This Privacy Policy explains how Brook Code Technologies ("Brook Code", "we", "us" or "our") collects, uses, stores, shares and protects personal data when you visit brookcode.com, contact us, create an account, or use our software products and services, including our fuel station ERP, point of sale (POS), inventory management, accounting, CRM, mobile applications, cloud software, AI analytics and business automation tools (together, the "Services").
We have written this policy to meet the requirements of the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), together with other privacy laws that apply to our customers in India and internationally.
1. Who we are and our role
Brook Code provides subscription-based cloud software to businesses. Depending on the data involved, we act in one of two roles:
- As a controller (GDPR) or Data Fiduciary (DPDP Act) for personal data we collect for our own purposes: website visitors, prospective customers, account users, billing contacts and people who contact our support team. This Privacy Policy covers that data.
- As a processor (GDPR), Data Processor (DPDP Act) or service provider (CCPA) for personal data that our business customers enter into the Services, such as their staff, their own customers, credit parties, vehicle details and transaction records ("Customer Data"). Our customer is the controller of that data and decides how it is used. Our processing of Customer Data is governed by our agreement with the customer and our Data Processing Addendum. If you are an individual whose data a business has entered into our Services, please contact that business first.
2. Information we collect
Information you provide to us
- Identity and contact details: name, job title, email address, phone number and WhatsApp number.
- Company details: business name, business address, number and location of outlets or fuel stations, tax registration numbers (such as GSTIN, VAT or EIN) and industry information.
- Account information: username, password (stored only in hashed form), user roles, preferences and security settings.
- Billing information: billing name and address, invoice details, subscription plan, purchase history and tax information.
- Communications: messages, emails, WhatsApp or Telegram conversations, call notes, demo requests, survey responses and feedback you send to us.
Payment information
Payments are processed by our payment partners Razorpay (primarily for customers in India) and Stripe (primarily for international customers). Card numbers, CVV codes, UPI credentials and bank account credentials are entered directly into the payment partner's secure systems and are not stored on our servers. We receive limited information from them, such as a payment token, the last four digits and expiry of a card, the payment method type, the transaction amount and the payment status. Razorpay and Stripe process payment data as independent controllers under their own privacy policies and are certified to the PCI DSS standard.
Information collected automatically
- Device and connection information: IP address, browser type and version, operating system, device model, device identifiers, language and time zone settings.
- Usage information: pages and screens viewed, features used, clicks, session duration, referring URLs, error reports and performance data.
- Log and security data: access times, login attempts, API requests and security events.
- Cookies and similar technologies: see Cookies below and our Cookie Policy.
Information from third parties
- Payment status and fraud signals from Razorpay and Stripe.
- Messages and profile details you share when you contact us on WhatsApp or Telegram.
- Referrals from resellers, implementation partners or other customers.
- Publicly available business information, used to verify business customers.
Customer Data
When you use the Services, you may enter or upload data about your business operations, including sales, shifts, tank and stock levels, nozzle readings, credit ledgers, expenses, employee records, customer records, and photos or documents submitted for AI-assisted entry. We process Customer Data only on your instructions, as described in Who we are and our role.
3. How we use personal data and our legal bases
We use personal data only for the purposes below. Where the GDPR applies, we rely on the legal basis shown. Where the DPDP Act applies, we process personal data on the basis of your consent or for the legitimate uses permitted by the Act, such as performing a service you have requested.
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Services | Create and manage accounts, host data, run features, deliver mobile and web apps | Performance of a contract |
| Billing and payments | Process subscriptions, issue invoices, collect payments, manage renewals | Performance of a contract; legal obligation |
| Customer support | Answer questions, resolve issues, onboarding and training | Performance of a contract; legitimate interests |
| Security and fraud prevention | Detect abuse, prevent unauthorised access, verify payments, keep logs | Legitimate interests; legal obligation |
| Improve our products | Analyse usage trends, fix bugs, measure performance, develop features | Legitimate interests; consent for non-essential cookies |
| Communications | Service notices, security alerts, renewal reminders, product updates | Performance of a contract; legitimate interests |
| Marketing | Newsletters, event invitations, offers about related products | Consent, or legitimate interests for existing business customers (you can opt out at any time) |
| Legal and compliance | Tax and accounting records, responding to lawful requests, enforcing our terms | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can ask us for details of that assessment and you have the right to object (see Your privacy rights).
We do not use personal data for automated decision-making that produces legal or similarly significant effects on you.
4. AI features and analytics
Some features use artificial intelligence, for example reading a photo of a meter, bill or register and turning it into an entry, turning a typed or spoken message into a structured record, or producing business insights. To provide these features, the relevant image, text or data is sent to AI model providers acting as our sub-processors, and the result is returned to your account.
- AI features process Customer Data only to deliver the feature you requested.
- Where the provider offers the option, we configure it so that your content is not used to train its general-purpose models.
- AI outputs can contain errors. You remain responsible for reviewing entries and reports before relying on them for accounting, tax or business decisions.
- We may use aggregated and de-identified data, which cannot reasonably be linked to you or your business, to measure and improve the accuracy of our features.
6. International data transfers
We serve customers in India and internationally, and our providers operate in several countries. Your personal data may therefore be transferred to, stored in or accessed from countries other than your own, including India, the United States and member states of the European Union.
- For transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where needed.
