Privacy Policy
Last updated: July 12, 2026
The German version is legally authoritative; this English text is provided for convenience.
1. Controller
The controller within the meaning of the GDPR is:
Brisky Bytes GmbH
Kolonnenstraße 8, 10827 Berlin, Germany
Managing Director: Denis Lobo
Email: [email protected]
Phone: +49 151 65909293
We have not appointed a data protection officer, as the legal requirements for doing so are not met. Please use the address above for all data protection matters.
2. Data we process, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Account and sign-in data (email, hashed password, display name) | Providing and managing your user account | Art. 6(1)(b) GDPR (contract / use relationship) |
| Email address for verification and password-reset messages | Sending transactional emails (account confirmation, password reset) | Art. 6(1)(b) GDPR |
| Lead and contact data of the prospects you enter (name, email, message text, profile URL) | Demonstrating the AI-based lead scoring | Art. 6(1)(f) GDPR (legitimate interest: providing the demo feature) |
| Usage and log data incl. IP address | Security, abuse and cost protection (rate limiting) | Art. 6(1)(f) GDPR |
| Error and diagnostic data | Stability and troubleshooting (monitoring) | Art. 6(1)(f) GDPR |
3. AI-based lead scoring
The core of the application is the automatic assessment of incoming messages (“leads”). For this, the message text of the respective lead is transmitted via the service provider OpenRouter to an AI language model (Anthropic or OpenAI, depending on the selected model) and processed there to produce a classification (COLD, WARM, HOT, SPAM) and a short justification. The integration is configured so that requests are routed only to the respective designated provider and the transmitted content is not used to train the models. This processing is based on Art. 6(1)(f) GDPR.
4. Recipients and processors
To provide the service, we use carefully selected providers that process personal data on our behalf and under our instructions (processing under Art. 28 GDPR):
| Provider | Purpose | Location / processing |
|---|---|---|
| Railway Corp. | Hosting of the application and database | USA (processing in the EU region) |
| Resend | Sending transactional emails | USA |
| OpenRouter | Routing of AI requests (gateway) | USA |
| Anthropic PBC | AI language model for lead scoring | USA |
| OpenAI | AI language model for lead scoring | USA |
| Sentry (Functional Software, Inc.) | Error and stability monitoring | USA |
5. Transfers to third countries
Some of the providers listed are based in the USA. Where personal data is transferred to a third country, this is done on the basis of the EU Standard Contractual Clauses (Art. 46 GDPR) and — where the respective provider is certified — the EU-US Data Privacy Framework (Art. 45 GDPR). The core infrastructure (hosting and database) is operated in the EU region.
6. Retention
- Demo data (leads and the data attached to them) is automatically deleted after 7 days. Your account is not affected.
- Account data is stored until you or we delete the account; you can request deletion at any time.
- Log and monitoring data is stored only as long as necessary for security and troubleshooting, then deleted.
- Session tokens are short-lived and expire automatically.
7. Cookies
We do not use cookies for analytics or marketing and do not embed any tracking services. We use only one strictly necessary cookie (refreshToken) that keeps you signed in. It is required for operation (§ 25(2) TDDDG, Art. 6(1)(f) GDPR) and therefore does not require consent. A cookie banner is not necessary.
8. Your rights
Under the GDPR you have the following rights:
- Access to the data stored about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure (Art. 17) and restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing based on legitimate interest (Art. 21)
To exercise these rights, a message to [email protected] is sufficient. You also have the right to lodge a complaint with a data protection supervisory authority.
9. Competent supervisory authority
Berlin Commissioner for Data Protection and Freedom of Information
Alt-Moabit 59–61, 10555 Berlin, Germany
10. Your responsibility for third-party data you enter
If you enter data about other people (e.g. the name, email address or message text of a prospect) into the application, you may only do so if you are authorised and a legal basis exists. You are responsible for not entering data you are not permitted to use.