to send you email communications:
We process and send certain email communications under the legal basis of legitimate interest (Article 6(1)(f) GDPR) when:
Even if you choose not to subscribe to newsletters, you may still receive emails based on our legitimate interest in helping you successfully use the Services and maintain platform functionality. You may object to such processing at any time by contacting support@brizy.io, though doing so may impact your ability to receive important product information.
Where required, we rely on your express consent (Article 6(1)(a) GDPR) to send promotional emails such as newsletters or special offers that are not directly related to your account or services. You give this consent by actively opting in, such as by ticking a checkbox on a form. You may withdraw this consent at any time by using the unsubscribe link in our emails or contacting us directly.
If you are an existing customer, have signed up for a free trial, or requested information from us, we may send you occasional emails about similar Brizy products, features, or offers. This is in line with applicable laws (e.g., Article 13(2) of the ePrivacy Directive and UK PECR), which allow marketing on the basis of a prior relationship — known as a "soft opt-in."
You can opt out at any time by clicking the unsubscribe link in any email or contacting us at dpo@brizy.io
You can manage your email preferences or unsubscribe from certain types of communications at any time by clicking the appropriate link in the footer of any Brizy marketing email.
Note that opting out of promotional communications does not affect service-related emails, such as billing reminders, security alerts, or onboarding support messages necessary for the performance of our contract with you or our legitimate interest.
Brizy has implemented robust technical and organizational security measures to protect your personal information against accidental loss, unauthorized access, disclosure, alteration, or any other unlawful processing. Your personal data is securely stored within protected networks, accessible only to a limited number of authorized personnel who are required to maintain confidentiality. All sensitive information you provide, especially financial details, is securely transmitted via Secure Socket Layer (SSL) encryption technology. Transactions are exclusively processed by trusted third-party payment gateways, and full payment details are never stored on Brizy’s servers.
To ensure high-level security, Brizy hosts all data on GDPR-compliant cloud servers provided by Amazon Web Services (AWS), a leading global cloud infrastructure provider. For more details about Amazon's data security and compliance practices, please review Amazon's Data Protection Addendum here.
All employees, collaborators, and third-party service providers are bound by confidentiality agreements and data protection obligations, and they access personal data strictly according to their professional responsibilities. Additionally, our internal systems and endpoint devices are secured by password protection, regularly updated antivirus software, anti-spam solutions, firewalls, and secure encryption protocols, ensuring continuous protection of your personal data.
Despite these comprehensive measures, please understand that no online platform or transmission method is completely secure. Should you have any concerns regarding the security of your personal data or if you wish to learn more about our security practices, please contact us at dpo@brizy.io.
We may disclose information about you in the following circumstances:
We share information with vendors that perform services on our behalf. These vendors only process personal data as instructed by us and in accordance with applicable data protection laws:
In limited cases, we may share your information with our professional advisors (e.g., external legal counsel or financial advisors) to ensure compliance with our legal and financial obligations, or to protect our rights and interests. Depending on the circumstances, we may share any of the categories of personal data described in our “Personal Data We Collect” section with these advisors.
We also work with various partners who may receive certain data about you, always subject to appropriate safeguards:
We transmit your Payment Information to our third-party payment processors through encrypted channels to process transactions. Your payment details are not stored on our servers beyond the limited billing and verification information needed for record-keeping and compliance.
We disclose information if we believe such disclosure is necessary to:
Depending on the circumstances, we may share any of the categories of personal data described in our “Personal Data We Collect” section to meet these obligations.
If Brizy undertakes or is involved in any merger, acquisition, reorganization, sale of assets, or other business transaction, we may disclose personal data as part of the negotiation, due diligence, or completion of such a transaction. In such cases, appropriate measures will be taken to ensure the confidentiality and integrity of the data transferred.
When these third parties act as our data processors, we ensure that data processing agreements are in place under Article 28 of the GDPR (or equivalent obligations in other jurisdictions). These agreements obligate the service providers to protect your personal data and process it solely in accordance with our instructions and applicable legal standards.
