Brexy
Product
Security
Careers
Blog
Log in

Legal

Privacy Policy

Last updated: 28 July 2026

Your privacy matters to us at Brexy. This Privacy Policy ("Policy") explains how we collect, use, disclose, process and safeguard personal data, and sets out your rights in relation to that data.

Because we are continually developing our website and platform, this Policy may be revised from time to time. Whenever we make a material change, we will post a notice on the Brexy website and email the most recent address you have shared with us.

Table of Contents

  • 1. Who We Are
  • 2. What This Policy Applies To
  • 3. Definitions
  • 4. Types of Personal Data We Collect
  • 5. Sources of Personal Data
  • 6. Why We Collect, Use and Disclose Personal Data
  • 7. Legal Bases for Processing
  • 8. How We Share Your Personal Data
  • 9. Transfers of Personal Data Outside Singapore
  • 10. Cookies and Tracking Technologies
  • 11. Marketing Communications
  • 12. Artificial Intelligence: Use, Governance and Safeguards
  • 13. Data Security
  • 14. Data Breach Notification
  • 15. Data Retention
  • 16. Accuracy of Personal Data
  • 17. Your Rights
  • 18. How to Exercise Your Rights
  • 19. Personal Data of Children
  • 20. Third-Party Websites
  • 21. Amendments to This Policy
  • 22. General
  • 23. How to Reach Us

1. Who We Are

The Brexy platform, available at https://www.brexy.ai (together with any mobile or desktop application version, the "Platform"), is owned and operated by Brexy Pte. Ltd. ("Brexy", "we", "us" or "our"), a company incorporated in Singapore.

Brexy provides AI-powered deal intelligence and workflow software to financial institutions, advisory firms and their professionals.

2. What This Policy Applies To

This Policy applies to personal data:

  • collected when you visit, browse or interact with our website;
  • collected when you register for, access or use the Platform as an individual user; and
  • otherwise provided to us in the course of your dealings with us, including business development, recruitment and general correspondence.

This Policy does not apply to the practices of businesses we do not own or control, or individuals we do not manage.

3. Definitions

  • "Personal Data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access. This includes information described as "personally identifiable information" or "personal information" under applicable data privacy laws.
  • "PDPA" means the Personal Data Protection Act 2012 of Singapore, as amended from time to time.
  • "Brexy Group" means Brexy and its related corporations, including any subsidiary, holding company and the subsidiaries of that holding company, wherever situated.
  • "Services" means the products, features and services that we, our related entities, partners and/or vendors make available on or through the Platform.

4. Types of Personal Data We Collect

CategoryExamples
Profile and contact dataFirst and last name, business email address, phone number, employer, job title
Account and credential dataUsername, authentication and login credentials, single sign-on identifiers, security settings, role and permission assignments
Usage and device dataIP address, browser and device type, operating system, referring pages, pages and features accessed, session timestamps, activity and audit logs, online identifiers, approximate location derived from IP address
Communications and content you submitMessages and enquiries you send us, free-text entries, survey and questionnaire responses, feedback, support tickets
Commercial and relationship dataRecords of demonstrations, trials, subscriptions, billing contacts and correspondence relating to your organisation's engagement with us
Recruitment data (where applicable)CV, employment and education history, references

Sensitive personal data. We do not seek to collect NRIC or passport numbers, financial account numbers, precise geolocation, biometric data, or data revealing racial or ethnic origin, religious beliefs, health, sexual orientation or political opinions. Please do not submit such data to us unless we have specifically requested it.

5. Sources of Personal Data

We collect personal data about you from the following sources:

From you directly

  • When you provide it to us, including when you register for an account, request a demonstration, or subscribe to updates.
  • When you enter information into open text fields, surveys or questionnaires.
  • When you email, call or otherwise contact us.

From your use of the Platform and website

  • Automatically, when you use the Platform or website.
  • Through cookies and similar technologies (see Section 10).
  • Where your browser or device has location services enabled, we may receive information about your general location.
  • Where you download and install our applications, we may receive data transmitted from your device in order to deliver the Services to you.

From your organisation

  • Where an enterprise customer creates or provisions an account for you, or provides your contact details to us in connection with an engagement or evaluation.

From third parties and public sources

  • Business contact information from publicly available sources, business directories, professional networking platforms, conferences and events, and reputable data enrichment providers, used for business development purposes.

