Privacy Policy — Pilot
Last updated: 29 June 2026.
BRAIKE — Pilot service (AI Ad Manager)
This policy describes how BRAIKE processes your personal data as data controller when you access or use the Service (the “Privacy Policy” or “Policy”); it forms part of the GTCS between you and BRAIKE. This Policy is drafted in accordance with Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act No. 78-17, as amended.
1. Who are we?
Data controller: BRAIKE, a simplified joint-stock company (SAS) with share capital of EUR 20,000, registered office at 18 bis rue de Villiers, 92300 Levallois-Perret, registered with the Nanterre Trade and Companies Register under number 106 573 983. Data protection contact: Edris PAIKAN — contact@braike.com.
With respect to BRAIKE’s processing of your own clients’ data for the purpose of providing the Service, you (or your client, where you act as a processor on behalf of a third-party controller of such data) remain the controller of that processing and we act as processor within the meaning of Article 28 GDPR, under the conditions set out in the Data Processing Agreement between BRAIKE and you (“DPA”).
2. What data do we collect?
2.1 Account data. Email address, identifier, name and OAuth profile; workspace(s) and role (owner/admin/editor/viewer).
2.2 Platform connection data. Encrypted OAuth tokens (AES-GCM); connected advertising accounts (external identifier, name, currency, time zone).
2.3 Conversations and AI. Conversation content (text and voice queries from Pilot Call mode, AI responses); documents provided for context (RAG) and their vector representations (embeddings).
2.4 Usage and logs. Action audit log (author, tool, platform, risk level, parameters with redacted secrets, outcome, duration, IP address, timestamp), usage events and counters (credits), strategies, automations and scheduled prompts, voice-mode errors.
2.5 Technical data. IP addresses, user agent, session identifiers and technical metadata, in particular recorded in the action audit log.
Sensitive data: no special category of personal data is required to use the Service. The Client expressly refrains from providing any sensitive data to BRAIKE.
3. Why do we collect your data?
| Purpose | Legal basis (Art. 6 GDPR) | Data concerned |
|---|---|---|
| Creation and management of the account and workspaces | Performance of the contract | Account, profile, roles |
| Connection to advertising accounts | Performance of the contract | OAuth tokens |
| Advertising management and execution of actions | Performance of the contract | Campaign data, audit logs |
| Assistance via conversational and voice AI | Performance of the contract | Conversation content, RAG documents |
| Usage measurement and credit management | Performance of the contract | Usage events and counters |
| Billing and subscription | Performance of the contract / legal obligation (accounting) | Billing data |
| Security, logging, abuse prevention | Performance of the contract / legitimate interest | Logs, connection data |
| Improvement of our products or development of new products (e.g. research, aggregated and anonymous statistics) | Legitimate interest | Aggregated usage data, aggregated and de-identified statistics, feedback |
4. Automated decision-making and profiling
BRAIKE does not carry out any solely automated decision-making producing legal effects concerning you or similarly significantly affecting you within the meaning of Article 22 GDPR. The AI assistance tool provides analyses and suggestions subject to your validation; no action is applied without your intervention.
5. With whom do we share your data?
| Recipient | Role | Location | Transfer safeguard |
|---|---|---|---|
| Supabase | Database, authentication, real-time, storage | European Union (AWS infra.) | No transfer outside the EU |
| Vercel Inc. | Application hosting (front end + API) | United States | DPF-certified |
| Google Cloud (Cloud Run) | MCP microservices (connectors) | European Union (europe-west1, Dublin) | Google DPA; no transfer outside the EU |
| Google LLC (Gemini) | Conversational and voice AI | United States | DPF (to be confirmed on the list) |
| Google Ads / Meta / TikTok | Reading and writing of campaigns | United States / China (TikTok) | OAuth consent; DPF (Google, Meta); SCCs + TIA (TikTok) |
| Resend Inc. | Transactional emails | United States | DPF-certified |
| Upstash | Cache, rate limiting, vectors | European Union | No transfer outside the EU |
| Inngest Inc. | Scheduled jobs (token refresh) | United States | SCCs + TIA (not DPF-certified) |
| E2B | Isolated code-execution sandbox (advanced features) | United States [to be confirmed] | SCCs + TIA; DPA to be verified |
| Optional connectors (GA4, GSC, CRM, Gmail…) | Enabled at the user’s request | Variable | OAuth consent; DPF/SCCs as applicable |
6. Transfers outside the EU
Our databases (Supabase), our connector microservices (Google Cloud Run, Dublin) and our cache (Upstash) are located within the European Union. Transfers outside the EEA occur to: United States — Vercel and Resend are certified under the Data Privacy Framework (DPF); Google and Meta participate in it; Inngest and E2B are not certified and rely on Standard Contractual Clauses (SCCs, EU 2021/914), supplemented by a transfer impact assessment; China (TikTok / ByteDance) — SCCs, supplemented by a transfer impact assessment and enhanced measures.
7. How long do we keep your data?
| Data type | Retention period |
|---|---|
| Account and workspaces | Term of the contract, then deletion within 30 days after termination (subject to BRAIKE’s compliance with its legal obligations) |
| OAuth tokens | As long as the connection is active; deleted upon disconnection |
| Conversation content and RAG documents | Term of the account + 12 months |
| Billing data | 10 years (accounting obligation, Article L.123-22 of the French Commercial Code) |
| Audit and security logs | 6 to 12 months |
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, as well as the right to issue post-mortem directives (instructions regarding the fate of your data after death). You may exercise them with contact@braike.com; we respond within one month. You may also lodge a complaint with the CNIL (www.cnil.fr).
9. Cookies
BRAIKE’s use of any cookie relating to the Service is governed by the Cookie Policy.
10. Security
Two-factor authentication (TOTP), HTTPS/TLS, encryption of OAuth tokens at rest (AES-256-GCM), data isolation per workspace (PostgreSQL Row-Level Security) preventing any client-side reading of tokens, tamper-proof action audit log with redaction of secrets, circuit breaker, rate limiting and quotas, and server-side secrets management.
11. Amendments to this Policy
BRAIKE may amend any provision of this Policy at any time, including to reflect legal, technical or functional developments, provided that it notifies the Client of any material change at least thirty (30) days before its entry into force. Should the Client refuse to accept a change, the Client may terminate the Contract under the conditions set out in the GTCS. The date of the latest version in force appears at the top of this Policy.
12. Contact us
Email / personal data: contact@braike.com — Address: 18 bis rue de Villiers, 92300 Levallois-Perret.
Governing language
This document is an English translation provided for information purposes only. The French-language version is the sole authoritative version and shall prevail in the event of any discrepancy or divergence of interpretation.