Skip to content
Brain Hours
Home Products About Contact
  • English
  • Português
  • Español
Talk to us
Legal

Privacy Policy

Last updated: 4 August 2026

Privacy Terms Cookies

1. Who we are

Brain Hours Company is a Delaware C-Corporation, registration #10568877. In this policy we call ourselves Brain Hours, we, us or our. The Site means brainhours.com and its subpages. You means the person visiting the Site or writing to us. For everything described here, Brain Hours is the controller: we decide what personal data is processed and why.

  • Email: contact@brainhours.com
  • Phone: +1 (862) 356-5090
  • Post: Brain Hours Company, 1111B S Governors Ave, Suite 56762, Dover, DE 19904, USA
  • Or use the contact page.

We are a small, senior team. We have not appointed a Data Protection Officer and we have no EU or UK representative; given the scale of what we process, we do not believe we need either. Privacy requests go to the people who run the company: contact@brainhours.com is our channel for data subject requests and for any other privacy communication.

2. What this policy covers

This policy covers your visit to the Site and your direct dealings with us: enquiries, calls, emails, and business contact we start ourselves.

It does not cover personal data we handle for customers. When we operate GetRaze for a customer, or deliver a consulting engagement inside a client's own systems, the customer decides what is processed and why. There we act as a processor on their documented instructions, under a separate services agreement and data processing agreement. This website policy does not govern that processing.

So if a business contacted you using GetRaze, or your data sits in a system we built for a client, that business is the controller, not us — ask them for their privacy notice. GetRaze has its own terms at getraze.co. If you cannot tell who to ask, write to us and we will point you to the right party.

3. What we collect

(a) If you visit the Site

The Site collects nothing about you. It is static HTML: no server-side application, no database, no accounts, no login, no analytics, no tracking pixels, no third-party requests of any kind. Fonts, images, scripts and styles all come from brainhours.com.

The exception is ordinary hosting. The Site runs on third-party shared hosting, and our hosting provider keeps standard access logs — IP address, timestamp, URL requested, referring page, browser user agent — for security and diagnostics. We do not use them to profile you or combine them with anything else.

(b) If you contact us

The contact form does not submit to a server. Your browser assembles what you typed into a pre-filled message and opens your own email client. Nothing reaches us unless you then choose to send it — until then, the text stays on your device.

If you do write — by form, email, phone or a business network — we receive what you chose to send: name, email address, company, the topic you picked, your message, and anything else you include. We keep that correspondence so we can reply and pick up where we left off. The form also carries a hidden anti-spam field that real people never see; it collects nothing about you at all.

(c) If we approach you about business

We sell to businesses, and sometimes we make the first move. Then we hold business contact details: name, job title, employer, business email, business phone, a public professional profile link, the source we found you in, and our correspondence. We find these details in public company websites, public professional profiles, public business directories, and from people who give them to us directly or introduce us. That is data about your professional role, not your private life. Where we use our own tools, including GetRaze, for our own outreach, we are the controller of that data and this policy applies.

We do not ask for special category data — health, biometrics, political or religious views. Please do not send it.

4. Cookies and local storage

The Site sets no cookies. Not one, first-party or third-party. No analytics, no advertising or retargeting tag, no session recording, no fingerprinting, no A/B testing.

It uses exactly one browser localStorage entry, bh-theme, holding dark or light. It remembers your theme choice. It is first-party, holds no personal data, is never transmitted anywhere, and is readable only by brainhours.com in your own browser. Clearing browser storage removes it. Detail is on the cookies page.

5. Why we process it, and our legal bases

The GDPR requires us to name a basis in Article 6. Brazil's LGPD has close equivalents in Article 7.

  • Answering your enquiry and taking pre-contract steps. GDPR Art. 6(1)(b) where you are asking about our services, otherwise Art. 6(1)(f), our legitimate interest in replying to people who write to us. LGPD Art. 7, V or Art. 7, IX.
  • Running and defending the Site — server logs, spam prevention, abuse investigation. GDPR Art. 6(1)(f). LGPD Art. 7, IX.
  • Managing a client relationship — contracts, scoping, invoicing, support. GDPR Art. 6(1)(b). LGPD Art. 7, V.
  • Business-to-business outreach. GDPR Art. 6(1)(f), our legitimate interest in offering relevant services to businesses that plausibly need them. LGPD Art. 7, IX.
  • Legal, tax and accounting obligations. GDPR Art. 6(1)(c). LGPD Art. 7, II.

On outreach we will be direct. Legitimate interest is not a free pass. We keep to business contact details in a professional context, we say who we are and why we are writing, and we weigh our commercial interest against your interest in being left alone. If that balance fails, we do not send. Every message carries a way to opt out, and you can simply reply and tell us to stop — we honour it on the first request, permanently, and you owe us no reason. Where local law requires consent for a channel or a recipient, we ask for consent instead.

