Privacy Policy
Effective date: 3 August 2026
This Privacy Policy explains how BrainCore ("BrainCore", "we", "us") collects, uses, and protects personal data. BrainCore is a multi-tenant business operations platform, available at brain-core.ai, used by companies ("tenants") to run their operations — including bookings, invoicing, customer communication, and management of their own accounts on third-party platforms.
1. Who we are
The BrainCore platform is operated by Ride & Drive Sweden AB, org. no. 559083-7430, a company registered in Sweden ("the controller"). For personal data described in this policy that we process for our own purposes — such as your platform account and usage data — Ride & Drive Sweden AB is the data controller within the meaning of the EU General Data Protection Regulation (GDPR).
For business data that a tenant company stores or processes in the platform (for example a tenant’s customer records, bookings, or messages), the tenant company is the data controller and we act as a data processor on that tenant’s documented instructions.
Privacy contact: johan.windzer@oceangroup.se
2. What data we process
- Account data — name, email address, login credentials, profile information, language preference, and role/permission settings for users of the platform.
- Tenant business data — data that tenant companies enter into or connect to the platform in the course of their business, such as customer and guest records, bookings and reservations, invoices, documents, and communications. We process this data on behalf of, and under the instructions of, the tenant that owns it. It is never shared between tenants.
- Usage and log data — technical information generated when you use the platform, such as IP address, browser and device information, timestamps, and actions performed. We use this for security, troubleshooting, and reliability of the service.
- Connected platform data — data received from third-party platforms (Meta, Google, LinkedIn, TikTok) when a tenant chooses to connect its own accounts. See section 4.
3. Purposes and legal bases
We process personal data for the following purposes and on the following legal bases under Article 6 GDPR:
- Providing and operating the platform, including authentication, tenant workspaces, and the features tenants use — performance of a contract (Art. 6(1)(b)).
- Security, abuse prevention, monitoring, and troubleshooting — our legitimate interest in keeping the service safe and reliable (Art. 6(1)(f)).
- Complying with legal obligations, such as bookkeeping and tax requirements under Swedish law — legal obligation (Art. 6(1)(c)).
- Service-related communication, such as important notices about your account or changes to the service — performance of a contract and legitimate interest (Art. 6(1)(b) and (f)).
- Where a specific feature requires it, consent (Art. 6(1)(a)), which you may withdraw at any time with effect for the future.
We do not sell personal data, and we do not use personal data for third-party advertising.
4. Third-party platform data
Tenants can connect their own accounts on third-party platforms to BrainCore in order to manage their own presence and communications from one place. The following principles apply to all such connections: data received from a connected platform is used solely to provide the connected tenant with the functionality it requested; it is never sold; it is never used for advertising purposes; it is never shared with other tenants or unrelated third parties; access tokens are stored encrypted; and connected platform data is deleted when the tenant disconnects the integration or deletes its account. See also our Data Deletion page at brain-core.ai/en/data-deletion.
4.1 Meta Platform Data (Facebook and Instagram)
When a tenant connects a Facebook Page or Instagram professional account, we access Meta Platform Data — such as page and account details, posts, comments, messages, and insights — solely to enable that tenant to manage its own pages, content, and audience interactions through BrainCore. We do not sell Meta Platform Data, we do not use it for advertising or ad targeting, we do not use it to build profiles unrelated to the tenant’s own account management, and we never share it across tenants. Meta Platform Data is retained only while the connection is active and is deleted when the tenant disconnects the integration, deletes its account, or requests deletion.
4.2 Google API Services
BrainCore’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Where a tenant connects a Google account (for example Gmail), the data received is used only to provide the tenant with the features it requested — such as sending and managing email from the tenant’s own account. Google user data is not used for advertising. It is not read by humans, except with the user’s explicit consent, where necessary for security purposes (such as investigating abuse), or where required to comply with applicable law. It is not transferred to third parties except as necessary to provide the requested feature, for security purposes, or to comply with applicable law.
4.3 LinkedIn
When a tenant connects a LinkedIn account or organization page, data received from LinkedIn is used solely to enable that tenant to manage its own LinkedIn presence — such as creating and managing its own posts and page content. It is not used for advertising, is never shared across tenants, and is deleted when the connection is removed.
4.4 TikTok
When a tenant connects a TikTok account, data received from TikTok is used solely to enable that tenant to manage its own TikTok account and content. It is not used for advertising, is never shared across tenants, and is deleted when the connection is removed.
5. Subprocessors
We use a small number of service providers (subprocessors) to operate the platform. Each processes data only as necessary to provide its service to us and under a data processing agreement:
- Amazon Web Services (AWS) — cloud hosting and storage, EU region.
- Anthropic — AI-assisted processing of content within the platform.
- Google Cloud — cloud infrastructure services.
- Stripe — payment processing.
- Resend — transactional email delivery.
6. Data retention
We keep account data for as long as the account is active. Tenant business data is retained according to the instructions of the tenant that controls it. Data connected from third-party platforms is deleted when the integration is disconnected, as described in section 4. Some data must be retained for longer periods where the law requires it — for example accounting records under Swedish bookkeeping law. Log data is kept only for a limited period needed for security and troubleshooting. When data is no longer needed, it is deleted or anonymized.
7. International transfers
The platform is hosted in the European Union. Where a subprocessor processes personal data outside the EU/EEA, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission’s Standard Contractual Clauses (SCCs), together with supplementary measures where applicable.
8. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Have inaccurate data rectified.
- Have your data erased ("right to be forgotten").
- Restrict or object to certain processing.
- Receive your data in a portable format (data portability).
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights, contact us at johan.windzer@oceangroup.se. If the data in question is controlled by a tenant company (see section 1), we will refer your request to that tenant or assist them in responding. You also have the right to lodge a complaint with the Swedish supervisory authority, IMY — Integritetsskyddsmyndigheten (www.imy.se), or with the supervisory authority in your country of residence.
9. Cookies
BrainCore uses only a minimal set of functional cookies: cookies required to keep you signed in (session/authentication) and to remember preferences such as your language. We do not use third-party advertising or tracking cookies.
10. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on this page, together with its effective date. If a change materially affects how your personal data is processed, we will inform affected users through the platform or by email.
11. Contact
For any questions about this Privacy Policy or how we handle personal data, contact: Ride & Drive Sweden AB, org. no. 559083-7430, Sweden — johan.windzer@oceangroup.se.