6. Why We Collect, Use and Disclose Personal Data

We may collect, use and disclose personal data for the following purposes:

Providing and operating the Services

  • Creating, administering and securing your account, and authenticating your access.
  • Providing, maintaining, personalising and improving the Platform and the Services.
  • Providing the information, features or materials you request.
  • Fulfilling the purpose for which you provided the data to us.
  • Carrying out research, planning, statistical analysis and analytics to develop and improve our products, services, security and service quality.
  • Managing our infrastructure and business operations, and complying with internal policies and procedures.

Communicating with you

  • Responding to your enquiries, requests, complaints and feedback.
  • Sending you service, security, billing and administrative communications, including notice of changes to the Services or their terms.
  • Sending marketing communications, where you have consented or where otherwise permitted by law (see Section 11).

Commercial and administrative purposes

  • Assessing and processing applications, instructions and requests.
  • Onboarding, contracting with and invoicing enterprise customers, and administering their accounts.
  • Conducting screening, sanctions and due diligence checks on prospective and existing counterparties where required or appropriate.
  • Financial, management and regulatory reporting, risk management, audit and record-keeping.
  • Enabling any actual or proposed assignee, transferee or acquirer of our rights, obligations or business to evaluate a proposed transaction.

Legal, safety and enforcement purposes

  • Meeting our obligations under applicable law, regulation, court order or other legal process, and responding to lawful requests from regulatory, governmental, tax and law enforcement authorities in Singapore or elsewhere.
  • Detecting, preventing and investigating security incidents, fraud, abuse, and unlawful or prohibited conduct.
  • Protecting the rights, property or safety of you, Brexy or any other party.
  • Enforcing our agreements and terms of use, addressing claims that content infringes third-party rights, and resolving disputes.

7. Legal Bases for Processing

In Singapore, we process personal data on the basis of your consent (including deemed consent), or on another basis permitted under the PDPA, such as the legitimate interests exception, business improvement, or where processing is required or authorised by law.

8. How We Share Your Personal Data

We may disclose personal data to the following categories of recipients, whether located inside or outside Singapore:

  • Members of the Brexy Group, for the purposes set out in this Policy.
  • Service providers and vendors who support our operations or perform functions on our behalf, including hosting and cloud infrastructure providers, communications and email providers, analytics providers, identity and access management providers, customer support platforms, payment and billing processors, and professional advisers.
  • Technology and AI service providers, including providers of large language models and related infrastructure, who supply the tools and infrastructure underpinning our AI-enabled features, subject to confidentiality and data protection commitments (see Section 12).
  • Your organisation, where you access the Platform through an enterprise account, including administrators, who may have visibility of account activity and audit logs.
  • Regulatory authorities, courts, tribunals and governmental agencies, and other third parties, in connection with the legal, safety and enforcement purposes described in Section 6.
  • Parties to a corporate transaction. Personal data may be transferred to a third party in connection with a merger, acquisition, financing, reorganisation, insolvency or other transaction in which that third party acquires control of all or part of our business. Where this occurs, we will notify you as required by applicable law.
  • Professional advisers, including legal, accounting, audit and insurance advisers, in connection with the performance of our duties and obligations.

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising.

9. Transfers of Personal Data Outside Singapore

We may transfer, store, process or otherwise deal with your personal data outside Singapore, including in jurisdictions where our group entities, cloud infrastructure providers or AI service providers operate. Where we do so, we will comply with the PDPA and any other applicable data protection laws, and will take reasonable steps to ensure your personal data continues to receive a standard of protection at least comparable to that provided under the PDPA — including through contractual commitments with the receiving party.

10. Cookies and Tracking Technologies

Our website and Platform use cookies and similar technologies, including pixel tags, web beacons, clear GIFs, local storage and scripts (collectively, "Cookies"). Cookies are small pieces of data stored on your device that allow our servers to recognise your browser, show us how and when you use our website and Platform, analyse trends, understand our user base, and operate and improve the Services.

We use the following categories of Cookies:

  • Essential Cookies, which are necessary to deliver the features and services you have requested — for example, to allow you to sign in to secure areas of the Platform and to maintain your session. Disabling these may render parts of the Platform unavailable.
  • Analytics and performance Cookies, which help us understand how the website and Platform are used so that we can improve them.
  • Preference Cookies, which remember your settings and choices.

We may combine information collected through Cookies with information obtained from third parties, including third parties that have set their own cookies on your devices.

