BrikPlan

Privacy policy

Last updated:

BrikPlan helps you keep your building budget, quotes and invoices in one place, together with your architect and the people you invite. To do that we process personal data about you, and about the people who appear in your project.

Below you will find what we collect, why we collect it, who we share it with, how long we keep it and what rights you have. We keep it concrete: where something is stored, with which supplier, and for how long.

1. Who we are

BrikPlan is a service of Habex Sven BV. We are the controller for the personal data processed through this website and the application.

  • Company: Habex Sven BV
  • Company number: 1014.245.559 (VAT BE 1014.245.559)
  • Address: Sint-Landradastraat 4/11, 3740 Bilzen-Hoeselt, Belgium
  • Email: [email protected]

We have not appointed a data protection officer. For an organisation of our size, with the kind of processing we do, that is not required. Privacy questions therefore reach us directly, at the address above.

2. What this policy covers

This policy covers brikplan.com, the website you are reading this on, and app.brikplan.com, the application where you manage your projects, including the sign-in environment at auth.brikplan.com.

It does not cover third-party websites we link to, and it does not cover what your architect, your contractor or anyone else does with your data outside BrikPlan.

3. What data we collect

We collect only what the service needs in order to work.

  • Account data: your email address, your first name and your last name. Your password is managed by our sign-in server and stored there only as an encrypted hash. We cannot see it and cannot retrieve it.
  • Project data: the name, address, type and expected start date of your building or renovation project.
  • Budget data: the categories and line items in your budget, estimated amounts, quotes, invoices, VAT rates and the status of each item.
  • Documents: the quotes, invoices and other files you upload, including everything they contain.
  • Team data: the email addresses of the people you invite, their role in the project and the status of their invitation. Of the invitation link we store only a hash, never the link itself.
  • Technical data: your IP address, the time and type of your requests, and error messages. These end up in our server logs and are used to keep the service running, limit abuse and resolve outages.
  • Preferences: your language, your choice of light or dark theme, and which explanatory screens you have already seen.

We do not process payment data: BrikPlan is free today and no payment provider is connected to the application. We also do not ask for special categories of personal data, such as health or biometric data. You do not need them to use BrikPlan.

4. Data about other people you add

A building file almost always contains other people's data: your contractor's name on an invoice, your architect's email address, sometimes a site address that is also someone's home address.

When you put that data into BrikPlan, we process it in order to show the project to you and to the people you share it with. We use it for nothing else. You remain responsible for what you upload: do not include more personal data than you need, and share a project only with people who are allowed to see it.

Did you end up in BrikPlan because someone invited you, or because your name appears on an uploaded document? The rights in this policy apply to you too. Email us at [email protected].

6. Cookies and local storage

We use no advertising cookies, no tracking cookies and no social network cookies. That is also why you see no cookie banner: everything we set is either strictly necessary or contains no personal data.

  • On this website: we measure visits with Cloudflare Web Analytics. It works without cookies and without a unique identifier per visitor. We see how many people view which page, not who you are and not where you go next. Your theme choice is kept in your browser's local storage; it never leaves your device.
  • In the application: your sign-in session uses cookies from our own sign-in server at auth.brikplan.com and tokens held in your browser tab's session storage. Those tokens disappear the moment you close the tab. They are strictly necessary to keep you signed in.

7. Who we share your data with

We do not sell your data and we do not share it with advertisers. We do work with a small number of suppliers who act as our processors. We have a data processing agreement with each of them, and they may use your data only to provide their service to us.

SupplierWhat forWhere the data sits
Hetzner Online GmbH The server running the application and the database Nuremberg, Germany
Cloudflare, Inc. Storage of your uploaded documents, hosting of this website, protection of traffic Document storage pinned to EU jurisdiction; traffic passes through Cloudflare's global network
Anthropic PBC Reading quotes and invoices into filled-in fields United States
Resend Sending verification and invitation emails United States

Beyond that we share your data only with the other members of your own project, as you invite them, and with a competent authority where the law obliges us to.

8. Documents read by AI

When you upload a quote or an invoice, BrikPlan reads the document right away: supplier, date, description, amount and VAT rate are filled into the form for you. This happens on every upload, automatically, without you doing anything.

Reading in a whole budget structure works differently: there you open the import dialog yourself and press a button to have the document read.

To do it we send the text of the document, or an image of it when the document is a scan, to Anthropic, the maker of the Claude model. Anthropic processes it as our processor, purely to return the answer. The content of your documents is not used to train AI models.

The result is a suggestion, not a decision. The extracted fields land in a form that you review, adjust and confirm. There is therefore no automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR.

