This privacy policy describes how Bryntra B.V. processes personal data in connection with the website bryntra.com, the application app.bryntra.com and the related services. It has been drawn up in accordance with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act and the Dutch Telecommunications Act. This document is an English translation of the Dutch privacyverklaring; in the event of any discrepancy, the Dutch version prevails.
Controller
Bryntra B.V., having its registered office in Deventer, the Netherlands
Visbystraat 9, 7418 BE Deventer, the Netherlands
Dutch Chamber of Commerce (KvK) no. 42133268 · VAT id NL869871456B01
E-mail: support@bryntra.com
Bryntra has not appointed a data protection officer; there is no legal obligation to do so. Privacy requests are handled via the e-mail address above.
1. Who we are
Bryntra B.V. ("Bryntra", "we") provides business software (SaaS) for window, construction and installation companies: quotes with e-signing, a 3D configurator, CRM, orders and invoicing, planning, work orders and reporting. Our customers are exclusively business users.
2. Scope and roles: controller and processor
Bryntra acts in two distinct roles. This policy covers only the first.
- 2.1Bryntra as controller. For personal data of visitors to our website, of persons who contact us or request a demo, and of account holders and users of the application (insofar as their own account, billing and usage data is concerned), Bryntra itself determines the purposes and means of the processing. This policy applies to those processing operations.
- 2.2Bryntra as processor. For personal data that our customers enter into their workspace or have processed there — such as data of their own customers, leads, contact persons and employees in quotes, orders, invoices, schedules and work orders — the customer concerned is the controller and Bryntra acts as processor. That processing is governed by the data processing agreement, which forms an integral part of our terms of service. We process such data solely on the customer's instructions and never for our own purposes.
- 2.3Is your data held in the workspace of a company that uses Bryntra (for example because you are a customer of that company)? Then please address requests about that data to that company; it is the controller. If we receive such a request directly, we forward it to the customer concerned and support them in handling it.
3. Which personal data we process
Depending on your relationship with us, we process the following categories of personal data. We do not process special categories of personal data (such as health data) and ask that you do not provide them to us.
- Contact and identification data: name, business e-mail address, phone number, company name, position/role and industry.
- Account and authentication data: login credentials (passwords exclusively as a cryptographic hash), two-factor authentication settings, language preference, session data.
- Billing and payment data: company name, billing address, VAT number, selected plan, payment status and payment history. Payments run through our payment service provider Stripe; full card or account numbers never reach Bryntra.
- Communication data: the content of contact and demo requests, support correspondence and your chosen demo slot.
- Technical and usage data: IP address, browser and device characteristics, log files, error reports and security logs.
- Partner attribution data: only if you reach us through a partner's referral link: the partner code and the date of the first visit.
We obtain this data directly from you, from your use of the website and the application, or — in the case of a user account created for you by an employer or colleague — from the customer who invites you.
4. Purposes, legal bases and retention periods
The overview below is the core of this policy: for each purpose it shows which data we process, the legal basis under Article 6(1) GDPR and how long we keep the data. After a retention period expires, data is deleted or irreversibly anonymised.
| Purpose | Data | Legal basis (Art. 6(1) GDPR) | Retention |
|---|---|---|---|
| Securely serving the website | IP address, browser and device characteristics, log files | (f) — legitimate interest (security and operation) | at most 90 days, unless longer is necessary for an ongoing incident investigation |
| Handling contact and demo requests | name, e-mail, phone, company, industry, message, preferred demo slot | (b) — (pre-)contractual steps at your request | at most 12 months after the request has been handled |
| Providing and securing account and workspace | contact, account and authentication data | (b) — performance of the contract | duration of the account; deletion 30 days after the end of the agreement |
| Invoicing and accounts receivable | billing and payment data | (b) and (c) — contract and legal (tax) obligation | 7 years (Dutch tax retention obligation) |
| Service and product notices about your account | name, e-mail address, account data | (b) — performance of the contract | duration of the account |
| Commercial e-mail to existing customers about similar services | name, business e-mail address | (f) — legitimate interest; unsubscribe available in every message | until unsubscribe or end of the customer relationship |
| Partner programme: attribution and settlement of referrals | partner code and date (first-party cookie) | (f) — legitimate interest (correct partner commission) | at most 60 days |
| Stability: error reporting and performance monitoring | technical error data, truncated context, IP address | (f) — legitimate interest (a reliable service) | at most 90 days |
| Complying with legal obligations and requests from competent authorities | the data necessary for that purpose | (c) — legal obligation | the legally prescribed period |
Where we rely on a legitimate interest, we have balanced that interest against your interests and fundamental rights. Further information about that balancing test is available on request via support@bryntra.com.
5. Cookies and similar techniques
We use no tracking or advertising cookies and therefore show no cookie banner. Visitor statistics are measured cookielessly and in aggregate. The functional cookies we do use — with name, purpose and duration — are listed in the cookie policy, which forms part of this policy.
