Privacy Policy
A clear account of the information Branix handles, the people who can access it and the choices available to you.
Last updated: 18 September 2026
1. Who operates Branix
Branix is a Softobia product operated by the UAE entity identified below. In this policy, “we”, “us” and “our” refer to that entity.
SOFT UTOPIA DATA MANAGEMENT AND CYBER SECURITY SERVICES L.L.C
A limited liability company (Single Owner) registered in Dubai, United Arab Emirates. Licence number 1308074, issued by the Dubai Department of Economy and Tourism. Commercial registration number 2660728.
Registered address: Office A-08, Business Bay, Dubai, United Arab Emirates.
Contact: develop@softobia.com
Our organisation customer decides why its conversations are recorded, who may access them and how its workspace is used. We process workspace content to provide the service under that organisation’s instructions and agreement. We also handle account administration, service security and enquiries. The respective responsibilities depend on the processing activity and applicable law.
2. Information we handle
- Account information: your name, email address, organisation, team memberships, role, ownership and account status. Password sign-in stores a salted password hash, not your readable password. We maintain invitation, recovery and sign-in-link records, including delivery status; stored one-time credentials are hashed. Google sign-in uses basic identity information with the openid, email and profile permissions. It does not give Branix access to your Gmail messages or Google Drive files.
- Conversation content: audio or video submitted through uploads, configured browser capture or authorised connections; transcripts and their timestamps; recording titles, source, language, duration and associated metadata. Where enabled, analysis results are also workspace content.
- Service records: session and capture-token records, upload and processing status, access and audit events, and technical information needed to operate and troubleshoot the service.
- Enquiries: information you choose to send when contacting us, including your contact details and message.
3. Why we use information
We use information to authenticate authorised users, receive and process recordings, produce and display transcripts, support search, playback and exports, administer access, maintain security, investigate faults and respond to requests.
Processing must have an applicable lawful basis, such as valid consent, performing an agreement or complying with a legal obligation, as relevant to the activity and jurisdiction. Your organisation is responsible for establishing the appropriate basis for recording and submitting conversations, including required participant notices and permissions. Agreeing to a website policy does not replace those responsibilities.
We do not sell or rent your personal data. Roadmap features described on our homepage are not a statement that those features are processing your data today.
4. Who can access workspace content
Access is restricted by organisation, role, team and explicit sharing. Depending on your permissions, recordings may be visible to their owner, authorised colleagues, team leaders, managers and organisation administrators. Owners and organisation administrators can manage accounts and have content access within their organisation. Platform administrators manage organisation setup, suspension and operational usage metadata. Platform status alone does not grant access to another organisation’s recordings or transcripts.
Authorised operational personnel may need access to support and secure the service. Information may also be disclosed where required by law, to protect legal rights, or in connection with a lawful business transfer, subject to applicable safeguards.
5. Service providers and international processing
Branix uses Google for optional linked sign-in. When email authentication is enabled, the configured email provider delivers invitations, recovery messages and personal sign-in links. These messages contain an expiring access link and must be kept private. The current pilot uses DigitalOcean for application hosting and backup storage, and RunPod infrastructure for speech transcription. Recordings are made available to transcription processing through time-limited media access. Audio processing is therefore not confined to infrastructure owned by your organisation.
Personal data may be stored or processed outside the United Arab Emirates. Provider locations and the safeguards relevant to a particular organisation should be confirmed as part of onboarding and its data-processing arrangements. Contact us for information about the locations, providers and transfer arrangements that apply to your workspace.
International transfers must satisfy applicable data-protection requirements. This policy does not claim that all processing takes place in the UAE or that every provider offers identical data-handling terms.
6. Retention, deletion and legal holds
Your organisation’s administrator can configure recording-retention periods by recording type. Automatic expiry is not enabled merely by creating an account; where no retention policy is configured, recordings do not automatically expire.
Authorised deletion requests hide recordings from normal access while background processing removes recording media and related transcripts and results. Storage failures can delay completion. Legal holds can prevent deletion. Limited audit and deletion records may be retained for accountability and to prevent deleted connected recordings from being imported again.
Deleting an active recording does not guarantee immediate erasure from backups. Backup copies follow separate retention and recovery procedures and may remain until those copies expire. Contact your administrator or us to discuss a specific request, its status and any applicable retention obligation.
8. Protecting information
Branix uses access controls, authenticated service connections and restricted recording storage. Public application traffic uses HTTPS in the deployed service. Administrators should provision only authorised users and remove access when it is no longer needed.
No online service can guarantee absolute security. Report suspected unauthorised access or a privacy concern to develop@softobia.com. Do not include passwords or access tokens in your message.
9. Your choices and privacy requests
Depending on applicable law and the circumstances, you may request access, correction, a copy of your data, deletion, restriction of processing, or withdrawal of consent where consent is the basis for processing. Rights can be subject to legal exceptions and retention obligations. Withdrawal does not invalidate processing that was lawful before withdrawal.
For a workplace recording, contact your organisation’s administrator first, or email develop@softobia.com and identify the organisation and request. We may need proportionate information to verify your identity and authority. You may also raise a concern with the competent data-protection authority where applicable.
10. Updates and contact
We may update this policy as Branix or its processing arrangements change. The date above identifies the latest version. We will provide additional notice when required by applicable law.
Send questions to develop@softobia.com. Our legal entity particulars are listed in the “Who operates Branix” section above. This Branix policy describes this product; unrelated group-service descriptions do not expand Branix’s features or processing.
