Data Protection & GDPR
How Briyoo approaches data protection, your rights, and our commitments under the GDPR.
Last updated: 9 August 2026
Privacy Policy
How we collect, use, and protect personal data.
Cookie Policy
How we use cookies and similar technologies.
DPA
Our standard Data Processing Agreement.
Briyoo's Role Under GDPR
Under the GDPR, our role depends on why and how we process personal data.
When we determine the purposes and means of processing — for example, running our website, managing our own accounts, communicating with prospects, and administering subscriptions — we act as a data controller.
When we process personal data on behalf of a business customer through their Briyoo workspace — for example, processing customer-provided marketing data to generate AI outputs — we act as a data processor, and the customer typically acts as the controller.
How Customer Data is Handled
Customer data is processed according to the customer's documented instructions and the functionality they choose to use.
Customers control what data they provide to Briyoo, which third-party integrations they connect, and which AI-powered features they activate.
Briyoo does not claim ownership of customer data. Customer data is used to provide, secure, and operate the Service — not for unrelated purposes.
AI Processing Approach
Artificial intelligence is a core component of Briyoo. AI systems may process customer-provided information to generate marketing strategies, content, recommendations, and analyses.
AI-generated outputs are probabilistic. They may be incomplete or require human review. Briyoo does not guarantee that an AI output is always factually correct or suitable for every use case.
Customer data is not used for generalized AI model training except where expressly permitted under the customer's agreement, applicable privacy documentation, and applicable law.
Where third-party AI infrastructure providers process customer personal data on our behalf, they are treated as subprocessors under applicable data protection law.
Your Rights
Under the GDPR, individuals may have the right to access, rectify, erase, restrict, or object to the processing of their personal data, as well as the right to data portability and the right to withdraw consent.
Where Briyoo acts as controller, individuals may exercise these rights directly with us by contacting privacy@briyoo.com.
Where Briyoo acts as processor on behalf of a business customer, individuals should direct their requests to the customer (the controller). Briyoo will assist the customer in responding to such requests as required by applicable law.
Individuals also have the right to lodge a complaint with the competent data protection supervisory authority.
International Data Transfers
Briyoo may use providers operating outside the European Economic Area.
Where personal data is transferred internationally and applicable law requires safeguards, we rely on recognized transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, or other legally recognized safeguards.
Additional technical and organizational measures may be implemented where appropriate based on the circumstances of the transfer.
Security Principles
Briyoo implements technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures may include authentication controls, role-based access, encryption in transit, logging and monitoring, environment and data segregation, and incident-response procedures.
No online service can guarantee absolute security. Customers remain responsible for securing their own credentials, devices, and workspace configuration.
Data Processing Agreement
Business customers who require a Data Processing Agreement (DPA) under Article 28 of the GDPR can review our standard DPA.
The DPA governs Briyoo's processing of personal data on behalf of customers in connection with the Briyoo Service.
It covers processing instructions, security measures, subprocessors, international transfers, data subject requests, breach notification, and audit rights.
Privacy Questions
For privacy questions, data subject requests, or to request a copy of our DPA, contact us at:
privacy@briyoo.com