Cerebera — Privacy Policy
1. Introduction
Welcome to Cerebera. At Cerebera Systems Ltd ("Cerebera", "we", "our" or "us"), we are committed to protecting your privacy and handling your personal information responsibly, securely and transparently.
This Privacy Policy explains how we collect, use, store, protect and disclose personal information when you access or use the Cerebera platform, including our website, web applications, mobile applications, APIs and related services (collectively, the "Services"). Please read this Privacy Policy carefully before using the Services.
2. Who this Privacy Policy applies to
This Privacy Policy applies to: organisations subscribing to Cerebera; customer administrators; managers and supervisors; employees; workers; contractors; consultants; temporary staff; agency workers; volunteers; visitors to our website; individuals contacting Cerebera; and anyone authorised to use the Cerebera platform or mobile application.
3. Who we are
Cerebera is operated by Cerebera Systems Ltd, a company incorporated in England and Wales. For the purposes of applicable data protection legislation:
- Cerebera acts as a Data Controller when processing personal information relating to its own business activities, including customer accounts, billing, website enquiries, marketing communications and customer support.
- Cerebera acts as a Data Processor when processing personal information on behalf of a customer organisation using the Cerebera platform.
4. Information we collect
Depending on how you use the Services, we may collect the following categories of personal information:
Identity information
- Name
- Job title
- Organisation
- Employee or worker ID
- Username
- Profile photograph (if provided)
Contact information
- Business email address
- Telephone number
- Company address
- Emergency contact details (where enabled by your organisation)
Account information
- Login credentials
- Password (stored in encrypted form)
- Authentication information
- User preferences
- Language settings
Device information
- Device type
- Operating system
- Browser type
- Device identifiers
- Mobile device identifiers
- IP address
- App version
- Crash reports
Location information
Where enabled by your organisation or permitted by you, we may collect location data, including precise GPS location and location collected while the app is running in the background during an active shift or safety alert:
- Live GPS location
- Historical location data
- Geofencing events
- Route information
- Time and location stamps
Operational information
Information generated through your use of the Platform, including: tasks; attendance records; shift information; forms; reports; inspections; checklists; workflow activity; communications; audit logs; and activity history.
Content
Information uploaded through the Platform, including: photographs; videos; audio recordings; documents; digital signatures; notes; comments; incident reports; and other work-related content.
Payment information
Where applicable, we may collect limited billing information for subscription management. Payment card information is processed securely by our third-party payment providers and is not stored by Cerebera.
5. How we collect information
We may collect information: directly from you; from your organisation; when you create an account; when you use the Platform; when you upload content; when you communicate with us; through cookies and similar technologies; through integrated third-party services; and automatically through your device and browser.
6. How we use your information
We use personal information to: provide the Services; authenticate users; manage user accounts; allocate and manage operational tasks; enable communications; provide worker safety features; generate reports and analytics; provide customer support; improve platform performance; maintain platform security; detect fraud and misuse; comply with legal obligations; develop new features and functionality; and communicate important service updates. We will only process personal information where we have a lawful basis to do so.
7. Lawful basis for processing
Where required by applicable law, we process personal information on one or more of the following legal bases: performance of a contract; compliance with a legal obligation; legitimate interests; consent (where required); protection of vital interests; and performance of a task carried out in the public interest, where applicable. Where Cerebera acts as a Data Processor, the Customer determines the lawful basis for processing personal information.
8. Location services
The Cerebera platform includes optional location-based functionality. Where enabled by your organisation, location information — including background location while a shift or safety alert is active — may be used for: workforce coordination; task allocation; attendance verification; route optimisation; worker safety; emergency response; and operational reporting. Location is used only for these work purposes; it is not used for advertising and is not sold. Your organisation determines how location information is used within the Platform and is responsible for ensuring compliance with applicable employment and privacy laws.
9. Camera, microphone and device permissions
Certain features require access to your device's camera, microphone, GPS, storage and notifications. These permissions are used only to provide the functionality requested by you or your organisation. You may manage these permissions through your device settings, although disabling them may limit certain features of the Platform.
10. Artificial intelligence
Cerebera may use artificial intelligence technologies to assist with workflow automation, operational insights, reporting, recommendations, task management, document analysis and productivity improvements. AI-generated outputs are intended to assist users and should not be relied upon as the sole basis for business, legal, medical or safety-critical decisions.
11. Cookies
Our website and web applications use cookies and similar technologies to keep you signed in, remember preferences, improve security, analyse usage and enhance performance. Further information is available in our Cookie Policy.
