top of page

Privacy Policy

BriefVision Privacy Policy

Last updated: 20 August 2026

This policy explains how BriefVision handles personal data across the marketing website, web app, API, mobile apps, business-development activity, and founding-cohort outreach. It is written for UK legal-sector customers, invited users, website visitors, prospective business contacts, and people whose information may appear in customer case material.

1. Who we are

BriefVision is operated by Dynamics Development Solutions Limited, registered in England and Wales under company number 06692820, with its registered office at International House, South Molton Street, London, W1K 5QF, United Kingdom.

For privacy questions, data protection requests, or complaints, contact us at info@briefvision.co.uk. ICO registration number: ZC178910

In this policy, "BriefVision", "we", "us", and "our" refer to that legal entity.

2. What this policy covers

This policy covers personal data processed through:

 

- the marketing website at www.briefvision.co.uk, including contact or demo forms;

- the BriefVision web app at app.briefvision.co.uk;

- the BriefVision API and backend services;

- BriefVision mobile and tablet apps; and

- support, security, administration, and service communications.

 

Customer agreements, data processing agreements, product terms, or specific notices may add more detail for a particular deployment or customer workflow.

3. When we are controller and when we are processor

We act as a controller for personal data we use to run our business and administer the service, such as website enquiries, account records, authentication, support, security logs, billing or commercial administration, and marketing communications.

 

For customer case files, uploaded evidence, extracted records, document text, generated summaries, notes, search indexes, and similar case material, we usually act as a processor. The customer decides what is uploaded, why it is processed, who can access it, and how long it should be retained, unless a separate agreement says otherwise.

4. Personal data we collect

Website visitors and enquiries

We may collect your name, work email address, phone number, organisation, role, enquiry details, marketing preferences, technical logs, and information collected by Wix forms, hosting, security, and essential cookies.

App users and administrators

We may collect identity and account data from Microsoft, Google, Apple, or Microsoft Entra External ID sign-in, including name, email address, organisation, authentication provider identifiers, tenant membership, case access, roles, permissions, session records, audit events, support messages, and product usage metadata.

Customers may upload or import case material that includes personal data. Depending on what the customer provides, this can include documents, PDFs, emails, messages, call history, contacts, calendar records, notes, web history, URLs, search terms, location data, images, media, voice memos, device and app metadata, extracted text, document metadata, AI prompts, AI outputs, search indexes, embeddings, and review annotations.

 

Case material may include confidential, legally privileged, special category, criminal offence, child, vulnerable person, witness, victim, suspect, employee, or third-party data. Customers are responsible for ensuring they have an appropriate lawful basis and authority to upload and process that material in BriefVision.

Customer case and evidence data

Mobile apps

The mobile apps process account, authentication, case access, document review, search, notes, and app diagnostic data. They do not provide general public self-signup. Secure tokens may be stored on the device to keep invited users signed in.

5. How we use personal data

We use personal data for the following purposes:

Responding to enquiries and arranging demos
We use contact details, organisation details, role information, and enquiry messages to respond to enquiries, arrange demos, and take steps requested before entering into a contract.

Providing and administering BriefVision accounts
We use identity data, tenant membership, roles, permissions, and session records to create, manage, secure, and administer BriefVision accounts. This is usually necessary for contract performance, our legitimate interests, or processing on customer instructions.

Authenticating users and protecting the service
We use authentication provider identifiers, session cookies, tokens, IP information, and audit logs to verify users, maintain secure sessions, prevent unauthorised access, and protect the service.

Processing customer case material
We process evidence uploads, extracted records, notes, search data, and AI outputs so authorised users can review and manage case material. We usually do this as a processor on customer instructions.

Running document extraction, search, and AI-assisted review
We process document text, metadata, prompts, summaries, embeddings, and search indexes to support extraction, search, timeline generation, summaries, and AI-assisted review. We usually do this as a processor on customer instructions.

Providing support and maintaining reliability
We use support messages, diagnostic metadata, operational logs, and service status information to investigate issues, provide support, maintain security, and improve reliability.

Business development and founding-cohort outreach
We may use limited professional information to identify organisations and legal professionals who may have a relevant interest in BriefVision, understand their needs, invite them to product research or the founding cohort, arrange demonstrations, and develop business relationships. This information may include a person's name, professional email address, employer, job title, role or practice area, the reason the contact may be relevant, the source and date collected, communications, and marketing or objection preferences.

