Privacy Policy — Pilot

Last updated: 29 June 2026.

BRAIKE — Pilot service (AI Ad Manager)

This policy describes how BRAIKE processes your personal data as data controller when you access or use the Service (the “Privacy Policy” or “Policy”); it forms part of the GTCS between you and BRAIKE. This Policy is drafted in accordance with Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act No. 78-17, as amended.

1. Who are we?

Data controller: BRAIKE, a simplified joint-stock company (SAS) with share capital of EUR 20,000, registered office at 18 bis rue de Villiers, 92300 Levallois-Perret, registered with the Nanterre Trade and Companies Register under number 106 573 983. Data protection contact: Edris PAIKAN — contact@braike.com.

With respect to BRAIKE’s processing of your own clients’ data for the purpose of providing the Service, you (or your client, where you act as a processor on behalf of a third-party controller of such data) remain the controller of that processing and we act as processor within the meaning of Article 28 GDPR, under the conditions set out in the Data Processing Agreement between BRAIKE and you (“DPA”).

2. What data do we collect?

2.1 Account data. Email address, identifier, name and OAuth profile; workspace(s) and role (owner/admin/editor/viewer).

2.2 Platform connection data. Encrypted OAuth tokens (AES-GCM); connected advertising accounts (external identifier, name, currency, time zone).

2.3 Conversations and AI. Conversation content (text and voice queries from Pilot Call mode, AI responses); documents provided for context (RAG) and their vector representations (embeddings).

2.4 Usage and logs. Action audit log (author, tool, platform, risk level, parameters with redacted secrets, outcome, duration, IP address, timestamp), usage events and counters (credits), strategies, automations and scheduled prompts, voice-mode errors.

2.5 Technical data. IP addresses, user agent, session identifiers and technical metadata, in particular recorded in the action audit log.

Sensitive data: no special category of personal data is required to use the Service. The Client expressly refrains from providing any sensitive data to BRAIKE.

3. Why do we collect your data?

PurposeLegal basis (Art. 6 GDPR)Data concerned
Creation and management of the account and workspacesPerformance of the contractAccount, profile, roles
Connection to advertising accountsPerformance of the contractOAuth tokens
Advertising management and execution of actionsPerformance of the contractCampaign data, audit logs
Assistance via conversational and voice AIPerformance of the contractConversation content, RAG documents
Usage measurement and credit managementPerformance of the contractUsage events and counters
Billing and subscriptionPerformance of the contract / legal obligation (accounting)Billing data
Security, logging, abuse preventionPerformance of the contract / legitimate interestLogs, connection data
Improvement of our products or development of new products (e.g. research, aggregated and anonymous statistics)Legitimate interestAggregated usage data, aggregated and de-identified statistics, feedback

4. Automated decision-making and profiling

BRAIKE does not carry out any solely automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. The AI assistance tool provides analyses and suggestions subject to your validation; no action is applied without your intervention.

5. With whom do we share your data?

RecipientRoleLocationTransfer safeguard
SupabaseDatabase, authentication, real-time, storageEuropean Union (AWS infra.)No transfer outside the EU
Vercel Inc.Application hosting (front end + API)United StatesDPF-certified
Google Cloud (Cloud Run)MCP microservices (connectors)European Union (europe-west1, Dublin)Google DPA; no transfer outside the EU
Google LLC (Gemini)Conversational and voice AIUnited StatesDPF (to be confirmed on the list)
Google Ads / Meta / TikTokReading and writing of campaignsUnited States / China (TikTok)OAuth consent; DPF (Google, Meta); SCCs + TIA (TikTok)
Resend Inc.Transactional emailsUnited StatesDPF-certified
UpstashCache, rate limiting, vectorsEuropean UnionNo transfer outside the EU
Inngest Inc.Scheduled jobs (token refresh)United StatesSCCs + TIA (not DPF-certified)
E2BIsolated code-execution sandbox (advanced features)United States [to be confirmed]SCCs + TIA; DPA to be verified
Optional connectors (GA4, GSC, CRM, Gmail…)Enabled at the user’s requestVariableOAuth consent; DPF/SCCs as applicable

6. Transfers outside the EU

Our databases (Supabase), our connector microservices (Google Cloud Run, Dublin) and our cache (Upstash) are located within the European Union. Transfers outside the EEA occur to: United States — Vercel and Resend are certified under the Data Privacy Framework (DPF); Google and Meta participate in it; Inngest and E2B are not certified and rely on Standard Contractual Clauses (SCCs, EU 2021/914), supplemented by a transfer impact assessment; China (TikTok / ByteDance) — SCCs, supplemented by a transfer impact assessment and enhanced measures.

7. How long do we keep your data?

Data typeRetention period
Account and workspacesTerm of the contract, then deletion within 30 days after termination (subject to BRAIKE’s compliance with its legal obligations)
OAuth tokensAs long as the connection is active; deleted upon disconnection
Conversation content and RAG documentsTerm of the account + 12 months
Billing data10 years (accounting obligation, Article L.123-22 of the French Commercial Code)
Audit and security logs6 to 12 months

8. Your rights

You have the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, as well as the right to issue post-mortem directives (instructions regarding the fate of your data after death). You may exercise them with contact@braike.com; we respond within one month. You may also lodge a complaint with the CNIL (www.cnil.fr).

9. Cookies

BRAIKE’s use of any cookie relating to the Service is governed by the Cookie Policy.

10. Security

Two-factor authentication (TOTP), HTTPS/TLS, encryption of OAuth tokens at rest (AES-256-GCM), data isolation per workspace (PostgreSQL Row-Level Security) preventing any client-side reading of tokens, tamper-proof action audit log with redaction of secrets, circuit breaker, rate limiting and quotas, and server-side secrets management.

11. Amendments to this Policy

BRAIKE may amend any provision of this Policy at any time, including to reflect legal, technical or functional developments, provided that it notifies the Client of any material change at least thirty (30) days before its entry into force. Should the Client refuse to accept a change, the Client may terminate the Contract under the conditions set out in the GTCS. The date of the latest version in force appears at the top of this Policy.

12. Contact us

Email / personal data: contact@braike.com — Address: 18 bis rue de Villiers, 92300 Levallois-Perret.

Governing language

This document is an English translation provided for information purposes only. The French-language version is the sole authoritative version and shall prevail in the event of any discrepancy or divergence of interpretation.