Who we are and our role
Bravery Technology Ltd (referred to as Bravery, we, or us) is a company registered in England and Wales that operates usebravery.com and the usebravery platform. Our registered office and full company details are available on request and through the contact channels at the end of this policy.
For personal data we process about you in connection with usebravery.com and the customer panel, including your account, billing, and use of the service, Bravery is the data controller under the UK GDPR and the Data Protection Act 2018.
For an end customer's published site and its visitors, the customer is the data controller and Bravery acts as a data processor on the customer's behalf, processing personal data only on the customer's documented instructions and under a data processing agreement. If you are a visitor to a site we host, the operator of that site is responsible for its privacy practices.
Personal data we collect
We collect the account information you provide, which includes your name and email address, and authentication metadata associated with your passwordless email one-time code (OTP) and optional TOTP two-factor authentication, such as login times and security events.
We collect billing information processed through Stripe in order to take payment. We do not store full card numbers; Stripe handles card details and provides us with limited information needed to manage your subscription, such as billing status and the last digits of your card.
We collect the configuration of your site, including your domain settings, catalogue, and content, together with provisioning and usage logs generated as we set up and operate your isolated server, and the records of any support communications you have with us.
On our marketing website we collect analytics and similar data through cookies, but only where you have given consent. This may include data gathered through Google Analytics 4 and PostHog. Strictly necessary cookies operate without consent because they are required for the site to function.
How we use personal data
We use personal data to provide and operate the service, including provisioning and running your isolated site, managing your account, and authenticating you securely; to process billing and subscriptions; and to maintain the security of the platform and to prevent and detect fraud and abuse.
We also use personal data to provide customer support, to send service communications such as transactional emails, security notices, and important updates about your subscription, and to comply with our legal, tax, and regulatory obligations.
In addition, we use aggregated and individual usage information to understand how the service is used and to improve it, and, where you have given consent, to send marketing communications and to measure the performance of our marketing website.
Our legal bases for processing
Under Article 6 of the UK GDPR we rely on the performance of a contract to provide and operate the service, manage your account, authenticate you, and process your subscription and billing, because this processing is necessary to deliver the service you have asked for.
We rely on our legitimate interests to keep the platform secure, prevent and investigate fraud and abuse, maintain provisioning and usage logs, provide support, and improve the service, having balanced those interests against your rights and freedoms. Where the balance does not favour us, we rely on another basis or seek your consent.
We rely on compliance with a legal obligation to retain billing, tax, and certain account records and to respond to lawful requests from authorities. We rely on your consent for non-essential analytics and cookies on our marketing website and for any direct marketing, and you may withdraw that consent at any time without affecting processing carried out before withdrawal.
International transfers
Some of our sub-processors may process personal data outside the United Kingdom. Where this happens, we ensure that the transfer is protected by an appropriate safeguard under Chapter V of the UK GDPR.
Depending on the recipient and country, we rely on UK adequacy regulations that recognise a country as providing an adequate level of protection, or on the International Data Transfer Agreement (IDTA) or the UK Addendum to the European Commission's standard contractual clauses (SCC), supplemented where appropriate by additional technical and organisational measures.
You can request further information about the specific transfer mechanism that applies to a given sub-processor through the contact channels at the end of this policy.
How long we keep personal data
We keep account data for as long as your account is active and for a reasonable period after closure to deal with follow-up queries, resolve disputes, and enforce our agreements, after which it is deleted or anonymised.
We keep provisioning, usage, and security logs for a limited period appropriate to their purpose, such as protecting the platform and investigating incidents, and we then delete or anonymise them.
We keep billing, tax, and other records for as long as required by applicable law, which is typically several years for financial and tax records. Where personal data is no longer needed for any lawful purpose, we securely delete or anonymise it.
Your rights
Under the UK GDPR and the Data Protection Act 2018 you have the right to access the personal data we hold about you, to have inaccurate data rectified, and to have your data erased in certain circumstances. You also have the right to restrict or object to certain processing and the right to data portability for data you have provided to us.
Where we rely on your consent, for example for analytics cookies or marketing, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact us through the channels below, and we will respond within the time limits set by law. If you are a visitor to a site we host on behalf of a customer, you should contact that customer as the controller, and we will assist them as their processor.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the United Kingdom's supervisory authority, although we would welcome the chance to address your concerns first.
How we protect personal data
We use a range of technical and organisational measures to protect personal data, including encryption of data in transit using TLS, encryption of sensitive data at rest, and an architecture in which each tenant runs on its own isolated server, which limits the impact of any single incident.
We support two-factor authentication (TOTP), apply access controls and the principle of least privilege to our systems, log security-relevant events, and maintain backups to support recovery. We review and update these measures as the service and the threat landscape evolve.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO and, where required, affected individuals in accordance with our legal obligations.
Children
The service is intended for business use by adults and is not directed to children under the age of 16. We do not knowingly collect personal data from children.
If you believe that a child has provided us with personal data, please contact us using the channels below and we will take appropriate steps to delete that data.
As a customer, you are responsible for ensuring that any site you operate is itself appropriate for its intended audience and complies with applicable laws relating to children.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the service, to our practices, or to legal and regulatory requirements. The effective date of the current version is shown on this page.
Where changes are material, we will provide reasonable notice, for example by email or through the platform, before they take effect.
We encourage you to review this policy periodically so that you stay informed about how we handle personal data.
Contact us
If you have any questions about this policy or wish to exercise your rights, please reach us through our contact page or by email at [email protected].