PrivacyPolicy

Last updated: 11.06.2026

This Privacy Policy (the “Policy”) describes how BRIDGES GLOBAL INVESTMENT LLC (registration number 01-09-438746, Hungary) (the “Company”, “we”, “us”, “our”) collects, uses, stores, discloses and protects users’ personal data when they use the website brgsglobal.com (the “Site”) and our services.

We respect your privacy and process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the Hungarian Data Protection Act (Act CXII of 2011) and, where applicable, the UK GDPR, the California Consumer Privacy Act (as amended by the CPRA) and other applicable data protection rules.

Please read this Policy carefully. By using the Site and our services you confirm that you have read and understood the data processing practices described here.

01

THE DATA CONTROLLER

The controller of your personal data is:

BRIDGES GLOBAL INVESTMENT LLC
Registration number: 01-09-438746
Registered address: 1063 Budapest, Sziv utca 33, Hungary
Office: Budapest, Szervita tér 8, 1052, Hungary
Additional offices: Dubai, London
E-mail: office@bridges.global

For any question relating to the processing of personal data you may contact our data protection officer (DPO): dpo@bridges.global.

02

THE LEGAL BASES FOR PROCESSING

We process personal data only where there is a lawful basis under Article 6 of the GDPR:

  • Consent (Art. 6(1)(a)) — for marketing communications, analytics and advertising cookies, and other purposes requiring your explicit consent;
  • Performance of a contract (Art. 6(1)(b)) — to handle enquiries, provide services and perform our obligations to you;
  • Legitimate interest (Art. 6(1)(f)) — to ensure the security of the Site, prevent fraud, carry out internal analytics, improve the service and develop the business, provided that your rights and freedoms do not override it;
  • Legal obligation (Art. 6(1)(c)) — to comply with the requirements of the law, including anti-money-laundering (AML) and counter-terrorist-financing (CFT) obligations and KYC procedures.

In individual cases we may process special categories of data (Art. 9 GDPR) — for example when providing immigration services — only on the basis of your explicit consent or another applicable ground provided for by law.

03

WHAT DATA WE COLLECT

3.1. Data you provide to us directly:

  • First name and surname;
  • Contact phone number;
  • E-mail address;
  • Citizenship, country of residence and residence status;
  • Family composition (when services are arranged for family members);
  • Information about the source of funds and financial position (as part of KYC and due diligence procedures);
  • Copies of identity documents and other documents required to provide the services;
  • Payment details (when paying for services);
  • Any other information you provide when filling in forms, quizzes or calculators, in correspondence or when speaking to our specialists.

3.2. Data collected automatically:

  • IP address and approximate geolocation (country, city);
  • Browser type and version, operating system, device type and model;
  • Data on the pages visited, the referral source, search queries, the time and length of the visit and the sequence of actions on the Site;
  • UTM tags and advertising campaign parameters;
  • Cookies and similar tracking technologies;
  • Engagement metrics (the number of visits, pages viewed, interaction with buttons and forms).

3.3. Data from third-party sources:

  • Information from public and open sources;
  • Data from advertising, analytics and marketing platforms;
  • Information from partners who referred you to us.
04

HOW WE USE YOUR DATA

We use personal data for the following purposes:

  • Handling enquiries and requests and providing the services requested;
  • Identifying the client and carrying out KYC, due diligence and AML/CFT checks;
  • Communicating with you about the services, consultations and support;
  • Personalising content and improving the user experience;
  • Analysing traffic and the effectiveness of the Site and the marketing channels;
  • Marketing and advertising communications (where there is consent or a legitimate interest);
  • Assessing the priority and quality of enquiries (see section 6 on profiling);
  • Ensuring security and preventing fraud and abuse;
  • Complying with applicable laws and regulatory requirements.
05

MARKETING AND COMMUNICATIONS

5.1. With your consent or on the basis of a legitimate interest we may send you informational and promotional messages about our services, programmes and offers by e-mail, phone or messenger.

5.2. You may opt out of marketing communications at any time — by clicking the “unsubscribe” link in an e-mail, replying to a message asking to unsubscribe, or sending a request to office@bridges.global.

5.3. Opting out of marketing does not affect service messages necessary to provide the services you have ordered.

06

AUTOMATED PROCESSING AND PROFILING

6.1. To improve the quality of our service we use automated tools that analyse visitor behaviour on the Site (the referral source, pages viewed, time on site, device type, interactions) and assign an internal priority score to enquiries.

6.2. This processing helps our specialists respond to enquiries faster and better. It does not produce legal effects for you and is not automated decision-making within the meaning of Article 22 of the GDPR — final decisions are always taken by a person.

6.3. You may request information about the profiling logic used and object to such processing by sending a request to dpo@bridges.global.

07

COOKIES AND TRACKING TECHNOLOGIES

7.1. We use cookies and similar technologies to operate the Site and for analytics and personalisation. Strictly necessary cookies are used on the basis of a legitimate interest; analytics and advertising cookies only with your consent, given through the cookie banner on your first visit.

7.2. You may change or withdraw your consent at any time through the “Cookie settings” link at the bottom of any page of the Site. Detailed information is in our Cookie Policy.

