Privacy Notice

Version 1.0 — draft prepared for legal review. This notice describes BriefGate's actual data handling as implemented in the product; the clauses most likely to need a lawyer's sign-off are the lawful-basis assignments in §3 and the retention periods in §5, both of which turn on judgment calls rather than a number in the code.

This is the notice linked from the Google OAuth consent screen and from your account settings. It is addressed to you, the account holder — the person who signs up for and uses BriefGate — under Article 13 of the GDPR.

If you are looking for how BriefGate handles your own clients' data (the people you send an intake to), that is a separate relationship in which you, not BriefGate, are the controller. It is covered in depth in the GDPR page, which this notice cites rather than repeats in §6 below.

1. Who is the controller

For the personal data described in this notice, the controller is:

Radim Sekera, trading as BriefGate (a Czech sole trader / OSVČ). IČO: 04217764. Registered address: Kostelní 2022/18, 741 01 Nový Jičín, Czech Republic. Contact for data protection matters: [email protected].

BriefGate has not designated a data protection officer; it does not meet the criteria in Article 37(1) GDPR that would require one.

2. What data we collect about you

Category Examples Source
Account identity Name, email address, Google account identifier (if you sign in with Google), password hash (argon2id) if you use a password You, at sign-up
Session and authentication bg_session cookie value, session creation/expiry timestamps, IP address at login Generated when you sign in
Billing Stripe customer ID, subscription status and tier, invoices — card numbers are handled by Stripe and never reach BriefGate's servers You, via Stripe Checkout/Portal
Account configuration Retention settings, branding, custom domain, API keys (hashed), webhook URLs, team members you invite You
Usage and audit Actions you take (login, key creation, secret reveals, intake operations), IP address, timestamp, in the append-only audit log Generated by the product
Support communication Anything you send us when asking for help You

This is distinct from the data your own clients submit through an intake (their contact details, files, and any secret credentials) — that data is described in the GDPR page, and BriefGate is your processor for it, not its controller (see the DPA).

3. Why we process it, and the lawful basis

Purpose Data used Lawful basis (Art. 6 GDPR)
Create and operate your account, provide the service you subscribed to Account identity, configuration, sessions Performance of a contract (6(1)(b))
Billing and invoicing Billing data Performance of a contract (6(1)(b)); statutory retention is a legal obligation (6(1)(c))
Keep the service secure — rate limiting, fraud and abuse signals, audit trail Session/login IP addresses, audit log Legitimate interest (6(1)(f)) — protecting the service and other customers from abuse
Respond to support requests Support communication Performance of a contract (6(1)(b)) / legitimate interest (6(1)(f))
Comply with legal obligations (tax, accounting, lawful requests from authorities) Billing and account records Legal obligation (6(1)(c))

BriefGate does not currently run marketing email campaigns to account holders; if that changes, any marketing communication will be sent only on the basis of your consent (6(1)(a)) or an equivalent narrow legitimate interest with an opt-out, and this notice will be updated to say so before it happens.

4. Cookies

Cookie Purpose Who it's set for Lifetime
bg_session Keeps you signed in to the BriefGate dashboard You, the account holder 30 days (configurable by the operator)
bg_portal Keeps a client's portal session active while they work through an intake Your client, on the intake portal — not you 14 days

Both are strictly necessary session cookies used to keep you (or your client) authenticated; they are not used for advertising or cross-site tracking, and Czech/EU cookie-consent rules for strictly necessary cookies do not require a consent banner for them. bg_portal is listed here for completeness because it is set by BriefGate infrastructure, even though the person it identifies is your client, not you — your clients' use of the portal is covered under your own privacy notice to them, which is your responsibility as controller (see the GDPR page, "Subject rights").

5. How long we keep your account data

This is separate from intake data — the material your clients submit — whose retention you control per-account and per-intake as described in the GDPR page ("Data retention").

6. Who we share it with

7. International transfers

Application processing happens in the EU (Germany); some sub-processors are US companies, and transfers to them rest on the EU-U.S. Data Privacy Framework together with the 2021/914 standard contractual clauses as a fallback. The detail — including the pending Court of Justice appeal noted against the adequacy decision — is in the DPA §3, which is the authoritative statement for both this notice and the GDPR page.

8. Your rights

As a data subject, you have the right to:

To exercise any of these rights, email [email protected]. We will respond within the time limits set by the GDPR (normally one month). We may ask you to verify your identity before acting on a request.

Right to lodge a complaint. If you believe BriefGate has not handled your personal data lawfully, you have the right to complain to the Czech data protection authority:

Úřad pro ochranu osobních údajů (ÚOOÚ) Pplk. Sochora 27, 170 00 Praha 7, Czech Republic www.uoou.cz

or to the supervisory authority of your own EU member state of residence, if different.

9. Automated decision-making

BriefGate does not make any decision about you, based solely on automated processing, that produces legal or similarly significant effects. Rate limiting and abuse signals (§3) inform manual review; they do not automatically close accounts or deny service on their own.

10. Security

The technical and organizational measures protecting your account data — encryption, access control, key isolation, audit logging — are the same ones described in detail in the DPA Annex III, which applies to account data as much as to intake data.

11. Changes to this notice

We will update this notice as the product or our processing changes, and post the new version here with an updated version number. Material changes will be notified to your account's registered email address.