Open Brain
  • Home
  • Workspace
  • Capabilities
  • Brain
  • Models
  • Pricing
Meridian
Legal

Data Compliance

Last updated: 26 May 2026  ·  GDPR · CCPA/CPRA · India DPDP Act 2023

Terms of Use Privacy Policy IP Infringement Data Compliance

Table of Contents

  1. Controller & Processor Roles
  2. Data Categories
  3. Lawful Bases (GDPR Art. 6)
  4. Retention Windows
  5. Sub-Processors
  6. International Transfers
  7. GDPR Rights (Art. 15–22)
  8. CCPA / CPRA Rights
  9. Security Controls
  10. Breach Notification
  11. Children & Sensitive Categories
  12. DPO & Contact

This page provides the operational compliance details that auditors, data protection officers (DPOs), enterprise procurement teams, and regulators ask for. It supplements our Privacy Policy and is binding as part of our overall privacy framework.

1. Controller & Processor Roles

PartyRoleScope
Open BrainData ControllerAccount data, usage analytics, billing records, log data, and any personal data collected directly from users through the Service
Open BrainData ProcessorUser prompt content transmitted to third-party AI model providers at user direction
AI Model Providers (Anthropic, OpenAI, Google, xAI, NVIDIA, etc.)Independent Controllers or Sub-processorsProcessing of prompts and responses under their own terms and privacy policies
Infrastructure Sub-processorsData ProcessorsStorage, compute, and delivery of the Service on behalf of Open Brain

Where Open Brain acts as a data processor on behalf of enterprise customers, a Data Processing Agreement (DPA) is available on request at legal@openbrain.ai.

2. Data Categories

CategoryExamplesSource
Identity dataName, email address, username, profile pictureProvided by user at registration or via OAuth
Authentication dataPassword hash, OAuth tokens, session tokens, MFA stateGenerated during account creation and login
Billing dataSubscription tier, billing address, last 4 digits of card (full card numbers processed only by payment processor)Provided at checkout; tokenised by payment processor
Content dataPrompts, AI responses, uploaded files, project rules, workspace settingsSubmitted by user during Service use
Usage dataFeature interactions, models selected, routing decisions, token counts, session duration, click eventsCollected automatically during Service use
Technical dataIP address, browser fingerprint, device type, operating system, timestamps, error logsCollected automatically via server logs and analytics

3. Lawful Bases (GDPR Art. 6)

Processing ActivityLawful BasisArt. 6
Account creation and authenticationPerformance of a contract6(1)(b)
Providing the Service (prompt routing, workspace)Performance of a contract6(1)(b)
Payment processing and billingPerformance of a contract6(1)(b)
Transactional communications (receipts, alerts)Performance of a contract6(1)(b)
Service improvement and analyticsLegitimate interests6(1)(f)
Security monitoring and fraud preventionLegitimate interests6(1)(f)
Marketing and product updatesConsent (with opt-out)6(1)(a)
Tax and financial record-keepingLegal obligation6(1)(c)
Compliance with law enforcement requestsLegal obligation6(1)(c)

A Legitimate Interests Assessment (LIA) for the processing activities listed under 6(1)(f) is available on request at privacy@openbrain.ai.

4. Retention Windows

Data CategoryRetention PeriodDeletion Trigger
Account and identity dataDuration of account + 30 daysAccount deletion request or inactivity termination
Content data (prompts, files)Duration of account + 30 daysAccount deletion or explicit content deletion
Usage and analytics data24 months (aggregated after 12 months)Rolling deletion; aggregated data retained indefinitely
Billing and financial records7 yearsLegal obligation under financial regulations
Server and access logs90 daysRolling deletion
Security incident logs3 yearsRolling deletion after 3 years
Encrypted backups35 daysAutomatic cascade deletion on rolling 35-day schedule

5. Sub-Processors

Sub-ProcessorRoleRegion
Vercel Inc.Hosting, edge network, and deployment infrastructureGlobal (US-based)
Supabase Inc.Database, authentication, and file storageUS / EU (region-selectable)
Stripe Inc.Payment processing and billingUS / EU
Anthropic PBCClaude AI model inference (at user direction)US
OpenAI LLCGPT-4o model inference (at user direction)US
Google LLCGemini model inference (at user direction)US / EU
PostHog Inc.Product analytics and session recording (anonymised)US / EU

All sub-processors are bound by data processing agreements ensuring GDPR-equivalent protections. We will notify enterprise customers of material sub-processor changes with at least 30 days' notice.

