Privacy Policy
This Privacy Policy explains how BrewMyCode (Business ID 3518342-5, Laviontie 78, 19950 Luhanka, Finland — "BrewMy{Code}", "we", "us") collects, uses and protects personal data when you visit brewmycode.com, contact us, or use the BrewMy{Code} platform (the "Service").
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act (1050/2018).
1. Who is responsible
Controller for data about website visitors, prospects, customer contacts and users' account data: BrewMyCode, Laviontie 78, 19950 Luhanka, Finland. Contact: privacy@brewmycode.com.
Processor for content our customers connect to or upload into the Service ("Customer Content" — documents, messages, tickets, records and the personal data they contain): the customer is the controller and we process that data only on the customer's instructions under our Data Processing Agreement.
2. What we collect and why
2.1 Website visitors
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Technical data (IP address, browser, device, pages viewed, referrer) | Operate, secure and improve the website; aggregate analytics | Legitimate interest (art. 6(1)(f)) | 14 months |
| Cookie and similar identifiers | See our Cookie Policy | Consent for non-essential cookies; legitimate interest for essential ones | See Cookie Policy |
2.2 People who contact us or book a call
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, company, role, message content, call booking details | Respond to your request, prepare and follow up on meetings | Legitimate interest; pre-contractual steps (art. 6(1)(b)) | 24 months after last contact |
| Marketing communications preferences | Send relevant updates about the Service, where you have opted in | Consent (art. 6(1)(a)); you may withdraw at any time | Until withdrawn |
2.3 Customer account users
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, work email, role, workspace membership, authentication data | Provide and secure the Service, manage access and permissions | Contract (art. 6(1)(b)) | Duration of the contract + 12 months |
| Usage data (queries made, agents run, features used, timestamps) | Operate the Service, billing, security and audit logs, support | Contract; legitimate interest | Audit logs: 12 months by default, configurable by the customer |
| Support communications | Resolve your requests | Contract | 24 months |
| Billing contact and invoicing data | Invoicing and accounting | Contract; legal obligation (Finnish Accounting Act) | 6 years after the end of the financial year |
2.4 Customer Content
Customer Content is processed only to provide the Service to the customer: indexing it into the customer's knowledge bases, answering users' questions, running agents the customer has configured, and producing the traces and logs the customer uses to supervise them. We do not use Customer Content to train machine-learning models, and we do not sell or share it for advertising.
3. Where data is processed
We process and store data in the European Union. Our primary regions are Stockholm (Sweden) and Helsinki (Finland). Some sub-processors, such as email delivery or model providers, may process data outside the EU; in those cases we rely on the European Commission's Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable, and we use model providers under zero-data-retention terms. The current list of sub-processors is published in our Data Processing Agreement.
4. Who we share data with
- Sub-processors that host and operate the Service (cloud infrastructure, model providers, email delivery, error monitoring), bound by data processing agreements.
- Professional advisers (accountants, lawyers) where necessary.
- Authorities, where required by law or to protect our rights.
We do not sell personal data.
5. How we protect data
Encryption in transit (TLS 1.2+) and at rest (AES-256); role-based access control; multi-factor authentication for staff; least-privilege access; logging and monitoring; regular backups with tested restores; independent security testing. Access to Customer Content by our staff is limited to what is strictly necessary for support and is logged.
6. Your rights
Under the GDPR you have the right to access your personal data, have it corrected or erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. To exercise these rights, email privacy@brewmycode.com. We respond within 30 days.
If you are a user of a customer's workspace, requests about Customer Content should be directed to that customer; we will assist them as their processor.
You also have the right to lodge a complaint with a supervisory authority. In Finland this is the Office of the Data Protection Ombudsman (tietosuoja.fi).
7. Automated decision-making
The Service produces answers and carries out tasks configured by our customers. It does not make decisions with legal or similarly significant effects on individuals without human involvement; customers configure approval steps for consequential actions.
8. Children
The Service and website are intended for business use and are not directed at children under 16.
9. Changes
We update this policy when our practices change and publish the date of the latest version at the top. Material changes affecting customers are announced by email.
10. Contact
BrewMyCode · Laviontie 78, 19950 Luhanka, Finland · privacy@brewmycode.com · +358 44 923 6472