Privacy
Privacy Policy
Last updated: 11 September 2026
This Privacy Policy explains how Brainwave GmbH (“Brainwave”, “we”, “us”) processes personal data when you visit wearebrainwave.co, contact us, subscribe to updates, use the client portal or AI assistant, attend a Brainwave event, or work with us. It is intended to meet the transparency requirements of the Swiss Federal Act on Data Protection (“FADP”) and, where applicable, the EU GDPR and UK GDPR.
1. Controller and contact
Brainwave GmbHRebackerstrasse 2
3210 Kerzers
Switzerland
Email: hello@wearebrainwave.co
UID: CHE-150.886.832
Brainwave GmbH is the controller for the processing described here unless a separate notice says otherwise.
2. Personal data we process
2.1 Website and device data
When you access the site, our hosting and security systems may process your IP address, request URL, browser and device information, referring page, timestamps, response status, and related security or diagnostic events. We use this information to deliver the site, prevent abuse, and investigate failures.
2.2 Enquiries, session feedback and business relationships
If you contact us or submit a form, we process the information you provide, including your name, company, email address, optional telephone number, message, and later correspondence. Please do not send medical records or sensitive health information through the public contact form.
Submissions are stored in our database as well as sent to us by email, so that we can answer you reliably and so that a later request to see or delete your information can actually be met. We also keep a salted, one-way hash derived from your network address for a short period, used only to detect automated abuse of the forms; we do not store the address itself.
For current website enquiries only, we may use Anthropic's Claude API to prepare an internal draft reply. The structured input contains only your first name, company, selected services, budget band, and message for this purpose. We do not add the dedicated email-address or telephone-number fields, network address or its hash, internal identifiers, or consent metadata. Because the company and message fields are included as entered, anything you choose to type within either field is part of the model input. Once generated, the draft is frozen in a private Supabase retry record, an outbox used solely for durable retry, and then copied to the restricted Draft Responses field in Notion. It is not shown on the website or admin portal, added to a notification email, or sent to you automatically. A Brainwave team member must review it and decide whether and how to reply. A drafting failure does not prevent the original enquiry from reaching our Notion workflow.
If you complete one of our post-session feedback forms, we process the workshop and company identified by its link, your ratings, anything you write in your own words and, on the general form, the topics you would like us to cover next. We use it to improve the sessions we run and to report aggregate results over time. An organiser may give us attendee email addresses so that we can send the workshop link; we use those addresses for that invitation and keep its delivery outcome. We do not connect an invitation address to a response unless you choose to type your own email into the form. The name and email fields are optional: if you leave them blank we hold no contact details in your response, and the salted network hash and short-term records described above are the only technical traces, on the same schedules. If you tick the box giving us permission to quote your feedback publicly, we may publish your words on our website and social channels attributed to your first name and company only, never your email address or full name; we record that you gave the permission and when. You can withdraw it at any time by contacting us, and we will stop using the quote.
2.3 Newsletter
If you actively consent to email updates, we process your email address, the consent wording and source, the date and time of consent, delivery events needed to operate the mailing, and any unsubscribe request. We store your signup and consent record in Supabase and add your email address to our newsletter list in Resend, which sends our fortnightly newsletters and manages unsubscribe preferences. You can withdraw consent at any time using the unsubscribe link in a newsletter or by contacting us.
2.4 Client portal
For invited clients, we process the invited email address, authentication and session events, account role, engagement profile and dates, assigned actions and completion status, project milestones, requests or feedback submitted through the portal, document metadata, files Brainwave shares with that account, and access or administrative events needed to keep the service secure. Portal files are held in private storage. Each download is re-authorised by the portal and recorded using the document identifier, time, and pseudonymous user and network hashes; the private short-lived storage link stays on the server. Please do not submit medical records or sensitive health information in portal requests.
2.5 AI assistant
When you choose to use the AI assistant, the messages and recent conversation context you submit are sent to Anthropic to generate a response. The visible conversation is also stored in your browser's session storage so it remains available in that browser tab. Brainwave does not intentionally add public-assistant transcripts to its own client database. For both this assistant and the internal enquiry drafting described in section 2.2, Anthropic states that standard API inputs and outputs are automatically deleted from its backend within 30 days, except where a service has longer retention, different terms have been agreed, or longer retention is needed for usage-policy enforcement or legal compliance. Do not submit confidential, identifying, medical, or other sensitive information. The assistant is not a healthcare service and is not suitable for emergencies.