6. Who we share it with

  • Our hosting provider, which serves the Site and keeps the access logs above.
  • Our email and business software providers, which carry and store our correspondence.
  • Professional advisers — accountants and lawyers — where they need it to advise us.
  • Authorities, where a valid legal obligation or lawful request requires disclosure.

We do not sell personal data. We do not rent, trade or share it with advertising networks, ad-tech platforms or data brokers, and we run no advertising on the Site. The contact form sends nothing to a third party today; if we later point it at a hosted form handler, we will update this policy and name that provider here before the change goes live.

7. International transfers

We are a US company. Contacting us from the EU, the UK, Brazil or elsewhere in Latin America means your data may be processed in the United States, and in other countries where we and our providers operate.

The United States is not covered by a general adequacy decision, and we are not certified under the EU-US Data Privacy Framework. We make no other certification claims. Where a transfer of EU or UK data needs a safeguard, we rely on the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum for UK data, or on an applicable Article 49 derogation — for example a transfer necessary to perform a contract with you. For transfers out of Brazil we rely on LGPD Articles 33 and 35, typically contractual clauses or the necessity of performing a contract at your request. Ask us and we will tell you which applies.

8. How long we keep it

  • Enquiries and correspondence: up to 24 months after our last contact, then deleted.
  • Server access logs: retained by our hosting provider under its standard settings, typically a few weeks.
  • Business outreach records: up to 24 months from the last meaningful contact.
  • Opt-out records: kept indefinitely, because forgetting them is how people get contacted twice. We keep only the minimum needed to honour the request.
  • Contracts, invoices and accounting records: seven years, to meet US tax and corporate requirements.

If a dispute or legal obligation requires us to keep something longer, we keep it that long and no longer.

9. Your rights

Under the GDPR you have the rights in Articles 15 to 22: access, correction, erasure, restriction, portability, and objection to processing based on legitimate interests — including our outreach, which we stop on request without asking why. You also have the right not to be subject to a decision based solely on automated processing with legal or similarly significant effects; we make none through the Site. Where we rely on consent, you can withdraw it at any time without affecting what came before.

Under LGPD Article 18 you can ask for confirmation that we process your data, access to it, correction of incomplete or outdated data, anonymisation, blocking or deletion of unnecessary or excessive data, portability, deletion of data processed with consent, information about who we share data with and about the consequences of refusing consent, and you can revoke consent.

To use any of them, email contact@brainhours.com. Tell us what you want and give us enough to find you, usually the address you wrote from. We may ask one question to confirm it is really you, and we will not use that to stall. We reply within 30 days, and within 15 days where the LGPD requires it. There is no fee. If a request concerns data we hold as a processor for a customer, we forward it to that customer and tell you we have.

If you are in the United States, we do not sell or share your personal data, and we run no targeted advertising. Whichever state you live in, use the same route as everyone else: email contact@brainhours.com and ask for access, correction or deletion. We will not treat you differently for asking.

10. Security

Our plainest security measure is that the Site collects nothing: no database to breach, no account to take over, no password to steal. Beyond that, the Site is served over HTTPS with TLS in transit, and its Content-Security-Policy allows resources only from our own domain, which is why there are no third-party requests. Access to our email and business records is limited to the people who need it for their work, and each of them works from an individual account rather than a shared login.

We will not claim a certification we do not hold or a guarantee nobody can honestly give. No system is perfectly secure. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the applicable deadlines.

11. Children

Brain Hours sells to businesses. The Site and our services are not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has sent us personal data, write to contact@brainhours.com and we will delete it.

12. Changes to this policy

We update this policy when what we do changes, and the date at the top is the current version. If a change is material — a new processor, a new purpose, a different legal basis, or the contact form starting to send data to a third party — we will say so plainly on this page rather than quietly editing a line.

13. How to complain

Start with us: contact@brainhours.com. It is the fastest route, and we would rather fix a problem than argue about it.

If that does not resolve it, you can go to a regulator. In the EU, complain to the supervisory authority where you live or work, or where the issue arose. In the UK, that is the Information Commissioner's Office. In Brazil, it is the Autoridade Nacional de Proteção de Dados (ANPD). Doing so does not affect any other legal remedy available to you. Our Terms of Use and cookies page complete the picture.

Brain Hours

Applied AI for go-to-market teams. Incorporated in Delaware, building for the world.

Company

About Products Contact

What we build

GetRaze AI consulting getraze.co ↗

Contact

contact@brainhours.com +1 (862) 356-5090 Dover, DE · USA

Legal

Privacy Terms Cookies
© 2026 Brain Hours Company · Delaware C-Corporation Registration #10568877