Skip to content
Coming soonA new version of Brolly is on its way. Register for the early previewA new version of Brolly is coming soon
Brolly
Core product
ArchiveCapture posts, comments, edits and deletions. Search & exportFind, review and produce records. Versions & editsChanges, deletions and version history.
Add-ons
InsightsUnderstand themes, sentiment and emerging issues. ProtectApply moderation rules while retaining evidence.
Integrations
HootsuiteYour archive inside Hootsuite. Content ManagerSend records into your EDRMS.
Platform
Supported platformsFacebook, Instagram, Threads, X, YouTube, LinkedIn, TikTok. Security & complianceISO 27001, encryption and audit trails. Explore the Brolly platform →
Govern
Official channel governanceKeep channel coverage, records, access and activity evidence in one place. Moderation governanceApply policy consistently while keeping the original content and decision.
Understand
Insights & reportingExplainable reporting, linked back to the record.
Preserve and respond
Social media recordkeepingSearchable records with the context and metadata your team needs. Public records requestsFind, review and export responsive records.
Why Brolly
One archive, shared across teams

See how communications, records, legal and governance teams work from the same evidence.

Explore the platform
By role
Communications teamsGovern official channels and report with confidence. Social & community teamsEngage consistently and preserve the conversation. Records & information managersCapture, retain, search and export official records.
 
Public records teamsFind, review and produce responsive records. Legal, risk & compliance teamsReview complaints, decisions and supporting evidence. IT & security teamsManage access, integrations and security controls.
By organization
GovernmentLocal, state and federal agencies. EducationSchools, systems and higher education. HealthPublic health services and organizations. UtilitiesEssential services and public infrastructure. Financial servicesRegulated communications and complaints.
Resources
Case studiesPublished customer stories, in their own words. BlogRecords, policy and platform updates. Guides & templatesUseful resources for your team. FAQsStraight answers about Brolly.
Featured
US legislation map

Records and information-access laws for all 50 states.

Find your state
Pricing
US Login Get a demo

Brolly Privacy Notice — United States

Published: August 27, 2026 · Updated: September 2, 2026 (expanded Meta Platform Data disclosures)

Effective date: September 1, 2026

Brolly Australasia Pty Ltd (ABN 66 633 439 577) (“Brolly,” “we,” “us,” or “our”) respects the privacy of the people whose personal information we handle.

This Notice explains how we collect, use, disclose and protect personal information in connection with our websites, sales and marketing activities, support services and the Brolly platform. It also explains the choices and rights that may be available to United States residents.

The short version

  • We collect information needed to provide, secure, support and improve Brolly and to operate our business.
  • Customer-controlled social media records are processed on the customer’s behalf. We do not sell Customer Data or use it for third-party advertising.
  • We use necessary cookies and, subject to applicable choices, analytics and attribution technologies.
  • A person may have rights over information Brolly controls. Requests concerning a government or other customer’s archive generally need to be directed to that customer.
  • We retain information only for documented business, contractual and legal purposes and apply reasonable safeguards while it is retained.

1. Scope and our role

This Notice applies to personal information handled through:

  • brolly.io and Brolly’s United States website pages;
  • the Brolly applications and services, including Archive, Monitoring, Insights, Protect and supported integrations;
  • Brolly’s knowledge base, support and customer-success channels;
  • trials, demonstrations, Orders, billing and account administration;
  • events, downloads, newsletters, surveys and other sales or marketing activities; and
  • dealings with suppliers, partners, advisors, job applicants and contractors.

Brolly handles information in two different capacities:

  1. For Brolly’s own business activities, including website analytics, sales, user accounts, security, support and billing, Brolly determines why and how personal information is processed and may be a “business” or “controller” under applicable law.
  2. For Customer Data, Brolly generally acts as a service provider or processor for the customer. The customer decides which accounts to connect, who may access its archive, how long records are kept and how records are used or disclosed. The customer’s privacy notices and legal obligations also apply.

Customer Data is controlled by the customer and processed by Brolly on the customer’s behalf. This does not change any rights held by social media users, content creators or other third parties.

This Notice does not govern a customer’s independent handling of information, third-party social media platforms, or websites and services Brolly does not control.

2. Personal information we collect

The information we collect depends on how a person interacts with Brolly.

2.1 Website visitors, prospects and business contacts

We may collect:

  • name, work email address, telephone number, organization, role and general location;
  • information submitted through forms, correspondence, calls, demonstrations, events, surveys or resource downloads;
  • marketing preferences and records of communications;
  • referral source, campaign and interaction information; and
  • professional information available from a person’s organization, authorized representative, business partner or a public source.

