草稿,待律师审阅。[方括号] 内是法律实体占位。
Privacy policy
Status: draft pending counsel review.
Last updated: [LAST_UPDATED]
This policy describes how [LEGAL_ENTITY_NAME] (“Bruchim”, “we”, “us”) handles personal information when you visit bruchim.io, create a workspace on app.bruchim.io, or check in as a visitor at a customer location.
It is not legal advice. We intend to consult counsel on Quebec Law 25, PIPEDA, and the GDPR. Placeholder tokens in square brackets must be replaced before this text is treated as production.
Who we are
- Legal entity: [LEGAL_ENTITY_NAME]
- Registered address: [REGISTERED_ADDRESS]
- Governing law (intended): [JURISDICTION]
- Privacy contact: [PRIVACY_EMAIL]
- Data protection contact / DPO (if appointed): [DPO_EMAIL]
Information we collect
Marketing site (bruchim.io)
This site is static content. In v1 we do not use advertising pixels or a cookie consent manager. Locale is chosen in the URL (/en, /fr, …), not stored as a tracking cookie.
If you email us, we receive whatever you write in that message (name, address, content).
Server and CDN providers (Vercel, Cloudflare) may process ordinary request logs (IP address, user agent, path, time). See the subprocessors list.
Product (app.bruchim.io)
Workspace customers and their visitors may provide:
- Visitor name, email or phone (configurable), host, visitor type, expected and actual sign-in / sign-out times
- Optional photo
- Optional acceptance of customer terms or an NDA (consent version and timestamp)
- Badge print metadata and host-notification action history
- Account identity for workspace users (handled by our authentication provider)
Customers configure what their kiosk asks for. We process that data to provide the service they subscribe to.
How we use information
- To operate and secure the marketing site and the product
- To create and bill workspaces (billing is handled by Stripe; we do not put visitor records on invoices)
- To send transactional email that a customer configures (for example, host notifications)
- To investigate abuse, outages, and support requests
- To meet legal obligations when we have them
We do not sell personal information.
Retention
Workspace customers choose how long visitor personal data is kept. The product default is to keep records until the customer changes that setting or deletes the workspace. When a retention limit is set, the product anonymizes visit personal data after the visit ends (operational facts such as timestamps and location may remain for analytics).
Request logs at hosting providers follow those providers’ retention.
Sharing
We share information with the processors listed on our subprocessors page, with the customer who invited a visitor, and when the law requires it.
International transfers
Infrastructure may be in Canada, the United States, or other regions depending on the provider. Data residency is not a current product selling point. Customer contracts and a future DPA should state this clearly.
Your rights
Depending on where you live (including Quebec, Canada, and the EEA/UK), you may have rights to access, correct, delete, or export personal information, or to withdraw consent. Visitors should start with the company they visited. Workspace owners can contact us at [PRIVACY_EMAIL]. Product tools for a data-subject request on a single visit exist in the app; a full self-serve privacy portal is not shipped yet.
Cookies
v1 of this marketing site does not set analytics or advertising cookies. If we later add Vercel Analytics, Cloudflare Web Analytics, or a similar cookieless product, we will update this section. The product app uses cookies required for authentication and session.
Children
Bruchim is a business visitor-management service. It is not directed at children.
Changes
We will update the date above when this policy changes. Material changes should be announced to workspace owners when we have a production mailing list.
Contact
[PRIVACY_EMAIL]
[LEGAL_ENTITY_NAME]
[REGISTERED_ADDRESS]