Brand Climb
AI is becoming your next acquisition channel. Is it sending customers to you — or to your competitor?Check my score

Data Processing

The factual annexes of a data-processing agreement: categories, purposes, recipients and safeguards. The operative clauses need a lawyer, and we say so.

What this page is

The factual annexes of a data-processing agreement: the categories, the purposes, the recipients and the safeguards. This is the part a reviewer actually checks against reality, and the part we can state precisely because it comes from the code. The operative clauses — the Article 28 obligations themselves — are not drafted here; they need a lawyer and a registered entity, and a draft that looks finished is a draft somebody signs.

Roles

For your account data you are the data subject and we determine the purposes, which makes us the controller. For the brand data you configure and the answers we collect on your instruction, you decide what is tracked and we act on that instruction, which makes you the controller and us the processor. The distinction matters for who answers a subject request, and we will act on either.

Categories of data subjects

Users of your account: the people you invite and their email addresses. Indirectly, any individual named inside an answer an engine returned — we do not select for this, but a model asked about a company may mention its executives, and the answer is stored as returned.

Categories of personal data

Email addresses, optional names and roles, and authentication data held by Supabase. Billing identity held by Lemon Squeezy, not by us. Free-text content you enter, which is under your control and should not contain special-category data. No IP addresses, no device identifiers, no location data, no behavioural tracking.

Processing operations

Collection of the answers engines return to your prompts; storage of those answers and the metrics derived from them; analysis that produces your action plan; transmission to the answer engines listed as subprocessors; and delivery of email you have asked for. Processing is limited to operating, securing and supporting the service.

Subprocessors and international transfers

The full list is published at /subprocessors, with what each receives. It is kept in the same repository as the code, so a provider cannot enter the request path without appearing there in the same change. Most of these providers are established in the United States, which means personal data is transferred outside the EEA; the transfer mechanism belongs in the signed agreement and has not been settled, because there is no entity to sign it.

Security measures

Row-level security in Postgres scopes every read and write to the owning account. Stored third-party credentials are encrypted with AES-GCM. Outbound fetches are guarded against server-side request forgery. Payment credentials are never received. Error reports carry no personal information. Access to production is limited to the founder. That last sentence is the honest measure of the current organisation, and it is what a one-person company can truthfully claim.

Return and deletion

Data can be exported from the product, and deletion is performed on request by writing to legal@brandclimbai.com. As stated in the privacy summary, deletion is a manual operation today rather than a scheduled one.

Request the reviewed DPA at legal@brandclimbai.com. This page is a product summary, not a signed agreement.