Consult our list of approved sub-processors as of October 1, 2025, in Appendix 2.
Brizy is established in the United Kingdom and uses service providers located in the United Kingdom, European Economic Area, United States, Canada and other countries identified in our list of third parties and subprocessors.
The location of processing depends on the feature used. For example, AI, e-commerce, support, payment and stock-media providers may process Personal Data outside the country in which you are located.
Where Personal Data protected by the EU GDPR is transferred to a country that has not been recognised as providing an adequate level of protection, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required.
For restricted transfers under UK data protection law, we rely on an applicable adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.
You may contact dpo@brizy.io for additional information about the safeguards applicable to a particular transfer.
Under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the EU GDPR, you have certain rights regarding your personal data. These rights may vary depending on your jurisdiction, but generally include:
We are not obliged to comply with all requests for erasure (e.g., when we must retain data to comply with a legal obligation or to establish, exercise, or defend legal claims).
4. Right to Restrict Processing: You can request that we restrict (i.e., store but not further process) your personal data in limited circumstances, for example when:
5. Right to Data Portability: Where we process your personal data based on your consent or the necessity to perform a contract with you, and the processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format. You can also request that we transfer your data directly to another data controller where technically feasible.
6. Right to Object You have the right to object to the processing of your personal data when it is based on our legitimate interests or those of a third party, if you believe your fundamental rights and freedoms outweigh those interests. You can also object to direct marketing at any time by using the “unsubscribe” link in such communications or contacting us.
7. Right Not to be Subject to Automated Decisions: You may request not to be subject to decisions based solely on automated processing (including profiling) which produce legal or similarly significant effects on you. This right does not apply if:
8. Right to Lodge a Complaint
With Brizy:
If you have any concerns or complaints regarding the processing of your personal data, we encourage you to contact us first at dpo@brizy.io. We will do our best to investigate and address your concerns promptly.
Alternatively, you can contact us by post at:
ProWebCraft LTD: 71-75 Shelton Street, Covent Garden, WC2H 9JQ, London, United Kingdom
However, please note that given the global reach of our app, we strongly recommend that you contact us by email. We cannot guarantee the arrival on time by post. If you, however, choose to submit a request through the mail, we recommend that you mail your request with confirmation of receipt.
We will consider and act upon any request in accordance with applicable data protection laws.
With the ICO (UK):
If you are located in the United Kingdom and feel that we have not adequately resolved your complaint or concern, you have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO):
We aim to respond to any valid request relating to your rights within one month, or within two months if the request is complex or if you have made multiple requests. In such cases, we will let you know about the delay and provide an explanation. You may also send your request by post if needed:
9. Personal Data processed on behalf of a Brizy customer
If your Personal Data was submitted through a website, Shop, white-label service or other service operated by a Brizy customer, that customer is normally the data controller.
You should contact the relevant website owner, Shop operator, agency or white-label provider to exercise your rights. Brizy will assist the customer in responding to your request where required by our Data Processing Addendum.
Brizy may not be able to identify the relevant customer unless you provide information such as the website address, Shop name, order reference or other relevant details
For any questions or concerns about this Privacy Policy or how we manage your personal data, please contact us at dpo@brizy.io.
You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us at dpo@brizy.io. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, to respond to service requests, or for other non-marketing purposes.
Our services may include links to third-party websites, mobile applications, or social media platforms. Brizy does not control and is not responsible for the content, accuracy, or practices of any third-party websites or materials accessible through such links. Any interactions with these external sites are governed by their own privacy policies and terms of service, and we encourage you to review them carefully before engaging in any transaction or providing personal data. We disclaim all responsibility and liability for your use of or access to any external websites. If you have difficulty locating a third party’s privacy policy, please contact them directly for more information or reach out to us at dpo@brizy.io for assistance.
Unless otherwise required by local law, this Privacy Policy, and any dispute or claim arising from or related to its subject matter, shall be governed by and interpreted in accordance with the laws of the United Kingdom. You agree to submit to the exclusive jurisdiction of the state or federal courts located in the United Kingdom, with respect to any matter arising out of or relating to this Privacy Policy or the processing of your personal data.