2.6 Workshops, events, and services
When you or your organisation books or attends a service, we may process participant and organiser contact details, role, attendance, scheduling information, feedback, contractual records, and billing information. If photographs or recordings are planned, we will provide an event-specific notice and, where required, obtain consent or provide a practical opt-out.
2.7 Sensitive data
Brainwave does not need medical records for ordinary website use. Where a workshop or service legitimately requires health-related accessibility or wellbeing information, we collect only what is necessary, provide a specific notice, restrict access, and obtain explicit consent or rely on another valid legal basis where required. Reports for organisations should be aggregated or de-identified wherever practical.
2.8 Social media and external sites
This site links to Brainwave pages on Instagram and LinkedIn. The visible Instagram images on this website are hosted locally and are not social-media embeds. If you follow an external link, that provider processes information under its own privacy terms.
3. Where the data comes from
We receive personal data directly from you, from your employer or event organiser, from people who invite you to the client portal, and automatically from your device and our service providers when you use the site. We may also receive ordinary professional contact information from publicly available sources or business partners.
4. Purposes and legal bases
Under the FADP, we process data lawfully, proportionately, and for disclosed purposes. Where the GDPR or UK GDPR applies, the corresponding legal bases are set out below.
| Purpose | Typical GDPR / UK GDPR basis |
|---|---|
| Delivering and securing the website; preventing misuse | Legitimate interests in a secure, reliable service (Art. 6(1)(f)) |
| Responding to enquiries, including preparing a human-reviewed reply draft, and preparing or performing services | Steps before or performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Administering the client portal and sharing contracted work | Contract (Art. 6(1)(b)); legitimate interests in secure delivery (Art. 6(1)(f)) |
| Sending newsletters and optional marketing updates | Consent (Art. 6(1)(a)) |
| Answering a user-requested AI chat | Requested service or steps before a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Keeping invoices, contracts, and compliance records | Legal obligations (Art. 6(1)(c)); legitimate interests in establishing or defending claims (Art. 6(1)(f)) |
| Processing sensitive data where genuinely required | Explicit consent or another condition permitted by applicable law (including Art. 9 GDPR) |
Where we rely on legitimate interests, we assess the necessity and impact of the processing and take reasonable steps to protect your rights. You may object as described below.
5. Recipients and service providers
We disclose data only where needed for the purposes above, including to authorised Brainwave personnel, professional advisers, public authorities where legally required, and the following categories of processors:
| Provider | Function and data involved |
|---|---|
| Vercel | Website hosting, content delivery, server functions, and operational/security logs; device and request data and information submitted to site functions. |
| Supabase | Passwordless authentication, database, and private portal storage; account details, authentication events, document metadata, and files. Also the record of website form submissions: the details you enter, any newsletter consent record, a salted hash used only to detect abuse, and a private retry record for a generated enquiry reply draft. |
| Notion | Internal operations and optional workflow copies: website enquiry and feedback fields, contact and company details, consent metadata, human-reviewed enquiry reply drafts, client-request summaries, invoice metadata and PDFs, and administrator task/brief information. Access is restricted to the Brainwave workspace and only the configured data sources/pages are used. |
| Anthropic | AI response generation when you use the assistant, using the prompts and recent conversation context you submit; and internal website-enquiry reply drafting, using structured inputs limited to first name, company as entered, selected services, budget band, and the message as entered. |
| Resend or a documented form-delivery webhook | Delivery of contact submissions and service emails; form details, email address, consent record, and delivery metadata. Resend also holds our newsletter mailing list, sends newsletters, and manages unsubscribe preferences. |
Service providers may use subprocessors. They are contractually restricted to the relevant service and must protect the information. If Brainwave changes a material provider, this notice will be updated.
6. International transfers
Brainwave is based in Switzerland. Depending on the selected hosting region and provider subprocessors, data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States, or other countries. Where a destination does not provide an adequate level of protection, we use recognised safeguards such as contractual data-protection clauses, data-processing agreements, and supplementary technical or organisational measures, or rely on a permitted exception. You may contact us for more information about applicable safeguards.
