Legal
Privacy and Cookie Policy
Effective Date: 12 August 2026
Brava Labs Ltd (“Brava”, “we”, “us” or “our”) respects your privacy and is committed to protecting personal data. This Policy explains how we collect, use, share and protect personal data in connection with brava.finance, our platform, trials, demonstrations, support, and our business relationships.
Brava Labs Ltd is a company incorporated in England and Wales (company no. 15158267) with registered office at 86-90 Paul Street, London EC2A 4NE.
1. Who this Policy applies to
This Policy applies to:
- visitors to our website;
- people who request information, demonstrations or support;
- authorised users participating in evaluations or trials;
- authorised users of Brava through an institutional customer; and
- business contacts at customers, prospects, suppliers and partners.
Brava primarily provides non-custodial technology to institutional customers such as regulated investment managers, wealth managers and custodians. Our services are not directed at children or retail consumers.
2. Our role under data protection law
Brava is generally a controller of personal data used to operate our website, manage accounts and trials, secure our systems, communicate with business contacts and manage our own commercial relationships.
Where we process personal data solely on the instructions of an institutional customer, that customer may be the controller and Brava may act as its processor. In those circumstances, the customer's privacy notice and our contract with that customer govern that processing.
3. Personal data we collect
3.1 Information you or your organisation provides
- name, business email address, job title, employer and other business contact details;
- account, authentication and access information;
- communications, support requests, feedback and other information you provide to us;
- information provided when requesting or participating in a demonstration, evaluation or trial; and
- wallet addresses or related blockchain information where relevant to the specific service or trial.
3.2 Information collected automatically
- IP address, browser type, operating system and device information;
- login, security and authentication logs;
- pages viewed, features used, actions performed, timestamps and diagnostic information; and
- cookies and similar technologies as described in section 8.
3.3 Information from third parties and public sources
We may receive information from:
- your employer or other organisation that has authorised your access;
- authentication, infrastructure, security and other technology providers;
- public blockchains and blockchain data providers, where relevant to the service; and
- publicly available business, regulatory or sanctions sources where relevant to our institutional counterparty checks.
4. How and why we use personal data
We use personal data for the purposes set out below. In each case we've noted the lawful basis we typically rely on under UK GDPR.
- Operate the website and platform: to provide access, authenticate users, deliver features and maintain accounts. Legitimate interests; contract where applicable.
- Trials and customer relationships: to run evaluations and demonstrations, and to handle onboarding, support and customer administration. Legitimate interests; contract where applicable.
- Security and abuse prevention: to protect accounts, systems and infrastructure, and to detect fraud, misuse or security incidents. Legitimate interests; legal obligation where applicable.
- Improve Brava: to diagnose errors, understand product usage, and improve performance and user experience. Legitimate interests; consent where required for non-essential cookies.
- Communications: to respond to enquiries and support requests, and to send operational communications. Legitimate interests; contract where applicable.
- Legal and compliance: to comply with law, legal process and sanctions requirements, and to protect our legal rights. Legal obligation; legitimate interests.
- Marketing: to send relevant B2B information where permitted. Legitimate interests or consent, depending on applicable law.
Where we rely on legitimate interests, we use personal data only where we consider the processing necessary for a legitimate business purpose and not overridden by your rights and interests.
5. Institutional customer and blockchain data
Brava does not take custody of customer assets or private keys. Where our platform displays or processes wallet addresses or blockchain transaction information, this may include information already recorded on a public blockchain.
Information recorded on a public blockchain may be publicly accessible and generally cannot be altered or deleted by Brava. Brava does not control the underlying blockchain.
6. Sharing personal data
We may share personal data where reasonably necessary with:
- hosting, cloud infrastructure and database providers;
- authentication, security and blockchain infrastructure providers;
- analytics and product-performance providers, subject to cookie choices where required;
- communications, support and business software providers;
- professional advisers, auditors and insurers;
- our institutional customer where you access Brava on its behalf;
- law enforcement, courts, regulators or public authorities where required by law; and
- a buyer, investor or successor in connection with a merger, financing, restructuring or sale of all or part of our business.
We require service providers processing personal data on our behalf to handle it only for the agreed purposes and to apply appropriate safeguards.
7. Data retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing the service, managing our customer and business relationships, maintaining security and audit records, resolving disputes and complying with legal obligations.
Retention periods vary according to the type of information, the nature of the relationship and applicable legal or contractual requirements.
Cookies and similar technologies
We use cookies and similar technologies to operate and secure our website and, where enabled, to understand how it is used.
8.1 Strictly necessary technologies
These are required for functions such as security, authentication, network management and remembering your privacy choices. They may be used without consent where permitted by law.
8.2 Non-essential cookies and analytics
We will not place or use non-essential cookies or similar technologies that require consent unless you have made a positive choice to allow them. Where our cookie controls are available, you can accept, reject or change your non-essential cookie preferences at any time.
If no non-essential cookies are enabled on the website, only strictly necessary technologies will be used.
9. International data transfers
Some of our service providers may process personal data outside the United Kingdom. Where a transfer is subject to UK international-transfer restrictions, we use a lawful transfer mechanism where required, such as UK adequacy regulations or appropriate contractual safeguards, including the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
10. Your data protection rights
Under UK data protection law, and subject to applicable conditions and exemptions, you may have the right to:
- request access to personal data we hold about you;
- ask us to correct inaccurate or incomplete personal data;
- ask us to delete personal data in certain circumstances;
- ask us to restrict processing in certain circumstances;
- object to processing based on legitimate interests in certain circumstances;
- receive certain personal data in a portable format where the right to data portability applies; and
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out before withdrawal.
11. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or misuse. No system can be guaranteed to be completely secure.
13. Changes to this Policy
We may update this Policy from time to time to reflect changes to our services, technology, legal requirements or data practices. We will publish the updated version and revise the effective date above.
14. Contact us
For privacy questions or requests, contact:
Brava Labs Ltd
86-90 Paul Street, London EC2A 4NE
United Kingdom