Legal
Privacy Policy
Last updated: 1 September 2026. Bren Labs, Inc. is a fictional company; this document is provided for demonstration purposes and is modelled on a standard SaaS policy.
1. Who we are
Bren Labs, Inc. ("Bren", "we", "us") provides the Bren service at getbren.com and in the Bren apps for Slack and Microsoft Teams. Our address is 548 Market St, San Francisco, CA 94104, USA. For privacy questions contact privacy@getbren.com. Our Data Protection Officer can be reached at the same address.
2. Scope and roles
This policy covers two situations:
- Website visitors and prospective customers (people who browse getbren.com, start a trial, or book a demo). Here Bren is the controller.
- People whose employer uses Bren ("Workspace Users"). Here your employer (the "Customer") is the controller and Bren is a processor acting on its instructions under our Data Processing Agreement. Questions about how your employer configures Bren — which channels, projects and documents are connected, whether private notes feed AI summaries — should go to your employer's workspace admin.
3. Data we collect
3.1 From website visitors and prospects
- Information you give us in the trial sign-up or demo forms: name, work email, company, role, team size, tools in use, notes.
- Support correspondence sent to help@, security@ or privacy@getbren.com.
- Technical data: IP address, browser type, pages viewed, referrer, approximate location derived from IP, and cookies described in section 9.
- If an AI assistant is enabled on this website, the content of your conversation with it.
3.2 From Workspace Users (as processor)
- Account data: name, email, role, team, manager, profile picture, time zone.
- Content from tools the Customer connects, limited to the scope the Customer's admin configures: messages in chat channels Bren is invited to and direct messages with Bren; task and project data; documents shared with connected users; meeting transcripts and recordings already produced by the meeting tool; calendar metadata; pull-request and commit metadata (never source code); emails only in folders a user explicitly labels.
- Content Workspace Users create in Bren: updates, notes, questions to Ask Bren, outcome marks, OKRs.
- Derived data: summaries, digests, timelines, embeddings, red flags.
3.3 What we never collect
Keystrokes, screenshots, screen time, device location, application or browser usage, webcam or microphone input, direct messages between people, or source code.
4. How we use data
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the Bren service to Customers | Workspace User data | Processor on Customer instructions (Art. 28); Customer's legitimate interests |
| Set up trials, arrange demos, respond to enquiries | Form and correspondence data | Pre-contractual steps (Art. 6(1)(b)); legitimate interests |
| Send product and marketing email to prospects | Work email, company | Legitimate interests; consent where required. Unsubscribe in every email. |
| Secure, monitor and improve the website and service | Technical data, aggregated usage | Legitimate interests |
| Comply with law and enforce terms | Any | Legal obligation; legitimate interests |
AI models. Bren uses third-party large language models under enterprise agreements with zero data retention: prompts and outputs are not stored by the provider and are not used to train their models. Bren does not train or fine-tune models on Customer or visitor data.
5. Sharing
We share personal data only with: (a) sub-processors that host or support the service (cloud hosting, model providers, email delivery, payment processing, support tooling), each bound by contract; the current list is available on request and in the DPA; (b) the Customer that controls a workspace; (c) professional advisers, and authorities where required by law; (d) a successor in a merger or acquisition, with notice. We do not sell personal data and do not share it for cross-context behavioural advertising.
6. International transfers
Data is hosted on Amazon Web Services in the United States by default, or in the European Union (Frankfurt) for Enterprise Customers who select EU residency. Transfers out of the EEA/UK rely on Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
7. Security
Bren is SOC 2 Type II audited. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Private notes are additionally encrypted per workspace and cannot be read by Bren staff or workspace admins. Access to production systems is restricted, logged and reviewed. We notify affected Customers of confirmed personal-data breaches within 72 hours.
8. Retention
- Prospect data: up to 24 months after last contact, unless you become a Customer or ask us to delete it sooner.
- Workspace data: for the life of the subscription, subject to plan history limits and any Customer-configured retention. After cancellation, export is available for 30 days; all data is deleted within 30 days of the end of the paid period, and backups purge within a further 35 days.
- Individual Workspace Users: deleted within 30 days of a Customer request or a verified data-subject request; contributions to team timelines are anonymised unless the Customer requests removal.
9. Cookies
getbren.com sets only strictly necessary cookies and local storage needed for the site to function (for example, remembering a form state). If an on-site AI assistant is enabled it may set its own functional cookie to keep your conversation continuous. We do not use advertising cookies. You can block cookies in your browser; the site will still work.
10. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or port your personal data, to object to processing, and to withdraw consent. Website visitors and prospects can exercise these rights by emailing privacy@getbren.com; we respond within 30 days. Workspace Users should contact their employer, who controls the workspace; we will assist the Customer in responding. You may also complain to your supervisory authority. California residents: we do not sell or share personal information; you may request disclosure or deletion and will not be discriminated against for doing so.
11. Children
Bren is a workplace tool and is not directed at anyone under 16. We do not knowingly collect data from children.
12. Changes
We will post changes here and, for material changes, notify Customers by email at least 30 days in advance.
13. Contact
Bren Labs, Inc., 548 Market St, San Francisco, CA 94104, USA. Privacy: privacy@getbren.com. Security: security@getbren.com. Support: help@getbren.com.