Privacy Policy
1. Introduction
Welcome to Brieft ("Brieft", "we", "our", or "us").
Brieft is a cloud-based document management and collaboration platform that enables businesses and their teams to securely upload, store, review, share, approve, and manage digital files and creative assets.
We understand that your information is important. This Privacy Policy explains how we collect, use, disclose, store and protect your personal information when you use our website, applications, services and any related features (collectively, the "Services").
This Privacy Policy applies to all users worldwide, including customers, authorised users, invited guests, reviewers, collaborators and visitors to our Services.
By accessing or using Brieft, you acknowledge that you have read and understood this Privacy Policy.
Where required by law, we will seek your consent before collecting or processing certain information.
Business Customer Responsibilities
Brieft provides a platform that enables organisations to upload, store, manage, review and share their own information.
This Privacy Policy explains how Brieft collects, uses and protects personal information in connection with providing the Services. It does not govern how our Business Customers independently collect, use or disclose personal information outside of the Services.
Where a Business Customer uploads personal information relating to its employees, contractors, clients, suppliers or other individuals, that Business Customer is responsible for ensuring it has the legal authority to collect and upload that information and for complying with all applicable privacy and data protection laws.
2. Interpretation and Definitions
For the purposes of this Privacy Policy:
- Account means an account created to access the Services.
- Business Customer means the organisation, company or entity that subscribes to or uses Brieft.
- Guest User means an individual invited to view, comment on, review or approve documents without creating a full account.
- Personal Information means any information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual.
- Services means the Brieft platform, website, applications and all associated features.
- Workspace means an isolated environment within Brieft that stores documents, comments, approvals and user permissions belonging to a Business Customer.
- You means any person using or accessing the Services.
3. Information We Collect and Process
Brieft collects information necessary to provide, secure and improve the Services. The information we collect depends on how you interact with Brieft.
A. Account Information
When you create or are invited to use a Brieft account, we may collect:
- Full name
- Email address
- Company or organisation name
- Account credentials
- Profile information you choose to provide
If your organisation creates an account on your behalf, we may receive this information from your employer or workspace administrator.
B. Workspace Information
To provide our document management services, we collect information associated with your workspace, including:
- Workspace name
- Workspace settings
- User permissions
- Team membership
- Roles
- Approval workflows
- Activity history
C. Uploaded Files
Brieft is designed to securely manage digital files. Accordingly, we collect and store files that you choose to upload, including:
- Documents
- Artwork
- Images
- PDFs
- Videos
- Design files
- Source files
- Other digital assets
We also collect associated metadata including:
- File names
- File size
- Upload timestamps
- Version history
- Approval status
- Comments
- Annotations
- Download history
- Audit logs
Brieft does not claim ownership of your uploaded content. Ownership of all uploaded files remains with the customer or the applicable rights holder.
D. Comments, Reviews and Approvals
When using collaboration features we collect:
- Comments
- Replies
- Pinpoint annotations
- Approval decisions
- Approval timestamps
- Review history
- User actions associated with reviews
This information forms part of the document audit trail.
E. Payment Information
If you purchase a subscription or paid services, payment processing is handled by Stripe. Brieft does not store complete payment card numbers.
We may receive limited payment-related information from Stripe, including:
- Payment status
- Subscription status
- Billing country
- Transaction identifiers
- Invoice information
Stripe processes payment information in accordance with its own Privacy Policy.
F. Technical Information
When you access the Services we automatically collect technical information, including:
- IP address
- Browser type
- Operating system
- Device identifiers
- Language preferences
- Time zone
- Referral URLs
- Date and time of access
- Crash reports
- Error logs
G. Usage Information
To improve Brieft, we collect information regarding how users interact with the Services, including:
- Pages viewed
- Features used
- Navigation paths
- Session duration
- Upload activity
- Download activity
- Collaboration activity
- Approval activity
- General usage analytics
Some of this information is collected using cookies and similar technologies.
H. Communications
If you contact us, we may collect:
- Email address
- Name
- Company name
- Support requests
- Feedback
- Survey responses
- Correspondence with our support team
I. Information from Third Parties
We may receive limited information from trusted service providers that assist us in operating Brieft, including:
- Stripe
- Google Analytics
- Cloudflare infrastructure services
- GitHub (development and software management)
We only receive information necessary to provide or improve our Services.
