Least-privilege + MFA
Founder-only access today, unique accounts, MFA on hosting, mailbox, calendar, and Cal.com. Named reviewers per SOW.
TLS + platform encryption
Encrypted in transit everywhere; at rest via Vercel, mailbox, and Cal.com platform encryption. No secrets in code.
Logged and retained on schedule
Complete privacy-request log for 36 months, server logs 90 days rolling, inquiries and bookings 24 months.
Breach notice per law
Contain, assess, and notify affected individuals and regulators under KCDPA, CCPA, and GDPR timelines.
Nº 01
Overview
BRANCLE TECHNOLOGIES LLC (“Brancle,” “we,” “us”), 212 N. 2nd St. STE 100, Richmond, KY 40475, maintains reasonable administrative, technical, and physical safeguards proportionate to the volume and sensitivity of Site inquiry data. Our approach is defense in depth: least-privilege access, encryption, logging, enforced retention, and a practiced incident-response playbook.
No method is perfectly secure. This page states what we do, what we depend on our processors for, and what we do not promise. To report a suspected vulnerability, email security@brancle.com with subject “Security Report” — see Section 9.
Nº 02
Scope — what this covers
This page covers personal information we handle when you:
- browse brancle.com and its one-page sections;
- email hello@brancle.com, including the pre-addressed audit enquiry draft;
- book through the Cal.com modal or the direct booking page.
It does not certify your systems or environments. When we are engaged to automate work inside your CRM, ERP, inbox, or databases — including any “environments you control” — access, residency, logging, and retention for that project data are specified in your signed SOW and governed by our DPA (Policy #6), which controls on conflict. Workflow governance (thresholds, checkpoints, escalation) is additionally specified per SOW and described in principle in our Responsible AI Policy (Policy #5).
Nº 03
Access control — need to know
| Surface | Control |
|---|---|
| Workforce | Founder-only access to inquiry data today; unique accounts, no shared passwords; access reviewed on role change and revoked on offboarding |
| Hosting (Vercel) | Least-privilege team roles, MFA required, deploy access limited to release authority |
| Mailbox & calendar | Access-controlled on a need-to-know basis; booking invites limited to participants; forwarding rules reviewed |
| Scheduler (Cal.com event arqamwithbrancle/30min) | Single owning account with MFA; event configuration changes logged; calendar ACL limited to hosts |
| Client systems (under SOW) | Time-boxed, scoped grants provisioned by you; least-privilege roles; named human reviewers for checkpoints; revocation at milestone or termination |
Reviewer duties from Terms §§6–7 apply: you name qualified approvers for consequential actions and accept or reject escalations promptly. Threshold tuning and control changes are made only by authorized personnel and recorded.
Nº 04
Encryption — in transit and at rest
| Layer | Control |
|---|---|
| In transit | TLS 1.2+ for the Site, Cal.com embed and booking page, and mail delivery where supported; HSTS enforced by hosting |
| At rest | Platform encryption for Vercel hosting artifacts, mailbox and calendar stores, and Cal.com booking records |
| Secrets | API keys and tokens in environment variables only; never committed to the repository or pasted into inquiry fields |
| End devices | Screen lock, disk encryption, and patched operating systems for devices accessing inquiry data |
Please do not include Social Security numbers, credentials, or other sensitive identifiers in inquiry or booking free-text fields. If you do, we handle the content as general inquiry data and delete it on verified request.
Nº 05
Logging and monitoring — what audit trail means
“Complete audit trail” means every privacy request and every consequential workflow action records, at minimum: actor, action, timestamp, input/output reference, confidence or rule applied, and approver where human review applied. Workflow-level schemas are fixed per SOW; Site-level logging follows the table below.
