Privacy Policy

    Last updated: May 15, 2026

    Ibrave Technologies ("we", "us", "our") respects your privacy and takes the protection of your personal data seriously. This Privacy Policy explains, in plain language, what information we collect when you use https://ibrave.co, why we collect it, how we use it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and similar laws including the UK GDPR.

    1. Data controller

    The data controller is Ibrave Technologies, registered at Zewdu Gessesse Building, Qelebet Menged, Bole Sub-City W-03 K-03 H-2414, Addis Ababa, Ethiopia. You can reach us about any privacy matter, including to exercise your rights, at hello@ibrave.co.

    2. Information we collect

    2.1 Information you give us

    • Contact form submissions: name, email, optional company and phone, the service you are interested in, and the contents of your message. We deliver these submissions to our team by email through a transactional email provider.

    2.2 Information collected automatically

    • Technical data: IP address, browser type, device type, referring page, and pages viewed. This information is processed transiently to keep the site available, secure, and performant. It is not used to build behavioural profiles.
    • Cookies and similar technologies: see section 5 below. Non-essential cookies are only set after you opt in.

    3. Why we use your information (purposes & legal bases)

    Under the GDPR, every use of personal data needs a legal basis. The bases we rely on are:

    • Performance of a contract (Art. 6(1)(b)): when you are a client and we need your data to deliver work.
    • Legitimate interests (Art. 6(1)(f)): to respond to enquiries you send us, to operate, maintain, and secure the site, and to prevent fraud or abuse. We balance these interests against your rights and freedoms; you can object at any time (see section 7).
    • Consent (Art. 6(1)(a)): for analytics and marketing cookies. Consent is freely given, specific, informed, and can be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
    • Legal obligation (Art. 6(1)(c)): when we have to retain or disclose information to comply with the law.

    4. Sharing your information

    We do not sell your personal information and we do not share it for cross-context behavioural advertising. We share it only with:

    • Service providers (processors) who help us run the site, such as our cloud hosting provider, our transactional email provider, and (if you opt in) analytics providers. Each processor is bound by a written contract that requires them to process your data only on our documented instructions and to keep it confidential and secure. For client engagements involving personal data, we offer an Article 28 GDPR Data Processing Agreement on request.
    • Authorities, when we are legally required to disclose information (for example to comply with a valid court order).
    • Successors, in the event of a merger, acquisition, or sale of assets, in which case we will give you notice before your information becomes subject to a different policy.

    5. Cookies

    We classify cookies into three categories:

    • Essential cookies are required for the site to function (for example, remembering your consent choice). They cannot be turned off. No consent is required to set them under the ePrivacy Directive.
    • Analytics cookies help us understand how the site is used so we can improve it. They are not set unless you explicitly opt in.
    • Marketing cookies are used to measure campaigns. They are not set unless you explicitly opt in.

    You can change or withdraw your consent at any time by clicking or via the link of the same name in the footer.

    6. International transfers

    We operate from a single office in Addis Ababa, Ethiopia, and we use cloud providers that may store and process data outside the European Economic Area (EEA) or the United Kingdom. When personal data is transferred outside the EEA/UK to a country that has not received an adequacy decision, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with additional technical and organisational measures where required. A copy of the relevant safeguards is available on request from hello@ibrave.co.

    7. Your rights

    If you are in the European Economic Area, the United Kingdom, Switzerland, or a country with similar laws, you have the right to:

    • access the personal data we hold about you;
    • have inaccurate data corrected;
    • have your data erased ("the right to be forgotten");
    • restrict or object to our processing;
    • receive your data in a portable format;
    • withdraw consent at any time, where we rely on consent (this does not affect the lawfulness of prior processing); and
    • lodge a complaint with your local data protection authority. If you are in the EU you can find your authority here.

    To exercise any of these rights, email hello@ibrave.co. We will respond within one month, as required by the GDPR (this period may be extended by up to two further months for complex requests, in which case we will inform you).

    8. Data retention

    We keep personal data only for as long as we need it for the purpose it was collected:

    • Contact form submissions: typically up to 24 months from the last interaction, then deleted.
    • Technical logs: retained for a short period (typically 30 to 90 days) for security and debugging.
    • Consent records: retained while your consent choice remains active, plus a reasonable period afterwards as evidence of compliance.

    9. Security

    We use industry-standard technical and organisational measures, including encrypted transport (HTTPS/TLS), access controls, principle of least privilege, audit logging, and managed cloud infrastructure, to protect your information. No system is perfectly secure; if we ever become aware of a personal data breach affecting your rights and freedoms, we will notify the relevant supervisory authority within 72 hours, and notify you without undue delay where required by law.

    10. Automated decision-making

    We do not use your personal data to make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects.

    11. Children

    The site is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

    12. Changes to this policy

    We may update this policy from time to time. Material changes will be highlighted on this page with an updated "Last updated" date. We will not weaken your rights without your explicit consent.

    13. Contact

    Questions about this policy, requests to exercise your rights, or other privacy matters? Email us at hello@ibrave.co or write to Zewdu Gessesse Building, Qelebet Menged, Bole Sub-City W-03 K-03 H-2414, Addis Ababa, Ethiopia.