Reading is part of uploading a quote or an invoice and cannot be switched off separately. If you would rather a document was not read by AI, do not upload it and fill the fields in yourself.

9. Transfers outside the EEA

Your project data, your documents and our backups stay inside the European Economic Area: the server is in Germany and document storage is pinned to our storage provider's EU jurisdiction.

Two processing activities leave the EEA: document reading by Anthropic and email delivery by Resend, both in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses in our data processing agreement with those suppliers, alongside technical measures such as encrypted transport.

Cloudflare protects and speeds up traffic to our domains through a global network, which means traffic can pass outside the EEA. The Standard Contractual Clauses cover that too.

10. How long we keep your data

  • While your account exists: your account, project, budget and document data is kept for as long as you use your account. You decide when that ends.
  • After a deletion request: we deactivate your account immediately and permanently delete your data after 30 days. See the next section.
  • Backups: we take an encrypted backup daily and keep the last 7 daily, 4 weekly and 6 monthly versions. Deleted data therefore also disappears from the backups within six months of deletion at the latest.
  • Server logs: logs containing technical data such as IP addresses are kept no longer than 90 days.
  • Invitations: an invitation that is never accepted expires and is removed together with the project.
  • Statutory retention: where the law requires us to keep certain data longer, we keep it for as long as the law asks and no longer.

11. Deleting your account and exporting your data

You delete your account yourself, in your account settings in the application. Here is what happens then:

  • Immediately: your account is deactivated, you can no longer sign in, and your data is no longer visible in the application.
  • Within 30 days: you can still undo the deletion by emailing us at [email protected]. That grace period exists so that one wrong click does not cost you everything.
  • After 30 days: your account and your personal data are permanently removed from our systems, including from our sign-in server and from document storage. They disappear from backups within six months of deletion at the latest.

You can also request an export of all your data at any time, again in your account settings. You receive a file containing your account data, your projects, your budgets and your documents, in a common, machine-readable format.

If you are part of a shared project, that project continues to exist for the other members. What you added and what shapes the budget, an invoice for example, stays in the project but is disconnected from you as a person.

12. How we protect your data

  • Encrypted traffic: all traffic to and from BrikPlan runs over HTTPS.
  • Separate sign-in: passwords are managed by a separate sign-in server and stored only as a hash.
  • Per-project access: who may see or change what is enforced per project and per role by the server, not only by the interface.
  • Shielded documents: uploaded files sit in private storage and are reachable only through temporary links that expire after a few minutes.
  • Encrypted backups: backups are encrypted before they leave our server.
  • Limited access: only the people who keep the service running can reach the production environment.

No system is entirely without risk. If you suspect something is wrong with your account, or you find a vulnerability, tell us at [email protected]. In the event of a data breach with a high risk to you, we will notify you personally, and we report the breach to the Belgian Data Protection Authority within 72 hours.

13. Your rights

Under the GDPR you have the rights below. You can exercise all of them by emailing [email protected]. For access, correction, export and deletion, your account settings are usually faster.

  • Access: you may know what data we hold about you and receive a copy of it.
  • Rectification: if something is wrong, you correct it, or you have us correct it.
  • Erasure: you may ask us to delete your data, unless we are legally required to keep it.
  • Restriction: you may ask us to freeze your data temporarily, for instance while we look into a dispute.
  • Portability: you may receive your data in a machine-readable format and take it to another service.
  • Objection: you may object to processing based on our legitimate interest. We stop unless we have compelling grounds that outweigh yours.
  • Withdrawing consent: where we rely on your consent, you may withdraw it at any time. What happened before that stays lawful.
  • No automated decision-making: we make no decisions about you based solely on automated processing.

We respond within one month. If your request is unusually complex, we will tell you within that month that we need up to two months more. Sending your request from your account's email address lets us be sure it is you.

Exercising your rights is free.

14. Filing a complaint

If you are unhappy with how we handle your data, tell us first at [email protected]. We would rather fix it ourselves.

You always have the right to lodge a complaint with the supervisory authority as well:

If you live in another EU member state, you can also go to the supervisory authority of your own country.

15. Changes to this policy

If something changes in how we handle your data, because we start working with a new supplier for example, we update this policy and the date at the top changes with it. For a change that genuinely affects you, we will tell you beforehand by email or through a message in the application.

16. Contact

Questions about this policy or about your data? Email [email protected] and we will answer as soon as we can.

Habex Sven BV, Sint-Landradastraat 4/11, 3740 Bilzen-Hoeselt, Belgium.