Privacy Policy

Last updated: October 7, 2026

1. Introduction

At Brio, we respect the privacy and protection of the personal data of individuals who visit our websites, communicate with us, use our services, or interact with the Brio platform.

This Privacy Policy explains how 3S SOFTWARE COMPANY, owner of the Brio brand (“Brio,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal data.

This Privacy Policy applies to brio.team, its subdomains, and any other Brio websites or services that reference this Privacy Policy.

Brio provides technology designed to digitize and manage frontline operations, quality, health and safety, maintenance, environmental processes, contractor management, and other business operations.

⸻

2. Identity of the Data Controller

For processing activities where Brio determines the purposes and means of processing, the data controller is:

3S SOFTWARE COMPANY
Tax ID / CUIT: 30717156222
Registered Address: Thames 1384, C1414DDB CABA, Argentina
Privacy Contact: info@brio.team
Website: brio.team

For certain services provided to corporate customers, Brio may instead act as a data processor, service provider, or data processing provider acting on behalf of the customer.

⸻

3. Personal Data We Process

The personal data we process depends on an individual’s relationship with Brio.

Website Visitors

When you visit our website, we may receive technical information such as:

* IP address;
* device type;
* browser type;
* operating system;
* pages visited;
* date and time of access;
* referring URL; and
* similar information relating to the security, operation, and use of our website.

We may also use cookies and similar technologies as described in this Privacy Policy.

Individuals Who Contact Brio

When an individual requests information, a product demonstration, a commercial proposal, customer support, or otherwise communicates with us, we may process information such as:

* first and last name;
* company;
* job title;
* email address;
* telephone number;
* country; and
* the content of communications with us.

Brio Customers and Users

We may process information necessary to manage our contractual relationship with customers and authorized users, including:

* professional identity;
* company and job title;
* business contact information;
* account credentials;
* roles and permissions;
* login and access records;
* activity within the platform; and
* communications relating to the service.

Data Submitted by Customers to the Brio Platform

Our customers may use Brio to process information relating to their employees, contractors, suppliers, visitors, or other individuals.

Depending on the modules used, this information may include:

* identification information;
* employment and professional information;
* training records;
* facility access information;
* occupational health and safety information;
* incident records;
* work permits;
* contractor information; and
* other information required for the business processes managed by the customer.

In these circumstances, the customer generally determines the purposes of the processing and acts as the data controller, while Brio processes the information on behalf of and under the instructions of the customer.

The specific categories of information processed depend on the configuration and modules selected by each customer.

⸻

4. Purposes of Processing

Brio may process personal data to:

* operate, maintain, and improve our websites and services;
* respond to inquiries and requests;
* provide demonstrations and commercial proposals;
* manage relationships with customers, users, suppliers, and business partners;
* create and administer user accounts;
* authenticate users;
* provide technical support and implementation services;
* protect our systems, users, and customers;
* prevent, detect, and investigate security incidents, fraud, or misuse;
* fulfill contractual, accounting, regulatory, and legal obligations;
* develop and improve product functionality;
* generate aggregated statistics and analytics; and
* communicate information about our products and services where legally permitted.

When information is used for product analytics, benchmarking, or statistical purposes, we seek to use aggregated, anonymized, or minimized information whenever reasonably possible.

⸻

5. Data Processed on Behalf of Customers

Brio is an enterprise technology platform, and a significant portion of the information processed within the platform is controlled by our customers.

When Brio acts as a data processor or service provider, Brio processes personal data solely for the purpose of providing the contracted services and in accordance with the customer’s documented instructions and applicable agreements.

The customer is responsible for determining the lawful basis, purpose, and scope of the personal data it submits to the platform and for providing individuals with any notices or obtaining any authorizations or consents required by applicable law.

Brio implements technical and organizational measures designed to protect the confidentiality, integrity, and availability of such information.

If an individual wishes to exercise rights in relation to personal data submitted to Brio by their employer or another customer organization, the request should generally be directed to that organization.

Brio will reasonably assist its customers in responding to valid data subject requests.

⸻

6. Legal Basis for Processing

Brio processes personal data pursuant to the legal bases available under the laws applicable to each processing activity.

Depending on the circumstances, processing may be based on:

* the consent of the individual;
* performance of a contract;
* steps taken prior to entering into a contract;
* compliance with a legal obligation;
* legitimate interests pursued by Brio or a third party, provided those interests are not overridden by the rights and freedoms of the individual; or
* any other legal basis permitted under applicable law.

