Privacy Policy
BROSBRAIN LTD · brosbrain.guru · United Kingdom · Last updated: 17 July 2026
1. Introduction and Controller Details
This Privacy Policy explains how BROSBRAIN LTD (“we”, “us”, “our”) collects, uses, stores, shares and protects personal data when you visit https://brosbrain.guru, submit an enquiry, communicate with our Birmingham desk, or otherwise engage with our digital commerce platform services. BROSBRAIN LTD is the data controller for personal data collected through the Site unless a separate engagement agreement states otherwise.
We are a United Kingdom company providing digital commerce platforms, online store development, marketplace platform development, retail software development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, web application development, mobile commerce applications, custom computer programming services, computer systems design and related services, and IT consulting services.
Our registered operating address for privacy correspondence is 618 Washwood Heath Road, BIRMINGHAM, B8 2HG United Kingdom. Privacy enquiries should be sent to assist@brosbrain.guru. You may also telephone +44 7934 667700 during business hours.
This Policy is designed to meet expectations under the UK GDPR and the Data Protection Act 2018, and to provide transparent notice to individuals located in the United Kingdom. If you are outside the United Kingdom, local laws may provide additional rights; we will honour mandatory local rights where they apply to our processing.
2. Scope of this Policy
This Policy applies to personal data processed in connection with the public website, enquiry forms, email and telephone communications, meeting scheduling, marketing preferences where lawfully established, supplier onboarding for website operations, and limited analytics necessary to understand Site performance.
This Policy does not replace client contracts for delivery of commerce platforms. Where we process personal data on behalf of a client as a processor, the processing agreement and statement of work govern that activity. Where we act as an independent controller for our own business operations, this Policy and applicable law govern.
Children are not the intended audience of the Site. We do not knowingly collect personal data from individuals under 16 through the Site. If you believe a child has provided personal data, contact assist@brosbrain.guru so we can delete it where appropriate.
3. Categories of Personal Data
Depending on how you interact with us, we may process identity and contact data such as name, business role, company name, email address, telephone number and postal address; enquiry content including project descriptions, system landscapes and commercial objectives; technical data such as IP address, browser type, device type, referring URL, pages viewed and approximate location derived from IP; communication records including emails and call notes; and preference data regarding how you wish to be contacted.
We do not seek special category data through the public Site. Please do not submit health, biometric, political, religious or similarly sensitive information in the enquiry form. If such information is unexpectedly received, we will assess whether deletion or restricted handling is required.
Payment card data is not collected through the public website enquiry form. Any payment processing for contracted services occurs through agreed commercial channels with appropriate safeguards.
4. Sources of Personal Data
We collect personal data directly from you when you submit forms, email us, call us, attend meetings, or provide business cards or introductions. We may receive personal data from your colleagues when they include you in project correspondence. We may collect limited technical data automatically through cookies and similar technologies as described in our Cookie Policy. We may receive business contact details from reputable networking contexts where sharing is lawful and expected.
We do not purchase marketing lists of individuals for unsolicited email campaigns through the Site.
5. Purposes and Lawful Bases
We process personal data to respond to enquiries and provide requested information (legitimate interests and/or steps prior to entering a contract); to perform contracts for digital commerce services (contractual necessity); to operate, secure and improve the Site (legitimate interests); to comply with legal obligations such as accounting, tax and regulatory duties (legal obligation); to establish, exercise or defend legal claims (legitimate interests); and, where required, to send optional updates only with consent or soft opt-in where permitted by PECR.
Legitimate interests assessments consider your reasonable expectations as a business contact enquiring about commerce platforms, the necessity of the processing, and safeguards such as limited retention and access controls.
You may object to processing based on legitimate interests where the law allows. Contact assist@brosbrain.guru with sufficient detail for us to assess the objection.
6. Enquiry Form Processing
When you submit the contact form, we process your name, email address and message to route the enquiry to the appropriate service desk section, evaluate fit, and reply with next steps. Messages may be stored in email systems and internal tracking tools used by BROSBRAIN LTD staff.
Do not include passwords, full payment card numbers, or confidential third-party data belonging to others without authority. If your enquiry concerns an existing project, include any issue code so we can maintain continuity without unnecessary data sprawl.
7. Sharing and Recipients
We share personal data only where necessary with service providers who support email hosting, website hosting, security monitoring, analytics (if enabled), professional advisers, and authorities where legally required. Providers are engaged under written terms requiring confidentiality and appropriate security.
