This Privacy Policy explains how Brantial AI (“Brantial”, “we”, “us” or “our”) handles personal data when you visit our website, request an audit, contact us, create an account, connect a supported integration, or use the Brantial services (together, the “Services”). It applies where we act as the controller of your personal data.
The laws that apply depend on where you are and how you use the Services. These may include the UK GDPR and Data Protection Act 2018 and, where applicable, the EU GDPR and Turkey’s Personal Data Protection Law No. 6698 (KVKK).
1. Who We Are and When This Policy Applies
Brantial is developed and operated by:
WEBTURES LTD. (Company number 11948574)
494a Fulham Road, London, England, SW6 5NH
Email: hello@brantial.ai
When a business customer uploads or connects personal data for us to process only on its documented instructions, that customer generally acts as controller and Brantial acts as processor. In that situation, the customer’s privacy notice governs its collection and use of the data, and requests relating to that data should usually be directed to the customer first.
This Policy does not govern third-party websites or services that you choose to access from Brantial.
2. Personal Data We Collect
Depending on how you interact with Brantial, we may collect:
- Account and contact data: name, business email address, company, role, company size, account identifiers, language, and communication preferences.
- Audit and enquiry data: the domain you submit, the content of your enquiry, referral information, and information you provide in contact or BrandScore forms.
- Service and project data: domains, URLs, prompts, keywords, competitors, configuration choices, reports, and AI-generated outputs.
- Connected-service data: data made available through integrations you authorize, such as Google Search Console and Google Analytics, together with integration status and authorization metadata. We do not receive your password for an OAuth-based integration.
- Technical and usage data: IP address, device and browser information, timestamps, referrer, pages viewed, interactions, diagnostic logs, and security events.
- Subscription and transaction data: plan, subscription status, invoices, billing contact details, payment status, and transaction identifiers. Payment card details are handled by the payment provider and are not stored on Brantial’s infrastructure.
- Communications: support requests, feedback, and correspondence with us.
Please do not submit special-category or highly sensitive personal data through prompts, free-text fields, or support channels unless it is necessary, lawful, and specifically agreed with us.
3. How We Obtain Personal Data
We obtain personal data:
- directly from you when you complete a form, open an account, subscribe, contact us, or use the Services;
- from an administrator or colleague at your organization;
- from services you choose to connect and authorize;
- automatically from your browser, device, and use of the Services; and
- from publicly accessible websites and sources when you ask Brantial to analyze a domain, URL, brand, or topic.
If you provide personal data about another person, you are responsible for ensuring that you are permitted to do so and that they receive any privacy information required by law.
4. How and Why We Use Personal Data
We use personal data only when we have a lawful basis. The principal purposes and bases are:
| Purpose | Typical lawful basis |
|---|---|
| Create and administer accounts; provide audits, reports, analytics, integrations, and support | Performance of a contract or steps requested before entering a contract |
| Process subscriptions, maintain transaction records, and meet tax or accounting duties | Performance of a contract and compliance with legal obligations |
| Secure the Services, prevent abuse and fraud, diagnose faults, and maintain reliability | Our legitimate interests in operating a secure and reliable service; legal obligations where applicable |
| Improve product performance and user experience using service telemetry and aggregated insights | Our legitimate interests, balanced against users’ rights and expectations |
| Measure use of our website through non-essential analytics technologies | Consent |
| Respond to enquiries and manage business relationships | Steps requested before a contract and our legitimate interests in communicating with customers and prospective customers |
| Send marketing communications where permitted | Consent, or legitimate interests where applicable law permits; you may opt out at any time |
| Establish, exercise, or defend legal claims and respond to lawful requests | Legal obligations and legitimate interests |
We do not treat the submission of a contact or free-audit form as consent to unrelated marketing. Where we rely on consent, you may withdraw it at any time without affecting processing that took place before withdrawal.
5. Information You Must Provide
Information marked as required in an account, audit, contact, checkout, or integration flow is needed to complete the action you request. If you do not provide it, we may be unable to create the account, deliver the audit, respond to the enquiry, process the subscription, or activate the integration.
Optional integrations and optional profile fields are not required to browse the public website. You may disconnect an integration through the available account controls, subject to any retention required for security, legal, or audit purposes.
