Privacy Policy
Effective date – 3 July 2026
Version 1.0
1. About this policy
This privacy policy explains how FibreCRM Limited (“FibreCRM”, “we”, “us” or “our”) handles personal information in connection with the public website at usebraid.co.uk (the “Website”) and the Braid risk assessment platform at usebraid.ai (the “Platform”).
It applies principally to authorised users of the Platform, prospective users and visitors to the Website. It also explains, at a high level, how the Platform processes information about clients, directors, beneficial owners and other connected individuals on behalf of customer accounting firms.
Where an accounting firm uses Braid to assess a client or prospective client, that firm is responsible for providing any privacy information required to the people whose information it uses. This policy does not replace the accounting firm’s own privacy notice.
This policy should be read with the customer agreement, data processing agreement and any cookie policy made available on the Website. If there is a conflict concerning processing carried out for a customer firm, the applicable contract and data processing agreement will take priority to the extent permitted by law.
2. Who we are and our data protection roles
2.1 FibreCRM Limited
Braid is operated by FibreCRM Limited, a company registered in England and Wales under company number 06059445. Our correspondence address is Pool Innovation Centre, Trevenson Road, Redruth, Cornwall, TR15 3PL, United Kingdom. Our Information Commissioner’s Office registration number is ZA084151.
2.2 When the customer accounting firm is the controller
For personal information entered into, generated by or stored in a client risk assessment, the customer accounting firm decides the purposes and essential means of the processing. The customer firm is therefore the data controller and FibreCRM acts as its data processor. We process this information only on the customer’s documented instructions, subject to the customer agreement and data processing agreement.
2.3 When FibreCRM is the controller
FibreCRM acts as a data controller for personal information that we use for our own purposes, including Website analytics, platform account administration, service communications, support, security monitoring, legal compliance, product improvement and direct marketing.
2.4 Data Protection Officer
Our appointed Data Protection FibreCRM Limited You can contact the Data Protection Officer through privacy@fibrecrm.com or by writing to our address above, marked for the attention of the Data Protection Officer.
3. The personal information we handle
3.1 Website visitors and prospective customers
- contact details, such as your name, business email address, telephone number, organisation and job title;
- information you provide through enquiries, demonstrations, meetings, forms and correspondence;
- marketing preferences and records of your interactions with our communications; and
- analytics and technical information, such as IP address, device and browser information, pages viewed, referring website, approximate location and interaction data, where you consent to Google Analytics.
3.2 Platform users
- identity and business contact information, including name, business email address, organisation and role;
- account and access information, including username, hashed password information, permissions, firm membership and account status;
- technical and security information, including IP address, device and browser information, login times, audit events, session information and security logs;
- support information, including messages, screenshots, diagnostic information and details of issues raised; and
- usage information, including features used, actions performed, assessment status and administrative activity.
3.3 Client assessment information processed for customer firms
Depending on the assessment and the customer’s configuration, the Platform may process:
- names and contact or identification information relating to clients, directors, officers, persons with significant control, beneficial owners and other connected individuals;
- company names, company numbers, registered details, business activities, ownership structures and Companies House records;
- date of birth, home address, nationality and source-of-funds information supplied through the Platform’s API or user interface;
- customer-supplied risk questionnaire responses, services being considered, internal risk factors, partner commentary, MLRO or MLCP review information and final risk scores;
- sanctions, politically exposed person (PEP) and adverse-media screening results, including source links, publication dates and search findings;
- risk assessment reports, recommended actions, audit records and generated PDF documents; and
- customer policy documents, rules, thresholds and instructions used to configure assessments.
Screening data may include allegations, regulatory findings, sanctions information or information about actual or suspected criminal conduct. It may also incidentally reveal sensitive information contained in public reporting. The customer firm is responsible for determining whether it has an appropriate lawful basis and, where required, an additional condition for processing this information.
Users should avoid placing personal information in free-text fields or support requests unless it is necessary for the relevant assessment or support issue and permitted by their firm’s policies.
