Privacy Policy

Last updated

28 February 2026

This Privacy Policy explains how NTPC Consult ApS (the “Company”, “we”, “us”, “our”) collects, uses, and protects personal data in connection with Brief PE (the “Service”). It forms part of, and should be read alongside, our Terms of Service.

Data controller: NTPC Consult ApS (Denmark)

CVR: DK41761210

Website: briefpe.com

Privacy contact: hello@briefpe.com


1. What Personal Data We Collect

We collect personal data necessary to operate the Service, such as name, email, company/organization affiliation (if provided), and usage data (e.g., feature usage and diagnostic logs). Subscription and payment details are processed primarily by our payment processor, Polar.sh; we may receive limited billing metadata (e.g., subscription status, invoice identifiers) for account administration.

2. How We Use Personal Data

We use personal data to (a) create and administer accounts, (b) deliver the Service and weekly digest emails, (c) provide customer support, (d) manage subscriptions and billing, (e) secure, maintain, and improve the Service (including analytics and troubleshooting), and (f) comply with legal obligations and enforce our Terms of Service.

3. Storage and Processors

We store and process data using hosted infrastructure, including Azure, which also serves as our authentication identity provider. We also use service providers as processors/sub-processors to run and deliver the Service, including Polar.sh (payments and billing as merchant-of-record), and Kimi (AI processing). We may also use third-party data providers (currently including Perplexity and Coresignal) to fetch or enrich company-level data.

AI processing and model training. We use AI providers to generate summaries and related outputs. We do not use Customer Data (such as your tracked company lists and configurations) to train general-purpose public AI models, except to the extent a third-party provider processes data as a processor to provide the Service. Where possible, we configure providers and systems to reduce unnecessary retention and to align with contractual and legal requirements.

Security. We implement reasonable technical and organizational measures designed to protect personal data. Such measures may include access controls and encryption in transit where appropriate. No method of transmission or storage is 100% secure, and you acknowledge that security risks cannot be eliminated entirely.

4. No Sale of Personal Data

We do not sell personal data to third parties. We may share personal data only with (a) our processors/sub-processors to provide the Service, (b) professional advisers and authorities where required by law, and (c) parties to a corporate transaction (e.g., merger or sale of assets) subject to applicable law.

5. Cookies and Tracking

We use minimal, functional cookies or similar technologies (for example, to maintain sessions and security). We do not use third-party advertising cookies on the Service at this time.

6. Retention and Deletion

We retain personal data for as long as needed to provide the Service and for legitimate business purposes (e.g., security and recordkeeping), and longer where required by law (such as accounting records). You may request account deletion by emailing hello@briefpe.com. We will delete or anonymize personal data where reasonably possible, subject to legal retention requirements.

What is erased upon account deletion. When an account deletion is confirmed, we erase: your user account and profile information, your Azure authentication identity, your tracked company lists and configurations, your BriefZone weekly summaries, and other app-generated data tied to your account.

What is retained (anonymized) for audit and compliance. We retain anonymized billing records — including subscription history, transaction records, webhook event logs, and reconciliation audit logs — with the user link (user ID) removed and any duplicated personal information (such as email) cleared. These records are retained for financial audit, tax compliance, and dispute resolution purposes as required by law and by our obligations to our payment processor (Polar.sh).

7. GDPR

NTPC Consult ApS is a Danish company and EU data protection law (including GDPR) applies where relevant. We process personal data based on one or more lawful bases, including performance of a contract (providing the Service), legitimate interests (operating and improving the Service), legal obligations, and consent where required. Depending on applicable law, you may have rights to access, rectify, erase, restrict processing of, or object to processing of your personal data, and to data portability. You may also lodge a complaint with your supervisory authority.

Right to erasure. You may exercise your right to erasure by requesting account deletion (see Section 6 above). Upon confirmed deletion, we erase your personal data from our application database and from our authentication provider (Azure). Anonymized billing records are retained as described in Section 6 under the lawful basis of legal obligation (financial record-keeping requirements). Polar.sh, as our payment processor and merchant-of-record, may independently retain transaction records in accordance with their own privacy policy and legal obligations.

An unhandled error has occurred. Reload 🗙

Connection Interrupted

Your current session is still open. We'll keep trying to restore it.

Rejoining the server...

Rejoin failed. Trying again in s.

Failed to rejoin. Retry now or reload the page.

The session has been paused by the server.

Failed to resume the session. Retry now or reload the page.