Privacy policy
Version: 2026-07-28 · Effective: 2026-08-11
brainattic is a knowledge-base service that your team — and the AI agents you connect — read from and write to. We keep core Service data on FSS-controlled infrastructure in the European Union, do not send Customer Content to a third-party AI model, and collect only what we need to run, secure, and support the Service.
1. Who we are
The Service and the brainattic.ai website are operated by Finite Software Systems Ltd. (Bulgarian: ФИНИТ Софтуер Системс ЕООД) ("FSS", "we", "us"), the provider of the brainattic product.
- Registered office: 4 Gorotzvet Street, Sofia, Bulgaria
- Company No. (ЕИК): 175276896 · VAT: BG175276896
- Privacy contact: privacy@brainattic.ai
- Data Protection Officer: none appointed (not required at our scale); privacy enquiries are handled through the contact above.
- Supervisory authority: Commission for Personal Data Protection (CPDP), Sofia, Bulgaria — www.cpdp.bg
2. Scope
This notice covers (a) the brainattic.ai website and its public contact and registration surfaces and (b) the brainattic Service — the knowledge-base web application and the connector that exposes it to AI clients over the Model Context Protocol (MCP). brainattic is a business-to-business service for organisations and their authorised users aged 18 or over. It is not directed to consumers or children.
3. Controller and processor — who decides what
The split matters because it determines who is responsible for which data:
- Customer Content and customer-directed service records — documents, attachments, search queries, reminders, and in-product audit entries created through your organisation's use of brainattic, including personal data you choose to put in them. Here your organisation is the controller and FSS is a processor acting on documented instructions. This processing is governed by our Data Processing Agreement.
- Account, identity, authentication, access-control, contract-acceptance, website, support, marketing, and operational security data — described below. Here FSS is the controller because FSS determines why and how that data is used to operate, secure, administer, and support the Service.
4. What we process
Account and identity data (FSS as controller). Name, work email, organisation, a securely hashed password where you set one, provider account identifiers and identity claims returned by a sign-in provider (such as name, email, and email-verification status), workspace membership and role, and OAuth/session tokens used to authenticate and authorise you.
Customer Content (FSS as processor). Documents, attachments, vector embeddings derived from content, search queries, reminders, and in-product audit entries — plus personal data your organisation chooses to include.
Reminder-delivery data (FSS as processor). The content and destination needed for a channel your organisation enables: an email address, a Slack member ID, or a mobile phone number.
Contract and registration evidence (FSS as controller). Company/workspace name, the policy bundle, document versions and content hashes presented to you, locale, acceptance time and source, and limited request metadata such as IP address, user agent, and request/correlation identifier. We use this evidence to establish and administer the customer relationship and demonstrate what was accepted.
Technical and security data (FSS as controller). IP address, timestamps, endpoint/request and status, correlation identifier, and basic device/browser metadata in operational and security logs. We use it to keep the Service reliable, investigate abuse, and protect tenants.
Website, support, and marketing data (FSS as controller). Information you submit through the pilot/contact form, registration flow, or a support request, such as work email, company/workspace name, affected client, and the safe description you provide.
reCAPTCHA security data (FSS as controller; Google as processor). Google reCAPTCHA protects the public contact form and, where shown, the public self-registration form against spam, fraud, and abuse. It processes IP address, device/browser or application signals, interaction signals, and a short-lived verification token. Google Cloud EMEA Limited processes that data on FSS's behalf. This is FSS-controlled website/account-security data, not Customer Personal Data processed on a Customer's instructions.
Cookies and security technologies. We use strictly necessary session and CSRF cookies and Google reCAPTCHA's _GRECAPTCHA security cookie. We use no analytics, advertising, or behavioural-tracking cookies. See the Cookie Statement.
What we do not collect. We do not request or store the broader content of your AI conversations or prompts. When you use brainattic through an AI client, the connector receives only the input needed for the action you request and returns a tenant-scoped result. We do not ingest the rest of your chat history, transcripts, or precise location.
