Compliance
At Brava, we maintain the highest standards of compliance with industry regulations, data protection laws, and security protocols to ensure trust and safety for all our users.
Last updated: August 12, 2026
Quick Navigation
Data Protection & Privacy
Data Protection Law
Brava is established in India and sells to businesses in India, so our handling of personal data is governed by the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, notified in November 2025. The substantive obligations those Rules place on a data fiduciary take effect in May 2027, and we are building towards them now. We follow practices aligned with the General Data Protection Regulation (GDPR), including data minimisation, purpose limitation and the access and deletion rights described below, but we hold no GDPR certification and do not represent ourselves as fully GDPR compliant.
Data Processing
We process personal data only for legitimate purposes and with appropriate legal basis. All data processing activities are documented and regularly audited to ensure compliance with applicable regulations.
Right to Access
Users have the right to access, rectify, delete, and port their personal data. We provide tools within our platform to exercise these rights easily and efficiently.
Payment Card Industry (PCI) Compliance
Secure Payment Processing
All payment transactions are processed through PCI DSS Level 1 compliant payment processors. We do not store sensitive card information on our servers.
Encryption Standards
We use industry-standard encryption (AES-256) for data at rest and TLS 1.3 for data in transit to protect all payment and sensitive information.
Regular Security Audits
Our systems undergo regular security assessments and penetration testing to ensure the highest level of payment security for our users.
Digital Wallet Compliance
Apple Wallet Guidelines
Our Apple Wallet integration fully complies with Apple's Pass Design and Creation guidelines, ensuring a secure and consistent user experience.
Google Wallet Standards
We adhere to Google Pay and Google Wallet API policies, implementing proper security measures and user consent flows for all digital wallet interactions.
Data Minimization
We collect and store only the minimum data necessary for digital wallet functionality, in accordance with platform-specific requirements and best practices.
Accessibility Standards
WCAG 2.1 Compliance
Our platform is designed to meet Web Content Accessibility Guidelines (WCAG) 2.1 Level AA standards, ensuring accessibility for users with disabilities.
Inclusive Design
We implement keyboard navigation, screen reader compatibility, and proper color contrast ratios throughout our platform to ensure an inclusive user experience.
Continuous Improvement
We regularly test and improve our platform's accessibility features based on user feedback and evolving accessibility standards.
Legal & Regulatory Compliance
Terms of Service
All users must agree to our Terms of Service, which outline the rights, responsibilities, and obligations of both Brava and our users.
Consumer Protection
We comply with applicable consumer protection laws and regulations, ensuring fair business practices and transparent communication with our users.
Anti-Fraud Measures
We implement robust anti-fraud systems and comply with anti-money laundering (AML) regulations to protect both businesses and customers.
Compliance Updates & Monitoring
Regular Reviews
Our compliance policies are reviewed and updated regularly to reflect changes in regulations, industry standards, and best practices.
Incident Response
We maintain a comprehensive incident response plan to address any security or compliance issues promptly and effectively.
Transparency Reports
We are committed to transparency and will publish regular compliance reports detailing our adherence to applicable regulations and standards.
Questions About Compliance?
Our compliance team is here to help answer any questions about how we protect your data and maintain regulatory standards.
