Brisky Bytes

Privacy Policy

Last updated: July 12, 2026

The German version is legally authoritative; this English text is provided for convenience.

1. Controller

The controller within the meaning of the GDPR is:

Brisky Bytes GmbH
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Denis Lobo
Email: [email protected]
Phone: +49 151 65909293

We have not appointed a data protection officer, as the legal requirements for doing so are not met. Please use the address above for all data protection matters.

2. Data we process, purposes and legal bases

DataPurposeLegal basis
Account and sign-in data (email, hashed password, display name)Providing and managing your user accountArt. 6(1)(b) GDPR (contract / use relationship)
Email address for verification and password-reset messagesSending transactional emails (account confirmation, password reset)Art. 6(1)(b) GDPR
Lead and contact data of the prospects you enter (name, email, message text, profile URL)Demonstrating the AI-based lead scoringArt. 6(1)(f) GDPR (legitimate interest: providing the demo feature)
Usage and log data incl. IP addressSecurity, abuse and cost protection (rate limiting)Art. 6(1)(f) GDPR
Error and diagnostic dataStability and troubleshooting (monitoring)Art. 6(1)(f) GDPR

3. AI-based lead scoring

The core of the application is the automatic assessment of incoming messages (“leads”). For this, the message text of the respective lead is transmitted via the service provider OpenRouter to an AI language model (Anthropic or OpenAI, depending on the selected model) and processed there to produce a classification (COLD, WARM, HOT, SPAM) and a short justification. The integration is configured so that requests are routed only to the respective designated provider and the transmitted content is not used to train the models. This processing is based on Art. 6(1)(f) GDPR.

4. Recipients and processors

To provide the service, we use carefully selected providers that process personal data on our behalf and under our instructions (processing under Art. 28 GDPR):

ProviderPurposeLocation / processing
Railway Corp.Hosting of the application and databaseUSA (processing in the EU region)
ResendSending transactional emailsUSA
OpenRouterRouting of AI requests (gateway)USA
Anthropic PBCAI language model for lead scoringUSA
OpenAIAI language model for lead scoringUSA
Sentry (Functional Software, Inc.)Error and stability monitoringUSA

5. Transfers to third countries

Some of the providers listed are based in the USA. Where personal data is transferred to a third country, this is done on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR) and — where the respective provider is certified — the EU-US Data Privacy Framework (Art. 45 GDPR). The core infrastructure (hosting and database) is operated in the EU region.

6. Retention

  • Demo data (leads and the data attached to them) is automatically deleted after 7 days. Your account is not affected.
  • Account data is stored until you or we delete the account; you can request deletion at any time.
  • Log and monitoring data is stored only as long as necessary for security and troubleshooting, then deleted.
  • Session tokens are short-lived and expire automatically.

7. Cookies

We do not use cookies for analytics or marketing and do not embed any tracking services. We use only one strictly necessary cookie (refreshToken) that keeps you signed in. It is required for operation (§ 25(2) TDDDG, Art. 6(1)(f) GDPR) and therefore does not require consent. A cookie banner is not necessary.

8. Your rights

Under the GDPR you have the following rights:

  • Access to the data stored about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17) and restriction of processing (Art. 18)
  • Data portability (Art. 20)
  • Objection to processing based on legitimate interest (Art. 21)

To exercise these rights, a message to [email protected] is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority.

9. Competent supervisory authority

Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin, Germany

10. Your responsibility for third-party data you enter

If you enter data about other people (e.g. the name, email address or message text of a prospect) into the application, you may only do so if you are authorised and a legal basis exists. You are responsible for not entering data you are not permitted to use.