Privacy Policy.
We process as little data as possible. This policy describes every processing activity on this website in detail and reflects the GDPR (EU/EEA), the UK GDPR, the Swiss FADP, the CCPA/CPRA (California) and the UAE PDPL.
1. Controller and contact
Brendit Media LLC, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Email: support@brendit.com.
We have not appointed a statutory data protection officer. For any privacy matter - access, erasure, objection - an informal email to the address above is sufficient. We normally respond within one month.
2. Definitions and principles
Personal data means any information relating to an identified or identifiable person. We process such data only where a legal basis exists, limit processing to the stated purpose (purpose limitation) and to what is necessary (data minimisation).
We do not sell personal data, do not profile for advertising purposes and do not carry out automated individual decision-making producing legal effects within the meaning of Art. 22 GDPR.
3. Cookies, consent and audience measurement
When you first visit the website, a consent banner appears. Without your explicit consent we only use technically necessary storage; analytics and marketing cookies are set only after you click "Accept all". Your decision is stored in your device's local storage (key "brendit-consent-v1") and you can withdraw or change it at any time via the "Cookie settings" link in the footer - withdrawal takes effect for the future.
Origin tracking: to understand which channel enquiries come from, on your first visit we store in a technically necessary first-party cookie ("brendit_ft", 30-day lifetime) or in session storage only campaign parameters (UTM values), the hostname of the referring website, the landing path and a flag indicating whether a LinkedIn, Meta or Google click parameter was present - no personal data and no click IDs. These values are only transmitted together with your enquiry when you submit a form (Art. 6(1)(f) GDPR).
With your consent we use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics sets cookies and processes a truncated IP address, device and browser data, approximate location at country/region level, pages viewed, time on page, referrer and triggered events (e.g. starting and completing the Entity-Score self-test, submitting an enquiry). The purpose is statistical analysis of website usage and improvement of our content. We use neither Google Signals nor advertising or remarketing features; data sharing with Google advertising services is disabled and IP anonymisation is active.
With your consent we also use the LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland; outside the EEA: LinkedIn Corporation, Sunnyvale, California, USA) and Meta Pixel (Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland). These services may process a truncated IP address, referrer, pages viewed, device and browser data, approximate location and campaign events. Their purposes are campaign measurement, retargeting and aggregated audience analysis. Transfers to the USA cannot be excluded; the providers use appropriate transfer mechanisms.
The legal basis is your consent under Art. 6(1)(a) GDPR and equivalent national e-privacy rules. Before consent, analytics_storage, ad_storage, ad_user_data and ad_personalization are set to "denied" and the Google, LinkedIn and Meta scripts are not loaded. Google Analytics data is retained for 14 months; LinkedIn and Meta cookies follow the providers' respective expiry periods.
We only use technically necessary browser storage: the result of your Entity-Score self-test and - if you use the support chat - a random conversation identifier. Both are stored in your device's local storage, serve usability only and can be deleted at any time in your browser settings. The legal basis is Art. 6(1)(f) GDPR and the equivalent national e-privacy rules.
4. Server log files and hosting
When you visit the website, our hosting provider automatically processes technical access data: IP address, date and time of the request, page requested, referrer, volume of data transferred, browser type, language and operating system. This data is technically required to deliver, stabilise and secure the website.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation). The data is not merged with other sources and is deleted automatically after a short period.
5. Contact form and Entity-Score request
When you submit the form we process the details you provide: type (person or company), name, email address, website or LinkedIn profile, country and - if available - the result of your Entity-Score self-test.
The sole purpose is to handle your inquiry and produce your free Entity-Score. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest in responding to inquiries). Providing the data is voluntary, but without it we cannot process your request.
The details are stored in our inquiry database, sent to us by email and transferred into our internal CRM (Brendit Hub) so the request can be handled and tracked. We do not pass them on to third parties for advertising purposes.
6. Personal feasibility review
For the free feasibility review, a member of our team evaluates publicly available information about the person or organisation you specify, such as your website, public profiles and publicly retrievable search results.
AI-assisted tools from our infrastructure provider may be used during this review. Only the details required for the review are transmitted. The processing serves the delivery of the service you requested; the legal basis is Art. 6(1)(b) or (f) GDPR.
