Legal
Privacy Policy
Last updated: 28 July 2026
Your privacy matters to us at Brexy. This Privacy Policy ("Policy") explains how we collect, use, disclose, process and safeguard personal data, and sets out your rights in relation to that data.
Because we are continually developing our website and platform, this Policy may be revised from time to time. Whenever we make a material change, we will post a notice on the Brexy website and email the most recent address you have shared with us.
Table of Contents
- 1. Who We Are
- 2. What This Policy Applies To
- 3. Definitions
- 4. Types of Personal Data We Collect
- 5. Sources of Personal Data
- 6. Why We Collect, Use and Disclose Personal Data
- 7. Legal Bases for Processing
- 8. How We Share Your Personal Data
- 9. Transfers of Personal Data Outside Singapore
- 10. Cookies and Tracking Technologies
- 11. Marketing Communications
- 12. Artificial Intelligence: Use, Governance and Safeguards
- 13. Data Security
- 14. Data Breach Notification
- 15. Data Retention
- 16. Accuracy of Personal Data
- 17. Your Rights
- 18. How to Exercise Your Rights
- 19. Personal Data of Children
- 20. Third-Party Websites
- 21. Amendments to This Policy
- 22. General
- 23. How to Reach Us
1. Who We Are
The Brexy platform, available at https://www.brexy.ai (together with any mobile or desktop application version, the "Platform"), is owned and operated by Brexy Pte. Ltd. ("Brexy", "we", "us" or "our"), a company incorporated in Singapore.
Brexy provides AI-powered deal intelligence and workflow software to financial institutions, advisory firms and their professionals.
2. What This Policy Applies To
This Policy applies to personal data:
- collected when you visit, browse or interact with our website;
- collected when you register for, access or use the Platform as an individual user; and
- otherwise provided to us in the course of your dealings with us, including business development, recruitment and general correspondence.
This Policy does not apply to the practices of businesses we do not own or control, or individuals we do not manage.
3. Definitions
- "Personal Data" means data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which we have or are likely to have access. This includes information described as "personally identifiable information" or "personal information" under applicable data privacy laws.
- "PDPA" means the Personal Data Protection Act 2012 of Singapore, as amended from time to time.
- "Brexy Group" means Brexy and its related corporations, including any subsidiary, holding company and the subsidiaries of that holding company, wherever situated.
- "Services" means the products, features and services that we, our related entities, partners and/or vendors make available on or through the Platform.
4. Types of Personal Data We Collect
| Category | Examples |
|---|---|
| Profile and contact data | First and last name, business email address, phone number, employer, job title |
| Account and credential data | Username, authentication and login credentials, single sign-on identifiers, security settings, role and permission assignments |
| Usage and device data | IP address, browser and device type, operating system, referring pages, pages and features accessed, session timestamps, activity and audit logs, online identifiers, approximate location derived from IP address |
| Communications and content you submit | Messages and enquiries you send us, free-text entries, survey and questionnaire responses, feedback, support tickets |
| Commercial and relationship data | Records of demonstrations, trials, subscriptions, billing contacts and correspondence relating to your organisation's engagement with us |
| Recruitment data (where applicable) | CV, employment and education history, references |
Sensitive personal data. We do not seek to collect NRIC or passport numbers, financial account numbers, precise geolocation, biometric data, or data revealing racial or ethnic origin, religious beliefs, health, sexual orientation or political opinions. Please do not submit such data to us unless we have specifically requested it.
5. Sources of Personal Data
We collect personal data about you from the following sources:
From you directly
- When you provide it to us, including when you register for an account, request a demonstration, or subscribe to updates.
- When you enter information into open text fields, surveys or questionnaires.
- When you email, call or otherwise contact us.
From your use of the Platform and website
- Automatically, when you use the Platform or website.
- Through cookies and similar technologies (see Section 10).
- Where your browser or device has location services enabled, we may receive information about your general location.
- Where you download and install our applications, we may receive data transmitted from your device in order to deliver the Services to you.
From your organisation
- Where an enterprise customer creates or provisions an account for you, or provides your contact details to us in connection with an engagement or evaluation.
From third parties and public sources
- Business contact information from publicly available sources, business directories, professional networking platforms, conferences and events, and reputable data enrichment providers, used for business development purposes.
6. Why We Collect, Use and Disclose Personal Data
We may collect, use and disclose personal data for the following purposes:
Providing and operating the Services
- Creating, administering and securing your account, and authenticating your access.
- Providing, maintaining, personalising and improving the Platform and the Services.
- Providing the information, features or materials you request.
- Fulfilling the purpose for which you provided the data to us.
- Carrying out research, planning, statistical analysis and analytics to develop and improve our products, services, security and service quality.
- Managing our infrastructure and business operations, and complying with internal policies and procedures.
Communicating with you
- Responding to your enquiries, requests, complaints and feedback.
- Sending you service, security, billing and administrative communications, including notice of changes to the Services or their terms.