6. Recipients and sub-processors
We do not sell personal data and do not provide it to third parties for their own (marketing) purposes. Personal data is shared only with the categories of recipients below, in each case limited to what is necessary for the purpose:
- 6.1Sub-processors that enable us to provide the service. Data processing arrangements have been concluded with each of them offering at least the level of protection of our own data processing agreement:
Party Service Processing location Transfer safeguard Supabase database, authentication, file storage EU (Ireland); US parent company EU-US DPF and/or SCCs Vercel hosting of website and application; cookieless web statistics EU region (Dublin); US parent company EU-US DPF and/or SCCs Stripe payments and subscription management EU and US EU-US DPF and/or SCCs Resend transactional e-mail (verification codes, notifications) US EU-US DPF and/or SCCs Cloudflare bot protection on forms (Turnstile) EU and US EU-US DPF and/or SCCs Mapbox address autocomplete (only the address you type) US SCCs OpenRouter AI processing, per request only, for AI features you use US SCCs Sentry error reporting EU and US EU-US DPF and/or SCCs - 6.2Professional advisers (such as an accountant or lawyer), only insofar as necessary and under confidentiality.
- 6.3Competent authorities, only where we are legally required to do so or where necessary for the establishment, exercise or defence of legal claims.
- 6.4Legal successors in the event of a merger, acquisition or transfer of (part of) our business, with continuation of the safeguards of this policy; we will inform you of such a transition.
7. Transfers outside the EEA
- 7.1Application data is stored within the European Union (database and storage in Ireland; application servers in the EU region Dublin).
- 7.2Some of our sub-processors are established in, or are part of a group established in, the United States. Insofar as personal data is processed outside the European Economic Area in that context, this takes place exclusively on the basis of a valid transfer mechanism under Chapter V GDPR: an adequacy decision of the European Commission — including the EU-US Data Privacy Framework for recipients certified under it — and/or the European Commission's Standard Contractual Clauses (SCCs), supplemented where necessary by additional measures such as encryption and EU data residency.
- 7.3A copy of, or reference to, the safeguards used is available on request via support@bryntra.com.
8. Security
We implement appropriate technical and organisational measures within the meaning of Article 32 GDPR, including: encryption of data in transit (TLS) and at rest; logical separation of workspaces at the database level (row-level security); two-factor authentication, enforceable per workspace and mandatory for our own platform administration; role-based access following the least-privilege principle; audit logging of sensitive actions; daily backups within the EU; and a responsible-disclosure process for vulnerabilities. A more detailed description is available at bryntra.com/en/security and in Annex 2 to the data processing agreement. If you suspect a vulnerability, please report it via support@bryntra.com.
9. Your rights
Under the GDPR you have the following rights:
- 9.1Access (Art. 15 GDPR): confirmation as to whether we process personal data about you and, if so, a copy of it with the accompanying information.
- 9.2Rectification (Art. 16 GDPR): correction or completion of inaccurate or incomplete data. You can adjust most account data yourself in the application.
- 9.3Erasure (Art. 17 GDPR): deletion of your data, among other cases where it is no longer necessary. Workspace owners additionally have a built-in export and deletion function (Settings → Data & privacy). Data we are legally required to retain is exempt from erasure.
- 9.4Restriction of processing (Art. 18 GDPR) in the cases set out there, for example while an objection is being assessed.
- 9.5Data portability (Art. 20 GDPR): receipt of data you provided in a structured, commonly used and machine-readable format. The export function in the application largely provides for this.
- 9.6Objection (Art. 21 GDPR) to processing based on legitimate interest, on grounds relating to your particular situation. You may object to the use of your data for direct marketing at any time and free of charge; we will then stop that processing immediately.
- 9.7Withdrawal of consent (Art. 7(3) GDPR), insofar as processing is based on consent, without affecting the lawfulness of processing before the withdrawal.
You can exercise these rights by sending a request to support@bryntra.com. We may ask you to prove your identity before handling a request, for example by responding from the e-mail address known to us. We respond within one month; for complex or numerous requests this period may be extended by at most two further months, in which case we will inform you within the first month. Exercising your rights is free of charge, save for the cases referred to in Article 12(5) GDPR.
10. Automated decision-making and profiling
We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR), and we do not engage in profiling. AI features within the application run only at the user's initiative; their output serves as an aid that is reviewed by a human and is not used to train AI models.
11. Minors
Our services are aimed at business users. We do not target persons under 16 years of age and do not intend to process their data. If you believe we nevertheless process a minor's data, please contact us; we will then delete that data.
12. Changes to this policy
We may amend this policy, for example in the event of changes to our services, sub-processors or laws and regulations. In the event of material changes we will inform account holders by e-mail or through the application. The current version, with date and version number, is always available on this page; earlier versions are available on request.
13. Contact and complaints
Questions about this policy or about the processing of your personal data can be addressed to support@bryntra.com or by post to Bryntra B.V., Visbystraat 9, 7418 BE Deventer, the Netherlands.
If you disagree with the way we process personal data, we would appreciate you contacting us first so that we can look for a solution together. In addition, you have the right at any time to lodge a complaint with the supervisory authority. For Bryntra the lead supervisory authority is the Dutch Data Protection Authority: Autoriteit Persoonsgegevens, P.O. Box 93374, 2509 AJ The Hague, the Netherlands, autoriteitpersoonsgegevens.nl. You may also contact the supervisory authority of the EU member state where you live or work.