BrandNavigator – Privacy Notice
1. The Data Controller
Data Controller: Mind Bridge Kft.
Registered address: 13/2 Szegfű Street, Úrhida, 8142, Hungary
Company registration number: 07-09-020559
Tax number: 23384778-1-07
Data protection contact: privacy@brandnavigator.app
Website: brandnavigator.app
The Data Controller has not appointed a Data Protection Officer (DPO), as the current data processing activities do not give rise to a statutory obligation to do so.
2. Scope of this Notice and Our Principles
This notice applies to the brandnavigator.app website and the BrandNavigator SaaS service available thereon.
BrandNavigator is an AI-powered marketing platform that provides, among other features, the creation of brand and marketing profiles, content generation, campaign planning, content calendars, AI assistant functions, social media publishing, email integration and personalised marketing support.
We process personal data only for specified purposes, on an appropriate legal basis, to the extent necessary and for the duration required.
Personal data is:
- not sold;
- not rented;
- not used for selling advertising profiles to third parties;
- used solely for the purposes set out in this notice.
Certain features of the service rely on the APIs of third-party providers. These are described in detail in Section 7.
3. Scope of Data Subjects
BrandNavigator may process the data of the following persons:
- registered users;
- subscribers;
- invited team members;
- newsletter subscribers;
- visitors to the website;
- persons contacting customer support;
- persons whose data is included in content uploaded or provided by the user.
If the User provides or uploads personal data relating to another person, the User is responsible for ensuring that they have an appropriate legal basis for making that data available.
Where the User processes personal data of their own customers or other third parties within BrandNavigator, the User may be the data controller in that regard, and Mind Bridge Kft. may act as data processor in the course of providing the service.
4. What Data Do We Process and for What Purpose?
4.1 Account and Identity Data
To use the service, we may process:
- email address;
- user UUID;
- registration timestamp;
- last activity timestamp;
- subscription plan;
- subscription status;
- Stripe customer and subscription identifiers;
- entitlement and credit data.
Purpose: registration, Magic Link-based login, user identification, account management, provision of subscription entitlements.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
4.2 Profile, Brand and Marketing Data
The User may provide, among other things, the following data:
- name or company name;
- industry;
- niche or area of expertise;
- target audience;
- communication style;
- brand personality;
- brand strategy;
- marketing strategy;
- buyer persona data;
- marketing goals;
- challenges;
- platform preferences;
- website URL;
- logo, images and other uploaded files;
- text content of uploaded documents.
Purpose: personalisation of BrandNavigator services, AI-based content and strategy creation.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
Where the User provides a website URL for analysis purposes, BrandNavigator may analyse the publicly accessible website in order to fulfil the function initiated by the User.
4.3 Generated Content and Workflows
The following may be created and stored in BrandNavigator:
- AI-generated posts;
- campaigns and campaign plans;
- lead magnet content;
- brainstorm results;
- AI chat and Navigator history;
- content calendar entries;
- topics and topic trees;
- project and cockpit data;
- marketing strategy outputs;
- generated images and image prompts.
Purpose: provision of the service, accessing and further developing previous work.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
4.4 Learning Loop, Personalisation and Behavioural Data
BrandNavigator may process certain usage and feedback data for the purpose of personalising and improving the service. Such data may include:
- which modules and features the User used;
- positive or negative feedback on generated content;
- saving content to the calendar;
- copying content, requesting regeneration, or significant editing;
- channel, content type, hook or topic used;
- daily active days, streak and gamification data;
- completed challenges and credit usage.
The Learning Loop may use these signals to build a personalisation profile — referred to as a marketing fingerprint — regarding the User's content and communication preferences. We use this exclusively to generate more relevant content, personalise AI responses, recommend relevant next steps, improve onboarding and the user experience, and develop the service.
The memory created by the Learning Loop can be viewed, deleted or reset in the Settings.
Legal basis:
- for processing necessary for personalisation of the service: GDPR Article 6(1)(b) – performance of a contract;
- for service development, usability and internal statistical purposes: GDPR Article 6(1)(f) – legitimate interest of the Data Controller (improving the operation, usability, security and quality of BrandNavigator).
4.5 Social Media Integrations
At the User's own discretion, the User may connect their BrandNavigator account to a Facebook Page, an Instagram Business account, or a LinkedIn personal profile or company page.
During integration, we may process: OAuth access token; refresh token (where provided by the platform); token expiry information; platform user or page identifier; page or profile name; text, images and associated metadata selected for publishing.
Purpose: social media publishing initiated by the User and maintaining the connection.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
BrandNavigator uses only the permissions authorised by the User and does not publish content without an action or approval initiated by the User. The OAuth connection can be terminated at any time; upon termination or account deletion, stored tokens are deleted. To handle data deletion requests initiated by Meta, BrandNavigator operates a dedicated technical data deletion endpoint.