5. How the connector handles data
brainattic exposes MCP tools that read and write your knowledge base under your instruction. Each tool processes only the inputs required for that call and returns only the data needed for the result. Tools are permission-gated, tenant-scoped, and paginated; write actions are explicit. An Authorised User who has not accepted a required material policy version may be prevented from using tenant-data MCP operations until acceptance is completed in the web application.
6. Why we process data and our legal bases (GDPR Art. 6)
| Purpose | Role and legal basis |
|---|---|
| Provide Customer Content functions, search, retrieval, exports, and reminders | FSS as processor on the Customer's documented instructions — GDPR Art. 28 |
| Create and operate accounts, authenticate users, administer access, and keep contract-acceptance evidence | FSS as controller — performance of a contract or steps before one, Art. 6(1)(b); legitimate interests in contract administration, Art. 6(1)(f) |
| Secure the website and Service, prevent abuse, and keep operational logs, including reCAPTCHA where enabled | FSS as controller — legitimate interests in security and abuse prevention, Art. 6(1)(f) |
| Respond to contact-form and support enquiries | Legitimate interests or steps before a contract, Art. 6(1)(f)/(b) |
| Meet legal obligations and establish, exercise, or defend legal claims | Legal obligation, Art. 6(1)(c), or legitimate interests, Art. 6(1)(f) |
We do not sell personal data or carry out advertising profiling or automated eligibility decisions.
7. AI models and clients
brainattic does not send Customer Content to a third-party AI model. The AI client you choose, such as Claude, ChatGPT, or Mistral, connects to brainattic as your client. Your use of that AI is governed by your relationship with its provider. That provider is not our Sub-processor, and we are not theirs, for this purpose. The client may receive content that you direct brainattic to return.
8. Who else is involved
The core Service is self-hosted on FSS-controlled infrastructure in the EU, including document storage, search and embeddings, email, and FSS's authorisation server. The following external parties may be involved:
| Party | Role | Data involved | Location | When |
|---|---|---|---|---|
| Telepoint EAD | Data-centre colocation (physical facility; no logical access to data) | Hardware housing stored data | Sofia, Bulgaria (EU) | Always |
| A1 Bulgaria EAD (SPNET) | Internet connectivity / IP transit | Encrypted data in transit | Bulgaria (EU) | Always |
| Google Cloud EMEA Limited | Processor to FSS — reCAPTCHA security | IP address, device/browser or application signals, interaction signals, and a short-lived verification token | EEA and other countries where Google or its Subprocessors maintain facilities, subject to Google Cloud transfer safeguards | When a protected public form is loaded or submitted |
| Google Ireland Limited | Separate controller — optional Google sign-in | Provider identifier and identity claims you authorise Google to return | Ireland and Google's international operations | Only if you choose Google sign-in |
| Meta Platforms Ireland Limited | Separate controller — optional Facebook sign-in | Provider identifier and identity claims you authorise Meta to return | Ireland and Meta's international operations | Only if you choose Facebook sign-in |
| Apple Distribution International Limited (with Apple Inc. where applicable) | Separate controller — optional Sign in with Apple | Provider identifier and identity claims you authorise Apple to return, including an email address or private-relay address | Ireland / United States | Only if you choose Sign in with Apple |
| Slack Technologies, LLC (a Salesforce company) | Sub-processor — optional Slack reminder delivery | Reminder content and recipient Slack member ID | United States | Only if your organisation enables Slack reminders |
| Yettel Bulgaria EAD | Sub-processor — optional SMS reminder delivery | Recipient phone number and message content | Bulgaria (EU) | Only if your organisation enables SMS reminders |
Google Cloud EMEA Limited acts as our processor for reCAPTCHA data used to protect the public contact and self-registration forms. This processing is outside the customer DPA and its Annex III because FSS controls it for its own website and account-security purpose. Google, Meta, and Apple act as separate controllers for their optional sign-in services and are outside Annex III for that distinct reason.