08

TO WHOM WE DISCLOSE DATA

8.1. We do not sell your personal data. We may disclose data only in the following cases:

  • To service providers and contractors acting on our behalf (legal advisers, notaries, payment systems, IT and hosting providers, CRM systems, communication and analytics services);
  • To state authorities and regulators — where there is a lawful requirement;
  • To professional advisers (lawyers, auditors, insurers);
  • In connection with a reorganisation, merger or sale of the business;
  • To protect our rights and security and to prevent fraud.

8.2. All recipients of data are required to observe strict confidentiality and security measures and sign a data processing agreement.

8.3. The main categories of third-party services: Google Analytics, Yandex Metrica (analytics); Meta / Facebook (advertising analytics); WhatsApp, Telegram (communication); a CRM system (managing enquiries); payment providers (processing payments).

09

INTERNATIONAL DATA TRANSFERS

9.1. Because our work is international, your data may be transferred and processed outside the European Economic Area (EEA).

9.2. For such transfers we ensure an adequate level of protection through:

  • Transfers to countries recognised by the European Commission as providing an adequate level of protection;
  • Standard Contractual Clauses (SCC) approved by the European Commission;
  • Carrying out a Transfer Impact Assessment taking the “Schrems II” practice into account, and implementing additional safeguards where necessary.
10

DATA SECURITY

We apply technical and organisational measures to protect data against unauthorised access, alteration, disclosure and destruction, including:

  • Encryption of data in transit using SSL/TLS;
  • Restricting access to data on a need-to-know basis;
  • Confidentiality agreements with all employees and contractors;
  • Regular audits and monitoring of security systems;
  • Incident response and breach notification procedures.
11

RETENTION PERIODS

11.1. We keep personal data no longer than is necessary for the purposes of the processing or than the law requires.

  • Client data — for the term of the contract and 5 years after the last interaction;
  • KYC/AML documents — for the period set by anti-money-laundering law (as a rule at least 5–8 years);
  • Prospective client (lead) data — up to 24 months from the last contact, unless consent to longer storage has been given;
  • Marketing data — until consent is withdrawn;
  • Analytics and cookie data — in line with the periods stated in the Cookie Policy.

11.2. Once the retention period has expired the data is deleted or anonymised.

12

DATA MINIMISATION

We collect only the personal data necessary for the stated purposes and do not request excessive information. If a limited set of data is enough to provide a service, we do not ask for more.

13

YOUR RIGHTS (GDPR)

Under the GDPR you have the following rights:

  • The right of access to your data (Art. 15);
  • The right to rectification of inaccurate data (Art. 16);
  • The right to erasure — the “right to be forgotten” (Art. 17);
  • The right to restriction of processing (Art. 18);
  • The right to data portability (Art. 20);
  • The right to object to processing, including profiling and direct marketing (Art. 21);
  • The right to withdraw consent at any time;
  • The right not to be subject to solely automated decisions (Art. 22).

To exercise your rights send a request to dpo@bridges.global. We will reply within 30 days. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests.

14

RIGHTS OF CALIFORNIA RESIDENTS (CCPA/CPRA)

If you are a resident of the State of California, you have additional rights under the CCPA (as amended by the CPRA):

  • The right to know what personal data we collect, use and disclose;
  • The right to deletion of personal data;
  • The right to correction of inaccurate data;
  • The right to opt out of the “sale” or “sharing” of personal data — we do not sell personal data;
  • The right to limit the use of sensitive personal information;
  • The right not to be discriminated against for exercising your rights.

To exercise these rights send a request to dpo@bridges.global marked “California Privacy Request”.

15

RIGHTS IN OTHER JURISDICTIONS

If you are in the United Kingdom, your data is processed in accordance with the UK GDPR and the Data Protection Act 2018. Residents of other jurisdictions are granted rights to the extent provided for by the applicable local law.

16

COMPLAINT TO A SUPERVISORY AUTHORITY

You have the right to lodge a complaint with a data protection supervisory authority. The Hungarian supervisory authority is:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Website: naih.hu

You may also contact the supervisory authority in the place where you live or work.

17

PERSONAL DATA OF MINORS

Our Site and services are intended for persons aged 18 and over. We do not knowingly collect the data of minors without the consent of their legal representatives. If you believe we have received a child’s data, please contact us so that it can be deleted.

18

AML/CFT AND CLIENT SCREENING

As a company providing services in investment immigration, we are required to comply with anti-money-laundering (AML) and counter-terrorist-financing (CFT) legislation. For those purposes we carry out client identification (KYC) and due diligence procedures and may request documents confirming identity and the lawful origin of funds. This data is processed on the basis of a legal obligation.

19

CHANGES TO THE POLICY

We may update this Policy. Where the changes are material we will place a notice on the Site. The current version is always available on this page with the date of the last update. Continued use of the Site means acceptance of the updated version.

20

CONTACT INFORMATION

BRIDGES GLOBAL INVESTMENT LLC
Registration number: 01-09-438746
Registered address: 1063 Budapest, Sziv utca 33, Hungary
Office: Budapest, Szervita tér 8, 1052, Hungary
Additional offices: Dubai, London
Phone: +36 70 421 32 63
E-mail: office@bridges.global
Data protection (DPO): dpo@bridges.global

Related documents: Terms of Use · Cookie Policy · Disclaimer

Contents