Skip to content
brainattic.ai
Product Connect Docs
EN
  • English
  • Български
  • Deutsch
  • Français
Log in
Sign up

Privacy Policy

Version: 2026-09-15 · Published: 2026-09-15 · Effective: 2026-09-29

Прочетете на български Auf Deutsch lesen Lire en français

brainattic is a knowledge-base service that your team — and the AI agents you connect — read from and write to. We keep core Service data on FSS-controlled infrastructure in the European Union, do not send Customer Content to a third-party AI model, and collect only what we need to run, secure, and support the Service.

1. Who we are

The Service and the brainattic.ai website are operated by Finite Software Systems Ltd. (Bulgarian: ФИНИТ Софтуер Системс ЕООД) ("FSS", "we", "us"), the provider of the brainattic product.

  • Registered office: 4 Gorotzvet Street, Sofia, Bulgaria
  • Company No. (ЕИК): 175276896 · VAT: BG175276896
  • Privacy contact: privacy@brainattic.ai
  • Data Protection Officer: none appointed (not required at our scale); privacy enquiries are handled through the contact above.
  • Supervisory authority: Commission for Personal Data Protection (CPDP), Sofia, Bulgaria — www.cpdp.bg

2. Scope

This notice covers (a) the brainattic.ai website and its public contact and registration surfaces and (b) the brainattic Service — the knowledge-base web application and the connector that exposes it to AI clients over the Model Context Protocol (MCP). brainattic is a business-to-business service for organisations and their authorised users aged 18 or over. It is not directed to consumers or children.

3. Controller and processor — who decides what

The split matters because it determines who is responsible for which data:

  • Customer Content and customer-directed service records — documents, attachments, search queries, reminders, and in-product audit entries created through your organisation's use of brainattic, including personal data you choose to put in them. Here your organisation is the controller and FSS is a processor acting on documented instructions. This processing is governed by our Data Processing Agreement.
  • Account, identity, authentication, access-control, contract-acceptance, website, support, marketing, and operational security data — described below. Here FSS is the controller because FSS determines why and how that data is used to operate, secure, administer, and support the Service.

4. What we process

Account and identity data (FSS as controller). Name, work email, organisation, a securely hashed password where you set one, provider account identifiers and identity claims returned by a sign-in provider (such as name, email, and email-verification status), workspace membership and role, and OAuth/session tokens used to authenticate and authorise you.

Customer Content (FSS as processor). Documents, attachments, vector embeddings derived from content, search queries (for each search: the query text, up to 500 characters, the searching account's identifier, the search mode, the number of results, any project or group filter you applied, and timing and diagnostic data about how the search was served), reminders, edit-session drafts (a working copy of a document your AI client is editing, held with the editing account's identifier for a short period after the edit is committed or discarded), and in-product audit entries, each recording the acting account's identifier and workspace role, the OAuth client identifier of the AI client where the action came through the connector, and the request correlation identifier — plus personal data your organisation chooses to include. When you connect an AI client, the connector returns to that client the knowledge-base content you direct it to retrieve — document bodies, passages, revisions, rule documents and attachment files, the names and descriptions of the projects and groups that organise them, the differences between two versions of a document, and the passage your client asked us to replace when an edit cannot be applied — together with the connector response data described below.

Connector response data (FSS as processor). Alongside content, connector responses carry: record identifiers of the objects you work with (document, revision, attachment, edit-session, reminder and schedule identifiers); the names, short names (slugs) and links that locate content in your workspace (workspace, project, group and document slugs, permalinks, revision numbers, the position of a retrieved passage within its document, and whether a returned snippet is a shortened view of the document it came from); last-modified, archival, document, due, expiry, schedule start and next-run, revision and delivery timestamps; file metadata (name, type, size) for attachments; relevance signals for search results (a relative score, the matching channel, and a confidence level for passage retrieval); counts and sizes (documents in a project or group, recipients on a reminder, total matches, the byte size of a revision, and, in a refusal, the number of workspaces your token is entitled to or the limit the call exceeded); the state of an object after a call (created, updated, archived, attached, detached, linked, unlinked, discarded, resumed, deleted, whether a write changed anything, whether a schedule is active, the delivery channels a reminder uses, a reminder or delivery status and, where a delivery failed, the reason recorded for it, a rule layer or scope) and the display preferences your workspace has set for a project or group (pinned to the menu, hidden); a short-lived download link for an attachment, only when your client asks for one; and, when a call fails, an error reference code you may quote to support, together with the field, tool or permission the refusal names and — where the refusal is a policy one — the link to the acceptance page, the policy bundle and document versions, and the date they take effect.