The assessment is personally reviewed and is not an automated decision with legal effect. Our team contacts you by email or phone within 48–72 hours.
7. Support chat
The chat on this website is answered by an AI assistant. We store the history of your messages and the replies as well as a random conversation identifier; if you leave contact details in the chat, these are stored too and handled like a contact request.
The purpose is to answer your questions and improve our support. The legal basis is Art. 6(1)(f) GDPR, or Art. 6(1)(b) GDPR for concrete inquiries about our services. Please do not enter special categories of personal data (such as health or financial data) in the chat.
8. Abuse and spam prevention
To prevent automated bulk submissions we log, for every form and chat submission, a cryptographic hash (SHA-256) of your IP address and email address, the timestamp and, where applicable, the reason for a block. The original address cannot realistically be derived from the hash; the plain-text IP is not stored for this purpose.
We also use invisible form fields (honeypots), timing checks and rate limits. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in preventing abuse). These logs are deleted after 90 days at the latest.
9. Email communication
If you email us, we process your message and sender details to handle your request (Art. 6(1)(b) or (f) GDPR). Notifications and reports are sent through a specialised email provider acting as our processor.
We do not send newsletters or automated advertising. Unencrypted email can have security gaps; for strictly confidential information please choose another channel.
10. Recipients and processors
Contracts under Art. 28 GDPR are in place with all processors. Transfers to third countries take place only on the basis of an adequacy decision or the EU standard contractual clauses together with supplementary safeguards. As our company is established in the United Arab Emirates, inquiries are handled there.
- Hosting, database and application infrastructure: Lovable (deployment and backend), acting as our processor.
- Email delivery: our contracted sending provider for notifications and reports.
- AI analysis: our infrastructure provider's AI gateway using models from Google and OpenAI, solely to generate report and chat responses.
- Website insights, campaign attribution and retargeting after consent: LinkedIn Ireland Unlimited Company (EEA users) or LinkedIn Corporation (users outside the EEA), and Meta Platforms Ireland Limited.
- Internal CRM: Brendit Hub, operated by us to manage inquiries.
- Professional advisers and authorities, where we are legally required to disclose.
11. External content and links
We do not load external fonts, maps, videos or social media plugins. All fonts and scripts are served from our own server, so simply visiting a page creates no connection to third parties.
If you follow a link to an external service (e.g. LinkedIn, Wikipedia, Google), that provider's privacy terms apply there.
12. Retention
- Contact and Entity-Score inquiries: no later than 24 months after our last communication.
- Chat transcripts: no later than 12 months after the last message.
- Abuse logs (hash values): no later than 90 days.
- Server log files: short term, deleted automatically by the host.
- Contract documentation: for the applicable commercial and tax retention periods.
13. Your rights
For California residents: under the CCPA/CPRA you have the right to know, delete and correct, and not to be discriminated against for exercising those rights. We do not sell personal information and do not share it for cross-context behavioral advertising.
For users in the United Arab Emirates the corresponding rights under Federal Decree-Law No. 45 of 2021 (PDPL) apply; for users in the United Kingdom the UK GDPR, and in Switzerland the FADP.
To exercise your rights, simply email support@brendit.com. For security we may ask for additional details to verify your identity.
- Access to the data stored about you (Art. 15 GDPR).
- Rectification of inaccurate data (Art. 16 GDPR).
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
- Complaint to a supervisory authority (Art. 77 GDPR), for example where you live.
14. Data security
The website is served exclusively over an encrypted TLS connection (HTTPS). Form data is transmitted encrypted and stored in a database whose tables are protected by access rules and which cannot be read publicly. Access to inquiries is limited to the people who handle them.
15. Minors
Our services are aimed at businesses and adults with legal capacity. We do not knowingly collect data from children under 16. If such data reaches us inadvertently, we delete it as soon as we become aware.
16. Changes to this policy
We update this policy whenever our processing activities or the legal framework change. The version published on this page, with the date shown above, always applies.
As of: August 2026
Services
All services →Brendit Media LLC - Google Knowledge Panels, entity building and digital reputation. No upfront payment · success-based. You only pay once it is visibly working.