4. Sensitive Information
As a document management platform, Brieft enables Business Customers to upload and manage a wide range of digital content. Depending on how our Services are used, uploaded files may contain personal information, confidential business information or, in some cases, information that is considered sensitive under applicable privacy laws.
Brieft does not require or intentionally seek the collection of sensitive personal information unless it is necessary for our Business Customers to use the Services for their legitimate business purposes.
Examples of sensitive information may include information relating to an individual's health, financial circumstances, government-issued identification, biometric information, or other categories of personal information that receive additional protection under applicable law.
Business Customers are responsible for determining whether it is appropriate and lawful to upload sensitive information to the Services and for ensuring they have obtained any required consents, authorisations or other lawful basis for doing so.
Where sensitive information is uploaded to Brieft, we process that information solely for the purpose of providing, maintaining, securing and improving the Services in accordance with our agreements with the relevant Business Customer and applicable law.
Brieft does not access, review or use customer content except where reasonably necessary to operate the Services, provide customer support, comply with legal obligations, investigate suspected misuse, protect the security or integrity of the platform, or where otherwise authorised by the relevant Business Customer.
We encourage Business Customers to upload only the information necessary for their intended business purpose and to apply appropriate access controls within their workspaces to protect confidential or sensitive information.
5. How We Use Your Personal Information
We use personal information only where necessary to operate our Services, fulfil our contractual obligations, comply with legal requirements, and improve the Brieft platform. Specifically, we may use your information to:
Provide the Services
Including to:
- Create and manage accounts
- Authenticate users
- Operate workspaces
- Store uploaded documents
- Maintain version history
- Enable collaboration
- Process approvals
- Facilitate secure sharing
- Deliver requested features
Secure the Platform
Including to:
- Detect fraud
- Prevent abuse
- Monitor unauthorised access
- Protect customer data
- Investigate security incidents
- Maintain audit logs
Improve Brieft
We analyse aggregated and, where appropriate, de-identified usage information to:
- Improve performance
- Fix bugs
- Develop new features
- Optimise user experience
- Understand feature adoption
- Improve platform reliability
We do not use customer documents to build publicly available datasets or sell customer information.
Customer Support
We use information to:
- Respond to enquiries
- Resolve technical issues
- Investigate reported problems
- Communicate about support requests
Billing
Where applicable we use information to:
- Process subscriptions
- Manage invoices
- Prevent payment fraud
- Maintain billing records
Communications
We may communicate with users regarding:
- Account notifications
- Security alerts
- Product updates
- Service announcements
- Changes to our policies
- Maintenance notifications
Where required by law, marketing communications will only be sent with your consent, and you may opt out at any time.
Legal Compliance
We may use information where necessary to:
- Comply with legal obligations
- Respond to lawful requests from government authorities
- Enforce our agreements
- Protect the rights, safety and property of Brieft, our customers or others
6. Legal Bases for Processing (GDPR)
Where the General Data Protection Regulation ("GDPR") or similar privacy laws apply, Brieft processes personal information on one or more of the following legal bases:
Performance of a Contract
We process information where necessary to provide the Services you or your organisation have requested, including creating accounts, storing documents, managing workspaces, processing approvals and delivering platform functionality.
Legitimate Interests
We process personal information where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. These interests include:
- Improving the Services
- Maintaining platform security
- Detecting fraud
- Preventing misuse
- Developing new features
- Providing customer support
- Monitoring system performance
- Protecting our legal rights
Consent
Where required by law, we rely on your consent before:
- Sending marketing communications
- Using non-essential cookies
- Processing information for purposes where consent is legally required
You may withdraw your consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
Legal Obligations
We may process information where necessary to comply with legal or regulatory obligations, including taxation, accounting, law enforcement requests, court orders, and applicable privacy legislation.
Protection of Vital Interests
In exceptional circumstances, we may process information where necessary to protect the vital interests of an individual or another person, where permitted by law.
7. Sharing and Disclosure of Information
Brieft does not sell your personal information. We only share personal information where necessary to operate our Services, comply with legal obligations, protect our users, or where you have instructed us to do so.
