Privacy
Privacy Policy
Last updated: 3 August 2026
This Privacy Policy explains how Brainwave GmbH (“Brainwave”, “we”, “us”) processes personal data when you visit wearebrainwave.co, contact us, subscribe to updates, use the client portal or AI assistant, attend a Brainwave event, or work with us. It is intended to meet the transparency requirements of the Swiss Federal Act on Data Protection (“FADP”) and, where applicable, the EU GDPR and UK GDPR.
1. Controller and contact
Brainwave GmbHRebackerstrasse 2
3210 Kerzers
Switzerland
Email: hello@wearebrainwave.co
UID: CHE-150.886.832
Brainwave GmbH is the controller for the processing described here unless a separate notice says otherwise.
2. Personal data we process
2.1 Website and device data
When you access the site, our hosting and security systems may process your IP address, request URL, browser and device information, referring page, timestamps, response status, and related security or diagnostic events. We use this information to deliver the site, prevent abuse, and investigate failures.
2.2 Enquiries and business relationships
If you contact us or submit a form, we process the information you provide, including your name, company, email address, optional telephone number, message, and later correspondence. Please do not send medical records or sensitive health information through the public contact form.
Submissions are stored in our database as well as sent to us by email, so that we can answer you reliably and so that a later request to see or delete your information can actually be met. We also keep a salted, one-way hash derived from your network address for a short period, used only to detect automated abuse of the forms; we do not store the address itself.
2.3 Newsletter
If you actively consent to email updates, we process your email address, the consent wording and source, the date and time of consent, delivery events needed to operate the mailing, and any unsubscribe request. You can withdraw consent at any time using the unsubscribe method in an email or by contacting us.
2.4 Client portal
For invited clients, we process the invited email address, authentication and session events, account role, engagement profile and dates, assigned actions and completion status, project milestones, requests or feedback submitted through the portal, document metadata, files Brainwave shares with that account, and access or administrative events needed to keep the service secure. Portal files are held in private storage and downloads use short-lived signed links. Please do not submit medical records or sensitive health information in portal requests.
2.5 AI assistant
When you choose to use the AI assistant, the messages and recent conversation context you submit are sent to Anthropic to generate a response. The visible conversation is also stored in your browser's session storage so it remains available in that browser tab. Brainwave does not intentionally add public-assistant transcripts to its own client database. Anthropic states that standard commercial API inputs and outputs are normally deleted from its systems within 30 days, subject to its policy-enforcement and legal exceptions. Do not submit confidential, identifying, medical, or other sensitive information. The assistant is not a healthcare service and is not suitable for emergencies.
2.6 Workshops, events, and services
When you or your organisation books or attends a service, we may process participant and organiser contact details, role, attendance, scheduling information, feedback, contractual records, and billing information. If photographs or recordings are planned, we will provide an event-specific notice and, where required, obtain consent or provide a practical opt-out.
2.7 Sensitive data
Brainwave does not need medical records for ordinary website use. Where a workshop or service legitimately requires health-related accessibility or wellbeing information, we collect only what is necessary, provide a specific notice, restrict access, and obtain explicit consent or rely on another valid legal basis where required. Reports for organisations should be aggregated or de-identified wherever practical.
2.8 Social media and external sites
This site links to Brainwave pages on Instagram and LinkedIn. The visible Instagram images on this website are hosted locally and are not social-media embeds. If you follow an external link, that provider processes information under its own privacy terms.
3. Where the data comes from
We receive personal data directly from you, from your employer or event organiser, from people who invite you to the client portal, and automatically from your device and our service providers when you use the site. We may also receive ordinary professional contact information from publicly available sources or business partners.
4. Purposes and legal bases
Under the FADP, we process data lawfully, proportionately, and for disclosed purposes. Where the GDPR or UK GDPR applies, the corresponding legal bases are set out below.
| Purpose | Typical GDPR / UK GDPR basis |
|---|---|
| Delivering and securing the website; preventing misuse | Legitimate interests in a secure, reliable service (Art. 6(1)(f)) |
| Responding to enquiries and preparing or performing services | Steps before or performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Administering the client portal and sharing contracted work | Contract (Art. 6(1)(b)); legitimate interests in secure delivery (Art. 6(1)(f)) |
| Sending newsletters and optional marketing updates | Consent (Art. 6(1)(a)) |
| Answering a user-requested AI chat | Requested service or steps before a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Keeping invoices, contracts, and compliance records | Legal obligations (Art. 6(1)(c)); legitimate interests in establishing or defending claims (Art. 6(1)(f)) |
| Processing sensitive data where genuinely required | Explicit consent or another condition permitted by applicable law (including Art. 9 GDPR) |
Where we rely on legitimate interests, we assess the necessity and impact of the processing and take reasonable steps to protect your rights. You may object as described below.