We reserve the right to update this Privacy Policy from time to time. The most current version of this Policy will be posted on our website under the “Last Updated” date. Any material changes will become effective as soon as they are posted, and we may also provide notice of significant updates via email or directly within our services. We encourage you to review this Privacy Policy regularly to stay informed about how we are protecting your information.
We welcome any questions, comments, or concerns you may have about this Privacy Policy or our data processing practices. Please contact us at:
Email: dpo@brizy.io
Mailing Address: ProWebCraft LTD
71-75 Shelton Street, Covent Garden, WC2H 9JQ
London, United Kingdom
We will make every effort to address and resolve any issues promptly and professionally.
Depending on where you live, you may have additional privacy rights under applicable law. These rights may be subject to legal exceptions or limitations.
To exercise your rights, contact us at dpo@brizy.io. We may request reasonable information to verify your identity and process your request.
Where your Personal Data was collected through a customer website, Brizy Shop, white-label service, reseller service, or API integration, the relevant website owner, Shop operator, reseller, or partner generally acts as the data controller. In these cases, you should normally submit your request directly to that organisation. Brizy will assist it with your request where required by applicable law and our Data Processing Addendum. This reflects Brizy’s role as a processor for customer-controlled website and end-user data.
Where the EU GDPR or UK GDPR applies, you may have the right to access, correct, delete or restrict the processing of your Personal Data, receive certain data in a portable format, object to certain processing and withdraw your consent where processing is based on consent. You may also have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
You may lodge a complaint with your local data protection authority or, in the United Kingdom, with the Information Commissioner’s Office.
Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), California residents have the following rights (subject to applicable legal limitations):
We do not knowingly Sell or Share the personal information of children under 16.
You also have the right to not be discriminated against (as provided for in applicable law) for exercising certain of your rights. Brizy does not discriminate against California Residents for exercising their rights.
Brizy does not sell your personal information in exchange for monetary value. However, we may use third-party analytics or advertising services that could be considered a “sale” or “sharing” under the CPRA. You may exercise your rights by contacting us at dpo@brizy.io.
Nevada residents have the right to opt out of the sale of certain personal information as defined under Nevada Revised Statutes Chapter 603A. Brizy does not currently sell personal information as defined under Nevada law. However, you may submit a request to opt out by emailing dpo@brizy.io.
Virginia residents have the following rights under the Virginia Consumer Data Protection Act (VCDPA):
Where the Personal Information Protection and Electronic Documents Act, or an applicable provincial privacy law, applies, you may request access to the Personal Information Brizy holds about you, challenge its accuracy and request its correction.
You may also withdraw your consent, subject to applicable legal or contractual restrictions, and submit a complaint to the Office of the Privacy Commissioner of Canada or the relevant provincial privacy authority.
Where the Privacy Act 1988 and the Australian Privacy Principles apply, you may request access to the Personal Information Brizy holds about you and request the correction of information that is inaccurate, incomplete, outdated, irrelevant or misleading.
You may also submit a privacy complaint to Brizy. If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner
To the extent that the Digital Personal Data Protection Act 2023 and other applicable Indian privacy laws apply and the relevant provisions are in force, you may have the right to:
- obtain information about the processing of your Personal Data;
- request correction, completion, updating or erasure of your Personal Data;
- withdraw consent where processing is based on consent;
- use Brizy’s grievance redressal process; and
- nominate another person to exercise your rights in the event of death or incapacity.
Where permitted by applicable law, you may also submit a complaint to the Data Protection Board of India after first using Brizy’s grievance redressal process.
To exercise your rights, please contact dpo@brizy.io.