A. Within Your Organisation
Information you upload to a workspace may be visible to other authorised users within that workspace, depending on the permissions configured by your workspace administrator. This may include:
- Uploaded documents
- Comments and annotations
- Approval history
- Version history
- User names
- Activity logs
- Workflow actions
Workspace administrators are responsible for managing user permissions and determining who has access to information within their organisation.
B. Guest Users
Brieft allows customers to share documents externally using secure links. Where enabled by the workspace owner, guest users may be permitted to:
- View files
- Download files
- Leave comments
- Create annotations
- Approve documents
- Access version history where authorised
Guest access is controlled entirely by the workspace owner or administrator and may include additional restrictions such as:
- Expiration dates
- Password protection
- Download restrictions
- Permission-based access
- Link revocation
Information associated with guest activity may be recorded within the workspace audit trail.
C. Service Providers
We share information with trusted third-party service providers that assist us in delivering the Services. These providers are only permitted to process personal information on our behalf for authorised business purposes and are contractually required to protect your information. Examples include providers that assist with:
- Cloud storage
- Payment processing
- Analytics
- Infrastructure
- Security
- Customer communications
- Software development
- Monitoring and reliability
We do not permit these providers to use your information for their own marketing purposes.
D. Legal Requirements
We may disclose personal information where we reasonably believe disclosure is necessary to:
- Comply with applicable laws
- Respond to lawful requests from government authorities
- Comply with court orders
- Respond to subpoenas
- Protect the rights or property of Brieft
- Investigate fraud
- Enforce our agreements
- Protect the safety of users or the public
Where legally permitted, we will attempt to notify affected users before disclosing personal information.
E. Business Transfers
If Brieft is involved in a merger, acquisition, investment transaction, financing, corporate restructuring, sale of assets, or insolvency proceedings, personal information may be transferred as part of that transaction.
Any successor organisation will remain bound by this Privacy Policy (or a policy providing substantially similar protections) until users are notified of any material changes.
F. With Your Consent
We may share information where you expressly authorise us to do so.
G. Aggregated and De-Identified Information
We may create aggregated, anonymised or de-identified information that cannot reasonably identify an individual or organisation. We may use this information to:
- analyse platform performance;
- understand product usage;
- improve the Services;
- produce statistical reports;
- support business planning.
Where information has been irreversibly de-identified, it is no longer considered personal information under many privacy laws.
8. Third-Party Service Providers
Brieft relies on carefully selected third-party providers to operate the Services. These providers process information only as necessary to provide their respective services. Our current providers include, but are not limited to:
Cloudflare R2
Cloudflare R2 is used to securely store customer files and associated content uploaded to Brieft. Depending on how the Services are configured, Cloudflare may process:
- uploaded documents;
- artwork;
- source files;
- previews;
- metadata;
- download requests;
- storage requests.
Cloudflare operates globally and applies industry-standard security measures to protect customer data.
Stripe
Stripe is used to process subscription payments and billing transactions. Payment card information is collected directly by Stripe and is not stored by Brieft. Brieft may receive limited billing information from Stripe, including:
- payment status;
- subscription status;
- invoice information;
- customer identifiers;
- transaction references.
Stripe processes payment information under its own privacy practices.
Google Analytics
We use Google Analytics to better understand how visitors use our website and Services. Google Analytics may collect information such as:
- browser type;
- device information;
- approximate geographic location;
- pages visited;
- session duration;
- referring websites;
- interactions with our website.
This information helps us improve usability, reliability and performance. Where required by applicable law, analytics cookies will only be activated following user consent.
GitHub
We use GitHub as part of our software development workflow. GitHub may host source code, issue tracking and development workflows relating to Brieft. Customer documents are not intentionally stored within public GitHub repositories. Access to development environments is restricted to authorised personnel.
Future Providers
As Brieft evolves, we may engage additional service providers for services including:
- infrastructure hosting;
- email delivery;
- authentication;
- customer support;
- security monitoring;
- application performance monitoring;
- communications;
- backup services.
Where we engage new providers that process personal information, we will update this Privacy Policy where required.
