Bright Frame

Legal

Privacy Policy

This page is maintained by Bright Frame Labs and explains what personal data we handle when you visit this website, contact us, or work with us. We collect as little as we can get away with.

01

Controller

Bright Frame Labs is the controller of the personal data described here. Our privacy contact is info@brightframepal.com. Where we deliver services to a client, that client is usually the controller of end-user data and we act as a processor under a data processing agreement.

02

Data we collect

  • Contact data — name, email address, company and anything you choose to write when you email us or reply to a proposal.
  • Technical data — IP address, user agent, referring page and approximate region, recorded in server logs for security and troubleshooting.
  • Usage data — pages viewed and time on page, only if you accept analytics cookies. This data is aggregated and not used to build profiles.
  • Recruitment data — CV, portfolio links and interview notes if you apply for a role.

We do not collect special category data through this site, and we ask that you do not send it to us by email.

03

Why we use it and our legal bases

  • Responding to enquiries and delivering services — performance of a contract, or steps taken at your request before entering one.
  • Security, fraud prevention and service integrity — our legitimate interest in keeping the site and our clients’ systems safe.
  • Analytics and site improvement — your consent, withdrawable at any time through the cookie settings.
  • Legal and accounting obligations — compliance with law.

04

Sharing and processors

We do not sell personal data and we do not share it for advertising. We use a small number of processors under written agreements: a cloud hosting provider, a transactional email provider, a privacy-focused analytics provider that does not fingerprint visitors, and standard accounting software. Where an international transfer is unavoidable, it relies on approved standard contractual clauses and supplementary technical measures.

05

Retention

  • Enquiry correspondence — 24 months from last contact.
  • Server security logs — 30 days.
  • Analytics data — 14 months, aggregated.
  • Recruitment records — 12 months, or longer with your consent.
  • Contracts and invoices — as required by accounting law, typically 5 years.

06

Your rights

Under applicable data protection law you may request access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it at any time without affecting prior processing. Email info@brightframepal.com and we will respond within thirty days. You may also complain to your local supervisory authority.

07

Security

Access to systems holding personal data is limited to staff who need it, protected by single sign-on and multi-factor authentication. Data is encrypted in transit and at rest, dependencies are scanned continuously, and access is reviewed quarterly. No system is perfectly secure; if a breach affects your data and is likely to result in a risk to your rights, we will notify you and the relevant authority without undue delay.

08

Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under sixteen.

09

Changes and contact

When this policy changes materially we will publish the revised version here and, for active clients, notify the named contact. Questions go to info@brightframepal.com. Cookie details live in the Cookie Policy; contractual matters in the Terms of Service.