Draft — pending legal review. This document is a working scaffold describing our current practices. It has not been reviewed by counsel and is not a compliance statement.

Privacy Policy

Version 0.1 (draft) · Last updated July 6, 2026

Who we are

BriskTag is an XBRL/iXBRL financial reporting platform operated by Briskflow. This policy describes how we handle personal data of platform users. For questions or requests, contact tech@briskflow.ai.

What we collect

Account data: name, email address, phone number (optional), job designation, and an optional avatar image. Usage data: comments, document reviews, tagging activity, and audit records of actions you take on the platform. Technical data: session IP address and browser user-agent for security purposes.

Financial documents you upload are processed on your organization's behalf and remain isolated to your organization.

Cookies

We use strictly necessary session cookies for authentication only. We do not use advertising, analytics, or cross-site tracking cookies, which is why no cookie consent banner is shown.

Your rights

You can export a copy of your personal data (Settings → Privacy & Data → Export my data) and request deletion of your account (Settings → Danger Zone). Deletion anonymizes your personal information immediately after email confirmation. Content you authored (documents, comments, reviews) is retained for regulatory record-keeping and shown as "Deleted User".

Retention

Identifying account data is anonymized immediately upon confirmed account deletion. Audit records are retained for 7 years to meet financial-reporting and SOC 2 obligations. Email addresses on our delivery suppression list are retained as a legitimate-interest deliverability record.

Processors

We use Google Cloud Platform (hosting and storage), Resend (email delivery), Sentry (error monitoring), and GitLab (development infrastructure). Data processing agreements with these providers are managed under our vendor management policy.

Breach notification

If a data breach affects your personal data, we will notify affected customers and, where required, supervisory authorities within 72 hours of becoming aware, in line with our incident response plan.