This policy explains how personal data is handled in Brucely. It covers two roles:
- Controller: for account and billing data of the people who sign up for and pay for Brucely, and for the website, Brucely (demo entity) is the controller.
- Processor: for data that an organisation (for example a gym or fitness provider) puts into Brucely about its instructors and staff, that organisation is the controller and we process the data on its behalf (see the DPA). Please contact that organisation first about this data.
Data we process
- Account data: name, email address, password (stored only as a secure hash), language, login times.
- Work data entered by organisations: schedules, sessions and attendance, locations, pay rates and payment calculations, tax settings (for example VAT/retention status and tax ID), team membership.
- Billing data for paying organisations: billing email, plan, payment status, invoices (card details are handled by Stripe and never reach us).
- Technical data: IP address and device information in security logs and the audit trail, and push notification tokens if you use the mobile app.
Purposes and legal bases
- Providing the Service and your account: performance of a contract (Art. 6(1)(b) GDPR).
- Billing and keeping accounting records: legal obligation (Art. 6(1)(c)).
- Security, fraud prevention and the audit trail that makes changes attributable: legitimate interests (Art. 6(1)(f)).
- Service emails (password resets, schedule changes, billing notices): contract and legitimate interests. You can turn off schedule-change emails under My account.
Recipients and sub-processors
We use: Stripe (payments), an email delivery provider (transactional email), Expo (mobile push notifications, only if you use the app), and our hosting and database provider. We list them, with their locations, on request. Transfers outside the EEA rely on adequacy decisions or Standard Contractual Clauses.
Retention
Account data is kept while you have access to at least one organisation. Organisation data is kept until the organisation deletes it or closes, then deleted within 30 days. Billing records are kept for the period required by tax law (in Portugal, 10 years). Audit records follow the organisation's data. Notifications are deleted after 180 days.
Your rights
You can access, correct, export and ask for erasure of your personal data, and object to or restrict some processing. In the app, My account lets you download your data and request erasure. Erasure anonymises your profile: records the organisation must keep for accounting (such as sessions it paid for) stay, but no longer identify you. You can also complain to your data protection authority (in Portugal, the CNPD).
Contact
Data protection contact: angryventures@gmail.com.