Fictional startup · A Plyco onboarding & compliance demo About Plyco
← Back to Brieflane

PRIVACY, IN PLAIN LANGUAGE

Privacy policy

Illustrative policy · Updated 5 October 2026

Fictional business policyThis policy describes the invented Brieflane product for Plyco onboarding. The actual demo is static: no accounts, uploads, analytics, application cookies, or contact submissions. Hosting infrastructure may process visitor IP addresses and access logs to deliver and protect this site. All contacts below are non-deliverable examples.

1. Who we are and how we act

Brieflane Labs Limited is a fictional 8-person B2B SaaS startup registered in Ireland, with an illustrative office at 14 Example Quay, Dublin, Ireland (fictional address). We serve creative and digital agencies in the EU and US.

Our primary service is Brieflane Workspace. Brieflane Customer Portal is a separate client-facing service linked to an agency workspace. Our public marketing website is a third service.

We act as a processor for project content, client contacts, and approval records that agencies instruct us to handle. The agency is the controller and determines the purposes and legal basis for that content. Our fictional data processing agreement covers instructions, confidentiality, security, subprocessors, assistance with rights requests, and deletion.

We act as a controller for our own account administration, billing, fraud prevention, security, support, and consent-based marketing. Privacy contact: privacy@brieflane.example (illustrative; does not receive messages).

2. What we process and why

Business-user accounts
Agency staff names, work email addresses, roles, and authentication records.
Client contact details
Client names, work email addresses, organizations, and portal invitations.
Requests and documents
Project briefs, comments, uploaded files, and deliverables provided by agency teams and clients.
Approval records
Reviewer identity, decisions, timestamps, and document-version references.
Usage and security logs
IP addresses, device/browser information, access events, and service diagnostics.

We collect data directly from agency staff and invited clients through account setup, project requests, uploads, comments, and approvals. We generate operational logs as people use the product. Support messages and billing details are collected when needed.

Controller processing purposes and legal bases in the fictional business
PurposeLegal basis
Administer subscriptions and provide the service to contracting individualsPerformance of a contract
Manage business contacts, provide support, secure accounts, and prevent abuseLegitimate interests in operating and protecting the service, balanced against individual rights
Maintain statutory invoices and accounting recordsLegal obligation
Send optional marketing emailsConsent, withdrawable at any time

Agency-controlled requests, documents, and approvals are processed to deliver the agency’s instructed workflow; the agency supplies its own lawful basis. We do not sell personal data or share it for cross-context behavioral advertising.

The product is not intended to process health data or other GDPR special-category personal data. Customers should not upload such information. We use no AI, send no customer data to AI providers, and train no models on it. We do not make automated decisions producing legal or similarly significant effects.

3. Hosting and supporting providers

Customers select EU hosting in AWS Ireland (eu-west-1) or US hosting in AWS Northern Virginia (us-east-1) when creating a workspace. Application compute, databases, file storage, usage/security logs, and backups stay in that region. The Customer Portal follows the Workspace region. Customer content is not replicated between the two regions.

Amazon Web Services (AWS)

Application compute, PostgreSQL database, object storage, logs, and backups.

Data: Accounts, client contacts, requests/documents, approvals, and logs.

Location: Ireland or Northern Virginia, following the selected workspace region.

Stripe

Subscription billing and payment processing.

Data: Billing contacts, invoice details, and payment information; no project documents.

Location: EU and US processing; not restricted to the workspace region.

Resend

Transactional notifications and opted-in marketing emails.

Data: Recipient names/emails and minimal notification content; no document attachments.

Location: US processing; not restricted to the workspace region.

Notification emails contain minimal information and a link back to the service, without uploaded documents or full project briefs. Billing and email processing do not inherit the workspace’s regional storage promise. Provider descriptions here are fictional configuration assumptions, not assertions about these vendors’ actual offerings.

4. International transfers

Cross-border transfers can occur for US-hosted workspaces, US email delivery, billing operations, or authorized provider support. Choosing EU hosting does not mean every supporting service processes data exclusively in the EU.

In this fictional scenario, we document international transfers, maintain processor agreements, and use the European Commission’s Standard Contractual Clauses where required. We assess destination-country risks and apply supplementary technical and organizational measures where needed, including encryption, access restrictions, and minimizing data sent to supporting providers. SCCs alone are not a guarantee of GDPR compliance.

Customers can request the fictional DPA, provider list, and transfer safeguards through privacy@brieflane.example. These documents and this mailbox are illustrative, not live services.

Background: EDPB guidance on Standard Contractual Clauses.

5. Retention and deletion

We have a documented retention policy. In the fictional product, account and project records remain while the workspace is active. On closure, customers have 30 days to export their data; we delete it from active systems by the end of that period. Deleted data expires from regional rolling backups within a further 35 days. Backups are restricted to recovery and are not used for routine processing.

Security logs are retained for 90 days, resolved support conversations for 12 months, and statutory billing records for six years, unless applicable obligations require otherwise. Marketing contact data is removed on withdrawal, apart from a minimal suppression record needed to honor the opt-out. Legal holds may delay deletion of specific records, with access restricted.

Agency administrators can request export or deletion of client records. Clients should contact their agency for agency-controlled content; Brieflane assists that agency under its instructions.

6. Your rights and requests

Subject to applicable conditions, individuals can request access, correction, erasure, restriction, portability, or object to processing. Consent can be withdrawn without affecting prior lawful processing. Requests are accepted by email at privacy@brieflane.example; no online request form is provided in this scenario.

Our standard response target is 30 days, within the GDPR requirement of one calendar month. If a complex request needs a permitted extension, we explain the reason within the initial month. We verify identity proportionately before disclosing or changing personal data, requesting only what is needed. Authorized representatives may act with proof of authority.

For agency-controlled data, we forward or direct requests to the agency and help it respond. Individuals can ask for an internal review of a refusal and lodge a complaint with Ireland’s Data Protection Commission or their local supervisory authority.

7. Emails, cookies, and tracking

The fictional product sends transactional emails for invitations, account security, request updates, and approvals. Optional marketing emails are sent only after a separate opt-in, with an unsubscribe link in every marketing email; withdrawal does not stop necessary service notifications.

The fictional authenticated services use essential session cookies for sign-in and security. They use no non-essential analytics or advertising cookies. The marketing website uses no analytics or advertising tracking and collects only basic hosting access logs; no consent banner is needed for application cookies because none are set on the actual static demo.

The actual demo has no email signup, cookie storage, live sessions, or tracking scripts.

8. Privacy governance and security

The fictional company has assessed its activities and has not appointed a statutory data protection officer. Privacy responsibilities belong to the operations lead, reachable through privacy@brieflane.example. As an Irish-established business, it has no separate EU representative.

Production customer data is not used in development or testing; those environments use synthetic data. Documented controls include encryption, role-based access, region-specific backups, and an incident notification process. Our first formal incident-response exercise and independent penetration test remain pending. See Security & providers for details.

These practices illustrate GDPR readiness. They do not establish certification, guaranteed compliance, or the existence of a real company.