- Sending marketing communications, where you have consented or where otherwise permitted by law (see Section 11).
Commercial and administrative purposes
- Assessing and processing applications, instructions and requests.
- Onboarding, contracting with and invoicing enterprise customers, and administering their accounts.
- Conducting screening, sanctions and due diligence checks on prospective and existing counterparties where required or appropriate.
- Financial, management and regulatory reporting, risk management, audit and record-keeping.
- Enabling any actual or proposed assignee, transferee or acquirer of our rights, obligations or business to evaluate a proposed transaction.
Legal, safety and enforcement purposes
- Meeting our obligations under applicable law, regulation, court order or other legal process, and responding to lawful requests from regulatory, governmental, tax and law enforcement authorities in Singapore or elsewhere.
- Detecting, preventing and investigating security incidents, fraud, abuse, and unlawful or prohibited conduct.
- Protecting the rights, property or safety of you, Brexy or any other party.
- Enforcing our agreements and terms of use, addressing claims that content infringes third-party rights, and resolving disputes.
7. Legal Bases for Processing
In Singapore, we process personal data on the basis of your consent (including deemed consent), or on another basis permitted under the PDPA, such as the legitimate interests exception, business improvement, or where processing is required or authorised by law.
9. Transfers of Personal Data Outside Singapore
We may transfer, store, process or otherwise deal with your personal data outside Singapore, including in jurisdictions where our group entities, cloud infrastructure providers or AI service providers operate. Where we do so, we will comply with the PDPA and any other applicable data protection laws, and will take reasonable steps to ensure your personal data continues to receive a standard of protection at least comparable to that provided under the PDPA — including through contractual commitments with the receiving party.
11. Marketing Communications
Where you have consented, or where otherwise permitted by applicable law, we may send you newsletters, product updates, event invitations, service announcements and offers relating to the Services (together, "Marketing Communications"), by email or other channels you have agreed to.
You may change your Marketing Communications preferences or unsubscribe at any time using the link in any such message, or by contacting us at hello@brexy.ai. We comply with the Do Not Call provisions of the PDPA in respect of telephone and text-message marketing to Singapore numbers.
Separately from Marketing Communications, we may send you service, security, billing and legal notices that are necessary to your use of the Platform. These will be sent regardless of your marketing preferences.
12. Artificial Intelligence: Use, Governance and Safeguards
Brexy is an AI-powered platform, and we are committed to the secure, transparent and responsible use of artificial intelligence.
How we use AI
- To provide the core functionality of the Platform, including document analysis, research, summarisation, drafting and workflow automation features.
- To personalise your experience by analysing how you use the Platform, so that we can surface more relevant insights, recommendations and features.
- To improve the security, reliability and quality of the Services, and to develop new features.
- To conduct automated checks for purposes such as fraud detection, abuse prevention and risk management.
Model training. We do not use enterprise customer content — including documents, deal files and transaction data uploaded to the Platform — to train our own or any third party's foundation models, except where the relevant enterprise customer has expressly agreed in writing. Where we use data to improve our models or services, we use aggregated or de-identified data wherever practicable. We contractually require our third-party AI providers not to use data submitted through the Platform to train their models.
Governance and safeguards
- Data minimisation. We apply data minimisation across use cases, transmitting to AI models only the specific fields and content required for the task.
- Reliability controls. We apply confidence thresholds where appropriate, and conduct back-testing to assess the reproducibility and reliability of model outputs.
- Security testing. We test the models and AI systems we use against recognised industry standards and frameworks, including testing for prompt injection and manipulation attacks and for sensitive information disclosure.
- Vendor due diligence. We conduct due diligence on our external AI and large language model providers and impose contractual controls to obtain assurance that data submitted through the Platform is protected.
- Human oversight. Outputs generated by the Platform are intended to support, not replace, professional judgement. They may contain errors or omissions and should be independently verified before being relied on.
Automated decision-making. Where we use automated processing or AI to make a decision that has a significant effect on you, you may request information about how that decision was made and, in certain circumstances, request review of the decision by a human.
If you have questions, comments or concerns about our use of AI systems, please contact us at hello@brexy.ai.
13. Data Security
We seek to protect personal data against unauthorized access, collection, use, disclosure, copying, modification, disposal and similar risks by applying administrative, physical and technical measures appropriate to the type of personal data and the way we process it. These include encryption of data in transit and at rest, access controls and role-based permissions, audit logging, network and endpoint protection, and disclosure of personal data internally and to authorised third parties on a need-to-know basis.
Please understand that no method of transmitting data over the internet, and no method of electronic storage, is entirely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly of any suspected unauthorised use of your account.
14. Data Breach Notification
In the event of a data breach affecting personal data, we will assess the breach and, where required under the PDPA or other applicable law, notify the Personal Data Protection Commission of Singapore and the affected individuals as soon as reasonably practicable. Our notification will describe the nature and extent of the breach, the personal data affected, and the steps we have taken to address the breach and limit its consequences. Where we act as a data intermediary for an enterprise customer, we will notify that customer without undue delay in accordance with our agreement with them.
