Privacy Notice
Version 1.0 — draft prepared for legal review. This notice describes BriefGate's actual data handling as implemented in the product; the clauses most likely to need a lawyer's sign-off are the lawful-basis assignments in §3 and the retention periods in §5, both of which turn on judgment calls rather than a number in the code.
This is the notice linked from the Google OAuth consent screen and from your account settings. It is addressed to you, the account holder — the person who signs up for and uses BriefGate — under Article 13 of the GDPR.
If you are looking for how BriefGate handles your own clients' data (the people you send an intake to), that is a separate relationship in which you, not BriefGate, are the controller. It is covered in depth in the GDPR page, which this notice cites rather than repeats in §6 below.
1. Who is the controller
For the personal data described in this notice, the controller is:
Radim Sekera, trading as BriefGate (a Czech sole trader / OSVČ). IČO: 04217764. Registered address: Kostelní 2022/18, 741 01 Nový Jičín, Czech Republic. Contact for data protection matters: [email protected].
BriefGate has not designated a data protection officer; it does not meet the criteria in Article 37(1) GDPR that would require one.
2. What data we collect about you
| Category | Examples | Source |
|---|---|---|
| Account identity | Name, email address, Google account identifier (if you sign in with Google), password hash (argon2id) if you use a password | You, at sign-up |
| Session and authentication | bg_session cookie value, session creation/expiry timestamps, IP address at login |
Generated when you sign in |
| Billing | Stripe customer ID, subscription status and tier, invoices — card numbers are handled by Stripe and never reach BriefGate's servers | You, via Stripe Checkout/Portal |
| Account configuration | Retention settings, branding, custom domain, API keys (hashed), webhook URLs, team members you invite | You |
| Usage and audit | Actions you take (login, key creation, secret reveals, intake operations), IP address, timestamp, in the append-only audit log | Generated by the product |
| Support communication | Anything you send us when asking for help | You |
This is distinct from the data your own clients submit through an intake (their contact details, files, and any secret credentials) — that data is described in the GDPR page, and BriefGate is your processor for it, not its controller (see the DPA).
3. Why we process it, and the lawful basis
| Purpose | Data used | Lawful basis (Art. 6 GDPR) |
|---|---|---|
| Create and operate your account, provide the service you subscribed to | Account identity, configuration, sessions | Performance of a contract (6(1)(b)) |
| Billing and invoicing | Billing data | Performance of a contract (6(1)(b)); statutory retention is a legal obligation (6(1)(c)) |
| Keep the service secure — rate limiting, fraud and abuse signals, audit trail | Session/login IP addresses, audit log | Legitimate interest (6(1)(f)) — protecting the service and other customers from abuse |
| Respond to support requests | Support communication | Performance of a contract (6(1)(b)) / legitimate interest (6(1)(f)) |
| Comply with legal obligations (tax, accounting, lawful requests from authorities) | Billing and account records | Legal obligation (6(1)(c)) |
BriefGate does not currently run marketing email campaigns to account holders; if that changes, any marketing communication will be sent only on the basis of your consent (6(1)(a)) or an equivalent narrow legitimate interest with an opt-out, and this notice will be updated to say so before it happens.
4. Cookies
| Cookie | Purpose | Who it's set for | Lifetime |
|---|---|---|---|
bg_session |
Keeps you signed in to the BriefGate dashboard | You, the account holder | 30 days (configurable by the operator) |
bg_portal |
Keeps a client's portal session active while they work through an intake | Your client, on the intake portal — not you | 14 days |
Both are strictly necessary session cookies used to keep you (or your client)
authenticated; they are not used for advertising or cross-site tracking, and
Czech/EU cookie-consent rules for strictly necessary cookies do not require a
consent banner for them. bg_portal is listed here for completeness because
it is set by BriefGate infrastructure, even though the person it identifies
is your client, not you — your clients' use of the portal is covered under
your own privacy notice to them, which is your responsibility as controller
(see the GDPR page, "Subject rights").
5. How long we keep your account data
- Account and configuration data: for as long as your account is active, plus a period after closure to handle any outstanding billing, dispute, or legal-hold need.
- Billing records (invoices, payment records): kept for the period required by Czech tax and accounting law, which is longer than the life of your account regardless of when you close it.
- Audit log entries: retained as part of the append-only security log described in the GDPR page and the DPA Annex III; it is not deleted on request because its purpose is to provide a reliable record of account activity, including in the period around any dispute.
- Account deletion: on request, BriefGate deletes your account and personal data within 30 days, save for what a legal obligation (billing records) requires it to keep.
This is separate from intake data — the material your clients submit — whose retention you control per-account and per-intake as described in the GDPR page ("Data retention").
6. Who we share it with
- Sub-processors who support the service: netcup GmbH (hosting, Germany), Cloudflare, Inc. (storage/CDN), Plus Five Five, Inc. (Resend, transactional email), Twilio Inc. (SMS), Stripe, LLC (payments). Their role, location, and transfer basis are detailed in the DPA (Annex IV) and the GDPR page, which this notice incorporates by reference rather than duplicating a table that would then have to be kept in sync in two places.
- Legal and safety: where required by law, to protect BriefGate's rights, or to investigate abuse of the service (see the Acceptable Use Policy).
- We do not sell your personal data, and we do not share it for third-party advertising.
7. International transfers
Application processing happens in the EU (Germany); some sub-processors are US companies, and transfers to them rest on the EU-U.S. Data Privacy Framework together with the 2021/914 standard contractual clauses as a fallback. The detail — including the pending Court of Justice appeal noted against the adequacy decision — is in the DPA §3, which is the authoritative statement for both this notice and the GDPR page.
8. Your rights
As a data subject, you have the right to:
- Access the personal data BriefGate holds about you.
- Rectify inaccurate or incomplete data — much of this you can do yourself in account settings.
- Erase your data ("right to be forgotten"), subject to the legal-obligation retention in §5.
- Restrict processing in the circumstances set out in Article 18 GDPR.
- Port your account data to yourself or another provider in a structured, machine-readable format.
- Object to processing based on legitimate interest (§3).
- Withdraw consent at any time, where processing is based on consent, without affecting processing carried out before the withdrawal.
To exercise any of these rights, email [email protected]. We will respond within the time limits set by the GDPR (normally one month). We may ask you to verify your identity before acting on a request.
Right to lodge a complaint. If you believe BriefGate has not handled your personal data lawfully, you have the right to complain to the Czech data protection authority:
Úřad pro ochranu osobních údajů (ÚOOÚ) Pplk. Sochora 27, 170 00 Praha 7, Czech Republic www.uoou.cz
or to the supervisory authority of your own EU member state of residence, if different.
9. Automated decision-making
BriefGate does not make any decision about you, based solely on automated processing, that produces legal or similarly significant effects. Rate limiting and abuse signals (§3) inform manual review; they do not automatically close accounts or deny service on their own.
10. Security
The technical and organizational measures protecting your account data — encryption, access control, key isolation, audit logging — are the same ones described in detail in the DPA Annex III, which applies to account data as much as to intake data.
11. Changes to this notice
We will update this notice as the product or our processing changes, and post the new version here with an updated version number. Material changes will be notified to your account's registered email address.