4. Where information comes from
We may obtain personal information from:
- you, when you register, sign in, contact us, use the Platform or communicate with us;
- your employer or customer accounting firm, including its administrators and authorised integrations;
- APIs, webhooks or connected systems configured by the customer firm;
- official and public sources, including Companies House and the UK Sanctions List;
- screening and research providers, including OpenSanctions where optional PEP screening is enabled, Tavily for adverse-media and background searches, and the public webpages returned by those searches;
- our systems automatically, through security logs, audit records and strictly necessary session technologies; and
- marketing and business-development activity, including events, enquiries and customer relationship records.
5. How we use information and our lawful bases
The lawful basis depends on the context. Where FibreCRM acts as a processor, the customer accounting firm determines the lawful basis. Where FibreCRM acts as a controller, we generally rely on the bases described below.
|
Purpose |
Information typically used |
Lawful basis |
|
Provide and administer the Website and Platform |
Contact, account, role, usage and customer relationship information |
Contract where you are a party; otherwise legitimate interests in delivering services to the customer firm |
|
Authenticate users and protect the service |
Account, login, IP address, device, session, security and audit information |
Legitimate interests in preventing misuse, maintaining security and protecting users and customers; legal obligation where applicable |
|
Provide support and service communications |
Contact details, account details, correspondence and diagnostics |
Contract and legitimate interests in supporting the service |
|
Manage customer relationships, billing and records |
Business contact, contract, transaction and communication information |
Contract, legitimate interests and legal obligation |
|
Improve reliability, usability and performance |
Usage, diagnostics, feedback and aggregated service information |
Legitimate interests in improving the service; consent where required for analytics technologies |
|
Send product updates and marketing |
Business contact details, preferences and engagement information |
Consent where required; otherwise legitimate interests in business-to-business marketing, subject to your right to object |
|
Comply with law and handle disputes |
Relevant account, communication, security and transaction information |
Legal obligation and legitimate interests in establishing, exercising or defending legal claims |
|
Website analytics through Google Analytics |
Online identifiers, device/browser and Website interaction information |
Consent |
Where we rely on legitimate interests, those interests include operating a secure and effective business service, supporting customers, maintaining business records, improving our products and communicating with business users. We consider the effect on individuals and apply safeguards appropriate to the circumstances.
You are not generally required by law to provide personal information to FibreCRM. However, some information is required to create and secure an account, provide support or enter into and administer a customer relationship. If it is not provided, the relevant service may not be available.
6. Client assessment data processed for customer firms
When a customer accounting firm uses Braid to assess a client or prospective client, FibreCRM processes the assessment information as a processor. This means:
- the customer firm decides what information is submitted, why it is processed and how long it should be retained, subject to the Platform’s functionality and the customer contract;
- FibreCRM processes the information to host the Platform, perform screening and research, generate the assessment, store the results, create PDFs, provide audit records and deliver results through customer-configured integrations;
- FibreCRM does not use client assessment information for its own direct marketing or sell it to third parties;
- requests about access, correction, deletion, restriction, objection or other rights relating to an assessment should normally be made to the customer accounting firm; and
- FibreCRM will assist the customer firm with rights requests, security incidents and compliance obligations in accordance with the data processing agreement.
A customer may configure the Platform to send information to a webhook, CRM or other destination selected by that customer. Such delivery is made on the customer’s instructions. The customer is responsible for ensuring that its chosen destination and onward use are lawful and secure.
7. AI-assisted risk assessment and human review
Braid uses Google Cloud Vertex AI to help produce a structured risk assessment. The system combines information supplied by the customer with research and screening results, applies the customer firm’s configured policies and rules, and generates a report and suggested risk indication.
The AI-generated assessment is decision support only. It does not make the final decision about whether a client should be accepted, rejected or subject to enhanced due diligence. The partner responsible for the client must review the assessment and determine the final risk score. Where the matter is considered high risk, the firm’s MLRO or other designated compliance officer is involved in the final review.
The responsible partner can record whether they agree or disagree with the AI assessment and add their own final commentary. This creates a record of meaningful human review and allows the firm to correct or depart from the AI output.
AI-generated content can be incomplete or incorrect. The Platform is designed to use structured inputs, evidence and validation controls, but customer users remain responsible for checking the accuracy, relevance and proportionality of the output before relying on it.