In Argentina, personal data processing is subject, among other applicable regulations, to Personal Data Protection Law No. 25,326, its implementing regulations, and rules issued by the Argentine Agency for Access to Public Information.

⸻

7. Sensitive Personal Data

Brio does not request sensitive personal data through its public website unless such information is strictly necessary for a specific purpose and an appropriate legal basis exists.

Certain customers may use Brio modules to manage information that, depending on the applicable jurisdiction and circumstances, may qualify as sensitive, special-category, or otherwise protected personal data.

Where this occurs, the information is processed in accordance with the customer’s instructions, applicable contractual arrangements, applicable law, and appropriate security safeguards.

⸻

8. Artificial Intelligence and Use of Customer Data

Brio may incorporate features powered by artificial intelligence, automation, machine learning models, or similar technologies.

When these features process Customer Data, such processing will be carried out for the purpose of providing the contracted functionality and in accordance with the applicable terms governing the service.

Brio will not use Customer Data to train general-purpose artificial intelligence models operated by Brio or third parties without the customer’s express authorization, unless the data has first been anonymized so that neither individuals nor the originating customer can reasonably be identified.

Where an artificial intelligence feature uses an external technology provider and Customer Data is processed by that provider, the provider will be subject to applicable contractual, confidentiality, security, and data protection obligations.

⸻

9. Sale of Personal Data and Advertising

Brio does not sell personal data.

We do not commercialize databases containing information about users, customer employees, contractors, or website visitors as an independent product.

Brio does not use Customer Data to create advertising profiles for third parties.

⸻

10. Service Providers and Subprocessors

Brio may engage specialized third-party providers that are necessary to operate our infrastructure and provide our services.

These providers may deliver services such as:

* cloud infrastructure;
* hosting and storage;
* databases;
* authentication;
* communications;
* email delivery;
* analytics;
* customer support;
* monitoring;
* cybersecurity;
* business management services; and
* payment processing.

When such providers have access to personal data, Brio requires them to process the information only for authorized purposes and to maintain appropriate confidentiality and security measures.

For enterprise services involving the processing of Customer Data, Brio may maintain an up-to-date list of subprocessors at [brio.team/subprocessors] or provide such information upon request through our privacy contact.

⸻

11. Customer-Enabled Integrations

The Brio platform may allow customers to integrate Brio with external systems selected by the customer.

When a customer enables an integration with a third-party system, information may be transmitted between Brio and that system in accordance with the customer’s configuration and instructions.

The privacy practices of the third-party provider will be governed by that provider’s privacy policy and by any agreements between the provider and the customer.

⸻

12. International Data Transfers

Brio provides services to organizations located in multiple countries and may use technology infrastructure distributed across different jurisdictions.

As a result, personal data may be processed or stored outside the country in which it was originally collected.

Where required by applicable law, Brio will implement mechanisms designed to provide an appropriate level of protection for international data transfers, which may include:

* adequacy decisions;
* standard contractual clauses approved by competent authorities;
* data processing agreements;
* contractual safeguards; or
* other legally recognized transfer mechanisms.

International transfers subject to Argentine law will be carried out in accordance with Law No. 25,326, its implementing regulations, and regulations issued by the Argentine Agency for Access to Public Information.

⸻

13. Information Security

Brio implements technical, administrative, and organizational measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, misuse, or destruction.

These measures are determined taking into account the nature of the information, the context of the processing, the risks involved, and technological developments.

Our security measures may include:

* access controls and role-based permissions;
* authentication mechanisms;
* logical separation of customer information;
* activity logging and monitoring;
* encryption where appropriate;
* vulnerability management;
* backup and recovery procedures;
* incident response procedures; and
* security controls relating to third-party providers.

No information system can guarantee absolute security.

Brio periodically reviews and adapts its security measures in light of changes in technology, risks, and business operations.

⸻

14. Data Retention

Brio retains personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected and to comply with applicable contractual, regulatory, accounting, or legal obligations.

Customer Data processed within the Brio platform will generally be retained for the duration of the contractual relationship and thereafter for any period established in the applicable agreement, customer instructions, or applicable law.

Following the applicable retention period, information may be deleted, anonymized, or retained where a legal obligation requires continued preservation.

⸻

15. Cookies and Similar Technologies

Brio may use cookies and similar technologies that are strictly necessary for the operation, authentication, security, and maintenance of our websites and services.

We may also use analytics technologies to better understand, on an aggregated basis, how our website is used and to improve its performance and usability.

