BrioMon
How It WorksPricingResearchBlog
LoginRequest Access

GDPR & UK GDPR Compliance

Version 1.3 Last Updated: October 1, 2026

This page explains how and why the GDPR and UK GDPR apply to BrioMon, and what we do to comply.

The short version

BrioMon is a US company, but GDPR still applies to us because we serve individuals and organisations in the EU and UK. We act as a Data Controller for individual subscribers and as a Data Processor for corporate employees, under a signed Data Processing Agreement with each corporate client. We encrypt your data, notify supervisory authorities within 72 hours of any confirmed breach, and use approved legal mechanisms for every transfer of EU/UK data to our US-based infrastructure.

Looking for your specific rights and how to exercise them? See Your Data Rights. Looking for the third parties we share data with? See Sub-Processors.

Jump to section

1. Why GDPR Applies to BrioMon 2. Our Role: Controller & Processor 3. Legal Bases for Processing 4. Security Measures 5. Breach Notification 6. International Data Transfers 7. Your Rights 8. Sub-Processors 9. Data Processing Agreement 10. Contact & Supervisory Authorities

GDPR / privacy enquiries:

privacy@briomon.com

This page explains how BrioMon Technologies LLC complies with the EU General Data Protection Regulation (GDPR) 2016/679 and the UK GDPR (as retained in UK law). It's a companion to our Privacy Policy, our detailed Data Rights page, and our Sub-Processors page -- together, these four pages are BrioMon's full public GDPR disclosure.

Section 1

Why GDPR Applies to BrioMon


Although BrioMon Technologies LLC is incorporated in Wyoming, USA, the GDPR applies to us because we offer services to individuals and organisations in the European Economic Area (EEA) and United Kingdom, and process personal data of EEA/UK data subjects in connection with those services (GDPR Article 3(2)).

Territorial scope -- Article 3

GDPR applies to BrioMon under Art. 3(2)(a): offering goods or services to data subjects in the EEA. This means every EU and UK employee user whose employer has purchased a BrioMon corporate licence, and every EU/UK individual who subscribes directly to BrioMon, is protected by GDPR regardless of where BrioMon's servers are located.

The UK GDPR (retained EU law under the European Union (Withdrawal) Act 2018, as amended) applies the same requirements for UK data subjects. References to GDPR on this page include UK GDPR where applicable. For UK data subjects, the supervisory authority is the Information Commissioner's Office (ICO).

Section 2

Our Role: Controller & Processor


Data ControllerBrioMon is the Data Controller for: individual (B2C) subscribers; website visitors (cookie data); email marketing recipients; and support enquiry senders.
Data ProcessorBrioMon is a Data Processor under GDPR Art. 4(8) when processing employee personal data on behalf of a Corporate Client (the Data Controller). A signed Data Processing Agreement is in place for every Corporate Client -- see Section 9.
Section 3

Legal Bases for Processing


BrioMon identifies and documents a lawful basis under GDPR Article 6 for every category of personal data we process -- Contract, Legal Obligation, Legitimate Interest, and Consent. The full breakdown, activity by activity, is in Privacy Policy, Section 3, so we don't maintain two versions of the same table.

Section 4

Security Measures


Article 32 requires appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk. BrioMon maintains:

  • Encryption in transit: TLS 1.2 or higher for all data in transit between client and server.
  • Encryption at rest: AES-256 for all stored personal data and database backups.
  • Authentication: Strong password requirements enforced account-wide; multi-factor authentication is mandatory for all BrioMon staff and administrative access, and available as an optional, opt-in feature for individual and corporate-employee accounts.
  • Access controls: Role-based access control; data accessed on a need-to-know basis only.
  • Pseudonymisation: Where possible, personal identifiers are separated from processing data -- B2B dashboard data is anonymised at an aggregate level with a minimum 5-user threshold.
  • Logging & monitoring: Access to personal data is logged with timestamps and user IDs.
  • Staff training: All staff with access to personal data receive GDPR awareness training.
  • Confidentiality: All staff and contractors with access to personal data are bound by written confidentiality obligations.
  • Supplier management: GDPR-compliant Data Processing Agreements are executed with every sub-processor before any data is shared -- see Section 8.
Section 5

Breach Notification


A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. BrioMon maintains a documented breach response procedure:

Within 72 hoursIf the breach is likely to result in a risk to individuals' rights and freedoms, BrioMon notifies the relevant supervisory authority (your national DPA in the EU, or the ICO in the UK) within 72 hours of becoming aware, per GDPR Article 33.
Corporate ClientsWhere BrioMon acts as a Processor, we notify the affected Corporate Client (the Data Controller) without undue delay, targeting within 24 hours, per our Data Processing Agreement.
High-risk breachesIf the breach is likely to result in a high risk to individuals, BrioMon notifies affected data subjects directly, in clear plain language, without undue delay, per GDPR Article 34.

The 72-hour clock starts from the moment BrioMon becomes aware of a breach, not from when it is fully confirmed. We would rather over-notify than notify late.

Section 6

International Data Transfers


BrioMon is a US company. When personal data of EU, UK, or Swiss data subjects is transferred to BrioMon's systems or its sub-processors' systems in the USA, an appropriate transfer mechanism is used, as required under GDPR Chapter V and UK GDPR. Full detail, including the specific Standard Contractual Clauses module and the UK transfer instrument used, is in Privacy Policy, Section 8.

Section 7

Your Rights


GDPR Articles 15-22 grant you eight specific rights over your personal data -- access, rectification, erasure, restriction, portability, objection, protection from solely automated decisions, and withdrawal of consent. For the full procedure, timeframe, and how to submit a request for each one, see Your Data Rights.

Section 8

Sub-Processors


BrioMon does not sell personal data. We share it only with vetted infrastructure and payment providers, each under their own Data Processing Agreement with BrioMon. The complete, current list -- who each provider is, what they do, and what data they see -- is maintained at Sub-Processors, with at least 14 days' advance notice before any addition.

Section 9

Data Processing Agreement


Every Corporate Client executes a Data Processing Agreement (DPA) with BrioMon before any employee data is processed, as required by GDPR Article 28(3). The DPA covers: the subject matter, duration, and purpose of processing; BrioMon's obligations as Processor (instructions-only processing, confidentiality, security, sub-processor authorisation, assistance with data subject rights and breach notification, audit rights, and deletion/return of data on termination); and the international transfer mechanisms that apply.

Request our DPA

Corporate clients can request BrioMon's standard Data Processing Agreement for review and execution by emailing privacy@briomon.com.

Section 10

Contact & Supervisory Authorities


Contact BrioMon

BrioMon Technologies LLC
1603 Capitol Avenue, Suite 413
Cheyenne, WY 82001, USA
Data Protection Inquiries: privacy@briomon.com
General Communications: connect@briomon.com

If you are unhappy with how BrioMon has handled a privacy matter, you have the right to lodge a complaint with your local supervisory authority -- your national DPA in the EU, or the ICO in the UK. See Your Data Rights, Escalation for the full regulator list across every jurisdiction we serve.

BrioMon

A gym membership for the brain. Cognitive training and workplace resilience for modern tech teams.

Product
  • How It Works
  • For Corporate Admins
  • For Employees
  • Pricing
Company
  • About
  • Research
  • Blog
  • Contact
Legal
  • Privacy Policy
  • Terms of Service
  • GDPR
  • Data Rights
  • Sub-Processors
  • Cookie Policy
© 2026 BrioMon Technologies LLC · 1603 Capitol Avenue, Suite 413, Cheyenne, WY 82001, USA. All rights reserved.
Built with ❤️ for the modern workforce.