Braino.AI

PRIVACY POLICY

(Jan 2026 Version)

Braino.AI

EU REGULATION 679/2016 ON THE PROCESSING OF PERSONAL DATA - ART. 13 Braino.AI S.r.l. Società Benefit, with registered office in via Ippodromo 56, 20151 Milan VAT number 13049530960 (hereinafter, "Data Controller" or "Company"), as Data Controller, informs you, pursuant to Legislative Decree 101/2018 (hereinafter, "Privacy Code") and art. 13 of EU Regulation no. 2016/679 (hereinafter, "GDPR"), that your data will be processed according to principles of fairness, lawfulness, transparency, in compliance with the purposes and methods indicated below, collecting them to the extent necessary and exact for the processing. The contact details of the Data Protection Officer, RPD or DPO (Data Protection Officer), are as follows: [email protected]

1. Definitions

"Personal Data" refers to any information associated with an identified or identifiable individual, such as the data provided to Braino.AI srl by users and the information collected by Braino.AI srl during users' interaction with the related Services (e.g., device data, IP address, etc.). The term "Services" refers to products, services, and applications provided by Braino.AI srl pursuant to the Terms of Service for consumers ("End-User Services"), to websites ("Sites") such as www.braino.ai and to other online applications and services of Braino.AI srl. "End Users" are those who use a Service, and are private individuals who enter into a contract with Braino.AI srl and operate through the use of the platform of the same name. Visitors. When users interact with Braino.AI srl by visiting a Site without having logged into a Braino.AI srl account or if the interaction with Braino.AI srl does not require the generic user to be an End User, the user is considered a "Visitor." For example, users are considered Visitors when they send a message to Braino.AI srl asking for further information about the Services. In this Policy, the term "Transaction Data" refers to the data collected and used by Braino.AI srl to facilitate transactions requested by users. Some Transaction Data constitutes Personal Data and may include: name, e-mail address, contact number, billing address, shipping address, payment method data (e.g., credit or debit card number, bank account information, or image of the payment card selected by the user), merchant and location details, purchase amount, date of purchase and, in some cases, information on the products purchased.

2. Legal Basis for the Processing of Personal Data

We collect Data based on a legal obligation, a legitimate interest, or your consent. This collection is necessary to perform the contract concluded when you use our Services in the Application. We collect your Data through the forms you fill out on our website or our mobile applications to access our services or those of our partners. We also collect your Data when you communicate with us, particularly with our customer service via the chat in our Application or by email. In this case, we keep a copy of our conversation. It is also likely that we collect your Data when you interact with us on social networks. At the time of collecting your Data, we inform you whether it is mandatory or optional to provide it. Mandatory data is necessary for the functioning of the Services. As for optional data, you are completely free to provide it or not. We also indicate to you the possible consequences of a lack of a response.

3. Data Usage

Your Data is collected in order to fulfill the contract concluded when you use our Services in the Application or to fulfill a legal obligation. We use it for one or more of the following purposes:

3.1 Marketing Purposes

3.2 Profiling Purposes

Carrying out analysis of the use of the Services, in order to improve the Services provided and meet specific user needs. The provision of data necessary for these purposes is optional and the legal basis for processing is the consent of the data subjects. Lack of consent will have no consequence in the relationship between the parties, possibly resulting only in an improvement of the service. Consent may be revoked at any time by communicating it to the Data Controller.

4. Data Recipients

The collected Data is intended for us and, when strictly necessary, for our subcontractors and partners involved in the provision of our services, as well as for employees and collaborators of the Data Controller in their capacity as authorized and/or internal data processors and/or system administrators. Your Data may also be communicated to the competent authorities, upon their request, in the context of legal proceedings, requests for information by authorities, or simply to comply with legal obligations.

5. Data Retention Period

We retain your Data only for the time necessary for the purposes pursued. In accordance with our obligations in the fight against money laundering and terrorist financing, data related to your transactions will be kept for a period of five years after the closure of your account and the end of our contractual relationship.

6. Data Storage

We retain your Data only for the time necessary for the purposes pursued. In accordance with our obligations in the fight against money laundering and terrorist financing, data related to your transactions will be kept for a period of five years after the closure of your account and the end of our contractual relationship. The Data we collect is stored on the servers of our provider Amazon Web Services, which ensures a high level of security. These servers are located within the European Union.

7. Data Security

In order to protect your Data, we adopt all precautions, organizational and technical measures useful to preserve its security, integrity, and confidentiality and, in particular, to prevent it from being distorted, damaged, or accessed by unauthorized third parties. We also use secure payment systems compliant with the state of the art and applicable legislation. The transmission of your Data via the Internet is protected through the HTTPS connection secured by an SSL certificate.

8. Data Subject Rights and Exercise Methods

We inform you that, at any time and if the prerequisites exist, you can exercise your rights under Articles 15 et seq. of the GDPR:

9. International Data Transfers

We normally process your data within the European Union; however, for technical or operational reasons, we may transfer data outside the European Union or the European Economic Area (so-called Third Countries). The Company ensures from now on that the transfer will be carried out in compliance with applicable legal provisions by stipulating, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses provided by the European Commission. For more information, you can contact the DPO by writing to the address [email protected]

10. Effective Date

This Policy entered into force on 01/01/2026

11. Updates and Notifications

Braino.AI srl may modify this Policy periodically to comply with the introduction of new services or any changes to privacy practices or current laws. The wording "Last updated" at the beginning of the page of this Policy indicates the date of the last material revision. Any changes take effect from the moment Braino.AI srl publishes the revised Policy on the Services or sends a notice of the update, as required by law, whichever condition occurs later. Braino.AI srl may provide communications and notices relating to the Policy or the Personal Data acquired by publishing them on its website and contacting End Users or Representatives through the Braino.AI platform, the e-mail address and/or the physical address indicated in the users' Braino.AI accounts.

Join the waitlist

Leave your details and be among the first to try Braino. We will write as soon as sign-ups open: no spam, no commitment.

Select the services you are interested in:

We only use the details you leave here to let you know when sign-ups open. How we handle them is set out in our privacy policy.

Become a beta tester

Try Braino early and tell us what does not work. A few weeks of testing, a direct line to the team, and your feedback going into the product.

Your smartphone’s operating system:

Minimum requirements: iOS 18 or Android 14 — earlier versions cannot install the test build.

We use your details to review your application and, if you're in the next test group, to send you the instructions to install the app. How we handle them is set out in our privacy policy.

The test is confidential: preview features aren't to be shared publicly, and we use your feedback to improve the product.