4.6 Brevo Integration
BrandNavigator may provide email communication features through the Brevo service. If the User connects their own Brevo account, we may process: Brevo API key (stored encrypted); sender email address and name; email content to be sent.
Purpose: provision of email functionality initiated by the User.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
BrandNavigator may also use Brevo to send system messages or — with separate consent — marketing communications. Marketing messages are sent only on the basis of appropriate consent or other applicable legal basis.
4.7 Payment and Subscription
Online payment is processed through Stripe. BrandNavigator does not store full card numbers, CVC/CVV codes or other complete card data. Data that may be transferred to BrandNavigator includes: Stripe customer ID; subscription ID; payment status; transaction identifier; amount paid; currency; subscription plan and status.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
4.8 Invoicing
Invoices are issued using the Számlázz.hu system. For invoicing purposes, we may process: name or company name; billing address; tax number (where required); email address; service description; amount and currency; payment and billing data.
Legal basis: GDPR Article 6(1)(b) – performance of a contract; GDPR Article 6(1)(c) – compliance with a legal obligation.
4.9 Website Analytics and Marketing Measurement
We use Google Analytics 4 to measure usage of brandnavigator.app. The system may process: approximate geographic data derived from IP address; device and browser information; page views; session data; traffic source; conversion events; cookies and other online identifiers.
Legal basis: GDPR Article 6(1)(a) – consent. Google Analytics is activated only after the user has given analytics consent.
BrandNavigator may also use Meta Pixel for marketing and conversion measurement. Meta Pixel is activated only where the feature is technically enabled and the visitor has previously given marketing consent. During operation, event data, browser, device and online identifier data may be transmitted to Meta. Legal basis: GDPR Article 6(1)(a) – consent.
Detailed cookie and tracking information is set out in BrandNavigator's separate Cookie and Storage Policy.
4.10 System Logs and Security Data
BrandNavigator may process system logs for service security, debugging and operation. Logs may contain: timestamp; module or function identifier; operation status; user UUID; AI model or function identifier; technical error data; IP address or technical request data (where necessary for security operations).
Purpose: debugging, incident investigation, abuse prevention, service security.
Legal basis: GDPR Article 6(1)(f) – legitimate interest (secure and reliable operation of the service).
4.11 Team Members and Invitations
Where the subscription plan permits, the User may invite other persons to use BrandNavigator. Data processed: invitee's email address; invitation status; access permission. The email address is received from the inviting User.
Purpose: provision of team functionality.
Legal basis: GDPR Article 6(1)(f) – legitimate interest in operating a service that enables collaborative work.
4.12 Browser-Based Speech Recognition
Browser-based speech recognition may be used in certain text fields. BrandNavigator's own servers do not store raw audio. The resulting text is processed in the same way as manually entered text. The actual technical processing may depend on the browser and operating system; some browsers use their own service for audio processing, subject to that browser provider's data protection terms.
5. Use of Artificial Intelligence
BrandNavigator uses AI APIs for content generation, marketing strategy development, campaign planning, brainstorming, chat functions, image generation and brand profile analysis.
Prompts transmitted to external AI providers may contain: industry and brand data; target audience information; communication style; marketing and campaign data; text entered by the User; text extracted from uploaded documents; relevant parts of previous AI conversations; personalisation context from the Learning Loop.
BrandNavigator currently uses primarily the Google Gemini API and the OpenAI API.
BrandNavigator uses paid/API service arrangements and does not enable optional data sharing that would result in API inputs or outputs being passed for general model training. Under current provider terms, OpenAI API inputs and outputs are not used for model training by default; at the paid API level of Google Gemini, content is not used for developing Google's products.
This does not mean that AI providers perform no technical data retention at all. Providers may carry out limited-duration processing for security, abuse prevention, legal or technical purposes in accordance with their contractual terms.
Please do not provide special category personal data, passwords, card details or other sensitive confidential information unnecessarily when using AI features.
Legal basis: GDPR Article 6(1)(b) – performance of a contract.
6. Cookies, localStorage and Other Browser Storage
6.1 Necessary Storage
Login session, authentication token, security information, consent settings. Without these, basic service functions do not operate properly.
6.2 Functional Storage
Selected language, UI settings, certain cached user data, gamification display settings. Where not strictly necessary, used only in accordance with the relevant consent settings.
6.3 Analytics and Marketing Storage
Google Analytics and Meta Pixel can only operate after prior consent has been given for the respective category. Consent can be withdrawn at any time without affecting the lawfulness of prior processing.