6. International Transfers

Open Brain is headquartered in India. Some of our sub-processors are located in the United States and other countries. We rely on the following mechanisms for international transfers from the EEA, UK, and Switzerland:

  • Standard Contractual Clauses (SCCs): We incorporate the EU Commission's 2021 SCCs into our agreements with US-based sub-processors
  • EU–US Data Privacy Framework (DPF): Where sub-processors are certified under the DPF, we rely on this adequacy mechanism
  • UK International Data Transfer Agreements (IDTA): Used for transfers to the UK where applicable
  • India DPDP Act 2023: We comply with the Digital Personal Data Protection Act 2023 for processing of Indian residents' data

Transfer impact assessments (TIAs) are conducted for all cross-border transfers. Copies are available to enterprise customers on request.

7. GDPR Rights (Art. 15–22)

RightArticleHow to Exercise
Right of access — obtain a copy of your personal dataArt. 15Email privacy@openbrain.ai or use account settings
Right to rectification — correct inaccurate dataArt. 16Account settings or email request
Right to erasure ("right to be forgotten")Art. 17Delete account in settings or email request
Right to restriction of processingArt. 18Email request with specific grounds
Right to data portability — export in machine-readable formatArt. 20Account settings → Export data
Right to object to processing based on legitimate interestsArt. 21Email request with specific grounds
Rights related to automated decision-makingArt. 22Email request; we do not make solely automated decisions with legal effects

Response SLA: We will acknowledge rights requests within 5 business days and provide a substantive response within 30 calendar days (extendable to 90 days for complex requests with notice). All rights requests are free of charge.

You have the right to lodge a complaint with your local supervisory authority. EEA users may contact their national data protection authority. UK users may contact the ICO at ico.org.uk.

8. CCPA / CPRA Rights

California residents have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

  • Right to know: Request disclosure of the categories and specific pieces of personal information we have collected
  • Right to delete: Request deletion of your personal information, subject to exceptions
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt out of sale or sharing: We do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may exercise this right by contacting us.
  • Right to limit use of sensitive personal information: We do not use sensitive personal information beyond what is necessary to provide the Service
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights

To exercise CCPA rights, contact privacy@openbrain.ai or use the "Delete my account" option in settings. We will respond within 45 days (extendable to 90 days with notice).

9. Security Controls

We implement the following technical and organisational measures:

  • Encryption in transit: TLS 1.3 for all data in transit; HSTS enforced with 1-year max-age and preload
  • Encryption at rest: AES-256 for all stored data; database-level encryption via sub-processor
  • Access control: Row-level security (RLS) in the database; principle of least privilege for all staff and systems
  • Authentication: JWT-based tokens with short expiry (15 minutes access / 7 day refresh); MFA available for all accounts
  • Secrets management: Environment-isolated secrets storage; no secrets in source code or logs
  • Webhook signing: All outbound webhooks signed with HMAC-SHA256; signatures verified before processing
  • Dependency management: Automated vulnerability scanning on all dependencies; critical patches applied within 24 hours
  • Penetration testing: Annual third-party penetration tests; findings remediated within SLA based on severity
  • Audit logging: Immutable audit logs for all privileged actions with 3-year retention

10. Breach Notification

In the event of a personal data breach, Open Brain will:

  • Notify relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR Art. 33
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34)
  • Notify affected enterprise customers within 48 hours of confirming a breach affecting their users' data
  • Provide a post-incident report within 30 days of resolution detailing the cause, impact, and remediation steps

To report a security vulnerability, contact security@openbrain.ai.

11. Children & Sensitive Categories

The Service is not directed to children under 13 (16 in the EU/UK). We do not knowingly process children's personal data. We do not process special categories of personal data as defined in GDPR Art. 9 (health, biometric, genetic, religious, political, or similar data) and our Terms of Use prohibit users from submitting such data through the Service.

The Service is not designed for use cases regulated by HIPAA (US health data), FERPA (US educational records), or PCI-DSS beyond the standard payment processing handled by our certified payment processor. Enterprise customers with regulated data requirements should contact legal@openbrain.ai before use.

12. DPO & Contact

Data Protection Officer & Privacy Contact

Email: privacy@openbrain.ai
Legal / DPA requests: legal@openbrain.ai
Security / breach reporting: security@openbrain.ai
Response SLA: 5 business days acknowledgement · 30 days substantive response

Open Brain operates under the laws of India. For GDPR Art. 27(2) purposes, EU/EEA residents may contact us directly at the email above. We are evaluating the appointment of a formal EU Representative and will update this page when appointed.

Open Brain

The model-agnostic AI workspace for serious work.

Product
  • Features
  • Pricing
  • Changelog
  • Roadmap
Legal
  • Terms of Use
  • Privacy Policy
  • IP Infringement
  • Data Compliance
Company
  • About Open Brain
  • Blog
  • Careers
  • Contact
  • Instagram

© 2026 Open Brain. All rights reserved.

PrivacyTermsIPCompliance