Compliance & Data Transparency

Privacy Policy & Public Ingestion Protocols

BrandEye is engineered with privacy-by-design at every layer. We ingest strictly public social discourse, prohibit individual user profiling, guarantee customer query isolation, and enforce zero model training on your private analytical workflows.

Updated: October 2026 Frameworks: GDPR · CCPA · DPDP Zero Demographic Profiling

1. Scope of Public Data Ingestion

Public Sources

BrandEye processes exclusively publicly accessible content across digital social networks and open media ecosystems, including Reddit public subreddits, YouTube comments and video metadata, Instagram public posts, LinkedIn public discourse, Bluesky posts, and indexed RSS feeds.

What BrandEye NEVER Accesses or Stores:
  • Direct messages (DMs), private group chats, or closed forum threads.
  • User account passwords, phone numbers, or private payment records.
  • Content from password-protected walls or paywalled private intranets.
  • Deleted social media posts once notified through official network removal webhooks.

2. Zero Personal Profiling Mandate

Theme-Level Only

Our machine learning pipelines (RoBERTa and AI) evaluate text semantics, sentiment polarity, and emotional drivers strictly at an aggregate thematic level. BrandEye does not build personal demographic profiles, behavioral ad trackers, or surveillance dossiers on individual platform users.

Aggregate Volume & NSS

We calculate net sentiment scores, volume curves, and crisis spikes across millions of posts without tying sentiment to individual citizens.

Anonymous Ingestion

Internal analytical storage strips unnecessary metadata and handles public handles purely as contextual reference for original quotes.

3. Legal Basis & Global Privacy Frameworks

GDPR / CCPA

BrandEye operates under well-established international data protection standards for market research and public media intelligence:

  • GDPR (Article 6(1)(f) Legitimate Interests): Ingestion of public brand mentions is conducted for the legitimate commercial purpose of market reputation monitoring, PR risk mitigation, and consumer sentiment intelligence.
  • CCPA / CPRA Compliance: BrandEye does not sell personal information to data brokers or advertising exchanges. Consumers may request verification or exclusion of their public handle via our DPO desk.
  • India Digital Personal Data Protection (DPDP) Act: Ingestion pipelines respect publicly available data exemptions and implement stringent processing safeguards for regional dialect processing.

4. Workspace Isolation & Model Governance

Zero Model Training

Customer queries, configured keywords, private tags, and generated PowerPoint/Google Sheet reports reside in logically isolated multi-tenant database partitions.

AI Model Training Guarantee:

We mandate zero model training on customer workspace data. Enterprise prompts sent to synthesis engines are ephemeral and stateless, processed under zero-data-retention enterprise enterprise agreements.

5. Retention Schedules & Data Erasure

Automated Purge

BrandEye does not retain historical public social data indefinitely. Cached mention payloads expire automatically on fixed retention schedules based on customer subscription tiers:

Standard Ingestion Buffer:90-Day Rolling Cache
Enterprise Extended Archive:365-Day Partition (Contractual)
Account Termination Purge:30-Day Export Window, then Complete Erasure

Customers may request complete data expulsion or export at any time by contacting support or using the dashboard data governance controls.

6. Cryptographic Security Standards

TLS 1.3 / AES-256

All data in transit across BrandEye applications, public APIs, and external webhook integrations is protected with strict TLS 1.3 encryption and HSTS preloading. Stored persistent database volumes and cold backup snapshots utilize AES-256 encryption at rest.

Multi-factor authentication (MFA) and granular Role-Based Access Control (RBAC) ensure that access to organizational intelligence is strictly partitioned among your team members.

7. Sub-Processors & Cloud Architecture

Infrastructure

BrandEye partners with Tier-4 cloud infrastructure providers and certified processing vendors under strict Data Processing Addendums (DPAs):

Cloud Hosting & Storage
Tier-4 regional data centers with SOC 2 & ISO 27001 certifications.
AI Synthesis Infrastructure
Enterprise zero-retention inference APIs (Google Gemini / Vertex Cloud).

8. Data Subject Rights & Contact DPO

Your Rights

Under applicable privacy laws, you possess the right to: (a) request access to personal data processed in connection with your account; (b) request correction or deletion; (c) object to processing; and (d) request portability of your stored workspace configurations.

Submit a Data Subject Request or DPA Inquiry
Our compliance team handles all inquiries within 5 business days.
Contact Privacy Team