Subprocessors
Briedo uses a small number of trusted third-party services to deliver the platform. Under GDPR, these are called subprocessors, companies that process personal data on Briedo's behalf, under a Data Processing Agreement.
This page lists every subprocessor we engage, the data each one handles, and links to their privacy documentation. We keep this list short, and update it before adding any new vendor.
1. Infrastructure, Google Firebase / Google Cloud
Briedo's entire backend runs on Google Firebase and Google Cloud Platform, operated by Google LLC. The following Firebase services are in use:
- Firebase Authentication, user account creation, login, password management, and session tokens
- Cloud Firestore, primary application database (workspaces, user profiles, briefs, configuration). Database location: eur3 (EU multi-region, Belgium / Netherlands)
- Cloud Storage for Firebase, uploaded files and branding assets stored by workspace members
- Cloud Functions for Firebase, serverless compute for application form processing and email dispatch. Function region: europe-west1 (Belgium)
- Firebase Hosting, web application delivery via Google's managed CDN
Data processed: All data stored in or transmitted through Briedo, account credentials, workspace content, uploaded files, and HTTP access logs.
Legal basis for transfer: Google Cloud Data Processing Addendum, incorporating EU Standard Contractual Clauses (SCCs) for transfers outside the EEA where applicable.
2. AI Conversation, Anthropic
Briedo uses the Claude API, operated by Anthropic PBC, to run the intake conversation. The conversation text is sent to Anthropic to produce the next response and to extract structured information. Which provider handles a given conversation depends on platform configuration, workspace settings, availability, and fallback processing; OpenAI (section 3) can also process intake conversations.
Data processed: The conversation messages and brief content submitted during an intake session. This may include personal data that a lead chooses to share about themselves or their business.
Processing location: United States. Transfer covered by Anthropic's Data Processing Addendum, incorporating EU Standard Contractual Clauses. Anthropic does not use data submitted through its API to train its models.
3. AI Conversation & Brief Generation, OpenAI
Briedo uses OpenAI models (operated by OpenAI, L.L.C.) to generate the structured readiness brief delivered to agencies, the client-facing recap, and AI insight reports. OpenAI can also power the intake conversation, subject to the configuration described in section 2. When it does, conversation text is sent to OpenAI to produce the next response and to extract structured information; the brief is then produced from the information collected.
Data processed: The conversation messages and brief content submitted during an intake session, and the extracted field values needed to generate reports. This may include personal data that a lead chooses to share about themselves or their business.
Processing location: United States. Transfer covered by OpenAI's Data Processing Addendum, incorporating EU Standard Contractual Clauses. Data submitted through the API is not used to train OpenAI's models.
4. Research Enrichment, Brave Search
When generating AI insight reports, Briedo may use the Brave Search API, operated by Brave Software, Inc., to research publicly available information about a company or website referenced during the intake.
Data processed: Search queries derived from the company name or website provided during intake, typically business identifiers rather than personal contact details.
Processing location: United States. Transfer covered by Brave's terms incorporating EU Standard Contractual Clauses.
5. Analytics, Google Analytics 4
We use Google Analytics 4 to collect anonymised, aggregated data about how visitors use Briedo, pages viewed, session duration, and broad device type. No personally identifiable information is stored in analytics reports. IP addresses are anonymised at the collection layer.
Data processed: Anonymised usage events, page views, session identifiers (no PII).
Processing location: United States (Google data centres). Transfer covered by Google's EU Standard Contractual Clauses.
Consent: Consent-gated Google Analytics only loads after you grant analytics consent via the cookie banner. Until consent is given, no data is sent to Google Analytics.
6. Transactional Email, Resend
Briedo uses Resend to deliver transactional email notifications, such as workspace member invitations, support ticket replies, and brief readiness notifications sent to agencies and their clients.
Data processed: Recipient name and email address, plus the minimal context needed to render the notification (for example a workspace name or a secure link). This data is transmitted to Resend solely to deliver the email.
Processing location: Per Resend infrastructure, see their privacy policy for details.
7. Company Registry Data (Romania), InfoCUI
For Romanian companies, Briedo uses InfoCUI.ro to retrieve public company registry information (legal name, registration number, registered address, VAT status) when an agency or a lead provides a Romanian company identifier (CUI), and the public ANAF web service for filed annual financial statements.
Data processed: The company identifier (CUI) is transmitted to InfoCUI solely to retrieve the corresponding public registry record. Note that registry records of sole traders and home-registered businesses can contain personal data (for example a personal registered address).
8. EU VAT Validation, VIES (European Commission)
For supported EU countries, Briedo validates VAT identifiers against VIES, the European Commission's official VAT Information Exchange System, and displays the company name and address where the member state supplies them.