You can control Cookies through your Cookie management settings on our website, and through your browser settings. Most browsers allow you to block new Cookies, choose whether to accept individual Cookies, and delete Cookies already stored on your device. If you block or delete Cookies, you may need to reset certain preferences on each visit, and parts of the website and Platform may not function correctly. General information about Cookies, including how to manage and delete them, is available at http://www.allaboutcookies.org.

Our website does not currently respond to "Do Not Track" signals sent from browsers.

11. Marketing Communications

Where you have consented, or where otherwise permitted by applicable law, we may send you newsletters, product updates, event invitations, service announcements and offers relating to the Services (together, "Marketing Communications"), by email or other channels you have agreed to.

You may change your Marketing Communications preferences or unsubscribe at any time using the link in any such message, or by contacting us at hello@brexy.ai. We comply with the Do Not Call provisions of the PDPA in respect of telephone and text-message marketing to Singapore numbers.

Separately from Marketing Communications, we may send you service, security, billing and legal notices that are necessary to your use of the Platform. These will be sent regardless of your marketing preferences.

12. Artificial Intelligence: Use, Governance and Safeguards

Brexy is an AI-powered platform, and we are committed to the secure, transparent and responsible use of artificial intelligence.

How we use AI

  • To provide the core functionality of the Platform, including document analysis, research, summarisation, drafting and workflow automation features.
  • To personalise your experience by analysing how you use the Platform, so that we can surface more relevant insights, recommendations and features.
  • To improve the security, reliability and quality of the Services, and to develop new features.
  • To conduct automated checks for purposes such as fraud detection, abuse prevention and risk management.

Model training. We do not use enterprise customer content — including documents, deal files and transaction data uploaded to the Platform — to train our own or any third party's foundation models, except where the relevant enterprise customer has expressly agreed in writing. Where we use data to improve our models or services, we use aggregated or de-identified data wherever practicable. We contractually require our third-party AI providers not to use data submitted through the Platform to train their models.

Governance and safeguards

  • Data minimisation. We apply data minimisation across use cases, transmitting to AI models only the specific fields and content required for the task.
  • Reliability controls. We apply confidence thresholds where appropriate, and conduct back-testing to assess the reproducibility and reliability of model outputs.
  • Security testing. We test the models and AI systems we use against recognised industry standards and frameworks, including testing for prompt injection and manipulation attacks and for sensitive information disclosure.
  • Vendor due diligence. We conduct due diligence on our external AI and large language model providers and impose contractual controls to obtain assurance that data submitted through the Platform is protected.
  • Human oversight. Outputs generated by the Platform are intended to support, not replace, professional judgement. They may contain errors or omissions and should be independently verified before being relied on.

Automated decision-making. Where we use automated processing or AI to make a decision that has a significant effect on you, you may request information about how that decision was made and, in certain circumstances, request review of the decision by a human.

If you have questions, comments or concerns about our use of AI systems, please contact us at hello@brexy.ai.

13. Data Security

We seek to protect personal data against unauthorized access, collection, use, disclosure, copying, modification, disposal and similar risks by applying administrative, physical and technical measures appropriate to the type of personal data and the way we process it. These include encryption of data in transit and at rest, access controls and role-based permissions, audit logging, network and endpoint protection, and disclosure of personal data internally and to authorised third parties on a need-to-know basis.

Please understand that no method of transmitting data over the internet, and no method of electronic storage, is entirely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised use of your account.

14. Data Breach Notification

In the event of a data breach affecting personal data, we will assess the breach and, where required under the PDPA or other applicable law, notify the Personal Data Protection Commission of Singapore and the affected individuals as soon as reasonably practicable. Our notification will describe the nature and extent of the breach, the personal data affected, and the steps we have taken to address the breach and limit its consequences. Where we act as a data intermediary for an enterprise customer, we will notify that customer without undue delay in accordance with our agreement with them.

15. Data Retention

We retain personal data for as long as necessary to provide the Services, to fulfil the business or commercial purposes for which the data was collected, or as otherwise permitted or required by law.

In setting retention periods, we consider the source of the data, our need for it, the purpose for which it was collected, and its sensitivity. We may retain personal data for longer where necessary to meet legal or regulatory obligations, resolve disputes, collect amounts owed, or defend legal claims. We may retain data in anonymised or aggregated form, where that data no longer identifies you personally.

Where an enterprise customer terminates its relationship with us, we may retain personal data for so long as we reasonably consider necessary for business, audit, legal or regulatory purposes. We will cease to retain personal data, or remove the means by which it can be associated with you, as soon as we consider that retention no longer serves the purpose for which it was collected or any other business, audit or legal purpose.