6.4 Locally Hosted Fonts
BrandNavigator serves the Montserrat and Inter typefaces locally as part of its own build, using the @fontsource package. No connection is made to Google Fonts servers and no IP address is transmitted to Google in this regard.
A detailed list of browser storage and tracking technologies is set out in the Cookie and Storage Policy.
7. Recipients, Data Processors and Third-Party Providers
Not every third-party provider qualifies as a data processor for every data processing operation. Some providers act as data processors following the instructions of Mind Bridge Kft., while others may be independent data controllers for their own statutory, security or platform operation purposes. Where required by GDPR Article 28, data processing is carried out on the basis of data processing terms provided by the provider or separately agreed.
7.1 Infrastructure
| Provider | Role | Data / Region |
|---|---|---|
| Rackforest Zrt. rackforest.com | Hosting and related infrastructure | Server traffic, technical log data; Hungary |
| Supabase supabase.com | Database and authentication | Account, profile, content, campaign, integration and other SaaS data; EU (Frankfurt) |
| Vercel Inc. vercel.com | Serverless functions and application infrastructure | API requests and technical request data; United States / global |
| Upstash upstash.com | Rate limiting and short-term state management | User or request identifier and rate-limit information; retained only for the duration of the technical TTL |
7.2 AI Providers
| Provider | Role | Data |
|---|---|---|
| Google ai.google.dev | Gemini AI API, generative AI services | Prompts, brand context, content made available for generation |
| OpenAI openai.com | AI API service | Prompts, brand context, generation inputs and outputs |
7.3 Social Platforms
Meta Platforms Ireland Limited — Facebook and Instagram OAuth, social media publishing; Meta Pixel (marketing and conversion measurement where activated). Meta acts as an independent data controller for further processing on its own platform. A joint controllership situation may also arise under Meta Business Tools terms for certain Pixel operations.
LinkedIn Ireland Unlimited Company — LinkedIn OAuth and social media publishing. LinkedIn acts as an independent data controller for processing on its own platform.
7.4 Email Communication
Brevo SAS (brevo.com) — transactional emails, email features and, with consent, marketing communications. Data: email address, sender data, message content. Country: France / EU.
7.5 Payment and Invoicing
Stripe Payments Europe, Limited / Stripe, Inc. (stripe.com) — online payment and subscription processing. Stripe may also act as an independent data controller for payment, fraud prevention and regulatory purposes.
KBOSS.hu Kft. – Számlázz.hu (szamlazz.hu) — electronic invoicing. Company registration number: 01-09-303201; tax number: 13421739-2-41; registered address: 7 Záhony Street, Budapest 1031, Hungary.
7.6 Analytics and Error Tracking
Google Analytics 4 — web analytics (online identifiers, device and browser data, conversion events); activated only after analytics consent.
Meta Pixel — marketing and conversion measurement (online identifiers, event data); activated only after marketing consent.
Sentry (sentry.io) — error tracking and technical diagnostics (error messages, stack traces, technical request data). BrandNavigator does not knowingly pass user profiles or user IDs to Sentry.
7.7 Content and Search Services
Unsplash — stock photo search. BrandNavigator uses the Unsplash API through a server-side proxy; the API key is not exposed to the User's browser.
Serper.dev — real-time web search results for certain benchmark and research functions. BrandNavigator endeavours to structure searches so they do not contain unnecessary personal data.
8. Transfers Outside the EU and EEA
Some of BrandNavigator's providers may also process data outside the European Economic Area. In such cases, data transfer takes place only on the basis of an appropriate legal mechanism under Chapter V of the GDPR, which may include:
- an adequacy decision by the European Commission;
- the EU–US Data Privacy Framework (where the relevant US provider is duly certified);
- Standard Contractual Clauses (SCCs) adopted by the European Commission;
- or another data transfer mechanism permitted by the GDPR.
Where required, the data processing terms agreed with the provider include appropriate technical and contractual safeguards.
9. Data Retention Periods
We process data only for as long as is necessary for the purpose of processing or as required by law.
| Data category | Retention period |
|---|---|
| Account, profile and brand data | For the duration of the account |
| Generated content, campaigns, calendar, AI chat | For the duration of the account |
| Learning Loop / marketing fingerprint | For the duration of the account or until the memory is reset |
| Identifiable system logs | 7 days, thereafter anonymised |
| Anonymised system logs | Indefinitely (cannot be linked to a natural person) |
| Access token | Maximum 1 hour or until technical expiry |
| Refresh token | Maximum 7 days or until technical expiry |
| Social OAuth token | Until termination of the connection, expiry or account deletion |
| Brevo API key | Until termination of the integration or account deletion |
| GA4 event-level data | Maximum 14 months |
| Invoices and accounting data required by law | 8 years |
9.1 Inactive Accounts
If the User has not logged in for 12 months, we will send an email notification. If no login or account retention statement is made within 30 days of the notification, we may delete the account and associated personal data.