6. How We Share Personal Data
We do not sell personal data. We may share only the data reasonably necessary with:
- Infrastructure and security providers, including Cloudflare and hosting, monitoring, and email-delivery providers;
- AI and model providers used to process prompts or produce requested analysis and outputs;
- Connected platforms, including Google services, when you authorize an integration;
- Payment and billing providers, including Stripe, for subscription and transaction processing;
- Professional advisers and authorities where reasonably necessary for legal, accounting, security, or compliance purposes;
- A successor or transaction participant in connection with a merger, financing, reorganization, acquisition, or sale, subject to appropriate confidentiality and data-protection safeguards; and
- Other parties at your direction or with your consent.
Providers that process personal data for us are required to act under appropriate contractual and security obligations. Some third parties may act as independent controllers for their own activities; their privacy notices then also apply.
7. International Data Transfers
Brantial and its providers may process personal data outside your country, including outside the United Kingdom and European Economic Area. Where a restricted transfer requires safeguards, we use an applicable lawful mechanism, such as an adequacy regulation or decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. We also carry out transfer risk assessments where required.
You may contact us for further information about the safeguards relevant to your personal data. Some details may be redacted to protect confidential or security-sensitive information.
8. Cookies and Similar Technologies
We use cookies and similar technologies for essential security and session functions, interface preferences, and—only after consent—website analytics. Our consent tool allows you to accept or reject non-essential technologies and change your choice later.
See the Cookie Policy for the current inventory, purposes, providers, and retention periods.
9. Data Security
We use appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include access controls, encrypted transport, service monitoring, and security protections appropriate to the nature of the data and risk.
No online service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate account permissions, and notifying us promptly if you suspect unauthorized access.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services and meet legal, accounting, security, and dispute-resolution requirements. The criteria we use include the nature and sensitivity of the data, the customer relationship, account status, legal limitation periods, statutory record-keeping duties, security needs, and whether the data can be safely aggregated or anonymized.
In practice:
- account, subscription, and project data is generally retained while the account or customer relationship is active and for a limited period afterwards where needed for support, security, recovery, or legal claims;
- audit and contact enquiries are retained while we respond and, where relevant, for reasonable business relationship and record-keeping purposes;
- transaction and invoice records are retained for applicable tax, accounting, and legal periods;
- consent and preference records are retained long enough to demonstrate and respect your choice;
- security logs are retained for a limited period proportionate to investigation and prevention needs; and
- backups are removed or overwritten in accordance with our backup cycle.
When retention is no longer justified, data is deleted, de-identified, or securely isolated until deletion from backups.
11. Automated Analysis and AI-Generated Outputs
Brantial uses automated systems and AI models to analyze domains, prompts, search visibility, and connected data, and to generate scores, reports, recommendations, or content. These outputs may be incomplete or inaccurate and should be reviewed by a person before being relied upon.
Brantial does not use these features to make solely automated decisions about individuals that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by applicable law before the processing begins.
12. Your Data Protection Rights
Depending on applicable law and the circumstances, you may have the right to:
- request access to your personal data and information about how it is used;
- request correction of inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive certain data in a structured, commonly used, machine-readable format and transmit it to another controller;
- withdraw consent at any time; and
- complain to a competent data-protection authority.
These rights are not absolute, and a legal exception may apply. We may need to verify your identity and clarify the scope of your request. We will respond within the period required by applicable law and will explain any lawful reason why we cannot fully comply.
To exercise a right, email hello@brantial.ai. If we process the relevant data solely for one of our business customers, we may refer the request to that customer.
If you are in the United Kingdom, you may complain to the Information Commissioner’s Office. If you are in the EEA, you may contact your local supervisory authority. Rights available under Turkey’s KVKK, including the rights set out in Article 11, may be exercised through the procedures required by that law.
13. Questions, Complaints, and Policy Updates
Questions, privacy requests, and complaints may be sent to hello@brantial.ai or by post to the registered office listed in Section 1. Please contact us first so we have an opportunity to address your concern.
We may update this Policy when our Services, providers, or legal obligations change. We will publish the revised version with a new effective date and, where a change materially affects your rights or our use of personal data, provide additional notice where required.