Privacy Policy
Last Updated: Aug 13th 2026
1. Introduction and Scope
Brella Ltd. and its affiliate Brella Inc. (“Brella”, “we”, “our”, or “us”) respect the privacy of every individual whose personal data we process. This Privacy Policy (“Policy” or "Notice") explains in detail how Brella collects, uses, discloses, transfers, and safeguards personal data in connection with our websites, event-networking platform, mobile applications, and any related services (collectively, the “Services”).
Brella provides event-networking software to clients (“Organizers”), enabling them to host virtual, hybrid, and in-person events. Depending on the context, Brella may act as either:
- a Data Processor (or “Service Provider”), processing personal data strictly on behalf of the Organizer under a written agreement; or
- a Data Controller, determining the purposes and means of processing personal data
2. Contact Information
When Brella processes personal data on behalf of an Organizer, the specific Brella entity acting as Processor is identified in the Data Processing Agreement between Brella and that Organizer. The Organizer remains the primary contact for exercising your rights as an Attendee or Event Registrant; Brella will assist the Organizer as required under Article 28 GDPR.
Brella Ltd.
Siltasaarenkatu 10, 00530 Helsinki, Finland
Privacy contact: dpo@brella.io
If you have questions, requests, or complaints regarding this Policy or our privacy practices, you may contact our privacy contact using the above details.
3. Categories of Personal Data Processed
We process personal data relating to users, Organizers, and visitors as follows.
3.1 Data You Provide to Us
- Identification details (name, title, company, role)
- Contact information (email address, telephone number, postal address)
- Account credentials (username, password, authentication tokens)
- Profile information (photo, biography, interests, skills, social links)
- Event activity (agenda choices, sessions attended, messages sent, meetings scheduled)
- Communications with Brella (support requests, feedback, surveys)
- Marketing preferences and consent records
3.2 Data Received from Organizers or Third Parties
Organizers may provide attendee data—such as registration details or ticketing IDs—to enable event access and networking. Brella processes such data under the Organizer’s instructions and contractual agreement.
We may also receive information from third-party integrations (ticketing, CRM, or SSO providers) and public sources such as professional networks.
3.3 Automatically Collected Data
- Technical identifiers (IP address, device ID, browser type, OS, time zone)
- Usage data (pages visited, clickstream, session duration)
- Diagnostic logs and error reports
- Cookies, pixels, and analytics beacons
- Approximate geolocation (if enabled)
4. How and why we use personal data
Brella acts in two capacities. For our own business — our website, marketing, customer relationships and the operation of our platform — we determine how personal data is used. For the personal data an Organizer collects and manages through their event, the Organizer determines how it is used and we act on their instructions.
Where we determine how personal data is used
|
Purpose |
Legal basis |
|
Providing, operating, maintaining and improving our platform and services |
Performance of a contract (Art. 6(1)(b)); our legitimate interest in operating and developing our services (Art. 6(1)(f)) |
|
Managing customer and commercial relationships, including sales, billing and support |
Performance of a contract, or steps taken before entering one (Art. 6(1)(b)); statutory record-keeping (Art. 6(1)(c)) |
|
Marketing and communications about our services |
Your consent where required (Art. 6(1)(a)); otherwise our legitimate interest in promoting our services to business contacts (Art. 6(1)(f)) |
|
Security, integrity and prevention of misuse |
Our legitimate interest, and that of our customers, in a secure service (Art. 6(1)(f)); legal requirements (Art. 6(1)(c)) |
|
Compliance with law, and establishing or defending legal claims |
Legal obligation (Art. 6(1)(c)); our legitimate interest in protecting our legal position (Art. 6(1)(f)) |
Where we rely on consent, you may withdraw it at any time. This does not affect processing carried out beforehand.
Where an Organizer determines how personal data is used
Where we process personal data on an Organizer's behalf in connection with their event, the Organizer is responsible for deciding what is collected and why, and for providing you with information about that processing and the legal basis for it. We act on their documented instructions. If you contact us with a request relating to that data, we will pass it to the relevant Organizer and assist them in responding.
5. Disclosure and Recipients of Personal Data
Brella shares personal data only under lawful conditions and appropriate safeguards.
- Organizers: Attendee data shared with event Organizers for management and analytics.
- Service Providers and Sub-processors: Cloud hosting, communications, analytics, and support vendors under Data Processing Agreements (DPAs).
- Corporate Affiliates: Internal administrative and operational purposes.