12. How we share your information
We only share personal information where necessary to provide the Services, comply with legal obligations or protect our legitimate business interests. Depending on how the Platform is used, personal information may be shared with: your organisation; authorised administrators within your organisation; authorised users of the Platform; our trusted service providers; payment providers; cloud hosting providers; identity verification providers; communication service providers; analytics providers; artificial intelligence service providers (where AI features are enabled); and regulators, courts or law enforcement authorities where required by law. We do not sell your personal information.
13. Our service providers
To deliver the Services, Cerebera may engage carefully selected third-party providers, including providers of cloud infrastructure, payment processing, email delivery, SMS and communication services, mapping services, customer support, identity verification, security monitoring, analytics and artificial intelligence functionality. All service providers are required to maintain appropriate security and confidentiality obligations.
14. Regional data hosting
Cerebera is committed to storing Customer Data within the geographical region selected by the Customer wherever commercially and technically practicable. Unless otherwise agreed: customers in the United Kingdom are hosted within AWS UK regions; customers in India are hosted within AWS India regions; customers in the United States are hosted within AWS United States regions; and customers in other countries may be hosted within the agreed regional infrastructure. Certain operational metadata, encrypted backups, audit logs and support information may be processed outside the primary hosting region where necessary to maintain the security, resilience and continuity of the Services and where permitted by applicable law.
15. International data transfers
Where personal information is transferred outside the country in which it was collected, Cerebera will implement appropriate safeguards required under applicable data protection legislation. These safeguards may include the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, the European Commission Standard Contractual Clauses (SCCs), or other legally recognised transfer mechanisms.
16. Data retention
We retain personal information only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, maintain business records and protect our legitimate business interests. Retention periods may vary depending on the nature of the information and the requirements of applicable law. Where personal information is no longer required, it will be securely deleted, anonymised or irreversibly destroyed.
17. Security
We take the security of personal information seriously and maintain appropriate technical and organisational measures designed to protect it against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include encryption in transit; encryption at rest where appropriate; secure cloud infrastructure; role-based access controls; multi-factor authentication for privileged accounts where appropriate; audit logging; network security controls; vulnerability management; penetration testing; disaster recovery procedures; business continuity planning; staff confidentiality obligations; and regular security awareness training. While we strive to protect personal information, no internet-based service or electronic storage system can be guaranteed to be completely secure.
18. Your privacy rights
Subject to applicable law, you may have the right to: request access to your personal information; request correction of inaccurate information; request deletion of personal information; request restriction of processing; object to certain processing activities; request portability of your personal information; withdraw consent where processing is based on consent; and lodge a complaint with the relevant supervisory authority. Where Cerebera processes personal information on behalf of your organisation, requests relating to your personal information should generally be directed to your organisation in the first instance. Cerebera will assist customer organisations in responding to such requests where required by applicable law.
19. Marketing communications
Where permitted by law, Cerebera may send business-related updates, newsletters, product announcements and marketing communications. You may opt out of receiving marketing communications at any time by clicking the unsubscribe link included in our emails, updating your communication preferences within your account settings, or contacting us directly. Operational, security and account-related communications are not marketing communications and cannot generally be opted out of while you continue to use the Services.
20. Children's privacy
The Cerebera platform is intended for business use and is not designed for children. We do not knowingly collect personal information directly from children through the Enterprise platform. Where a Customer uses the Services in a way that involves information relating to minors, the Customer remains responsible for ensuring that all necessary legal requirements, notices and permissions have been obtained.
21. Third-party websites, services and connected accounts
21.1 Links to third-party services
The Platform may contain links to third-party websites, applications or services. Cerebera is not responsible for the privacy practices, content or security of third-party services. Users should review the privacy policies of those third-party providers before using their services.
21.2 Connected accounts (integrations)
A customer administrator may choose to connect a third-party business account — for example Slack, Microsoft Teams, Microsoft Outlook, Gmail or Google Meet — to their Cerebera organisation. Connecting an account is always optional, is initiated by the customer, and requires the account holder to grant access through that provider's own consent screen. Where an account is connected:
- We request the narrowest set of permissions the feature needs. For mail integrations this is the ability to read the connected mailbox and to send mail as the connected account; for messaging integrations it is the ability to read and post messages in the channels or chats the customer selects; for meeting integrations it is the ability to create a meeting link.
- We store an encrypted access token (and, where the provider issues one, a refresh token) so the connection can keep working without asking the user to sign in repeatedly. Tokens are encrypted at rest and are never exposed through our APIs.
- We store the content the feature needs to function — for example the messages and mail of the channels or folders the customer has chosen to display, their attachments, and the sender and recipient details attached to them — so that they can be shown in the Cerebera Comms Hub and email workspace.
