
Privacy
Effective date: 11 September 2026
Version: 2026-09-11
This Privacy Policy explains how Collaborative Intelligence, Inc., doing business as Brade AI ("Brade AI", "Brade", "we", "us", or "our"), collects, uses, discloses, and protects Personal Data when you visit our websites or use our products, services, and applications (collectively, the "Services").
This Privacy Policy is a notice, not a request for blanket consent. By using the Services, you acknowledge that you have received this notice. Where applicable law requires consent for a specific activity, such as optional analytics technologies, we request that consent separately and provide a way to withdraw it.
Product use is governed by our Enterprise Terms and, where applicable, our Data Processing Addendum. The public website is governed by our Website Terms.
We may update this Privacy Policy as our Services or processing practices change. We will identify the effective date of each version and provide any additional notice, acknowledgment, or consent required by applicable law or contract. Continued use is not treated as consent where affirmative consent is legally required.
Scope and our roles
"Personal Data" means information that identifies, relates to, describes, or could reasonably be linked with an individual, including equivalent concepts under applicable privacy laws.
Brade generally acts as a processor or service provider when we process email content, attachments, contacts, customer business records, prompts, and related data on a business customer's instructions. The business customer determines why and how that data is processed and is generally the controller. Requests concerning that customer-controlled data should first be directed to the relevant customer.
Brade acts as a controller for account administration, our direct business relationships, billing, security, fraud prevention, legal compliance, support, and our own website and product analytics. A single record may be processed in different roles for different purposes.
Personal Data we process
Account and identity data
Names, business email addresses, telephone numbers, organization and role information, account identifiers, authentication events, and information received from identity providers.
Mailbox and integration data
Connected mailbox identifiers, provider and folder information, authorization records and tokens required to maintain a connection, synchronization state, and integration configuration. Brade does not receive your third-party account password from the mailbox provider.
Communications and attachments
Email sender and recipient details, subjects, message bodies, attachments, message identifiers, timestamps, and related conversation metadata processed through a connected mailbox or submitted directly to the Services.
Business and extracted data
Contacts, organizations, products, catalogues, pricing, inventory, orders, quotes, purchase requests, document contents, and structured information extracted or generated from customer-provided data.
AI inputs and outputs
Prompts, instructions, contextual records, model and provider information, generated drafts, extracted fields, responses, feedback, and information needed to operate and troubleshoot AI features.
Device, usage, and audit data
IP address, browser and device information, login and security events, page and feature interactions, request identifiers, application logs, audit trails, error reports, and performance information.
Commercial, billing, and support data
Subscription and order information, billing contacts, transaction records, usage and cost data, correspondence, support requests, survey responses, and other information you provide to us. Payment-card details may be collected directly by a payment provider rather than by Brade.
Sources
We obtain Personal Data from:
- you and the organization that provides your account;
- mailbox, identity, and other services that you or your organization connect;
- your use of the Services, including logs and audit records;
- service providers acting for Brade; and
- public or commercial sources used for business development, where permitted by law.
Purposes and legal bases
We process Personal Data to:
- provide, administer, secure, support, and troubleshoot the Services;
- connect and synchronize authorized mailboxes and integrations;
- extract, organize, retrieve, and present customer business information;
- generate AI-assisted analysis, recommendations, drafts, and other requested outputs;
- authenticate users and enforce permissions;
- process billing, measure usage, and administer customer relationships;
- monitor reliability, prevent abuse, investigate incidents, and maintain audit records;
- respond to requests and communicate about the Services;
- improve the Services using usage information and feedback, subject to contractual restrictions;
- comply with law and protect the rights, safety, and property of Brade, our customers, and others; and
- complete a merger, financing, acquisition, reorganization, or similar transaction.
Where the EU GDPR, UK GDPR, or similar law applies to processing for which Brade is the controller, our legal bases may include performance of a contract, compliance with a legal obligation, Brade's or a third party's legitimate interests, and consent where we specifically request it. Our legitimate interests include providing and securing the Services, administering business relationships, improving reliability, and preventing misuse. We do not rely on consent when another legal basis applies.
Artificial intelligence
Brade uses AI to analyze documents and communications, extract business information, assist with conversations, and generate drafts and quotes. Depending on customer configuration, relevant inputs and context may be sent to Anthropic, OpenAI, Google, or Microsoft Azure for model inference. Document-library PDFs and email attachments may also be sent to Google Cloud Document AI in the United Kingdom (London, europe-west2) for optical character recognition.
