Privacy Policy
Last updated: 2026-04-20
Controller: Leadership Under Uncertainty (operator of the NorthBrief pilot). Contact: privacy@leadershipunderuncertainty.org.
1. Who we are
NorthBrief delivers AI-powered strategic intelligence briefs, forecasts, and advisory to executives. This policy explains what personal data we process, why, how long we keep it, and your rights under the EU General Data Protection Regulation (GDPR).
2. What we process
We process these categories of personal data:
- Identifiers: name, email address, phone number (WhatsApp/SMS), LinkedIn URL.
- Professional profile: organization, job title, industry, geography, strategic themes, goals.
- Strategic context: the free-text operating context and Strategic Living Script you provide. Please avoid including special-category data (health, political opinions, religion, union membership) in these fields.
- Behavioral data: clicks, reads, feedback, conversational input to the advisor.
- Optional Gmail content: only if you explicitly connect Gmail via OAuth.
- Security data: IP address, user agent, audit log entries.
- Billing identifiers: Stripe customer and subscription IDs. Payment card data is held by Stripe; we never see it.
3. Why we process it and our lawful basis
We rely on the following GDPR Article 6 bases:
- Contract (Art 6(1)(b)): delivering briefs, forecasts, and the advisor service; account management; billing.
- Consent (Art 6(1)(a)): marketing communications; non-essential analytics (Vercel, Sentry); behavioral profiling for personalization. You can withdraw consent at any time from Settings without affecting the lawfulness of prior processing.
- Legitimate interest (Art 6(1)(f)): security audit logging; fraud prevention; aggregate pseudonymized analytics.
4. How long we keep it
Default retention periods:
- Active account data: for the lifetime of the account.
- Audit logs: 90 days.
- Behavioral telemetry: 180 days.
- Search query logs: 30 days.
- Newsletters / brief deliveries: 90 days.
- Optional Gmail threads: 180 days once the retention job is enabled.
- Deleted accounts: 30-day grace period, then full erasure.
- Legal / tax records: retained per statutory obligation (typically 5 years).
Full retention register: cookie policy + our internal Records of Processing Activities (available on request).
5. Sub-processors
We rely on a small set of processors to deliver the service. Each processes personal data under our instructions, subject to a Data Processing Agreement.
- Infrastructure: Vercel, Neon (PostgreSQL), Upstash (Redis).
- LLMs: OpenRouter (which proxies Anthropic Claude and Google Gemini), OpenAI (fallback and audio).
- Signal sources: Perplexity, Brave Search, Exa, news APIs.
- Communications: Resend (email), Twilio (WhatsApp, SMS).
- Voice: ElevenLabs (optional audio briefs).
- Profile enrichment: Brightdata (LinkedIn).
- Payments: Stripe.
- Monitoring: Sentry, Vercel Analytics.
Most of these vendors are established in the United States. Transfers rely on Standard Contractual Clauses (Module 2, controller→processor) and, where available, the EU–US Data Privacy Framework. We maintain a Transfer Impact Assessment for the sub-processors that are not covered by an adequacy decision.
6. Your rights
- Access (Art 15): download a JSON bundle of your data from Settings → Privacy → Export my data.
- Rectification (Art 16): edit your profile from Settings.
- Erasure (Art 17): request deletion from Settings → Privacy → Delete my account. A 30-day grace period allows recovery; after that, data is permanently erased.
- Restriction (Art 18), Object (Art 21): contact privacy@leadershipunderuncertainty.org.
- Portability (Art 20): the same JSON export as Art 15 is in a structured, machine-readable format.
- Automated profiling opt-out (Art 22): from Settings → Privacy → Automated profiling. Opting out does not affect core brief delivery; it disables behavior- derived personalization.
- Complaint: you may lodge a complaint with your local supervisory authority. The lead authority for us is the Spanish AEPD (www.aepd.es).
7. Security
We encrypt phone numbers and multi-factor authentication secrets at rest with AES-256-GCM. All data in transit is protected by TLS 1.2 or higher. We maintain an audit log, require multi-factor authentication on admin actions, and run pre-commit security gates on every code change. Our security controls are tracked against SOC 2 criteria.
8. Breach notification
If a personal-data breach is likely to result in a risk to your rights and freedoms, we notify the Spanish AEPD within 72 hours of confirmation. If the breach is likely to result in a high risk, we notify affected users directly without undue delay.
9. Children
NorthBrief is a business-to-business product for executives and does not target users under 16. We do not knowingly process personal data of children.
10. Changes to this policy
We review this policy at least annually and upon material change. When we update the policy in a way that affects your rights, we bump the version and request your re-consent on next sign-in. The current policy version is 2026-04-20.