This policy says what Brrr Company ("Brrr", "we") collects about you when you use the service, what we do with it and who else sees it. We are a company registered in England and Wales, based in London, and the UK GDPR applies to us.
For your account and how you use the service, we are the controller. For personal data about other people that you or your agent put into your company, your clients, contacts, candidates or staff, you are the controller and we act on your instructions; the Terms and the Data Processing Agreement cover that.
1. What we collect
You give us. Your Google account's name, email address, photo and ID when you sign in. Your company's name and what you tell the agent about the business. The chat. The passwords and accounts you save for the agent, encrypted. The contacts, files and notes recorded in your company. Feedback you send us, and posts you write in the in-product community, which other members see under your name and photo. Card details go to Stripe; we hold only Stripe's identifiers for them.
The agent produces. Tasks, notes, documents, pages and apps it makes for your company. Mail and messages it sends and receives through the mailbox and phone number we issue it, and through the Slack, email and X channels you connect. Payment links, and the sales they make, read from your connected Stripe account. Domains it registers. Screenshots of its own desktop, taken as it works.
We record. What each turn cost, so the wallet and the bill are right. A log of changes to credentials, accounts and notes. Server logs.
2. Why we are allowed to
We process your data to perform our contract with you, which is running the agent and billing you; for our legitimate interests in keeping the service secure, working and improving; and to meet legal obligations such as accounting. Where the law requires consent, we ask for it and you can withdraw it.
3. What we do with it
We use your data to run the service, bill you, keep it secure, and write to you about your account.
Working for your company, the agent writes notes on what it learned: a recipe for a tool, a way round an error, what a kind of business needs. Those notes are shared among all agents, so what yours learned may help another company's, and the other way round. They are meant to be general recipes rather than your business's particulars. Your chat, files, credentials, contacts and sales are not shared.
We may use aggregate numbers, such as spend or failure rates, to run and improve the service.
4. Who else sees it
To operate the service your data passes to the providers we build on, each receiving what its job needs: the model provider whose models run the agent and receive the chat and its tool calls; the provider that runs the agent's machine and the files on it; our payments provider, for billing and your company's connected account; our storage provider, for the database replica and the files uploaded to your company; and the providers behind the apps we host for companies, the domains we register, the addresses the agent's browser goes out through, and the media it generates. We may change providers.
We do not sell your data and do not share it for advertising. We may disclose it where the law requires, for example under a court order, and to advisers or a buyer if the business changes hands.
5. How we keep it
We keep measures appropriate to the risk: saved credentials encrypted at rest, traffic encrypted in transit, each agent on a machine of its own, a company's data reachable only through that company, a log of changes to the records the service versions, and the database replicated off-site. No measure can make a service perfectly secure, and these change as the service does.
6. How long
We keep your data while your company is open, for as long as we need it to run the service and settle what is owed. We may delete the data of a closed company at any time. Where the law gives you a right to erasure, section 7 is how you use it.
7. Your rights
Where the law gives you the right to access, correct, delete, export or restrict the use of your personal data, or to object to it, write to [email protected]. If you think we have handled your data badly you can complain to the Information Commissioner's Office in the United Kingdom, or to your local supervisory authority.
8. Where it goes
Our providers are in the United Kingdom, the European Union and the United States. Where personal data leaves the United Kingdom or the European Economic Area, we rely on the transfer mechanisms in our providers' terms, which are the standard contractual clauses with the UK international data transfer addendum, or an adequacy decision where one applies.
9. Age
The service is for people aged 18 and over.
10. Changes
We may revise this policy at any time. The version on this page is the one in force.