- Integration Partners: Optional SSO, calendar, ticketing, or CRM connections enabled by you.
- Public or Other Users: Limited profile data visible to other attendees based on your settings.
- Regulatory and Legal Authorities: When required by law or to protect rights and safety.
- Business Transfers: As part of a merger, acquisition, or corporate reorganization, subject to continuing protections.
- Sponsors. Where an Organizer has enabled it and you choose to share your information with a Sponsor (for example, by visiting a Sponsor's booth, scanning, or opting in within the Service), we share limited profile and interaction data with that Sponsor.
Brella does not sell or rent personal data to third parties.
6. International Data Transfers
Where providing the Services requires a transfer outside the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers subject to UK law and the amendments recognised by the Swiss Federal Data Protection and Information Commissioner for transfers subject to Swiss law. We carry out transfer impact assessments and apply additional technical and organisational measures — including encryption, access controls and segmentation — where appropriate. Where a recipient also holds an active certification under the EU–U.S. Data Privacy Framework, we take that into account as an additional safeguard.
7. Data Retention
We only keep your information for as long as we genuinely need it — to provide our services, meet our contractual obligations, or comply with legal requirements.
Here's how it works:
• Account information (including messages): where we process personal data for contractual purposes, we keep it for as long as it is necessary to fulfil the contractual obligations. For other purposes, we keep it for as long as it is necessary to fulfil the purpose of the processing. We also have the right to delete an inactive account as described in the Participant Terms. Where Brella processes Personal Data on behalf of an Organizer, retention and deletion are governed by the Organizer's instructions and the applicable Data Processing Agreement.
• Event information: kept for the duration instructed by the event organizer.
• Financial records and compliance documentation: kept for as long as required by law or needed to resolve any disputes.
• Security and operational data (like logs): retained for the minimum time necessary to ensure system integrity, prevent misuse, or comply with audits and regulations.
When the retention period ends — or if you delete your account — we have the right to securely erase or anonymize your personal information so it can no longer be linked back to you.
8. Data Subject Rights
Depending on your jurisdiction, you may exercise the following rights:
- Access and confirmation of processing
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Portability of data
- Objection to processing based on legitimate interest or direct marketing
- Withdrawal of consent
- Complaint to a supervisory authority
Requests should be submitted to dpo@brella.io. We may require identity verification to protect your data.
When Brella acts as a processor, we will forward the request to the relevant Organizer.
9. Security of Processing
Brella implements appropriate technical and organizational measures under Article 32 GDPR, including:
- Encryption of data in transit and at rest (TLS 1.2+, AES-256);
- ISO 27001-certification
- Multi-factor authentication and role-based access;
- Data minimization and segregation;
- Security awareness training for personnel; and
- Incident response and breach notification protocols.
In the event of a personal data breach, Brella will act according to its role in the processing. Where Brella acts as a processor on behalf of an Organizer, Brella will notify the relevant Organizer without undue delay after becoming aware of the breach, in accordance with the applicable Data Processing Agreement, and will provide reasonable assistance to the Organizer in meeting its own notification obligations. Where Brella acts as a controller and applicable law requires notification to a supervisory authority or to affected individuals, Brella will make those notifications within the timeframes and in the manner required by that law.
10. Cookies and Similar Technologies
We use cookies, pixels, and analytics tools to operate and improve our Services.
- Essential cookies – required for security and authentication.
- Functional cookies – store preferences and enhance experience.
- Analytics cookies – collect aggregate usage data.
- Advertising cookies – used only with explicit consent.
Users may adjust cookie settings via browser controls or our cookie banner. See our Cookie Policy for details.
11. Children’s Privacy
Our Services are not directed to individuals under 16 years of age. We do not knowingly collect data from children. If such data is discovered, it will be promptly erased.
12. Automated Decision-Making, Artificial Intelligence (AI), and Profiling
Where enabled by an Organizer for a given event, Brella may deploy artificial-intelligence ("AI") and algorithmic-processing capabilities within the Services to enhance functionality and user experience. Organizers control whether AI-based features are activated for their event, and Brella implements such functionality solely on the Organizer's documented instructions where Brella acts as a processor.
These activities include:
- automated matching and recommendation engines used to suggest networking opportunities, sessions, or content based on user-supplied profile data and declared interests;
- translation services, where enabled by the Organizer, using AI to help attendees interact, communicate, or access content in their preferred language;
- an AI-powered chatbot available to assist users with support requests, combining automated responses with the option to escalate to human support;
- fraud- and abuse-detection models analysing technical and behavioural indicators; and
- generative features, where enabled by the Organizer, producing summaries, descriptions, or other content from event and profile data.
