BrewMy{Code}
Last updated 19 September 2026

Privacy Policy

This Privacy Policy explains how BrewMyCode (Business ID 3518342-5, Laviontie 78, 19950 Luhanka, Finland — "BrewMy{Code}", "we", "us") collects, uses and protects personal data when you visit brewmycode.com, contact us, or use the BrewMy{Code} platform (the "Service").

We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).

1. Who is responsible

Controller for data about website visitors, prospects, customer contacts and users' account data: BrewMyCode, Laviontie 78, 19950 Luhanka, Finland. Contact: privacy@brewmycode.com.

Processor for content our customers connect to or upload into the Service ("Customer Content" — documents, messages, tickets, records and the personal data they contain): the customer is the controller and we process that data only on the customer's instructions under our Data Processing Agreement.

2. What we collect and why

2.1 Website visitors

DataPurposeLegal basisRetention
Technical data (IP address, browser, device, pages viewed, referrer)Operate, secure and improve the website; aggregate analyticsLegitimate interest (art. 6(1)(f))14 months
Cookie and similar identifiersSee our Cookie PolicyConsent for non-essential cookies; legitimate interest for essential onesSee Cookie Policy

2.2 People who contact us or book a call

DataPurposeLegal basisRetention
Name, email, company, role, message content, call booking detailsRespond to your request, prepare and follow up on meetingsLegitimate interest; pre-contractual steps (art. 6(1)(b))24 months after last contact
Marketing communications preferencesSend relevant updates about the Service, where you have opted inConsent (art. 6(1)(a)); you may withdraw at any timeUntil withdrawn

2.3 Customer account users

DataPurposeLegal basisRetention
Name, work email, role, workspace membership, authentication dataProvide and secure the Service, manage access and permissionsContract (art. 6(1)(b))Duration of the contract + 12 months
Usage data (queries made, agents run, features used, timestamps)Operate the Service, billing, security and audit logs, supportContract; legitimate interestAudit logs: 12 months by default, configurable by the customer
Support communicationsResolve your requestsContract24 months
Billing contact and invoicing dataInvoicing and accountingContract; legal obligation (Finnish Accounting Act)6 years after the end of the financial year

2.4 Customer Content

Customer Content is processed only to provide the Service to the customer: indexing it into the customer's knowledge bases, answering users' questions, running agents the customer has configured, and producing the traces and logs the customer uses to supervise them. We do not use Customer Content to train machine-learning models, and we do not sell or share it for advertising.

3. Where data is processed

We process and store data in the European Union. Our primary regions are Stockholm (Sweden) and Helsinki (Finland). Some sub-processors, such as email delivery or model providers, may process data outside the EU; in those cases we rely on the European Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable, and we use model providers under zero-data-retention terms. The current list of sub-processors is published in our Data Processing Agreement.

4. Who we share data with

  • Sub-processors that host and operate the Service (cloud infrastructure, model providers, email delivery, error monitoring), bound by data processing agreements.
  • Professional advisers (accountants, lawyers) where necessary.
  • Authorities, where required by law or to protect our rights.

We do not sell personal data.

5. How we protect data

Encryption in transit (TLS 1.2+) and at rest (AES-256); role-based access control; multi-factor authentication for staff; least-privilege access; logging and monitoring; regular backups with tested restores; independent security testing. Access to Customer Content by our staff is limited to what is strictly necessary for support and is logged.

6. Your rights

Under the GDPR you have the right to access your personal data, have it corrected or erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. To exercise these rights, email privacy@brewmycode.com. We respond within 30 days.

If you are a user of a customer's workspace, requests about Customer Content should be directed to that customer; we will assist them as their processor.

You also have the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).

7. Automated decision-making

The Service produces answers and carries out tasks configured by our customers. It does not make decisions with legal or similarly significant effects on individuals without human involvement; customers configure approval steps for consequential actions.

8. Children

The Service and website are intended for business use and are not directed at children under 16.

9. Changes

We update this policy when our practices change and publish the date of the latest version at the top. Material changes affecting customers are announced by email.

10. Contact

BrewMyCode · Laviontie 78, 19950 Luhanka, Finland · privacy@brewmycode.com · +358 44 923 6472