Privacy Policy
Beta Version (GDPR-Compliant) - Effective date: 21 November 2025
At BRAG, we respect your privacy and are committed to protecting your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable Dutch and European data protection laws.
1. Information We Collect
Required for account creation:
- Name, email address, and job information
- Work experience, OKRs/KPIs, goals, weekly tasks, and success lists
Optional features (requiring explicit consent):
- Calendar data (meeting names, attendees, descriptions)
- Notion workspace data (pages, tasks, databases)
- Uploaded files (e.g., to-do lists, documents)
Optional profile information:
- Job description and company description
- Industry and role/function information
Technical & usage data:
- IP address, device information, and usage analytics (pages visited, session length, frequency of use)
2. How We Use Your Information
We process your personal data to:
- Provide, maintain, and improve our services
- Respond to your enquiries and provide customer support
- Analyze usage patterns to enhance app functionality and user experience
- Send you updates, tips, and newsletters (only if you opted in)
Legal basis for processing:
- Consent: For marketing communications and optional features (calendar, Notion integrations, file uploads)
- Contractual necessity: To provide the core functionality of BRAG
- Legitimate interest: For analytics and service improvements
3. AI Processing & Third-Party Services
We value your privacy and handle your personal data according to applicable laws. Your data is treated confidentially and stored securely.
All data is processed exclusively within the EU data zone to ensure compliance with European data protection regulations.
We use trusted third-party service providers to deliver our services:
- Microsoft Azure (Azure OpenAI Service): Used for AI-powered features (e.g., content analysis, suggestions). All processing occurs exclusively within the EU data zone.
- Supabase: Database hosting and authentication
- Vercel: Application hosting and delivery
These providers process your data on our behalf under strict data processing agreements and are prohibited from using your data for any other purpose. Your data never leaves the EU.
4. Marketing & Communications
- You may opt in to receive newsletters and updates during signup
- You can withdraw consent at any time via unsubscribe links in emails or by contacting us at hello@bragbetter.eu
- We will never share your email address with third parties for their marketing purposes
5. Data Sharing
- We share data only with trusted service providers as described in Section 3
- We do not sell your personal data to third parties
- We may share anonymized or aggregated data (with no personal identifiers) for research, analytics, or product improvement purposes
- We may disclose data if required by law or to protect our legal rights
6. Data Storage & Security
- All personal data is stored securely on EU-based servers
- We implement industry-standard security measures including encryption, access controls, and regular security assessments
- We continuously improve our security practices as BRAG evolves from beta to full release
Data retention: We retain your data for as long as your account is active or as needed to provide services. You may request deletion at any time.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct any inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Data portability: Receive your data in a structured, machine-readable format
- Withdraw consent: Revoke consent for marketing, optional integrations (calendar, Notion, file uploads), or AI processing
- Restrict processing: Limit how we use your data
- Object: Object to processing based on legitimate interest
- Lodge a complaint: File a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority
To exercise your rights, contact us at: hello@bragbetter.eu
We will respond to your request within 30 days.
8. Consent Tracking
For optional features and marketing communications, we:
- Obtain explicit consent before processing
- Record consent with timestamp and scope
- Allow you to withdraw consent at any time through app settings or by contacting us
9. International Data Transfers
We do not transfer your personal data outside the European Economic Area (EEA). All data processing occurs within the EU data zone.
10. Children's Privacy
BRAG is not intended for users under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
11. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will notify you via email or through the app.
The latest version is always available at this page. Your continued use of BRAG after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data:
- Email: hello@bragbetter.eu
- Data Controller: BRAG
- Location: Netherlands
Last updated: 21 November 2025