PRIVACY POLICY

Brainqub3, a consulting brand of DATA-CENTRIC SOLUTIONS LTD

Last updated: 2 October 2026

1. THE SHORT VERSION

  • We do not sell personal data, and we do not give it to other companies for their own marketing.
  • We use what you tell us to reply to you, to run the calls, programmes and projects you ask for, and to tell you about our services where the law allows. You can opt out of marketing at any time.
  • We keep enquiry, application and client records in Zoho CRM, hosted in Zoho's EU data centre. We also keep data in Google Workspace, in private GitHub repositories and on servers we rent from hosting providers.
  • We use service providers to run our business, including Vercel, Zapier, Google and the AI model providers Anthropic and OpenAI. Some of them process data in the United States. We have turned off model training in the AI tools we use.
  • We may record and transcribe calls and meetings, and we tell you before we do.
  • We analyse our records to understand and improve our business. We may publish statistics drawn from them, but only in aggregated form that does not identify you or your organisation.
  • This policy covers brainqub3.com and its subdomains, including architect.brainqub3.com.
  • You have rights over your personal data. Email info@brainqub3.com to use them.

2. ABOUT THIS PRIVACY POLICY

This Privacy Policy explains how DATA-CENTRIC SOLUTIONS LTD, trading through the Brainqub3 brand, collects, uses, stores, shares and protects personal data.

This policy applies to:

  • the websites at brainqub3.com and its subdomains, including architect.brainqub3.com, and their pages, forms, resource downloads and booking flows;
  • enquiries, lead magnet downloads, discovery call bookings and marketing interactions;
  • applications for, and places on, The Architect Programme;
  • sales, consultancy, enablement, workshops, training, custom AI engineering work and fractional CTO services;
  • personal data we handle as a controller for our own business purposes.

When we process personal data on behalf of a client as part of a client project, such as personal data contained in a client dataset, workflow, knowledge base, CRM, internal system, code repository, prompt, evaluation set, transcript or production AI agent, we will usually act as the client's processor. In that situation, the client is normally the controller and the processing is governed by our contract, statement of work and, where applicable, data processing agreement with that client. The client's own privacy notice should explain how it uses personal data in its business or service.

3. WHO WE ARE

The controller for the personal data covered by this policy is:

DATA-CENTRIC SOLUTIONS LTD

Company number: 14829432

Trading brand: Brainqub3

Registered in England & Wales

Registered office: 86-90 Paul Street, London, EC2A 4NE, United Kingdom

Website: brainqub3.com

Email: info@brainqub3.com

In this policy, "Brainqub3", "we", "us" and "our" refer to DATA-CENTRIC SOLUTIONS LTD trading as Brainqub3.

4. THE SERVICES WE PROVIDE

We are an AI engineering consultancy. We provide services including custom AI agent and automation builds, AI enablement, workshops, implementation support, technical strategy and fractional CTO services.

We also run The Architect Programme at architect.brainqub3.com. It prepares people for the Claude Certified Architect – Professional exam in small groups, for individuals and for organisations getting their people certified. The Architect Programme is independent exam preparation by Brainqub3. It is not made, endorsed, sponsored or reviewed by Anthropic.

Because of the nature of these services, we may process business contact information, project information, operational requirements, workflow information and, where a client instructs us to do so, data contained in client systems or datasets. We aim to collect only what is relevant and necessary for the purpose in question.

5. PERSONAL DATA WE COLLECT

5.1 Information you give us directly

We may collect personal data when you:

  • visit our websites;
  • complete a form;
  • download a lead magnet, playbook, guide, blueprint or other resource;
  • book a discovery call;
  • attend a discovery call, workshop, enablement session or meeting;
  • apply for The Architect Programme, or ask us to tell you when places open;
  • take part in The Architect Programme's group sessions, community or debriefs;
  • contact us by email, phone, website form, social media, messaging tool or other channel;
  • become a client, supplier, partner or prospective client;
  • send us project materials or grant access to systems for a project.

This may include:

  • name;
  • business email address;
  • telephone number;
  • company name;
  • job title, occupation, role or seniority;
  • industry;
  • country and time zone;
  • company website or professional profile;
  • your stated AI goals, desired outcomes, current stage, project requirements, use case information and implementation challenges;
  • information about a dataset, workflow, tool stack, process, system or technical environment you have in mind;
  • your plans for a programme or exam, such as which plan interests you, your exam date and who is likely to pay;
  • how you found us, referral source, campaign source or UTM information;
  • meeting availability, booking details and calendar information;
  • communications, notes, call summaries, messages, attachments and feedback;
  • marketing preferences, the consent wording you agreed to and unsubscribe records;
  • contract, invoice and payment administration information;
  • any other information you choose to provide.

Please do not provide special category personal data, criminal offence data, confidential third party personal data or personal data you are not authorised to share unless we have expressly agreed this in writing and there is a clear lawful basis for doing so.

5.2 Discovery call and preparation information

If you book a discovery call, we collect information to understand whether and how we may be able to help, to prepare for the call and to follow up afterwards. This may include your contact details, company information, the outcome you want to achieve with AI, your current project stage, your dataset or workflow readiness, your role, your industry, how you found us and any further information you provide in the booking flow or during the call.

If we record or transcribe a discovery call, or take notes with an AI tool, we tell you beforehand, as described in section 5.5. You may object to a recording. We may still keep manual notes where necessary for our legitimate business purposes.

5.3 Lead magnet and resource download information

If you request a resource, such as a playbook, guide, checklist, blueprint or other lead magnet, we collect the information required to provide that resource and to understand your business interest. We may use this information for sales follow-up, lead qualification, CRM administration, segmentation and related business-to-business marketing, subject to your rights and applicable rules on direct marketing.

Submitting a resource form does not mean you have to buy anything. You can opt out of marketing communications at any time.

5.4 The Architect Programme

When you apply at architect.brainqub3.com, we collect:

  • your email address. We ask for a work email, because Anthropic's certification exams need a company email address to register;
  • your first name;
  • which plan interests you: Individual, or Enterprise for five or more people at your organisation;
  • whether your organisation is in the Claude Partner Network and, if so, its partner level;
  • your company name, industry and country;
  • your time zone, so we can place you in a group whose sessions fall at a sensible time for you;
  • whether you have booked the exam, and your exam date or the month you plan to sit it;
  • for an Enterprise enquiry, your role and how many people you want to certify;
  • who is likely to pay for your place: you, your employer, or not sure yet;
  • how you heard about us;
  • whether you would like our occasional emails about building with Claude and future exam prep.

We also note the domain of your email address and whether it is a work or personal address, and we may use the domain to identify your company. We keep a record of the wording you agreed to when you applied.

If you cannot sit the exam yet and ask us to tell you when places open, we keep only your email address and the few answers you gave, and use them only to tell you when places open.

If you take a place, The Architect Programme's Terms of Service, which you accept when you pay, set out how the programme works. They are linked from every page of architect.brainqub3.com. The personal data a place involves includes your Offer, invoice and payment; your group, Session Lead and attendance; the recordings and transcripts we use to write session packs, and the packs themselves; what you post in the community; your debrief notes; the record we keep if you claim a Retake Meeting; any testimonial you agree to; and any report we make about a breach of the exam confidentiality rule. The Terms of Service explain how each of these works, including how long we keep session recordings and transcripts.

5.5 Call and meeting recordings

We may record and transcribe discovery calls and client meetings, and use AI tools to make summaries and notes from them.

We tell you before we record. For meetings on Google Meet, the meeting invitation says if we will record or transcribe the meeting or take notes with Gemini, so you know before you accept it. You can object to a recording.

Recordings and transcripts are a core part of how we work. We keep them to:

  • deliver what we agreed with you, including summaries and follow-up;
  • keep an accurate record of the advice we gave, what was discussed and what was decided;
  • check and improve the quality of our consultancy and other services;
  • deal with questions, complaints or disputes.

We keep them for as long as they serve these purposes, as set out in section 14.

5.6 Website, device and analytics information

When you use our websites, we and our service providers may process technical information needed to deliver, secure, maintain and improve them. This may include:

  • IP address and approximate location derived from it, where processed by hosting, security or logging systems;
  • browser type and version;
  • device type;
  • operating system;
  • pages visited;
  • referrers;
  • date and time of visits;
  • interactions with forms, buttons, videos, embedded content or resources;
  • campaign, source, medium and UTM parameters;
  • error logs and diagnostic information;
  • cookie or consent preference information, where applicable.

We use Vercel Web Analytics on brainqub3.com and architect.brainqub3.com to understand page activity and improve our websites. We turn it on only if you accept analytics in our cookie banner. Vercel Web Analytics is designed to provide aggregated website analytics and, by default, does not use cookies or associate page view data with an individual visitor or IP address. The events we record say what happened on a page, such as a form being started or sent. They never include your name, email address or what you type into a form.

Our forms use hCaptcha to check that a submission comes from a person rather than a bot. To do this, hCaptcha processes information about your device and browser and how you interact with the check. We may also use technical logs and security tools that process personal data for website delivery, fraud prevention and security.

Where analytics information is anonymous and cannot identify or re-identify an individual, it is not personal data. Where website, device, analytics or log information is personal data, we process it in line with this policy.

5.7 Information from third parties and public sources

For business-to-business sales and relationship management, we may receive or collect limited professional information about you from third parties or public sources, such as referrals, your employer's website, public company pages, LinkedIn or other professional platforms. This may include your role, employer, professional contact details and business context.

We use this information only where relevant to our services and where we have a lawful basis to do so.

5.8 Client project data

For consultancy, workshops, enablement, custom AI builds, production agent work and fractional CTO services, clients may provide information about their teams, users, customers, suppliers, workflows, documents, datasets, systems, prompts, logs, outputs, call transcripts, integrations, tools or business processes.

Where this information contains personal data, we process it according to the role we have in the relevant engagement:

  • if we decide why and how the data is processed for our own purposes, we act as controller and this policy applies;
  • if we process the data only on the client's documented instructions, we act as processor and the relevant client contract and data processing agreement apply.

Unless agreed in writing, clients should not provide personal data that is not necessary for the project. Clients remain responsible for ensuring they have an appropriate lawful basis, transparency notice and authority to share personal data with us for the engagement.

6. SPECIAL CATEGORY DATA

We do not intentionally collect special category data through our websites, standard sales forms or programme application forms. Special category data includes information about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sex life or sexual orientation.

We also do not intentionally collect criminal offence data through our websites, standard sales forms or programme application forms.

If you provide such information without being asked, we may delete it, restrict it, return it or process it only to the extent necessary to deal with the matter and comply with the law. If a client project requires special category or criminal offence data to be processed, this must be agreed in writing in advance and supported by appropriate contractual, technical and organisational safeguards.

7. HOW WE USE PERSONAL DATA AND OUR LAWFUL BASES

We process personal data only where we have a lawful basis under UK data protection law. The lawful bases we most commonly rely on are:

  • contract, where processing is necessary to perform a contract with you or take steps at your request before entering into a contract;
  • legitimate interests, where processing is necessary for our business or a third party's business interests and those interests are not overridden by your rights and freedoms;
  • consent, where you have given clear consent and can withdraw it at any time;
  • legal obligation, where we must process data to comply with the law.

The main purposes for which we process personal data are set out below.

7.1 Responding to enquiries

We use contact details, message content and business context to respond to enquiries, answer questions, provide requested information and manage follow-up.

Lawful basis: legitimate interests and, where the enquiry relates to a potential contract, contract.

Our legitimate interests: communicating with people who contact us, understanding business requirements and developing appropriate proposals.

7.2 Providing lead magnets and resources

We use form information to deliver requested resources, confirm delivery, prevent abuse of forms, record your interest and understand which content is useful.

Lawful basis: contract or legitimate interests.

Our legitimate interests: providing requested business resources, measuring content performance, managing leads and improving our materials.

7.3 Sales follow-up, lead qualification and CRM administration

We use contact details, company information, stated interests, form responses, meeting notes, public professional information and CRM records to assess whether our services are relevant, prioritise follow-up, maintain accurate records and contact business prospects about our services.

Lawful basis: legitimate interests. Where consent is required for a particular form of direct marketing, we rely on consent or another applicable permission under the Privacy and Electronic Communications Regulations 2003.

Our legitimate interests: business development, maintaining a sales pipeline, avoiding irrelevant outreach, preparing appropriate proposals and growing our business.

7.4 Discovery call preparation and follow-up

We use booking information, form responses, call notes and communications to prepare for discovery calls, tailor the conversation, understand your business context, send follow-up materials and decide whether we can help.

Lawful basis: legitimate interests and contract.

Our legitimate interests: preparing properly for meetings, providing relevant advice and avoiding wasted time for both parties.

7.5 Delivering consultancy, workshops, enablement, custom builds and fractional CTO services

We use client and project information to deliver services, manage engagements, create deliverables, build or configure systems, run workshops, provide advice, test and evaluate outputs, document work and communicate with client stakeholders.

Lawful basis: contract, legitimate interests and legal obligation where applicable.

Our legitimate interests: delivering professional services, managing projects, maintaining quality, resolving issues and keeping appropriate records.

7.6 Running The Architect Programme

We use your application to decide whether we can offer you a place, to email you about the programme you applied for (pricing, start dates, your place and your group), to place you in a group that suits your time zone, to time our offer around your exam plans and to invoice you or your employer. If you take a place, we use your information to provide it as the programme's Terms of Service describe.

Lawful basis: contract, including steps you ask us to take before entering into a contract, and legitimate interests. We use a testimonial only with your written permission.

Our legitimate interests: running the programme well, forming workable groups, protecting the integrity of the exam the programme prepares people for and improving the programme.

7.7 AI automations and internal workflow support

We may use AI systems and automation tools to support internal workflows, such as CRM routing, lead qualification, meeting preparation, call, session or email summarisation, proposal drafting, task creation, document organisation, research support, internal quality review and project administration.

Where these tools process personal data, we use only the data reasonably necessary for the task. We apply human review where outputs affect meaningful decisions. We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.

Lawful basis: legitimate interests, contract or legal obligation depending on the context.

Our legitimate interests: running efficient operations, reducing manual administration, improving response quality and preparing better for client work.

7.8 Internal analysis and published statistics

We analyse enquiry, application, CRM and website records to understand demand and improve our services. For example, we look at which industries and countries people come from, how they find us, which plans and services they choose and how our forms perform.

We may publish statistics and insights drawn from this analysis, such as the share of programme applicants who work in a particular industry. Anything we publish is aggregated and does not identify you or your organisation. We do not publish figures about groups so small that someone could be picked out, and we do not name individuals or organisations without their permission.

Lawful basis: legitimate interests.

Our legitimate interests: understanding and growing our business, improving our services and sharing useful findings about AI adoption and certification.

7.9 Website analytics, performance and improvement

We use analytics and technical information to understand how our websites are used, which pages and resources are useful, where visitors come from, how forms perform and how to improve website content and user experience.

Lawful basis: consent for analytics that you accept in our cookie banner. Legitimate interests for technical information that is needed to deliver and secure our websites.

Our legitimate interests: maintaining and improving our websites, understanding aggregate usage and making our content more useful.

