GDPR Compliance
Last updated: 16 June 2026
Braio.ai is built for organizations that operate under the EU General Data Protection Regulation (GDPR). Our infrastructure and customer data are hosted in the European Union, and the Services are designed around data minimization, transparency, and human approval. This statement summarizes how we support your GDPR obligations.
1. Roles
For personal data you submit through the Services, you are typically the data controller and Braio acts as the data processor, processing it on your documented instructions. For data we collect about your use of our website, Braio is the controller (see our Privacy Policy).
2. Data Processing Agreement (DPA)
We make a GDPR-compliant Data Processing Agreement available to customers, including the European Commission’s Standard Contractual Clauses where relevant. Contact team@braio.ai to execute a DPA.
3. EU hosting and data residency
Customer data is stored and processed within the European Union. Where any processing outside the European Economic Area is necessary, we rely on appropriate safeguards such as Standard Contractual Clauses and additional technical measures.
4. Sub-processors
We engage a limited set of vetted sub-processors under written agreements that impose GDPR-equivalent obligations. A current list of sub-processors, and a mechanism to be notified of changes, is available on request.
5. Data subject rights
We support your ability to fulfil data subject requests — access, rectification, erasure, restriction, portability, and objection. As a processor, we assist you in responding to such requests relating to data processed on your behalf.
6. Security measures
We implement technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access controls, audit logging, and least- privilege access. Human approval is required before Braio acts, reducing the risk of unintended automated processing.
7. Data breach notification
We maintain incident response procedures and will notify affected customers without undue delay after becoming aware of a personal data breach affecting their data, consistent with GDPR requirements.
8. International transfers
Where transfers outside the EEA occur, we use the European Commission’s Standard Contractual Clauses and assess supplementary measures to maintain an essentially equivalent level of protection.
9. Contact and Data Protection
For GDPR enquiries, DPAs, or to reach our data protection contact, email team@braio.ai. You also have the right to lodge a complaint with your local supervisory authority.