Data Processing & Security Policy
Last updated July 18, 2026
This policy explains how Gulf Stream Tech Group, LLC (“BrytIO,” “we”) handles the data you and your team put into BrytIO to run your business (“Customer Content”): how it’s stored, secured, shared, retained, and deleted. For personal information where we are the controller (your account, billing, and website data), see our Privacy Policy.
You are the controller, we are the processor
Customer Content belongs to you: your contacts, companies, deals, quotes, invoices, payments, shipments, attachments, synced emails and calendar events, and anything else you enter or import. You are the controller of that data; BrytIO is a processor that handles it only on your instructions and to provide the service. You are responsible for having a lawful basis to collect and use the data you put into BrytIO, and for meeting your own privacy obligations to the people it describes.
How we use Customer Content
We process Customer Content only to:
- Provide, maintain, secure, and support the product for you
- Perform the actions you take in the app (create records, send email, sync an integration you connected, generate an AI draft you requested)
- Prevent fraud, abuse, and security incidents
- Comply with law
We do not sell or rent your Customer Content, use it for advertising, or use it to train AI models, yours or anyone else’s. We access it only as needed to operate the service, support you (with your authorization), or comply with law.
Where your data lives
Customer Content is hosted on DigitalOcean infrastructure in the United States, in a database managed by BrytIO. File attachments are stored in Cloudflare R2 object storage.
Sub-processors
We use the following sub-processors to provide the service. Each is bound by contract to protect your data and use it only to provide their service to us. An integration is only active if you connect it.
| Sub-processor | Role | When it applies |
|---|---|---|
| DigitalOcean | Hosting, compute, and database | Always |
| Cloudflare | CDN, edge security, and file storage | Always |
| Clerk | Authentication and identity | Always |
| Stripe | Subscription billing; payments via Stripe Connect | Always (billing); Connect when you collect payments |
| Anthropic (Claude) | AI assistant, drafting, and quote features | When you use AI features |
| Resend | Sending and logging email | When you send or log email |
| Sentry | Error monitoring and diagnostics | Always |
| Microsoft | Microsoft 365 mail and calendar sync | When you connect it |
| Intuit (QuickBooks Online) | Accounting sync | When you connect it |
| Shippo | Shipping labels and carrier tracking | When you create shipments |
We will give notice before a new sub-processor starts processing Customer Content, so you have a chance to object.
Security measures
- Encryption in transit (TLS) for all connections
- Encryption at rest for sensitive credentials and integration tokens
- Strict tenant isolation: every record is scoped to your workspace
- Role-based access controls, and least-privilege internal access to production
- Optional two-factor authentication for account sign-in
- Auditing and monitoring of application activity and errors
- Secure development practices, including code review and automated checks before changes ship
No system is perfectly secure, and we continually work to strengthen these measures.
AI processing of Customer Content
When you use an AI feature, we send the specific content and context needed for that request to Anthropic (Claude) to generate your result. This data is used only to produce the response, is not used to train models, and is not retained by the provider for training. AI features run only when you invoke them and only on plans that include them.
Retention and deletion
- While active: we retain Customer Content for as long as your workspace is active so the product works.
- Export anytime: you can export your data from the product whenever you want.
- Deletion: when you delete a record it is removed from active systems; when you delete or close your workspace, we delete Customer Content from production systems within a reasonable period (and subsequently from backups), except where retention is legally required.
Breach notification
If we become aware of a security incident affecting your Customer Content, we will notify you without undue delay, describe what we know, and tell you what we’re doing about it.
Your responsibilities
- Ensure you have the right and a lawful basis to collect, upload, and process the data you put into BrytIO
- Provide any notices and obtain any consents your own customers require
- Keep your credentials secure and manage your team’s access
Data Processing Agreement
If you require a signed Data Processing Agreement with this sub-processor list as an annex, contact privacy@brytio.com and we will provide one.
Contact
Data and security questions: privacy@brytio.com.