Privacy Policy
1. Who We Are
Briedo ("we", "us", "our") operates the briedo.com platform, an AI-powered pre-call discovery service for professional service agencies. This Privacy Policy explains what personal data we handle, why, the legal basis for doing so, and the rights you have.
For any privacy question or to exercise your rights, contact us at privacy@briedo.com.
2. Our Two Roles (Controller vs Processor)
Briedo handles personal data in two distinct capacities, and which one applies determines who is responsible for the data:
- Controller, for data about our own customers (agency owners and their team members) and visitors to briedo.com. We decide how and why this data is processed.
- Processor, for the information a lead submits during an intake conversation hosted by an agency ("Lead Data"). Here the agency is the data controller and Briedo processes Lead Data on the agency's behalf and under its instructions. A Data Processing Agreement governs this relationship, see our DPA page.
If you are a lead and have questions about how your information is used, contact the agency that invited you, they are the controller of your data. Briedo will assist that agency in responding.
3. Data We Collect
We process the following categories of personal data:
- Account data (agency users): Name, email address, agency name, and website provided during sign-up or application.
- Usage data (visitors & users): Pages visited, features used, session duration, browser type, and IP address, collected via analytics only where you have given consent (see our Cookie Policy).
- Lead Data (intake conversations): The text, answers, and any files a lead submits through an intake conversation, plus contact details such as name, email, and phone where provided. This is processed on behalf of the agency.
- Billing data (paid plans only): Where an agency is on a paid plan, we hold the billing contact and company details needed to issue an invoice. Briedo does not operate a self-serve checkout, so no card details are collected or stored on the platform.
4. How We Use Data and Our Legal Basis
For data where Briedo is the controller, we rely on the following GDPR Article 6 legal bases:
- To provide and operate the platform, including running intake conversations and generating readiness briefs. Legal basis: performance of a contract (Art. 6(1)(b)).
- To send transactional emails, account notifications, member invitations, support replies, and brief-ready notifications. Legal basis: contract / legitimate interests (Art. 6(1)(b)/(f)).
- To measure and improve the product, analytics and service improvement. Legal basis: consent for analytics cookies (Art. 6(1)(a)); legitimate interests for aggregated improvement (Art. 6(1)(f)).
- To prevent abuse and secure the service, bot detection, rate limiting, and fraud prevention. Legal basis: legitimate interests (Art. 6(1)(f)).
- Marketing communications, where you have opted in. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time.
- To meet legal obligations. Legal basis: legal obligation (Art. 6(1)(c)).
We do not sell your data. We do not use Lead Data to train external AI models, our AI subprocessors are contractually prohibited from using data submitted through their APIs to train their models.
5. AI Processing of Conversations
Briedo's core function is to run AI-assisted intake conversations and to generate structured briefs. To do this, conversation content is sent to the following AI providers acting as our subprocessors:
- Anthropic (Claude API): powers the intake conversation, producing the next response and extracting structured information from what a lead shares.
- OpenAI (GPT-4.1 family): generates the structured readiness brief, the client-facing recap, and AI insight reports, and can also power the intake conversation.
- Brave Search, used to research publicly available information about a company or website referenced during intake, when generating AI insights.
Which provider handles a given intake conversation depends on platform configuration, workspace settings, availability, and fallback processing. Each provider is bound by a data processing agreement and does not use API data to train its models. A full list, with the data each handles and its processing location, is on our Subprocessors page.
6. Data Sharing and Subprocessors
We share data only with vetted subprocessors that help us deliver the service:
- Hosting & infrastructure: Google Firebase / Google Cloud (data stored in the EU).
- AI providers: Anthropic, OpenAI, and Brave Search, as described above.
- Transactional email: Resend, used to deliver member invitations, support ticket replies, and brief notifications.
- Company registry data (Romania): InfoCUI.ro and the public ANAF web service, used to retrieve public company registry information and filed financial statements when a Romanian company identifier is provided.
- EU VAT validation: VIES (European Commission), used to validate VAT identifiers for supported EU countries when one is provided.
- Bot protection: Google reCAPTCHA, on public forms.
- Analytics: Google Analytics 4 and Microsoft Clarity (session and interaction analytics), loaded only with your consent.
- Scheduling (user-directed): Google Calendar and Google Meet, when a workspace administrator connects the workspace's own Google account. To schedule a client call, the client's email address, the meeting time, and the invitation text are sent to Google to create the calendar event and deliver the invitation.
Every subprocessor is bound by a data processing agreement and is prohibited from using your data for its own purposes. The complete, current list is maintained on our Subprocessors page, which we update before engaging any new vendor.
7. International Data Transfers
Our primary infrastructure (Google Cloud / Firebase) is hosted in the European Union. Some subprocessors, in particular our AI providers (Anthropic, OpenAI), Brave Search, and Microsoft Clarity, process data in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, additional safeguards, as the legal mechanism for the transfer.
8. Cookies
We use strictly necessary cookies for authentication and security, and, only with your consent, analytics cookies to understand product usage. We do not use advertising or third-party ad-targeting cookies. You can review and change your choices at any time via the cookie preferences in our footer. For full detail, see our Cookie Policy.
9. Data Retention
We keep personal data only for as long as needed for the purpose it was collected:
- Account data: Retained for the life of the account. When an account is deleted, data is removed from our active production systems promptly. Residual copies may remain in restricted, access-controlled backup and recovery systems until they expire automatically, within a maximum of 98 days, unless a longer period is required by law.
- Submitted briefs & lead data: When an intake is submitted, the resulting brief is retained on behalf of the controlling agency for as long as the agency's account is active, or until it is deleted. The agency determines its own retention policy for this data, and it may be removed earlier on the agency's instruction, on a data deletion request, or when the workspace or account is deleted. This is separate from the raw intake conversation data below.
- Intake conversation & session data: The raw intake conversation and related operational session records are retained for up to 180 days, after which they are deleted automatically. Unfinished or abandoned sessions may be cleaned up sooner.
- Access links: Access links are separate from the underlying data, and a link expiring does not by itself delete a submitted brief. Guest report links expire within 48 hours; intake resume links expire within 24 hours.
- Email delivery logs: Retained for operational and troubleshooting purposes for a limited period.
- Analytics data: Retained per the configured Google Analytics retention window.
You may request earlier deletion at any time by contacting privacy@briedo.com.
10. Your Rights
Under the GDPR and applicable data protection law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data ("right to be forgotten").
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests.
- Data portability, receive your data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with a supervisory authority (see below).
To exercise any of these rights, email privacy@briedo.com. We will respond within one month. If you are a lead, please direct your request to the agency that invited you, as they control your data.
11. Supervisory Authority
If you believe your data has been handled unlawfully, you have the right to lodge a complaint with a data protection supervisory authority. In Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro). You may also contact the authority in your country of residence.
12. Data Security
We apply industry-standard safeguards including encryption in transit (TLS), workspace-level access isolation, server-side access controls, and hashing of access tokens. No system is perfectly secure, if you discover a vulnerability, please report it to privacy@briedo.com. For more detail, see our Security page.
13. Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where Briedo acts as a processor for an agency, we will notify the affected agency (the controller) without undue delay so they can meet their own obligations.
14. Children's Privacy
Briedo is a business-to-business product not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact privacy@briedo.com and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on the platform. The "Last updated" date at the top of this page always reflects the most recent revision.
Privacy questions or data requests?
privacy@briedo.com