MCP access events (FSS as processor; FSS as controller for security use). Each connector call that touches your knowledge base — reads included — and each rule-resource read records the tool or resource name, the permission checked, the decision (allowed, denied or failed), your account identifier, the OAuth client identifier of your AI client, the identifier of the access token used (not the token itself), the correlation identifier your client supplied, and the time. Your organisation's administrators can view these events, disable or narrow the recording, set the retention period within the range stated in §10, and optionally store the token's scope and claim attributes with each event.

Reminder-delivery data (FSS as processor). The content and destination needed for a channel your organisation enables: an email address, a Slack member ID, or a mobile phone number.

Contract and registration evidence (FSS as controller). Company/workspace name, the policy bundle, document versions and content hashes presented to you, locale, acceptance time and source, and limited request metadata such as IP address, user agent, and request/correlation identifier. We use this evidence to establish and administer the customer relationship and demonstrate what was accepted.

Technical and security data (FSS as controller). IP address, timestamps, endpoint/request and status, correlation identifier, and basic device/browser metadata in operational and security logs. We use it to keep the Service reliable, investigate abuse, and protect tenants. Operational logs may also carry an error reference code and, for unexpected failures, the error text, which can include text your client sent.

Website, support, and marketing data (FSS as controller). Information you submit through the pilot/contact form, registration flow, or a support request, such as work email, company/workspace name, affected client, and the safe description you provide.

Acquisition and campaign data (FSS as controller). If you consent to optional acquisition-attribution storage, we may record the first allowlisted campaign source associated with your public-site and registration journey: utm_source, utm_medium, utm_campaign, utm_content, utm_term, the landing path without its query string, the referring origin (scheme and host only), a Meta click identifier derived from fbclid, and a LinkedIn first-party advertising click identifier derived from li_fat_id, where present. We do not store unrestricted query strings. Advertising click identifiers are collected only after consent. We preserve the first source rather than overwriting it with later visits and use the record for first-party acquisition and funnel measurement.

Funnel and commercial records (FSS as controller). We record a bounded set of product and commercial milestones, including registration, successful MCP connection and use, activation, commercial qualification, payment, and 7- or 30-day retention, together with the first-source snapshot, staff-controlled commercial status, and the account identifier of the user whose action produced the milestone or activity record. These records do not contain Customer Content and are used to understand whether acquisition results in an activated or commercial relationship.

Advertising-conversion delivery data (FSS as controller). If you separately consent, we may send limited conversion data to Meta Platforms Ireland Limited and/or LinkedIn Ireland Unlimited Company, depending on the campaign source and the advertising platform you consented to. The data are limited to the relevant platform click identifier, the event name and timestamp, and a pseudonymous event-deduplication identifier. For PaidWorkspace only, where a contracted value is recorded and platform delivery of value is enabled, we may also send that value and its currency. The only eligible events are ActivatedWorkspace, CommerciallyQualifiedWorkspace, PaidWorkspace, and, where enabled, RetainedWorkspace30d. We do not send an email address, phone number, name, company name, IP address, user agent, Customer Content, documents, prompts, search text, or unrestricted internal identifiers for this purpose.

reCAPTCHA security data (FSS as controller; Google as processor). Google reCAPTCHA protects the public contact form and, where shown, the public self-registration form against spam, fraud, and abuse. It processes IP address, device/browser or application signals, interaction signals, and a short-lived verification token. Google Cloud EMEA Limited processes that data on FSS's behalf. This is FSS-controlled website/account-security data, not Customer Personal Data processed on a Customer's instructions.

Cookies and security technologies. We use strictly necessary session and CSRF cookies and Google reCAPTCHA's _GRECAPTCHA security cookie. If you consent, we also use optional first-party browser storage to carry the first acquisition source and supported advertising click identifiers through the current public-site and registration journey. We do not install Meta Pixel, LinkedIn Insight Tag code, or any other third-party advertising, analytics, or behavioural-tracking runtime on the site. See the Cookie Statement.

What we do not collect. We do not request or store the broader content of your AI conversations or prompts. When you use brainattic through an AI client, the connector receives only the input needed for the action you request and returns a tenant-scoped result. We do not ingest the rest of your chat history, transcripts, or precise location.