9. International transfers
FSS stores core Service data on infrastructure in Bulgaria, European Union. Processing outside the EEA may occur when your organisation enables Slack delivery in the United States, you choose an identity provider whose international operations process the sign-in interaction, or Google processes reCAPTCHA data in a country where Google or its Subprocessors maintain facilities. Restricted reCAPTCHA transfers rely on the mechanisms and safeguards in the Google Cloud Data Processing Addendum, including an applicable alternative transfer solution or Standard Contractual Clauses. Other recipients must use an appropriate GDPR Chapter V mechanism where required. SMS delivery through Yettel stays within the EU.
10. How long we keep data
| Data | Retention |
|---|---|
| Customer Content and live tenant data | While the workspace is active. An authorised immediate-deletion request, executed by FSS, removes live data without creating a recovery archive. Under the customer-initiated closure path, live removal occurs only after a cancellable 14-day window, during which every workspace administrator is notified and any of them may cancel the closure; no recovery archive is created. Under the dormancy path, live removal occurs only after six months without meaningful web or MCP activity plus a 60-day warning/export opportunity. |
| Dormancy recovery archive | Encrypted and kept for 30 days after live removal, then permanently deleted. No archive is created for an immediate customer-requested deletion. |
| Sanitized post-closure audit and legal-acceptance evidence | For no more than 90 days after tenant closure, then permanently deleted with the residual closed-tenant record, unless applicable law or a documented legal hold requires longer retention. |
| Rolling infrastructure backups | Up to 30 days, then overwritten under the backup cycle. |
| Application and security logs | 30 days. |
| reCAPTCHA data retained by FSS | The verification token and Google's raw response are not retained. Limited operational metadata — timestamp, outcome, score if returned, action, hostname, and request/correlation identifier — may be kept for up to 30 days. |
| Incomplete registration reservations | Automatically deleted after the short registration-intent window expires. |
| Contact-form submissions and related correspondence | 12 months, unless a longer period is needed for an ongoing relationship or legal claim. |
| Billing and accounting records | No fees apply during the free pilot. If billing is introduced, records required by tax or accounting law will be retained separately for the applicable statutory period and will never be used to preserve Customer Content. |
During the bounded 90-day post-closure period, the tenant remains disabled. Retained records are sanitized and used only for security investigation, abuse prevention, service-integrity verification, contract evidence, and the establishment, exercise, or defence of legal claims. A legal hold must be explicit and documented; it is not the default. When the hold or legal duty ends, deletion resumes.
11. How we protect data
We use TLS encryption in transit, role-based access controls and least-privilege administration, logical isolation of customer tenants, network segmentation, and physical security at our data-centre facility. Our practices are aligned with the principles of ISO/IEC 27001, ISO/IEC 20000, and ISO 9001; FSS was previously certified to these standards, but certifications are not currently maintained. Operational logs do not contain document bodies or broader AI prompts. We do not log or persist the reCAPTCHA token or Google's raw verification response.
12. Your rights
Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, and data portability, and the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. To exercise rights concerning data for which FSS is controller, email privacy@brainattic.ai; we normally respond within one month.
For Customer Content for which your organisation is controller, direct your request to that organisation; we will assist it as processor. For data processed independently by Google, Meta, or Apple during sign-in, exercise your rights with the relevant provider. For reCAPTCHA data, FSS remains your controller contact and Google processes the data on our behalf.
You may complain to the Commission for Personal Data Protection (CPDP), www.cpdp.bg, or another competent EU supervisory authority.
13. Children
brainattic is intended for business users aged 18 or over. It is not directed to children, and we do not knowingly process children's personal data through the public registration flow.
14. Changes to this notice
We may update this policy. We publish each version with its publication and effective dates. For material changes, we normally give at least 14 days' notice and notify customers through the Service or by email. We may require renewed acceptance before tenant-data web or MCP access continues after the effective date.
15. Contact
Privacy and data-protection enquiries: privacy@brainattic.ai. Product support: brainattic.ai/support or hello@brainattic.ai.
Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria.