How BriefMaster 3000 collects, uses, stores and protects your data — under the EU GDPR and the Swiss revFADP.
BriefMaster 3000 is operated by kreisvier communications AG, Thiersteinerallee 29, CH-4053 Basel, Switzerland ("we", "us"). This policy explains what data we collect, why, where it is stored, and what rights you have. It applies to www.briefmaster3000.com and the BriefMaster 3000 application.
For your account data — the details you provide to register and run a subscription — we are the data controller.
For the content you create inside briefs, including any personal data you choose to put there, you (or your organisation) are the controller and we act as your processor, processing that content only on your instructions.
Data protection contact: privacy@briefmaster3000.com
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, organisation | Create and operate your account | Contract (GDPR Art. 6(1)(b)) |
| Authentication credentials | Sign you in securely — handled by Clerk, never stored by us in plain text | Contract |
| Brief content you create | Provide the service to you and your workspace | Contract |
| Billing details | Process subscription payments — card data handled by Stripe, never by us | Contract / legal obligation |
| Product usage events | Understand which features are used, to improve the product | Consent / legitimate interest |
| Server and security logs | Detect abuse, debug faults, keep the service available | Legitimate interest (GDPR Art. 6(1)(f)) |
| Website analytics (public pages) | Measure marketing effectiveness | Consent — set via the cookie banner |
We do not collect special categories of personal data, and we ask that you do not place them in briefs.
Brief content and account records are stored in MongoDB Atlas in Frankfurt, Germany. The application runs on Render in Frankfurt. Product analytics run on PostHog's EU instance in Frankfurt. Your brief content does not leave the EU.
Some supporting services — authentication, payments, transactional email, and marketing analytics on our public website — are operated by providers who may process limited data outside the EEA. Those transfers are covered by EU Standard Contractual Clauses. Switzerland benefits from an EU adequacy decision, so transfers between the EEA and Switzerland require no additional safeguards.
We use the following sub-processors to operate the service. The current list is always published on our Trust & Security page, and we notify customers of material changes before they take effect.
| Provider | Purpose | Location |
|---|---|---|
| MongoDB Atlas | Primary database — brief content and account records | Frankfurt, Germany (EU) |
| Render | Application and API hosting | Frankfurt, Germany (EU) |
| Clerk | Authentication and session management | EU / USA |
| Stripe | Payment processing and invoicing | EU / USA |
| PostHog | Product analytics (EU instance, no session recording) | Frankfurt, Germany (EU) |
| Resend | Transactional email (invitations, notifications) | EU / USA |
| HubSpot | Marketing website analytics and CRM — public pages only, never brief content | EU / USA |
Asana and Microsoft 365 are optional integrations. They receive data only if a workspace administrator connects them and a user explicitly triggers an action.
Account and brief data are retained while your account is active. When you delete your account or workspace, personal data and brief content are permanently removed within 30 days, including from backups on their normal rotation.
Invoicing records are retained for 10 years where Swiss commercial law requires it. Aggregated, anonymised statistics that cannot be linked to a person may be retained indefinitely.
All traffic is served over TLS 1.2 or higher with HSTS enforced. Data at rest is encrypted with AES-256. Access to production is restricted to named engineers on a least-privilege basis. Briefs are scoped to a workspace at the database level, and fields marked internal are filtered server-side before they reach a client or guest.
Report a security issue to security@briefmaster3000.com. We acknowledge reports within two business days.
The application sets only strictly necessary cookies for authentication and session management. Our public marketing pages additionally use analytics cookies, which load only after you consent via the cookie banner. See our Cookie Policy for the full list.
Under the GDPR and the Swiss revFADP you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.
To exercise any of these, write to privacy@briefmaster3000.com. We respond within 30 days and do not charge for reasonable requests. If your data sits inside a customer workspace, we will forward your request to that workspace's controller and support them in answering it.
You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your national data protection authority.
A DPA covering GDPR Art. 28 obligations, our sub-processor list and Standard Contractual Clauses is available for all paid plans. Request one at privacy@briefmaster3000.com.
We update this policy when our processing changes. Material changes are announced in-app or by email at least 14 days before they take effect. The date at the top of this page always reflects the current version.
kreisvier communications AG
Thiersteinerallee 29
CH-4053 Basel
Switzerland
privacy@briefmaster3000.com