7.10 Security, fraud prevention and abuse prevention

We use technical logs, IP addresses, form submission information, anti-spam checks, hCaptcha or similar verification tools, access logs and system data to protect our websites, services, systems, client data and business from spam, fraud, misuse, security threats and unauthorised access.

Lawful basis: legitimate interests and legal obligation where applicable.

Our legitimate interests: keeping our systems and data secure, preventing abuse and protecting clients, prospects and our business.

7.11 Direct marketing

We may send business-to-business marketing about our services, resources, events, workshops, insights or related content where permitted by law. We may do this using business contact details you provide, details collected from business interactions, or limited professional details from public sources or referrals.

Lawful basis under UK GDPR: legitimate interests or consent, depending on the context.

Where the Privacy and Electronic Communications Regulations 2003 apply, we comply with the relevant rules for electronic mail, telephone calls and other channels. For individual subscribers, such as sole traders and some partnerships, we will use consent or the soft opt-in where available. For corporate subscribers, such as companies and LLPs, we may contact business email addresses where permitted, but we will identify ourselves and provide a clear way to opt out.

On architect.brainqub3.com, applying means you are asking us to email you about The Architect Programme: pricing, start dates, your place and your group. We send our wider emails, about building with Claude and future exam prep, only if you tick the box asking for them. If you only asked us to tell you when places open, we use your email address for that and nothing else.

You can opt out of marketing at any time by using the unsubscribe link in our emails or by emailing info@brainqub3.com.

7.12 Legal, compliance, finance and business administration

We use personal data to maintain business records, manage contracts, issue invoices, keep accounting records, handle disputes, enforce agreements, respond to legal requests, comply with tax and company law obligations, manage insurance and obtain professional advice.

Lawful basis: legal obligation, contract and legitimate interests.

Our legitimate interests: running a lawful business, keeping accurate records, protecting legal rights and managing risk.

8. LEGITIMATE INTERESTS

Where we rely on legitimate interests, we consider the impact on individuals and use safeguards where appropriate. Our legitimate interests include:

  • operating and growing an AI engineering consultancy and training business;
  • responding to enquiries;
  • providing relevant resources and follow-up;
  • preparing for discovery calls and meetings;
  • managing sales, client relationships and CRM records;
  • delivering professional services;
  • keeping recordings and transcripts of calls and meetings as a record of our work and to improve it;
  • running The Architect Programme and protecting the integrity of the exam it prepares people for;
  • improving our websites, content and services;
  • analysing our records and publishing aggregated statistics that do not identify anyone;
  • using proportionate AI and automation tools to support internal work;
  • preventing fraud, spam and security incidents;
  • maintaining business records;
  • establishing, exercising or defending legal rights;
  • suppressing marketing to people who have opted out.

You have the right to object to processing based on legitimate interests. If you object to direct marketing, we will stop using your data for that purpose.

9. AI TOOLS, MODEL PROVIDERS AND AUTOMATIONS

Because we provide AI engineering and enablement services, we use AI-enabled tools and automation platforms in our business and, where agreed, in client projects.

The AI and automation providers that may process enquiry, applicant and client data are:

  • Zapier, which moves form submissions into our CRM, sends emails and runs automated workflows, some of which include AI steps;
  • Google, through Google Workspace, which records and transcribes meetings on Google Meet and takes meeting notes with Gemini;
  • Anthropic (Claude), OpenAI and Google (Gemini), whose AI models we use for tasks such as summarising and routing enquiries, preparing for calls, drafting emails and documents, transcribing and summarising calls and sessions, making session packs and analysing our records.

These providers act as our processors. They are US companies and may process data in the United States, so using them involves an international transfer (see section 13).

Personal data may be included in prompts, inputs, metadata, workflow events, meeting summaries, documents, outputs, logs or integration payloads. We apply data minimisation and access controls to reduce unnecessary exposure of personal data.