Third-Party Policies
Each third-party provider maintains its own privacy policy governing how it processes personal information. We encourage users to review those policies where appropriate. Brieft is not responsible for the privacy practices of independent third-party services.
9. International Data Transfers
Brieft serves customers around the world. As a result, personal information may be transferred to, processed in, or stored in countries outside your country of residence. This may occur because:
- our infrastructure operates globally;
- our service providers operate internationally;
- authorised users access workspaces from different countries;
- documents are shared with collaborators located overseas.
These countries may have privacy laws that differ from those in your jurisdiction.
Where we transfer personal information internationally, we take reasonable steps to ensure that appropriate safeguards are in place. Depending on the applicable law, these safeguards may include:
- contractual data protection obligations;
- standard contractual clauses;
- recognised international transfer mechanisms;
- adequacy decisions issued by relevant regulators;
- technical and organisational security controls.
Regardless of where your information is processed, Brieft applies reasonable security measures designed to protect personal information from unauthorised access, misuse or disclosure.
By using the Services where permitted by applicable law, you acknowledge that your information may be processed outside your country of residence.
10. Security of Your Personal Information
Protecting customer information is a core part of Brieft's platform. We implement technical, organisational and administrative safeguards designed to protect personal information against accidental loss, unauthorised access, disclosure, alteration and destruction.
Our security measures include, where appropriate:
- encryption of data in transit;
- encryption of stored data where applicable;
- secure cloud infrastructure;
- access controls;
- authentication mechanisms;
- role-based permissions;
- workspace isolation;
- audit logging;
- security monitoring;
- regular software updates;
- vulnerability management;
- least-privilege access practices.
Brieft is designed so that each customer workspace remains logically isolated from other customer workspaces. Access to customer information is restricted to authorised personnel who require access to perform their responsibilities. Employees and contractors with access to customer information are subject to confidentiality obligations.
Although we take commercially reasonable measures to protect personal information, no method of transmitting information over the internet or storing information electronically is completely secure. Accordingly, while we strive to protect your information, we cannot guarantee absolute security.
Users also play an important role in protecting their accounts and should:
- maintain strong passwords;
- keep login credentials confidential;
- use secure devices;
- promptly notify Brieft of suspected unauthorised access.
If we become aware of a security incident affecting personal information, we will investigate the incident and, where required by applicable law, notify affected users and relevant regulatory authorities.
We continually review and improve our security practices to respond to evolving technologies, emerging threats and changes in applicable legal requirements.
11. Data Retention
Brieft retains personal information only for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements, and protect the security and integrity of our platform.
The length of time we retain information depends on the type of information involved and the purpose for which it was collected.
A. Account Information
We retain account information while your account remains active. Following account closure, we may retain limited account information where reasonably necessary to:
- comply with legal obligations;
- resolve disputes;
- enforce our agreements;
- prevent fraud;
- maintain security records;
- protect the integrity of our Services.
B. Uploaded Files
Uploaded documents, artwork, source files and other customer content remain stored until:
- you delete the content;
- your organisation deletes the workspace;
- you request deletion where applicable; or
- retention is required by law.
Brieft does not retain deleted customer files longer than reasonably necessary to complete deletion from active systems and backups. Some information may remain in encrypted backups for a limited period before being permanently removed through normal backup rotation processes.
C. Comments, Version History and Audit Logs
Comments, annotations, approval records, version history and audit logs form part of the integrity of a workspace. These records may be retained for as long as the associated workspace exists, unless deleted by the customer or where applicable law requires otherwise. Where technically feasible, deleted workspaces will also result in deletion of associated collaboration records.
D. Billing Records
Certain billing and financial records may be retained for longer periods where required to comply with taxation, accounting or other legal obligations.
E. Analytics Information
Analytics data may be retained in aggregated or de-identified form for product improvement, reporting and business analysis. Where analytics information can reasonably identify an individual, it will be retained only for as long as necessary for the relevant purpose.
F. Legal Obligations
In some circumstances we may retain information longer than described above where required to:
- comply with applicable laws;
- respond to legal claims;
- protect the rights of Brieft;
- investigate security incidents;
- prevent fraud.