2.2 Account users

We may collect:

  • name, work email address, organization, role and account permissions;
  • account, authentication and security information;
  • connected-service authorizations and configuration choices;
  • support requests, product feedback and communications;
  • service activity, audit and diagnostic logs; and
  • information required to administer a trial, subscription or Order.

2.3 Billing and commercial information

We may collect contact, invoicing, transaction, tax and subscription information. Payment-card details are handled by Brolly’s payment providers; Brolly does not need to retain a complete payment-card number to administer an account.

2.4 Customer Data from connected services

When an authorized customer connects a supported social media account or another service, Brolly may retrieve and preserve information made available through the relevant official API or integration. Depending on the service, authorization and product configuration, this may include:

  • account and profile information;
  • posts, comments, replies, reactions and conversation context;
  • edits, deletions and version history;
  • images, video, audio, attachments and linked content;
  • usernames, display names and other public or authorized identifiers;
  • timestamps, post and account IDs, URLs, visibility status and other metadata; and
  • private or direct messages where the connected service and customer’s authorization permit capture.

Customer Data may contain personal information about people who do not have a Brolly account. It may also contain sensitive personal information if a social media user or customer includes that information in content. Brolly does not require customers to provide sensitive information unless it is necessary for their authorized use of the service and lawful for them to process. Brolly processes it to provide the customer’s service under the customer’s instructions, subject to the applicable agreement and law.

2.5 Usage, device and analytics information

We may collect:

  • IP address, browser, device, operating system and approximate location derived from IP;
  • pages and features viewed, website and knowledge-base searches, clicks, navigation paths, referrer and campaign information;
  • login, authentication, performance, error, security and audit events;
  • cookie and similar-technology identifiers; and
  • interaction information such as scrolling, clicks and session-replay data where that technology is enabled and permitted.

Searches made inside the Brolly platform are not logged; export actions are.

2.6 Other business relationships

For suppliers, partners, advisors, contractors and job applicants, we may collect business contact details, qualifications, correspondence, payment information, checks and other information reasonably required for the relationship.

3. Sources of personal information

We collect personal information:

  • directly from you when you contact us, complete a form, create an account, start a trial, enter an Order, request support or otherwise interact with Brolly;
  • from your organization, account administrator or authorized representative;
  • automatically through your use of Brolly websites, applications and support properties;
  • from connected services that a customer authorizes Brolly to access;
  • from service providers, resellers, partners and referral sources;
  • from public professional and organizational sources; and
  • where authorized or required by law.

If you provide personal information about another person, you must be authorized to do so and, where required, make them aware of this Notice.

4. How we use personal information

We may use personal information to:

  • provide, configure, operate and maintain the websites and services;
  • create and administer accounts, trials, subscriptions and Orders;
  • capture, preserve, index, search, analyze and export Customer Data on a customer’s instructions;
  • authenticate users and manage permissions;
  • provide support, training and customer-success services;
  • communicate about services, incidents, changes, renewals and billing;
  • process payments, invoices and tax records;
  • monitor performance, diagnose faults and improve usability and functionality;
  • maintain security, prevent misuse, investigate suspected fraud and enforce agreements;
  • conduct analytics, attribution, research and business planning;
  • provide requested resources and relevant marketing communications, subject to available choices;
  • manage suppliers, partners, advisors, contractors and recruitment;
  • establish, exercise or defend legal claims;
  • comply with legal, regulatory, records-management and law-enforcement obligations; and
  • support a merger, financing, reorganization or sale of all or part of the business, subject to appropriate protections.

We may use information for another purpose with consent or where authorized or required by law.

5. Cookies, analytics and cross-property identifiers

Brolly uses cookies and similar technologies for:

  • necessary functions, such as authentication, security, load balancing and remembering privacy choices;
  • preferences, such as language, region and display settings;
  • analytics, such as understanding visits, feature use, errors and journeys; and
  • attribution and advertising, such as measuring campaigns and, where enabled, limiting or assessing advertising.

Depending on the Brolly property and a visitor’s choices, providers may include Google Tag Manager/Analytics, Google Ads conversion linking, Clicky, HubSpot, Microsoft Clarity, Meta, LinkedIn and Brolly’s self-hosted Umami analytics. The Cookie Preferences tool is intended to provide the current list and control non-essential technologies.

Brolly also uses Umami, a self-hosted, first-party analytics tool operated on Brolly’s own infrastructure, to measure visits and journeys across Brolly-controlled properties. Umami does not use cookies or similar identifiers stored on a device and is not used for advertising; it receives technical information such as IP address, pages viewed and referrers. Because it stores nothing on a device, it operates independently of the Cookie Preferences tool.

