Privacy Policy

How we protect your personal data.

Personal Data Protection Policy

Last updated: 25 March 2026

1. Who is the data controller?

Brain Security SAS, registered with the Paris Trade and Companies Register (RCS) under number 918 391 905, with its registered office at 229 rue Saint-Honore, 75001 Paris, France (hereinafter “Brain”), is the data controller for the processing of personal data carried out through the website startbrain.ai and the Brain platform.

When the platform is used by employees of a client organisation, Brain acts as a data processor (within the meaning of the GDPR). The client organisation is then the data controller.

For any questions: contact@startbrain.ai

2. What personal data do we process?

Data collected via the startbrain.ai website

DataSourcePurpose
Professional email addressDemo request formSending demo access and sales follow-up
Company nameDemo request formDemo personalisation
Industry sectorDemo request formContent personalisation
Company sizeDemo request formSales qualification
IP address, browser, pages visitedWebsite browsingAudience measurement, website improvement
Cookie preferencesConsent bannerRespecting your choices

Data collected via the demo area

DataSourcePurpose
Access code and passwordAutomatically generatedDemo access authentication
Completed exercises, scoresDemo usageDemonstrating platform functionality
Customisations (sector, theme, free text)Prospect’s choicesContent adaptation
Navigation events (logins, clicks)Demo usageSales tracking (internal notifications)

Data collected via the platform (employees of client organisations)

DataSourcePurpose
Surname, first name, professional emailProvided by the client organisationAccount creation and management
Role, department, groupProvided by the client organisationCourse assignment
Completed exercises, scores, time spentPlatform usageProgress tracking
Login dataPlatform usageSecurity and logging

3. Why is your data processed?

PurposeLegal basis
Sending personalised demo accessConsent (form)
Internal notification during demo usageLegitimate interest (sales follow-up)
Sending email with login credentialsPerformance of request (consent)
Generating personalised content via AI (Gemini)Legitimate interest (product demonstration)
Creating and managing user accountsPerformance of contract
Delivering exercises and calculating scoresPerformance of contract
Reporting and statistics for the client organisationLegitimate interest
Website audience measurement (Google Analytics, Clarity)Consent (cookies)
Page visit tracking (HubSpot)Consent (cookies)
Platform improvementLegitimate interest
Compliance with legal obligationsLegal obligation

4. Who may access your data?

Your personal data may be accessed by:

  • Authorised employees of Brain Security
  • Your employer (platform administrator): aggregated progress data and scores by group
  • Our technical subprocessors:
SubprocessorServiceData location
Google Cloud (Cloud Run, Firestore)Hosting and databaseEurope (Belgium)
Google (Gemini API)AI content generationEU / United States*
SendGrid (Twilio)Transactional email sendingUnited States*
Slack (Salesforce)Internal notificationsUnited States*
Google AnalyticsAudience measurementUnited States*
Microsoft ClarityUX analysisUnited States*
HubSpotCRM and sales trackingUnited States*

* Transfers are governed by the European Commission’s Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.

Brain does not sell your personal data to third parties. Brain does not share your browsing data with third parties for advertising purposes.

5. How is your data protected?

Brain implements the following technical and organisational measures:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Authentication via hashed passwords (bcrypt) and signed session tokens (JWT)
  • Hosting in Europe on Google Cloud Run (region europe-west1)
  • Strict access control and logging
  • Server-side input validation (injection protection)
  • Rate limiting per email (anti-abuse)
  • Honeypot field for anti-spam protection

6. How long is your data retained?

Data typeRetention period
Demo request data (email, company)3 years
Demo access data (code, password, exercises)Validity period of the demo (14 days by default) + 3 months
Account and progress data (platform)Duration of contract + 1 year
Billing data10 years (accounting obligation)
Cookies and trackers13 months maximum
Anonymised statisticsUnlimited

7. What are your rights?

In accordance with the GDPR, you have the following rights:

  • Right of access: obtain a copy of your data
  • Right to rectification: correct inaccurate data
  • Right to erasure: request deletion of your data
  • Right to restriction: restrict processing
  • Right to data portability: receive your data in a structured format
  • Right to object: object to processing based on legitimate interest
  • Right to withdraw consent: withdraw your consent at any time

To exercise your rights: contact@startbrain.ai

Response time: 1 month. You may lodge a complaint with the relevant data protection authority.

8. Cookies and trackers

For information on cookies and trackers used on startbrain.ai, please see our Cookie Policy.

9. Artificial intelligence

Brain uses the Gemini API (Google) to generate personalised content within demo spaces. The data sent to the API is limited to the sector, theme and free text entered by the prospect. No personally identifiable data is sent to the generation API.

The website may contain links to third-party websites (HubSpot for appointment booking). Brain is not responsible for the privacy practices of these websites.

11. Changes to this policy

Brain may update this policy. In the event of a substantial change, you will be informed by email or via the platform. The date of the last update appears at the top of this page.

12. Contact us

Brain Security SAS 229 rue Saint-Honore, 75001 Paris, France Email: contact@startbrain.ai SIREN: 918 391 905

Ready to accelerate AI adoption?