- For personal data subject to the DPDP Act, we transfer data outside India only as permitted by the Act and not to any country or territory restricted by the Government of India.
You can request more information about the safeguards we use by contacting us.
7. How we store and protect data
Personal data and Customer Data are stored on secure cloud infrastructure operated by our hosting providers. We maintain technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit using TLS, and encryption of backups and sensitive data at rest.
- Passwords stored using strong one-way hashing; payment card data never stored on our systems.
- Role-based access controls, the principle of least privilege and multi-factor authentication for administrative access.
- Network protection including firewalls, a web application firewall and DDoS mitigation through Cloudflare.
- Logical separation of each customer's data within the Services.
- Security monitoring, audit logging, regular patching and vulnerability management.
- Automated encrypted backups and a tested disaster recovery process, as described in our Service Level Agreement.
- Confidentiality obligations and security training for personnel with access to data.
No method of transmission or storage is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law, including the GDPR and the DPDP Act.
8. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy:
| Data | Retention period |
|---|---|
| Account and contact information | For the life of your account, then up to 24 months for legitimate business and legal purposes |
| Customer Data in the Services | For the subscription term. After termination you may export it for 30 days, after which it is deleted from live systems and removed from backups as they rotate |
| Invoices, payment and tax records | As required by tax, accounting and company laws, generally up to eight (8) years |
| Support communications | Up to 36 months after the conversation is closed |
| Security and access logs | Up to 12 months, or longer when needed to investigate an incident |
| Marketing preferences | Until you unsubscribe or withdraw consent; we keep a record of opt-outs so we can honour them |
| Website analytics | Up to 14 months in Google Analytics |
| Prospects who did not become customers | Up to 24 months after our last interaction |
When retention ends, we delete or anonymise the data. Where the DPDP Act applies, we erase personal data once the purpose is no longer served or consent is withdrawn, unless retention is required by law.
9. Your privacy rights
Depending on where you live, you have some or all of the rights below. We will not discriminate against you for exercising any of them.
Rights under the GDPR and UK GDPR
- Access: obtain a copy of your personal data and information about how it is used.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your data in certain circumstances.
- Restriction: ask us to limit how we use your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent at any time, without affecting processing that took place before.
- Complain to your local data protection supervisory authority.
Rights under the CCPA (California residents)
- The right to know the categories and specific pieces of personal information we collect, use and disclose.
- The right to delete personal information, subject to legal exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information, and we honour Global Privacy Control signals.
- The right to limit the use of sensitive personal information. We use sensitive personal information (such as account credentials) only for purposes permitted by the CCPA.
- The right not to receive discriminatory treatment for exercising your rights.
In the preceding 12 months we have collected the categories of personal information described in Information we collect(identifiers, commercial information, internet activity, and professional information) for the business purposes described in How we use personal data. You may use an authorised agent to submit a request on your behalf.
Rights under India's DPDP Act, 2023
- The right to obtain a summary of your personal data and the processing activities carried out.
- The right to correction, completion, updating and erasure of your personal data.
- The right to withdraw consent, as easily as it was given.
- The right to grievance redressal through our Grievance Officer (see Contact us).
- The right to nominate another person to exercise your rights in the event of death or incapacity.
- If your grievance is not resolved, the right to complain to the Data Protection Board of India after first using our grievance process.
How to exercise your rights
Email [email protected] from the address associated with your account, or use the settings in your account. We will verify your identity before acting on a request, and we respond within one month under the GDPR, within 45 days under the CCPA, and within the timelines prescribed under the DPDP Act. If a request concerns Customer Data held on behalf of a business customer, we will refer it to that customer and assist them in responding.
11. Marketing and service communications
We send service communications that are necessary for your account, such as invoices, renewal reminders, security alerts and changes to our terms. You cannot opt out of these while you have an active account.
We send marketing communications by email, WhatsApp or SMS only where permitted by law. You can unsubscribe at any time using the link in the email, by replying "STOP" to a message, or by contacting [email protected]. In India we follow the applicable telecom commercial communication regulations.
12. Children's privacy
Our Services are designed for businesses and are not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Third-party websites and integrations
Our website and Services may link to or integrate with third-party websites, apps and services, such as payment pages, app stores and messaging platforms. Their privacy practices are governed by their own policies, and we encourage you to review them. We are not responsible for third-party practices.
14. Information for business customers
If you are a business using our Services, you are responsible for:
- Having a lawful basis, and any required consents, for the personal data you enter into the Services.
- Providing privacy notices to your staff, customers and other individuals whose data you process.
- Responding to requests from those individuals, with our assistance where needed.
Our obligations as your processor are set out in our Data Processing Addendum, which forms part of our Terms of Service.
15. Changes to this policy
We may update this Privacy Policy from time to time. The effective date at the top shows when it was last changed. If we make material changes, we will notify account holders by email or in the Services before the changes take effect. Your continued use of the Services after that date means you acknowledge the updated policy.
16. Contact us and Grievance Officer
For questions about this policy, to exercise your rights, or to raise a grievance, contact our privacy team, which also acts as our Grievance Officer under Indian law:
Brook Code Technologies
- Privacy and data protection: [email protected]
- Customer support: [email protected]
- Website: brookcode.com
We acknowledge grievances promptly and resolve them within the timelines prescribed by applicable law. Where required under Article 27 of the GDPR or the UK GDPR, we will appoint a representative in the European Union or the United Kingdom and publish their details on this page.