Limited assessment information is sent to Google Cloud Vertex AI for processing in the europe-west1 region in Belgium. Under the enterprise service terms used for the Platform, customer prompts and outputs are not used to train or fine-tune Google’s models without permission or instruction. See section 9 for information about international transfers.
8. Who we share information with
We may disclose personal information to the following categories of recipients, only where necessary for the purposes described in this policy:
- Amazon Web Services, which hosts the Platform and its backups in the United Kingdom (eu-west-2);
- Google Cloud Vertex AI, which performs AI processing in Belgium (europe-west1);
- Tavily, which supports adverse-media and background searches, together with the public websites returned in search results;
- OpenSanctions, where the customer has chosen to enable optional PEP screening; PEP screening is disabled by default;
- Google Analytics, where a Website visitor has consented to analytics;
- Campaign Monitor, for permitted product updates and marketing communications;
- customer-configured CRM systems, webhooks and integration providers, acting on the customer’s instructions;
- professional advisers, insurers, auditors and corporate transaction advisers, subject to appropriate confidentiality obligations;
- regulators, courts, law-enforcement bodies and public authorities where disclosure is required or permitted by law; and
- a purchaser, investor or successor in connection with a proposed or completed corporate transaction, subject to appropriate safeguards.
Our suppliers may act as processors or, for limited activities, as independent controllers. We require processors to handle personal information under written terms and appropriate security and confidentiality obligations. A current subprocessor schedule may also be provided to customer firms under the applicable data processing agreement.
9. International transfers
The main Platform application, database and backups are hosted by Amazon Web Services in the United Kingdom, in the eu-west-2 region.
Some AI processing takes place through Google Cloud Vertex AI in Belgium. Belgium is in the European Economic Area, which is recognised by the United Kingdom as providing adequate protection for personal information. The selected regional configuration is intended to keep that AI processing within the stated European region.
Some other suppliers, including providers of analytics, marketing or online research services, may process personal information in countries outside the United Kingdom. Where a restricted transfer occurs, we use an applicable lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another safeguard permitted by UK data protection law. We also assess the protections provided by the recipient and apply supplementary measures where appropriate.
Customer-configured integrations may send assessment information to locations selected by the customer firm. In those circumstances, the transfer is made on the customer’s instructions and the customer is responsible for assessing and documenting the transfer as controller.
You may contact privacy@fibrecrm.com for more information about the safeguards relevant to a particular transfer.
10. Retention and deletion
We retain personal information only for as long as necessary for the purposes for which it is used, including contractual, security, regulatory and legal requirements. The following Platform rules apply unless a customer contract or legal requirement requires otherwise:
- Platform user accounts are deleted after 12 months of inactivity;
- a customer firm’s Platform record, configuration and uploaded policies are removed after 12 months of inactivity;
- completed assessments remain available until they are manually deleted by an authorised user or the customer’s service terminates;
- on termination, customer data in the live service is deleted. Customers should download any required completed assessment PDFs before termination;
- backup copies are removed through the ordinary backup rotation and overwrite cycle; and
- security, audit and diagnostic logs are retained for the period reasonably required to operate and protect the service, investigate incidents and meet legal obligations.
We may retain limited records for longer where necessary to establish, exercise or defend legal claims, meet a legal obligation, investigate fraud or security incidents, or maintain a suppression record showing that a person has opted out of marketing. Where possible, information retained for these purposes is restricted from ordinary use.
11. Security
We use technical and organisational measures designed to protect personal information against unauthorised access, accidental loss, alteration, disclosure or destruction. Measures used for the Platform include:
- firm-level tenant separation and application controls that scope customer data to the relevant firm;
- role-based access controls for customer users, firm administrators and authorised FibreCRM personnel;
- password hashing, authenticated sessions and controlled password reset processes;
- HTTPS encryption for data in transit and managed secure hosting in AWS eu-west-2;
- hashed and revocable integration credentials, with secrets held in secure configuration rather than source code;
- logging, monitoring, queue controls, backups and operational recovery procedures; and
- access restrictions and contractual obligations for personnel and service providers.
