01 Introduction
This Privacy Policy explains how Vertical Real Estate B.V., registered with the Dutch Chamber of Commerce (KvK) under number 99566346, located at Zanddwarsstraat 12, 1011 HP Amsterdam, the Netherlands (“Company”, “we”, “us”, or “our”), trading under the brand name BrickPilot, collects, uses, shares, and protects your personal data when you access or use our website and the BrickPilot platform (collectively, the “Service”).
This Privacy Policy should be read together with ourTerms of Service,Cookie Policy, and, where applicable, theData Processing Agreement (“DPA”). In the event of a conflict, the order of precedence set out in the Terms of Service applies.
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, you should not use the Service.
02 Privacy contact
We have not appointed a Data Protection Officer as this is not required under Article 37 GDPR given the nature and scale of our processing activities. For all privacy-related questions, requests, or complaints, you can contact our designated privacy contact:
Laurens van Duin, Privacy Contact
Email: [email protected]
03 Personal data we collect
3.1 Data you provide to us
- Account registration data: name, email address, company name, and authentication credentials (including via Google and Microsoft SSO).
- Payment and billing data: payment method details and transaction history. We do not store your payment card details; these are processed by our payment provider Mollie.
- Project data: documents, files, project descriptions, addresses, and other materials you upload or create through the Platform.
- Communications: messages, support requests, and feedback you send to us.
3.2 Data collected automatically (Usage Data)
- Device and browser information: IP address, browser type and version, operating system, device type, unique device identifiers.
- Usage information: pages visited, time and date of visits, time spent on pages, referral URLs, click patterns, and feature usage.
- Log data: server logs, error reports, and diagnostic data.
3.3 Data from third-party authentication
If you register or log in through Google or Microsoft, we may collect your name, email address, and profile picture as made available by those providers. The scope of data depends on your privacy settings with the relevant provider.
3.4 Public source data
The Platform retrieves data from public sources (Kadaster, BAG, DSO, PDOK) on your behalf. This data typically does not constitute personal data, but where it does (e.g. property ownership records), we process it solely to provide the Service on the basis of the performance of our contract with you.
04 How we use your personal data
We process your personal data for the following purposes and on the following legal bases:
| Purpose | Description | Legal basis |
|---|---|---|
| Providing the Service | Operate, maintain, and improve the Platform; manage your account; process AI-assisted project workflows, document analysis, and data retrieval from public sources. | Performance of contract (Art. 6(1)(b) GDPR) |
| Public source data retrieval | Retrieve and process data from public registries (Kadaster, BAG, DSO, PDOK) on your behalf, which may incidentally include personal data such as property ownership records. | Performance of contract (Art. 6(1)(b) GDPR) |
| Payment processing | Process subscription payments and one-time purchases via Mollie. | Performance of contract (Art. 6(1)(b) GDPR) |
| Communication | Contact you regarding account matters, security updates, service notifications, and support requests. | Legitimate interest (Art. 6(1)(f) GDPR) |
| Marketing | Send information about products, services, and events similar to those you have used. You can opt out at any time. | Legitimate interest (Art. 6(1)(f) GDPR) with opt-out |
| Analytics and improvement | Analyse usage trends, measure campaign effectiveness, and improve the Service and AI model performance. Google Workspace Data is expressly excluded from these analytics and model-improvement purposes. | Legitimate interest (Art. 6(1)(f) GDPR) |
| Security and fraud prevention | Monitor for and prevent unauthorised access, misuse, or security incidents. | Legitimate interest / Legal obligation (Art. 6(1)(c)/(f) GDPR) |
| Business transfers | Evaluate or conduct mergers, acquisitions, or asset sales where personal data may be among transferred assets. | Legitimate interest (Art. 6(1)(f) GDPR) |
05 Google Workspace API data
This section applies specifically to information that BrickPilot receives from Google Workspace APIs, including Gmail data and data derived from it (“Google Workspace Data”). If this section conflicts with a more general provision elsewhere in this Privacy Policy, this section controls for Google Workspace Data.
5.1 Data we access
When you connect Gmail, BrickPilot may access your Google account email address; Gmail message and thread identifiers; senders, recipients, subjects, timestamps, labels, and read, unread, or archive status; message bodies that you ask BrickPilot to find or read; and the recipients, subject, and body of drafts created at your request. BrickPilot requests thegmail.modify permission so these user-facing features can work. We do not access Gmail attachments through the current integration.
5.2 How we use the data
We use Google Workspace Data only to provide features that you can see and request in BrickPilot: connecting your account, searching and reading relevant email, producing a user-requested summary or answer, creating Gmail drafts, and changing mailbox state such as marking a thread read or unread or archiving it. The BrickPilot AI assistant creates drafts and does not send them automatically. If a separate user-facing mailbox action supports sending, it requires your additional explicit confirmation before the message is sent.
5.3 Storage and retention
OAuth access and refresh tokens are encrypted at rest and retained only while your Gmail connection remains active. Message content is retrieved on demand; we do not create a permanent copy of your mailbox or use Gmail data to build an independent database. Content that you deliberately place in a BrickPilot conversation, summary, or draft is retained as part of that user-requested output under the retention periods in section 10. When you disconnect Gmail, we revoke the Google authorisation where technically available and delete the stored connection credentials. You can also revoke access in your Google Account or ask us to delete related data by contacting [email protected].
