Data Processing
Last updated: September 2026
This document reflects GoBrise LLC's current practices as an early-stage company and has not yet been reviewed by outside legal counsel. It will be formally reviewed and may be updated before general availability.
1. Purpose of this page
This page describes how GoBrise LLC, registered in Wyoming, United States (“GoBrise”, “we”, “us”), processes personal data on behalf of the businesses that use the GoBrise platform (“customers”). It is written for customers reviewing us as a vendor — it is not aimed at end visitors, whose privacy relationship is primarily with the business whose website they are visiting.
2. Controller and processor roles
For end-visitor data collected through a customer's chat widget — including conversation content — the customer is the data controller: it decides what data is collected, why, and how long it is kept. GoBrise LLC acts as a data processor, handling that data only to provide the Service and in accordance with the customer's configuration and instructions.
For the customer's own account data (registration details, billing, team member profiles), GoBrise LLC acts as the data controller, as described in our Privacy Policy.
3. Data we process on the customer's behalf
In the processor role, we handle:
- Visitor conversations — messages, timestamps and related session metadata exchanged through the customer's widget
- Knowledge base content — documents, pages and text the customer uploads so the AI agent can answer from them
- Operational metadata — the logs and identifiers needed to deliver, secure and troubleshoot the Service
4. Sub-processors
We engage a small number of sub-processors to operate the Service, principally a cloud hosting and database provider (which stores account, conversation and knowledge base data) and an AI language model provider (which processes message content solely to generate responses, subject to its own data processing terms).
Because our providers may change as the Service evolves, we describe them here by function rather than by name. Customers with a compliance requirement to approve specific sub-processors should contact us — we will confirm the current providers in writing as part of an Enterprise review.
5. Data location
Customer data is hosted on managed cloud infrastructure. At this early stage we host data on infrastructure located in the United States, and additional regions may be added over time as the Service grows.
If your organisation requires data residency in a specific region, raise it with us before committing — we would rather tell you what is possible today than imply otherwise.
6. Security measures
The measures that protect customer data are described in detail on our Security & Trust page. In summary: every record is scoped to the customer that owns it, access rules are enforced in the database itself rather than only in the application, dashboard queries run with the signed-in user's own permissions, and widget traffic can only reach the single business its widget key belongs to.
We do not currently hold formal certifications such as SOC 2 or ISO 27001, and we do not claim otherwise; the Security & Trust page states plainly which controls are on the Enterprise roadmap.
7. Customer responsibilities
As the data controller, each customer is responsible for:
- Ensuring it has a lawful basis to collect and process the visitor data its widget gathers
- Not uploading unlawful content, or content it does not have the rights to use, to its knowledge base
- Informing its own visitors about the chat and AI processing as required by applicable law
- Configuring retention and deletion in line with its own privacy commitments
8. International data transfers
Because data is hosted in the United States, personal data of EU/EEA or UK data subjects may be transferred outside those regions. Where the GDPR or UK GDPR applies to such transfers, we rely on appropriate safeguards — such as standard contractual clauses — and will put them in place with customers who require them.
9. Data processing agreements and enterprise requests
Customers that need a signed Data Processing Agreement, a list of current sub-processors, or answers to a vendor security questionnaire should contact us through our Contact page. These requests are handled the same way as other Enterprise enquiries — directly, in writing, with no self-serve form to get lost in.
Need a DPA or vendor review?
Contact us about data processing agreements, sub-processors, or anything your compliance review needs documented.