Privacy policy
Last updated: 23 July 2026
1. Who controls your data
The controller of your personal data is Company X sp. z o.o., with its registered office in Warsaw at ul. Żelazna 51/53, 00-841 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, under KRS 0001246886, tax ID NIP 5273222699, REGON 544978227, with share capital of PLN 5,000. For any data protection matters you can reach us at kontakt@braio.ai.
2. What data we process
- account data: name, e-mail address, company name and role in the team,
- authentication and contract-formation data: a cryptographic password hash, session identifiers, the accepted terms version, acceptance time and confirmation of the business nature of the service,
- billing data: invoice details and payment history (payments are handled by an external processor),
- product usage data: event logs, task and approval history, agent run metadata,
- content passed to agents: documents, messages and data from connected integrations - within the scope configured by the organisation and resulting from the permissions it grants,
- contact form data: name, company name, e-mail, phone number and the message content.
3. Why and on what basis
- providing the Braio service, including task execution by AI agents - Art. 6(1)(b) GDPR (contract),
- billing and accounting - Art. 6(1)(c) GDPR (legal obligation),
- security, auditing of agent actions and abuse prevention - Art. 6(1)(f) GDPR (legitimate interest),
- taking steps at your request before entering into a contract, or handling correspondence from a person acting for an organisation - Art. 6(1)(b) or (f) GDPR as applicable,
- marketing communication - only after separate prior consent where required; creating an account or sending an inquiry is not such consent.
4. Controller and processor roles
Company X is the controller of account, billing, contact and service-security data. When an organisation using Braio submits its own content, documents or integration data to agents, that organisation generally determines the purposes and means of processing and Company X acts as its processor on documented instructions. The organisation is responsible for the legal basis and scope of data submitted to the service. If the organisation intends to submit personal data for which it is the controller, it must first agree processing terms with Company X in the order or a separate data processing agreement (DPA), including rules for the use of sub-processors. Creating an account does not itself put those terms in place; until they take effect, the organisation must not submit such data to agent features. Information needed to agree the terms is available from the contact address.
5. Recipients and international transfers
The organisation's data region follows the service configuration or order. Depending on the features used, recipients may include providers of cloud infrastructure, databases, e-mail, payments, support, security and AI models, including AWS, Anthropic and OpenAI. The core infrastructure of Braio's current production environment is deployed in AWS region eu-central-1 (Frankfurt); this does not mean that every provider processes data only in that region. Content passed to models is limited to what is needed to complete the task. We do not use customer data to train our own models.
Some providers may process data outside the European Economic Area. In that case, the transfer mechanism applicable to the specific provider and configuration is used, in particular an adequacy decision or Standard Contractual Clauses (SCC). Information about the current provider, processing location and how to obtain a copy of the applicable safeguards is available from the contact address.
6. Retention and whether data is required
We process data for as long as necessary to provide the service, comply with legal obligations and until potential claims become time-barred. We erase or anonymise logs, audit data and correspondence when they are no longer needed for the purpose for which they were collected, subject to statutory retention requirements.
Evidence of contract formation — including the accepted terms version, document fingerprint, acceptance time and the name, e-mail address and organisation recorded at that time — is retained for the period needed to establish, exercise or defend legal claims. This limited evidence may therefore remain after an operational account is anonymised.
Name, organisation name, e-mail address, password, acceptance of the terms and confirmation of the business nature of the service are required to create an account; without them we cannot enter into or perform the account agreement. Fields marked with an asterisk in the contact form are required to handle the message; company name and phone number are optional. Data submitted to agents and integrations is optional, but without it the selected task or integration may not work.
7. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, port it, and object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. You can withdraw consent or object to marketing through the same channel used to provide it or by contacting us. You also have the right to lodge a complaint with your data protection authority. Requests can be sent to kontakt@braio.ai.
8. Automation and cookies
AI agents automate tasks according to the organisation's configuration and granted permissions. Company X does not use account or contact data to profile individuals or make decisions about them that produce legal effects solely by automated means.
The braio.app website and the app.braio.app application use technical and functional cookies and similar browser storage, including to maintain and protect a session and retain organisation settings, preferences, onboarding state and user-created drafts. We do not use marketing or profiling cookies. If that changes, we will update this policy and ask for the required consent.
9. Changes to this policy
We will announce material changes to this policy on the website and - if you have an account - by e-mail, at least 14 days in advance.