15. Data Retention
We retain personal data for as long as necessary to provide the Services, to fulfil the business or commercial purposes for which the data was collected, or as otherwise permitted or required by law.
In setting retention periods, we consider the source of the data, our need for it, the purpose for which it was collected, and its sensitivity. We may retain personal data for longer where necessary to meet legal or regulatory obligations, resolve disputes, collect amounts owed, or defend legal claims. We may retain data in anonymised or aggregated form, where that data no longer identifies you personally.
Where an enterprise customer terminates its relationship with us, we may retain personal data for so long as we reasonably consider necessary for business, audit, legal or regulatory purposes. We will cease to retain personal data, or remove the means by which it can be associated with you, as soon as we consider that retention no longer serves the purpose for which it was collected or any other business, audit or legal purpose.
16. Accuracy of Personal Data
We generally rely on personal data provided by you or your authorised representative. Please ensure that the personal data you provide is accurate, current and complete. You can update your account details within the Platform, or notify us of any changes.
Where you provide us with another person's data, you represent and warrant that: (i) the relevant individual has been notified of the purposes for which their data will be collected, used and disclosed; and (ii) you have obtained that individual's consent, and have been duly authorised by them, to provide their personal data to us. You must promptly inform us if you become aware that the individual has withdrawn their consent. Withdrawal of consent may affect the Services we are able to provide.
Subject to applicable law, any consent given in relation to personal data provided to us survives the death, incapacity, bankruptcy or insolvency of the relevant individual and the termination or expiry of any account.
17. Your Rights
17.1 Rights under the PDPA (Singapore)
- Access. You may request information about the personal data we hold about you and how it has been used or disclosed in the past year.
- Correction. You may request that we correct any personal data we hold about you that is inaccurate or incomplete.
- Withdrawal of consent. You may withdraw your consent to our collection, use or disclosure of your personal data, on reasonable notice. We will inform you of the likely consequences, which may include our being unable to continue providing the Services to you.
- Data portability. You may request that we transmit your personal data held with us to another organisation, and we will comply where the applicable requirements under the PDPA are satisfied.
Subject to the PDPA, we reserve the right to charge a reasonable fee for granting access, making corrections or transmitting data. You will be notified of any fee before we process your request. If we are unable to comply with your request, we will inform you of our refusal and, except where we are not required to do so, the reasons for it.
18. How to Exercise Your Rights
To exercise any of the rights described in Section 17, email us at hello@brexy.ai with the subject line "Data Protection Request", and tell us which right you wish to exercise and the jurisdiction you are writing from.
We will verify your identity before responding, which may require you to provide additional information. We do not use that information for any purpose other than verifying your request. An authorised agent may submit a request on your behalf where they provide evidence of your written authorisation, and we may require you to verify the agent's authority directly.
We aim to respond as soon as reasonably possible. If we are unable to respond within 30 days of receiving your request, we will inform you in writing within that period of the time by which we expect to respond.
19. Personal Data of Children
The Platform is a business tool intended for use by professionals. We do not knowingly collect or solicit personal data from individuals under 16 years of age, and the Platform is not directed at children. If you are under 16, please do not register for or use the Platform or send us any personal data. If we discover that we have collected personal data from a child under 16, we will delete it as soon as possible. If you believe a child under 16 may have provided personal data to us, please contact us at hello@brexy.ai.
20. Third-Party Websites
The website and Platform may contain links to websites and services that we do not operate. This Policy applies only to our website and Platform. When you visit a third-party site, you should read its privacy policy, which will govern your use of that site.
21. Amendments to This Policy
We may amend this Policy from time to time to reflect changes in the way we use personal data or changes in applicable law. We will make the updated Policy available on our website at https://www.brexy.ai, and where the change is material we will notify you by posting a notice on the website and emailing the most recent address you have provided. All dealings with us are subject to the latest version of this Policy in force at the time.
22. General
Nothing in this Policy constitutes an indemnity by Brexy to any customer in relation to personal data or its use. To the extent permitted by applicable law, Brexy excludes liability for losses arising from our collection, storage, use, transfer or retention of personal data in accordance with this Policy, and in any event excludes liability for indirect, consequential or special losses, loss of profits, loss of contracts, or loss of reputation or goodwill.
If any provision of this Policy is found to be unenforceable, the remaining provisions will continue in full force and effect. This Policy is governed by the laws of Singapore, without prejudice to any mandatory rights you have under the data protection laws of your own jurisdiction.
23. How to Reach Us
For any questions or comments about this Policy, how we collect and use personal data, or your rights and choices, please contact:
Amit Kumar
Brexy Pte. Ltd.
11 Nathan Road, #03-02, Regency Park, Singapore 248732
Email: hello@brexy.ai
Web: https://www.brexy.ai