Privacy notice
Last updated 3 October 2026
Brillrec is run by Brillrec Ltd, a company registered in Nigeria (RC 9904969), 10, Dr Olumide Close, Ajah, Lagos, Nigeria ("we"). This notice explains what personal data the service holds, why, and your rights under the Nigeria Data Protection Act 2023 (NDPA).
Who is responsible
Your organisation decides what to reconcile and uploads its own records, so for the financial records and the people named in them your organisation is the data controller and we are its data processor: we only use them to provide the service to your organisation. For the accounts of the people who sign in (name, email address, sign-in history) we are the controller.
What we hold
- Your account: name, email address, role, a salted hash of your password (never the password itself), your two-factor secret (encrypted), and records of sign-ins (time, IP address, browser).
- Your organisation's records: the files you upload (ledgers, bank statements, processor reports), the reconciliations made from them, explanations, notes, approvals and the audit trail. These contain names of customers, suppliers and staff and the amounts paid.
- Connections: if an admin connects an accounting system or bank, the access tokens it issues (encrypted) and the transactions read for the period you import. We never see or store the password for those systems.
- Technical logs: which page or action was requested, when, the result and the person and organisation numbers - not file contents. Kept for 30 days.
Why, and on what basis
To provide the reconciliation service under our agreement with your organisation (contract), to keep it secure and investigate misuse (legitimate interests), and to meet legal obligations. We don't sell personal data, don't use it for advertising, and don't use your organisation's records to train AI models. Brillrec's own matching and suggestions run inside the service itself.
AI review and our AI provider
AI review is on for new organisations, in masked mode: accepting these terms when your organisation is created is its agreement to it. Organisations created before this change keep AI review off until an admin switches it on. An admin can switch it off, or change what it's shown, at any time (Settings → AI review); full text is only sent once an admin records the organisation's agreement to that. When it's on, the open items of a reconciliation - by default masked: long numbers (account, BVN, phone and card numbers), email addresses and dates in the text replaced with placeholders; names, the rest of the narration and amounts included - are sent to our AI provider, which suggests matches. A person or the bank account's matching policy decides what's matched. With the same setting and masking, a person can also ask the AI to explain one open item (that item and the facts Brillrec found about it, with dates given as days apart), to draft the commentary on a reconciliation (its figures, and the largest open items), or to read the column headings and first rows of a file they uploaded.
Our AI provider is an established supplier of AI models, engaged by us under a written contract. It processes the data only to answer our requests, and only under terms that do not allow it to use your data to train its models. Its servers may be outside Nigeria (see transfers below). If we change the provider or model, admins of organisations using AI review are told by email and in the app, and can switch AI review off at any time. A new model is only used once it has passed our accuracy check. Admins can ask us which provider is in use.
Who else handles it
- Our hosting provider, where the service and its database run (on servers chosen by the operator).
- Our email provider, to send sign-in, invitation and notification emails (your name and email address only).
- Our payment processor, when an admin pays for a plan online: the admin's name, email address and payment details are entered on the processor's own page, and we never see or store card details.
- Backup storage, holding encrypted copies of the database and files.
- Accounting systems, banks or SFTP servers your admin connects - data flows from them to us, at your organisation's request. Their access details are kept encrypted.
- Our AI provider, for organisations using AI review - on by default for new organisations, masked (see above).
If any of these are outside Nigeria, we rely on the safeguards the NDPA allows for transfers (adequacy, contractual protections or your organisation's instructions).
How long we keep it
- Uploaded files that are not used for a reconciliation: deleted after 24 hours.
- Reconciliations: kept while your organisation uses the service, because they are your accounting records. Finished ones (signed off, archived or failed) are deleted with their files once their period ended longer ago than your organisation's retention period - 7 years unless an admin sets another (1 to 30 years, Settings > Organisation).
- The audit trail: kept while your organisation uses the service, including a record that deleted reconciliations existed.
- Free trials: if no plan is chosen, the organisation and everything in it are permanently deleted 30 days after the trial ends (people who belong to no other organisation have their accounts deleted too).
- When an admin deletes the organisation (Settings > Organisation), everything is permanently deleted after a 30-day grace period in which they can change their mind; people who belong to no other organisation have their accounts deleted too. Encrypted backups roll off within 90 days after that.
Security
Encrypted connections (HTTPS), two-factor sign-in (which your admins can require for everyone), encrypted secrets and backups, role-based access (only admins see the organisation's audit log), a tamper-evident audit trail, and daily backups.
Your rights
You can ask for a copy of your personal data, to correct it, to delete it, to restrict or object to its use, and to move it to another service. Admins can download all of the organisation's data at any time (Settings > Organisation > Download all data). For records your organisation controls, we'll pass your request to your organisation. Contact info@brillrec.com. If you're not satisfied you can complain to the Nigeria Data Protection Commission (ndpc.gov.ng).
Breaches
If a breach puts personal data at risk we will tell affected organisations without undue delay and the Nigeria Data Protection Commission within 72 hours where the law requires.
Privacy notice · Terms of service
Brillrec Ltd · Registered in Nigeria, RC 9904969 · 10, Dr Olumide Close, Ajah, Lagos, Nigeria · info@brillrec.com