Privacy Policy

How BriefMaster 3000 collects, uses, stores and protects your data, under the EU GDPR and the Swiss revFADP.

BriefMaster 3000 is operated by kreisvier communications AG, Thiersteinerallee 29, CH-4053 Basel, Switzerland ("we", "us"). This policy explains what data we collect, why, where it is stored, and what rights you have. It applies to www.briefmaster3000.com and the BriefMaster 3000 application.

1. Who is responsible

For your account data — the details you provide to register and run a subscription — we are the data controller.

For the content you create inside briefs, including any personal data you choose to put there, you (or your organisation) are the controller and we act as your processor, processing that content only on your instructions.

Data protection contact: support@briefmaster3000.com

2. What we collect and why

DataPurposeLegal basis
Name, email, organisationCreate and operate your accountContract (GDPR Art. 6(1)(b))
Authentication credentialsSign you in securely — handled by Clerk, never stored by us in plain textContract
Brief content you createProvide the service to you and your workspaceContract
Billing detailsProcess subscription payments — card data handled by Stripe, never by usContract / legal obligation
Product usage eventsUnderstand which features are used, to improve the productConsent / legitimate interest
Server and security logsDetect abuse, debug faults, keep the service availableLegitimate interest (GDPR Art. 6(1)(f))
Website analytics (public pages)Measure marketing effectivenessConsent — set via the cookie banner
Advertising (Google Ads)Measure which ads lead to sign-ups, and show our ads to past visitors on other websitesConsent — set via the cookie banner
Email address and languageRelease notes, subscriber benefits, early access to new features and programmes, and tips — only if you sign upConsent (GDPR Art. 6(1)(a)) — withdraw any time

Release notes and subscriber updates are opt-in. Sign up on our website and we first email you a link to confirm the address is really yours (double opt-in); in the app, you switch them on in your account settings. For this we use your email address, your language, the dates you subscribed or unsubscribed and, if you have an account, your first name for the greeting — nothing else. The list is stored in our database in Frankfurt and the emails are sent through Resend's EU infrastructure. Every email has a one-click unsubscribe link. When you unsubscribe we keep a note of the opt-out so you are not emailed again; ask us and we delete the entry entirely.

We do not collect special categories of personal data, and we ask that you do not place them in briefs.

3. Where your data is stored

Brief content and account records are stored in MongoDB Atlas in Frankfurt, Germany. The application runs on Render in Frankfurt. Product analytics run on PostHog's EU instance in Frankfurt. Your brief content does not leave the EU.

Sign-in (Clerk), payments (Stripe) and email (Resend) run on those providers' EU-hosted services. The only processing that may reach outside the EEA is the marketing tags on our public website (Google), which load only if you accept them in the cookie banner, and optional integrations a workspace chooses to connect (Asana, Microsoft 365). Those transfers are covered by EU Standard Contractual Clauses. Switzerland benefits from an EU adequacy decision, so transfers between the EEA and Switzerland require no additional safeguards.

4. Sub-processors

We use the following sub-processors to operate the service. The current list is always published on our Trust & Security page, and we notify customers of material changes before they take effect.

ProviderPurposeLocation
MongoDB AtlasPrimary database — brief content and account recordsFrankfurt, Germany (EU)
RenderApplication and API hostingFrankfurt, Germany (EU)
ClerkAuthentication and session managementEU
StripePayment processing and invoicingEU
PostHogProduct analytics (EU instance, no session recording)Frankfurt, Germany (EU)
ResendEmail — account and collaboration notifications, and release notes for subscribersDublin, Ireland (EU)

Asana and Microsoft 365 are optional integrations. They receive data only if a workspace administrator connects them and a user explicitly triggers an action.

5. What we never do

  • We do not sell, rent or trade your personal data. There is no advertising business model here.
  • We do not use your brief content to train AI models — ours or anyone else's.
  • We do not share your data with third parties beyond the sub-processors listed above.
  • Inside the application we run no advertising or cross-site tracking, except one Google Ads measurement when a new account is created — and only if you accepted cookies.

6. How long we keep it

Account and brief data are retained while your account is active. When you delete your account or workspace, personal data and brief content are permanently removed within 30 days, including from backups on their normal rotation.

Invoicing records are retained for 10 years where Swiss commercial law requires it. Aggregated, anonymised statistics that cannot be linked to a person may be retained indefinitely.

7. Security

All traffic is served over TLS 1.2 or higher with HSTS enforced. Data at rest is encrypted with AES-256. Access to production is restricted to named engineers on a least-privilege basis. Briefs are scoped to a workspace at the database level, and fields marked internal are filtered server-side before they reach a client or guest.

Report a security issue to security@briefmaster3000.com. We acknowledge reports within two business days.

8. Cookies

The application sets only strictly necessary cookies for authentication and session management. Our public marketing pages additionally use analytics and advertising cookies (PostHog, Google Ads), which load only after you consent via the cookie banner. See our Cookie Policy for the full list.

9. Your rights

Under the GDPR and the Swiss revFADP you have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.

To exercise any of these, write to support@briefmaster3000.com. We respond within 30 days and do not charge for reasonable requests. If your data sits inside a customer workspace, we will forward your request to that workspace's controller and support them in answering it.

You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, your national data protection authority.

10. Data processing agreement

A DPA covering GDPR Art. 28 obligations, our sub-processor list and Standard Contractual Clauses is available for all paid plans. Request one at support@briefmaster3000.com.

11. Changes to this policy

We update this policy when our processing changes. Material changes are announced in-app or by email at least 14 days before they take effect. The date at the top of this page always reflects the current version.

12. Contact

kreisvier communications AG
Thiersteinerallee 29
CH-4053 Basel
Switzerland
support@briefmaster3000.com