Skip to content
brainattic.ai
Watch Product Use cases Connect Docs How it works Log in
Request a pilot

Privacy Policy

Effective date: 9 June 2026 · Last updated: 9 June 2026

brainattic is a knowledge-base service that your team — and the AI agents you connect — read from and write to. We keep your data on our own infrastructure in the European Union, we don't send it to any third-party AI model, and we collect only what we need to run the service. This notice explains what we process, why, who else is involved, how long we keep it, and your rights.

1. Who we are

The service and the brainattic.ai website are operated by Finite Software Systems Ltd. (Bulgarian: ФИНИТ Софтуер Системс ЕООД) ("FSS", "we", "us"), the provider of the brainattic product.

  • Registered office: 4 Gorotzvet Street, Sofia, Bulgaria
  • Company No. (ЕИК): 175276896 · VAT: BG175276896
  • Privacy contact: privacy@brainattic.ai
  • Data Protection Officer: none appointed (not required at our scale); privacy enquiries are handled by the contact above.
  • Supervisory authority: Commission for Personal Data Protection (CPDP), Sofia, Bulgaria — www.cpdp.bg

2. Scope

This notice covers (a) the brainattic.ai website and (b) the brainattic service — the knowledge-base application and the connector that exposes it to AI clients over the Model Context Protocol (MCP). brainattic is a business-to-business service intended for organisations and their authorised users aged 18 or over. It is not directed to consumers or to children.

3. Controller and processor — who decides what

The split matters because it determines who is responsible for which data:

  • Your knowledge-base content — the documents, attachments, search queries, reminders and audit entries your organisation creates in brainattic, including any personal data you choose to put in them. Here your organisation is the data controller and FSS is a processor acting on your documented instructions. This processing is governed by our Data Processing Agreement.
  • Account, website, support and marketing data — described in §4. Here FSS is the controller.

4. What we process

Account & identity. Name, work email, organisation, a securely hashed password, and OAuth/session tokens used to authenticate you. Authentication is handled by FSS's own authorisation server — we do not use a third-party identity provider.

Customer content (as processor). Documents, attachments, vector embeddings derived from your content, search queries, reminders, and the in-product audit log — plus any personal data your organisation chooses to include.

Reminder-delivery data. If you use reminders, the identifier for the channel you choose: an email address; a Slack member ID (only if you enable Slack delivery); or a mobile phone number (only if you enable SMS delivery).

Technical & security data. IP address, timestamps, the endpoint/request and its status, and basic device/browser metadata, recorded in operational and security logs.

Website & marketing data. What you submit through the site's contact form — your email, company, and message.

Cookies. Only strictly necessary cookies (a session cookie and a CSRF-protection token). No analytics or tracking cookies. See the Cookie Policy.

What we do not collect. We do not request or store the content of your AI conversations or prompts. When you use brainattic through an AI client, the connector receives only the input needed to perform the specific action you ask for (for example, a search term, or the document text you ask it to save) and returns a scoped result. We do not ingest your broader chat history, transcripts, or precise location.

5. How the connector handles data

brainattic exposes MCP tools that read and write your knowledge base under your instruction. Each tool processes only the inputs required for that call and returns only the data needed to answer it. Tools are scoped and paginated; they do not collect extraneous conversation data, and write actions are explicit. This reflects the data-minimisation standards of the AI platforms through which brainattic is offered.

6. Why we process it, and our legal bases (GDPR Art. 6)

PurposeLegal basis
Provide and operate the service and your accountPerformance of a contract — Art. 6(1)(b); for customer content as processor, on the controller's documented instructions — Art. 28
Deliver reminders through the channel you choosePerformance of a contract / your instruction
Keep the service secure, prevent abuse, keep operational logsOur legitimate interests — Art. 6(1)(f)
Respond to contact-form enquiriesLegitimate interests / steps prior to a contract — Art. 6(1)(f)/(b)
Comply with legal obligationsLegal obligation — Art. 6(1)(c)

We do not carry out advertising profiling or sell personal data.