How we use your data in AI features. We use your profile information, declared interests and event activity to generate recommendations, matches and other AI-supported features for the event you are attending. We do this on behalf of the event Organizer and on their instructions.
We do not use your personal data — including the content of your private messages and any special-category data — to train, fine-tune or improve any AI or machine-learning model, and we do not make your personal data available to any third party for that purpose. The AI providers we work with are contractually bound to the same restriction.
To improve and evaluate our own products, including how well our matchmaking works, we use only anonymised and aggregated data: information derived from how the Service is used that can no longer be linked back to you. We do not attempt to re-identify it.
Brella does not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The features described above are assistive: they suggest matches, sessions, content and options, and a person — you, the event Organizer, or both — decides what to act on. Where an Organizer configures a feature to produce such a decision, that Organizer is the controller for that processing and is responsible for the lawful basis and for the safeguards Article 22(3) of the GDPR requires.
Where AI-based recommendations are enabled for an event, you may:
- adjust the profile or interest information used as inputs, via your account settings;
- opt out of event matchmaking using the setting in your profile;
- object to this processing by contacting the event organiser, who is the controller of your data for the event; and
- request deletion of your data.
Where Brella acts as a processor, Organizers remain responsible for providing appropriate notices and lawful bases to attendees regarding any AI-based or automated functionality they choose to activate.
Brella does not sell, license, or otherwise make available personal data for the training of third-party AI models.
13. Marketing Communications
With your consent or where lawful under legitimate interest, Brella may send updates, newsletters, and product announcements. You can opt out at any time through unsubscribe links or by emailing dpo@brella.io. Transactional or security notices are not subject to opt-out.
14. Subprocessors and Third-Party Vendors
Brella maintains a list of approved subprocessors and their locations, available upon request. Each subprocessor is bound by contractual obligations ensuring data protection consistent with this Policy and Article 28 GDPR. We conduct regular due diligence and audit reviews of these vendors.
15. Data Protection Impact Assessments (DPIAs)
Brella conducts DPIAs and risk assessments for processing activities that may pose high risk to data subjects (e.g., AI-based profiling or new features). Organizers may request assistance from Brella to fulfil their own DPIA obligations under Article 35 GDPR.
16. Jurisdiction-Specific Addenda
European Economic Area and UK
Brella Ltd. is established in Finland, and its lead supervisory authority is the Finnish Data Protection Ombudsman. You may lodge a complaint with that authority; with the supervisory authority of the EU or EEA country where you live, where you work, or where you consider the issue to have arisen; or, where your personal data is subject to the UK GDPR, with the UK Information Commissioner’s Office. Exercising this right does not affect any other remedy available to you.
California (United States)
Brella does not sell personal information. Under CCPA/CPRA, residents may request access, deletion, correction, and opt-out of sharing for cross-context behavioral advertising. Requests can be submitted to dpo@brella.io.
Brazil (LGPD)
Data subjects have rights to confirmation, access, correction, anonymization, and revocation of consent.
Canada (PIPEDA)
Residents may request access to their personal information and challenge its accuracy. Section 12 sets out how automated processing and AI features work in the Services, including our position on automated decision-making.
Singapore (PDPA) and Asia-Pacific
Where we process personal data subject to the Singapore Personal Data Protection Act or comparable laws in the region, we comply with applicable requirements for the transfer and protection of that data, including through contractual protections with our sub-processors.
17. Amendments and Version Control
Brella reserves the right to update this Policy at any time to reflect changes in laws, industry standards, or business operations. Material changes will be announced via notice on our website, in-app or through email notification. The “Last Updated” date indicates the latest revision.
18. Contact and Complaints
Brella Ltd.
Siltasaarenkatu 10, 00530 Helsinki, Finland
Privacy contact: dpo@brella.io
If you have questions, requests, or complaints regarding this Policy or our privacy practices, you may contact our privacy contact using the above details.
Annex A – Definitions
- “Personal Data” means any information relating to an identified or identifiable natural person.
- “Processing” means any operation performed on personal data, such as collection, storage, use, disclosure, or erasure.
- “Controller” means the entity that determines the purposes and means of processing.
- “Processor” means the entity that processes personal data on behalf of the Controller and in accordance with its documented instructions.