We have turned off model training in the AI tools we use, so these providers do not use the personal data we give them to train their models. We do not authorise our processors to use personal data supplied to us for their own unrelated marketing.

We may use anonymised or aggregated information to improve our internal methods, templates, quality assurance and services, provided individuals cannot be identified from that information.

AI outputs can be inaccurate or incomplete. We use human oversight where AI or automation meaningfully supports decisions about prospects, applicants, clients, deliverables or project work.

10. COOKIES, ANALYTICS AND SIMILAR TECHNOLOGIES

Cookies are small files placed on a device. Similar technologies include scripts, tags, pixels, local storage, embedded content and technologies that store or access information on a user's device.

We may use the following categories of cookies and similar technologies:

  • Strictly necessary technologies: required for website operation, security, form submission, consent preferences, load balancing, anti-spam protection or other functions you request. We keep your cookie choice in your browser's local storage so we do not have to ask again.
  • Analytics technologies: used to understand website performance, page views, referrers, events and aggregate user behaviour. We use Vercel Web Analytics, and only if you accept analytics in our cookie banner. By default, Vercel Web Analytics does not use cookies and provides aggregated analytics not tied to an identifiable visitor or IP address.
  • Attribution and campaign information: used to understand how people found us, such as referral information or UTM parameters. This helps us understand which content and campaigns are useful.
  • Embedded content and third-party widgets: some pages include embedded content, scheduling tools such as Calendly, anti-spam checks such as hCaptcha, credential badges, video players or other third-party functionality. These providers may process data when you interact with their tools.

Each of our sites, brainqub3.com and architect.brainqub3.com, asks for your choice separately, because your browser keeps it for each site. You can change your choice using the cookie settings where available, and you can also use browser settings to block or delete cookies and local storage.

If we materially change the cookies or similar technologies we use, we will update this policy or our cookie information.

11. WHERE WE STORE PERSONAL DATA

We store personal data in these places:

  • Zoho CRM, our customer relationship management system, hosted in Zoho's EU data centre. This is where we keep enquiry, application, lead and client records.
  • Google Workspace, for email, calendars and documents, and for recordings, transcripts and Gemini notes of meetings held on Google Meet.
  • Private GitHub repositories, for project work, code and working documents. GitHub is a US company and may store data in the United States or other countries.
  • Linux servers that we rent from hosting providers, for running our systems and project work.

Our website forms pass through Vercel and Zapier on their way to Zoho CRM. We do not log the contents of form submissions. Zapier keeps a history of each automation run for a limited period.

Vercel hosts our websites on its global network, which serves pages from locations near each visitor. Applications sent from architect.brainqub3.com are received in Vercel's London region. Forms sent from brainqub3.com are received in Vercel's Washington, D.C. region in the United States.

12. WHO WE SHARE PERSONAL DATA WITH

We do not sell personal data, and we do not give it to other companies for their own marketing.

The main service providers that process personal data for us are:

  • Zoho, for our CRM;
  • GitHub, for private repositories;
  • server hosting providers, for the servers we rent;
  • Vercel, for website hosting, form handling and web analytics;
  • Zapier, for automation;
  • Google, for Google Workspace (email, calendars, documents, Google Meet recordings and transcripts, and Gemini);
  • Anthropic and OpenAI, for AI models;
  • hCaptcha, for checking that form submissions come from people;
  • Calendly, for booking calls;
  • the community platform we use for The Architect Programme.

For The Architect Programme, we also share personal data with:

  • your Session Lead, who may be a contractor working for us under a confidentiality agreement, so they can run your group;
  • the other members of your group, who see your name, what you share in sessions and your group's session packs;
  • whoever pays for your place, such as your employer, as the programme's Terms of Service describe;
  • Anthropic or its exam provider, if we report a breach of the exam confidentiality rule under the programme's Terms of Service, or if we must tell Anthropic about a complaint about the programme.

