Privacy Policy — Sentinel

Last updated: June 29, 2026

BRAIKE — Sentinel service (sentinel.braike.com)

Version: 1.0

Last updated: June 29, 2026

This policy describes how BRAIKE (“we”) processes your personal data as controller when you use Sentinel, our budget-monitoring and media-tracking copilot, accessible at sentinel.braike.com. It is drafted in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the French Data Protection Act No. 78-17, as amended.

1. Who are we?

Controller: BRAIKE, a simplified joint-stock company with share capital of EUR 20,000, whose registered office is located at 18 bis rue de Villiers, 92300 Levallois-Perret, registered with the Nanterre Trade and Companies Register under number 106 573 983.

Data protection contact: Edris PAIKAN — contact@braike.com.

Personal-data contact: contact@braike.com.

For the processing of data by BRAIKE in order to provide the Service to its customers, including audience data from advertising campaigns monitored via Sentinel, you (or your client, where you act as a processor for a third party that is the controller of such data) remain the controller and we act as processor (Art. 28 GDPR), under our data processing agreement (DPA).

2. What data do we collect?

2.1 Account data. Email address (unique identifier), full name, avatar and preferred language; workspace(s), role (owner, member, viewer) and invitations (invitee email, date of joining).

2.2 Platform connection data. OAuth access and refresh tokens for the connected platforms (Google Ads, Meta, TikTok, Microsoft Advertising), encrypted with AES-GCM-256.

2.3 Notification data. Telephone numbers of alert recipients (SMS / WhatsApp), in international format; email addresses and webhook URLs (Slack, Teams, Google Chat) that you configure.

2.4 Billing data. Stripe customer identifier and subscription identifier, subscription status, quantity billed and billing period.

2.5 Usage data and logs. Notification-sending logs (recipient, status), activity logs, workspace health snapshots, synchronisation statuses.

2.6 Technical and connection data. IP addresses, session identifiers and technical metadata generated when using the Service (server logs). [To be confirmed according to the actual hosting configuration.]

We do not collect sensitive data within the meaning of Article 9 GDPR.

3. Why do we collect your data?

PurposeLegal basis (Art. 6 GDPR)Data concerned
Creation and management of the account and workspacesPerformance of the contractAccount, profile, invitations
Budget monitoring and conversion-tracking auditPerformance of the contractCampaign data, logs
Connection to advertising accountsPerformance of the contractOAuth tokens
Sending notifications (email, SMS, WhatsApp, webhooks)Performance of the contractEmail, phone, webhook URL
Alerts and proactive monitoringPerformance of the contract (service reliability)Campaign data, logs
Assistance by the AI copilotPerformance of the contractBusiness context (budgets, labels, rules)
Billing and subscriptionPerformance of the contract / legal obligation (accounting)Billing data
Security and abuse preventionPerformance of the contract / legitimate interestLogs, connection data
Improving our products or developing new products, for example for research purposes or to generate aggregated and anonymous statisticsLegitimate interestLogs, connection data, aggregated and anonymous statistics, feedback

4. Automated decision-making and profiling

Sentinel implements no solely automated decision producing legal effects concerning you or significantly affecting you within the meaning of Article 22 GDPR. The AI copilot provides analyses and suggestions subject to your validation; no action is applied without your intervention.

5. With whom do we share your data?

RecipientRoleLocationTransfer safeguard
SupabaseDatabase, authentication, real-time, storageEuropean Union (AWS infra.)No transfer outside the EU
Vercel Inc.Application hostingUnited StatesDPF if certified, otherwise SCCs
Inngest Inc.Scheduled tasks (syncs, alerts)United StatesDPF if certified, otherwise SCCs
Google LLC (Gemini)AI copilot suggestionsUnited StatesDPF if certified, otherwise SCCs
Stripe Inc.Payment and subscriptionsUnited StatesDPF if certified + Stripe DPA, otherwise SCCs
Resend Inc.Sending emailsUnited StatesDPF if certified, otherwise SCCs
InfobipSending SMS and WhatsAppBosnia and Herzegovina / multi-regionSCCs + impact assessment (TIA)
Slack / Teams / Google ChatReceiving the webhooks you configureUnited StatesDepending on the channel you configure
Google Ads / Meta / TikTok / Microsoft AdsConnected advertising platforms (read access)United States / China (TikTok)OAuth authorisation + DPF/SCCs; SCCs + TIA for TikTok

6. Is your data transferred outside the European Union?

Our databases (Supabase) are hosted in the European Union: your account and campaign data resides there. Some providers are nonetheless located outside the European Economic Area (EEA), which entails transfers governed as follows:

United States (Vercel, Inngest, Google, Stripe, Resend, as well as the Google, Meta and Microsoft ad platforms): these transfers rely on the “EU–US Data Privacy Framework” adequacy decision where the provider is certified thereunder, and failing that on the standard contractual clauses (SCCs, EU Decision 2021/914).

China (TikTok) and Bosnia and Herzegovina (Infobip): in the absence of an adequacy decision, these transfers are governed by SCCs, supplemented by a transfer impact assessment and appropriate additional measures.

7. How long do we keep your data?

Type of dataRetention period
Account and workspacesTerm of the contract, then deletion within 30 days after termination (subject to legal obligations)
OAuth tokensAs long as the connection is active; deleted upon disconnection
Telephone numbers / notification channelsAs long as the channel is configured
Billing data10 years (accounting obligation, Art. L.123-22 of the French Commercial Code)
Logs and connection data12 months

8. Information for persons receiving notifications

When you configure the sending of notifications to third parties (for example by SMS or WhatsApp), you provide us with their contact details (such as name and telephone number). We process these contact details as a processor, on your behalf only and on your instructions, for the sole purpose of delivering the notifications you have set up.

As the controller of this processing, and in accordance with Article 8 of the Terms of Use, it is your responsibility: (i) to have an appropriate legal basis within the meaning of Article 6 GDPR; (ii) to inform these persons of this processing in accordance with Article 14 GDPR and, for the SMS and WhatsApp channels, to obtain their prior consent (Article 8.2 of the Terms of Use); (iii) to have the right to provide us with these contact details, it being recalled that you indemnify us against any claim by a recipient or third party in this respect (Articles 8.3 and 15.5 of the Terms of Use).

To enable you to meet your information obligation, we make available to you, upon simple request, the information about us that is useful for this purpose: the identity and contact details of the processor, the purpose of delivering the notifications, the categories of data processed and, where applicable, the sub-processors involved in the sending (our SMS / WhatsApp delivery provider is listed in section 5).

9. What are your rights?

You have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw your consent at any time. You may also set directives concerning the fate of your data after your death. Exercising these rights may require verification of your identity. You exercise them with contact@braike.com; we respond within one month. You may also lodge a complaint with the CNIL (www.cnil.fr).

10. Cookies and trackers

Sentinel uses only strictly necessary cookies (an authentication session cookie). No audience-measurement tracker or marketing pixel is used. See the Cookie Policy.

11. Security

Encryption of OAuth tokens (AES-GCM-256), HTTPS/TLS, data isolation per workspace (PostgreSQL Row-Level Security), signing of incoming webhooks (Stripe, Inngest) and session-token rotation.

12. Amendments to this policy

In the event of a material change, you will be informed by appropriate means at least 30 days before it takes effect, consistently with our Terms of Use. The update date appears at the top of this document.

13. Contact us

Email: contact@braike.com

Personal data: contact@braike.com

Address: 18 bis rue de Villiers, 92300 Levallois-Perret