Privacy Policy
Effective date: April 2026.
Privacy Policy
This Privacy Policy explains how Brandlight Inc. and its affiliates ("Brandlight", "we", "us", or "our") collect, use, disclose, store, transfer, and otherwise process personal data in connection with our websites, platform, and related services (collectively, the "Services"). It describes the categories of personal data we process, the purposes and legal bases for processing (where applicable), the categories of recipients with whom we may share personal data, international transfer practices, retention, and the rights available to individuals under applicable data protection laws.
Scope of Data Processed by Brandlight
Brandlight’s platform primarily analyzes and processes publicly available information, including publicly accessible web content and system-generated outputs derived from such information. We do not seek to collect or infer sensitive personal data (such as health, biometric, precise geolocation, or government identifiers) as part of our core Services.
Brandlight does not intentionally ingest customer proprietary or confidential information as part of its core service offering, except where such information is expressly provided by or on behalf of a customer for a permitted purpose (for example, account administration, support, configuration, or enablement of requested features), or is otherwise processed in accordance with applicable law and applicable contractual arrangements. Customers are responsible for ensuring they have the necessary rights and lawful basis to provide any personal data to Brandlight for processing.
The personal data processed directly by Brandlight generally consists of limited business contact and account information, such as name, business email address, company affiliation, authentication identifiers, and related access-management data, which are processed for user authentication, account administration, security, and service delivery, including through our authentication provider where applicable.
Who This Privacy Policy Applies To
This Privacy Policy applies to individuals who access or use our Services, communicate with us, subscribe to marketing communications, communicate with us, apply for a role with us, refer candidates to us, or otherwise interact with Brandlight in a business or professional context.
What personal data do we collect and how do we use it?
Depending on how you interact with us, we may collect and process the following categories of personal data (some of which may be considered "personal information" or similar terms under applicable law):
- Account Information: When you register for or access our Services, we may collect limited account information such as your name, business email address, company affiliation, role, and authentication-related data in order to create and manage your account, provide access to the platform, verify authorized use, and maintain the security of our Services.
- Profile Information: If you create or maintain a user profile, we may collect the information you choose to provide in that profile, such as a display name, profile preferences, and other optional account details, for the purpose of administering your profile and improving your user experience.
- Sign-In Information: If you choose to sign in through a Single Sign-On (SSO) provider, such as Google, Microsoft, or another identity provider, we may receive certain profile and authentication information from that provider in accordance with your settings with the provider and the permissions granted during the sign-in process. We do not control the SSO provider's processing of your personal data.
- Third-Party Service Information: If you connect our Services with a third-party service, we may receive or share limited information necessary to enable the integration, maintain functionality, authenticate access, or support the requested features, subject to the applicable privacy settings, contractual terms, and legal requirements.
- Communications and Live Chat Information: If you contact us, including through a live chat function, email, or other support channel, we may collect your name, contact details, the content of your communication, and related technical or contextual information in order to respond to your request, provide support, improve our Services, and maintain appropriate records. Where required by law, we will obtain consent before recording calls or accessing the content of communications.
- Newsletter and Marketing Information: If you subscribe to our newsletter or otherwise agree to receive marketing communications, we may collect your email address and related marketing preferences in order to send you updates, insights, and promotional communications. You may opt out at any time.
- Other Information You Choose to Provide: We may collect additional personal data that you voluntarily provide to us through our website, forms, events, surveys, webinars, business correspondence, job applications, referral submissions, or other interactions with Brandlight. Please do not provide sensitive personal data unless we specifically request it and you have a lawful basis to provide it.
Recruitment and Job Application Data
If you apply for a job with us, we may collect the personal data you provide as part of your application and throughout the recruitment process. This may include your name, contact details, resume or CV, cover letter, academic and professional qualifications, employment history, skills, references, compensation expectations, work authorization information, and any other information you choose to provide or that we may lawfully request. We may also review information that is publicly available and relevant to your application, such as information on professional networking platforms. If you submit an application through a third-party platform such as LinkedIn, we may receive the personal data you make available through that platform.
We process recruitment-related information to assess your candidacy, communicate with you about the recruitment process, schedule interviews, verify information you provide, conduct lawful screening where permitted, improve our hiring procedures, protect our legal interests, and comply with applicable legal and regulatory obligations. Where permitted by law, we may retain candidate information for a reasonable period after the recruitment process in order to consider candidates for future opportunities.
If you refer a candidate to us through an employee referral program or another referral arrangement, we may collect personal data relating to the referral. This may include your name, contact details, your relationship to the referred candidate, the candidate's contact and professional details that you submit, and any payment or tax information necessary to administer a referral fee if the referral results in a successful hire, subject to the terms of the applicable program. You represent that you have informed the referred candidate about the referral and are authorized to provide their personal data to us, or that you otherwise have a valid legal basis to do so under applicable law.
- Usage and Technical Information: We may automatically collect limited technical and usage information, such as IP address, device type, browser type, operating system, log data, timestamps, approximate location derived from IP address, pages or features accessed, and other diagnostic information, to operate, secure, maintain, troubleshoot, and improve our website and platform. Where required by applicable law, we will provide appropriate notice and choices regarding cookies and similar technologies.
