1. Roles and Responsibilities (GDPR)
WeAreBrain as Data Controller: We are the Data Controller for personal data related to account creation, user identities, billing management, customer support correspondence, and platform-level telemetry.
WeAreBrain as Data Processor: For all content, files, databases, prompts, agent memories, and logs processed inside a customer’s Sinas instance, the Customer is the Data Controller and WeAreBrain acts strictly as a Data Processor, processing data solely on the Customer's documented instructions.
2. Information We Collect
A. Account & Profile Data
Identity: Email address (used for account identity and passwordless/password sign-in), full name, and organization name.
Billing Details: Payment processing and credit card details are handled directly and securely by Stripe. WeAreBrain does not store full credit card numbers on its servers.
Operational Records: Active instances, instance size configurations, and aggregate monthly operations usage count per organization.
Support Correspondence: Tickets, emails, and messages sent to our support desk.
B. Request Logs per Instance
For security, operational integrity, and customer exportability, we record execution request logs per instance. These contain:
Timestamp, HTTP method, request path, response status code, execution duration, and payload size.
User identity and permission checks evaluated during the request.
Originating IP address.
Redaction Guarantee: Sensitive authentication endpoints and token parameters are automatically redacted from system logs. Customer request logs belong to the Customer and are exportable.
3. What We Do NOT Do
No AI Model Training: We do not read, mine, inspect, or train AI models on the contents, inputs, or outputs processed within your Sinas instance.
No Selling of Personal Data: We never sell, rent, or trade your personal data or customer payload data to third parties.
4. Sub-Processors and Data Transfers
We engage trusted third-party sub-processors to deliver hosting, payments, and infrastructure automation. We maintain Data Processing Agreements (DPAs) and Standard Contractual Clauses (SCCs) where applicable with each provider:
Sub-Processor | Role / Function | Processing Location |
|---|---|---|
Scaleway | Cloud Infrastructure & Instance Hosting | European Union (EU) |
Stripe | Payment Processing & Customer Portal | EU / USA (SCCs) |
Transactional Email Provider | Sign-in Codes & System Notifications | EU / USA (SCCs) |
GitHub | Infrastructure Provisioning Automation | USA (SCCs) |
Atlassian (Jira) & Slack | Customer Support & Technical Ticketing | EU / USA (SCCs) |
Google (Gmail) | Support Mailbox Administration | EU / USA (SCCs) |
n8n | Customer Support Workflow Automation | EU / USA (SCCs) |
Grafana | System Infrastructure Monitoring & Telemetry | EU / USA (SCCs) |
Notice of Changes: We maintain an updated list of sub-processors and will provide a 30-day advance notice prior to publishing changes to our authorized sub-processor list.
5. Data Retention Schedules
Account Data: Email, name, organization name, billing records, and aggregate usage records are retained for the duration of your active account. Following account closure or cancellation, data is retained for 30 calendar days, after which it is permanently deleted.
Free Instances: Free instances that remain unused for 14 consecutive days are automatically removed along with all stored instance contents.
Backups (Paid Plans Only): Daily backups are performed for paid plans and retained for 7 calendar days. A final backup taken upon account/instance deletion is retained for 30 calendar days before permanent destruction. Free instances do not include automated backups.
Data Inside an Instance: Files, databases, agent memory, and chats stored inside an instance are retained for as long as the Customer keeps them. WeAreBrain sets no independent retention limits on instance data. Customers may configure auto-expiry dates on chat histories, after which they are permanently deleted by a scheduled platform job.
Invoices: Payment invoices and core transactional records are retained for the applicable statutory tax period (7 to 10 years as required by Dutch tax legislation).
6. Your Rights under GDPR
Under European data protection law, you hold the following rights:
Access, Rectification, & Portability: Profile information can be reviewed and updated via self-service in the account dashboard. Configuration exports are available as YAML at any time.
Email Changes & Erasure: Email address updates and account deletion requests are handled by submitting a ticket to support.
Immediate Erasure: Customers can request immediate data erasure (bypassing the standard 30-day post-cancellation window) via support, which will be executed manually.
Restriction & Objection: Requests to restrict or object to data processing under GDPR Art. 18/21 are processed manually upon contacting support@sinas.co.