G. Deletion Requests
Where permitted by law, users may request deletion of their personal information by contacting us. Following verification of the request, we will delete or anonymise personal information unless we are legally required or otherwise permitted to retain it.
12. Cookies and Analytics
Brieft uses cookies and similar technologies to operate, secure and improve the Services. Cookies are small text files stored on your device that allow websites and applications to recognise your browser and remember certain information.
A. Essential Cookies
Essential cookies are necessary for the operation of the Services. These cookies enable functions such as:
- user authentication;
- account security;
- session management;
- load balancing;
- fraud prevention;
- remembering user preferences;
- maintaining logged-in sessions.
Because these cookies are necessary for the operation of the Services, they cannot generally be disabled through our platform.
B. Analytics Cookies
We use analytics technologies, including Google Analytics, to understand how users interact with our Services. Analytics information may include:
- pages visited;
- navigation paths;
- feature usage;
- device information;
- browser information;
- approximate geographic region;
- session duration;
- referral sources.
This information helps us improve performance, usability and reliability. Where required by applicable law, analytics cookies will only be activated after obtaining your consent.
C. Functional Cookies
Functional cookies help remember user preferences, improve usability and personalise aspects of the Services. Examples include remembering:
- language preferences;
- interface settings;
- recently used options;
- user preferences.
D. Managing Cookies
Most web browsers allow users to control or disable cookies through browser settings. Disabling certain cookies may affect the functionality of the Services.
Users located in jurisdictions requiring cookie consent may also manage cookie preferences through our cookie banner or preference centre where available.
E. Do Not Track
Some browsers support "Do Not Track" signals. Because there is currently no universally accepted standard governing such signals, Brieft does not currently respond differently to Do Not Track requests. Should an industry standard become widely adopted, we may update our practices accordingly.
13. Your Privacy Rights
Depending on where you live, you may have legal rights regarding your personal information. These rights may vary by jurisdiction. Subject to applicable law, you may have the right to:
Access
Request access to the personal information we hold about you.
Correction
Request correction of inaccurate, incomplete or outdated personal information.
Deletion
Request deletion of your personal information where there is no lawful basis requiring us to retain it.
Restriction
Request that we temporarily restrict certain processing activities while a request is being reviewed.
Objection
Object to certain types of processing, including processing based on our legitimate interests where permitted by law.
Data Portability
Request a copy of your personal information in a structured, commonly used and machine-readable format where applicable.
Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal will not affect processing already undertaken before consent was withdrawn.
Marketing Communications
You may opt out of receiving marketing communications at any time by:
- using the unsubscribe link included in emails; or
- contacting us directly.
Service-related communications regarding your account or the operation of the Services may still be sent where necessary.
Lodging a Complaint
If you believe Brieft has not handled your personal information appropriately, we encourage you to contact us first so we have an opportunity to resolve your concerns. You may also lodge a complaint with the relevant privacy regulator in your jurisdiction where permitted by law.
Exercising Your Rights
To exercise any of the rights described in this Privacy Policy, please contact:
Email: mackenzie@brieft.work
We may request information necessary to verify your identity before responding to your request. We will respond within the timeframes required by applicable law.
14. Australian Privacy Act
Brieft is committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply.
We seek to collect only the personal information reasonably necessary to operate our Services and conduct our business. Where required, we will:
- collect information by lawful and fair means;
- inform individuals about our collection practices;
- use personal information only for authorised purposes;
- take reasonable steps to protect personal information;
- provide access to personal information where required;
- correct inaccurate information when requested;
- securely destroy or de-identify information that is no longer required.
Where personal information is disclosed overseas, we take reasonable steps to ensure that recipients handle personal information consistently with applicable privacy obligations.
If you believe Brieft has breached the Australian Privacy Principles, you may contact us using the details provided in this Privacy Policy. If we are unable to resolve your complaint, you may contact the Office of the Australian Information Commissioner (OAIC).
15. General Data Protection Regulation (GDPR)
For individuals located in the European Economic Area ("EEA"), United Kingdom or other jurisdictions where similar legislation applies, Brieft is committed to complying with applicable data protection laws, including the General Data Protection Regulation ("GDPR") where relevant.
Data Controller and Data Processor
Depending on how the Services are used:
- Brieft may act as a Data Controller in relation to information about our customers, website visitors and account administration.
