Data Processing
The factual annexes of a data-processing agreement: categories, purposes, recipients and safeguards. The operative clauses need a lawyer, and we say so.
What this page is
The factual annexes of a data-processing agreement: the categories, the purposes, the recipients and the safeguards. This is the part a reviewer actually checks against reality, and the part we can state precisely because it comes from the code. The operative clauses — the Article 28 obligations themselves — are not drafted here; they need a lawyer and a registered entity, and a draft that looks finished is a draft somebody signs.
Roles
For your account data you are the data subject and we determine the purposes, which makes us the controller. For the brand data you configure and the answers we collect on your instruction, you decide what is tracked and we act on that instruction, which makes you the controller and us the processor. The distinction matters for who answers a subject request, and we will act on either.
Categories of data subjects
Users of your account: the people you invite and their email addresses. Indirectly, any individual named inside an answer an engine returned — we do not select for this, but a model asked about a company may mention its executives, and the answer is stored as returned.
Categories of personal data
Email addresses, optional names and roles, and authentication data held by Supabase. Billing identity held by Lemon Squeezy, not by us. Free-text content you enter, which is under your control and should not contain special-category data. No IP addresses, no device identifiers, no location data, no behavioural tracking.
Processing operations
Collection of the answers engines return to your prompts; storage of those answers and the metrics derived from them; analysis that produces your action plan; transmission to the answer engines listed as subprocessors; and delivery of email you have asked for. Processing is limited to operating, securing and supporting the service.
Subprocessors and international transfers
The full list is published at /subprocessors, with what each receives. It is kept in the same repository as the code, so a provider cannot enter the request path without appearing there in the same change. Most of these providers are established in the United States, which means personal data is transferred outside the EEA; the transfer mechanism belongs in the signed agreement and has not been settled, because there is no entity to sign it.
Security measures
Row-level security in Postgres scopes every read and write to the owning account. Stored third-party credentials are encrypted with AES-GCM. Outbound fetches are guarded against server-side request forgery. Payment credentials are never received. Error reports carry no personal information. Access to production is limited to the founder. That last sentence is the honest measure of the current organisation, and it is what a one-person company can truthfully claim.
Return and deletion
Data can be exported from the product, and deletion is performed on request by writing to legal@brandclimbai.com. As stated in the privacy summary, deletion is a manual operation today rather than a scheduled one.
Request the reviewed DPA at legal@brandclimbai.com. This page is a product summary, not a signed agreement.