Privacy Policy
Bridgly is provided by DataGo Ltd, a company registered in England and Wales under company number 14751587. References to DataGo, Bridgly, we, us or our in this policy mean DataGo Ltd.
This Privacy Policy explains how we collect, use, disclose and protect personal information when you:
- Visit bridgly.ai or another Bridgly website.
- Contact us, request a demonstration or join an early-access programme.
- Use a Bridgly account, workspace, application or integration.
- Install or use Bridgly through Databricks Marketplace.
- Receive support or otherwise interact with us.
Our role
DataGo acts as a data controller when we decide why and how personal information is used. This includes information about website visitors, prospective customers, customer administrators, billing contacts and people who contact us directly.
Where an organisation uses Bridgly to process information contained in its workspaces, connected systems or business records, that organisation normally acts as the controller and DataGo acts as its processor or service provider. We process that Customer Content only on the organisation's documented instructions and under the applicable customer agreement or data processing agreement.
If your information was placed in Bridgly by your employer or another organisation, you should contact that organisation first about how it uses your information. We will assist it in responding to valid privacy requests.
Information we collect
Website and enquiry information
When you visit our website or contact us, we may collect:
- Your name, work email address, company and job information.
- Information included in demo requests, messages or support enquiries.
- Early-access preferences and the type of product information requested.
- Communications between you and DataGo.
- Your marketing preferences, where you separately choose to receive marketing.
Account and organisation information
When you or your organisation creates or administers a Bridgly account, we may collect:
- Name, work email address and account identifiers.
- Organisation, team, role and workspace membership.
- Authentication, access-control and permission information.
- Account settings and administrative activity.
- Subscription, contract and billing-contact information.
Where payments are offered, payment-card information is processed by the relevant payment provider. DataGo should not receive or retain full payment-card numbers.
Customer Content
Depending on the features selected by your organisation, Customer Content may include:
- Sessions, decisions, outcomes and associated business context.
- Project, team, task and workflow information.
- Evidence, source references, approvals and governance records.
- Delegations, authority records and audit receipts.
- Questions submitted to Bridgly and the responses produced.
- Information retrieved from systems connected by your organisation.
- Files, structured data or metadata made available in a customer-controlled Databricks workspace.
Customer Content may include personal information if a customer or authorised user chooses to provide it.
AI interaction information
When an AI-assisted feature is used, we may process:
- Prompts, questions and instructions.
- Context selected or retrieved for the request.
- Model responses and supporting references.
- Model, token, cost, latency and execution metadata.
- Feedback, approvals and other human review signals.
Bridgly is designed to support governed human decision-making. Its outputs are recommendations or evidence-based assistance and should be reviewed by an authorised person.
Integration information
When an organisation connects Bridgly to Databricks or another service, we may process:
- Connection and workspace identifiers.
- Configuration, permission and synchronisation status.
- Records made available through the integration.
- Operational information about connector activity and errors.
Credentials and secrets should be handled using the relevant platform's protected secret-management facilities. We do not use connected-system information for purposes unrelated to providing and securing Bridgly.
Technical and usage information
We may collect:
- IP address, browser, device and operating-system information.
- Dates and times of access.
- Pages, features and actions used.
- Authentication, security and audit events.
- Error, performance and diagnostic information.
- Cookie or consent preferences.
We minimise the personal information included in operational logs and do not intentionally log Customer Content, prompts, form submissions, credentials or secrets.
Sources of information
We obtain information:
- Directly from you.
- From your employer, customer organisation or workspace administrator.
- From systems your organisation chooses to connect to Bridgly.
- From Databricks or another marketplace through which Bridgly is obtained.
- Automatically from your browser, device or use of the service.
- From business partners or public business sources where permitted by law.
Providing account and contact information may be necessary for us to respond to a request or provide the service. If required information is not provided, we may be unable to create an account, deliver the requested service or respond to you.
How and why we use information
We use personal information for the following purposes and lawful bases:
| Purpose | Typical lawful basis |
|---|---|
| Responding to enquiries, demonstrations and requested pre-contract activity | Steps requested before a contract and our legitimate interests in communicating with prospective customers |
| Providing accounts, workspaces, support and contracted services | Performance of a contract and our legitimate interests in administering business-customer relationships |
| Processing Customer Content | The customer's documented instructions and applicable data processing agreement |
| Authentication, access control, fraud prevention and service security | Legitimate interests and, where applicable, legal obligations |
| Operating, troubleshooting and improving reliability | Legitimate interests in maintaining a safe and effective business service |
| Maintaining governance, audit and support records | Contract, legitimate interests and applicable legal obligations |
| Billing, accounting and corporate administration | Contract and legal obligations |
| Optional website analytics | Consent |
| Marketing communications | Consent, or another lawful basis where expressly permitted by applicable law |
| Establishing, exercising or defending legal claims | Legitimate interests and legal obligations |
Where we rely on legitimate interests, those interests include operating and improving Bridgly, protecting customers and systems, communicating with business users and administering our commercial relationships. We consider whether these interests are proportionate and whether they are overridden by an individual's rights.
AI and model providers
Bridgly may use Databricks model-serving capabilities or model providers enabled by the customer. Information necessary to perform an AI request may be sent to the selected provider.
Where a customer connects its own model account or chooses a provider, the customer's configuration and its agreement with that provider also apply.
DataGo does not use Customer Content, prompts or AI responses to train shared Bridgly models or third-party foundation models by default. Any future use of Customer Content for model training would require a separate, explicit customer opt-in and updated contractual and privacy information.
We may use de-identified operational measurements, such as aggregate feature usage, latency and error rates, to operate and improve Bridgly. We do not attempt to re-identify de-identified information.