Brade does not use Customer Data to train or fine-tune general-purpose AI models. We use business or API services and provider configurations intended to restrict providers from using Customer Data for their own model training. Provider processing and retention are governed by the applicable service terms, configurations, and our agreements with those providers. Current providers and processing locations are identified in our public subprocessor list.
AI outputs may be incomplete or inaccurate and should be reviewed by an authorized user before they are relied upon or sent. Brade does not design the Services to make solely automated decisions about individuals that produce legal or similarly significant effects.
Disclosures and subprocessors
We may disclose Personal Data to:
- cloud hosting, database, storage, security, and monitoring providers;
- identity, mailbox, communication, and integration providers;
- AI model, document-processing, and analytics providers;
- billing, payment, support, and professional-service providers;
- parties you or your organization direct us to interact with;
- government authorities or other parties when required by law or necessary to protect rights and safety; and
- participants in a corporate transaction, subject to appropriate confidentiality protections.
Service providers processing customer-controlled Personal Data are governed by the DPA and our subprocessor list. Brade does not sell Personal Data for monetary consideration or use Customer Data for cross-context behavioral advertising.
Cookies and analytics
The Services use essential storage technologies for authentication, security, load balancing, and preference management. These technologies are necessary to provide requested functionality.
We use optional analytics technologies, including Google Analytics where configured, to understand page and feature usage. We do not initialize optional analytics until the user has made an affirmative choice to accept them. Rejecting optional analytics does not prevent use of the core Services. You can withdraw or change your choice through the cookie banner, the public site's Privacy choices control, or the Privacy section of application settings.
Brade does not currently use session replay technology. If that changes, we will update this notice and obtain any consent required before enabling it.
Retention and deletion
We retain each category of Personal Data only for as long as reasonably necessary for the purpose for which it was collected, to provide the Services, to follow customer instructions, to meet contractual or legal requirements, or to establish, exercise, or defend legal claims. The applicable period depends on the nature and sensitivity of the data, the customer's configuration and contract, security needs, and legal obligations.
- Customer content is generally retained for the customer relationship and deleted or returned as described in the DPA and applicable agreement.
- Mailbox authorization data is retained while the connection is active and is revoked or deleted when the connection or account is removed, subject to operational recovery periods.
- Account and relationship records are retained while the account or relationship is active and afterward where needed for security, dispute resolution, or legal compliance.
- Security, audit, and application records are retained according to operational and security needs and any applicable customer commitments.
- Billing and transaction records are retained for applicable tax, accounting, and legal periods.
- Backups are overwritten or deleted according to the relevant backup lifecycle.
Deletion from active systems may not immediately remove information from encrypted backups. Data in a backup is not restored except for continuity or recovery and remains subject to access controls until the backup is overwritten or deleted.
Security
We use administrative, technical, and organizational safeguards designed to protect Personal Data, including access controls, encryption in transit and at rest where supported, secrets management, logging, monitoring, backups, and incident-response procedures. No security measure can eliminate all risk, and we cannot guarantee absolute security.
Children
The Services are intended for business use and are not directed to children under 18. We do not knowingly collect Personal Data directly from children under 18. Contact us if you believe a child has provided Personal Data to Brade without appropriate authorization.
Privacy rights
Depending on your location and Brade's role, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of Personal Data, withdraw consent where processing is based on consent, and complain to a supervisory authority. These rights may be subject to exceptions and identity verification.
If Brade processes your Personal Data for a customer, submit your request to that customer first. We assist customers with verified requests as required by the DPA. For Personal Data controlled by Brade, contact privacy@brade.ai. We will respond within the period required by applicable law.
United States state privacy laws
Where an applicable U.S. state privacy law covers Brade's processing, residents may have additional rights, which can include confirming processing, access, correction, deletion, portability, and opting out of covered sales, sharing, targeted advertising, or certain profiling. Brade will provide any additional notices or controls required where those obligations apply.
EEA, UK, and Swiss rights
Residents of the European Economic Area, including Liechtenstein, Norway, and Iceland, the United Kingdom, and Switzerland may exercise applicable data-protection rights and may complain to their local supervisory authority. When Brade relies on legitimate interests, you may object to that processing as provided by applicable law.
International transfers
The Services' primary infrastructure, including application hosting and the database used to store Personal Data, is located in the European Union. Brade and its service providers may transfer Personal Data to the United States, the United Kingdom, and other countries outside the European Economic Area, the United Kingdom, or Switzerland. Where required, we use an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism.
Contact
Questions and privacy requests can be submitted to:
- Email: privacy@brade.ai
- Address: Collaborative Intelligence, Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States