This Privacy Policy explains how EnBra Group LLC (“EnBra Group,” “we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with our websites, platforms, tools, and services (collectively, the “Services”). EnBra Group LLC is currently the sole registered legal entity operating these Services; where this Policy refers to representatives in Singapore, Mexico, and the UK (Section 2), those are not separate legal entities or affiliates.
01 · Scope of This Policy
This Policy applies to:
- enbragroup.com — corporate site
- enbra.online — EnBra Group's Digital division and all tools hosted under it
- enbra.co — EnBra Group's Commercial/Industrial division and all tools hosted under it
- Any subdomain, mobile app, API, or client portal operated by EnBra Group LLC or its divisions
- All current systems listed in Schedule A below, and any future system, tool, platform, or Worker that EnBra Group develops, deploys, or acquires, whether or not it has yet been added to Schedule A
This Policy is designed to extend automatically to new EnBra Group systems as they are built. Schedule A is a living inventory, updated as new tools launch; the absence of a specific tool from Schedule A at any given time does not exclude it from this Policy's coverage — the general terms in Sections 2–13 apply to any EnBra Group system by default from the moment it goes live, and Schedule A is updated at our next revision cycle to reflect it specifically.
02 · Who We Are
EnBra Group LLC — registered offices:
- 1321 Upland Drive, Suite 15139, Houston, TX 77043, USA
- 1314 Rua Antônio de Albuquerque, Suite 504, Lourdes, Belo Horizonte, MG, 30.112-015, Brazil
Contact: info@enbragroup.com · +1 832 600 1408 · +55 31 98349 7009
EnBra Group LLC is also represented by local representatives/agents (not separate registered legal entities) in Singapore, Mexico, and the United Kingdom. These representatives act on behalf of EnBra Group LLC for regional business development and client relationships; EnBra Group LLC (through its registered US and Brazilian offices) remains the data controller/operator for all Services described in this Policy.
Because EnBra Group operates from Brazil and the United States, is represented in Singapore, Mexico, and the United Kingdom, and serves clients that may be located in the EU/EEA and elsewhere, this Policy is written to satisfy the disclosure requirements of:
- LGPD — Lei Geral de Proteção de Dados (Brazil)
- CCPA/CPRA — California Consumer Privacy Act, as amended
- GDPR — EU General Data Protection Regulation, to the extent it applies to specific clients or site visitors
- UK GDPR and the Data Protection Act 2018, given our UK representation
- LFPDPPP — Mexico's Federal Law on Protection of Personal Data Held by Private Parties and its regulations, given our Mexico representation
- PDPA — Singapore's Personal Data Protection Act, given our Singapore representation
03 · Information We Collect
We collect different categories of information depending on which EnBra Group system you use. The categories below are drawn directly from what our systems actually store, not a generic template.
3.1 Information you provide directly
| Category | Examples | Collected via |
|---|---|---|
| Contact/lead information | Name, email, company, message content | Contact forms, “email me this report” features, RFQ forms |
| Account credentials | Email address, password (hashed), security question and answer (hashed), access PIN/key | Account registration on client portals (EISE, EnBra Scan, EnBra Digital Passport, theTrade.Zone, EnBra FBS) |
| Business/partner data | Company name, partner tier, discount tier, contact details | Partner/reseller PIN registration (theTrade.Zone) |
| Domain/asset information | Domains you ask us to monitor or scan; product serial numbers, ship dates, warranty terms | Domain monitoring signup (EISE, EVM), asset registration (EnBra Digital Passport) |
| Payment information | Processed and stored by our payment processor (Stripe), not by EnBra Group directly | Checkout flows |
| Evidence/claims submitted for verification | Text of claims, quoted source text, page references | EIM evidence-verification tool (processed only — see 3.4) |
3.2 Information collected automatically
| Category | Examples |
|---|---|
| Usage data | API/query usage counts against your access key or quota |
| Technical/diagnostic data | HTTP response codes, response times, uptime/health-check results for monitored domains |
| Access logs | Timestamp, which access key or PIN was used, action taken (masked/partial credential only) |
| Session data | Session tokens (used only to keep you logged in; expire automatically — see Section 6) |
3.3 Information about third-party websites you ask us to analyze
Certain EnBra Group tools (EISE, EVM, EnBra Scan) are competitive intelligence, SEO, and security-scanning tools . When you submit a domain for analysis — including your own domain or a competitor's — our systems retrieve publicly available information about that domain (search rankings, on-page content, backlink data, technology/vendor detection, publicly exposed credentials, breach-database matches for email addresses found on the page, etc.). This is not information “about you” in the traditional sense unless the domain is your own — see Section 8 for how this is handled with respect to third parties.
