How BrightAP handles your client data in the Business Performance Report, including GDPR compliance, data storage, and AI model governance.
This article explains how your client data is handled when you use the Business Performance Report — including where it is processed, how it is protected, and what Bright's obligations are under UK and EU GDPR.
What data does the Business Performance Report use?
The BPR uses only your client's nominal ledger data already held within BrightAP. It does not access:
▪ Data from any other client in your practice
▪ External data sources or benchmarking datasets
▪ Any data outside BrightAP
Where is the data processed?
When you generate a report, your client's nominal ledger data is sent securely to Bright's AI platform for analysis. Processing takes place within Bright's cloud infrastructure — hosted on Microsoft Azure and AWS, both of which are:
▪ GDPR-compliant
▪ ISO 27001 and SOC 2 certified
▪ Hosted in European regions
Trace data is retained within Bright's AI infrastructure for audit purposes.
Important: No data is shared with any third party outside Bright's published sub-processor list.
Does the AI learn from my client data?
No. Your client data is used solely to generate the specific report you have requested. It is not used to train external AI models.
Bright AI data assurance: Your data never leaves Bright or trains external models.
Is the Business Performance Report GDPR compliant?
Yes. The BPR is processed in line with UK and EU GDPR and Bright's existing data protection policies — the same framework that already governs your use of BrightAP.
If you need a Data Processing Addendum (DPA) for your own compliance records, you can download it from the Bright Security page: brightsg.com/security
Who in my practice can access reports?
Only users with the Business Performance Report permission enabled in Staff and Access Permissions. The report also inherits the standard BrightAP business-level access controls — users can only generate reports for clients they already have access to.
What happens if I stop using the feature?
No further data is sent to the AI platform. Your ledger data remains in BrightAP exactly as before. Disabling the Business Performance Report permission for a user immediately prevents any further report generation for that user.
Further information
For detailed information about Bright's security posture — including encryption standards, ISO 27001 alignment, and sub-processor details — visit the Bright Security page: brightsg.com/security
If your DPO or compliance team has specific contractual questions, please contact us at brightapsupport@brightsg.com and we will direct your query to the appropriate team.