7. AI models

brainattic does not send your data to any third-party AI model. The AI you use (for example, Claude, ChatGPT, or Mistral) connects to brainattic as your own client; your use of that AI is governed by your agreement with its provider. That provider is not our sub-processor, and we are not theirs, for this purpose.

8. Who else is involved (recipients & sub-processors)

The core service is self-hosted on FSS-controlled infrastructure in the EU — including document storage, search and embeddings, e-mail, and authentication. We engage a small number of external parties:

PartyRoleData involvedLocationWhen
Telepoint EADData-centre colocation (physical facility; no logical access to data)Hardware housing all stored dataSofia, Bulgaria (EU)Always
A1 Bulgaria EAD (SPNET)Internet connectivity / IP transitData in transit (encrypted)Bulgaria (EU)Always
Slack Technologies, LLC (a Salesforce company)Optional reminder delivery via Slack DMReminder content + recipient Slack member IDUnited StatesOnly if your organisation enables Slack reminders
Yettel Bulgaria EADOptional reminder delivery via SMSRecipient phone number + message contentBulgaria (EU)Only if your organisation enables SMS reminders

We require recipients that process personal data on our behalf to provide appropriate safeguards. The current sub-processor list is maintained in our Data Processing Agreement; we will give customers notice of material changes.

9. International transfers

Our infrastructure and your data are located in the European Union (Bulgaria). The only processing that may occur outside the EEA is an optional integration you choose to enable — Slack (United States) for reminder DMs — carried out under an appropriate transfer mechanism (e.g. Standard Contractual Clauses or the provider's certified framework). SMS delivery via Yettel stays within the EU. If you do not enable Slack reminders, no transfer outside the EEA takes place.

10. How long we keep it

DataRetention
Customer content (documents, attachments, embeddings, reminders)For the life of the account; deleted within 30 days of account closure
In-product audit logFor the life of the tenant; deleted with content on closure
BackupsRolling, up to 30 days, then overwritten
Application & security logs30 days
Account & administrative dataLife of the account, then 30 days
Contact-form submissions12 months

We may retain limited information for longer where required to meet a legal obligation or to establish, exercise or defend legal claims.

11. How we protect it

We use TLS encryption for data in transit; role-based access controls and least-privilege administration; logical isolation of each customer tenant; network segmentation; and physical security at our data-centre facility. Our internal practices are aligned with the principles of ISO/IEC 27001 (information security), ISO/IEC 20000 (IT service management) and ISO 9001 (quality) — FSS was previously certified to these standards; certifications are not currently maintained. Our logs capture operational and security metadata, not the content of your documents or AI prompts.

12. Your rights

Subject to the GDPR, you have the right to access your personal data and to rectification, erasure, restriction, data portability, and to object to processing based on legitimate interests; where processing relies on consent, you may withdraw it at any time. To exercise these, email privacy@brainattic.ai; we respond within one month.

Where the data is customer content for which your organisation is the controller, please direct your request to that organisation — we will assist them as their processor.

You also have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), www.cpdp.bg, or with your local EU supervisory authority.

13. Children

brainattic is intended for business users aged 18 or over. It is not directed to children, and we do not knowingly process the personal data of minors.

14. Changes to this notice

We may update this policy from time to time. We will post the updated version here with a new "last updated" date and, where changes are material, notify customers by email.

15. Contact

Finite Software Systems Ltd. — 4 Gorotzvet Street, Sofia, Bulgaria · privacy@brainattic.ai

brainattic.ai

The governed knowledge base your team and your agents both trust.

Product

Features Use cases Connect to Claude, ChatGPT & Mistral Docs How it works FAQ Request a pilot

Company

About Security Contact

Legal

Privacy Policy Terms of Service Cookie Policy Data Processing Agreement
© 2026 Finite Software Systems. brainattic is a product of Finite Software Systems. hello@brainattic.ai