Skip to main content

Help Center

Privacy Policy

MyBusinessBrain privacy policy: personal data of client companies and their correspondents, GDPR compliance, processors, retention periods.

ARTICLE 1 - DATA CONTROLLER

[to be completed] ([to be completed]) is the data controller for the data relating to the relationship with the client company (hereinafter the "Client"): account, billing, use of the portal by the Client's staff. For the personal data of the Client's correspondents processed through the Service (e-mails received and sent, requests recorded by the assistant, customer relationship book records), the Client is the data controller and the Publisher acts as a processor within the meaning of article 28 GDPR, on behalf of and on the instructions of the Client. A data processing agreement (DPA) is made available to clients. Contact: [to be completed].

ARTICLE 2 - DATA COLLECTED

In the course of operating the Service, the following categories of data are collected and processed:

  • Client identification data: surname, first name, e-mail address, telephone number, trade name and company name
  • Billing data: postal address, SIRET number, payment information (handled by Stripe when card payment is chosen)
  • Connected mailbox credentials: app password or OAuth token, stored encrypted and never displayed
  • Data of the Client's correspondents: content of e-mails received and sent, contact details provided by the correspondent, requests expressed (company, role, need, timeline, stated budget)
  • Data entrusted by the Client: knowledge-base documents and texts, customer relationship book records
  • Usage data: login logs, usage statistics, browsing data on the dashboard

ARTICLE 3 - PURPOSES AND LEGAL BASES

The data is processed for the following purposes:

Performance of the contract: Operation of the Service (reading e-mails, drafting replies, tracking requests), user account management, billing.

Legitimate interest: Improvement of the Service, anonymised statistical analysis, prevention of fraud and abuse, security.

Legal obligation: Retention of invoices and accounting data in accordance with the applicable legislation.

ARTICLE 4 - PROCESSORS AND DATA TRANSFERS

The data is processed by the following processors, all contractually bound to comply with the GDPR and all established in the European Union:

The provider of the connected mailbox (for example Google, Microsoft or OVH) is not a processor of the Publisher: it is the Client's own provider, chosen by the Client, and the Service accesses it with the authorisations the Client grants. No other transfer outside the European Union takes place.

  • OVHcloud (OVH SAS, France): hosting of the application infrastructure and data (servers, database, cache, vector database, storage of documents) in a data centre located in France, and sending of the Service's transactional e-mails
  • Mistral AI (France): language models and computation of vector representations for drafting replies and searching the knowledge base; no data is used to train models
  • Stripe Payments Europe (Ireland): card payment processing, only when card payment is chosen; as an international group, Stripe may carry out processing outside the European Union, governed by the European Commission's Standard Contractual Clauses (decision 2021/914)

ARTICLE 5 - RETENTION PERIOD

The data is retained for the following periods:

  • Account data: for the whole duration of use of the Service, then deleted when the account is closed; upon an erasure request (art. 17 GDPR), as soon as possible
  • E-mails and conversations handled by the assistant: 12 months after the last exchange
  • Requests recorded by the assistant (demonstration, quote, trial): same period as the conversation they come from (12 months)
  • Connected mailbox credentials: until the mailbox is disconnected, then deleted immediately
  • Billing data: 10 years in accordance with accounting obligations
  • Login logs: 12 months

ARTICLE 6 - RIGHTS OF DATA SUBJECTS

In accordance with the General Data Protection Regulation (GDPR), you have the following rights, to be exercised with [to be completed]; a correspondent of the Client exercises their rights with the Client, which the Publisher assists:

  • Right of access: Obtain a copy of your personal data
  • Right to rectification: Correct inaccurate data
  • Right to erasure: Request the deletion of your data
  • Right to portability: Receive your data in a structured format
  • Right to object: Object to the processing of your data
  • Right to restriction: Request the restriction of processing

See also

MyBusinessBrain

The AI that runs your company's inbox around the clock: product questions, demo, trial and quote requests, first-level support.

Contact

MyBusinessBrain v2.2.0 · © 2026 MyBusinessBrain. All rights reserved. Based in Menton, France.