This page is a detailed, practical companion to our GDPR & UK GDPR Compliance overview and our Privacy Policy. It sets out exactly what rights you have over your personal data, how BrioMon fulfils each one, and how long each takes -- regardless of where in the world you're located.
Rights All Users Have
Regardless of where you are located, BrioMon honours the following data rights for all users:
Access
Request a copy of the personal data BrioMon holds about you, in a readable format.
Correction
Ask us to correct any inaccurate or incomplete personal data we hold.
Deletion
Request that we delete your personal data. Some data may be retained to meet legal obligations (e.g., tax records).
Portability
Receive your data in a structured, machine-readable format so you can transfer it elsewhere.
Withdraw Consent
Withdraw consent for marketing emails or optional data uses at any time -- one click in any email footer, or email us.
Object to Processing
Object to us processing your data based on our legitimate interests. We will stop unless we have compelling grounds.
How BrioMon Handles Each Right
GDPR Articles 15-22 grant data subjects eight specific rights. Here is exactly how BrioMon fulfils each one and within what timeframe. All requests are verified (proof of identity) before we act on them.
| Right | Article | Timeframe | BrioMon's Procedure |
|---|---|---|---|
| Access (SAR) | Art. 15 | 1 month (extendable to 3 for complex requests) | Email privacy@briomon.com; identity verified; data exported from the platform in machine-readable format. |
| Rectification | Art. 16 | 1 month | You can self-correct profile data. Other corrections are actioned by our privacy team. |
| Erasure | Art. 17 | 1 month | Account deleted; your data purged within 30 days. Exceptions: legal retention obligations (tax records, 7 years). |
| Restriction | Art. 18 | 1 month | Account flagged; processing paused while a dispute is resolved. You're notified of the outcome. |
| Portability | Art. 20 | 1 month | Your data exported in JSON or CSV format upon verified request. |
| Object | Art. 21 | Immediate (marketing); 1 month (other) | Marketing: instant opt-out link in every email. Legitimate-interest objections reviewed within 1 month. |
| Automated Decisions | Art. 22 | N/A | BrioMon does not make solely automated decisions with legal or similarly significant effects. |
| Withdraw Consent | Art. 7(3) | Immediate effect | Unsubscribe links in all marketing emails; cookie consent can be withdrawn at any time. |
If you're an employee of a corporate client
Where BrioMon acts as Data Processor for a Corporate Client, requests from Authorised Users are forwarded to your employer (the Data Controller) within 5 business days, and BrioMon provides reasonable assistance to help them fulfil your request (GDPR Art. 28(3)(e)). You can still email us directly and we will route it correctly.
Additional Rights — Where You Live
The following additional rights apply based on your country or region. Where multiple jurisdictions apply to you, you benefit from all applicable rights.
Under GDPR (General Data Protection Regulation):
- Right to restriction of processing
- Right not to be subject to automated decisions with significant effects
- Right to lodge a complaint with your national DPA
Under UK GDPR & Data Protection Act 2018:
- Same rights as EU GDPR above
- Right to complain to the ICO
- UK statutory consumer rights are not affected by our Terms
Under CCPA / CPRA (California residents):
- Know what categories of personal data are collected and shared
- Opt out of sale or sharing (BrioMon does not sell data)
- Limit use of sensitive personal information
- Non-discrimination for exercising rights
Under PIPEDA (Personal Information Protection and Electronic Documents Act):
- Access and correction rights
- Right to withdraw consent
- Right to complain to the OPC
Under Privacy Act 1988 & Australian Privacy Principles:
- Right to access and correct personal information
- Right to complain to the OAIC
- Cross-border transfer safeguards apply
Submit a Data Rights Request
No forms to fill out
Just email us directly -- we handle all requests within the timeframes required by your local law.
- Email privacy@briomon.com with the subject line: "Privacy Rights Request"
- Include your full name and the email address on your BrioMon account
- Tell us your country of residence and what right(s) you want to exercise
- We may ask you to verify your identity before processing the request
We acknowledge all requests within 2 business days and resolve them within the timeframes below.
How Long Requests Take
| Jurisdiction | Acknowledgement | Resolution | Extension |
|---|---|---|---|
| EU & UK (GDPR) | Within 2 business days | Within 30 days of receipt | Up to 2 additional months for complex or multiple requests -- we will notify you if this applies |
| USA -- California (CCPA) | Within 10 days | Within 45 days of receipt | Up to 45 additional days with prior notice |
| Canada (PIPEDA) | Within 5 days | Within 30 days of receipt | Extension available where necessary; we will notify you |
| Australia (Privacy Act) | Within 2 business days | Within 30 days of receipt | Reasonable extension if required |
| All other users | Within 5 business days | Within 30 days of receipt | We apply GDPR standards as a baseline for all users globally |
We never charge a fee for rights requests
Processing a data rights request is free. The only exception is if a request is manifestly unfounded, repetitive, or excessive -- in which case we may charge a reasonable administrative fee or decline to act, and will explain why in writing.
What Data BrioMon Holds About You
When you submit an access request, here is typically what you will receive:
- Account data: name, email, job title, company, country, registration date
- Usage data: login history, modules accessed, completion status
- Assessment responses: your answers to Mental Capacity check-ins and journal reflections
- Payment records: transaction history, plan type, billing address (card numbers are never stored -- our Merchant of Record partners handle those, see Sub-Processors)
- Communications: support emails you sent us
- Marketing preferences: your opt-in/opt-out history
We do not hold: government IDs, medical records, health diagnoses, biometric data, financial account numbers, or precise GPS location.
If You Are Not Satisfied
If you are unhappy with how BrioMon has handled your privacy request, you have the right to escalate to your local data protection authority. We will always aim to resolve concerns directly -- but your right to complain to a regulator exists independently of any response from us.
Find your national DPA from the EDPB list
Information Commissioner's Office
California Privacy Protection Agency
Office of the Privacy Commissioner
Office of the Australian Information Commissioner
Contact us directly -- we will cooperate with any applicable authority