Privacy Policy

How BriefMaster 3000 collects, uses, stores and protects your data — under the EU GDPR and the Swiss revFADP.

BriefMaster 3000 is operated by kreisvier communications AG, Thiersteinerallee 29, CH-4053 Basel, Switzerland ("we", "us"). This policy explains what data we collect, why, where it is stored, and what rights you have. It applies to www.briefmaster3000.com and the BriefMaster 3000 application.

1. Who is responsible

For your account data — the details you provide to register and run a subscription — we are the data controller.

For the content you create inside briefs, including any personal data you choose to put there, you (or your organisation) are the controller and we act as your processor, processing that content only on your instructions.

Data protection contact: privacy@briefmaster3000.com

2. What we collect and why

DataPurposeLegal basis
Name, email, organisationCreate and operate your accountContract (GDPR Art. 6(1)(b))
Authentication credentialsSign you in securely — handled by Clerk, never stored by us in plain textContract
Brief content you createProvide the service to you and your workspaceContract
Billing detailsProcess subscription payments — card data handled by Stripe, never by usContract / legal obligation
Product usage eventsUnderstand which features are used, to improve the productConsent / legitimate interest
Server and security logsDetect abuse, debug faults, keep the service availableLegitimate interest (GDPR Art. 6(1)(f))
Website analytics (public pages)Measure marketing effectivenessConsent — set via the cookie banner

We do not collect special categories of personal data, and we ask that you do not place them in briefs.

3. Where your data is stored

Brief content and account records are stored in MongoDB Atlas in Frankfurt, Germany. The application runs on Render in Frankfurt. Product analytics run on PostHog's EU instance in Frankfurt. Your brief content does not leave the EU.

Some supporting services — authentication, payments, transactional email, and marketing analytics on our public website — are operated by providers who may process limited data outside the EEA. Those transfers are covered by EU Standard Contractual Clauses. Switzerland benefits from an EU adequacy decision, so transfers between the EEA and Switzerland require no additional safeguards.

4. Sub-processors

We use the following sub-processors to operate the service. The current list is always published on our Trust & Security page, and we notify customers of material changes before they take effect.

ProviderPurposeLocation
MongoDB AtlasPrimary database — brief content and account recordsFrankfurt, Germany (EU)
RenderApplication and API hostingFrankfurt, Germany (EU)
ClerkAuthentication and session managementEU / USA
StripePayment processing and invoicingEU / USA
PostHogProduct analytics (EU instance, no session recording)Frankfurt, Germany (EU)
ResendTransactional email (invitations, notifications)EU / USA
HubSpotMarketing website analytics and CRM — public pages only, never brief contentEU / USA

Asana and Microsoft 365 are optional integrations. They receive data only if a workspace administrator connects them and a user explicitly triggers an action.

5. What we never do

  • We do not sell, rent or trade your personal data. There is no advertising business model here.
  • We do not use your brief content to train AI models — ours or anyone else's.
  • We do not share your data with third parties beyond the sub-processors listed above.
  • We do not run advertising or cross-site tracking cookies in the application.

6. How long we keep it

Account and brief data are retained while your account is active. When you delete your account or workspace, personal data and brief content are permanently removed within 30 days, including from backups on their normal rotation.

Invoicing records are retained for 10 years where Swiss commercial law requires it. Aggregated, anonymised statistics that cannot be linked to a person may be retained indefinitely.

7. Security

All traffic is served over TLS 1.2 or higher with HSTS enforced. Data at rest is encrypted with AES-256. Access to production is restricted to named engineers on a least-privilege basis. Briefs are scoped to a workspace at the database level, and fields marked internal are filtered server-side before they reach a client or guest.

Report a security issue to security@briefmaster3000.com. We acknowledge reports within two business days.

8. Cookies

The application sets only strictly necessary cookies for authentication and session management. Our public marketing pages additionally use analytics cookies, which load only after you consent via the cookie banner. See our Cookie Policy for the full list.

9. Your rights

Under the GDPR and the Swiss revFADP you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.

To exercise any of these, write to privacy@briefmaster3000.com. We respond within 30 days and do not charge for reasonable requests. If your data sits inside a customer workspace, we will forward your request to that workspace's controller and support them in answering it.

You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your national data protection authority.

10. Data processing agreement

A DPA covering GDPR Art. 28 obligations, our sub-processor list and Standard Contractual Clauses is available for all paid plans. Request one at privacy@briefmaster3000.com.

11. Changes to this policy

We update this policy when our processing changes. Material changes are announced in-app or by email at least 14 days before they take effect. The date at the top of this page always reflects the current version.

12. Contact

kreisvier communications AG
Thiersteinerallee 29
CH-4053 Basel
Switzerland
privacy@briefmaster3000.com