More generally, we may share personal data with trusted third parties where necessary for the purposes described in this policy, including:

  • CRM and sales pipeline providers;
  • email, calendar, meeting and scheduling providers;
  • form, survey, booking and lead capture providers;
  • website hosting, deployment, analytics, performance and security providers;
  • anti-spam, bot detection and verification providers;
  • AI, automation, workflow and integration providers;
  • cloud storage, server hosting, code repository, database, document management and backup providers;
  • communication, community and collaboration tools;
  • payment, accounting, finance and administrative providers;
  • professional advisers, such as lawyers, accountants, auditors, insurers and consultants;
  • client-authorised platforms, systems, model providers or integration partners in connection with a project;
  • regulators, public authorities, courts, law enforcement or other parties where required by law or necessary to protect legal rights;
  • prospective buyers, investors, advisers or counterparties in connection with a business sale, merger, restructuring, investment, acquisition or similar transaction, subject to confidentiality and appropriate safeguards.

Where a third party processes personal data on our behalf, we use contracts and safeguards designed to protect personal data and limit processing to authorised purposes. Where a third party acts as an independent controller, such as a community platform when you create your own account on it, its own privacy notice will apply to its processing.

13. INTERNATIONAL TRANSFERS

Some of our service providers, systems, clients or project tools process personal data outside the United Kingdom.

Zoho CRM keeps our records in the European Economic Area, which the UK recognises as providing adequate protection. Several of our providers are US companies that may process data in the United States, including Zapier, Anthropic, OpenAI, Google, GitHub, hCaptcha and Calendly, and Vercel, which receives forms sent from brainqub3.com there. Other providers may process data in other countries.

Where we transfer personal data internationally, we use appropriate safeguards where required by law. These may include:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to the EU Standard Contractual Clauses;
  • standard contractual clauses or equivalent transfer terms;
  • the UK Extension to the EU-US Data Privacy Framework, where applicable;
  • additional technical and organisational safeguards, such as encryption, access controls and data minimisation.

14. HOW LONG WE KEEP PERSONAL DATA

We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, tax, reporting, contractual, security and legitimate business requirements.

We use retention periods based on the type of data, purpose, sensitivity, risk, legal requirements and whether we need the data to establish, exercise or defend legal rights.

Our standard retention approach is:

  • Website analytics: aggregated or anonymous analytics may be kept for as long as useful for trend analysis. Technical logs that contain personal data are normally kept only for a limited period needed for security, debugging and operational purposes.
  • Enquiries that do not become active opportunities: normally up to 24 months after the last meaningful interaction, unless a longer period is justified.
  • Lead magnet and resource download records: normally up to 24 months after the last meaningful interaction, unless you remain engaged, become a client, opt in to receive communications, or a longer period is justified.
  • Discovery call booking details, notes and follow-up records: normally up to 24 months after the last meaningful interaction, unless the matter becomes a client engagement or a longer period is justified.
  • The Architect Programme applications, enterprise enquiries and requests to hear when places open: normally up to 12 months after the last meaningful interaction, unless you take a place or a longer period is justified.
  • Recordings and transcripts of calls and meetings: kept for as long as we need them for the purposes in section 5.5, rather than for a fixed period. For client work, this is normally the length of the engagement and then the period we keep client engagement records. For discovery calls that do not lead to work, it is normally the period we keep discovery call records. We delete recordings and transcripts once we no longer need them.
  • The Architect Programme session recordings and transcripts, Retake Meeting checks and testimonials: as the programme's Terms of Service set out.
  • The Architect Programme debrief notes: normally up to 24 months after the debrief.
  • CRM and business development records: for as long as there is an active business relationship, reasonable prospect relationship or legitimate business need, subject to objections and marketing opt-outs.
  • Marketing consent records: for as long as we rely on your consent, and for a period afterwards so we can show that we had it.
  • Marketing suppression records: minimal information needed to honour an opt-out may be kept for as long as necessary to make sure we do not contact you again for that purpose.
  • Client engagement and programme member records: normally for the duration of the engagement or place and then up to 7 years after it ends for contractual, tax, accounting, audit, insurance and legal purposes, unless a longer period is required.
  • Project working materials and client-provided datasets: retained only for as long as needed for the engagement, support period, handover, quality assurance, security, legal or agreed contractual purposes. Where we act as processor, return or deletion will be handled according to the relevant contract or data processing agreement.
  • Invoices, finance and accounting records: normally up to 7 years from the relevant financial year or transaction.
  • Legal dispute, complaint or claim records: for as long as necessary to resolve the matter and protect legal rights, which may be longer where limitation periods or proceedings require it.