No internet-based service can be guaranteed to be completely secure. Users are responsible for protecting their login credentials, using the Platform only through approved devices and networks, and promptly reporting suspected compromise or unauthorised access.
If a personal data breach affects information processed for a customer firm, we will notify and assist the customer in accordance with the data processing agreement. Where FibreCRM is the controller, we will assess and make any notification required by applicable law.
12. Marketing communications
We may send product updates, service announcements, event information and other business-to-business communications through Campaign Monitor and our customer relationship management system.
We rely on consent where it is required by the Privacy and Electronic Communications Regulations. In other business-to-business circumstances, we may rely on our legitimate interests in communicating with customers and relevant business contacts. Every marketing email will provide an unsubscribe option, and you may object at any time by contacting privacy@fibrecrm.com.
Unsubscribing from marketing does not prevent us from sending operational messages that are necessary to administer your account, provide the service, communicate security matters or meet contractual and legal obligations.
13. Cookies and analytics
The Website uses Google Analytics to help us understand how visitors use the Website. Google Analytics may collect online identifiers, device and browser information, approximate location, referring information, pages viewed and interaction data.
We will not use Google Analytics or place non-essential analytics technologies unless you have provided valid consent through the Website’s consent mechanism. You can withdraw or change that consent at any time through the cookie settings made available on the Website.
The Platform may use technologies that are strictly necessary for secure authentication, session management, fraud prevention and user-requested functionality. These technologies are not used for advertising.
Further information, including the names, purposes and durations of technologies in use, will be provided in our Cookie Policy.
14. Your rights
Depending on the circumstances, you may have the following rights in relation to personal information:
- to be informed about how your information is used;
- to request access to your personal information;
- to request correction of inaccurate or incomplete information;
- to request deletion of information in certain circumstances;
- to request restriction of processing in certain circumstances;
- to object to processing based on legitimate interests and to object to direct marketing at any time;
- to receive certain information in a portable format where the right to data portability applies;
- to withdraw consent at any time, without affecting processing that was lawful before withdrawal; and
- to raise concerns about AI-assisted processing and request appropriate human consideration where applicable.
These rights are not absolute and may be limited by exemptions or other legal requirements. We may need to verify your identity before responding.
14.1 Requests about Platform accounts, Website use or FibreCRM marketing
Contact privacy@fibrecrm.com. We will respond within the period required by law.
14.2 Requests about a client risk assessment
Contact the accounting firm that created or commissioned the assessment. That firm is the controller and is responsible for handling the request. If you contact FibreCRM directly, we will normally refer the request to the relevant customer firm and assist it as required by our data processing agreement.
15. Complaints
Please contact our Data Protection Officer at privacy@fibrecrm.com if you have a concern or complaint about how FibreCRM uses personal information. We will acknowledge a data protection complaint within 30 days and respond without undue delay, in accordance with applicable law.
You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data protection regulator:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
We would appreciate the opportunity to address your concerns before you contact the ICO, although you are not required to contact us first.
16. Children
The Website and Platform are designed for business and professional use and are not intended for children. We do not knowingly create Platform user accounts for people under 18. Information about a minor should not be submitted in an assessment unless the customer firm has determined that the processing is necessary, lawful and appropriately protected.
17. Changes to this policy
We may update this policy to reflect changes to the Platform, our suppliers, the law or our processing activities. We will publish the updated version on the Website, make it available through the Platform and change the effective date. Where a change is material, we may also notify customer administrators or Platform users through the service or by email.
18. Contact details
Which organisation should I contact?
For questions about your Braid account, Website use, FibreCRM marketing or this policy, contact FibreCRM. For questions about the contents of a client risk assessment, contact the accounting firm that created or commissioned the assessment.
|
Organisation |
FibreCRM Limited |
|
Product |
Braid risk assessment platform |
|
Address |
Pool Innovation Centre, Trevenson Road, Redruth, Cornwall, TR15 3PL, United Kingdom |
|
Privacy email |
|
|
Data Protection Officer |
FibreCRM Limited |
|
ICO registration |
