Privacy Notice
Version 3.0 · Last updated 14 August 2026
This notice covers both the Braingine website and the Braingine platform deployed at customer sites. If you are in Mexico, read it together with our Aviso de Privacidad, which sets out your ARCO rights under the LFPDPPP.
1. Who we are
Braingine SAPI de CV, Terra Business Park 83A, 88B, 89B, El Marqués, Santiago de Querétaro, Querétaro, Mexico, with an office in Zürich, Switzerland.
Privacy Officer / Data Protection Officer: [email protected] · AI ethics enquiries: [email protected] · +52 (442) 223-2315
2. The two roles we act in
This determines who decides what happens to your data, and who you should contact.
- We are the controller for our website, marketing, sales, support and recruitment. Contact us directly.
- We are the processor for AI video analysis running at a customer’s site. The site operator is the controller — not Braingine. Their notice and contact details are posted at the site. We act only on their documented instructions under a written data processing agreement, and we will pass on any request we receive.
3. What we collect
Website and enquiries (we are controller):
- Contact details you provide through demo requests and contact forms — name, email, telephone, company, role
- Technical data collected automatically — IP address, browser type and version, pages visited, referral source, dates and times, device identifiers
- Information provided during sales conversations and implementation engagements
Deployed platform (the site operator is controller):
- Video imagery — processed on the edge device at the site. Raw video is not transmitted to Braingine or to any cloud service.
- Event metadata — detections, counts, timestamps, zone, alert type
- Biometric feature vectors — numeric representations used to follow the same person between cameras at one site, segregated per customer and purged on the retention schedule
- Estimated characteristics — approximate age range and estimated sex, where the operator has enabled that capability
We do not collect or store payment card details. Payments are handled by third-party processors under PCI-DSS.
4. Capabilities that are off by default
Biometric identification, biometric categorisation (age and sex estimation) and cross-camera re-identification are disabled on delivery. They are enabled only at the operator’s written request, against a recorded legal basis and a completed impact assessment.
What our systems never do. They do not infer emotions, mood, stress, attention or attitude — that capability has been withdrawn from our catalogue and we will not supply it. They do not perform social scoring. They do not make automated decisions producing legal or similarly significant effects: every alert is reviewed by a person before action is taken. See our AI transparency page.
5. Special category data
Where a feature vector or an age or sex estimate is used to single out or distinguish a specific individual, it is biometric data — a special category of personal data under GDPR Article 9 and sensitive personal data under Mexican law. It is processed only where the site operator has established a valid Article 9(2) condition, and only within the site where it was captured.
6. Legal bases
Where the GDPR applies we rely on: performance of a contract; our legitimate interests in operating, securing and improving our services; consent, for marketing and for non-essential cookies; and compliance with legal obligations. You can ask us which basis applies to a specific processing activity.
7. Who we share data with
We share with service providers who help us operate, under confidentiality and data processing obligations:
- Cloudflare — content delivery, TLS, bot protection and DDoS mitigation for this site and our blog. Cloudflare processes the IP address and request metadata of every visitor, and runs the anti-abuse check on our demo form.
- Automattic (Akismet) — comment spam filtering on our blog.
- Payment processors, professional advisers and auditors, for the purposes those imply.
We may also disclose where required by law or valid legal process, and in connection with a merger or asset sale, with notice beforehand.
We do not sell personal data and we do not share it for cross-context behavioural advertising. Customer video and event data is never shared between customers.
8. International transfers
Mexico is not covered by a European Commission adequacy decision. Transfers of personal data from the EEA to Braingine in Mexico are made under the European Commission’s Standard Contractual Clauses, with a transfer impact assessment and the technical measures described in section 11. Switzerland benefits from an adequacy decision, so transfers to our Zürich office need no additional mechanism.
In deployed systems, customer production data resides and is processed within the customer’s own territory, on the customer’s own equipment, by default. Any exception is explicit and contractual.
9. How long we keep data
- Enquiry and contact records — 24 months from last contact
- Customer relationship records — duration of the contract plus the applicable limitation period
- Marketing subscriptions — until you unsubscribe; a suppression record is then kept so we do not contact you again
- Website usage data — 14 months
- Records of privacy requests — 5 years, with full traceability
- Raw video at customer sites — set by the site operator. Braingine does not retain raw video.
- Event metadata and feature vectors — set by the site operator in the data processing agreement, then purged automatically
10. Your rights
Where the GDPR applies you may access your data, have it rectified or erased, restrict or object to processing, object to direct marketing at any time, receive your data in a portable format, and withdraw consent at any time. In Mexico you hold ARCO rights — see the Aviso de Privacidad. California residents may know, access, correct, delete, opt out of sale or sharing, and limit the use of sensitive personal information; we honour the Global Privacy Control signal.
To exercise any right, write to [email protected]. We may ask you to verify your identity. We respond within 20 calendar days under Mexican law and within 30 days under the GDPR. You may also complain to your local supervisory authority — we would appreciate the chance to address your concern first.
11. Cookies and tracking
On this site we run no analytics and no advertising trackers. It sets no analytics cookies and loads no third-party fonts, scripts or images. The only third-party processing is Cloudflare, which sits in front of the site for security and delivery and may set a strictly necessary cookie or run a browser integrity check to distinguish visitors from automated traffic. Our demo form additionally runs Cloudflare Turnstile to block spam.
On blog.braingine.ai we use WP Statistics, a self-hosted visitor-statistics tool — the data stays on our own server and is not shared with an analytics provider. A cookie banner there lets you accept or reject non-essential cookies.
We honour the Global Privacy Control signal as a withdrawal of consent to non-essential cookies and an opt-out of sale and sharing.
12. Security
We protect personal data under our Information Security Policy: encryption in transit and at rest, role-based and privileged access control, network segmentation, hardened edge devices, centralised logging, and incident response with breach notification within 72 hours. Our architecture minimises exposure — raw video is processed on site and does not leave it. No transmission or storage system is completely secure, and we cannot guarantee absolute security.
13. Changes
We post any updated notice on this page with a new version and date. Where a change is material we will notify you by email or a prominent notice on the service before it takes effect.
