Privacy Policy
Last updated: 23/08/2026
1. Data controller
The controller of your personal data is Brisk (hereinafter: „we”, „us”, „Controller”).
Contact with the Controller — email: kontakt@localhost.
- For data provided when creating an account, joining the waitlist, or contacting us — Brisk is the controller
- For data the Organization enters into the Platform (e.g. its customers, work orders, and protocols) — the Organization is the controller and Brisk processes that data on its behalf as a processor (Art. 28 GDPR)
2. What data we collect — account and Platform
In connection with your use of the Brisk platform (web and mobile app) we process:
- Account data — first and last name, email address, phone number, role in the Organization
- Organization data — company name, tax ID (NIP), address, billing details
- Work order data — order contents, notes, photos and attachments, and the Organization's customer data (entered by the Organization)
- Protocol signatures — the signature image only (details in section 4)
- Technician location — only under the rules described in section 5
- Technical data — system logs, device identifiers and push notification tokens, application error reports
3. What data we collect — waitlist and contact
When signing up to the waitlist we collect:
- First and last name — to personalise communication
- Email address — to contact you and send platform updates
- Phone number (optional) — for phone contact
- Marketing consents — record of the consents you granted
- Date and time of registration — for technical and analytical purposes
4. Protocol signatures — no biometric data
Service protocols can be signed on the device screen (drawn signature). We store only the signature image (a PNG file) attached to the protocol.
We collect no biometric data — we do not record the dynamics, pressure, speed, or pace of the signature. The signature image is not used for biometric identification.
5. Technician location
The mobile app may process the technician's location so that the coordinator can see the team's position on a map and plan work more efficiently.
- Location is processed only while logged in, from the start of travel or work on an order until it ends — including when the app runs in the background
- It requires system-level consent (iOS/Android); background tracking may require the 'Always' permission. You can revoke consent at any time in your phone settings
- The position is visible only to authorized people in your Organization
6. Legal basis for processing
We process your data based on:
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the Platform services for your account and Organization
- Your consent (Art. 6(1)(a) GDPR) — waitlist sign-up, marketing communication, technician location
- Legal obligation (Art. 6(1)(c) GDPR) — accounting and retention of financial records
- Legitimate interest (Art. 6(1)(f) GDPR) — Platform security (bot and abuse protection), error monitoring, statistics and service improvement
7. Why we process your data
- Providing the Platform services — accounts, work orders, protocols, billing
- Sending notifications about work orders and Organization events (email, push notifications)
- Security — bot protection, rate limiting, error monitoring
- Billing, payments, and invoicing
- Informing you about the platform launch and updates (waitlist)
- Sending marketing materials (only with your consent)
- Statistics and service quality improvement
8. Who we share your data with
We use trusted providers that process data on our behalf:
- Supabase — database, authentication, and file storage (EU-based infrastructure)
- Vercel — web application hosting
- Cloudflare — bot protection for public forms (Turnstile)
- Sentry — application error monitoring
- PostHog — product analytics (EU servers, cookieless mode)
- Mapbox — maps and geocoding of work order addresses
- Stripe — payment processing
- Fakturownia — invoicing
- Email provider — transactional email delivery
9. How long we keep your data
We keep your data:
- Account data (name, email, phone) — deleted together with the Account; operational entries made in the Platform (work orders, notes, costs) remain with the Organization as its history, unlinked from the deleted Account
- Organization data — for the duration of the contract; deletion of the entire Organization is done on request (contact: kontakt@localhost)
- Financial records (invoices, billing data) — for the period required by law (as a rule, 5 years)
- Waitlist data — until consent is withdrawn, at most 24 months from sign-up
- Technical logs and error reports — for the period needed to ensure security and diagnose problems
10. Your rights (GDPR)
You have the right to:
- Access your data — request a copy of your personal data
- Rectify your data — request correction of inaccurate data
- Erase your data („right to be forgotten”) — request deletion of your data
- Restrict processing — request limits on how your data is processed
- Data portability — receive your data in a format allowing transfer to another controller
- Object — withdraw consent to processing at any time
- Lodge a complaint with UODO — the Polish Data Protection Authority (uodo.gov.pl)
11. Cookies and tracking technologies
Our site and Platform use only essential technologies:
- Technical cookies (essential) — login session and security; the Platform does not work without them
- Cookieless analytics — PostHog runs in memory-only mode (data is discarded when the tab closes); we do not build cross-session profiles or track you across other sites
12. Data security
We apply technical and organisational measures to protect your data:
- Encrypted connections (SSL/TLS)
- Secure storage in the database (Supabase with RLS)
- Regular backups
- Restricted access to personal data
13. Changes to this Privacy Policy
We may update this Privacy Policy. We will notify you of material changes by email or a notice on the site.
14. Contact regarding personal data
If you have questions about personal data protection, contact us — email: kontakt@localhost (subject: „GDPR inquiry”).