When personal data is no longer needed, we delete it, anonymise it, aggregate it or securely archive it with restricted access until deletion is possible.

15. SECURITY

We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include, depending on the context:

  • access controls and least privilege access;
  • multi-factor authentication where appropriate;
  • encryption in transit and, where appropriate, at rest;
  • private repositories, secure cloud storage and backups;
  • confidentiality obligations;
  • vendor due diligence and contractual protections;
  • separation of client data where appropriate;
  • monitoring, logging and security review;
  • secure development and deployment practices;
  • incident response processes.

No website, transmission or storage system can be guaranteed to be completely secure. If we become aware of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will assess it and notify the Information Commissioner's Office and affected individuals where required by law.

16. YOUR RIGHTS

Under UK data protection law, you may have the following rights:

  • the right to be informed about how your personal data is used;
  • the right of access to your personal data;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure, also known as the right to be forgotten;
  • the right to restrict processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interests;
  • the right to object to direct marketing at any time;
  • the right to withdraw consent where processing is based on consent;
  • rights relating to automated decision-making and profiling.

These rights are not absolute and may depend on the circumstances. For example, we may need to keep some information to comply with legal obligations, maintain suppression records, complete a contract or establish, exercise or defend legal rights.

To exercise your rights, contact us at info@brainqub3.com. We may need to verify your identity before responding. We aim to respond within one month. If a request is complex or we receive multiple requests, we may extend the response period where permitted by law.

17. MARKETING CHOICES

You can opt out of marketing communications at any time by:

  • clicking the unsubscribe link in any of our emails;
  • replying to a marketing email asking to be removed;
  • emailing info@brainqub3.com.

Opting out of marketing does not stop service, transactional or administrative messages, such as messages about an active project, programme place, contract, invoice, security issue or requested resource.

18. THIRD-PARTY WEBSITES AND SERVICES

Our websites may link to third-party websites, platforms, videos, scheduling tools, social networks, course platforms, certification and exam providers or other services. We are not responsible for the privacy practices of those third parties. You should review their privacy notices before providing personal data to them or interacting with embedded content.

19. CHILDREN

Our websites and services are intended for business users and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us at info@brainqub3.com so we can review and take appropriate action.

20. CHANGES TO THIS POLICY

We may update this policy from time to time to reflect changes in our services, providers, technology, legal requirements or data practices. When we make changes, we will update the "Last updated" date above. Material changes may also be notified by additional means where appropriate.

21. COMPLAINTS AND CONTACT

If you have questions about this policy or how we process personal data, contact us first:

Email: info@brainqub3.com

Website: brainqub3.com

Postal address: DATA-CENTRIC SOLUTIONS LTD, 86-90 Paul Street, London, EC2A 4NE, United Kingdom

You also have the right to complain to the UK Information Commissioner's Office.

Information Commissioner's Office

Wycliffe House

Water Lane

Wilmslow

Cheshire

SK9 5AF

United Kingdom

Telephone: 0303 123 1113

Website: ico.org.uk

We would appreciate the opportunity to address your concern before you contact the ICO, but you are not required to contact us first.