Skip to content
FIG. L-04 · BranclePlate Nº 04
04/Legal / Security

Security & Data Protection engineered for oversight

How BRANCLE TECHNOLOGIES LLC protects inquiry and booking data on brancle.com — who can access it, how it is encrypted and logged, how long it is kept, and what happens if something goes wrong. Site-only today; client project controls are set per engagement and governed by your SOW plus our DPA (Policy #6).

Controller
Brancle Technologies LLC
Effective
September 6, 2026
Reading time
≈ 8 min
  • Least-privilege + MFA

    Founder-only access today, unique accounts, MFA on hosting, mailbox, calendar, and Cal.com. Named reviewers per SOW.

  • TLS + platform encryption

    Encrypted in transit everywhere; at rest via Vercel, mailbox, and Cal.com platform encryption. No secrets in code.

  • Logged and retained on schedule

    Complete privacy-request log for 36 months, server logs 90 days rolling, inquiries and bookings 24 months.

  • Breach notice per law

    Contain, assess, and notify affected individuals and regulators under KCDPA, CCPA, and GDPR timelines.

FIG. L-01A · SummaryNº 01SHA · Plain EnglishStart here

01

Overview

BRANCLE TECHNOLOGIES LLC (“Brancle,” “we,” “us”), 212 N. 2nd St. STE 100, Richmond, KY 40475, maintains reasonable administrative, technical, and physical safeguards proportionate to the volume and sensitivity of Site inquiry data. Our approach is defense in depth: least-privilege access, encryption, logging, enforced retention, and a practiced incident-response playbook.

No method is perfectly secure. This page states what we do, what we depend on our processors for, and what we do not promise. To report a suspected vulnerability, email security@brancle.com with subject “Security Report” — see Section 9.

02

Scope — what this covers

This page covers personal information we handle when you:

  • browse brancle.com and its one-page sections;
  • email hello@brancle.com, including the pre-addressed audit enquiry draft;
  • book through the Cal.com modal or the direct booking page.

It does not certify your systems or environments. When we are engaged to automate work inside your CRM, ERP, inbox, or databases — including any “environments you control” — access, residency, logging, and retention for that project data are specified in your signed SOW and governed by our DPA (Policy #6), which controls on conflict. Workflow governance (thresholds, checkpoints, escalation) is additionally specified per SOW and described in principle in our Responsible AI Policy (Policy #5).

03

Access control — need to know

Who can access what
SurfaceControl
WorkforceFounder-only access to inquiry data today; unique accounts, no shared passwords; access reviewed on role change and revoked on offboarding
Hosting (Vercel)Least-privilege team roles, MFA required, deploy access limited to release authority
Mailbox & calendarAccess-controlled on a need-to-know basis; booking invites limited to participants; forwarding rules reviewed
Scheduler (Cal.com event arqamwithbrancle/30min)Single owning account with MFA; event configuration changes logged; calendar ACL limited to hosts
Client systems (under SOW)Time-boxed, scoped grants provisioned by you; least-privilege roles; named human reviewers for checkpoints; revocation at milestone or termination

Reviewer duties from Terms §§6–7 apply: you name qualified approvers for consequential actions and accept or reject escalations promptly. Threshold tuning and control changes are made only by authorized personnel and recorded.

04

Encryption — in transit and at rest

Encryption by layer
LayerControl
In transitTLS 1.2+ for the Site, Cal.com embed and booking page, and mail delivery where supported; HSTS enforced by hosting
At restPlatform encryption for Vercel hosting artifacts, mailbox and calendar stores, and Cal.com booking records
SecretsAPI keys and tokens in environment variables only; never committed to the repository or pasted into inquiry fields
End devicesScreen lock, disk encryption, and patched operating systems for devices accessing inquiry data

Please do not include Social Security numbers, credentials, or other sensitive identifiers in inquiry or booking free-text fields. If you do, we handle the content as general inquiry data and delete it on verified request.

05

Logging and monitoring — what audit trail means

“Complete audit trail” means every privacy request and every consequential workflow action records, at minimum: actor, action, timestamp, input/output reference, confidence or rule applied, and approver where human review applied. Workflow-level schemas are fixed per SOW; Site-level logging follows the table below.

