Privacy notice · version 2026-10-02
How BrainJam handles your data
This notice explains what personal data the BrainJam platform processes when your organisation takes part in a BrainJam programme, why, and what rights you have under the EU General Data Protection Regulation (GDPR). BrainJam is currently running as a pilot with a small number of invited organisations; the full Privacy Policy and Data Processing Agreement form part of your organisation's agreement with us and are available from us at any time.
1. Who is responsible
Your employer or organisation decides to run BrainJam for its team and is the data controller for your participation. BrainJam, a company registered in the Republic of Cyprus, provides the platform and acts as data processor on your organisation's behalf, under a data processing agreement. Our full company details are in that agreement. For anything in this notice, contact help@brainjam.quest.
For our own client records, billing, security logs and product analytics, BrainJam is the controller. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.
2. Who has an account
Only facilitators and administrators hold BrainJam accounts. The people who take part in a session do not: they are never entered into the platform as named individuals, and we hold no record of how any individual performed.
3. What we collect
- Account data: name, work email address, organisation, role, and a salted password hash. We never store your password in clear text, and nobody at BrainJam can read it.
- Session data: which quests are opened and started, by which facilitator, when, the answers submitted, clues opened, how long a session takes and its outcome.
- Technical data: a pseudonymised (keyed hash) version of your IP address and your browser type, used for security, abuse prevention and sign-in protection. The raw IP address is not stored.
- Email records: which service emails were sent to you and whether the provider accepted them.
- Consent record: the date and version of this notice you accepted when creating your account.
We hold no special category data — nothing about health, ethnicity, religion, trade union membership or biometrics — and nothing from anyone under 18. The debrief after a session is not captured by the platform at all.
The answer box is free text and is meant for quest answers. Please do not type personal information about yourself or anyone else into it; anything typed there is stored as part of the session record.
4. Why we process it and on what basis
- To provide the platform to your organisation (performance of the contract with your organisation).
- To show your organisation how its teams are getting on (the legitimate interest of your organisation in running the programme). For a workplace development activity this is normally the right basis rather than consent, which is rarely freely given in an employment relationship.
- To keep accounts secure, prevent abuse and meet legal obligations (legitimate interest / legal obligation).
We do not use your data for advertising, we do not sell it, we do not use it to train machine learning models, and there is no profiling or automated decision-making in BrainJam.
5. Who can see it
You can see your own account and session history. Your organisation, including its administrators, can see the account and session data belonging to it. BrainJam staff have access only where needed for support or maintenance, and that access is limited and logged. Nobody outside your organisation sees any of it.
BrainJam results are a team development tool. They are not a psychometric instrument or a competency assessment, and your organisation's agreement with us prohibits using them for recruitment, promotion, performance management, disciplinary decisions or redundancy selection.
6. Cookies
BrainJam uses a single strictly necessary session cookie to keep you signed in. No analytics, advertising or third-party cookies are set, so no cookie banner is required. Usage statistics are recorded on our own servers, not through a third-party tracker.
7. Where your data lives, and our processors
During the pilot the platform runs on the following providers, each under a written contract:
- Application hosting: Vercel, served from its Frankfurt region.
- Database: a managed PostgreSQL service in an EU region, encrypted at rest.
- Transactional email: Resend, for invitations, password resets and service messages.
Data is encrypted in transit (TLS) and at rest. Vercel and Resend are United States companies: the platform runs in their EU regions, but support and administrative access can involve a transfer outside the EEA. Both are certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing adequate protection, and both also carry the Standard Contractual Clauses in their data processing agreements. We will tell clients in advance if any of this changes.
8. How long we keep it
- Account and session data: for the duration of your organisation's programme and up to 12 months after it ends, unless your organisation asks for earlier deletion.
- Technical event logs and the record of emails sent: automatically deleted after 365 days.
- Deleted accounts: anonymised immediately and permanently removed within 30 days.
9. Your rights
You can, at any time:
- download a copy of your data from My account → Download my data (right of access & portability);
- correct your name from My account (right to rectification);
- delete your account from My account → Delete account (right to erasure);
- object to or ask for restriction of processing, and withdraw consent where we rely on it.
Anything you cannot do yourself can be sent to your organisation's administrator or to help@brainjam.quest. We respond within one month. Where we act as processor for your organisation, we pass your request to them and help them answer it.
You may also complain to your national data protection authority, or to ours: the Office of the Commissioner for Personal Data Protection, 15 Kypranoros Street, 1061 Nicosia, Cyprus.
10. Security
Passwords are hashed and salted, access is role-based and limited to those who need it, administrative actions are logged, and data is encrypted in transit and at rest. If a breach is likely to put your rights at risk we notify your organisation without undue delay and, where required, the supervisory authority within 72 hours.
11. Changes
When this notice changes materially we update the version number above and ask you to review it the next time you sign in.