Privacy Policy.
We process as little data as possible. This policy describes every processing activity on this website in detail and reflects the GDPR (EU/EEA), the UK GDPR, the Swiss FADP, the CCPA/CPRA (California) and the UAE PDPL.
1. Controller and contact
Brendit Media LLC, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Email: support@brendit.com.
We have not appointed a statutory data protection officer. For any privacy matter - access, erasure, objection - an informal email to the address above is sufficient. We normally respond within one month.
2. Definitions and principles
Personal data means any information relating to an identified or identifiable person. We process such data only where a legal basis exists, limit processing to the stated purpose (purpose limitation) and to what is necessary (data minimisation).
We do not sell personal data, do not profile for advertising purposes and do not carry out automated individual decision-making producing legal effects within the meaning of Art. 22 GDPR.
3. Cookies, consent and audience measurement
When you first visit the website, a consent banner appears. Without your explicit consent we only use technically necessary storage; analytics cookies are set only after you click "Accept all". Your decision is stored in your device's local storage (key "brendit-consent-v1") and you can withdraw or change it at any time via the "Cookie settings" link in the footer - withdrawal takes effect for the future.
With your consent we use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics sets cookies and processes a truncated IP address, device and browser data, approximate location at country/region level, pages viewed, time on page, referrer and triggered events (e.g. starting and completing the Entity-Score self-test, submitting an enquiry). The purpose is statistical analysis of website usage and improvement of our content. We use neither Google Signals nor advertising or remarketing features; data sharing with Google advertising services is disabled and IP anonymisation is active.
The legal basis is your consent under Art. 6(1)(a) GDPR and the equivalent national e-privacy rules. We use Google Consent Mode v2: before your consent, analytics_storage, ad_storage, ad_user_data and ad_personalization are set to "denied" and the Google script is not loaded at all. A transfer to the USA cannot be excluded; Google LLC is certified under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses apply in addition. Analytics data is retained in Google Analytics for 14 months.
No Meta pixel, Google Ads tags or comparable advertising and profiling services are embedded.
We only use technically necessary browser storage: the result of your Entity-Score self-test and - if you use the support chat - a random conversation identifier. Both are stored in your device's local storage, serve usability only and can be deleted at any time in your browser settings. The legal basis is Art. 6(1)(f) GDPR and the equivalent national e-privacy rules.
4. Server log files and hosting
When you visit the website, our hosting provider automatically processes technical access data: IP address, date and time of the request, page requested, referrer, volume of data transferred, browser type, language and operating system. This data is technically required to deliver, stabilise and secure the website.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). The data is not merged with other sources and is deleted automatically after a short period.
5. Contact form and Entity-Score request
When you submit the form we process the details you provide: type (person or company), name, email address, website or LinkedIn profile, country and - if available - the result of your Entity-Score self-test.
The sole purpose is to handle your inquiry and produce your free Entity-Score. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). Providing the data is voluntary, but without it we cannot process your request.
The details are stored in our inquiry database, sent to us by email and transferred into our internal CRM (Brendit Hub) so the request can be handled and tracked. We do not pass them on to third parties for advertising purposes.
6. Producing the Entity-Score report (AI analysis)
To produce the free report we evaluate publicly available information about the person or organisation you specify - for example your website, public profiles and publicly retrievable search results. In addition, your name, the domain or profile URL provided and your self-test answers are passed to an AI service that generates the written analysis in the report.
The analysis runs through our infrastructure provider's AI gateway, currently using models from Google (Gemini) and OpenAI. Only the details required for the analysis are transmitted. The transfer serves the delivery of the service you requested; the legal basis is Art. 6(1)(b) or (f) GDPR.
The result is a non-binding assessment, not an automated decision with legal effect. You receive the report by email as a PDF.
7. Support chat
The chat on this website is answered by an AI assistant. We store the history of your messages and the replies as well as a random conversation identifier; if you leave contact details in the chat, these are stored too and handled like a contact request.
The purpose is to answer your questions and improve our support. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR for concrete inquiries about our services. Please do not enter special categories of personal data (such as health or financial data) in the chat.
8. Abuse and spam prevention
To prevent automated bulk submissions we log, for every form and chat submission, a cryptographic hash (SHA-256) of your IP address and email address, the timestamp and, where applicable, the reason for a block. The original address cannot realistically be derived from the hash; the plain-text IP is not stored for this purpose.
We also use invisible form fields (honeypots), timing checks and rate limits. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). These logs are deleted after 90 days at the latest.
9. Email communication
If you email us, we process your message and sender details to handle your request (Art. 6(1)(b) or (f) GDPR). Notifications and reports are sent through a specialised email provider acting as our processor.
We do not send newsletters or automated advertising. Unencrypted email can have security gaps; for strictly confidential information please choose another channel.
10. Recipients and processors
Contracts under Art. 28 GDPR are in place with all processors. Transfers to third countries take place only on the basis of an adequacy decision or the EU standard contractual clauses together with supplementary safeguards. As our company is established in the United Arab Emirates, inquiries are handled there.
- Hosting, database and application infrastructure: Lovable (deployment and backend), acting as our processor.
- Email delivery: our contracted sending provider for notifications and reports.
- AI analysis: our infrastructure provider's AI gateway using models from Google and OpenAI, solely to generate report and chat responses.
- Internal CRM: Brendit Hub, operated by us to manage inquiries.
- Professional advisers and authorities, where we are legally required to disclose.
11. External content and links
We do not load external fonts, maps, videos or social media plugins. All fonts and scripts are served from our own server, so simply visiting a page creates no connection to third parties.
If you follow a link to an external service (e.g. LinkedIn, Wikipedia, Google), that provider's privacy terms apply there.
12. Retention
- Contact and Entity-Score inquiries: no later than 24 months after our last communication.
- Chat transcripts: no later than 12 months after the last message.
- Abuse logs (hash values): no later than 90 days.
- Server log files: short term, deleted automatically by the host.
- Contract documentation: for the applicable commercial and tax retention periods.
13. Your rights
For California residents: under the CCPA/CPRA you have the right to know, delete and correct, and not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioral advertising.
For users in the United Arab Emirates the corresponding rights under Federal Decree-Law No. 45 of 2021 (PDPL) apply; for users in the United Kingdom the UK GDPR, and in Switzerland the FADP.
To exercise your rights, simply email support@brendit.com. For security we may ask for additional details to verify your identity.
- Access to the data stored about you (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
- Complaint to a supervisory authority (Art. 77 GDPR), for example where you live.
14. Data security
The website is served exclusively over an encrypted TLS connection (HTTPS). Form data is transmitted encrypted and stored in a database whose tables are protected by access rules and which cannot be read publicly. Access to inquiries is limited to the people who handle them.
15. Minors
Our services are aimed at businesses and adults with legal capacity. We do not knowingly collect data from children under 16. If such data reaches us inadvertently, we delete it as soon as we become aware.
16. Changes to this policy
We update this policy whenever our processing activities or the legal framework change. The version published on this page, with the date shown above, always applies.
As of: August 2026
Services
All services →Brendit Media LLC - the agency for Google Knowledge Panels, entity building and digital reputation. DACH · UAE · International. Success-based - you only pay when it's visible.