Privacy Policy
Effective date: July 3, 2026 · Last updated: July 3, 2026
1. Who we are and what this covers
Brock Data, Inc, a Delaware C Corporation ("Brock", "we"), provides a data-migration platform. This Privacy Policy explains how we handle personal information.
Two different roles — please read this first:
- As a controller. When you create an account, pay, contact support, or visit our site, we decide how your personal information is used. This Privacy Policy governs that activity.
- As a service provider / processor. When you use the Service to migrate data, the source records you connect may contain personal information about your own customers, vendors, or staff. We process that data only on your instructions, on your behalf. Our handling of it is governed by our Data Processing Agreement (DPA) www.brocktransform.com/dpa, not by this Policy. If you are an individual whose data was migrated by one of our customers, that customer — not Brock — is responsible for it; please contact them.
2. Personal information we collect (as controller)
- Account data: name, work email, organisation name, role, password (hashed).
- Billing data: processed by our payment processor (Stripe); we receive limited details (e.g., card brand, last four digits, billing contact). We do not store full card numbers.
- Usage and log data: IP address, device/browser, pages and actions, timestamps, error logs.
- Communications: messages you send to support or sales.
- Connection metadata: which Source/Target systems you connect (we hold the credentials encrypted; see the DPA for data processed through those connections).
We do not intentionally collect special-category data (health, biometric, racial/ethnic, etc.) about our users, and we do not collect "sensitive personal information" as defined by the CCPA/CPRA.
Categories under California law. For residents of California and states with similar laws, the information above maps to these statutory categories, with retention periods:
| CCPA category | What we collect | Source | Retention |
|---|---|---|---|
| Identifiers | Name, work email, IP address | You; automatic | Life of account + up to 7 years for legal/tax records |
| Commercial information | Subscription tier, billing history (via Stripe) | You; Stripe | Life of account + up to 7 years for legal/tax records |
| Internet or network activity | Usage and log data, device/browser info | Automatic | 12 months |
| Professional information | Organisation name, role | You | Life of account |
| Communications | Support and sales messages | You | 24 months after resolution |
We collect these categories for the business purposes in §3, and disclose them only as described in §5 and §6. We do not sell or share any category.
3. How we use personal information
To provide, secure, and support the Service; to process payments and manage subscriptions; to communicate with you; to detect and prevent fraud and abuse; to improve the Service; and to comply with law.
4. Legal bases (GDPR / UK GDPR users)
Where GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for), legitimate interests (security, fraud prevention, improving the Service), consent (where required, e.g., certain cookies or marketing), and legal obligation.
5. How we share personal information
We share personal information only with:
- Service providers / subprocessors that help us run the Service (see §6).
- Professional advisers, auditors, and authorities where required by law or to protect our rights.
- A successor in a merger, acquisition, or sale of assets.
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law (CCPA/CPRA).
6. Subprocessors and service providers
We use the following providers, who process personal information on our behalf under contract:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | West US (Oregon) |
| Vercel | Application hosting | US (Washington D.C.) |
| Anthropic | AI features (model processing) | US |
| AWS Bedrock | AI features — private/enterprise tier | US |
| Stripe | Payment processing | US |
| Resend | Transactional email | US |
| Squarespace | Domain / DNS / marketing site | US |
AI provider data handling. Anthropic processes data submitted through the Service under its commercial terms: it does not train its models on that data, and inputs and outputs are deleted from its systems within its standard retention period — currently 30 days — except where longer retention is required by law or to enforce its usage policies. The Service is designed to minimise the data sent to AI providers; see our Data Processing Agreement for details.
A current list is maintained at www.brocktransform.com/subprocessors. We will update that page at least 30 days before a new subprocessor begins processing personal data; to receive email notice of changes, email admin@brocktransform.com with the subject "Subscribe: subprocessor updates".
7. International data transfers
We are based in the United States and our providers are primarily in the United States. Where we receive personal information from the EEA or UK, we rely on appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. You can request a copy via admin@brocktransform.com.
8. Retention
We keep account and billing data for as long as your account is active and for a reasonable period afterward to meet legal, tax, and accounting obligations; category-specific periods are in the table in §2. Personal information inside migration data (where we act as processor) is retained and deleted as described in the DPA: during an active subscription, per-project data is retained for 12 months after the project is completed or last active; after cancellation or termination, data is retained for 6 months to allow export, then deleted — unless you purchase extended retention or request earlier deletion. We notify your organisation's administrator before deletion.
9. Security
We use measures including tenant isolation, encryption of stored connection credentials, encryption in transit and at rest, and access controls. No system is perfectly secure; we cannot guarantee absolute security.
10. Your rights
California (CCPA/CPRA): you may request to know, access, correct, or delete your personal information, and to opt out of sale/sharing. We do not sell personal information or share it for cross-context behavioural advertising, and we do not use or disclose sensitive personal information for purposes that would trigger a right to limit. We will not discriminate against you for exercising these rights. You may designate an authorised agent to make a request on your behalf; we will verify the agent's authority.
Opt-out preference signals. Because we do not sell or share personal information, opt-out preference signals such as Global Privacy Control (GPC) do not change how we process your data; where the law requires us to treat such a signal as an opt-out request, we will honour it.
Other US states (e.g., Virginia, Colorado, Connecticut, Texas): where your state's privacy law applies, you may have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and profiling (we do none of these). If we decline a request, you may appeal by replying to our decision; we will respond within the period your state's law requires, and if we deny the appeal we will tell you how to contact your state attorney general.
EEA / UK (GDPR / UK GDPR): you may request access, rectification, erasure, restriction, portability, and may object to certain processing or withdraw consent. You may lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office).
To exercise any right, contact admin@brocktransform.com. We will verify your request before acting on it and respond within the timeframe applicable law requires.
11. Cookies
Our marketing site and app use cookies and similar technologies for functionality, security, and (where applicable) analytics. You can control cookies through your browser and any cookie banner we provide.
12. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their personal information.
13. Changes
We may update this Policy. We will post the new version with a revised "Last updated" date and, for material changes, provide notice.
14. Contact
Brock Data, Inc, Kalispell, Montana. Privacy questions: admin@brocktransform.com.