Third-party
| Purpose | Entity Location
|
|---|---|---|
1Password | Password management and secure storage | United States, Canada, & the EU |
aMember | Membership and subscription management platform | USA (assumed) |
AWS | Cloud infrastructure and hosting services | Global (notably USA, Europe, Asia-Pacific) |
Brevo | Email marketing and CRM | France (headquarters), European Union |
Close | Sales CRM and lead management | USA |
Customer.io | Customer engagement and marketing automation platform | USA |
Dext | Expense management and receipt processing | United Kingdom |
DigitalOcean | Cloud hosting and virtual servers | USA, Netherlands, Germany, Singapore, India, Australia, Canada |
Discord | Internal communication and collaboration | USA |
Docker | Containerization and software deployment | USA |
Figma | Design and prototyping collaboration | USA |
Fusion Consulting SRL
| Externalized development, maintenance, and operations | Republic of Moldova |
GitHub | Code hosting, version control, and collaboration | USA |
Google Analytics
| Website traffic analytics and user behavior tracking | USA |
Jumpshare | File sharing, collaboration, and quick media capture | USA |
Miro | Collaborative online whiteboarding and visual workspace | USA |
Notion | Project management and knowledge management | USA |
Paddle | Payment processing and subscription management | USA and Europe |
Slack | Team communication and collaboration | USA |
Stripe | Payment processing and financial transaction management | North America, Europe, and Asia-Pacific |
OpenAI | AI Content Generation | USA |
Xero | Accounting software and financial management | New Zealand, USA |
Zendesk | Customer service and support platform | USA, Europe, Asia-Pacific |
Clarity | Analytics alternative to Google Analytics | USA |
Piwik PRO
| Analytics alternative to Google Analytics | Europe (Poland HQ) |
YouTube | Posting and sharing video content | USA |
Facebook | Social media marketing | USA, Europe, and Asia |
Instagram | Social media marketing | USA |
LinkedIn
| Professional networking and advertising | USA |
Google Ads
| Creation of targeted advertisements | USA |
ChartMogul
| Financial reporting and analytics | Germany |
ChurnBuster.io
| Cart recovery and abandoned checkout management | USA |
Ahrefs | SEO tool | Singapore |
BunnyCDN | Content delivery network (CDN) | Slovenia |
DocuSign | Digital signing of documents | USA |
Innertrends | Internal analytics and reporting based on personal data accessed via aMember | Romania |
Namecheap | SSL certificates and domain registration | USA |
Sentry | Error tracking and analytics | USA |
Sucuri.net
| Website security and Web Application Firewall (WAF) | USA |
Streamyard | Webinar hosting platform used for collecting personal data via embedded forms | USA |
Softlead | Cold outreach tool used to send outbound emails (no personal data collection) | Romania |
Typeform | Online forms and surveys | Spain |
UptimeRobot | Service monitoring | USA and Europe |
Wise | Payments and international transfers | Europe, Asia-Pacific, and the USA |
Pursuant to Article 32 GDPR – Security of Processing
Brizy has implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of Regulation (EU) 2016/679 (GDPR). These measures are designed to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services, and are reviewed and updated regularly based on the state of the art, implementation costs, and the nature, scope, context, and purposes of processing.
Brizy has appointed a Data Protection Officer (DPO), who may be contacted at privacy@brizy.io for any data protection-related matters.
1. Physical Access Control
Measures to prevent unauthorized persons from gaining physical access to data processing equipment:
2. Logical Access Control
Measures to prevent unauthorized access to data processing systems:
3. Authorization Control
Measures to ensure that persons authorized to use data processing systems access only the data they are permitted to:
4. Separation Control
Measures to ensure data collected for different purposes is processed separately:
5. Transfer Control
Measures to protect personal data during transmission:
6. Input Control
Measures to ensure that personal data is entered, modified, or removed only by authorized individuals:
7. Availability and Resilience
Measures to protect data from accidental destruction or loss:
8. Monitoring and Alerting (AWS Infrastructure)
Measures to ensure infrastructure integrity and performance:
9. Subprocessor and Vendor Management
Measures to ensure third parties meet applicable security and privacy obligations:
10. Data Subject Rights Management
Measures to ensure compliance with GDPR Chapter III:
Brizy reviews and updates these measures on an ongoing basis in line with technological developments and regulatory requirements.