5. How the connector handles data

brainattic exposes MCP tools that read and write your knowledge base under your instruction. Each tool processes only the inputs required for that call and returns the content you asked for plus the connector response data described in §4. Results are returned to your AI client in two equivalent forms — as structured data and as a text rendering of the same data — so clients that read only one form still receive the result. Every call that touches your knowledge base records one MCP access event (§4); a search additionally records a search-log entry; a write additionally records an in-product audit entry. Tools are permission-gated, tenant-scoped and paginated; write actions are explicit; attachment download links and document bodies on write confirmations are returned only when your client asks for them. An Authorised User who has not accepted a required material policy version is refused with an error naming the acceptance page, and the refusal records nothing.

6. Why we process data and our legal bases (GDPR Art. 6)

PurposeRole and legal basis
Provide Customer Content functions, search, retrieval, exports, and remindersFSS as processor on the Customer's documented instructions — GDPR Art. 28
Create and operate accounts, authenticate users, administer access, and keep contract-acceptance evidenceFSS as controller — performance of a contract or steps before one, Art. 6(1)(b); legitimate interests in contract administration, Art. 6(1)(f)
Secure the website and Service, prevent abuse, and keep operational logs, including reCAPTCHA where enabledFSS as controller — legitimate interests in security and abuse prevention, Art. 6(1)(f)
Respond to contact-form and support enquiriesLegitimate interests or steps before a contract, Art. 6(1)(f)/(b)
Measure first-party acquisition source, activation, funnel, and commercial outcomesFSS as controller — legitimate interests in understanding and improving acquisition, onboarding, and commercial performance, Art. 6(1)(f). Optional storage or access on your device occurs only after your consent.
Send the four limited conversion events described above to the relevant supported advertising platform for attribution, measurement, ad personalisation, and optimisationFSS as controller — consent, Art. 6(1)(a). You may withdraw consent at any time; withdrawal stops future delivery.
Meet legal obligations and establish, exercise, or defend legal claimsLegal obligation, Art. 6(1)(c), or legitimate interests, Art. 6(1)(f)

We do not sell personal data, use Customer Content for advertising, build behavioural advertising profiles inside brainattic, or make automated eligibility decisions. If you consent, limited conversion events may be sent to Meta and/or LinkedIn for attribution, measurement, personalisation, and optimisation of FSS advertising. The recipient may match and use those events under its applicable advertising and data-protection terms. FSS does not send Customer Content, email addresses, phone numbers, names, company names, IP addresses, or user agents for this purpose.

7. AI models and clients

brainattic does not send Customer Content to a third-party AI model. The AI client you choose, such as Claude, ChatGPT, or Mistral, connects to brainattic as your client. Your use of that AI is governed by your relationship with its provider. That provider is not our Sub-processor, and we are not theirs, for this purpose. The client may receive content that you direct brainattic to return.

8. Who else is involved

The core Service is self-hosted on FSS-controlled infrastructure in the EU, including document storage, search and embeddings, email, and FSS's authorisation server. The following external parties may be involved:

PartyRoleData involvedLocationWhen
Telepoint EADData-centre colocation (physical facility; no logical access to data)Hardware housing stored dataSofia, Bulgaria (EU)Always
A1 Bulgaria EAD (SPNET)Internet connectivity / IP transitEncrypted data in transitBulgaria (EU)Always
Google Cloud EMEA LimitedProcessor to FSS — reCAPTCHA securityIP address, device/browser or application signals, interaction signals, and a short-lived verification tokenEEA and other countries where Google or its Subprocessors maintain facilities, subject to Google Cloud transfer safeguardsWhen a protected public form is loaded or submitted
Google Ireland LimitedSeparate controller — optional Google sign-inProvider identifier and identity claims you authorise Google to returnIreland and Google's international operationsOnly if you choose Google sign-in
Meta Platforms Ireland LimitedSeparate controller — optional Facebook sign-inProvider identifier and identity claims you authorise Meta to returnIreland and Meta's international operationsOnly if you choose Facebook sign-in
Meta Platforms Ireland LimitedProcessor for matching, measurement, and analytics; joint controller with FSS for collection and transmission where Event Data are used for ad personalisation or optimisation; independent controller for subsequent Meta processing under the Meta Business Tools TermsMeta click identifier derived from fbclid, conversion event name, and timestamp; no email address or Customer ContentIreland and Meta's international operations, subject to applicable transfer safeguardsOnly after consent and only when one of the four eligible conversion events occurs
LinkedIn Ireland Unlimited CompanyIndependent controller for LinkedIn Marketing Solutions Conversion Tracking and Conversions API under the LinkedIn Independent Controller AddendumLinkedIn first-party advertising click identifier derived from li_fat_id, conversion event name and timestamp, a pseudonymous event-deduplication identifier, and, for PaidWorkspace only where enabled, recorded contracted value and currency; no email address, phone number, name, company name, IP address, user agent, or Customer ContentIreland and LinkedIn's international operations; restricted EU transfers use Module 1 controller-to-controller SCCs under the applicable termsOnly after consent and only when one of the four eligible conversion events occurs
Apple Distribution International Limited (with Apple Inc. where applicable)Separate controller — optional Sign in with AppleProvider identifier and identity claims you authorise Apple to return, including an email address or private-relay addressIreland / United StatesOnly if you choose Sign in with Apple
Slack Technologies, LLC (a Salesforce company)Sub-processor — optional Slack reminder deliveryReminder content and recipient Slack member IDUnited StatesOnly if your organisation enables Slack reminders
Yettel Bulgaria EADSub-processor — optional SMS reminder deliveryRecipient phone number and message contentBulgaria (EU)Only if your organisation enables SMS reminders