5. Recipients and service providers
We disclose data only where needed for the purposes above, including to authorised Brainwave personnel, professional advisers, public authorities where legally required, and the following categories of processors:
| Provider | Function and data involved |
|---|---|
| Vercel | Website hosting, content delivery, server functions, and operational/security logs; device and request data and information submitted to site functions. |
| Supabase | Passwordless authentication, database, and private portal storage; account details, authentication events, document metadata, and files. Also the record of website form submissions: the details you enter, any newsletter consent record, and a salted hash used only to detect abuse. |
| Anthropic | AI response generation when you use the assistant; the prompts and recent conversation context submitted for a response. |
| Resend or a documented form-delivery webhook | Delivery of contact and newsletter submissions when enabled; form details, email address, consent record, and delivery metadata. |
Service providers may use subprocessors. They are contractually restricted to the relevant service and must protect the information. If Brainwave changes a material provider, this notice will be updated.
6. International transfers
Brainwave is based in Switzerland. Depending on the selected hosting region and provider subprocessors, data may be processed in Switzerland, the European Economic Area, the United Kingdom, the United States, or other countries. Where a destination does not provide an adequate level of protection, we use recognised safeguards such as contractual data-protection clauses, data-processing agreements, and supplementary technical or organisational measures, or rely on a permitted exception. You may contact us for more information about applicable safeguards.
7. Cookies and browser storage
The site currently uses only technologies needed for secure client access, saving your privacy choice, and chat functionality that you actively request. No analytics, advertising, or cross-site marketing cookies are active. The details, storage periods, and permanent settings control are in our Cookie Policy.
8. How long we keep information
We keep personal data only as long as needed for its purpose, legal obligations, or the establishment, exercise, or defence of legal claims. Typical periods are:
| Record | Typical retention |
|---|---|
| Enquiries that do not become an engagement | Up to 24 months after the last meaningful contact |
| Website form submissions held in our database | Up to 24 months, in line with the enquiry period above; the abuse-detection hash is removed after 30 days |
| Client, contract, invoice, and accounting records | Generally up to 10 years, where required by Swiss law or needed for claims |
| Client portal workspace data and files | For the engagement and an appropriate close-out period, then deleted or archived according to contractual/legal needs |
| Event and workshop administration | Usually up to 24 months, unless a contract or legal requirement needs longer |
| Newsletter consent | Until withdrawal; a limited suppression record may be kept to honour the unsubscribe |
| Security and operational logs under Brainwave's control | Normally no more than 12 months unless needed to investigate an incident |
| AI assistant history in the browser | Normally for the browser-tab session; provider-side API retention is described in section 2.5 |
| Sensitive workshop information | Only for the shortest necessary period, then deleted or aggregated |
| Event photographs or recordings | Until the stated purpose ends or applicable consent is withdrawn, subject to overriding legal grounds |
9. Security
We use reasonable technical and organisational measures appropriate to the risk, including access controls, private storage, short-lived file links, authenticated routes, input validation, rate limits, transport encryption, least-privilege credentials, and provider security controls. No internet service is completely secure. If you believe information has been exposed, contact us promptly.
10. Your rights
Depending on the law that applies, you may have the right to:
- ask whether we process personal data about you and receive a copy;
- correct inaccurate or incomplete information;
- request deletion or restriction, subject to legal exceptions;
- object to processing based on legitimate interests and object at any time to direct marketing;
- receive certain data in a portable format;
- withdraw consent at any time, without affecting earlier lawful processing; and
- complain to a competent data-protection authority.
To exercise a right, email hello@wearebrainwave.co. We may ask for proportionate information to verify your identity. In Switzerland, the supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland. If the GDPR or UK GDPR applies, you may also contact the authority where you live or work.
11. Automated decisions
Brainwave does not use the public AI assistant or the website to make decisions about you that produce legal or similarly significant effects. AI answers are informational and should be assessed by the user.
12. Children
The public website and assistant are not directed at children under 16. If you believe a child has submitted personal data without appropriate authorisation, contact us so we can review and delete it where required.
13. External links
Links to external websites are provided for convenience. Brainwave does not control their privacy practices; review the external service's notice before providing personal information.
14. Changes to this policy
We may update this policy when our services, providers, or legal obligations change. The current version and revision date will remain available here. Material changes will be highlighted where appropriate.
