Legal
Privacy policy
This page explains what the Digital Bricks Statement of Work generator does with personal data: the accounts of the staff who write documents, and the customer contacts named on the documents they write.
Last updated 17 September 2026
01Who is responsible
Digital Bricks B.V., Jacob Bontiusplaats 9, 1018 LL Amsterdam, Netherlands, is the controller for the personal data described on this page. You can reach us at max@digitalbricks.ai.
The Statement of Work generator is an internal application. Access to it is limited to Digital Bricks staff accounts created by an administrator. Customers never sign in: they receive a link to a single document.
02What we collect
Account data. Your name, work email address, role, a salted hash of your password, and the times at which you signed in or changed it. Passwords themselves are never stored and cannot be read by anyone, administrators included.
Customer details. The organisation name, registered address, registration number where applicable, and the name, job title and email address of the person the document is addressed to.
Document content. Everything recorded while a Statement of Work is configured: the services selected, delivery dates, commercial figures, and any wording a consultant writes or edits.
Signature records. When a customer accepts a document we record the signatory name, job title and email address, the signature they typed or drew, the moment of acceptance, and a cryptographic hash of the document exactly as it stood.
Technical records. The time of a request, the action taken, and a one-way hash of the originating IP address. Raw IP addresses are not written to the audit trail.
03Why we use it, and on what basis
To perform a contract. Preparing, issuing and concluding a Statement of Work, and keeping a record of what was agreed with whom.
Legitimate interests. Keeping the application secure, preventing unauthorised access to a customer document, and maintaining an audit trail that shows who did what.
Legal obligation. Retaining concluded agreements and the accounting information attached to them for the periods that Dutch law requires.
We do not use any of this data for advertising, we do not sell it, and we do not build profiles of the people named in a document.
04The company lookup
To save retyping, entering a company name can send that name to an Azure OpenAI deployment operated by Digital Bricks, which proposes a registered address and a public contact point. The result is a proposal with a confidence score and is never written to a document until a person confirms it.
The deployment is ours, inside our own Azure subscription. Content sent to it is not used to train any model. Every lookup is recorded in the audit trail, and the feature can be switched off entirely, in which case the details are typed by hand.
05Where it is stored, and who processes it
The application and its data run on Microsoft Azure in European regions. Microsoft acts as a processor on our instructions and under its own data protection terms.
Three Azure services are involved: a managed PostgreSQL database holding accounts, documents and the audit trail; blob storage holding an immutable archive copy of every published and accepted document; and Azure Communication Services, which sends the notification and password emails.
06How long we keep it
Drafts. Kept until an administrator deletes them. Deleting a draft removes the record, while the entry in the activity trail that says it existed remains.
Concluded agreements. Retained for as long as the engagement runs and afterwards for the period required by Dutch statutory retention and limitation rules.
Audit entries. Outlive the record they describe, because their purpose is to show what happened after the fact.
Accounts. Removed when the account is removed. An account that owns documents is disabled rather than deleted, so those documents keep a valid owner.
08Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, and object to processing based on legitimate interests. Where processing rests on a contract, you can ask for a portable copy.
Write to max@digitalbricks.ai and we will answer within one month. Requests that would require us to break a statutory retention rule, or to alter a document that has already been signed by both parties, are answered with an explanation rather than a change. If you are not satisfied, you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.
09How it is protected
Passwords are stored as salted scrypt hashes. Repeated failed sign-ins lock an account temporarily, and an unknown email address and a wrong password are indistinguishable from the outside.
Sessions are signed, httpOnly cookies with a limited life. A password change retires every outstanding password reset link.
A customer link carries a token in two halves and only a hash of it is stored, so the database alone cannot reconstruct a working link. Links stop working on the date set when they are issued.
The application authenticates to Azure storage and mail with a managed identity rather than with keys held in configuration.
10Changes to this policy
We update this page when the application changes in a way that affects personal data. The date at the top is the date of the most recent change, and earlier versions are available on request.