We collect to reply and schedule
Name, work email, company, message, and booking details you give us — plus basic technical logs that keep the site secure.
We never sell your data
No sale of personal information, no targeted advertising, no marketing spam without consent. Processors only: Vercel and Cal.com.
AI inquiries stay inquiries
Contact and booking data is not used to train public foundation models and has no automated legal effect on you.
You hold the rights
Access, correct, delete, and portability in every state we serve — plus a 45-day response and a right to appeal in Kentucky.
Nº 01
Overview
BRANCLE TECHNOLOGIES LLC (“Brancle,” “we,” “us”) is a Kentucky limited liability company with its principal office at 212 N. 2nd St. STE 100, Richmond, KY 40475. We operate the website at https://brancle.com (“Site”), where we describe our AI automation studio and invite visitors to request a free automation audit by email or through our embedded scheduler.
This Privacy Policy describes how we handle personal information when you visit the Site, contact us at hello@brancle.com, or book time with us. It is organized to satisfy the Kentucky Consumer Data Protection Act (“KCDPA,” effective January 1, 2026), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), other applicable U.S. state privacy laws, and — for visitors from the European Union, United Kingdom, and Switzerland — the General Data Protection Regulation (“GDPR”).
Controller at a glance
Controller: BRANCLE TECHNOLOGIES LLC, 212 N. 2nd St. STE 100, Richmond, KY 40475. Contact: hello@brancle.com (subject line “Privacy Request” or “Privacy Appeal”). Website: https://brancle.com.
Nº 02
Scope — what this covers
This Policy covers personal information we process when you:
- browse brancle.com, including the one-page sections (Solutions, Process, Industries, Why, Results, Testimonials, FAQ, Contact);
- email us at hello@brancle.com (including the pre-addressed “Automation audit enquiry” draft);
- open the booking modal and schedule through Cal.com (event type “arqamwithbrancle/30min”);
- click through to our Upwork agency profile or LinkedIn company page (once you leave, their policies apply).
This Policy does not replace the contracts that govern client project work. When we are engaged to automate workflows inside your CRM, ERP, inbox, or databases, access to your systems and data is governed by a master services agreement and a data processing addendum (“DPA”), published as Policy #6. Where a client agreement conflicts with this general Site notice about the same project data, the client agreement controls.
Nº 03
Data we collect
We follow data minimization: we collect what is needed to reply, schedule, secure the Site, and comply with law — nothing more. We do not operate accounts, newsletters, checkouts, or payments on this Site, so we do not collect passwords, payment credentials, or marketing preferences here.
| Category | Examples | Purpose |
|---|---|---|
| Contact & inquiry | Name, work email, company, role, message content you type | Respond to your audit request and follow up |
| Booking | Name, email, timezone, scheduling metadata, meeting notes you provide via Cal.com | Schedule, confirm, remind, and hold the 30-minute audit call |
| Technical & security | IP address, device/browser type, pages viewed, referrer, timestamps, error logs | Operate, secure, debug, and measure the Site at an aggregate level |
| Trust & compliance | Correspondence records, consent records, request/appeal history | Demonstrate compliance and resolve disputes |
We do not intentionally collect Social Security numbers, driver’s license numbers, precise geolocation, biometric data, or other sensitive personal information through the Site. Please do not include sensitive information in free-text inquiry or booking fields — if you do, we will handle it as general inquiry data and delete it on request.
Nº 04
Where it comes from
- Directly from you — when you email us or complete the Cal.com scheduler. This is the primary source.
- Automatically — via our hosting infrastructure (Vercel) and Next.js server logs when pages, fonts, images, or the scheduler load.
- From our scheduler processor — Cal.com passes back the booking you created so we can confirm and join the call.
We do not buy contact lists, scrape contacts, or enrich visitor profiles from data brokers.
Nº 05
How we use it — purposes and legal bases
Under the KCDPA we process personal information only for disclosed, proportionate purposes. Under the GDPR we process only with a valid Article 6 legal basis. The table below maps each purpose to its basis.
| Purpose | Legal basis (GDPR) | Detail |
|---|---|---|
| Reply to inquiries | Pre-contract / Legitimate interest | Answer audit requests sent to hello@brancle.com and follow up once |
| Scheduling | Pre-contract / Consent | Create, confirm, remind, reschedule, and log the Cal.com booking |
| Site operation & security | Legitimate interest / Legal obligation | Serve pages, prevent abuse, debug errors, keep aggregate analytics |
| Compliance & disputes | Legal obligation / Legitimate interest | Retain request history, enforce terms, respond to lawful process |
We do not use inquiry or booking data for cross-context behavioral advertising, and we do not make solely automated decisions with legal or similarly significant effect about Site visitors.
Nº 06
AI-specific disclosure
Brancle builds agentic workflows for clients, but this Site itself does not run an AI agent on your inquiry to decide whether you qualify, what price you receive, or whether you are hired. A human reads and responds to audit requests.
- Contact and booking content is not used to train public foundation models.
