Legal
Privacy Policy
What this website collects, which is very little, and what happens to anything you send us.
The short version
- This site sets no cookies on your device and runs no analytics, advertising or tracking scripts of any kind.
- We only hold personal information you deliberately send us, through the enquiry form, by email or by booking a meeting.
- We do not sell, rent or share your information with anyone for marketing, and we do not add you to a mailing list.
- Typefaces are served from our own server, so no font provider is contacted. Two third parties see your IP address because your browser fetches things from them: Unsplash for photographs, and HubSpot on the scheduling page only.
This summary is here to be useful, not to be relied on. The sections below are the actual terms.
Who we are
Brilliant Systems LLC is the controller of the personal data described in this policy. We operate from two offices and both handle client information.
- United States
- Brilliant Systems LLC, 1500 N Grant St Ste R, Denver, CO 80203, United States
- Pakistan
- 54H, Aitchison Society, Lahore 5400, Punjab, Pakistan
- Contact
- hello@brilliantsystems.io
If you have a question about this policy or about information we hold, write to the address above and a person will answer you. There is no privacy request portal to work through.
What we collect
We collect three things, and only the first two contain anything that identifies you.
- What you send us through the enquiry form
- Your name, email address, and optionally your telephone number, the service you are interested in and a budget range, together with whatever you write in the message field. The page you were on when you sent it is recorded so we know what you were reading.
- What you send us when booking a meeting
- The scheduling page embeds a booking calendar operated by HubSpot. If you book a time, the name, email address and any answers you give go to HubSpot and then to us. HubSpot is a separate company with its own privacy policy, and using that calendar is entirely optional.
- Ordinary server logs
- Our web server records requests in the normal way, including IP address, the page requested, the time, and the browser user agent. These are used to keep the site running and secure. They are not connected to anything else and not used to build a profile of you.
We do not collect special category data, we do not ask for it, and we would rather you did not send it to us in a message field.
Cookies and tracking
This website sets no cookies on your device when you browse it. There is no analytics package, no advertising pixel, no session recording, no heat mapping and no consent banner, because there is nothing to consent to.
Two exceptions are worth naming honestly. If you use the booking calendar on the scheduling page, HubSpot may set cookies within that embedded frame under its own policy. And the WordPress software that runs this site would set a cookie if you logged in to it, which applies to our staff rather than to visitors.
Third parties your browser contacts
Loading any page means your browser requests files from other companies, and those requests reveal your IP address to them. We keep this list short deliberately, and it is complete. Typefaces are served from our own server rather than from a font provider, which is why no font company appears below.
- Unsplash
- Photographs on this site are served from the Unsplash content delivery network rather than copied onto our server.
- HubSpot
- Only on the scheduling page, and only because that page embeds a booking calendar. No other page contacts HubSpot.
Our own hosting provider and our email provider process data on our behalf under contract. Links to client websites are ordinary links: nothing is loaded from them and following one is your choice.
Why we are allowed to hold it
Where the UK or EU General Data Protection Regulation applies, our lawful bases are these.
- Legitimate interests
- Responding to an enquiry you sent us, and keeping our website secure and available. We think you would expect both.
- Contract
- Where we are working with you or negotiating terms, we process what is necessary to do that.
- Legal obligation
- Retaining records we are required to keep, such as for tax and accounting.
We do not rely on consent for anything on this website, because we do not do anything on it that would need consent.
How long we keep it
- Enquiries that do not become projects are deleted after twenty four months.
- Records relating to clients are kept for seven years after the engagement ends, because tax and contract law requires it.
- Server logs are rotated and deleted within ninety days.
If you would like your enquiry deleted sooner, ask us and we will do it and confirm when it is done.
Your rights
Depending on where you live, you have some or all of the following rights over the information we hold about you. We apply them to everyone who asks, regardless of where they are, because operating two standards would be more work than operating one.
- Ask for a copy of what we hold about you.
- Ask us to correct anything that is wrong.
- Ask us to delete it.
- Ask us to restrict or stop a particular use of it.
- Ask for it in a portable format.
- Object to processing we carry out under legitimate interests.
We do not sell personal information and we do not share it for cross-context behavioural advertising, so the California right to opt out of sale or sharing has nothing to act on. We will never treat you differently for exercising any of these rights.
Write to hello@brilliantsystems.io and we will respond within thirty days. If you are in the European Economic Area or the United Kingdom and are unhappy with our answer, you may complain to your national supervisory authority.
Where your information goes
We operate from the United States and Pakistan, and our engineering team in Lahore works on the same systems as our team in Denver. If you contact us from the European Economic Area or the United Kingdom, your information will be accessed in both countries.
Pakistan is not the subject of a European Commission adequacy decision. Where the GDPR applies to a transfer, we rely on standard contractual clauses together with technical measures including access control, encryption in transit and at rest, and logging of access. For client work we can put specific arrangements in place, including keeping data within a particular region, and we do this routinely for regulated clients.
How we protect it
Access to enquiry records is limited to the people who need it. Traffic to this site is encrypted in transit. Our own security practices are the ones we sell to clients: least privilege by default, credentials in a managed store rather than in code, dependency scanning in the pipeline, and access reviewed on a schedule.
No system is perfect. If we ever suffered a breach affecting your information we would tell you promptly and directly, including where the mistake was ours, and we would tell you what we knew before we had a complete picture rather than after.
Children
This is a website about enterprise software engineering. It is not directed at children, we do not knowingly collect information from anyone under sixteen, and if we discovered we had we would delete it.
Changes to this policy
If we change this policy we will change the date at the top of it. If a change is significant, for example if we ever started using analytics, we would say so plainly on the page rather than quietly amending a paragraph.
Questions about anything on this page? Write to hello@brilliantsystems.io and a person will answer.