5.4 Sharing, human access, and AI
We do not sell Google Workspace Data, use it for advertising, share it with data brokers, or use it for credit, lending, or insurance decisions. We transfer it only to service providers that are necessary to deliver the specific feature you requested, such as our secured hosting and AI-inference providers, under contractual confidentiality and data-protection obligations; when required for security or applicable law; or with your explicit consent. We do not permit human access except with your affirmative agreement for specific data, when necessary for security or abuse investigation, when required by law, or for internal operations after the data has been aggregated and anonymised.
Google Workspace Data is used only to produce the specific, user-facing result you requested. It is not used to develop, improve, or train generalised or non-personalised AI or machine learning models, foundation models, or models for other customers.
5.5 Google Limited Use
BrickPilot’s use and transfer to any other app of information received from Google APIs will adhere to theGoogle API Services User Data Policy, including the Limited Use requirements.
08 International data transfers
Your information, including personal data, is processed at our offices and by our Service Providers, some of which are located outside the European Economic Area (EEA), including in the United States.
Where personal data is transferred outside the EU/EEA to a country without an adequate level of data protection, transfers are protected by EU Standard Contractual Clauses (SCCs) or other approved safeguards under Chapter V GDPR, supplemented by additional measures where required.
You can request information about safeguards in place by contacting us at[email protected].
09 Service providers and sub-processors
The following third-party Service Providers may access your personal data to provide services on our behalf:
| Provider | Processing activities | Location | Transfer mechanism | Category |
|---|---|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, computing, storage, hosting; AI model inference via AWS Bedrock (Anthropic) | Global cross-region inference; primary storage in EU / Switzerland | AWS DPA; SCCs for international transfers | Infrastructure & AI |
| Railway (Railway Corp.) | Application and frontend hosting, backend services, edge delivery, logging, container orchestration | US | Railway DPA; SCCs | Infrastructure |
| Storyblok (Storyblok GmbH) | Content management system (CMS) for website and platform content | EU | Storyblok DPA | CMS |
| OpenRouter (OpenRouter, Inc.) | AI model routing and API gateway; forwarding prompts to Mistral and other AI providers for inference | US | OpenRouter DPA; SCCs | AI Inference |
| Slack (Salesforce, Inc.) | Internal team communication, including support request handling and project coordination where User data may be referenced | US | Slack DPA; SCCs; DPF | Communication |
| GitHub (Microsoft) | Source code hosting, version control, CI/CD pipelines | US | GitHub DPA; SCCs; DPF | Development |
| Mollie B.V. | Payment processing for subscriptions and purchases | EU (NL) | Mollie DPA | Payments |
| Google (Google LLC) | Marketing lead capture — website scan and contact form submissions (name, email, company, address) are received and stored via Google Apps Script / Google Sheets | US | Google DPA; SCCs; DPF | Marketing |
| Google (Google Ireland Ltd / Google LLC) | Google Tag Manager and Google Analytics 4 for website analytics, used only on the brickpilot.ai marketing site and loaded only after active analytics consent | EU (Google Ireland Ltd, contracting party); onward transfer to Google LLC in the US may occur | DPF for Google LLC; SCCs where applicable | Consent-based analytics |
Note regarding OpenRouter: OpenRouter routes inputs to downstream AI model providers (including Mistral). We require OpenRouter to contractually ensure equivalent data protection obligations from each downstream provider.
Note regarding AWS Bedrock: AI inference via Anthropic models is provided through AWS Bedrock. Data processed through Bedrock is subject to AWS’s data processing terms, may be routed globally within AWS’s cross-region inference infrastructure, and does not leave AWS infrastructure.
10 Data retention
- Account data: retained for the duration of your active account and deleted two (2) years after deactivation or inactivity.
- Project data: retained for the duration of your active account. Upon termination, project data is retained for thirty (30) days to allow export, after which it is securely deleted.
- Google connection credentials: retained only while your Google connection is active and deleted when you disconnect it, revoke access, or delete your account, subject only to short-lived backups and legal or security obligations.
- Legal compliance data: retained for one (1) year after the purpose of collection has been fulfilled, to comply with legal obligations and resolve disputes.
- Usage data: retained for internal analysis purposes for a maximum of twenty-four (24) months, unless required for security or legal purposes.
11 Your rights
Under the GDPR and applicable data protection laws, you have the following rights:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your data, subject to legal retention obligations.
- Restriction: request restriction of processing in certain circumstances.
- Data portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: where processing is based on consent, withdraw at any time.
You can exercise these rights through your account settings or by contacting us at[email protected]. We will respond within one (1) month, unless complexity requires up to two additional months.
You have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your national supervisory authority.
12 Data Processing Agreement
If you upload personal data to the Platform in a professional capacity, we operate as a Data Processor and you as a Data Controller under the GDPR. TheData Processing Agreement, available as a separate document, sets out the details of this arrangement.
13 Children’s privacy
The Service is not directed at anyone under 18. We do not knowingly collect personal data from minors. If we become aware of such collection without parental consent, we will delete it promptly.
14 Security
We implement appropriate technical and organisational safeguards, including encryption in transit, access controls, least-privilege access, monitoring, and incident-response procedures. Google OAuth tokens are encrypted at rest and are accessible only to systems and authorised personnel that need them to operate the connected service. However, no method of electronic transmission or storage is 100% secure, and we cannot guarantee absolute security.
15 Changes to this privacy policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new version and, where appropriate, by email. The version date at the top indicates when it was last revised.
16 Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
Vertical Real Estate B.V. (trading as BrickPilot)
Zanddwarsstraat 12, 1011 HP Amsterdam
The Netherlands
KvK: 99566346
VAT: NL869042221B01
Privacy contact: Laurens van Duin
Email: [email protected]