- Brieft may act as a Data Processor where we process customer content solely on behalf of Business Customers using the platform.
Business Customers remain responsible for ensuring they have an appropriate legal basis for uploading personal information to Brieft.
Lawful Processing
We process personal information only where we have a lawful basis, including:
- performance of a contract;
- legitimate interests;
- consent;
- legal obligations;
- protection of vital interests.
These legal bases are described in Section 6 of this Privacy Policy.
International Transfers
Where personal information is transferred outside the EEA, United Kingdom or other jurisdictions with transfer restrictions, Brieft implements appropriate safeguards designed to protect personal information. These safeguards may include:
- Standard Contractual Clauses approved by relevant authorities;
- contractual commitments with service providers;
- recognised adequacy mechanisms;
- additional technical and organisational security measures where appropriate.
Data Subject Rights
Where GDPR applies, individuals may have the right to:
- access personal information;
- correct inaccurate information;
- erase personal information ("right to be forgotten");
- restrict processing;
- object to processing;
- receive data portability;
- withdraw consent;
- lodge a complaint with their local supervisory authority.
Automated Decision-Making
Brieft does not currently make decisions that produce legal or similarly significant effects based solely on automated processing. Should this change, we will update this Privacy Policy accordingly.
Data Protection by Design
Where appropriate, Brieft seeks to incorporate privacy and security considerations into the design, development and operation of the Services. We regularly review our technical and organisational measures to help ensure ongoing protection of personal information.
16. Responsibilities of Business Customers
Brieft is designed for use by businesses, organisations and professional teams. Business Customers control the information they upload to the Services and are responsible for determining the purposes and lawful basis for processing that information.
Accordingly, Business Customers are responsible for:
- ensuring they have the legal right to upload personal information to Brieft;
- obtaining any necessary consents, permissions or authorisations before uploading personal information;
- complying with applicable privacy and data protection laws;
- ensuring information uploaded to Brieft is accurate where required by law;
- managing user permissions and workspace access appropriately;
- managing guest access links and external sharing responsibly;
- responding to requests from individuals regarding personal information they control;
- ensuring that only authorised users have access to confidential or sensitive information.
Where Brieft processes customer content solely for the purpose of providing the Services, we do so on behalf of the relevant Business Customer and in accordance with applicable agreements and law.
Nothing in this Privacy Policy transfers ownership of customer content to Brieft. Business Customers retain ownership of their uploaded files, documents and associated intellectual property, subject to any rights necessary for Brieft to provide the Services.
17. Children's Privacy
Brieft is a business-focused platform and is not directed to children. The Services are intended for use by businesses, organisations and individuals who are at least 18 years of age or the age of legal majority in their jurisdiction.
We do not knowingly collect personal information directly from children. If we become aware that personal information has been collected directly from a child without appropriate authorisation where required by law, we will take reasonable steps to delete that information as soon as practicable.
If you believe that a child has provided personal information to Brieft, please contact us using the contact details provided in this Privacy Policy.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to our Services;
- changes to applicable laws or regulations;
- new technologies;
- changes to our business operations;
- improvements to our privacy practices.
When we make material changes, we will take reasonable steps to notify users where required by law. Notification may occur through the Services, by email, or by other appropriate means.
The "Last Updated" date at the beginning of this Privacy Policy indicates when this Privacy Policy was most recently revised.
Your continued use of the Services after an updated Privacy Policy becomes effective constitutes your acknowledgement of the revised Privacy Policy, except where applicable law requires additional consent.
We encourage users to review this Privacy Policy periodically to remain informed about how personal information is collected, used and protected.
19. Contact Us
If you have any questions, concerns or requests regarding this Privacy Policy or the way Brieft handles personal information, please contact us.
Privacy Contact
Brieft
Email: mackenzie@brieft.work
We will endeavour to respond to privacy enquiries and requests within a reasonable timeframe and in accordance with applicable law.
If you believe Brieft has not complied with applicable privacy legislation, we encourage you to contact us first so we have an opportunity to investigate and resolve your concerns.
Where applicable, you may also have the right to lodge a complaint with your local privacy regulator or supervisory authority.
