Privacy Policy of BrightBridge Engagement Solutions Ltd
Effective date: 13 July 2026
1. Introduction and company information
This Privacy Policy explains how BrightBridge Engagement Solutions Ltd collects, uses, discloses, transfers, and protects personal data in connection with its customer-engagement services and related business operations.
BrightBridge Engagement Solutions Ltd is the data controller for the personal data described in this Privacy Policy, unless we expressly state otherwise.
Company details:
- Legal name: BrightBridge Engagement Solutions Ltd
- Address: BrightBridge Engagement, 27 Temple Chambers, 3-7 Temple Avenue, London EC4Y 0DT, United Kingdom
- Email: [email protected]
- Phone: +44 20 7946 8372
This Privacy Policy applies to personal data we process when you visit our website, contact us, request information, use our services, interact with our communications, or otherwise engage with us in the course of our customer-engagement business.
2. Data collection and processing
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identity data: name, title, job title, employer, and similar identifiers.
- Contact data: email address, telephone number, business address, and communication preferences.
- Account and relationship data: customer records, enquiry details, service history, contract details, and correspondence.
- Technical data: IP address, browser type and version, device information, operating system, cookie identifiers, and usage logs.
- Marketing and engagement data: preferences, responses to campaigns, event attendance, survey responses, and engagement metrics.
- Financial and billing data: invoicing details, payment status, and transaction records where applicable.
- Other information you provide: feedback, support requests, and any personal data included in your communications with us.
We collect personal data directly from you, from your organisation, from our website and digital tools, from third-party service providers, and from publicly available sources where appropriate and lawful.
We may also process personal data automatically when you use our website or interact with our digital communications, including through cookies and similar technologies, subject to applicable consent and preferences where required.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our customer-engagement services;
- to respond to enquiries, requests, and communications;
- to administer contractual and business relationships;
- to personalise communications and improve customer experience;
- to send service updates, administrative messages, and marketing communications where permitted;
- to analyse service usage, engagement patterns, and campaign performance;
- to maintain records, perform billing, and manage payments;
- to comply with legal and regulatory obligations;
- to detect, prevent, and investigate fraud, misuse, security incidents, or other unlawful activity;
- to establish, exercise, or defend legal claims; and
- to operate, maintain, and improve our website, systems, and services.
4. Legal basis for processing
We only process personal data where we have a lawful basis to do so. Depending on the circumstances, our legal bases may include:
- Performance of a contract: where processing is necessary to enter into or perform a contract with you or your organisation.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include service delivery, business administration, improving our services, and protecting our operations.
- Consent: where you have given us clear consent to process your data for a specific purpose, such as certain marketing activities or non-essential cookies.
- Legal obligation: where processing is necessary to comply with legal or regulatory requirements.
- Vital interests: where processing is necessary to protect someone’s vital interests in rare and exceptional circumstances.
Where we rely on legitimate interests, we assess the impact on your rights and take appropriate safeguards. Where we rely on consent, you may withdraw it at any time.
5. Data sharing and third parties
We may share personal data with the following categories of recipients, where necessary and lawful:
- service providers acting on our behalf, such as IT hosting, cloud storage, analytics, CRM, communications, and support providers;
- professional advisers, including lawyers, auditors, accountants, insurers, and consultants;
- business partners, clients, or counterparties where required to deliver customer-engagement services;
- payment processors and financial institutions, where relevant;
- regulators, courts, law enforcement, and other public authorities where required by law or to protect our rights;
- successors in title, buyers, or investors in connection with a corporate transaction, merger, reorganisation, or asset transfer.
We require third parties to process personal data in accordance with applicable law and appropriate contractual safeguards. They are not permitted to use personal data for their own independent purposes unless they are separately acting as a controller and have a lawful basis to do so.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or other applicable jurisdictions, we take steps to ensure that appropriate safeguards are in place to protect your information. These safeguards may include:
- transfers to countries recognized as providing an adequate level of protection;
- standard contractual clauses or equivalent transfer mechanisms;
- transfer impact assessments and supplementary measures where appropriate; and
- other lawful transfer tools permitted by applicable privacy laws.
If you would like more information about international transfers and the safeguards we use, you may contact us using the details below.
7. Storage duration
We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, including for legal, accounting, reporting, and operational requirements.
Retention periods depend on the type of data and the reason we hold it. In general:
- customer and contract records are retained for the duration of the relationship and for a reasonable period afterwards;
- financial, tax, and accounting records are retained for the period required by law;
- marketing data is retained until you unsubscribe, object, or the data becomes otherwise unnecessary;
- technical and analytics data is retained for a limited period unless needed longer for security, legal, or operational reasons.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with our retention practices.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation of whether we process your personal data and to obtain a copy of that data.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of your personal data in certain circumstances.
- Restriction: to request that we limit processing in certain circumstances.
- Data portability: to receive certain data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Objection: to object to processing based on our legitimate interests and, in some cases, to object to direct marketing at any time.
To exercise your rights, please contact us using the details in the Contact Information section. We may need to verify your identity before responding. We will respond within the time limits required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
If you withdraw consent, we may no longer be able to provide certain features, communications, or services that depend on that consent. You may withdraw consent by contacting us or by using any unsubscribe or preference-management tools we provide.
10. Right to complain
If you have concerns about how we process your personal data, we encourage you to contact us first so that we can try to resolve the issue.
You also have the right to lodge a complaint with the relevant supervisory authority, including, where applicable, the UK Information Commissioner’s Office (ICO) or another competent data protection authority.
11. Data security
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures may include access controls, authentication procedures, encryption where appropriate, secure storage, network protections, staff confidentiality obligations, and internal policies and training.
No system can be guaranteed to be completely secure. However, we continuously review and improve our security measures in line with the nature of the data we process and the risks involved.
12. Contact information
If you have questions about this Privacy Policy, wish to exercise your rights, or need further information about our data handling practices, you may contact BrightBridge Engagement Solutions Ltd using the following details:
- Address: BrightBridge Engagement, 27 Temple Chambers, 3-7 Temple Avenue, London EC4Y 0DT, United Kingdom
- Email: [email protected]
- Phone: +44 20 7946 8372
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or operational requirements.
Any updated version will be posted on our website or otherwise made available to you. Where required by law, we will notify you of material changes using reasonable means.
We encourage you to review this Privacy Policy periodically to stay informed about how BrightBridge Engagement Solutions Ltd processes personal data.