Bridgly does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals. Customers must provide appropriate human oversight for decisions made using Bridgly.
Databricks deployments
Where Bridgly is installed through Databricks Marketplace or deployed in a customer's Databricks environment:
- The customer controls the workspace, users, permissions and data made available to the application.
- Customer data intended to remain in the customer's workspace is processed there using the permissions granted during installation.
- DataGo receives Customer Content only where required by the selected deployment, expressly configured by the customer, or provided for support.
- Databricks separately processes account, marketplace, workspace and platform information under the customer's relationship with Databricks and Databricks' own privacy terms.
- Application permissions should be limited to those required for the enabled Bridgly features.
- The listing, order form or deployment documentation will identify any information sent outside the customer's Databricks environment.
How we share information
We may share information with:
- The customer organisation and its authorised users and administrators.
- Databricks and infrastructure or hosting providers used to deliver Bridgly.
- Model providers selected or enabled for AI-assisted features.
- Email and communication providers used to deliver requested responses, including Resend and, where configured, Slack.
- Google Analytics, but only after analytics consent has been provided.
- Payment and billing providers where paid services are offered.
- Security, monitoring, professional-advisory and support providers.
- Regulators, courts or law-enforcement bodies where disclosure is legally required.
- A prospective purchaser, investor or successor in connection with a genuine corporate transaction, subject to appropriate confidentiality protections.
Service providers are authorised to process information only for the services they provide to us and must protect it appropriately.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising or use Customer Content for third-party advertising.
A current list of material service providers and subprocessors will be made available on request and, before general Marketplace availability, through a public subprocessor page.
International transfers
Some providers may process information outside the United Kingdom or the country where the information was collected.
Where a restricted international transfer occurs, we use an applicable legal mechanism, such as:
- A UK adequacy regulation.
- The UK International Data Transfer Agreement.
- The UK Addendum to the European Commission's Standard Contractual Clauses.
- Another safeguard or exception permitted by applicable data-protection law.
You may contact us for further information about the safeguards relevant to your information.
Retention
We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including contractual, security, accounting and legal requirements.
In particular:
- Enquiry and demonstration information is retained while we handle the request and for a reasonable follow-up period.
- Marketing information is retained until consent is withdrawn or the information is no longer needed. We may retain minimal suppression information to respect an unsubscribe request.
- Account and administrative information is retained for the customer relationship and as required for contract, dispute and legal-record purposes.
- Customer Content is retained according to the customer agreement, workspace configuration and customer instructions.
- Content stored solely in a customer-controlled Databricks workspace is subject to that customer's retention configuration.
- Security and audit information is retained for the period reasonably required to investigate incidents, protect the service and meet contractual or legal requirements.
- Financial and corporate records are retained for the period required by applicable accounting and company law.
- Backup copies are removed through the normal backup-expiry cycle unless preservation is legally required.
We may retain anonymised information that can no longer identify an individual.
Cookies and similar technologies
The Bridgly website may use:
- Strictly necessary storage for security, session management and remembering privacy choices.
- Optional analytics technologies, including Google Analytics, to understand website usage.
Optional analytics are disabled until consent is provided. We do not use advertising or behavioural-targeting cookies.
You may accept or decline analytics and change your choice through the website's Cookie settings control. Withdrawing consent does not affect processing that occurred before withdrawal.
Security
We use technical and organisational measures appropriate to the nature and risk of the information processed. These may include access controls, tenant and workspace boundaries, encryption in transit and at rest where supported, protected secret handling, audit logging, dependency management and incident-response procedures.
No internet service can guarantee absolute security. Customers are also responsible for configuring their users, permissions, connected systems and Databricks workspaces appropriately.
We do not claim that Bridgly holds a security certification unless that certification has been independently completed and remains current.
Your rights
Depending on applicable law and the circumstances of the processing, you may have rights to:
- Request access to your personal information.
- Ask us to correct inaccurate information.
- Request deletion of information.
- Ask us to restrict certain processing.
- Receive certain information in a portable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where processing is based on consent.
- Complain to a data-protection regulator.
- Receive equal service and treatment when exercising applicable US privacy rights.
You have the right to object to processing based on legitimate interests. You also have an unconditional right to object to direct marketing.
To exercise a right, contact info@datago.uk. We may need to verify your identity. We normally respond within one month where the UK GDPR applies, although the law permits additional time in certain complex circumstances.
If your request concerns Customer Content controlled by your employer or another Bridgly customer, please direct the request to that organisation. We will assist the organisation where required.
UK residents may complain to the Information Commissioner's Office. We would appreciate the opportunity to address your concern first, but you are not required to contact us before approaching the ICO.
Sensitive information and children
Bridgly is a business service and is not directed to children. You must be at least 18 years old to create an account or submit business information directly to DataGo.
Customers should not provide special-category, highly sensitive or criminal-offence information unless its use is expressly authorised, necessary for the agreed service and covered by appropriate legal and contractual safeguards.
If we learn that a child has provided personal information directly to us without appropriate authorisation, we will take reasonable steps to delete it.
Marketing
We use demo, contact and early-access information to respond to the request made.
We will not add a person to a general marketing list merely because they submitted a form. Marketing messages require a separate choice unless another basis is expressly permitted by applicable law.
Every electronic marketing message will provide an unsubscribe method. Service, security and contractual communications are not marketing and may still be sent where necessary.
Changes to this policy
We may update this policy as Bridgly, its deployment models or applicable law changes.
The effective date at the top identifies the latest version. Where a change materially affects how we use personal information, we will provide reasonable notice through the service, by email or by another appropriate method.