3.4 Information we explicitly do NOT retain
Our evidence/claim-verification tool (EIM) is stateless — the claim text and evidence you submit is evaluated in memory to produce a verdict and is not written to any database or storage. Nothing submitted to this tool persists after the response is returned.
04 · How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Services you've signed up for
- Authenticate you (via PIN, access key, or session token) and enforce plan/quota limits
- Generate the reports, scores, and analyses our tools are designed to produce (SEO/AEO/ GEO/VEO scoring, security scan findings, brand visibility scores, asset warranty status, etc.)
- Send transactional notifications (status-change alerts, weekly digests, scan results, payment confirmations)
- Process payments and manage subscriptions via Stripe
- Maintain security logs and audit trails (PIN/key access logs, admin action logs)
- Improve and troubleshoot our Services
- Comply with legal obligations and enforce our Terms of Use
We do not sell personal information to third parties for their own marketing purposes.
05 · Legal Basis for Processing (GDPR / LGPD)
Where GDPR or LGPD applies, we rely on the following legal bases:
- Contract necessity — to provide a Service you've signed up for (e.g., account creation, domain monitoring you requested)
- Legitimate interest — security logging, fraud/abuse prevention, service improvement
- Consent — where required, e.g., marketing communications, non-essential cookies
- Legal obligation — tax, billing, and compliance recordkeeping
06 · Data Retention
Retention periods vary by system and data type. The table below reflects what is actually configured in our systems as of this Policy's last update (see Schedule A for the technical detail behind each figure).
| Data type | Retention period | System(s) |
|---|---|---|
| Security scan reports | 7 days | EnBra Scan |
| Free-scan lead records | 90 days | EnBra Scan |
| Emailed-report lead records | 90 days | EnBra Scan |
| Pending tier/subscription grants (pre-registration) | 90 days | EnBra Scan, EISE |
| Queued admin alerts (failed email delivery) | 30 days | EnBra Scan, EISE |
| Login session tokens | 30 days | EnBra Scan |
| Login session tokens | 8 hours | EnBra Digital Passport |
| Login session tokens | 24 hours | EISE |
| Saved intelligence reports | Rolling, most recent 10–250 per account depending on plan tier | EISE |
| Monitored-prompt configuration | Retained until removed by the account holder or account deletion | EISE |
| Monitoring run history | Up to 400 days | EISE |
| Deep-dive and usage counters | Reset monthly; transient markers expire within the month | EISE |
| Account records (email, hashed credentials, security question/answer, tier) | Retained until account deletion is requested | EISE |
| SEO/AEO/AI-visibility monitoring snapshots | 24 hours (refreshed) | EVM |
| Brand/reputation monitoring snapshots | 6 hours (refreshed) | EVM |
| Domain health-check results | 5 minutes (refreshed) | EVM |
| Historical monitoring trend data | Rolling, most recent 90 data points per domain/module | EVM |
| Scan history (per account) | Rolling, most recent 25 scans | EnBra Scan |
| Access/pricing/product logs | Rolling, most recent 500 entries | theTrade.Zone, EnBra FBS |
| Account records (user profile, tier, credits) | Retained until account deletion is requested | EnBra Scan, EnBra Digital Passport |
| Access keys / API keys | Retained until manually revoked — no automatic expiry | EISE, EnBra FBS |
| Product/pricing/partner records | Retained indefinitely as operational business records — no automatic expiry | theTrade.Zone |
| Contact-form lead records | Retained indefinitely — no automatic expiry | EnBra Scan |
| Monitor configuration (Pro/Agency domain lists, frequency settings) | Retained indefinitely — no automatic expiry | EnBra Scan |
| Per-domain monitor state (used to detect changes between scheduled scans) | Retained indefinitely — no automatic expiry | EnBra Scan |
| Aggregate benchmark statistics (score distribution across all scans run) | Retained indefinitely — no automatic expiry. Not tied to any individual account or domain; used to generate the “vs. benchmark” comparison shown in scan reports. | EnBra Scan |
| Evidence/claims submitted for verification | Not retained — processed in memory only | EIM |
Where a system has “no automatic expiry,” this reflects that the data functions as an ongoing operational or business record (e.g., a product catalog, a partner account) rather than a transient user-activity record. You may still request deletion or correction of personal information within such records under Section 9. The one exception is the aggregate benchmark statistics row above: that dataset is not personal information (it stores only score distributions, not identifying details), so Section 9 deletion rights don't apply to it — it's listed here for storage-retention transparency, not because it carries privacy risk.