- We do not feed your inquiry into a model to profile you for advertising.
- If we later offer an interactive agent demo on the Site, that demo will carry its own just-in-time disclosure naming the model provider, what is sent, retention, and human-review controls — and will link to Policy #5 (Responsible AI).
Nº 09
How long we keep it
| Record | Window | Trigger |
|---|---|---|
| Inquiry emails | 24 months | From last message in the thread, then delete on request or by schedule |
| Booking records | 24 months | From the scheduled event, per Cal.com history and our calendar copy |
| Server / security logs | 90 days rolling | From collection, longer only if needed to investigate abuse |
| Privacy requests & appeals | 36 months | From closure, to demonstrate compliance with KCDPA/CCPA/GDPR |
Client project data, if later entrusted to us, is retained per the applicable services agreement and DPA — not per this Site schedule. You may request earlier deletion at any time under Section 11; we honor verified deletion unless retention is required by law or to establish, exercise, or defend legal claims.
Nº 10
Security
We maintain reasonable administrative, technical, and physical safeguards appropriate to the volume and sensitivity of inquiry data: TLS in transit, access-controlled mailboxes and calendars on a need-to-know basis, least-privilege hosting access, patched Next.js dependencies, and complete audit logging of privacy requests.
No method is perfectly secure. If we discover a personal-data breach affecting you, we will notify you and regulators as required by law. Our full controls, backup, logging, and incident-response commitments are published as Policy #4 (Security & Data Protection).
Nº 11
Your rights — and how to exercise them
Depending on where you live, you hold the rights below. We honor them for all Site visitors regardless of state, and we never discriminate for exercising them.
| Right | Kentucky (KCDPA) | California / other U.S. states | EU / UK (GDPR) |
|---|---|---|---|
| Know / access | Yes | Right to know | Right of access (Art. 15) |
| Correct | Yes | Right to correct | Rectification (Art. 16) |
| Delete | Yes | Right to delete | Erasure (Art. 17) |
| Portability | Yes, to the extent technically feasible | Right to portability | Data portability (Art. 20) |
| Opt out of sale / targeted ads / profiling | Yes | Opt out of sale/share + limit sensitive use | Object + restrict (Art. 18, 21) |
| Withdraw consent | Yes, where consent was the basis | Yes | Withdraw at any time (Art. 7) |
How to make a request (no account needed)
Email hello@brancle.com from the address you used to contact or book us, with subject “Privacy Request” and: (1) what right you are exercising, (2) what data or date range it concerns, and (3) how you want the response delivered. If you authorize an agent, include signed written permission plus your own verification.
We verify by matching your email and booking details, respond within 45 days, and may extend once by 45 days with notice. If we decline, we explain why and how to appeal.
Kentucky appeals. If we deny your request, reply within 30 days to the same thread with subject “Privacy Appeal.” We review with a person not involved in the original decision, respond in writing within 60 days, and include instructions to contact the Kentucky Attorney General, Office of Consumer Protection, if you disagree — as required by KRS 367.3613.
California notes. We do not sell or share personal information for cross-context behavioral advertising and have no actual knowledge of selling data of consumers under 16. You may designate an authorized agent under CCPA regulations, and you hold the right to non-discrimination for exercising your rights.
EU/UK notes. Where GDPR applies, you may also lodge a complaint with your supervisory authority. Our Article 27 representative, if appointed, will be named here; until then contact us directly and we route promptly.
Nº 12
Children
The Site is a business-to-business studio site and is not directed to children. We do not knowingly collect personal information from children under 13 (COPPA) or offer child-directed services. If you believe a child provided information through the Site, email hello@brancle.com with subject “Child Data Removal” and we will delete it promptly and restrict further collection from that address.
Nº 13
International transfers
We are based in the United States and host the Site in the United States. If you visit from the EU, UK, Switzerland, or elsewhere abroad, your inquiry and booking information transfers to and is processed in the United States to respond to you — on the bases of pre-contract necessity, consent via submission, and our legitimate interest in running a U.S. studio site.
Where GDPR requires a transfer mechanism, we rely on Standard Contractual Clauses with our processors and supplementary measures. Copies of relevant clauses are available on request to hello@brancle.com.
Nº 14
Changes to this Policy & contact
We update this Policy as the Site, scheduler, hosting, or law changes. Material changes are announced by updating the Effective date above and, for active inquiry threads, by email where appropriate. The current version always lives at https://brancle.com/privacy and supersedes prior versions.
Controller contact
BRANCLE TECHNOLOGIES LLC
212 N. 2nd St. STE 100, Richmond, KY 40475
Email: hello@brancle.com · Site: https://brancle.com
For rights requests use subject “Privacy Request”; for denials use “Privacy Appeal.” Kentucky residents may also contact the Kentucky Attorney General, Office of Consumer Protection, if an appeal does not resolve the matter.
This Policy is provided for transparency and does not constitute legal advice. Client project protections are set in your services agreement and DPA (Policy #6), which control in case of conflict about project data.