Privacy Policy
Last updated: December 2025
1. Introduction
BrixAurea ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our real estate feasibility analysis platform.
2. Information We Collect
2.1 Personal Information
When you register on our platform, we may collect: name, email address, payment information, company data, and other information voluntarily provided.
2.2 Usage Data
We automatically collect information about how you interact with our platform, including IP address, browser type, pages visited, and access times.
3. How We Use Your Information
- Provide and maintain our platform
- Process transactions and manage your account
- Improve and personalize your experience
- Communicate updates, offers, and related information
- Ensure security and prevent fraud
4. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
4.1 Cookies and Sessions
We use secure cookies for authentication and session management. Your sessions expire after 24 hours of inactivity. All cookies are transmitted via HTTPS with HttpOnly and SameSite flags for maximum security.
4.2 Security Audit Logging
For your security and ISO 27001 compliance, we log security events including: login attempts (successful and failed), password changes, account creation/deletion, and permission changes. These logs include hashed IP addresses (we do not store raw IPs) and user agents.
4.3 Data Retention
We retain your personal data only as long as necessary:
- Security audit logs: 90 days (critical events: 365 days)
- Active account data: while your account is active
- Inactive account data: 90 days after last activity, then permanently deleted
- Financial records: as required by law (typically 7 years)
4.4 Abuse Protection
We implement rate limiting to protect against brute force attacks and abuse. This means there are limits on the number of login attempts and other sensitive actions within a time period. These limits help keep your account secure.
5. Your Rights
You have the right to access, correct, delete, or port your personal data. To exercise these rights, contact us at support@brixaurea.com.
6. Contact
If you have questions about this Privacy Policy, contact us:
