Legal

Privacy and data processing

Information handling during website research, checkout, video production, delivery and support. Service: BrandCapture.

Last updated: 19 July 2026

1. Controller and scope

The service operator identified below is the controller for data collected through this website and the video production service. When a customer submits personal data about other people, that customer is responsible for having a lawful basis and giving required notices.

Definitions

Data Protection Laws encompass all applicable laws, regulations and frameworks governing the collection, processing, storage, transfer and protection of Personal Data — including, but not limited to, the General Data Protection Regulation (GDPR) of the European Union, the UK GDPR, the California Consumer Privacy Act (CCPA) and any other national or international privacy laws relevant to data processing under this Agreement.

Personal Data refers to any information relating to an identified or identifiable natural person (“Data Subject”). Personal Data excludes anonymised or aggregated data that cannot be used to identify an individual.

Processing means any operation or set of operations performed on Personal Data, whether by automated means or manually — including collecting, recording, organising, structuring, storing, adapting, altering, retrieving, consulting, using, disclosing, transmitting, restricting, erasing or destroying Personal Data.

Data Subject Rights refer to the rights granted to individuals under applicable Data Protection Laws, including access, rectification, deletion, restriction, portability, objection and the right to lodge complaints with a Supervisory Authority.

Authorized Sub-Processor means any third-party vendor, service provider or contractor engaged by BrandCapture to process the Customer's Personal Data strictly on behalf of and under the instructions of BrandCapture. All Sub-Processors must comply with the same data protection obligations, maintaining security, confidentiality and regulatory compliance.

Account Data refers to all business-related information collected, stored and processed by BrandCapture in relation to its contractual relationship with the Customer. This includes names, email addresses, phone numbers, payment details and access credentials of individuals authorised by the Customer to manage and operate their account on the platform. Account Data is used strictly for administrative, billing and support purposes.

2. Information we process

  • Contact, business and billing details, including name, company, email, phone, country and invoice information.
  • Creative briefs, instructions, messages, approvals, revision notes and support conversations.
  • Uploaded logos, images, video, audio, documents and other production assets.
  • Public business website content and technical results needed to prepare the creative plan.
  • Payment status and transaction references; full card details are handled by the payment provider and are not stored by us.
  • Security, device, request and service logs. Optional audience analytics are collected only after analytics consent.

3. Why we use it and legal bases

  • To provide a requested plan, perform the order, produce and deliver files, manage revisions, issue invoices and provide support—necessary for the contract or steps requested before it.
  • To secure the service, prevent abuse, maintain records, improve reliability and defend legal claims—our legitimate interests, balanced against individual rights.
  • To meet tax, accounting, consumer, sanctions and other legal duties—compliance with law.
  • To send optional marketing or run optional audience analytics—consent where required. Consent can be withdrawn at any time without affecting earlier lawful processing.

4. Website research and public data

The scanner accesses only publicly reachable pages from the website submitted by the user. We use that content to understand the business and draft a private creative plan. We do not treat public availability as permission to republish third-party personal data in a video.

5. Business contact and direct marketing

We may use a publicly listed business address or a lawfully supplied business-contact database to send a limited, relevant introduction to this service where local law permits. The source may be a company website, public business register or a provider that represents it may lawfully supply the information. We record delivery and objection status so an address that opts out is not contacted again for marketing.

You may object to direct marketing at any time and at no cost by using the link in the message or contacting us. After an objection, we stop using the address for direct marketing; we may retain a minimal suppression record solely to respect that choice. Electronic-marketing rules differ by country, and a message is sent only where the configured market rules allow it.

6. AI-assisted processing

Selected brief content, public website text or production assets may be sent to configured AI and media providers when needed for research, scripting, voice, imagery, translation, editing or quality checks. We minimise the data sent and use provider controls available to the service. Do not include unnecessary sensitive data. Unless a human recording is expressly agreed, the voice-over may use a synthetic AI voice rather than a recording of a real person.

We do not use a solely automated decision that produces legal or similarly significant effects for the customer. A person controls the production decision and reviews proofs before delivery.

7. Recipients and processors

Data is shared only as needed with infrastructure and hosting providers, content delivery and security services, payment processors, email providers, private file storage, professional advisers, and configured AI or media production providers. Providers act under their own terms or processing commitments, as applicable.

We may disclose information when lawfully required, to protect people or the service, or as part of a business transfer with appropriate safeguards. We do not sell personal data.

5. Sub-processors

BrandCapture engages third-party Sub-Processors to assist in providing and maintaining the service. These Sub-Processors perform specific functions such as infrastructure hosting, payment processing, transactional email and security. We ensure that all engaged Sub-Processors adhere to data-protection obligations equivalent to those outlined in this DPA, backed by signed agreements.

An up-to-date list is available on request from [email protected]. Current Sub-Processors include (but are not limited to):

  • Stripe — payment processing, invoicing and fraud screening.
  • Mailgun — transactional and notification email delivery.
  • Cloudflare — CDN and DDoS protection.
  • Managed-database providers — encrypted at-rest storage for application data.

8. International transfers

Some providers may process data outside your country or the European Economic Area. Where required, we rely on an adequacy decision, standard contractual clauses or another lawful transfer mechanism, with supplementary safeguards where appropriate.

BrandCapture may transfer Personal Data outside the European Economic Area (EEA), the United Kingdom or Switzerland to facilitate the provision of services. When such transfers occur, we ensure appropriate legal safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission or other competent authorities.
  • Supplementary Measures — additional technical, organisational and contractual safeguards.
  • Other Approved Transfer Mechanisms recognised under applicable law.

9. Retention

We keep information only for as long as needed for the project, delivery, support, security and legal obligations. Retention depends on the record: unsuccessful enquiries are removed when no longer useful; production assets are kept for the active workflow and a reasonable support/download period; invoices and transaction records are retained for the statutory accounting period; dispute and security records are retained while a claim or risk remains relevant. Final deliverables and active production assets are normally kept available for 90 days after final delivery.

BrandCapture retains Personal Data only for as long as necessary to fulfil its obligations under this Agreement or as required by applicable laws. We follow data-minimisation principles: data is retained only for legitimate business and compliance needs, and is deleted or anonymised once no longer necessary.

Customers may request deletion of Personal Data at any time. Upon termination of services, BrandCapture will delete or return Personal Data in accordance with the Customer's instructions. If no deletion request is made, Personal Data is automatically deleted within a reasonable timeframe unless legal retention requirements apply (tax records, fraud-prevention investigations, etc.).

10. Security

We use access controls, private storage, token-protected customer pages, transport encryption, validation and operational monitoring. You must protect private project links and tell us promptly if one is exposed. No method of storage or transmission can be guaranteed completely secure.

11. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent. You may also complain to your local data protection authority. We may need to verify identity before acting.

  • Right of Access — confirmation of whether data is being processed and access to it.
  • Right to Rectification — correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”) — deletion of Personal Data, subject to legal and contractual obligations.
  • Right to Restrict Processing — limiting the processing of Personal Data under certain conditions.
  • Right to Data Portability — obtaining and transferring Personal Data to another controller where technically feasible.
  • Right to Object — to processing based on legitimate interests, direct marketing or automated decision-making.
  • Right to Withdraw Consent — at any time if processing is based on consent.

We respond without undue delay and normally within one month under the GDPR. That period may be extended for complex or numerous requests where the law permits, and we will explain any extension.

12. Children

This business service is not directed to children and is not intended for orders by people who cannot enter a binding contract.

13. Changes and contact

We may update this notice when the service or legal requirements change. The current version and revision date are published here. Privacy contact: [email protected].