Where applicable law requires consent for cookies or technologies that are not strictly necessary, Brio will request the appropriate consent before using them.

Visitors may manage their preferences through any cookie preference mechanism made available by Brio.

⸻

16. Marketing Communications

Brio may send communications relating to our products, services, events, or content to individuals who:

* have requested information from us;
* have an existing business relationship with Brio; or
* have provided consent where consent is legally required.

Individuals may unsubscribe from marketing communications at any time by using the unsubscribe mechanism included in the communication or by contacting us.

Communications that are necessary to provide contracted services, administer an account, provide security notifications, or fulfill legal obligations are not considered marketing communications.

⸻

17. Individual Privacy Rights

Depending on the applicable jurisdiction, individuals may have rights to:

* confirm whether Brio processes their personal data;
* access personal data;
* request correction or updating of inaccurate data;
* request deletion where legally applicable;
* object to certain processing activities;
* request restriction of processing;
* withdraw previously given consent;
* request data portability where applicable; and
* lodge a complaint with a competent data protection authority.

Requests may be submitted to [privacy@brio.team].

Brio may request information reasonably necessary to verify the identity of the person making the request and to protect personal data against unauthorized disclosure.

Where Brio acts solely as a processor on behalf of a customer, the request may be referred to the relevant customer.

⸻

18. Rights of Individuals in Argentina

Individuals whose personal data is protected under Argentine law may exercise the rights provided under Personal Data Protection Law No. 25,326.

These include, where applicable, the rights to:

* access personal data;
* rectify inaccurate information;
* update personal data; and
* request deletion of personal data.

The right of access may be exercised free of charge in accordance with the terms and frequency established under applicable law.

The Argentine Agency for Access to Public Information (Agencia de Acceso a la Información Pública), as the supervisory authority responsible for enforcing Law No. 25,326, is authorized to receive complaints and claims relating to violations of personal data protection requirements.

⸻

19. Individuals in the European Economic Area, United Kingdom, and Other Jurisdictions

Where the European Union General Data Protection Regulation (“GDPR”), United Kingdom data protection law, or comparable privacy legislation applies, Brio will recognize the rights established by such laws and apply the required mechanisms for processing and international transfers.

Brio’s status as a controller or processor will be determined for each processing activity based on which party determines the purposes and means of processing.

Where required, Brio may enter into appropriate Data Processing Agreements and Standard Contractual Clauses with customers or service providers.

⸻

20. Children

Brio’s websites and commercial services are intended for organizations and professional users and are not designed to provide services directly to children.

Brio does not knowingly collect personal data from children through its website for commercial purposes.

Where a customer legitimately uses Brio services in connection with activities involving information about minors, the customer is responsible for ensuring that the processing is lawful and subject to all required protections.

⸻

21. Legally Required Disclosures

Brio may disclose personal data where reasonably necessary to:

* comply with applicable law or regulation;
* comply with a valid court order or lawful request from a competent authority;
* protect the rights, property, systems, or security of Brio, our customers, users, or third parties;
* investigate fraud, misuse, or security incidents; or
* establish, exercise, or defend legal claims.

Where legally permitted, Brio will assess the validity and scope of requests for information and seek to limit any disclosure to information reasonably necessary to comply with the request.

⸻

22. Corporate Transactions

If Brio is involved in a merger, acquisition, financing, reorganization, sale of assets, investment transaction, or similar corporate transaction, certain information may be shared with prospective purchasers, investors, lenders, professional advisers, or other parties subject to appropriate confidentiality obligations.

Any successor entity that assumes responsibility for such personal data will be required to process it in accordance with applicable law and the privacy commitments applicable to the information.

⸻

23. Changes to This Privacy Policy

Brio may update this Privacy Policy from time to time as a result of changes in applicable law, technology, business operations, or our services.

The current version will be made available on our website and will identify the date on which it was last updated.

Where a change is material and applicable law requires additional notice, Brio may provide appropriate notice to affected users or customers.

⸻

24. Contact Us

Questions regarding privacy, data protection, or this Privacy Policy may be directed to:

Brio – Privacy and Data Protection
Email: info@brio.team
Registered Address: Thames 1384, C1414DDB CABA, Argentina

For personal data processed by Brio on behalf of a customer organization, individuals should generally contact that organization first, as the organization will normally act as the data controller.

Logotipo BRIO SaaS para la gestión industrial integrada

Schedule a personalized demo.

Fill in your details and we’ll show you how BRIO can adapt to your operation.