briqbriq
Dashboard

Privacy notice

What personal data briq collects, why, for how long, and what you can ask us to do with it.

Article 12 of the GDPR asks for plain language, so this is written in plain language rather than in legal boilerplate. If anything here is unclear, write to us and we will fix the wording.

Last updated: 21 September 2026.

Who is responsible

briq is operated by [TO FILL: legal entity name], registered in France under [TO FILL: SIREN/SIRET], at [TO FILL: registered address].

For questions about this notice or about your data: privacy@briq.run.

We have not appointed a Data Protection Officer. Article 37 requires one where the core activity is large-scale systematic monitoring or large-scale processing of special categories of data; neither applies to briq. If that changes, this section changes with it.

What we collect and why

DataWhyLegal basis
Name, email addressCreate and identify your account; send service email you cannot opt out of, such as security noticesContract, Art. 6(1)(b)
Password hashAuthenticate youContract, Art. 6(1)(b)
Session token, IP address, browser user agentKeep you signed in; detect session abuseContract for the session itself; legitimate interests, Art. 6(1)(f), for abuse detection
Team name, slug, membership roleTenancy: decide who may see and change whatContract, Art. 6(1)(b)
API key name, prefix and SHA-256 hash, and the key's policyAuthenticate your agents and enforce their limits. The key itself is never stored and cannot be recoveredContract, Art. 6(1)(b)
Audit rows: key id, action, target, duration, cost deltaShow you what your agent did; bill correctly; investigate abuseContract and legitimate interests, Art. 6(1)(f)
Briq metadata: image reference, digest, ports, size, TTL, env keys and non-secret valuesRun and meter your briqsContract, Art. 6(1)(b)
Invoices and accounting recordsKeep the booksLegal obligation, Art. 6(1)(c), Code de commerce Art. L123-22

Where we rely on legitimate interests, the interest is running a service that is not abused and that bills accurately. You can object under Article 21; see your rights.

We do not collect special category data under Article 9, we do not profile you, and no decision about you is made by automated means under Article 22.

What we deliberately do not collect

For what is inside your briqs, you are the controller and we are the processor. That relationship is governed by the data processing agreement, not by this notice.

What is stored on your device

briq does not use tracking or advertising cookies, and there are no third-party scripts on this site. There is nothing to consent to, so we do not ask.

StoredWhat it isWhy it is exempt from consent
Session cookieSet by our authentication layer when you sign inStrictly necessary for a service you asked for
briq.team in localStorageThe team you last selected in the dashboardInterface customisation you asked for

Both are exempt under Article 82 of the Loi Informatique et Libertés, which implements the ePrivacy Directive and requires consent only for storage that is not strictly necessary. The CNIL is explicit that consent should not be requested where the exemption applies. Typefaces are served from our own domain, so no request leaves for a third party when you load a page.

If we ever add analytics, error tracking that records your session, or an embedded payment script, that changes, and a consent banner appears before those load. We would rather add the banner on the day it becomes necessary than habituate you to clicking one that means nothing.

Who else sees your data

RecipientRoleWhere
Infrastructure providerCompute, storage and logs, and hosting for briq itselfParis (cdg); its corporate parent is incorporated in the USA

That is the entire list today. We name each recipient to any customer who asks, and to anyone with a data processing agreement in place: write to legal@briq.run. Payments, error tracking and an email provider are planned and not yet connected; we will publish changes here before they take effect. Details, including the US jurisdiction point and what it means, are in data protection.

We do not sell personal data, and we do not share it for anyone else's marketing.

How long we keep it

DataKept for
Account, team and membership recordsThe life of the account, then deleted within 30 days
SessionsUntil they expire or you sign out
Briq metadata and audit rows12 months, so that you can investigate what an agent did and we can resolve billing disputes
Logs readable through briq_logsWhile the briq exists; not retained after it is destroyed
Invoices and accounting records10 years, as French commercial law requires

Automatic deletion jobs are not implemented yet. Until they are, deletion at the end of these periods is performed by hand on request, which is a gap we are closing rather than a policy.

Your rights

Under Articles 15 to 22 you may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, hand it to you in a portable format, or stop processing you object to. Write to privacy@briq.run.

We answer within one month, as Article 12(3) requires. If a request is complex we may extend by two further months, and we will tell you why within the first month. We do not charge for this.

Two limits worth stating plainly: we cannot recover an API key, because we only store its hash; and we cannot delete accounting records before the ten years are up, because the law requires us to keep them.

If you think we have handled your data badly, please tell us first, but you have every right to go straight to a supervisory authority instead. In France that is the CNIL.

Changes

If this notice changes in a way that affects you, we will email account holders rather than quietly editing the page. The date at the top is the version.