Draft for legal review. This notice is written to be accurate about how the platform actually works, so that counsel is editing facts rather than inventing them. It has not yet been reviewed by a qualified lawyer and is not legal advice. Placeholders in [brackets] need a decision before publication.
1. The two-layer point, first
Brandfora is infrastructure. That means personal data reaches us in two very different ways, and your rights differ depending on which one applies to you.
| Who decides what happens to the data | Who we are | |
|---|---|---|
| This website — brandfora.com | Brandfora | Controller |
| A store running on Brandfora — a partner’s branded shop | The partner operating that store | Processor, acting on their instructions |
If you bought something from a branded store and want your data corrected or deleted, the operator of that store is your first contact — they decide, and we act on their instruction. We will always help you reach them. Everything below concerns this website unless it says otherwise.
Controller for this website: [Brandfora legal entity name], [registered address]. Contact: [privacy@brandfora.com]. [Decision needed: is an EU/UK representative or a DPO required? Depends on where the entity is established and the scale of monitoring.]
2. What we collect here, and why
We collect only what a business website needs to function and to answer you.
When you submit an enquiry. Your name, work email, company, and whatever you choose to write, plus the topic you selected and which page you came from. We use it to answer you and to keep a record of the conversation. Lawful basis: legitimate interests — responding to someone who asked us a question.
When you book a meeting. Name, email and anything you add to the booking, via Cal.com. Lawful basis: taking steps at your request before entering a contract.
When you simply read the site. Our host processes standard server logs including IP address, user agent and requested URL, for security and to keep the site up. [Decision needed: we currently run no analytics or advertising cookies. If that stays true, this site needs no cookie banner — only a statement. Confirm before launch and re-check if any tag is ever added.]
We do not buy contact lists, we do not enrich your record from third-party data brokers, and we do not run behavioural advertising.
3. Who else touches it
We use a small number of processors. Each is bound by a contract that limits them to acting on our instructions.
| Processor | What for | Where |
|---|---|---|
| Cloudflare | Hosting, CDN, DDoS protection, server logs | Global edge |
| Resend | Sending enquiry replies | [region] |
| Cal.com | Meeting booking | [region] |
| Google Cloud | File and asset storage | [region] |
[Decision needed: confirm each processor’s contracting entity and hosting region, and complete the transfer basis below.] Where a processor stores data outside the UK/EEA we rely on the UK IDTA or the EU Standard Contractual Clauses together with a transfer risk assessment.
We publish material changes to this list before they take effect.
4. Inside the platform (the processor half)
When a partner runs stores on Brandfora, their buyers’ data is theirs. Some things are worth stating plainly because they are architectural, not policy:
- Tenancy is real. Each partner has its own database, cache key prefix, storage bucket, DNS zone and certificate. Catalog, pricing, customers and theming are per-tenant, not rows in a shared table filtered by an ID.
- Integration credentials are encrypted at rest with AES-256-GCM and are scoped to the tenant that entered them.
- Analytics are first-party and append-only. Raw events are pruned after 90 days; only aggregated daily rollups persist beyond that.
- We do not sell any of it, ever — not tenant data, not buyer data, not in aggregate.
Sub-processors used to deliver the platform itself (payments, email, storage, search, fulfillment and design services) are listed in each partner’s agreement, and partners are notified before that list changes.
5. How long we keep things
| Enquiries and their replies | [24 months] after the last contact, then deleted |
| Booking records | [24 months] |
| Server logs | [30 days] |
6. Your rights
You can ask us for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, withdraw consent at any time, and ask for it in a portable format. Write to [privacy@brandfora.com] and we will respond within one month.
If you are unhappy with how we handled it you can complain to your supervisory authority — in the UK that is the Information Commissioner’s Office.
7. Security, stated honestly
The platform ships TOTP multi-factor authentication on every admin surface, per-store OIDC single sign-on, managed TLS on every custom domain, and encrypted credential storage. A SOC 2 readiness programme is underway; Brandfora is not SOC 2 certified, and we will say so plainly until an auditor says otherwise.
No system is perfectly secure. If you believe you have found a vulnerability, write to [security@brandfora.com] — we will acknowledge within one business day and will not pursue good-faith research.
8. Changes
We will post material changes here and update the date at the top. If a change meaningfully affects your rights we will tell subscribers directly rather than relying on you noticing.