| Log | Content | Retention & access |
|---|---|---|
| Server / security logs | IP, timestamps, routes, error traces for operation and abuse prevention | 90 days rolling; extended only to investigate active abuse; hosting admins only |
| Privacy requests & appeals | Request, verification record, decision, response, appeal history | 36 months to demonstrate KCDPA/CCPA/GDPR compliance; controller only |
| Booking events | Name, email, timezone, notes, event outcome via Cal.com plus calendar copy | 24 months per Privacy §9; hosts only |
| Control changes | Threshold, reviewer, and configuration changes with author and reason | With the record they govern; SOW-defined for project work |
Nº 06
Retention and disposal — enforced, not aspirational
| Record | Window | Trigger |
|---|---|---|
| Inquiry emails | 24 months | From last message in the thread |
| Booking records | 24 months | From the scheduled event |
| Server / security logs | 90 days rolling | From collection |
| Privacy requests & appeals | 36 months | From closure |
| Client project data | Per SOW / DPA | Overrides this schedule where applicable |
Deletion means removal from live systems plus purge from platform backups within 30 days of the live delete, subject to legal-hold exception (litigation, investigation, or valid process, documented and time-boxed). De-identification, where used for aggregate learning, follows removal or hashing of direct identifiers plus suppression of rare quasi-identifiers so re-identification is not reasonably possible. The 3-year confidentiality floor in Terms §11 continues to protect client secrets even after personal-data deletion.
Nº 07
Backups and recovery — best effort, no SLA
Inquiry content exists in our mailbox and calendar copies plus Cal.com booking history and Vercel platform backups; we maintain no separate Brancle backup of inquiry content beyond those processor copies. Restoration is best-effort from the latest available processor copy — we state no RPO/RTO numbers and create no recovery SLA by this page.
Project-data backup, where applicable, is specified per SOW (frequency, location, and restore procedure) and governed by the DPA. Our aggregate liability for loss of data remains subject to the 6-month-fee cap and loss-of-data exclusion in Terms §13.
Nº 08
Incident response — detect, contain, notify
On suspected personal-data breach affecting you, our playbook runs in order:
- Detect & contain — isolate the vector (credential, embed, mailbox rule, hosting config), rotate secrets, preserve logs, and open a founder-led case record.
- Assess — determine categories and volume of data, affected individuals, and whether a processor (Vercel, Cal.com, mailbox provider) is the source, in which case we trigger their incident flow and preserve their case IDs.
- Notify — notify affected individuals without unreasonable delay and regulators as required: Kentucky Attorney General and other state authorities per applicable breach-notification statutes, and EU/UK supervisory authorities within 72 hours of awareness where GDPR applies, with follow-up detail without undue delay. Notices describe what happened, data involved, steps taken, and contact for questions.
Processor-breach dependency
Where Vercel, Cal.com, or our mailbox provider is the source, timing depends in part on their notice to us; we notify downstream promptly on receipt and do not wait for their investigation to close where the law requires earlier notice. Full vendor roles are listed in Policy #7 (Subprocessors).
Nº 09
Vulnerabilities and changes
We keep Next.js dependencies patched, review hosting and scheduler configuration on change, and track hardening incrementally (including security headers and a CSP allowlist scoped to Cal.com embed scripts and frames as the stack evolves).
To report an issue, email security@brancle.com with subject “Security Report,” describing the affected URL, steps to reproduce, and impact. We acknowledge receipt, investigate, and remediate proportionate to risk. We operate no paid bug-bounty program, and this page creates no bounty obligation.
Nº 10
Compliance scope — what we don't claim
We do not warrant SOC 2, HIPAA, PCI, or any other compliance certification and do not provide legal or compliance advice. Phrases on the Site about least-privilege access, logging, retention, or approval gates describe our standard approach for Site inquiry data; regulated-appropriate controls for your environment must be specified in your SOW, approved by your counsel, and — for project personal data — governed by the DPA.
Enterprise prospects may request a SIG-lite–style summary under NDA via security@brancle.com with subject “Security Review.” International transfers for Site visitors follow Privacy §13 (U.S. hosting with SCCs on request).
Nº 11
Changes to this Policy & contact
We update this page as the Site, scheduler, hosting, or law changes by posting the revised version with a new Effective date; material control changes are highlighted by date change. The current version always lives at https://brancle.com/security and companions Privacy (Policy #1), Terms (Policy #2), and Cookies (Policy #3).
Controller contact
BRANCLE TECHNOLOGIES LLC
212 N. 2nd St. STE 100, Richmond, KY 40475
Email: security@brancle.com · Security reports: subject “Security Report” · Site: https://brancle.com
This page is provided for transparency and does not constitute legal advice. Project-data protections are set in your SOW and DPA (Policy #6), which control on conflict about project data.