Braiv Tech Pty Ltd

Trust Center

How we protect your content, your data, and the people in your videos — security practices, sub-processors, international transfers, and your privacy choices, all in one place.

Encrypted everywhere

TLS 1.2+ in transit and AES-256 at rest across all storage, on Google Cloud and Microsoft Azure.

Australian data residency

Content and databases are hosted in Australia. Our in-house speech synthesis runs in Sydney.

No AI training on your content

We don't use your content to train AI models, and our AI providers are bound by no-training terms or opt-outs.

GDPR-ready transfers

EU Standard Contractual Clauses, the UK Addendum, and the EU-US Data Privacy Framework underpin every cross-border flow.

Consent-first analytics

Analytics, marketing and session recording run only with your consent. We honour Global Privacy Control as a full opt-out.

DPA for business customers

A negotiated, countersigned Data Processing Agreement — with SCCs and the UK Addendum built in — is available to Enterprise customers.

Security

We build security in from the architecture up. Braiv runs on managed, containerised cloud infrastructure — Google Cloud in Australia, and Microsoft Azure in Sydney running our media processing pipelines, including our in-house speech-synthesis service (with one Singapore compute instance used transiently for video imports). We operate no physical servers of our own.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256, platform-managed on Google Cloud and Azure).

Access control

Production access is restricted on a least-privilege basis, and multi-factor authentication is enforced on all administrative and vendor accounts.

Security testing

Adversarial security testing at least every six months, including AI-assisted adversarial code and configuration review, plus continuous automated dependency and vulnerability scanning.

Monitoring & logging

Centralised error and performance monitoring with alerting, cloud audit logging, and application log retention capped at 90 days.

Incident response

A documented incident response plan with designated roles and escalation paths. Enterprise customers are notified of personal data breaches without undue delay, and in any event within 72 hours, under our DPA.

Development practices

Code review before production deployment, segregated production and development environments, and provider-managed secret storage.

Braiv does not currently hold third-party certifications such as SOC 2 or ISO 27001. Our key infrastructure providers (Google, Microsoft, Mux, Stripe) maintain ISO 27001 and/or SOC 2 attestations, available from their trust portals. We believe in telling you exactly where we are rather than implying otherwise.

Data Processing & DPA

When you upload content containing other people's personal data — the speakers in your videos, your learners, your customers — you are the controller of that data and Braiv processes it on your instructions. For your own account and billing data, Braiv is the controller, as described in our Privacy Policy.

  • No AI training. We do not use your content or personal data to train AI models. Creating your own voice clones, localised voices and generated media is the service — those outputs belong to your workspace and are made at your instruction. Our AI providers are contractually restricted from training on your content.
  • Deletion. When you delete content or close your account, we delete personal data from systems under our control within 30 days. Copies held by sub-processors are purged on their contractual deletion cycles.
  • Breach notification. Without undue delay, and within 72 hours for customers on our DPA.
  • Sub-processor changes. At least 10 days' advance notice by email and on this page before a new sub-processor handles customer data, with a right to object.

Enterprise customers can request our negotiated, countersigned Data Processing Agreement — including EU Standard Contractual Clauses (Modules 2 and 3), the UK Addendum, and a full technical and organisational measures schedule — by contacting support@braiv.co.

Sub-Processors

Vendors that process personal data on our behalf to deliver the platform. Each is bound by a data processing agreement with protections consistent with our own commitments. Several are engaged only when you use the corresponding feature — if you don't use it, they never receive your data. Infrastructure and support vendors are named below; AI media providers used in optional pipeline features are summarised as a category. The full named list (legal entity, location, transfer mechanism and purge window) is in our Enterprise DPA and available to customers on request.

Google

Cloud infrastructure, authentication & YouTube integrations

Australia / Global

Microsoft

Cloud compute for media pipelines

Australia / Singapore

Mux

Video processing & delivery

US / Global edge

Vercel

Application hosting

US / Global

Stripe

Payments

US

AI media providers

Transcription, dubbing, translation & generation

US / EEA · Named in DPA

Klaviyo

Transactional email

US

Intercom

Customer support

US

Sentry

Error monitoring & replay

US · Replay consent-gated

PostHog

Product analytics

US · Consent-gated

Tolt

Affiliate attribution

US

Website analytics (Google Analytics / Tag Manager) are consent-gated and covered by our Cookie Policy, not by content sub-processing. Optional publishing integrations (YouTube, TikTok, Instagram, LinkedIn) are customer-connected accounts and are not Braiv sub-processors under our DPA. When we add or change a sub-processor, we update this page and give active customers at least 10 days' notice by email.

International Transfers

Braiv is an Australian company. Your content and databases are stored in Australia; one Singapore compute instance is used transiently for video imports; and some sub-processors listed above operate in the United States. Australia does not hold an EU adequacy decision, so every restricted transfer is protected by a recognised mechanism: EU Standard Contractual Clauses (Modules 2 and 3), the UK International Data Transfer Addendum, and — for certified US providers — the EU-US Data Privacy Framework with its UK and Swiss extensions. Our DPA includes supplementary measures and commitments on government access requests to support your transfer impact assessments.

Your Privacy Choices

You control what optional data we collect — wherever you are. If you're in a region where consent is granted by default, you can still review and change your preferences here at any time.

Do Not Sell or Share My Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. California and other US-state residents can confirm an opt-out of any "sale" or "sharing" by choosing Reject non-essential above, or by enabling Global Privacy Control in their browser — we treat GPC as a valid opt-out signal.

To exercise data rights — access, correction, deletion, or portability — email support@braiv.co. We respond within 30 days.