TheBrain Lab Legal documents

TheBrain Lab · Legal

Privacy Policy

How TheBrain Lab collects, uses, stores, and protects personal data when you use Our Site.

On this page

1. Controller 2. Scope 3. Data We Collect 4. Purposes & Legal Bases 5. Sensitive Data 6. Cookies & Tracking 7. Sharing 8. International Transfers 9. Retention 10. Security 11. Your Rights 12. Marketing 13–15. Other Information 16. Complaints 17. Changes 18. Contact

Effective date and last updated: 22 July 2026

This Privacy Policy explains how TheBrain Lab collects and uses personal data when you visit thebrainlab.co (“Our Site”), contact Us, purchase or participate in a Programme, attend a live session, or otherwise interact with Us.

“Personal data” means information relating to an identified or identifiable individual. We process personal data in accordance with applicable privacy law, including the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where they apply, the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, and EU GDPR.

1. Who Is Responsible for Your Data?

TheBrainLab (FZC), trading as TheBrain Lab, is the controller responsible for the personal data described in this Policy.

License number: 10108
Legal status: Free Zone Company

Registered address:
Block B – B50-193
Sharjah Research Technology and Innovation Park Free Zone
United Arab Emirates

Privacy email: team@thebrainlab.co

2. Scope of This Policy

This Policy covers Our Site, including the Programme page, sales and support communications, Programme delivery, Accounts, live sessions, and communities that We operate. A third-party service you choose to use may also process data under its own privacy notice.

3. Personal Data We Collect and Its Sources

Depending on how you interact with Us, We may collect:

  • Identity and contact data: name, email address, telephone number, country, postal address, and account identifiers.
  • Purchase data: Programme, tier, price, currency, transaction status, invoice details, refunds, and payment-provider references. Stripe processes complete card details; We normally receive only limited card information such as brand and last four digits.
  • Programme data: enrolment, progress, attendance, assessment or completion status, certificates, submitted exercises, and support history.
  • Professional data: role, organisation, qualifications, experience, goals, and information you choose to provide in an application or discovery call.
  • Communications and User Content: emails, messages, feedback, testimonials, survey answers, and content shared in sessions or communities.
  • Technical and usage data: IP address, device and browser information, referral URL, pages viewed, approximate location, timestamps, cookie identifiers, and interactions with Our Site and advertising.
  • Marketing data: subscriptions, consent records, campaign engagement, advertising audiences, and communication preferences.

We collect data directly from you, automatically from your device, and from providers that help Us operate Our Site, process payments, deliver the Programme, communicate, and measure advertising. If you provide another person’s data, you must have a lawful basis to do so and tell them about this Policy.

4. How We Use Personal Data and Our Legal Bases

The legal basis depends on the context and the law that applies. Under UK or EU data protection law, We generally rely on the following bases:

Purpose Data Legal basis
Respond to enquiries, applications, and discovery-call requests Identity, contact, professional, communications Steps before a contract; legitimate interests in responding and developing Our services
Process orders, payments, refunds, invoices, and instalments Identity, contact, purchase Contract; legal obligations relating to tax, accounting, and fraud prevention
Create Accounts and deliver Programme Content, live sessions, support, and credentials Identity, contact, purchase, Programme, communications Contract
Protect Accounts, prevent fraud and misuse, enforce terms, and establish legal claims Identity, purchase, technical, usage, communications Legal obligations; legitimate interests in security and protecting Our rights and users
Operate, troubleshoot, and improve Our Site and Programme Technical, usage, Programme, feedback Legitimate interests in reliable and effective services; consent where required for non-essential cookies
Send service messages and material updates Identity, contact, purchase, Programme Contract; legal obligations; legitimate interests in administering the service
Send marketing and measure campaigns, including through Meta Pixel Contact, marketing, technical, usage Consent where required; otherwise legitimate interests, subject to your right to object
Comply with law, regulatory requests, and court orders Relevant data from the categories above Legal obligation; public interest; legitimate interests in legal compliance

Where We rely on legitimate interests, We consider the necessity and impact of the processing and do not rely on that basis where your rights and interests override Ours. Where consent is the basis, you may withdraw it at any time without affecting earlier lawful processing.

5. Sensitive and Special-Category Data

The Programme is educational, and We do not require medical records, diagnoses, therapy notes, or other sensitive data. Please do not submit such information unless We specifically request it and explain why it is needed. If you voluntarily disclose health or similarly sensitive information in an enquiry, exercise, or live session, We will process it only where a lawful condition applies, such as your explicit consent or the establishment, exercise, or defence of legal claims, and will limit access as reasonably possible.

6. Cookies and Similar Technologies

Our Site uses cookies, pixels, local storage, and similar technologies. Strictly necessary technologies support security, network delivery, and functions you request. Non-essential analytics and advertising technologies are used only with consent where applicable law requires it.

Our current Site infrastructure may include:

  • Tilda: Site hosting, content delivery, forms, and technical site functions.
  • Meta Pixel: advertising measurement, audience creation, and campaign attribution.
  • Google Fonts: delivery of web fonts, which may involve technical request data such as an IP address.
  • Stripe: secure hosted checkout, fraud prevention, and payment processing.

Where consent is required, Meta Pixel and other non-essential technologies must not activate before you choose to accept them. You can reject non-essential technologies as easily as you accept them and can later change your choice through Our Site’s cookie controls. The cookie panel should identify each active technology, provider, purpose, and duration.