Brolly also stores first-party campaign-attribution information (such as referral source, campaign identifiers and the landing page) in the browser when a person arrives from a link carrying that information. It stays in the browser and is used by Brolly only if the person later submits a form.

Where a signed-in user interacts with more than one Brolly-controlled website, support property or service, Brolly may use an account-level identifier, such as a user_id, to associate usage information across those properties. This helps us understand a journey across the website, knowledge base and application and to operate, secure, support, analyze and improve Brolly.

Brolly does not use an email address as the analytics user_id. The identifier is pseudonymous to the analytics provider, but it remains personal information in Brolly’s hands because Brolly can associate it with an account. We do not use that identifier to sell personal information or enable third parties to market their own products to an individual.

You can use Cookie Preferences to reject or withdraw non-essential cookies. You may also use browser or device controls. If Brolly determines that an applicable state law treats a disclosure for advertising as a sale, sharing or targeted advertising, Brolly will provide the required opt-out mechanism and honor applicable universal opt-out signals, such as Global Privacy Control, before or at the time that treatment applies.

Brolly does not sell Customer Data or use Customer Data for third-party advertising. Advertising and attribution technologies on the public website are not permitted to receive the contents of Customer Data.

6. Connected platforms and API data

Brolly accesses a connected service only after an authorized customer completes that service’s authentication and permission process. Brolly uses the resulting access to retrieve supported content and metadata for the services selected by the customer.

This may include content made available by Meta services, Google/YouTube, X, LinkedIn and other supported providers. Each provider operates under its own terms and privacy policy.

Meta Platform Data

Brolly may use Meta APIs to retrieve supported content and metadata from an authorized Facebook Page, Instagram business account or other connected Meta property. Where authorized and supported, this can include Page content, comments, replies, reactions, media, metadata and Page inbox messages.

To authenticate and operate the integration, Brolly may also process Meta app-scoped user and account identifiers, connected Page or Instagram account identifiers, stored access or refresh tokens, the permissions granted, and connection metadata and authorization records. Brolly uses this information only to provide, secure and support the customer-authorized connection. Stored credentials are protected and access to them is restricted.

Meta Platform Data is used only to provide the customer’s selected Brolly services. Brolly does not sell, license or transfer Meta Platform Data to data brokers, advertising networks, advertising exchanges or other advertising or monetization services. It is not used for third-party advertising or advertising-profile creation.

Brolly does not use Meta Platform Data to track or profile individuals across customers, unrelated accounts, services or locations, or to provide individual-surveillance capabilities. Any organization, classification, sentiment analysis or customer-configured alerting is limited to authorized customer content and is provided for organizational recordkeeping, community governance and service administration.

If a Meta authorization is revoked or a connection is deleted, Brolly ceases using the connection and deletes stored access credentials when they are no longer required, subject to applicable security, legal and contractual requirements. See How to request data deletion.

7. Customer Data and individual requests

Where Brolly processes Customer Data for a customer, that customer is normally responsible for responding to people whose information appears in the archive. If you seek access, correction or deletion of a social media record held for a government agency or another Brolly customer, contact that customer first.

If Brolly receives the request directly, we may refer it to the relevant customer and assist that customer as required by the applicable agreement and law. Brolly will not delete or alter a public record or other Customer Data contrary to the customer’s lawful instructions, a retention schedule, legal hold or other binding obligation.

Requests concerning your own Brolly account, website interactions or direct dealings with Brolly can be sent under section 14.

8. Automated analysis

Depending on the products and configuration selected by a customer, Brolly may use automated tools to organize Customer Data, support search, identify versions, classify content, generate themes or sentiment, and surface customer-configured signals or alerts.

These outputs assist authorized customer users. They may be incomplete or incorrect and should be reviewed in context. Brolly does not use these features by themselves to make decisions that produce legal or similarly significant effects for an individual. Customers remain responsible for decisions they make using the outputs.

Where an applicable state law provides a right to opt out of qualifying profiling or automated decision-making, a person may submit a request using the methods in section 14. This does not require Brolly to alter a government or other customer’s official records contrary to law.

9. When we disclose personal information

We may disclose personal information to:

  • the customer and its authorized users where information relates to that customer’s service;
  • hosting, infrastructure, security, support and software providers;
  • payment, invoicing and financial-service providers;
  • customer relationship, communications, analytics, attribution and advertising-service providers;
  • connected platforms where transmission is necessary to operate an authorized integration;
  • resellers, implementation partners and professional advisors subject to appropriate obligations;
  • regulators, courts, law-enforcement bodies and other authorities where disclosure is authorized or required; and
  • a prospective or completed purchaser, investor or successor involved in a corporate transaction, subject to confidentiality and appropriate safeguards.