16. Accuracy of Personal Data

We generally rely on personal data provided by you or your authorised representative. Please ensure that the personal data you provide is accurate, current and complete. You can update your account details within the Platform, or notify us of any changes.

Where you provide us with another person's data, you represent and warrant that: (i) the relevant individual has been notified of the purposes for which their data will be collected, used and disclosed; and (ii) you have obtained that individual's consent, and have been duly authorised by them, to provide their personal data to us. You must promptly inform us if you become aware that the individual has withdrawn their consent. Withdrawal of consent may affect the Services we are able to provide.

Subject to applicable law, any consent given in relation to personal data provided to us survives the death, incapacity, bankruptcy or insolvency of the relevant individual and the termination or expiry of any account.

17. Your Rights

17.1 Rights under the PDPA (Singapore)

  • Access. You may request information about the personal data we hold about you and how it has been used or disclosed in the past year.
  • Correction. You may request that we correct any personal data we hold about you that is inaccurate or incomplete.
  • Withdrawal of consent. You may withdraw your consent to our collection, use or disclosure of your personal data, on reasonable notice. We will inform you of the likely consequences, which may include our being unable to continue providing the Services to you.
  • Data portability. You may request that we transmit your personal data held with us to another organisation, and we will comply where the applicable requirements under the PDPA are satisfied.

Subject to the PDPA, we reserve the right to charge a reasonable fee for granting access, making corrections or transmitting data. You will be notified of any fee before we process your request. If we are unable to comply with your request, we will inform you of our refusal and, except where we are not required to do so, the reasons for it.

18. How to Exercise Your Rights

To exercise any of the rights described in Section 17, email us at hello@brexy.ai with the subject line "Data Protection Request", and tell us which right you wish to exercise and the jurisdiction you are writing from.

We will verify your identity before responding, which may require you to provide additional information. We do not use that information for any purpose other than verifying your request. An authorised agent may submit a request on your behalf where they provide evidence of your written authorisation, and we may require you to verify the agent's authority directly.

We aim to respond as soon as reasonably possible. If we are unable to respond within 30 days of receiving your request, we will inform you in writing within that period of the time by which we expect to respond.

19. Personal Data of Children

The Platform is a business tool intended for use by professionals. We do not knowingly collect or solicit personal data from individuals under 16 years of age, and the Platform is not directed at children. If you are under 16, please do not register for or use the Platform or send us any personal data. If we discover that we have collected personal data from a child under 16, we will delete it as soon as possible. If you believe a child under 16 may have provided personal data to us, please contact us at hello@brexy.ai.

20. Third-Party Websites

The website and Platform may contain links to websites and services that we do not operate. This Policy applies only to our website and Platform. When you visit a third-party site, you should read its privacy policy, which will govern your use of that site.

21. Amendments to This Policy

We may amend this Policy from time to time to reflect changes in the way we use personal data or changes in applicable law. We will make the updated Policy available on our website at https://www.brexy.ai, and where the change is material we will notify you by posting a notice on the website and emailing the most recent address you have provided. All dealings with us are subject to the latest version of this Policy in force at the time.

22. General

Nothing in this Policy constitutes an indemnity by Brexy to any customer in relation to personal data or its use. To the extent permitted by applicable law, Brexy excludes liability for losses arising from our collection, storage, use, transfer or retention of personal data in accordance with this Policy, and in any event excludes liability for indirect, consequential or special losses, loss of profits, loss of contracts, or loss of reputation or goodwill.

If any provision of this Policy is found to be unenforceable, the remaining provisions will continue in full force and effect. This Policy is governed by the laws of Singapore, without prejudice to any mandatory rights you have under the data protection laws of your own jurisdiction.

23. How to Reach Us

For any questions or comments about this Policy, how we collect and use personal data, or your rights and choices, please contact:

Amit Kumar

Brexy Pte. Ltd.

11 Nathan Road, #03-02, Regency Park, Singapore 248732

Email: hello@brexy.ai

Web: https://www.brexy.ai

Brexy

The AI Infrastructure for Capital Markets
Purpose-built Financial AI Platform trusted by investors, bankers, advisors, and dealmakers.

SINGAPORE

Product
Products
Solutions
Investment BankingAsset ManagersDeal Makers
Company
AboutBlogSecurityCareersContact Us
Follow Us
X (Twitter)LinkedIn

Brexy © 2026. All rights reserved.

Privacy PolicySecurityTerms of Use