- We use that content only to provide the feature to the customer whose account is connected. We do not sell it, we do not use it for advertising, and we do not use it to build profiles unrelated to the Services.
21.3 Disconnecting and deletion
A customer administrator can disconnect an integration at any time from within the Platform. Disconnecting immediately stops further access, deletes the stored tokens and stops any further synchronisation. Content already synchronised is deleted in line with section 16 (Data Retention), and the account holder may additionally revoke our access directly with the provider at any time.
21.4 Google API Services — Limited Use
Cerebera's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not transfer Google user data to third parties except as necessary to provide or improve the Services, to comply with applicable law, or as part of a merger, acquisition or sale of assets with notice to the customer; we do not use Google user data for advertising; we do not allow humans to read Google user data unless we have the customer's explicit consent for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymised; and we do not use Google user data to develop, improve or train generalised artificial-intelligence or machine-learning models.
21.5 Microsoft services
Where a Microsoft account is connected, data is accessed through the Microsoft Graph API using permissions granted by the account holder or their tenant administrator, and is used only to provide the connected feature. The same restrictions set out in section 21.2 apply. Access can be revoked at any time from within the Platform or from the user's Microsoft account privacy settings.
22. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in applicable law, new features or functionality, improvements to the Services, changes in our business operations, or developments in industry best practice. Where material changes are made, we will notify Customers through the Platform, by email or by other appropriate means. The updated Privacy Policy will become effective from the date specified at the top of the document. Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.
23. Contacting Cerebera
If you have any questions about this Privacy Policy or how your personal information is processed, you may contact Cerebera using the contact details available on the Cerebera website. For general privacy enquiries, questions regarding the processing of your personal information, or to exercise any of your privacy rights, please contact our Privacy Team at: support@cerebera.com. We will use reasonable endeavours to respond to your enquiry promptly and in accordance with applicable data protection legislation.
24. Exercising your privacy rights
If you wish to exercise any of your privacy rights — including requests to access, correct, delete, restrict, object to processing, request data portability or withdraw consent — you may submit your request through your organisation (where Cerebera processes information on its behalf), your Cerebera account (where available), or the contact details published on our website. We may request reasonable information to verify your identity before responding. Where Cerebera acts as a Data Processor on behalf of your organisation, we may refer your request to your organisation, which is responsible for determining how your request should be handled under applicable data protection legislation.
25. Complaints
If you believe that Cerebera has not processed your personal information in accordance with this Privacy Policy or applicable data protection laws, we encourage you to contact us first at support@cerebera.com so that we have an opportunity to investigate and resolve your concerns. Please include your name and contact details, the nature of your complaint, the date of the relevant events and any supporting information. We will acknowledge receipt, investigate fairly and promptly, and endeavour to provide a substantive response within a reasonable timeframe. If you remain dissatisfied, you may have the right to lodge a complaint with the relevant data protection supervisory authority in the jurisdiction where you reside, work, or where the alleged infringement occurred. Nothing in this Privacy Policy limits any rights you may have under applicable law.
26. Customer responsibilities
Where Cerebera processes personal information on behalf of a customer organisation, that organisation is responsible for determining the lawful basis for processing, providing any required privacy notices, obtaining any necessary consents where required by law, configuring the Platform in accordance with its legal obligations, and responding to requests from its employees, workers or other data subjects. Cerebera processes such information only in accordance with the Customer's instructions and the Cerebera Data Processing Agreement.
27. Your responsibilities
When using the Cerebera platform, you agree to provide accurate information, keep your account credentials secure, use the Platform lawfully, respect the privacy of others, upload only information that you are authorised to upload, and promptly notify your organisation or Cerebera of any suspected unauthorised access or security incident.
28. Relationship with other policies
This Privacy Policy should be read together with the following Cerebera documents: Master Subscription Agreement; End User Terms of Use; Data Processing Agreement (DPA); Cookie Policy; Information Security Policy; Acceptable Use Policy; Service Level Agreement (SLA); Support & Maintenance Policy; AI Usage Policy; and Regional Data Residency Policy. Where there is any conflict between this Privacy Policy and the Data Processing Agreement in relation to the processing of Customer Personal Data, the Data Processing Agreement shall prevail.
29. Version history
- 1.0 — initial version.
- 1.1 — added sections 21.2–21.5 (connected third-party accounts, Google API Services Limited Use, Microsoft services).
- 1.2 — corrected the operating entity to Cerebera Systems Ltd.
- 1.3 — privacy enquiries and complaints now go to support@cerebera.com.