Privacy Policy
Overview
Brevwork ("we," "us," "our") is a sole proprietorship operated in Ontario, Canada by Mike Heintzman. We provide AI-powered professional services and digital products. This Privacy Policy explains what personal information we collect, how we use it, and your rights regarding that information.
We are committed to protecting your privacy. We collect only what we need, we do not sell your data, and we are transparent about how AI is used in our operations.
What Information We Collect
Information You Provide Directly
- Contact information — Name, email address, and business name when you contact us, sign up for our newsletter, or purchase a product or service.
- Payment information — Billing details processed through Stripe. We do not store your credit card number; Stripe handles this securely.
- Project information — Files, instructions, briefs, and other materials you provide when engaging our services.
- Communications — Emails, messages, and any other correspondence between you and Brevwork.
Information Collected Automatically
- Website analytics — We use Plausible Analytics, a privacy-friendly analytics tool that does not use cookies and does not collect personal data. We see aggregate data such as page views, referral sources, and general geographic region (country level).
- Essential cookies — Minimal cookies required for payment processing (Stripe) and basic website functionality. See our Cookie Policy for details.
Information We Do Not Collect
- We do not collect data from minors (under 18).
- We do not use tracking cookies or advertising pixels.
- We do not build user profiles for advertising purposes.
- We do not purchase data from third-party brokers.
How We Use Your Information
We use personal information for the following purposes:
- Delivering services — To complete the work you have hired us to do, including processing your materials through AI tools to produce deliverables.
- Processing payments — To charge for services and products via Stripe.
- Communication — To respond to inquiries, provide project updates, and send transactional emails (receipts, delivery confirmations).
- Newsletter — If you subscribe, to send you our newsletter via Beehiiv. You can unsubscribe at any time.
- Improving our services — To understand how our website and services are used in aggregate (via Plausible Analytics) so we can improve them.
- Legal obligations — To comply with applicable laws, including Canadian tax reporting requirements.
AI Processing
Brevwork uses AI tools (specifically Claude, developed by Anthropic) to deliver services. This means:
- Project materials you provide may be processed by AI as part of service delivery.
- We do not use your data to train AI models. Anthropic's commercial API does not use customer inputs for model training.
- All AI-generated deliverables are reviewed by a human before delivery.
- See our AI Disclosure for full details.
Third-Party Services
We share personal information only with the following third-party services, and only as necessary:
| Service | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Stripe | Payment processing | Name, email, billing address, payment method | stripe.com/privacy |
| Beehiiv | Email newsletter | Email address, name (if provided) | beehiiv.com/privacy |
| Plausible Analytics | Website analytics | No personal data (aggregate only) | plausible.io/privacy |
| Anthropic (Claude) | AI service delivery | Project materials as needed for service delivery | anthropic.com/privacy |
| Payhip / Gumroad / Etsy | Digital product sales | Name, email, purchase details | See each platform's privacy policy |
We do not sell, rent, or trade your personal information to anyone.
Data Retention
We retain personal information only as long as necessary for the purposes described above:
- Project files and deliverables — Retained for 12 months after project completion, then deleted unless you request otherwise.
- Payment records — Retained for 7 years as required by Canadian tax law.
- Email newsletter subscribers — Retained until you unsubscribe.
- Website analytics — Plausible retains aggregate (non-personal) data indefinitely.
- Communications — Retained for 24 months after last contact, then deleted.
You can request earlier deletion at any time (see Your Rights below).
Cookies
We use minimal cookies. Our website analytics (Plausible) are cookie-free. The only cookies used are essential cookies for payment processing and basic site functionality. See our full Cookie Policy for details.
Your Rights
For All Customers
Regardless of where you are located, you can:
- Access — Request a copy of the personal information we hold about you.
- Correction — Ask us to correct inaccurate information.
- Deletion — Ask us to delete your personal information (subject to legal retention requirements).
- Withdraw consent — Unsubscribe from our newsletter or withdraw consent for any non-essential data processing.
PIPEDA Rights (Canadian Customers)
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access your personal information held by us.
- Challenge the accuracy and completeness of your information.
- Withdraw consent for the collection, use, or disclosure of your information (subject to legal or contractual restrictions).
- File a complaint with the Office of the Privacy Commissioner of Canada if you believe your rights have been violated.
GDPR Rights (EU/EEA Customers)
If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):
- Right of access — Obtain confirmation of whether we process your data and receive a copy.
- Right to rectification — Have inaccurate data corrected.
- Right to erasure ("right to be forgotten") — Request deletion of your data.
- Right to restrict processing — Limit how we use your data.
- Right to data portability — Receive your data in a structured, machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Where processing is based on consent, withdraw it at any time.
Legal bases for processing (GDPR):
- Contract performance — Processing project materials to deliver services you have purchased.
- Legitimate interest — Communicating with you, improving our services, basic analytics.
- Consent — Sending marketing emails (newsletter).
- Legal obligation — Tax record retention.
To exercise any of these rights, contact us at the address below. We will respond within 30 days.
Data Security
We take reasonable measures to protect your personal information:
- All data transmission is encrypted via HTTPS/TLS.
- Payment processing is handled by Stripe, which is PCI DSS compliant.
- Access to client data is limited to Mike Heintzman (business owner) and AI tools used under his direction.
- We use strong, unique passwords and multi-factor authentication on all business accounts.
No method of transmission or storage is 100% secure. If we become aware of a data breach affecting your personal information, we will notify you and relevant authorities as required by law.
International Data Transfers
Brevwork is based in Ontario, Canada. If you are located outside Canada, your information may be transferred to and processed in Canada. Canada has been recognized by the European Commission as providing an adequate level of data protection.
Some of our third-party services (Stripe, Anthropic, Beehiiv) may process data in the United States. These transfers are governed by each provider's data processing agreements and applicable safeguards.
Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child, we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. For significant changes, we will notify you via email or a prominent notice on our website.
Contact Us
For privacy inquiries, data access requests, or complaints:
Brevwork
Mike Heintzman
Ontario, Canada
Email: privacy@brevwork.ca
We aim to respond to all privacy inquiries within 30 days.
If you are not satisfied with our response, you may contact:
- Canada: Office of the Privacy Commissioner of Canada — priv.gc.ca
- EU: Your local data protection authority