How We Use Personal Data
We use personal data as necessary to: (a) provide and administer our Services; (b) authenticate users; (c) communicate with users and business contacts and respond to inquiries; (d) operate integrations and process transactions you request; (e) support recruitment and referral activities; (f) improve and develop our website and platform; (g) maintain security, prevent misuse, and detect and prevent fraud; (h) send marketing communications where permitted; (i) enforce our terms and policies; and (j) comply with applicable legal, regulatory, and contractual obligations.
Legal Bases for Processing
Where required by applicable law, we process personal data only where we have a valid legal basis to do so, including where processing is necessary to perform a contract with you or your organization, to take steps at your request prior to entering into a contract, to comply with a legal obligation, to protect vital interests, to pursue our legitimate interests (or those of a third party) where those interests are not overridden by your rights and freedoms, or based on your consent where consent is required. Where we rely on legitimate interests, we consider and balance any potential impact on individuals and their rights.
How do we share personal data?
We may disclose personal data, subject to applicable law and appropriate safeguards, to the following categories of recipients where necessary for the purposes described in this Privacy Policy. We do not sell personal data, and we do not share personal data for cross-context behavioral advertising as those terms may be defined under applicable law.
- Corporate Affiliates: We may share personal data with our parent company, subsidiaries, and other affiliates for internal administrative purposes, service delivery, security, compliance, business operations, and corporate governance.
- Service Providers: We may share personal data with third-party vendors, contractors, and service providers that perform services on our behalf, such as hosting, cloud infrastructure, analytics, authentication, customer support, communications, recruitment support, security, and IT administration. These parties are authorized to process personal data only as necessary to provide services to us and pursuant to contractual restrictions, including confidentiality and, where required, data processing terms.
- Professional Advisors: We may disclose personal data to professional advisors such as external legal counsel, auditors, insurers, accountants, consultants, and bankers where necessary to obtain advice, manage risk, protect our interests, or support corporate transactions.
- Compliance, Fraud Prevention, and Safety: We may disclose personal data to courts, regulators, law enforcement authorities, government bodies, or other third parties where we believe disclosure is required or appropriate to comply with law, enforce our terms, detect or prevent fraud or security incidents, or protect the rights, property, safety, or security of Brandlight, our users, or others.
- Business Transactions: Personal data may be disclosed or transferred in connection with an actual or proposed merger, acquisition, financing, reorganization, sale of assets, insolvency event, or other corporate transaction. We will use reasonable efforts to ensure appropriate confidentiality protections are in place and, where required by applicable law, provide notice to affected individuals.
International Data Transfers
Personal data may be transferred to, stored in, or accessed from countries outside the jurisdiction in which you are located, including by our affiliates and service providers. Where required by applicable law, we implement appropriate safeguards for such transfers, which may include entering into standard contractual clauses (or other approved contractual mechanisms), conducting transfer impact assessments where required, and implementing supplementary measures as appropriate.
Marketing Communications
Where permitted by applicable law, we may send you marketing or promotional communications regarding our services, events, and updates. You may opt out of receiving such communications at any time by using the unsubscribe mechanism included in the communication or by contacting us directly. Even if you opt out of marketing messages, we may still send you transactional, administrative, security, or service-related communications where necessary.
Third-Party Websites
Our website or platform may contain links to third-party websites, products, plug-ins, or services that are not operated or controlled by Brandlight. This Privacy Policy does not apply to such third parties, and we encourage you to review their privacy notices before providing them with personal data.
Data Security
We implement appropriate technical, organizational, and administrative measures designed to protect personal data against unauthorized or unlawful access, use, disclosure, alteration, loss, or destruction. These measures are designed in light of the nature of the personal data and the risks involved. However, no internet-based service, information system, or method of electronic storage can be guaranteed to be completely secure.
Data Retention
We retain personal data for as long as reasonably necessary to fulfill the purposes for which it was collected, including to provide our Services, maintain business and operational records, comply with legal, tax, accounting, and regulatory obligations, resolve disputes, establish or defend legal claims, enforce our agreements, and protect our legitimate interests. Retention periods may vary depending on the nature of the data and the context in which it was collected. Where required by applicable law, we will delete, anonymize, or de-identify personal data when it is no longer needed for the purposes described above.
Recruitment-related personal data may be retained for a reasonable period following the conclusion of the relevant recruitment process in order to evaluate candidates for future opportunities, unless a longer retention period is required or permitted by law, or the individual requests earlier deletion where such right applies.
Your Privacy Rights
Subject to applicable law and depending on your jurisdiction, you may have the right to request access to the personal data we hold about you, request correction of inaccurate or incomplete data, request deletion of your personal data, request restriction of processing, object to certain processing activities, request data portability, withdraw consent where processing is based on consent, and lodge a complaint with a competent supervisory authority. We will not discriminate against you for exercising any privacy rights available under applicable law.
To exercise your rights or submit a privacy-related request, please contact us at privacy@brandlight.ai. We may request information necessary to verify your identity and your request before processing it, as permitted by applicable law.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us at privacy@brandlight.ai.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational considerations. When we do, we will post the updated version and revise the effective date above. Where required by applicable law, we will provide additional notice of material changes and, where required, obtain consent.