Notion is operated by a United States provider and its published infrastructure subprocessors currently include processing in the United States and Germany, with some global support services. Where a Notion transfer is restricted, Brainwave relies on the applicable Notion data-processing terms and recognised contractual transfer safeguards, together with access restriction and data minimisation.
7. Cookies and browser storage
The site currently uses only technologies needed for secure client access, saving your privacy choice, and chat functionality that you actively request. No analytics, advertising, or cross-site marketing cookies are active. The details, storage periods, and permanent settings control are in our Cookie Policy.
8. How long we keep information
We keep personal data only as long as needed for its purpose, legal obligations, or the establishment, exercise, or defence of legal claims. Typical periods are:
| Record | Typical retention |
|---|---|
| Enquiries that do not become an engagement | Up to 24 months after the last meaningful contact |
| Website form submissions and private enquiry-draft retry records held in our database | Up to 24 months, in line with the enquiry period above; the abuse-detection hash is removed after 30 days |
| Feedback responses and invitation delivery records | Up to 24 months; the abuse-detection hash is removed after 30 days |
| Resolved request-form responses and portal requests | Up to 24 months after resolution; open or in-review requests remain available until they are resolved |
| Operational copies in Notion | The same period as the source record where practical; deletion is queued and verified in Notion after the source period ends |
| Client, contract, invoice, and accounting records | Generally up to 10 years, where required by Swiss law or needed for claims |
| Client portal workspace data and files | For the engagement and an appropriate close-out period, then deleted or archived according to contractual/legal needs |
| Portal document authorization receipts | Up to 12 months; the network-derived hash is removed after 30 days |
| Public invoice access receipts | Up to 12 months, unless needed to investigate an incident or preserve a legal claim |
| Event and workshop administration | Usually up to 24 months, unless a contract or legal requirement needs longer |
| Newsletter consent | Until withdrawal; a limited suppression record may be kept to honour the unsubscribe |
| Security and operational logs under Brainwave's control | Normally no more than 12 months unless needed to investigate an incident |
| AI assistant history in the browser | Normally for the browser-tab session; provider-side API retention is described in section 2.5 |
| Sensitive workshop information | Only for the shortest necessary period, then deleted or aggregated |
| Event photographs or recordings | Until the stated purpose ends or applicable consent is withdrawn, subject to overriding legal grounds |
A legal, regulatory or dispute-preservation hold may pause deletion for the affected record. It does not extend the 30-day abuse-hash period. When a hold ends, the ordinary schedule resumes. Notion copies are included in access and deletion handling; a local database deletion is not treated as complete until the corresponding Notion copy has also been removed or a documented legal exception applies.
9. Security
We use reasonable technical and organisational measures appropriate to the risk, including access controls, private storage, short-lived file links, authenticated routes, input validation, rate limits, transport encryption, least-privilege credentials, and provider security controls. No internet service is completely secure. If you believe information has been exposed, contact us promptly.
10. Your rights
Depending on the law that applies, you may have the right to:
- ask whether we process personal data about you and receive a copy;
- correct inaccurate or incomplete information;
- request deletion or restriction, subject to legal exceptions;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time, without affecting earlier lawful processing; and
- complain to a competent data-protection authority.
To exercise a right, email hello@wearebrainwave.co. We may ask for proportionate information to verify your identity. In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. If the GDPR or UK GDPR applies, you may also contact the authority where you live or work.
11. Automated decisions
Brainwave does not use the public AI assistant, internal enquiry reply drafts, or the website to make decisions about you that produce legal or similarly significant effects. AI assistant answers are informational. Enquiry drafts are never sent automatically and must be assessed by a Brainwave team member.
12. Children
The public website and assistant are not directed at children under 16. If you believe a child has submitted personal data without appropriate authorisation, contact us so we can review and delete it where required.
13. External links
Links to external websites are provided for convenience. Brainwave does not control their privacy practices; review the external service's notice before providing personal information.
14. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. The current version and revision date will remain available here. Material changes will be highlighted where appropriate.