Google Cloud EMEA Limited acts as our processor for reCAPTCHA data used to protect the public contact and self-registration forms. This processing is outside the customer DPA and its Annex III because FSS controls it for its own website and account-security purpose. Google, Meta, and Apple act as separate controllers for their optional sign-in services and are outside Annex III for that distinct reason. Separately, Meta's role for consented Meta Conversions API processing is allocated by the Meta Business Tools Terms as described above. LinkedIn Ireland Unlimited Company acts as an independent controller for LinkedIn Marketing Solutions Conversion Tracking and Conversions API under the LinkedIn Independent Controller Addendum and may use the data to deliver, support, and improve those products, including conversions, and for its own reporting and performance analysis. These controller-side advertising activities are outside the customer DPA and Annex III.

9. International transfers

FSS stores core Service data on infrastructure in Bulgaria, European Union. Processing outside the EEA may occur when your organisation enables Slack delivery in the United States, you choose an identity provider whose international operations process the sign-in interaction, Google processes reCAPTCHA data in a country where Google or its Subprocessors maintain facilities, or consented advertising-conversion data is processed through Meta's or LinkedIn's international operations. Restricted reCAPTCHA transfers rely on the mechanisms and safeguards in the Google Cloud Data Processing Addendum. Meta conversion processing is governed by the Meta Business Tools Terms, incorporated processing terms, and applicable transfer safeguards. For the LinkedIn relevant products described above, restricted EU transfers use Module 1 controller-to-controller Standard Contractual Clauses under the LinkedIn Independent Controller Addendum. Other recipients must use an appropriate GDPR Chapter V mechanism where required. SMS delivery through Yettel stays within the EU.

10. How long we keep data

DataRetention
Customer Content and live tenant dataWhile the workspace is active. An authorised immediate-deletion request, executed by FSS, removes live data without creating a recovery archive. Under the customer-initiated closure path, live removal occurs only after a cancellable 14-day window, during which every workspace administrator is notified and any of them may cancel the closure; no recovery archive is created. Under the dormancy path, live removal occurs only after six months without meaningful web or MCP activity plus a 60-day warning/export opportunity.
Dormancy recovery archiveEncrypted and kept for 30 days after live removal, then permanently deleted. No recovery archive is created for either the FSS-executed immediate-deletion path or the customer-initiated 14-day closure path.
Sanitized post-closure audit and legal-acceptance evidenceFor no more than 90 days after tenant closure, then permanently deleted with the residual closed-tenant record, unless applicable law or a documented legal hold requires longer retention.
In-product audit entriesWhile the workspace is active; FSS may apply a shorter period on request.
MCP access events90 days by default; your organisation's administrators may set between 1 and 730 days.
Search log90 days by default; FSS may set a different period for your workspace on request.
Edit-session drafts24 hours after the edit is committed, discarded or expires, removed by the next nightly sweep (no later than 48 hours).
Rolling infrastructure backupsUp to 30 days, then overwritten under the backup cycle.
Application and security logs30 days.
reCAPTCHA data retained by FSSThe verification token and Google's raw response are not retained. Limited operational metadata — timestamp, outcome, score if returned, action, hostname, and request/correlation identifier — may be kept for up to 30 days.
Incomplete registration reservationsAutomatically deleted after the short registration-intent window expires.
Raw advertising click identifiers (Meta and LinkedIn)Until the last eligible enabled conversion event is delivered plus 30 days, with an absolute maximum of 180 days from capture. If no eligible event occurs, the identifier is deleted by that 180-day limit.
First-party acquisition record24 months from capture. It contains only the allowlisted source snapshot described in §4 and no Customer Content.
Funnel-milestone ledger and active-day record24 months from the date each entry was recorded.
Advertising conversion outbox and delivery evidence24 months after final delivery or permanent failure. The outbox stores bounded event and delivery evidence; raw platform click identifiers remain in the separately retained acquisition record and are not copied into the outbox.
Commercial lifecycle recordWhile the commercial relationship is active and for 24 months after it ends. Statutory tax, accounting, contract, or claim records may be retained separately for the applicable legal period.
Leads, contact-form submissions, registration enquiries, and related correspondence12 months, unless a longer period is needed for an ongoing relationship or legal claim.
Billing and accounting recordsNo fees apply during the free pilot. If billing is introduced, records required by tax or accounting law will be retained separately for the applicable statutory period and will never be used to preserve Customer Content.

