Privacy Policy
brainattic is a knowledge-base service that your team — and the AI agents you connect — read from and write to. We keep your data on our own infrastructure in the European Union, we don't send it to any third-party AI model, and we collect only what we need to run the service. This notice explains what we process, why, who else is involved, how long we keep it, and your rights.
1. Who we are
The service and the brainattic.ai website are operated by Finite Software Systems Ltd. (Bulgarian: ФИНИТ Софтуер Системс ЕООД) ("FSS", "we", "us"), the provider of the brainattic product.
- Registered office: 4 Gorotzvet Street, Sofia, Bulgaria
- Company No. (ЕИК): 175276896 · VAT: BG175276896
- Privacy contact: privacy@brainattic.ai
- Data Protection Officer: none appointed (not required at our scale); privacy enquiries are handled by the contact above.
- Supervisory authority: Commission for Personal Data Protection (CPDP), Sofia, Bulgaria — www.cpdp.bg
2. Scope
This notice covers (a) the brainattic.ai website and (b) the brainattic service — the knowledge-base application and the connector that exposes it to AI clients over the Model Context Protocol (MCP). brainattic is a business-to-business service intended for organisations and their authorised users aged 18 or over. It is not directed to consumers or to children.
3. Controller and processor — who decides what
The split matters because it determines who is responsible for which data:
- Your knowledge-base content — the documents, attachments, search queries, reminders and audit entries your organisation creates in brainattic, including any personal data you choose to put in them. Here your organisation is the data controller and FSS is a processor acting on your documented instructions. This processing is governed by our Data Processing Agreement.
- Account, website, support and marketing data — described in §4. Here FSS is the controller.
4. What we process
Account & identity. Name, work email, organisation, a securely hashed password, and OAuth/session tokens used to authenticate you. Authentication is handled by FSS's own authorisation server — we do not use a third-party identity provider.
Customer content (as processor). Documents, attachments, vector embeddings derived from your content, search queries, reminders, and the in-product audit log — plus any personal data your organisation chooses to include.
Reminder-delivery data. If you use reminders, the identifier for the channel you choose: an email address; a Slack member ID (only if you enable Slack delivery); or a mobile phone number (only if you enable SMS delivery).
Technical & security data. IP address, timestamps, the endpoint/request and its status, and basic device/browser metadata, recorded in operational and security logs.
Website & marketing data. What you submit through the site's contact form — your email, company, and message.
Cookies. Only strictly necessary cookies (a session cookie and a CSRF-protection token). No analytics or tracking cookies. See the Cookie Policy.
What we do not collect. We do not request or store the content of your AI conversations or prompts. When you use brainattic through an AI client, the connector receives only the input needed to perform the specific action you ask for (for example, a search term, or the document text you ask it to save) and returns a scoped result. We do not ingest your broader chat history, transcripts, or precise location.
5. How the connector handles data
brainattic exposes MCP tools that read and write your knowledge base under your instruction. Each tool processes only the inputs required for that call and returns only the data needed to answer it. Tools are scoped and paginated; they do not collect extraneous conversation data, and write actions are explicit. This reflects the data-minimisation standards of the AI platforms through which brainattic is offered.
6. Why we process it, and our legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide and operate the service and your account | Performance of a contract — Art. 6(1)(b); for customer content as processor, on the controller's documented instructions — Art. 28 |
| Deliver reminders through the channel you choose | Performance of a contract / your instruction |
| Keep the service secure, prevent abuse, keep operational logs | Our legitimate interests — Art. 6(1)(f) |
| Respond to contact-form enquiries | Legitimate interests / steps prior to a contract — Art. 6(1)(f)/(b) |
| Comply with legal obligations | Legal obligation — Art. 6(1)(c) |
We do not carry out advertising profiling or sell personal data.
7. AI models
brainattic does not send your data to any third-party AI model. The AI you use (for example, Claude, ChatGPT, or Mistral) connects to brainattic as your own client; your use of that AI is governed by your agreement with its provider. That provider is not our sub-processor, and we are not theirs, for this purpose.
8. Who else is involved (recipients & sub-processors)
The core service is self-hosted on FSS-controlled infrastructure in the EU — including document storage, search and embeddings, e-mail, and authentication. We engage a small number of external parties:
| Party | Role | Data involved | Location | When |
|---|---|---|---|---|
| Telepoint EAD | Data-centre colocation (physical facility; no logical access to data) | Hardware housing all stored data | Sofia, Bulgaria (EU) | Always |
| A1 Bulgaria EAD (SPNET) | Internet connectivity / IP transit | Data in transit (encrypted) | Bulgaria (EU) | Always |
| Slack Technologies, LLC (a Salesforce company) | Optional reminder delivery via Slack DM | Reminder content + recipient Slack member ID | United States | Only if your organisation enables Slack reminders |
| Yettel Bulgaria EAD | Optional reminder delivery via SMS | Recipient phone number + message content | Bulgaria (EU) | Only if your organisation enables SMS reminders |
We require recipients that process personal data on our behalf to provide appropriate safeguards. The current sub-processor list is maintained in our Data Processing Agreement; we will give customers notice of material changes.
9. International transfers
Our infrastructure and your data are located in the European Union (Bulgaria). The only processing that may occur outside the EEA is an optional integration you choose to enable — Slack (United States) for reminder DMs — carried out under an appropriate transfer mechanism (e.g. Standard Contractual Clauses or the provider's certified framework). SMS delivery via Yettel stays within the EU. If you do not enable Slack reminders, no transfer outside the EEA takes place.
10. How long we keep it
| Data | Retention |
|---|---|
| Customer content (documents, attachments, embeddings, reminders) | For the life of the account; deleted within 30 days of account closure |
| In-product audit log | For the life of the tenant; deleted with content on closure |
| Backups | Rolling, up to 30 days, then overwritten |
| Application & security logs | 30 days |
| Account & administrative data | Life of the account, then 30 days |
| Contact-form submissions | 12 months |
We may retain limited information for longer where required to meet a legal obligation or to establish, exercise or defend legal claims.
11. How we protect it
We use TLS encryption for data in transit; role-based access controls and least-privilege administration; logical isolation of each customer tenant; network segmentation; and physical security at our data-centre facility. Our internal practices are aligned with the principles of ISO/IEC 27001 (information security), ISO/IEC 20000 (IT service management) and ISO 9001 (quality) — FSS was previously certified to these standards; certifications are not currently maintained. Our logs capture operational and security metadata, not the content of your documents or AI prompts.
12. Your rights
Subject to the GDPR, you have the right to access your personal data and to rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests; where processing relies on consent, you may withdraw it at any time. To exercise these, email privacy@brainattic.ai; we respond within one month.
Where the data is customer content for which your organisation is the controller, please direct your request to that organisation — we will assist them as their processor.
You also have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), www.cpdp.bg, or with your local EU supervisory authority.
13. Children
brainattic is intended for business users aged 18 or over. It is not directed to children, and we do not knowingly process the personal data of minors.
14. Changes to this notice
We may update this policy from time to time. We will post the updated version here with a new "last updated" date and, where changes are material, notify customers by email.
15. Contact
Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria · privacy@brainattic.ai