GDPR · Transparency

Privacy Policy

This Policy explains processing by Ollyn in Braisely, including for visitors, customers, and people whose professional information appears in a signal or prospect list.

Version 1.1 · Last updated: October 6, 2026.

1. Controller and roles

OLLYN, a French simplified joint-stock company with a sole shareholder and share capital of EUR 1,000, Strasbourg RCS 932 407 729, 7 rue Joseph Schmitt, 67500 Weitbruch, France, is controller for website, account, billing, support, security and its own business-relationship processing.

For data imported or processed under a customer's criteria and instructions, that customer is generally controller and Ollyn is processor. Where Ollyn determines the purposes and means of collection or enrichment from public sources, it is controller for that operation. Individuals may always contact Ollyn, which will route the request where needed.

2. People and data covered

  • Visitors: IP address, technical logs, browser, device, requested pages, language and strictly necessary cookies.
  • Users and customers: email, company or workspace, hashed password, preferences, settings, support requests, login and usage history, billing identifiers, plan and credit movements. Braisely does not store full payment-card numbers.
  • Prospects and professional contacts: name, role, employer, business location, business email or phone where available, profile and website URLs, public posts and interactions, professional events, detected signals, source, date, scores, analyses and outreach drafts.
  • Customer-supplied data: imported lists, domains, targeting criteria, keywords, instructions, notes, export destinations, webhooks and technical credentials for enabled integrations.

3. Data sources

Data comes directly from users and customers, from publicly accessible or open sources, and from technical providers. Depending on enabled features, sources may include company websites, public professional profiles or content, news and press feeds, job postings, public-procurement notices, advertising libraries, domain-name data, and results supplied by collection or enrichment services.

Public availability does not remove a person's rights. Where possible, Braisely keeps the source or URL used to verify origin and limits collection to information relevant to the configured professional purpose.

4. Purposes and legal bases

  • Contract: create and administer accounts; provide analyses, exports, alerts and integrations; manage support, credits, subscriptions and payments.
  • Legal obligations: accounting, tax, data-subject requests and cooperation with competent authorities.
  • Legitimate interests of Ollyn or its customers: secure and diagnose the Service, prevent abuse, improve quality, manage B2B relationships and identify relevant professional opportunities from lawful sources after balancing the rights and interests involved.
  • Consent where the law requires it: optional communications, non-essential trackers, or outreach on a channel or in a context requiring prior permission. Consent may be withdrawn at any time.

5. Qualification, AI and decisions

Braisely may use rules and AI models to summarise public content, search for business context, qualify contact relevance, assign scores and draft messages. Data sent to an AI provider is limited to what the operation needs.

Outputs assist a professional user. Braisely is not intended to make decisions on its own that produce legal or similarly significant effects on an individual. The customer must conduct human review before outreach or action.

6. Recipients and providers

Data is available to authorised Ollyn personnel and the relevant Customer. Depending on the features used, the following provider categories may process it:

  • Infrastructure providers for application, database, backup and technical-log hosting.
  • AI-model, search, collection and enrichment providers, limited to the data needed for the requested operation.
  • Payment, service-email, error-diagnosis, media-delivery and business-email-verification providers.
  • AI assistant providers (for example Anthropic or OpenAI) that you choose to connect to Braisely, limited to the data returned by the requests you ask the assistant to make (see section 13).
  • When enabled by the Customer, outreach, customer-relationship-management and content-audit tools, webhooks or other destinations selected by the Customer. Those recipients then process data under their own terms and the Customer's configuration.
  • Authorities, advisers and potential acquirers only where legally required or within a secured restructuring process. Data is not sold for advertising.

7. Transfers outside the EEA

The primary infrastructure hosting the application and its database is configured in a European region. Some providers may nevertheless process data in the United States or other countries outside the EEA. Depending on the recipient, transfers are covered by an adequacy decision, the EU–US Data Privacy Framework for certified entities, European Commission Standard Contractual Clauses and appropriate supplementary measures.

The Customer must ensure that integrations it chooses provide safeguards appropriate to its processing. Further information about applicable safeguards may be requested from Ollyn.

8. Retention

  • Customer account and operational data: for the contract term. If you delete your account from your profile settings, access is disabled and all connected AI assistants are disconnected immediately, and your data is erased 30 days later. For other closure requests, data is returned or deleted within 90 days. In both cases this is subject to backups and legal duties.
  • AI assistant connector tokens: access tokens expire after one hour; refresh tokens remain valid until you disconnect the connector or delete your account, and both are revoked immediately in either case. Tokens are stored hashed.
  • Prospect and signal data: for the period set by the Customer where Ollyn acts on its behalf; without an instruction, no later than three years after collection, last contact or the last relevant update.
  • Ollyn's own prospecting data: three years after the latest contact or end of the business relationship. Suppression-list data: the minimum information needed to honour an objection on an ongoing basis.
  • Contracts, invoices, credit movements and accounting evidence: ten years where legally required, with personal identifiers removed when the account is erased. Security logs and support data: proportionate to their purpose, usually no more than twelve months unless an incident or dispute requires longer.
  • Deleted data may remain temporarily in access-restricted backups until rotation.

9. Notice for indirectly collected data

Where professional data is not collected from the individual, notice must be given as soon as possible and no later than one month, at first contact or before first disclosure to a third party, whichever happens first, unless a documented legal exception applies.

Where the Customer determines the campaign, it must give this notice, including its identity, purpose, legal basis, data categories and sources, recipients, retention, rights and the right to complain to the relevant supervisory authority.

10. Your rights

Depending on the processing, you may request access, correction, deletion, restriction and portability, withdraw consent and object to processing. You may object to direct marketing at any time, free of charge and without giving a reason. French law also allows instructions for data after death.

To exercise rights, email beforethefire@braisely.co with enough information to locate your data. Identity evidence is requested only where reasonable doubt exists. You may complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at cnil.fr.

11. Cookies and trackers

Braisely uses cookies strictly necessary for authentication, security, CSRF protection and language preferences. Consent is not required where they remain limited to those purposes. As of this Policy date, the site uses no advertising cookie or audience-measurement tool requiring consent.

If non-essential trackers are added, Braisely will present a choice tool before placing them and update this Policy. Requests to media-delivery providers may create technical logs at those providers.

12. Security

Ollyn uses risk-appropriate measures including HTTPS transport encryption, password hashing, logical workspace separation, access controls, backups and error monitoring. No system is completely invulnerable; suspected incidents may be reported to beforethefire@braisely.co.

13. AI assistant connector (Claude, ChatGPT)

Braisely offers an optional connector, based on the Model Context Protocol (MCP) and secured by OAuth 2.1 with PKCE, that lets an AI assistant such as Claude or ChatGPT read your Braisely workspace data on your behalf. You authorise it on a consent screen and can disconnect it at any time from the assistant's connector settings. Deleting your account disconnects it immediately.

The connector is read-only. It returns only signals about organisations from open sources (Google News articles, BOAMP French public tenders, the Meta Ad Library and France Travail job offers), your credit balance, workspace-level counts, and the outreach leads generated from those signals. Signals collected from social networks or marketplaces, signals that identify individuals, and prospect contact lists are not available through the connector.

Each request is attributed to your workspace only through your OAuth token, so the connector cannot reach another customer's data. It does not read or store your conversations with the assistant. The data returned by a request is delivered to the assistant provider you chose, which processes it under its own terms and privacy policy. Technical logs may record the request time, IP address and tool name; they are kept as described in section 8.

14. Changes

This Policy may change with the Service or law. Its date and version appear above. Customers will receive appropriate notice of a material change affecting existing processing.