07 · How We Share Information — Subprocessors and Third Parties
We share limited information with the following categories of third parties, only as necessary to provide the specific Service you're using. We do not permit these providers to use your data for their own independent purposes.
7.1 Infrastructure providers
- Cloudflare, Inc. — hosting, content delivery, KV/D1/R2 data storage, Worker execution, browser rendering, and transactional email delivery for all EnBra Group systems
7.2 AI and data-analysis providers
These providers receive query/domain/content data, not account credentials.
- Anthropic (Claude) — generates written analysis/summaries from data our tools have already gathered
- OpenAI (ChatGPT/GPT models) — same, plus AI-visibility/brand-mention testing
- Google (Gemini, Cloud Vision, Knowledge Graph, PageSpeed Insights, YouTube Data API) — visual/technical analysis of publicly available web pages, AI-visibility testing
- Perplexity AI — AI-citation visibility testing
- DataForSEO — search-ranking, keyword, backlink, and business-review data (sourced from public search engine results)
- OSV.dev (Open Source Vulnerabilities) — open-source library vulnerability lookups based on technology detected on a scanned page
- Have I Been Pwned — breach-database lookups for email addresses discovered on a scanned page (only when this feature is enabled and an API key is configured)
7.3 Payment processing
- Stripe, Inc. — payment processing and subscription billing. EnBra Group does not store full payment card details.
7.4 Email delivery
- Brevo and Resend — transactional and alert email delivery (EnBra Scan)
- Cloudflare Email Workers (backed by MailChannels) — transactional notifications (EnBra Digital Passport)
7.5 Legal disclosure
We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of EnBra Group, our users, or the public.
7.6 Business transfers
If EnBra Group is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy or a successor policy of which you will be notified.
08 · Information About Third-Party Domains (Not Our Users)
Several EnBra Group tools are built to analyze publicly available data about websites , which may belong to businesses or individuals who are not EnBra Group customers (e.g., a competitor domain entered into EISE or EVM by one of our clients). With respect to this data:
- We only retrieve information that is publicly accessible (public search results, public page content, public business listings) or specifically submitted to us by our own client for analysis
- We do not use this data to build profiles on individuals unaffiliated with our clients
- Any personal data incidentally surfaced (e.g., an email address found in publicly posted page content, checked against a breach database) is used solely to generate the requested security finding for our client and is subject to the retention limits in Section 6
- If you are the owner or operator of a domain analyzed through an EnBra Group tool and have concerns about this processing, contact us at info@enbragroup.com
09 · Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your information (“right to erasure” / “right to be forgotten”)
- Port your data to another provider in a structured format
- Object to or restrict certain processing
- Withdraw consent at any time where processing is based on consent
- Opt out of the sale or sharing of personal information (CCPA/CPRA) — note: EnBra Group does not sell personal information
- Non-discrimination for exercising any of the above rights
To exercise any of these rights, contact us at info@enbragroup.com. We will respond within the timeframe required by applicable law:
- Generally 30 days under LGPD (Brazil)
- 45 days under CCPA/CPRA (California)
- One month under GDPR and UK GDPR, extendable where permitted
- Within a reasonable timeframe under Mexico's LFPDPPP (typically 20 business days to respond, plus 15 additional business days to implement)
- Within 30 days under Singapore's PDPA (a reasonable timeframe if more time is genuinely needed, with notice to the requester)
We may need to verify your identity before fulfilling a request involving personal information tied to an account.