Browser controls can also block or delete cookies, but doing so may affect Site functions. A privacy policy alone does not constitute consent to non-essential cookies.

7. Who We Share Personal Data With

Where necessary for the purposes above, We may share data with:

  • Tilda Publishing and related hosting and content-delivery providers;
  • Stripe and banks or payment partners involved in processing transactions;
  • Meta Platforms where advertising technologies are enabled with the required consent;
  • WhatsApp/Meta if you choose to contact Us through a WhatsApp link;
  • course, credential, video-conferencing, email, CRM, file-storage, analytics, and customer-support providers used to deliver the Programme;
  • professional advisers, insurers, auditors, and prospective buyers or investors subject to appropriate confidentiality; and
  • courts, regulators, law enforcement, tax authorities, or other parties where disclosure is legally required or necessary to protect rights and safety.

We do not sell personal data for money. Some advertising disclosures may be treated as a “sale”, “sharing”, or targeted advertising under certain laws; where those laws apply, We will provide the required notice and opt-out method.

8. International Data Transfers

We are established in the United Arab Emirates and use providers that may process data in the UAE, United Kingdom, European Economic Area, United States, and other countries. Those countries may have different data-protection laws from the country where you live.

Where UK or EU restricted-transfer rules apply, We use a permitted transfer mechanism, such as an adequacy decision, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, and any required transfer-risk assessment and supplementary measures. You may contact Us for information about the relevant safeguard, subject to lawful redactions.

9. How Long We Keep Personal Data

We keep data only for as long as reasonably necessary, using the following criteria:

  • Orders, invoices, and contract records: for the applicable tax, accounting, chargeback, and legal-limitation periods.
  • Account and Programme records: for the access period and afterwards for support, credential verification, dispute handling, and legal obligations.
  • Enquiries and support: until resolved and for a reasonable period afterwards to maintain context and manage complaints.
  • Marketing records: until you unsubscribe or object, plus a minimal suppression record so We can respect that choice.
  • Security logs: for a period proportionate to security, fraud-prevention, and incident-investigation needs.
  • Cookie and advertising identifiers: for the duration disclosed in the Site’s cookie controls or until consent is withdrawn, where applicable.

We may retain data longer where required by law, a regulator, litigation, or a legal hold. We may retain anonymous information that no longer identifies you.

10. Security

We use proportionate organisational and technical measures designed to protect personal data, including access controls, reputable service providers, secure payment processing, and staff or contractor confidentiality obligations where appropriate. No internet transmission or storage system is completely secure, so absolute security cannot be guaranteed.

If a personal-data breach occurs, We will investigate, mitigate harm, and notify affected individuals and regulators where applicable law requires it.

11. Your Privacy Rights

Depending on where you live and the law that applies, you may have rights to:

  • receive clear information about Our processing;
  • access your personal data and obtain a copy;
  • correct inaccurate or incomplete data;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • receive certain data in a portable, machine-readable format;
  • withdraw consent at any time where processing is based on consent;
  • ask for human review of a qualifying solely automated decision; and
  • complain to a competent data-protection authority.

To exercise a right, email team@thebrainlab.co. We may request information needed to verify your identity and authority. We will respond within the period required by applicable law. Rights can be subject to lawful exceptions, and We will explain any refusal or limitation.

12. Direct Marketing

We send electronic marketing only where We have the permission or other lawful basis required in the recipient’s country. You can unsubscribe using the link in a marketing email or by contacting Us. Service messages about an order, Account, security, schedule, or active Programme are not marketing and may continue while needed to perform the contract.

We do not use data supplied by a Consumer for unrelated promotional marketing where UAE law prohibits that use. Withdrawing marketing consent does not affect processing required to provide a Programme or comply with law.

13. When Providing Data Is Required

You can browse parts of Our Site without directly identifying yourself. However, identity, contact, and purchase data are contractually required to process an order and deliver a Programme. If you do not provide required data, We may be unable to create an Account, take payment, provide access, issue a credential, or respond to a request.

14. Children

Our Site and Programme are intended for adults aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has provided data to Us, contact Us so We can investigate and take appropriate action.

15. Automated Decision-Making

We do not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on you. We may use routine automation for fraud signals, email routing, and advertising measurement, with human involvement where a decision could materially affect Programme access or a transaction.

16. Questions and Complaints

Please contact Us first so We can try to resolve a privacy concern. If UK data-protection law applies, you may complain to the UK Information Commissioner’s Office at ico.org.uk. If EU law applies, you may complain to the supervisory authority in your habitual residence, place of work, or place of the alleged infringement. UAE residents may use the complaint channels of the competent UAE data-protection or consumer-protection authority.

17. Changes to This Privacy Policy

We review this Policy and may update it when Our practices, providers, or legal obligations change. We will post the revised version with a new effective date and will provide a more prominent notice before a material change where required.

18. Contact Us

Email: team@thebrainlab.co

Controller: TheBrainLab (FZC), trading as TheBrain Lab

Registered address:
Block B – B50-193
Sharjah Research Technology and Innovation Park Free Zone
United Arab Emirates

TheBrain Lab

© 2026 TheBrain Lab. All rights reserved.

Programme Terms of Use Privacy Policy Contact