This page explains how BrioMon Technologies LLC complies with the EU General Data Protection Regulation (GDPR) 2016/679 and the UK GDPR (as retained in UK law). It's a companion to our Privacy Policy, our detailed Data Rights page, and our Sub-Processors page -- together, these four pages are BrioMon's full public GDPR disclosure.
Why GDPR Applies to BrioMon
Although BrioMon Technologies LLC is incorporated in Wyoming, USA, the GDPR applies to us because we offer services to individuals and organisations in the European Economic Area (EEA) and United Kingdom, and process personal data of EEA/UK data subjects in connection with those services (GDPR Article 3(2)).
Territorial scope -- Article 3
GDPR applies to BrioMon under Art. 3(2)(a): offering goods or services to data subjects in the EEA. This means every EU and UK employee user whose employer has purchased a BrioMon corporate licence, and every EU/UK individual who subscribes directly to BrioMon, is protected by GDPR regardless of where BrioMon's servers are located.
The UK GDPR (retained EU law under the European Union (Withdrawal) Act 2018, as amended) applies the same requirements for UK data subjects. References to GDPR on this page include UK GDPR where applicable. For UK data subjects, the supervisory authority is the Information Commissioner's Office (ICO).
Our Role: Controller & Processor
| Data Controller | BrioMon is the Data Controller for: individual (B2C) subscribers; website visitors (cookie data); email marketing recipients; and support enquiry senders. |
| Data Processor | BrioMon is a Data Processor under GDPR Art. 4(8) when processing employee personal data on behalf of a Corporate Client (the Data Controller). A signed Data Processing Agreement is in place for every Corporate Client -- see Section 9. |
Legal Bases for Processing
BrioMon identifies and documents a lawful basis under GDPR Article 6 for every category of personal data we process -- Contract, Legal Obligation, Legitimate Interest, and Consent. The full breakdown, activity by activity, is in Privacy Policy, Section 3, so we don't maintain two versions of the same table.
Security Measures
Article 32 requires appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk. BrioMon maintains:
- Encryption in transit: TLS 1.2 or higher for all data in transit between client and server.
- Encryption at rest: AES-256 for all stored personal data and database backups.
- Authentication: Strong password requirements enforced account-wide; multi-factor authentication is mandatory for all BrioMon staff and administrative access, and available as an optional, opt-in feature for individual and corporate-employee accounts.
- Access controls: Role-based access control; data accessed on a need-to-know basis only.
- Pseudonymisation: Where possible, personal identifiers are separated from processing data -- B2B dashboard data is anonymised at an aggregate level with a minimum 5-user threshold.
- Logging & monitoring: Access to personal data is logged with timestamps and user IDs.
- Staff training: All staff with access to personal data receive GDPR awareness training.
- Confidentiality: All staff and contractors with access to personal data are bound by written confidentiality obligations.
- Supplier management: GDPR-compliant Data Processing Agreements are executed with every sub-processor before any data is shared -- see Section 8.
Breach Notification
A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. BrioMon maintains a documented breach response procedure:
| Within 72 hours | If the breach is likely to result in a risk to individuals' rights and freedoms, BrioMon notifies the relevant supervisory authority (your national DPA in the EU, or the ICO in the UK) within 72 hours of becoming aware, per GDPR Article 33. |
| Corporate Clients | Where BrioMon acts as a Processor, we notify the affected Corporate Client (the Data Controller) without undue delay, targeting within 24 hours, per our Data Processing Agreement. |
| High-risk breaches | If the breach is likely to result in a high risk to individuals, BrioMon notifies affected data subjects directly, in clear plain language, without undue delay, per GDPR Article 34. |
The 72-hour clock starts from the moment BrioMon becomes aware of a breach, not from when it is fully confirmed. We would rather over-notify than notify late.
International Data Transfers
BrioMon is a US company. When personal data of EU, UK, or Swiss data subjects is transferred to BrioMon's systems or its sub-processors' systems in the USA, an appropriate transfer mechanism is used, as required under GDPR Chapter V and UK GDPR. Full detail, including the specific Standard Contractual Clauses module and the UK transfer instrument used, is in Privacy Policy, Section 8.
Your Rights
GDPR Articles 15-22 grant you eight specific rights over your personal data -- access, rectification, erasure, restriction, portability, objection, protection from solely automated decisions, and withdrawal of consent. For the full procedure, timeframe, and how to submit a request for each one, see Your Data Rights.
Sub-Processors
BrioMon does not sell personal data. We share it only with vetted infrastructure and payment providers, each under their own Data Processing Agreement with BrioMon. The complete, current list -- who each provider is, what they do, and what data they see -- is maintained at Sub-Processors, with at least 14 days' advance notice before any addition.
Data Processing Agreement
Every Corporate Client executes a Data Processing Agreement (DPA) with BrioMon before any employee data is processed, as required by GDPR Article 28(3). The DPA covers: the subject matter, duration, and purpose of processing; BrioMon's obligations as Processor (instructions-only processing, confidentiality, security, sub-processor authorisation, assistance with data subject rights and breach notification, audit rights, and deletion/return of data on termination); and the international transfer mechanisms that apply.
Request our DPA
Corporate clients can request BrioMon's standard Data Processing Agreement for review and execution by emailing privacy@briomon.com.
Contact & Supervisory Authorities
Contact BrioMon
BrioMon Technologies LLC
1603 Capitol Avenue, Suite 413
Cheyenne, WY 82001, USA
Data Protection Inquiries: privacy@briomon.com
General Communications: connect@briomon.com
If you are unhappy with how BrioMon has handled a privacy matter, you have the right to lodge a complaint with your local supervisory authority -- your national DPA in the EU, or the ICO in the UK. See Your Data Rights, Escalation for the full regulator list across every jurisdiction we serve.