Bryntra ("we") provides business software for construction and installation companies. We take privacy seriously, not as a legal obligation, but as a design principle. This policy explains what personal data we process, why, and what rights you have under the GDPR.
Two roles: data controller and processor
For data belonging to visitors of this website and account holders (name, e-mail, billing details), we are the data controller. For the data your company stores in Bryntra (customers, quotes, invoices, schedules), your company is the data controller and we are the processor: we process that data solely on your instructions and never use it for our own purposes.
What data we process
- Account & workspace: name, e-mail address, role, login credentials (hashed), 2FA settings, language.
- Billing: company name, address, VAT number and payment status. Payments run through Stripe; we never see or store full card numbers.
- Contact form: name, e-mail and your message, only to answer your question.
- Usage data: technical logs (error reporting, security logs) for stability and abuse prevention.
- Tenant data (as processor): everything your team enters into the application.
Where your data is stored
All application data is hosted within the European Union (database and storage in Ireland, application servers in Dublin). Every workspace is separated from other workspaces at database level through row-level isolation.
Sub-processors
We use a small number of carefully chosen sub-processors:
- Supabase: database, authentication and file storage (EU/Ireland)
- Vercel: application hosting (EU region, Dublin)
- Stripe: payments and subscriptions
- Resend: transactional e-mail (quotes, notifications, digests)
- Mapbox: address autocomplete (only the address you type)
- AI providers (via OpenRouter): only for AI features you actively use; AI processing happens per request and is never used to train models.
- Sentry: error reporting (technical logs)
Cookies
This website uses no third-party cookies for tracking or advertising and shows no cookie banner. We do set one first-party cookie for our partner programme: if you arrive via an affiliate link (for example bryntra.com/a?ref=partner), we remember for up to60 days which partner referred you, so we can reward them if you become a customer. That cookie holds only a partner code and a date, is never shared with anyone, and does not follow you across other websites. The application itself uses only functional cookies (session, active workspace, language preference).
Retention periods
We retain account data for as long as your account exists. If you cancel, you can export all your data; after that we delete the workspace data completely. We keep financial records for as long as the law requires (7 years). Contact form messages are deleted no later than 12 months after handling.
Your rights (GDPR)
You have the right to access, rectification, erasure, restriction, data portability and objection. Bryntra has this built in: owners can run a full export and request erasure via Settings → Data & privacy. For anything else, e-mail support@bryntra.com. We respond within 30 days. You can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security
Encryption in transit (TLS) and at rest, row-level isolation per workspace at database level, two-factor authentication (enforceable per workspace), role-based access, audit logging of sensitive actions and daily backups. More at bryntra.com/en/security.
Changes
If we make material changes to this policy, we'll notify account holders by e-mail or in the application. The current version is always available on this page.
Contact
Questions about privacy? E-mail support@bryntra.com.