(Jan 2026 Version)

Braino.AI
EU REGULATION 679/2016 ON THE PROCESSING OF PERSONAL DATA - ART. 13 Braino.AI S.r.l. Società Benefit, with registered office in via Ippodromo 56, 20151 Milan VAT number 13049530960 (hereinafter, "Data Controller" or "Company"), as Data Controller, informs you, pursuant to Legislative Decree 101/2018 (hereinafter, "Privacy Code") and art. 13 of EU Regulation no. 2016/679 (hereinafter, "GDPR"), that your data will be processed according to principles of fairness, lawfulness, transparency, in compliance with the purposes and methods indicated below, collecting them to the extent necessary and exact for the processing. The contact details of the Data Protection Officer, RPD or DPO (Data Protection Officer), are as follows: [email protected]
"Personal Data" refers to any information associated with an identified or identifiable individual, such as the data provided to Braino.AI srl by users and the information collected by Braino.AI srl during users' interaction with the related Services (e.g., device data, IP address, etc.). The term "Services" refers to products, services, and applications provided by Braino.AI srl pursuant to the Terms of Service for consumers ("End-User Services"), to websites ("Sites") such as www.braino.ai and to other online applications and services of Braino.AI srl. "End Users" are those who use a Service, and are private individuals who enter into a contract with Braino.AI srl and operate through the use of the platform of the same name. Visitors. When users interact with Braino.AI srl by visiting a Site without having logged into a Braino.AI srl account or if the interaction with Braino.AI srl does not require the generic user to be an End User, the user is considered a "Visitor." For example, users are considered Visitors when they send a message to Braino.AI srl asking for further information about the Services. In this Policy, the term "Transaction Data" refers to the data collected and used by Braino.AI srl to facilitate transactions requested by users. Some Transaction Data constitutes Personal Data and may include: name, e-mail address, contact number, billing address, shipping address, payment method data (e.g., credit or debit card number, bank account information, or image of the payment card selected by the user), merchant and location details, purchase amount, date of purchase and, in some cases, information on the products purchased.
We collect Data based on a legal obligation, a legitimate interest, or your consent. This collection is necessary to perform the contract concluded when you use our Services in the Application. We collect your Data through the forms you fill out on our website or our mobile applications to access our services or those of our partners. We also collect your Data when you communicate with us, particularly with our customer service via the chat in our Application or by email. In this case, we keep a copy of our conversation. It is also likely that we collect your Data when you interact with us on social networks. At the time of collecting your Data, we inform you whether it is mandatory or optional to provide it. Mandatory data is necessary for the functioning of the Services. As for optional data, you are completely free to provide it or not. We also indicate to you the possible consequences of a lack of a response.
Your Data is collected in order to fulfill the contract concluded when you use our Services in the Application or to fulfill a legal obligation. We use it for one or more of the following purposes:
Carrying out analysis of the use of the Services, in order to improve the Services provided and meet specific user needs. The provision of data necessary for these purposes is optional and the legal basis for processing is the consent of the data subjects. Lack of consent will have no consequence in the relationship between the parties, possibly resulting only in an improvement of the service. Consent may be revoked at any time by communicating it to the Data Controller.
The collected Data is intended for us and, when strictly necessary, for our subcontractors and partners involved in the provision of our services, as well as for employees and collaborators of the Data Controller in their capacity as authorized and/or internal data processors and/or system administrators. Your Data may also be communicated to the competent authorities, upon their request, in the context of legal proceedings, requests for information by authorities, or simply to comply with legal obligations.
We retain your Data only for the time necessary for the purposes pursued. In accordance with our obligations in the fight against money laundering and terrorist financing, data related to your transactions will be kept for a period of five years after the closure of your account and the end of our contractual relationship.
We retain your Data only for the time necessary for the purposes pursued. In accordance with our obligations in the fight against money laundering and terrorist financing, data related to your transactions will be kept for a period of five years after the closure of your account and the end of our contractual relationship. The Data we collect is stored on the servers of our provider Amazon Web Services, which ensures a high level of security. These servers are located within the European Union.
In order to protect your Data, we adopt all precautions, organizational and technical measures useful to preserve its security, integrity, and confidentiality and, in particular, to prevent it from being distorted, damaged, or accessed by unauthorized third parties. We also use secure payment systems compliant with the state of the art and applicable legislation. The transmission of your Data via the Internet is protected through the HTTPS connection secured by an SSL certificate.
We inform you that, at any time and if the prerequisites exist, you can exercise your rights under Articles 15 et seq. of the GDPR:
We normally process your data within the European Union; however, for technical or operational reasons, we may transfer data outside the European Union or the European Economic Area (so-called Third Countries). The Company ensures from now on that the transfer will be carried out in compliance with applicable legal provisions by stipulating, if necessary, agreements that guarantee an adequate level of protection and/or adopting the standard contractual clauses provided by the European Commission. For more information, you can contact the DPO by writing to the address [email protected]
This Policy entered into force on 01/01/2026
Braino.AI srl may modify this Policy periodically to comply with the introduction of new services or any changes to privacy practices or current laws. The wording "Last updated" at the beginning of the page of this Policy indicates the date of the last material revision. Any changes take effect from the moment Braino.AI srl publishes the revised Policy on the Services or sends a notice of the update, as required by law, whichever condition occurs later. Braino.AI srl may provide communications and notices relating to the Policy or the Personal Data acquired by publishing them on its website and contacting End Users or Representatives through the Braino.AI platform, the e-mail address and/or the physical address indicated in the users' Braino.AI accounts.