BrieflyWorks

Privacy Policy

How BrieflyWorks processes personal data when providing the website and business-assistant service.

Version and effective date: 2026-08-24

1. Controller

For account, website, contracting, support, security, and billing data, the controller is:

Louay Aousaji and Aziz Abderrahmane Ben Othmane
Connolystr. 3 80809
Email: loulouvicy@gmail.com

For business content uploaded or forwarded by a customer, the customer generally determines the purpose and means of processing and acts as controller. BrieflyWorks generally processes that content on the customer's documented instructions under the Data Processing Agreement.

2. Data we process

  • Account and contract data, including names, business details, login email, plan, acceptance records, and support messages.
  • Business content submitted by users, including notes, tasks, routines, customer follow-ups, staff references, website summaries, questions, and AI-generated results.
  • Forwarded-email data, including sender, recipients, subject, body, message metadata, and supported attached email files. Users must not forward unnecessary attachments.
  • Content from Notion pages that a customer explicitly shares with BrieflyWorks, together with page titles, links, edit times, sync status, AI-generated summaries, proposed operational insights, and the customer's approval decisions.
  • Technical and security data, including session data, IP-derived request information, timestamps, error logs, device/browser information supplied in requests, and webhook records.
  • Billing identifiers and subscription status. Full payment-card credentials are handled by Stripe or PayPal and are not stored by BrieflyWorks.

3. Purposes and legal bases

  • Providing accounts, subscriptions, requested AI features, and support: performance of a contract or steps requested before a contract, Article 6(1)(b) GDPR.
  • Security, abuse prevention, product reliability, and limited operational logs: legitimate interests, Article 6(1)(f) GDPR.
  • Accounting, tax, and lawful authority requests: compliance with legal obligations, Article 6(1)(c) GDPR.
  • Optional marketing communications, if introduced: consent under Article 6(1)(a) GDPR, which may be withdrawn at any time.

Where BrieflyWorks acts as processor, the customer is responsible for selecting a valid legal basis, giving required notices to employees, customers, suppliers, and other people, and limiting submitted data to what is necessary.

4. AI processing and human review

Submitted content may be sent to an AI model provider to extract tasks, draft summaries and email responses, organise business memory, and organise explicit source observations. Results may be inaccurate and require human review. Staff features do not assign performance scores and do not independently change employment status. BrieflyWorks is not intended to make solely automated decisions that produce legal or similarly significant effects, including hiring, dismissal, discipline, scheduling, credit, medical, or legal decisions.

5. Service providers and recipients

We use service providers only for defined operational purposes. Current categories and principal providers include:

  • Hosting and delivery: Vercel.
  • Database, authentication, and storage: Supabase and its configured infrastructure provider.
  • AI model processing: Anthropic.
  • Inbound email and webhook delivery: Resend.
  • Website retrieval fallback: Firecrawl, when a customer requests website analysis and direct retrieval fails.
  • Customer-selected workspace content integration: Notion, when a customer connects and shares pages.
  • Payments: Stripe and PayPal, which also process data under their own privacy notices for their independent payment obligations.
  • Domain and DNS services: Namecheap.

The current subprocessor list and contractual processing terms appear in the Data Processing Agreement. We may disclose data where legally required or necessary to establish, exercise, or defend legal claims.

6. International transfers

Some providers may process data outside Germany or the European Economic Area. Where required, transfers are based on an adequacy decision, the EU Standard Contractual Clauses, or another lawful safeguard described in the relevant provider agreement. Customers should review the DPA and subprocessor list before submitting personal data.

7. Retention and deletion

Account and business content is retained while the account is active and afterwards only as needed for deletion processing, backups, disputes, security, or legal retention duties. Payment and accounting records are retained for applicable statutory periods. Verified deletion requests are actioned without undue delay unless retention is legally required. Backup copies may remain for a limited rotation period and are protected from ordinary use.

8. Cookies and local storage

The service currently uses technically necessary session and security storage required for login and core functionality. It does not intentionally place advertising cookies. If optional analytics or marketing technologies are added, they will not be activated for users who require consent until an appropriate consent mechanism is available.

9. Your rights

Subject to the GDPR's conditions, individuals may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Consent may be withdrawn prospectively. Requests may be sent to loulouvicy@gmail.com. We may need to verify identity. Individuals may also complain to a competent data-protection supervisory authority, including the Bavarian State Office for Data Protection Supervision where applicable.

10. Required data and updates

Account and payment information marked as required is necessary to provide the service. Without it, an account or subscription cannot be supplied. We may update this notice when processing changes; material changes will be communicated through an appropriate channel.