Data processed: The country code and VAT number are transmitted to VIES solely to validate the identifier. A negative validation result means only that the number is not VAT-registered, and is never treated as proof that a company does not exist.
9. Bot Protection, Google reCAPTCHA v3
The public application form uses Google reCAPTCHA v3 to detect and block automated bot submissions. reCAPTCHA analyses browser behaviour and interaction patterns invisibly, no challenge puzzle is shown to users.
Data processed: Browser fingerprint and interaction data used to generate a risk score. The resulting token is verified server-side by Briedo's Cloud Function; the individual score is not stored.
Processing location: United States (Google data centres). Transfer covered by Google's EU Standard Contractual Clauses.
10. Web Fonts, Google Fonts
Briedo loads typefaces (Instrument Serif, Bricolage Grotesque, JetBrains Mono) from Google Fonts. When your browser loads a page, it requests font files from Google's CDN ( fonts.googleapis.com / fonts.gstatic.com), which transmits your IP address and standard browser metadata as part of the HTTP request.
Data processed: IP address and browser User-Agent. Google states it does not use this data to build user profiles or serve advertising.
Processing location: Google CDN (global).
11. Error Monitoring, Sentry
Briedo uses Sentry (operated by Functional Software, Inc.) to capture application errors on both the web application and the backend functions, so failures can be detected and fixed quickly.
Data processed: Error events and stack traces, browser and device metadata, and correlation identifiers (such as session, brief, and workspace IDs) used to trace a failure. Error payloads may incidentally include fragments of the data being processed when the error occurred.
Processing location: European Union, Briedo uses Sentry's EU region, so event data is stored in the EU. Covered by Sentry's Data Processing Addendum.
12. Analytics, Microsoft Clarity
Briedo uses Microsoft Clarity (operated by Microsoft Corporation) to understand how visitors use the public site, session and interaction analytics such as clicks, scrolling, and navigation, so we can improve usability.
Data processed: Device and browser information, online identifiers (including an IP address and a pseudonymous Clarity user ID), and interaction signals including consented session replay. Briedo masks sensitive application areas, the intake conversation, contact fields, and brief previews, using Clarity's DOM masking, and only sends bucketed, non-identifying custom tags such as funnel stage and language.
Processing location: United States. Transfer covered by Microsoft's Data Processing Addendum, incorporating EU Standard Contractual Clauses. Processing may occur outside the EU/EEA.
Consent: Consent-gated Microsoft Clarity only loads after you grant analytics consent via the cookie banner. Until consent is given, no data is sent to Microsoft Clarity, and you can withdraw analytics consent at any time through the cookie preferences.
User-directed integrations, scheduling
Some Briedo features connect to a third-party service at a workspace's explicit direction, using an account the workspace itself owns. These are listed separately from the subprocessors above, because Briedo does not engage the provider on its own behalf; the workspace administrator connects it and can disconnect it at any time.
Google Calendar and Google Meet
When a workspace administrator connects Google Calendar (Google LLC) from Settings, Briedo can schedule client calls: it creates a calendar event with a Google Meet link in the connected Google account's calendar, and Google sends the calendar invitation to the client.
Data sent to Google when scheduling a call: the client's email address, the meeting date, time, duration and time zone, and the invitation text, which includes the workspace's discovery link. Google processes this data under the connected account's own agreement with Google.
Credentials: the authorization tokens for this connection are held server-side, are never exposed to the browser, and are deleted when the integration is disconnected or the workspace is deleted, with a best-effort revocation at Google.
Sending information onward to your own tools
A workspace can ask Briedo to send information from a finished brief to another system that the workspace has connected itself, such as a CRM or a task tool. Briedo does this only when the workspace directs it, either by an explicit action or by a delivery setting the workspace has turned on.
What Briedo sends: by default, a small set of identifying details and a link back to the brief in Briedo. Any further information travels only when a workspace administrator has enabled it for that specific destination. Briedo keeps a record of each delivery: which brief and version was sent, to which destination, when, who authorised it and what the outcome was.
What happens to the copy: the receiving service processes the delivered information under the workspace's own agreement with that service, not under Briedo's. Deleting a brief in Briedo, or deleting a Briedo account, removes the information Briedo holds. It does not reach into the other system. Removing or correcting the delivered copy there is the responsibility of the workspace that directed the delivery, and Briedo's delivery record is what identifies where to look.
No such destination is available in Briedo today. This section will name each service, and the information sent to it, before any workspace can connect one.
Changes to this list
Briedo will update this page before engaging a new subprocessor. If you have an active contract with Briedo and the addition materially affects the processing of your data, we will notify you by email at least 14 days in advance.
The Last updated date at the top of this page reflects the most recent change to the subprocessor list.
Questions?
If you have questions about our subprocessors or data processing arrangements, contact us at privacy@briedo.com.