Providers may process personal information only for the services they perform for Brolly or as otherwise permitted by law and contract.

Brolly does not sell personal information for money. Brolly does not sell or share Customer Data for cross-context behavioral advertising. Certain public-website advertising or attribution disclosures may be treated as “sharing,” targeted advertising or a “sale” under a state privacy law even where no money is exchanged. Where that applies, Brolly will provide and honor the corresponding opt-out rights described in this Notice and the Cookie Preferences tool.

We may disclose aggregated or de-identified information that does not reasonably identify an individual. We maintain and use de-identified information in de-identified form and do not attempt to reidentify it except as permitted by law to test whether de-identification measures are effective.

10. International processing

Brolly is an Australian company serving customers in the United States and other countries. Personal information may be transferred to, stored in or accessed from Australia, the United States and countries in which Brolly’s service providers operate. Privacy and data-protection laws in those countries may differ from the laws where a person lives.

Customer Data hosting and residency commitments may be stated in an Order or DPA. Business systems used for customer relationship management, communications, analytics, support, security and billing may operate from other countries.

Brolly uses contractual, technical and organizational measures designed to protect personal information when it is processed internationally. The countries of likely recipients will be published on this page or in a linked subprocessor list, or made available through Brolly’s DPA process, once the production service-provider review is complete.

11. Retention and deletion

Brolly retains information only for as long as reasonably required for the purposes described in this Notice, an applicable agreement or law.

  • Customer Data: retained according to the customer’s subscription, applicable records schedules, legal holds and documented instructions.
  • After paid-service termination: unless an Order or DPA states otherwise, standard export functions remain available for 90 days. After that period, Brolly may delete Customer Data from active systems through its documented deletion cycle.
  • Trial data: may be deleted after a trial ends in accordance with Brolly’s documented retention practices (see the Terms of Service).
  • Account and support information: retained while the account is active and afterwards where needed for support history, security, disputes or legal compliance.
  • Billing, tax and contract records: retained for applicable statutory and business-record periods.
  • Analytics and marketing information: retained according to Brolly’s documented settings and the relevant consent or preference.
  • Backups: residual copies may remain until overwritten through the ordinary backup cycle and remain protected while retained.

Brolly may retain information where required by law, a legal hold, a customer’s lawful public-records or other retention obligation, fraud prevention, security or the establishment, exercise or defense of legal claims.

See How to request data deletion for request instructions.

12. Security and data incidents

Brolly uses reasonable administrative, physical and technical safeguards designed to protect personal information against unauthorized access, use, alteration and disclosure. Measures include access controls, encryption, authentication, monitoring, audit logging, supplier controls and incident-response processes appropriate to the information and service.

No internet-connected service is completely secure. Customers and users must protect their credentials, use available security controls and notify Brolly promptly of suspected unauthorized access.

Brolly will assess and provide notices concerning personal-information incidents as required by applicable law. Contractual notifications concerning Customer Data are addressed in the applicable agreement or DPA.

More information is available in Brolly’s Security and Compliance information.

13. Marketing choices

Brolly may send marketing communications where permitted by law. You can opt out using the unsubscribe facility in the message or by contacting us. Opting out of marketing does not prevent service, security, billing or legal communications required for an account or existing relationship.

Brolly does not use Customer Data to market to the people whose content appears in a customer archive.

14. United States privacy rights

Depending on where you live and subject to the scope and exceptions of applicable law, you may have the right to:

  • confirm whether Brolly processes personal information about you;
  • know or access the categories and specific pieces of information Brolly holds;
  • obtain information about sources, purposes and categories of recipients;
  • correct inaccurate personal information;
  • delete personal information;
  • obtain a portable copy of information you provided;
  • opt out of sale, sharing, targeted advertising or qualifying profiling;
  • limit certain uses or disclosures of sensitive personal information;
  • use an authorized agent to make a request; and
  • receive equal service and not be discriminated against for exercising a privacy right.

These rights are not absolute. For example, Brolly may need to retain information to provide a requested service, maintain security, comply with law, preserve a public record, honor a legal hold or establish or defend legal claims. A request concerning Customer Data may need to be handled by the relevant customer, as described in section 7.

How to submit a request

Email privacy@brolly.io with the subject “US Privacy Request” or use the Brolly contact page. Describe the right you wish to exercise and the information or Brolly interaction concerned.