9.2 Subscription Cancellation
Upon cancellation of a paid subscription, we may provide a grace period of up to 90 days during which data can be recovered. After that period, personal data associated with the account will be deleted, except for data whose further retention is required by law.
9.3 Account Deletion
The User may initiate permanent deletion of their account at any time. Upon deletion: the Supabase Auth user is deleted; profile, content, campaign and calendar data are deleted; social OAuth tokens are deleted; system logs linked to the person are anonymised; BrandNavigator data stored in the browser is deleted where technically feasible. Invoices and accounting data required by law cannot be deleted before the mandatory retention period expires.
10. Profiling and Automated Decision-Making
BrandNavigator's Learning Loop may infer preferences from the User's activity and feedback, which may constitute profiling within the meaning of the GDPR. The sole purposes are personalisation of generated content, more relevant recommendations and improvement of the user experience.
BrandNavigator does not make decisions based solely on automated processing that would produce legal effects or similarly significantly affect the User within the meaning of GDPR Article 22. Campaign evaluations, benchmarks, marketing recommendations and AI suggestions are informational only; every decision is made by the User.
11. Mandatory and Optional Data
Providing data necessary for creating an account and providing the service is mandatory. Providing data related to optional features — such as social integration, own Brevo integration, brand documents or website URL — is voluntary. If data required for an optional feature is not provided, that feature may be unavailable or limited, but this does not prevent use of other parts of BrandNavigator.
12. Special Categories of Personal Data
BrandNavigator is a business and marketing service; there is generally no need to provide health data, biometric data, religious or philosophical beliefs, political opinions, data concerning sexual life or sexual orientation, or other special category data within the meaning of GDPR Article 9. Please provide such data only when genuinely necessary and only when you have an appropriate legal basis for doing so.
13. Data Subject Rights
13.1 Right of Access
You may request information about what personal data we process about you and request a copy.
13.2 Right to Rectification
You may correct inaccurate data in the application or request rectification.
13.3 Right to Erasure
You may delete your account via BrandNavigator Settings or send a request to privacy@brandnavigator.app. The right to erasure does not extend to data whose retention is required by law.
13.4 Right to Restriction of Processing
In the cases specified in the GDPR, you may request restriction of the processing of your personal data.
13.5 Right to Data Portability
You can download your available personal data in a structured format via Settings > Export Data. For security reasons, the export does not include OAuth tokens, secret API keys or other access credentials.
13.6 Right to Object
You may object at any time, on grounds relating to your particular situation, to processing based on legitimate interest. Send objections to privacy@brandnavigator.app.
13.7 Withdrawal of Consent
Consent given for consent-based processing may be withdrawn at any time. This does not affect the lawfulness of processing carried out prior to withdrawal.
13.8 Right to Lodge a Complaint and Seek Judicial Remedy
If you believe that the processing of your personal data infringes the GDPR, you may lodge a complaint with the competent supervisory authority.
In Hungary:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
(National Authority for Data Protection and Freedom of Information)
9–11 Falk Miksa Street, Budapest 1055, Hungary
Postal address: P.O. Box 9, Budapest 1363, Hungary
Email: ugyfelszolgalat@naih.hu
Web: naih.hu
You also have the right to seek judicial remedy.
14. Data Security
Mind Bridge Kft. applies appropriate technical and organisational measures to protect personal data. BrandNavigator uses, among other things:
- TLS/HTTPS encryption during data transmission;
- Row Level Security rules in the user database;
- security authentication and session management;
- encryption of sensitive integration secrets and API keys;
- restricted access controls;
- rate limiting and abuse prevention measures;
- signature verification for relevant webhooks;
- logging of security events necessary for system operation;
- regular updates and audits of the technical components of the service.
Security issues can be reported to security@brandnavigator.app.
15. Children's Data
BrandNavigator's services may only be used by persons who have reached the age of 18. We do not knowingly collect account or user data from persons under 18. If we become aware that a person under 18 has registered or provided personal data without authorisation, we will delete that data following the necessary review.
16. Amendments to this Notice
We will update this Privacy Notice as necessary as our services and technologies evolve. In the event of a material change, we will notify the User appropriately — for example, within the application or by email. If a new data processing operation requires consent, it will only commence after the necessary consent has been obtained. The current version is available at all times on the brandnavigator.app website.
17. Contact
Mind Bridge Kft.
13/2 Szegfű Street, Úrhida, 8142, Hungary
Email: privacy@brandnavigator.app
We respond to data subject requests without undue delay, and as a general rule within the one-month deadline prescribed by the GDPR.