We may obtain this information from an organisation's website, Companies House, professional directories, public professional networking profiles, event or membership listings, referrals, or other legitimate public business sources. We do not intentionally collect private contact details or sensitive personal information for outreach.

For relevant named contacts at companies, LLPs and other corporate subscribers, we normally rely on our legitimate interests in developing BriefVision and seeking feedback from the UK legal sector. We assess necessity and impact, keep the information and communications limited and relevant, and provide an easy way to object. We comply with the Privacy and Electronic Communications Regulations and do not send unsolicited electronic marketing to individual subscribers, sole traders or partnerships treated as individual subscribers unless consent, the soft opt-in, or another permitted route applies.

Sending service or marketing communications
We may use contact details, communication preferences, organisation details, and message history to send service updates or relevant marketing communications. Depending on the communication and recipient, we rely on consent or legitimate interests and comply with applicable electronic-marketing rules.

Meeting legal, regulatory, tax, accounting, and claims requirements
We may use account, contract, billing, support, security, and audit records to comply with legal obligations, respond to lawful requests, maintain records, and protect our legal rights.

6. Our lawful bases
Where BriefVision acts as controller, we process personal data where necessary to perform a contract or take requested pre-contract steps; comply with a legal obligation; pursue our legitimate interests or those of a third party where these are not overridden by individual rights; or where consent has been given. Our legitimate interests include operating and securing the service, supporting customers, improving reliability, responding to enquiries, and proportionate business development. Where we rely on consent, it may be withdrawn at any time without affecting earlier processing.

7. Who we share personal data with
We may share personal data with service providers that support our website, cloud hosting, identity and access management, email and communications, payments, monitoring, security, support, and professional administration. These include Wix, Microsoft and relevant service providers, together with payment processors and other providers used for the relevant service. We may also share information with professional advisers, regulators, courts, law-enforcement bodies, or other authorities where required or appropriate. We require service providers acting for us to protect personal data and use it only for authorised purposes. We do not sell personal data.

When we process customer case material as a processor, sharing is governed by the customer's instructions and the applicable customer agreement or data processing agreement.

8. International transfers
Some service providers may process personal data outside the United Kingdom. Where UK data-protection law requires safeguards, we rely on an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful safeguard. Contact info@briefvision.co.uk if you would like more information about safeguards relevant to your data.

9. How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose collected and to meet legal, accounting, security, and claims requirements.

Website enquiries and prospective business-contact records are normally reviewed and deleted or anonymised after 12 months of inactivity, unless there is an active discussion, customer relationship, legal reason, or documented need to retain them longer. If a person objects to marketing, we may retain minimal suppression information so that we can respect the objection.

Account, contract, billing, support, security, and audit records are kept for the duration of the relationship and for any further period reasonably required by law, contract, security needs, or limitation periods. Customer case material is retained and deleted in accordance with customer instructions and the applicable agreement. Residual copies may remain temporarily in secure backups until overwritten through normal backup cycles.

10. Your data-protection rights
Depending on the circumstances, you may have rights to be informed; request access to and a copy of your personal data; correct inaccurate or incomplete data; request erasure; restrict processing; receive portable data; object to processing based on legitimate interests; and withdraw consent. These rights are not absolute and exemptions may apply.

To exercise a right, email info@briefvision.co.uk. We may need information to verify your identity and identify the relevant records. We normally respond within one month as required by UK data-protection law.

11. Your right to object to direct marketing
You have an absolute right to object at any time to our use of your personal data for direct marketing. You can reply to an outreach email, use any unsubscribe option provided, or email info@briefvision.co.uk. We will stop the marketing and may keep only the minimum suppression record needed to honour your request.

12. Complaints
Please contact info@briefvision.co.uk first so that we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office. Information about making a complaint is available at ico.org.uk/make-a-complaint.

13. Automated decision-making and AI-assisted features
BriefVision does not use personal data about website visitors, prospective business contacts, or account administrators to make solely automated decisions that produce legal or similarly significant effects. AI-assisted outputs in the service are tools for authorised customer users. Customers and their users remain responsible for reviewing outputs and making professional or case decisions.

14. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, alteration, disclosure, loss, or destruction. No system can be guaranteed completely secure, and customers and users must also protect their credentials and follow appropriate security practices.

15. Changes to this policy
We may update this policy to reflect changes to our services, providers, legal obligations, or processing. We will publish the revised version on this page, update the date above, and provide additional notice where a change is material.

bottom of page