PRIVACY, IN PLAIN LANGUAGE
Privacy policy
Illustrative policy · Updated 5 October 2026
1. Who we are and how we act
Brieflane Labs Limited is a fictional 8-person B2B SaaS startup registered in Ireland, with an illustrative office at 14 Example Quay, Dublin, Ireland (fictional address). We serve creative and digital agencies in the EU and US.
Our primary service is Brieflane Workspace. Brieflane Customer Portal is a separate client-facing service linked to an agency workspace. Our public marketing website is a third service.
We act as a processor for project content, client contacts, and approval records that agencies instruct us to handle. The agency is the controller and determines the purposes and legal basis for that content. Our fictional data processing agreement covers instructions, confidentiality, security, subprocessors, assistance with rights requests, and deletion.
We act as a controller for our own account administration, billing, fraud prevention, security, support, and consent-based marketing. Privacy contact: privacy@brieflane.example (illustrative; does not receive messages).
2. What we process and why
- Business-user accounts
- Agency staff names, work email addresses, roles, and authentication records.
- Client contact details
- Client names, work email addresses, organizations, and portal invitations.
- Requests and documents
- Project briefs, comments, uploaded files, and deliverables provided by agency teams and clients.
- Approval records
- Reviewer identity, decisions, timestamps, and document-version references.
- Usage and security logs
- IP addresses, device/browser information, access events, and service diagnostics.
We collect data directly from agency staff and invited clients through account setup, project requests, uploads, comments, and approvals. We generate operational logs as people use the product. Support messages and billing details are collected when needed.
| Purpose | Legal basis |
|---|---|
| Administer subscriptions and provide the service to contracting individuals | Performance of a contract |
| Manage business contacts, provide support, secure accounts, and prevent abuse | Legitimate interests in operating and protecting the service, balanced against individual rights |
| Maintain statutory invoices and accounting records | Legal obligation |
| Send optional marketing emails | Consent, withdrawable at any time |
Agency-controlled requests, documents, and approvals are processed to deliver the agency’s instructed workflow; the agency supplies its own lawful basis. We do not sell personal data or share it for cross-context behavioral advertising.
The product is not intended to process health data or other GDPR special-category personal data. Customers should not upload such information. We use no AI, send no customer data to AI providers, and train no models on it. We do not make automated decisions producing legal or similarly significant effects.
3. Hosting and supporting providers
Customers select EU hosting in AWS Ireland (eu-west-1) or US hosting in AWS Northern Virginia (us-east-1) when creating a workspace. Application compute, databases, file storage, usage/security logs, and backups stay in that region. The Customer Portal follows the Workspace region. Customer content is not replicated between the two regions.
Amazon Web Services (AWS)
Application compute, PostgreSQL database, object storage, logs, and backups.
Data: Accounts, client contacts, requests/documents, approvals, and logs.
Location: Ireland or Northern Virginia, following the selected workspace region.
Stripe
Subscription billing and payment processing.
Data: Billing contacts, invoice details, and payment information; no project documents.
Location: EU and US processing; not restricted to the workspace region.
Resend
Transactional notifications and opted-in marketing emails.
Data: Recipient names/emails and minimal notification content; no document attachments.
Location: US processing; not restricted to the workspace region.
Notification emails contain minimal information and a link back to the service, without uploaded documents or full project briefs. Billing and email processing do not inherit the workspace’s regional storage promise. Provider descriptions here are fictional configuration assumptions, not assertions about these vendors’ actual offerings.
4. International transfers
Cross-border transfers can occur for US-hosted workspaces, US email delivery, billing operations, or authorized provider support. Choosing EU hosting does not mean every supporting service processes data exclusively in the EU.
In this fictional scenario, we document international transfers, maintain processor agreements, and use the European Commission’s Standard Contractual Clauses where required. We assess destination-country risks and apply supplementary technical and organizational measures where needed, including encryption, access restrictions, and minimizing data sent to supporting providers. SCCs alone are not a guarantee of GDPR compliance.
Customers can request the fictional DPA, provider list, and transfer safeguards through privacy@brieflane.example. These documents and this mailbox are illustrative, not live services.
Background: EDPB guidance on Standard Contractual Clauses.
5. Retention and deletion
We have a documented retention policy. In the fictional product, account and project records remain while the workspace is active. On closure, customers have 30 days to export their data; we delete it from active systems by the end of that period. Deleted data expires from regional rolling backups within a further 35 days. Backups are restricted to recovery and are not used for routine processing.
Security logs are retained for 90 days, resolved support conversations for 12 months, and statutory billing records for six years, unless applicable obligations require otherwise. Marketing contact data is removed on withdrawal, apart from a minimal suppression record needed to honor the opt-out. Legal holds may delay deletion of specific records, with access restricted.
Agency administrators can request export or deletion of client records. Clients should contact their agency for agency-controlled content; Brieflane assists that agency under its instructions.
6. Your rights and requests
Subject to applicable conditions, individuals can request access, correction, erasure, restriction, portability, or object to processing. Consent can be withdrawn without affecting prior lawful processing. Requests are accepted by email at privacy@brieflane.example; no online request form is provided in this scenario.
Our standard response target is 30 days, within the GDPR requirement of one calendar month. If a complex request needs a permitted extension, we explain the reason within the initial month. We verify identity proportionately before disclosing or changing personal data, requesting only what is needed. Authorized representatives may act with proof of authority.
For agency-controlled data, we forward or direct requests to the agency and help it respond. Individuals can ask for an internal review of a refusal and lodge a complaint with Ireland’s Data Protection Commission or their local supervisory authority.
7. Emails, cookies, and tracking
The fictional product sends transactional emails for invitations, account security, request updates, and approvals. Optional marketing emails are sent only after a separate opt-in, with an unsubscribe link in every marketing email; withdrawal does not stop necessary service notifications.
The fictional authenticated services use essential session cookies for sign-in and security. They use no non-essential analytics or advertising cookies. The marketing website uses no analytics or advertising tracking and collects only basic hosting access logs; no consent banner is needed for application cookies because none are set on the actual static demo.
The actual demo has no email signup, cookie storage, live sessions, or tracking scripts.
8. Privacy governance and security
The fictional company has assessed its activities and has not appointed a statutory data protection officer. Privacy responsibilities belong to the operations lead, reachable through privacy@brieflane.example. As an Irish-established business, it has no separate EU representative.
Production customer data is not used in development or testing; those environments use synthetic data. Documented controls include encryption, role-based access, region-specific backups, and an incident notification process. Our first formal incident-response exercise and independent penetration test remain pending. See Security & providers for details.
These practices illustrate GDPR readiness. They do not establish certification, guaranteed compliance, or the existence of a real company.