Brolly will take reasonable steps to verify identity and authority. We may request information already associated with the relevant interaction and use it only for verification and response. An authorized agent may be required to provide proof of authority, and Brolly may seek direct confirmation from the individual where permitted.

We will acknowledge and respond within the period required by applicable law. Verified access, correction and deletion requests under many state laws are generally answered within 45 days, subject to a permitted extension. Opt-out requests will be processed within the shorter period required by applicable law. Brolly generally provides privacy-request responses without charge, but may charge or decline a request where law permits because it is manifestly unfounded, excessive or repetitive.

Appeals

If Brolly denies a request and applicable law provides an appeal right, reply to the decision or email privacy@brolly.io with the subject “Privacy Appeal.” The appeal will be reviewed by a person not responsible for the original decision where reasonably practicable. Brolly will explain the outcome and any available regulator contact.

15. California disclosures

This section supplements the rest of the Notice for California residents. It applies to the extent Brolly is subject to the California Consumer Privacy Act, as amended (“CCPA”).

Categories collected

In the preceding 12 months, Brolly may have collected the following CCPA categories, as described more fully in section 2:

CCPA categoryExamples relevant to Brolly
IdentifiersName, work email, username, account ID, IP address and cookie identifiers
California customer-record informationContact and account-administration information
Commercial informationSubscription, transaction, product-interest and customer-relationship records
Internet or electronic-network activityWebsite, application, support, authentication, search and interaction activity
GeolocationApproximate location derived from IP address
Professional or employment informationOrganization, role and professional contact information
InferencesProduct-interest, engagement or usage insights derived from Brolly-controlled business data
Sensitive personal informationAccount login credentials; private-message content or other sensitive information may appear in Customer Data processed for a customer

Brolly collects these categories from the sources in section 3, uses them for the purposes in sections 4–8, and discloses them to the recipient categories in section 9.

Brolly does not use sensitive personal information to infer characteristics about individuals for Brolly’s own unrelated purposes. Customer Data is processed for the customer under the applicable agreement.

Sale and sharing

Brolly does not sell personal information for money and does not sell or share Customer Data for cross-context behavioral advertising. Public-website advertising and attribution technologies may involve disclosures treated as “sharing” under California law. If Brolly determines it is subject to the CCPA and that such sharing occurs, Brolly will provide a Do Not Sell or Share My Personal Information control, allow opt-out through Cookie Preferences, and honor a valid Global Privacy Control signal.

Brolly does not knowingly sell or share personal information of people under 16.

Financial incentives

Brolly does not offer a financial incentive or price difference in exchange for personal information unless the material terms are described in a separate notice provided before enrollment.

16. Children

Brolly’s websites and services are designed for organizations and their personnel, not for children. They are not directed to children under 13, and Brolly does not knowingly create platform accounts for children under 13 or collect their personal information directly through a child-directed service.

Customer Data may contain social media content relating to minors where a customer lawfully captures that content for its organizational purposes. In that situation Brolly processes the information on the customer’s behalf and applies the contractual safeguards for Customer Data.

If you believe a child has provided personal information directly to Brolly contrary to this section, contact privacy@brolly.io.

17. Changes to this Notice

We may update this Notice to reflect changes in law, technology or Brolly’s practices. We will publish the updated Notice with a revised date. Where a change is material, we will provide additional notice where required or reasonably appropriate.

18. Contact Brolly

Privacy Officer

Brolly Australasia Pty Ltd

PO Box 356, Caloundra QLD 4551, Australia

  • Email: privacy@brolly.io
  • Support: support@brolly.io
  • Contact page: brolly.io/contact/
Brolly

Social media archiving, insights and protection for organizations that answer to the public.

ISO/IEC 27001:2022CSA STARG2 ★ 5.0

Product

  • Archive
  • Insights
  • Protect
  • Pricing
  • Security

Solutions

  • Channel governance
  • Recordkeeping
  • Public records requests
  • Moderation governance
  • Insights & reporting

Who we help

  • Government
  • Education
  • Higher education
  • Financial services
  • Healthcare
  • Utilities

Resources

  • Case studies
  • Blog
  • State law guides
  • Buyer's guide
  • Guides & templates
  • FAQs

Company

  • About
  • What is Brolly?
  • Customers
  • Contact
© 2026 Brolly · brolly.io
Terms of use Privacy policy Data deletion Service level agreement Cookie preferences
United States
Australia & NZ

Get a demo

A 20-minute walkthrough of Brolly

Pick a time that suits you — we'll walk through capture, search and export on your own channels.