10 · International Data Transfers
EnBra Group operates from the United States and Brazil, is represented in Singapore, Mexico, and the United Kingdom, and several of our subprocessors (Anthropic, OpenAI, Google, Stripe, Cloudflare) process data in the United States and other countries. Where personal information is transferred internationally, we rely on:
- Standard Contractual Clauses (SCCs) with relevant subprocessors, where applicable
- The UK's International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs, for transfers involving UK-represented clients
- LGPD-compliant international transfer mechanisms for data originating in Brazil
- Contractual safeguards consistent with LFPDPPP for data originating from Mexico-represented clients
- PDPA-compliant transfer safeguards (comparable protection obligations) for data originating from Singapore-represented clients
11 · Security
We use industry-standard technical and organizational measures to protect information, including:
- Encrypted transport (HTTPS/TLS) across all Services
- Access-key and PIN-based authentication with configurable expiry
- Session tokens with automatic expiration (8 hours to 30 days, depending on system — see Section 6)
- Access logging and audit trails for administrative actions
- Credential redaction in our own security-scanning tools (EnBra Scan does not store full exposed secrets it detects on third-party pages — see Section 8)
No system is completely secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law (including LGPD's ANPD notification requirements and applicable US state breach-notification laws).
12 · Cookies and Tracking Technologies
Our corporate site (enbragroup.com) uses Google Tag Manager and may set cookies or similar technologies for analytics purposes.
We do not currently use cookies for cross-site advertising or ad retargeting. This section will be updated if that changes.
13 · Children's Privacy
EnBra Group's Services are business-to-business tools intended for use by adults acting in a professional capacity. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected such information, we will delete it.
14 · Changes to This Policy
We may update this Policy as our Services evolve, including as new EnBra Group systems are added (see Schedule A). We will update the “Last Updated” date above and, for material changes, provide notice through our Services or by email to registered account holders.
15 · Contact Us
EnBra Group LLC
Email: info@enbragroup.com
Phone (US): +1 832 600 1408
Phone (Brazil): +55 31 98349 7009
Schedule A — Covered Systems
This schedule lists EnBra Group systems currently covered by this Policy in detail. It is updated as new systems launch; Section 1 clarifies that new systems are covered under the general terms above even before they are added here.
| System | Division | What it does | Personal data touched | Retention highlights |
|---|---|---|---|---|
| EISE EnBra Intelligence Search Environment | Digital (enbra.online) | Competitive SEO/AEO/GEO/VEO intelligence search, scoring, deep-dive analysis, and prompt monitoring | Account email, password (hashed), security question and answer (hashed), query and usage counts, saved reports, monitored prompt configuration, session tokens, Stripe customer ID | 24-hour session tokens; saved reports rolling per plan tier; monitoring history up to 400 days; account records retained until deletion is requested |
| EVM EnBra Visibility Monitors | Digital (enbra.online) | Ongoing SEO, AEO, AI-visibility, brand, and uptime monitoring for client domains | Client access keys, monitored domain lists | 5 min–24h snapshot refresh; 90-point history |
| EnBra Scan™ | Digital (enbra.online) | Website security/exposure scanning, lead capture, subscription management | Account email, scan history, leads, session tokens, Stripe customer ID | 7–90 days depending on record type |
| EnBra FBS Pro | Commercial (enbra.co) | PIN-based access control for FBS partner tools | Partner PIN records, access logs | No automatic expiry; rolling 500-entry log |
| theTrade.Zone | Commercial (enbra.co) | Multi-brand industrial parts catalog, partner pricing/PIN portal | Partner contact/pricing data, RFQs | No automatic expiry (operational records) |
| EnBra Digital Passport™ | Commercial (enbra.co) | Asset identity, warranty, and compliance tracking for manufactured products | Serial numbers, customer names, manufacturer notification emails, session tokens | 8-hour session tokens; core records retained per business need |
| EIM Evidence Verification | Shared | Stateless claim/evidence verification | None retained | Not stored |
EnBra Group LLC · Last updated August 18, 2026 · info@enbragroup.com