Privacy Policy
Last updated: April 2026
Who are we?
Bremedy is a Dutch company that helps organisations build their own AI system based on their own data and knowledge. We are the data controller for personal data we process via this website and our platform.
Bremedy
Nederland
info@bremedy.nl
What data do we process?
We only process data that is strictly necessary for our services.
| Situation | Data | Purpose |
|---|---|---|
| Contact form | Name, email address, company name, message | Answering your question or request |
| Portal (login) | Email address, name, role, project | Authentication and access management |
| Portal (uploads) | Files you upload | Processing and storing in your knowledge base |
| Intake | Company name, description, technical questions | Preparing a suitable offer |
We do not process special categories of personal data (such as health data, political views or biometric data) unless a client uploads these themselves as part of their own data. In that case this falls under the data processing agreement with the client.
What is our legal basis?
- Contact form — legitimate interest (Art. 6(1)(f) GDPR): we have a legitimate interest in responding to enquiries from potential clients.
- Portal & intake — performance of a contract (Art. 6(1)(b) GDPR): processing is necessary to deliver our services.
How long do we retain your data?
- Contact messages — maximum 12 months after receipt, unless an active client relationship arises.
- Portal accounts — as long as the account is active. After termination of service we delete the account within 30 days.
- Uploads & knowledge base — for the duration of the agreement with the client. After termination all data is deleted in accordance with the data processing agreement.
Do we share your data?
We never sell or rent your personal data to third parties. We only share data in the following situations:
- With processors who provide services on our behalf (e.g. server hosting), solely on the basis of a data processing agreement.
- If we are legally required to provide data to authorities.
Our servers are located in the European Union (Frankfurt, Germany). No transfer of personal data outside the EEA takes place.
How do we protect your data?
We take technical and organisational measures to protect your data:
- Encrypted connection (HTTPS/TLS) for all communications
- Passwords are stored encrypted with PBKDF2-SHA256 (260,000 iterations)
- Sessions expire automatically after 7 days
- Access to the portal is strictly based on email address and password
- Data is stored locally on our own server — not with third-party cloud providers
Your rights
Under the GDPR you have the following rights:
- Access — you can request which data we hold about you.
- Rectification — you can have incorrect data corrected.
- Erasure — you can request your data be deleted, to the extent permitted by law.
- Restriction — you can have processing temporarily restricted.
- Objection — you can object to processing based on legitimate interest.
- Lodge a complaint — you always have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
To submit a request, send an email to info@bremedy.nl. We respond within 30 days.
Cookies
We only use a strictly necessary session cookie (bremedy_sessie). This cookie contains an encrypted authentication token and is solely necessary for the portal to function. The cookie is httpOnly, contains no tracking data and is not shared with third parties.
We do not use analytical cookies, advertising cookies or social media trackers. Therefore no cookie banner is required.
Questions or requests?
For questions about this privacy policy or your data you can contact us via:
Bremedy
info@bremedy.nl
The Netherlands
This privacy policy may be updated when our services change. We always display the date of the last update at the top of the page.
