Privacy policy
Last updated: 28 July 2026
Document version: 2026-07-23. Analytics update: 28 July 2026.
1. Who controls your data
The controller of your personal data is Company X sp. z o.o., with its registered office in Warsaw at ul. Żelazna 51/53, 00-841 Warsaw, Poland, entered in the Register of Entrepreneurs of the National Court Register maintained by the District Court for the Capital City of Warsaw in Warsaw, 13th Commercial Division of the National Court Register, under KRS 0001246886, tax ID NIP 5273222699, REGON 544978227, with share capital of PLN 5,000. For any data protection matters you can reach us at kontakt@braio.ai.
2. What data we process
- account data: name, e-mail address, company name and role in the team,
- authentication and contract-formation data: a cryptographic password hash, session identifiers, the accepted terms version, acceptance time and confirmation of the business nature of the service,
- billing data: invoice details and payment history (payments are handled by an external processor),
- product usage data: event logs, task and approval history, agent run metadata,
- website and application analytics data after consent: visited page addresses and titles, interaction events, approximate location, browser and device information, and a pseudonymous client identifier,
- content passed to agents: documents, messages and data from connected integrations - within the scope configured by the organisation and resulting from the permissions it grants,
- contact form data: name, company name, e-mail, phone number and the message content.
3. Why and on what basis
- providing the Braio service, including task execution by AI agents - Art. 6(1)(b) GDPR (contract),
- billing and accounting - Art. 6(1)(c) GDPR (legal obligation),
- security, auditing of agent actions and abuse prevention - Art. 6(1)(f) GDPR (legitimate interest),
- measuring website and application usage and registration effectiveness with Google Analytics 4 - Art. 6(1)(a) GDPR (consent),
- taking steps at your request before entering into a contract, or handling correspondence from a person acting for an organisation - Art. 6(1)(b) or (f) GDPR as applicable,
- marketing communication - only after separate prior consent where required; creating an account or sending an inquiry is not such consent.
4. Controller and processor roles
Company X is the controller of account, billing, contact and service-security data. When an organisation using Braio submits its own content, documents or integration data to agents, that organisation generally determines the purposes and means of processing and Company X acts as its processor on documented instructions. The organisation is responsible for the legal basis and scope of data submitted to the service. If the organisation intends to submit personal data for which it is the controller, it must first agree processing terms with Company X in the order or a separate data processing agreement (DPA), including rules for the use of sub-processors. Creating an account does not itself put those terms in place; until they take effect, the organisation must not submit such data to agent features. Information needed to agree the terms is available from the contact address.
5. Recipients and international transfers
The organisation's data region follows the service configuration or order. Depending on the features used, recipients may include providers of cloud infrastructure, databases, e-mail, payments, support, security and AI models, including AWS, Anthropic and OpenAI. The core infrastructure of Braio's current production environment is deployed in AWS region eu-central-1 (Frankfurt); this does not mean that every provider processes data only in that region. Content passed to models is limited to what is needed to complete the task. We do not use customer data to train our own models.
After consent, Google Ireland Limited receives analytics data and Google LLC may also receive it for infrastructure and support. Google Tag Manager manages tags and Google Analytics 4 measures service usage. Data may be processed outside the EEA under Google's applicable transfer mechanism, including an adequacy decision or Standard Contractual Clauses.
Some providers may process data outside the European Economic Area. In that case, the transfer mechanism applicable to the specific provider and configuration is used, in particular an adequacy decision or Standard Contractual Clauses (SCC). Information about the current provider, processing location and how to obtain a copy of the applicable safeguards is available from the contact address.
6. Retention and whether data is required
We process data for as long as necessary to provide the service, comply with legal obligations and until potential claims become time-barred. We erase or anonymise logs, audit data and correspondence when they are no longer needed for the purpose for which they were collected, subject to statutory retention requirements.
Evidence of contract formation - including the accepted terms version, document fingerprint, acceptance time and the name, e-mail address and organisation recorded at that time - is retained for the period needed to establish, exercise or defend legal claims. This limited evidence may therefore remain after an operational account is anonymised.
We retain analytics event data for the period configured in Google Analytics 4. The current period is available from the contact address. The Google Analytics _ga cookie may be stored for up to 2 years unless you withdraw consent, delete cookies, or your browser applies a shorter period. We retain the cookie that records your consent choice for 12 months.
Name, organisation name, e-mail address, password, acceptance of the terms and confirmation of the business nature of the service are required to create an account; without them we cannot enter into or perform the account agreement. Fields marked with an asterisk in the contact form are required to handle the message; company name and phone number are optional. Data submitted to agents and integrations is optional, but without it the selected task or integration may not work.
7. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, port it, and object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of earlier processing. You can withdraw consent or object to marketing through the same channel used to provide it or by contacting us. You also have the right to lodge a complaint with your data protection authority. Requests can be sent to kontakt@braio.ai.
8. Automation and cookies
AI agents automate tasks according to the organisation's configuration and granted permissions. Company X does not use account or contact data to profile individuals or make decisions about them that produce legal effects solely by automated means.
The braio.app website and the use.braio.app application use technical and functional cookies and similar browser storage, including to maintain and protect a session and retain organisation settings, preferences, onboarding state and user-created drafts.
Google Tag Manager runs with Consent Mode v2. Analytics storage, advertising storage, advertising user data and ad personalisation are denied by default. Before consent, Google Analytics does not store the _ga identifier; Google may receive limited cookieless technical signals and the consent state. Accepting analytics grants analytics storage only. Advertising storage, advertising user data and personalisation remain disabled.
A successful-registration event contains only the registration method, such as “email”, without the e-mail address, name or other contact data. You can reject consent or change it at any time through the “Cookie settings” button. Withdrawal does not affect the lawfulness of earlier processing.
9. Changes to this policy
We will announce material changes to this policy on the website and - if you have an account - by e-mail, at least 14 days in advance.

