NewSocial Smart

Privacy Policy

Last updated May 2026

At a glance

This policy explains, in plain English, what personal data Bricksmart collects, why we collect it, how we use it and what rights you have over it. It applies whenever you use the Bricksmart website, sign up for an account, or interact with our outreach, chat or letter services.

The data controller is Subfocus Technologies Ltd, a company registered in England and Wales (number 14775280) with its registered office at c/o Savvy Accountancy, Kenward House, High Street, Hartley Wintney, Hampshire, RG27 8NY. You can reach us about anything in this policy at info@bricksmart.ai.

We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

What we collect and why

We try to collect only the data we need to run Bricksmart well. Below is a summary of what we hold, where it comes from, and the lawful basis on which we use it.

Account data

Your name, email address, login identifiers, organisation name (if you give us one), role, and any settings you save in your profile. We use this to keep you logged in, to provide the service you have signed up for, and to communicate with you about your account. Lawful basis: performance of our contract with you, and our legitimate interests in running the Platform securely.

Authentication data

When you sign in with Google or another OAuth provider, we receive your name and email from that provider; we do not receive your password. If you sign in by email link, we generate a one-time token tied to your email and discard it once used. Lawful basis: performance of our contract; legitimate interests in providing a passwordless sign-in option.

Payment data

Stripe handles all card details on our behalf. We never see or store your full card number. We do retain a record of the transaction (amount, date, plan, last four digits, country) and a Stripe customer ID so we can match payments to your account. Lawful basis: performance of our contract; compliance with our legal obligations (for example tax and accounting law).

Usage data

Information about how you use the Platform — which pages you visit, which searches and lookups you run, which features you click, what filters you set, how long you spend, and any errors the Platform throws. This is collected through a third-party product-analytics provider and a small amount of first-party logging. Lawful basis: legitimate interests in understanding and improving the Platform, with consent for non-essential analytics where required.

Device and network data

Standard metadata your browser sends with each request — IP address, user agent, language, referrer, device type, timestamps. We use this for security, abuse detection, fraud prevention (including automated bot detection) and basic service operation. Lawful basis: legitimate interests in keeping the Platform secure.

LinkedIn lookup data

When you join the waitlist or create an account, we may look up your publicly-available LinkedIn profile to understand who we are onboarding and help us decide which features and support to prioritise for your account. Where we find a match, we record the profile URL (slug) against your account and may store a short note for our internal team — for example, that the match looked confident, or that we were unsure. You can ask us to remove this link at any time. We do not share your LinkedIn information with other users or with third parties. Lawful basis: legitimate interests in qualifying users and tailoring the onboarding experience.

Communications

Any message you send us through the in-app feedback widget, chat, email or support form, together with our replies. We keep these so we can answer you and improve the product. Lawful basis: legitimate interests in supporting users; or performance of our contract where you are a subscriber.

Chat inputs and outputs

When you use the AI chat, the prompts you send and the responses we return are stored against your account so you can return to them later, and may be sent in the moment to the LLM provider that generates the response. We do not use your chat content to train any model. Lawful basis: performance of our contract; legitimate interests in product analytics where you have not opted out.

Outreach data

If you use our letter-sending feature, the recipient address, the rendered letter content, and the delivery status are stored against your account and passed to a third-party print-and-post provider so the letter can be produced and dispatched. Lawful basis: performance of our contract with you. Where you are using the data of an identifiable individual in outreach, you are responsible for ensuring you have your own lawful basis for that processing.

Where the data comes from

Most of the personal data we hold about you comes directly from you — when you sign up, fill in your profile, or use the Platform. A small amount comes from third-party sign-in providers (where you choose to use one) and from our payments and analytics suppliers listed below.

Note that Bricksmart shows public-record information about other people — for example named officers and persons with significant control of UK companies — drawn from Companies House and similar public registers. That information is published by the relevant authority under its own legal basis; we re-display it as a research tool. If you are the data subject of that public-record information and want to discuss how it appears on Bricksmart, please contact us.

Who we share data with

We use a small number of carefully chosen processors to run the Platform. We have contracts with each that meet UK GDPR requirements. Today these include:

  • Vercel — hosting, edge networking, bot mitigation, logs.
  • Supabase — authentication and primary database.
  • Stripe — payment processing.
  • Product analytics provider — usage analytics and feature flags.
  • Print & post provider — printing and posting outreach letters.
  • Sandboxed compute provider — isolated code execution for the financial modelling tool.
  • LLM providers — the models that power the AI chat and analysis. The current provider and its data-handling commitments are listed inside the chat settings.

We may also share data with our professional advisers, with the authorities where we are legally required to, and with a buyer (or their advisers) if Bricksmart or any of its assets are ever sold, merged or restructured. In that case the buyer would be required to honour the commitments in this policy.

We do not sell your personal data.

Where data is stored

We host the Platform primarily in the UK and EU. Some of our processors — for example LLM providers and parts of Vercel’s edge network — process data in other regions, including the United States. Where personal data leaves the UK we rely on the UK’s adequacy decisions or on standard contractual clauses, and we require similar safeguards through our contracts with those processors.

How long we keep data

We keep account data for as long as your account is open, and for a reasonable wind-down period after closure so you can reopen the account or retrieve saved work if you change your mind. After that we delete or anonymise it.

Certain records — such as transaction history, invoices and security logs — we keep for longer to comply with tax, accounting and security obligations. Chat history is retained against your account until you delete it; once deleted we make reasonable efforts to remove it from primary storage promptly, with short-lived copies persisting only in routine backups before being aged out.

Security

We follow practices appropriate to a modern SaaS platform — including HTTPS everywhere, secret rotation, secrets stored in managed vaults rather than code, signed and rate-limited internal APIs, bot detection, and least-privilege database access. No system is unbreakable; you should not send us anything via the Platform, chat or email that you would not be comfortable having compromised in a worst-case incident, particularly sensitive special-category personal data.

If we discover a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and tell you without undue delay.

Your rights

Under UK GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data deleted, where there is no overriding lawful basis for us to keep it;
  • restrict or object to certain processing;
  • receive your data in a portable format; and
  • withdraw any consent you have given us, without affecting the lawfulness of processing done before withdrawal.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data-protection regulator, if you think we have not handled your data properly. We would always prefer the chance to put things right first, so please tell us at info@bricksmart.ai before going to the ICO if you can.

To exercise any of these rights, email info@bricksmart.ai from the address on your account. We may ask for proof of identity for requests where we cannot easily verify you from the account itself.

Marketing

We may email you about new features, important product changes and related material. You can unsubscribe at any time from the link in the footer of any marketing email, or by emailing us. Operational and account messages (billing alerts, security notices, legal notifications) sit outside of marketing preferences and continue for as long as your account is active.

Changes to this policy

We will post any update to this policy on this page and bump the “Last updated” date at the top. Where the changes are material we will also email account holders.

Contact

Questions about this policy or the data we hold should go to info@bricksmart.ai.