Data processing, on your terms.

Last updated 4 July 2026

Brayns is built to run inside the environments of regulated financial institutions, on some of the most sensitive data a firm holds. How we process that data is not an afterthought. It is the core of how the product is designed. This page explains the roles, the safeguards and your rights.

01

Controller and processor

Under the GDPR, your firm is the data controller. You decide what personal data enters your compliance operation and why. Brayns acts as a data processor, handling that data only on your instructions and only to run the workflows you have configured. A data processing agreement governs the relationship and forms part of every customer contract.

02

Inside your environment

Brayns runs inside your own environment. Your policies, your case history and the personal data they contain stay where they already sit. We do not move your data into a shared platform, and we do not pool it with any other customer. Data residency is a deployment choice you make, not a promise we ask you to trust.

03

Your data does not train a shared model

Nothing from your operation is used to train a model that serves anyone else. Your cases and decisions make Brayns sharper at your compliance, inside your instance, and nowhere else. What is yours stays yours.

04

Purpose and minimisation

Brayns processes the personal data needed to carry out the compliance tasks you assign: customer records, transaction detail, screening results and the case notes that go with them. It processes that data to run your SOPs, clear routine cases, escalate the ones that need a person and keep a complete audit trail. It does not process personal data for any purpose you have not set.

05

How your data is protected

Access is controlled and least-privilege. Data is encrypted in transit and at rest. Every action the system takes is logged with its reasoning, which means the processing itself is auditable rather than opaque. We follow recognised security practices and support the controls your own risk and security teams require.

06

Third parties

We keep the number of sub-processors small and use them only where they are needed to deliver the service. Where a sub-processor is involved, it is bound by data protection terms consistent with this page and with your data processing agreement. A current list of sub-processors is available to customers on request.

07

Supporting the controller

As the controller, your firm remains responsible for the lawful basis of processing and for responding to data subject requests. Brayns is built to support those obligations: because every decision is traceable and the data stays within your environment, retrieving, correcting or deleting records is straightforward. We assist with data subject requests, deletion and audits as set out in the data processing agreement.

08

Status & contact

This page is informational and not legal advice. The binding terms are those in your data processing agreement.

Questions about data processing or to request our sub-processor list or DPA? Email contact@brayns.ai