Effective 24 August 2026

Privacy Policy

What this website collects, why, who else sees it, and how to have it deleted. It is short because the site does very little.

This policy covers www.braingenz.com. It does not cover software we build for clients, which is governed by the agreement covering that project.

Who is responsible

BrainGenz is the controller of the personal data described here. BrainGenz, 5th Floor, A1, 1 Sunrise Rd, Block H Valencia, Lahore 54000, Pakistan. Email sales@braingenz.com.

We are based in Pakistan and work with clients in the United States, Europe and the Gulf. Where we handle data about people in the European Union or the United Kingdom, we apply the rights set out below regardless of where we are located.

What we collect

When you use the contact form

The form collects your name, email address and message, which are required, and optionally your company, phone number and the service you are interested in. Nothing else is captured - there is no hidden field and no profiling.

We use it for one purpose: to reply to you and, if it goes further, to discuss and deliver a project. We do not sell it, rent it, or add you to a marketing list you did not ask for.

When you enter your email on the Insights page

Your email address is sent to the same inbox. To be plain about it, we do not currently run a newsletter platform, so this is a request that reaches a person rather than an automated subscription.

Analytics

We may use Google Analytics 4 to understand which pages are read and how people arrive. It records pages viewed, approximate location derived from IP address, device and browser type, and referring source. It does not tell us who you are.

Analytics loads only when it is configured, and it sets cookies when it does. If you are in a jurisdiction requiring consent before analytics cookies are set, you should not be tracked without being asked - if you believe you were, tell us and we will investigate and correct it.

Server logs

Our hosting provider records standard request logs, including IP address, timestamp and the page requested. This is ordinary infrastructure logging used for security and diagnostics, and it is retained on their schedule rather than ours.

What we do not do
  • No advertising or retargeting pixels.
  • No selling or sharing of personal data with data brokers.
  • No accounts, so no passwords are stored.
  • No payment details are collected on this website.
  • No automated decision-making that produces legal or similarly significant effects.

Who else is involved

Running the site means a small number of third parties process data on our behalf. This is the complete list:

ProviderWhat it handlesWhere
VercelWebsite hosting and request logsUnited States and global edge network
Twilio SendGridDelivers contact form submissions to our inboxUnited States
Microsoft 365The mailbox that receives and stores your enquiryMicrosoft data centres
Google AnalyticsWebsite usage statistics, when enabledUnited States

One thing deliberately absent from that table: Google Fonts. The site typeface used to load from Google's servers, which meant your browser contacted Google on every page view and your IP address was visible to them - a transfer a German court has held to require a legal basis. We now serve the font from our own servers, so that request no longer happens at all.

Because several of these are in the United States, data about EU and UK visitors may be transferred there. Those transfers rely on the providers' own transfer mechanisms, which each of them publishes.

How long we keep it

  • Enquiries that do not lead anywhere: deleted within 24 months.
  • Enquiries that become a project: kept for the life of the engagement and then for as long as we are required to retain business records.
  • Analytics data: on Google's retention setting, which we keep at the shortest option that is useful.

If you ask us to delete an enquiry sooner, we will, unless we are required to keep it.

Your rights

Depending on where you live, you may have the right to ask for a copy of what we hold, have it corrected, have it deleted, restrict or object to how we use it, or receive it in a portable form. Where we rely on consent, you can withdraw it at any time.

Email sales@braingenz.com and we will respond within 30 days. We will not ask you to justify the request, and we will not charge for it.

If you are in the EU or UK and are unhappy with our response, you can complain to your national data protection authority. We would rather you told us first, but that route is yours regardless.

Legal bases, if you need them

  • Replying to your enquiry: our legitimate interest in responding to someone who contacted us, and steps taken at your request before entering a contract.
  • Analytics cookies: consent, where consent is required.
  • Security logging: legitimate interest in keeping the site available and secure.

Security

The site is served over HTTPS and form submissions are encrypted in transit. Access to the inbox that receives enquiries is limited to the people who need it and protected by multi-factor authentication.

Being straight about the limits: BrainGenz does not currently hold ISO 27001 or SOC 2 certification. We say so here for the same reason we say it on our enterprise page - you should hear it from us rather than discover it during a review.

Changes

If this policy changes materially, the effective date above changes and the substance of the change is described here rather than replaced silently.

One honest caveat

This policy was written to describe accurately what the site does. It has not been reviewed by a qualified lawyer, and it is not legal advice. If you need a formal assurance for a procurement process, ask us and we will get it reviewed properly.