We do not sell personal data. We do not share personal data with unrelated third parties for their independent marketing.
If a corporate transaction such as a merger or asset transfer is contemplated, personal data may be disclosed under confidentiality protections as part of due diligence and transferred subject to applicable law.
8. International Transfers
BROSBRAIN LTD is based in the United Kingdom. Some processors may store or access data in other countries. Where personal data is transferred outside the UK, we implement appropriate safeguards such as the UK International Data Transfer Agreement, addendum to EU SCCs as recognised in the UK, or transfers to countries covered by UK adequacy regulations, unless a specific derogation under UK GDPR applies.
Details of relevant transfer mechanisms for a given processor can be requested via assist@brosbrain.guru.
9. Retention
Enquiry records are retained for as long as needed to complete correspondence and for a reasonable period afterward to maintain business continuity and defend legal claims, typically up to twenty-four months unless a longer period is required for an active matter. Contract and accounting records are retained according to UK statutory periods. Technical logs are retained for shorter operational windows unless needed for security investigations.
When retention ends, data is deleted or anonymised in a manner consistent with our systems’ capabilities.
10. Security Measures
We apply organisational and technical measures appropriate to the risk, including access control on a need-to-know basis, secure transmission where supported, staff awareness, vendor due diligence, and incident response procedures. No method of transmission or storage is perfectly secure. If you suspect unauthorised use of your information in connection with our Site, contact us promptly.
11. Your Rights
Under UK GDPR you may have the right to access personal data; rectify inaccuracies; erase data in certain circumstances; restrict processing; object to processing based on legitimate interests or direct marketing; data portability for data provided by you and processed by automated means on consent or contract bases; and withdraw consent where processing is consent-based.
To exercise rights, email assist@brosbrain.guru with enough information to verify your identity and locate the data. We will respond within statutory timeframes. You may lodge a complaint with the Information Commissioner’s Office (ICO) in the United Kingdom.
12. Automated Decision-Making
We do not use solely automated decision-making, including profiling, that produces legal or similarly significant effects concerning individuals who visit the Site or submit enquiries.
13. Marketing Communications
We do not add enquiry submitters to marketing lists by default. If we offer optional updates about digital commerce services, we will do so in compliance with PECR and UK GDPR. You may unsubscribe using the method provided in any such message or by emailing assist@brosbrain.guru.
14. Third-Party Links and Maps
The Site may embed Google Maps or link to third-party resources. Those services have their own privacy practices. We are not responsible for third-party privacy controls. Review their policies before interacting with embedded tools beyond what is necessary.
15. Changes to this Policy
We may update this Privacy Policy to reflect legal, technical or operational changes. The updated version will be posted on this page with a revised date. Material changes affecting existing clients may also be communicated through contractual channels.
16. Contact for Privacy Matters
BROSBRAIN LTD, 618 Washwood Heath Road, BIRMINGHAM, B8 2HG United Kingdom. Email: assist@brosbrain.guru. Telephone: +44 7934 667700. Website: https://brosbrain.guru.
Supplementary notice on commerce platform engagements (1432)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (1646)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (1860)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (2074)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (2288)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (2502)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (2716)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (2930)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (3144)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (3358)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (3572)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (3786)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (4000)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (4214)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (4428)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (4642)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.
Supplementary notice on commerce platform engagements (4856)
Where BROSBRAIN LTD provides digital commerce platforms, online store development, marketplace platform development, inventory management systems, payment gateway integration, CRM solutions, cloud computing services, API development and integration, mobile commerce applications, custom computer programming services, computer systems design and related services, or IT consulting services, personal data processed for project delivery is handled according to the roles defined in the engagement documents. Clients remain responsible for ensuring they have a lawful basis to provide end-customer data to BROSBRAIN LTD when such data is necessary for implementation, testing or support. Test environments should use anonymised or synthetic data wherever practicable. Access to production personal data is limited to personnel and subprocessors who need it for the agreed purpose, logged where systems allow, and withdrawn when the purpose ends. Security questionnaires, penetration testing and audit rights, if any, are governed by contract rather than this public Policy. Individuals whose data appears in client systems should generally contact the client as controller for storefront or marketplace end-user rights requests, unless BROSBRAIN LTD is independently the controller for that dataset. This supplementary notice is intended to reduce ambiguity between website privacy practices and project delivery privacy practices for UK organisations working with BROSBRAIN LTD from Birmingham and across the United Kingdom.