Site logging schedule
LogContentRetention & access
Server / security logsIP, timestamps, routes, error traces for operation and abuse prevention90 days rolling; extended only to investigate active abuse; hosting admins only
Privacy requests & appealsRequest, verification record, decision, response, appeal history36 months to demonstrate KCDPA/CCPA/GDPR compliance; controller only
Booking eventsName, email, timezone, notes, event outcome via Cal.com plus calendar copy24 months per Privacy §9; hosts only
Control changesThreshold, reviewer, and configuration changes with author and reasonWith the record they govern; SOW-defined for project work

06

Retention and disposal — enforced, not aspirational

Retention windows (then delete or de-identify)
RecordWindowTrigger
Inquiry emails24 monthsFrom last message in the thread
Booking records24 monthsFrom the scheduled event
Server / security logs90 days rollingFrom collection
Privacy requests & appeals36 monthsFrom closure
Client project dataPer SOW / DPAOverrides this schedule where applicable

Deletion means removal from live systems plus purge from platform backups within 30 days of the live delete, subject to legal-hold exception (litigation, investigation, or valid process, documented and time-boxed). De-identification, where used for aggregate learning, follows removal or hashing of direct identifiers plus suppression of rare quasi-identifiers so re-identification is not reasonably possible. The 3-year confidentiality floor in Terms §11 continues to protect client secrets even after personal-data deletion.

07

Backups and recovery — best effort, no SLA

Inquiry content exists in our mailbox and calendar copies plus Cal.com booking history and Vercel platform backups; we maintain no separate Brancle backup of inquiry content beyond those processor copies. Restoration is best-effort from the latest available processor copy — we state no RPO/RTO numbers and create no recovery SLA by this page.

Project-data backup, where applicable, is specified per SOW (frequency, location, and restore procedure) and governed by the DPA. Our aggregate liability for loss of data remains subject to the 6-month-fee cap and loss-of-data exclusion in Terms §13.

08

Incident response — detect, contain, notify

On suspected personal-data breach affecting you, our playbook runs in order:

  • Detect & contain — isolate the vector (credential, embed, mailbox rule, hosting config), rotate secrets, preserve logs, and open a founder-led case record.
  • Assess — determine categories and volume of data, affected individuals, and whether a processor (Vercel, Cal.com, mailbox provider) is the source, in which case we trigger their incident flow and preserve their case IDs.
  • Notify — notify affected individuals without unreasonable delay and regulators as required: Kentucky Attorney General and other state authorities per applicable breach-notification statutes, and EU/UK supervisory authorities within 72 hours of awareness where GDPR applies, with follow-up detail without undue delay. Notices describe what happened, data involved, steps taken, and contact for questions.

Processor-breach dependency

Where Vercel, Cal.com, or our mailbox provider is the source, timing depends in part on their notice to us; we notify downstream promptly on receipt and do not wait for their investigation to close where the law requires earlier notice. Full vendor roles are listed in Policy #7 (Subprocessors).

09

Vulnerabilities and changes

We keep Next.js dependencies patched, review hosting and scheduler configuration on change, and track hardening incrementally (including security headers and a CSP allowlist scoped to Cal.com embed scripts and frames as the stack evolves).

To report an issue, email security@brancle.com with subject “Security Report,” describing the affected URL, steps to reproduce, and impact. We acknowledge receipt, investigate, and remediate proportionate to risk. We operate no paid bug-bounty program, and this page creates no bounty obligation.

10

Compliance scope — what we don't claim

We do not warrant SOC 2, HIPAA, PCI, or any other compliance certification and do not provide legal or compliance advice. Phrases on the Site about least-privilege access, logging, retention, or approval gates describe our standard approach for Site inquiry data; regulated-appropriate controls for your environment must be specified in your SOW, approved by your counsel, and — for project personal data — governed by the DPA.

Enterprise prospects may request a SIG-lite–style summary under NDA via security@brancle.com with subject “Security Review.” International transfers for Site visitors follow Privacy §13 (U.S. hosting with SCCs on request).

11

Changes to this Policy & contact

We update this page as the Site, scheduler, hosting, or law changes by posting the revised version with a new Effective date; material control changes are highlighted by date change. The current version always lives at https://brancle.com/security and companions Privacy (Policy #1), Terms (Policy #2), and Cookies (Policy #3).

Controller contact

BRANCLE TECHNOLOGIES LLC

212 N. 2nd St. STE 100, Richmond, KY 40475

Email: security@brancle.com · Security reports: subject “Security Report” · Site: https://brancle.com

This page is provided for transparency and does not constitute legal advice. Project-data protections are set in your SOW and DPA (Policy #6), which control on conflict about project data.