GDPR · Transparency
Privacy Policy
This Policy explains processing by Ollyn in Braisely, including for visitors, customers, and people whose professional information appears in a signal or prospect list.
Version 1.0 · Last updated: September 14, 2026.
1. Controller and roles
OLLYN, a French simplified joint-stock company with a sole shareholder and share capital of EUR 1,000, Strasbourg RCS 932 407 729, 7 rue Joseph Schmitt, 67500 Weitbruch, France, is controller for website, account, billing, support, security and its own business-relationship processing.
For data imported or processed under a customer's criteria and instructions, that customer is generally controller and Ollyn is processor. Where Ollyn determines the purposes and means of collection or enrichment from public sources, it is controller for that operation. Individuals may always contact Ollyn, which will route the request where needed.
2. People and data covered
- Visitors: IP address, technical logs, browser, device, requested pages, language and strictly necessary cookies.
- Users and customers: email, company or workspace, hashed password, preferences, settings, support requests, login and usage history, billing identifiers, plan and credit movements. Braisely does not store full payment-card numbers.
- Prospects and professional contacts: name, role, employer, business location, business email or phone where available, profile and website URLs, public posts and interactions, professional events, detected signals, source, date, scores, analyses and outreach drafts.
- Customer-supplied data: imported lists, domains, targeting criteria, keywords, instructions, notes, export destinations, webhooks and technical credentials for enabled integrations.
3. Data sources
Data comes directly from users and customers, from publicly accessible or open sources, and from technical providers. Depending on enabled features, sources may include company websites, public professional profiles or content, news and press feeds, job postings, public-procurement notices, advertising libraries, domain-name data, and results supplied by collection or enrichment services.
Public availability does not remove a person's rights. Where possible, Braisely keeps the source or URL used to verify origin and limits collection to information relevant to the configured professional purpose.
4. Purposes and legal bases
- Contract: create and administer accounts; provide analyses, exports, alerts and integrations; manage support, credits, subscriptions and payments.
- Legal obligations: accounting, tax, data-subject requests and cooperation with competent authorities.
- Legitimate interests of Ollyn or its customers: secure and diagnose the Service, prevent abuse, improve quality, manage B2B relationships and identify relevant professional opportunities from lawful sources after balancing the rights and interests involved.
- Consent where the law requires it: optional communications, non-essential trackers, or outreach on a channel or in a context requiring prior permission. Consent may be withdrawn at any time.
5. Qualification, AI and decisions
Braisely may use rules and AI models to summarise public content, search for business context, qualify contact relevance, assign scores and draft messages. Data sent to an AI provider is limited to what the operation needs.
Outputs assist a professional user. Braisely is not intended to make decisions on its own that produce legal or similarly significant effects on an individual. The customer must conduct human review before outreach or action.
6. Recipients and providers
Data is available to authorised Ollyn personnel and the relevant Customer. Depending on the features used, the following provider categories may process it:
- Infrastructure providers for application, database, backup and technical-log hosting.
- AI-model, search, collection and enrichment providers, limited to the data needed for the requested operation.
- Payment, service-email, error-diagnosis, media-delivery and business-email-verification providers.
- When enabled by the Customer, outreach, customer-relationship-management and content-audit tools, webhooks or other destinations selected by the Customer. Those recipients then process data under their own terms and the Customer's configuration.
- Authorities, advisers and potential acquirers only where legally required or within a secured restructuring process. Data is not sold for advertising.
7. Transfers outside the EEA
The primary infrastructure hosting the application and its database is configured in a European region. Some providers may nevertheless process data in the United States or other countries outside the EEA. Depending on the recipient, transfers are covered by an adequacy decision, the EU–US Data Privacy Framework for certified entities, European Commission Standard Contractual Clauses and appropriate supplementary measures.
The Customer must ensure that integrations it chooses provide safeguards appropriate to its processing. Further information about applicable safeguards may be requested from Ollyn.
8. Retention
- Customer account and operational data: for the contract term, then normally returned or deleted within 90 days after a closure request, subject to backups and legal duties.
- Prospect and signal data: for the period set by the Customer where Ollyn acts on its behalf; without an instruction, no later than three years after collection, last contact or the last relevant update.
- Ollyn's own prospecting data: three years after the latest contact or end of the business relationship. Suppression-list data: the minimum information needed to honour an objection on an ongoing basis.
- Contracts, invoices and accounting evidence: ten years where legally required. Security logs and support data: proportionate to their purpose, usually no more than twelve months unless an incident or dispute requires longer.
- Deleted data may remain temporarily in access-restricted backups until rotation.
9. Notice for indirectly collected data
Where professional data is not collected from the individual, notice must be given as soon as possible and no later than one month, at first contact or before first disclosure to a third party, whichever happens first, unless a documented legal exception applies.
Where the Customer determines the campaign, it must give this notice, including its identity, purpose, legal basis, data categories and sources, recipients, retention, rights and the right to complain to the relevant supervisory authority.
10. Your rights
Depending on the processing, you may request access, correction, deletion, restriction and portability, withdraw consent and object to processing. You may object to direct marketing at any time, free of charge and without giving a reason. French law also allows instructions for data after death.
To exercise rights, email beforethefire@braisely.co with enough information to locate your data. Identity evidence is requested only where reasonable doubt exists. You may complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at cnil.fr.
11. Cookies and trackers
Braisely uses cookies strictly necessary for authentication, security, CSRF protection and language preferences. Consent is not required where they remain limited to those purposes. As of this Policy date, the site uses no advertising cookie or audience-measurement tool requiring consent.
If non-essential trackers are added, Braisely will present a choice tool before placing them and update this Policy. Requests to media-delivery providers may create technical logs at those providers.
12. Security
Ollyn uses risk-appropriate measures including HTTPS transport encryption, password hashing, logical workspace separation, access controls, backups and error monitoring. No system is completely invulnerable; suspected incidents may be reported to beforethefire@braisely.co.
13. Changes
This Policy may change with the Service or law. Its date and version appear above. Customers will receive appropriate notice of a material change affecting existing processing.