During the bounded 90-day post-closure period, the tenant remains disabled. Retained records are sanitized and used only for security investigation, abuse prevention, service-integrity verification, contract evidence, and the establishment, exercise, or defence of legal claims. A legal hold must be explicit and documented; it is not the default. When the hold or legal duty ends, deletion resumes.

The acquisition, funnel, conversion-delivery, and commercial records listed above are FSS's own business and marketing records. They are stored separately from Customer Content, remain usable without retaining a closed workspace or its content, and may survive workspace closure for the listed periods. They do not preserve Customer Content. When the applicable period ends, identifiers are deleted or the remaining statistics are made genuinely anonymous, unless a documented legal duty or hold requires longer retention.

11. How we protect data

We use TLS encryption in transit, role-based access controls and least-privilege administration, logical isolation of customer tenants, network segmentation, and physical security at our data-centre facility. Our practices are aligned with the principles of ISO/IEC 27001, ISO/IEC 20000, and ISO 9001; FSS was previously certified to these standards, but certifications are not currently maintained. Operational logs do not contain broader AI prompts and do not record document bodies in the ordinary course; where an unexpected failure is recorded, the error text may include content your client sent, as described in §4. Search text is held only in the search log described in §4 and §10. We do not log or persist the reCAPTCHA token or Google's raw verification response.

12. Your rights

Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, and data portability, and the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it. To exercise rights concerning data for which FSS is controller, email privacy@brainattic.ai; we normally respond within one month.

You may object to first-party acquisition, funnel, and commercial measurement based on legitimate interests. If the objection is upheld, we suppress future use and future advertising-platform delivery linked to the identifiable record. You may withdraw advertising-conversion consent at any time through the site's cookie choices or by emailing privacy@brainattic.ai; withdrawal stops future delivery to Meta and LinkedIn but does not reverse processing already completed by either recipient. We erase identifiers where no overriding legal basis requires retention; genuinely anonymous aggregate campaign counts may remain.

For advertising-conversion data, FSS remains your first contact for FSS-controlled collection and disclosure and will coordinate with the relevant recipient where the applicable role allocation requires it. Meta and LinkedIn may also provide their own advertising and off-platform-activity controls under their respective services.

For Customer Content for which your organisation is controller, direct your request to that organisation; we will assist it as processor. For data processed independently by Google, Meta, or Apple during sign-in, exercise your rights with the relevant provider. For reCAPTCHA data, FSS remains your controller contact and Google processes the data on our behalf.

You may complain to the Commission for Personal Data Protection (CPDP), www.cpdp.bg, or another competent EU supervisory authority.

13. Children

brainattic is intended for business users aged 18 or over. It is not directed to children, and we do not knowingly process children's personal data through the public registration flow.

14. Changes to this notice

We may update this policy. We publish each version with its publication and effective dates. For material changes, we normally give at least 14 days' notice and notify customers through the Service or by email. We may require renewed acceptance before tenant-data web or MCP access continues after the effective date.

15. Contact

Privacy and data-protection enquiries: privacy@brainattic.ai. Product support: brainattic.ai/support or hello@brainattic.ai.

Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria.

We use strictly necessary cookies to run this site. With your permission we would also remember which campaign brought you here, so we can tell which of our own links are worth keeping. Decline and nothing optional is stored — the site works exactly the same either way. Read the Cookie Statement.

brainattic.ai

The governed knowledge base your team and your agents both trust.

Product

Features Use cases Connect to Claude, ChatGPT & Mistral Docs How it works FAQ Sign up Talk to us

Company

About Security Support Contact

Legal

Privacy Policy Terms of Service Cookie Policy Data Processing Agreement Cookie choices
© 2026 Finite Software Systems Ltd. brainattic is a product of Finite Software Systems Ltd. hello@brainattic.ai