The controller within the meaning of the General Data Protection Regulation (GDPR) is:
brandfast.co
Danilo Abreu Ott
Turmstraße 59
72351 Geislingen
Germany
[email protected]
We process personal data (e.g., name, email address, IP address) only as necessary for the provision and operation of our SaaS platform.
Authentication data is processed via Auth0. Server hosting is provided by Digital Ocean; data is stored in MongoDB. Uploaded files (such as images, logos, and other assets) are stored on Google Cloud.
We use Hotjar and Google Tag Manager for analytics and tag management purposes.
Data processing is based on Art. 6(1)(b) GDPR (contract performance) and, where applicable, Art. 6(1)(f) GDPR (legitimate interests in secure and efficient operation of the service). For analytics and marketing tools (Hotjar, Google Tag Manager), we rely on your consent in accordance with Art. 6(1)(a) GDPR.
Some of these providers may process data outside the EU/EEA. We ensure that appropriate safeguards (such as Standard Contractual Clauses) are in place for any data transfers to third countries.
You can manage your consent for analytics and tracking tools via our cookie banner or settings.
User data is retained for the duration of the contract. After termination and expiry of the 30-day grace period, all data (including Brand Guides and uploaded files) will be deleted.
Users can request deletion of their account and data at any time by contacting [email protected].
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or misuse. Data is encrypted in transit and at rest where possible.
We reserve the right to update this Privacy Policy to reflect changes in legal requirements or our processing activities. The current version is always available on our website.