Legal

Privacy Policy

BridgeComp moves business data between the systems you connect, so this policy is specific rather than general: what is collected, what is stored, what the AI features send and never send, and what changes by deployment model. BridgeComp is operated by Priotech. [LEGAL REVIEW REQUIRED — COMPANY LEGAL ENTITY]

Draft This document requires review by qualified legal counsel before production publication. Statements here are written from the actual implementation; bracketed items are unresolved and must be settled by review.

This website

The public pages set no cookies, run no analytics or advertising scripts, and load nothing from a third-party domain — fonts, styles and images are served from this site. The web server keeps ordinary access logs (IP address, page, time, user agent) for operations and abuse handling.

The demo form. What you type is what we get: name, business email, company, the ERP and systems you named, your message, contact preference and phone if you gave one — plus the time, the plan or topic you arrived from, and the requesting IP address and user agent, which are kept for abuse handling only and are excluded from the views our team normally works from. Demo requests are used to prepare and run your demo and to reply to you. They are not sold, not shared with advertisers, and not loaded into a third-party marketing platform.

Account information

  • Profile: name, business email, role assignments and group memberships for each user your organization invites. There is no self-serve public sign-up.
  • Authentication: passwords stored only as argon2id hashes; two-factor enrolment secrets and one-time recovery codes; server-side session records. Passwords are never logged and never sent back.
  • Activity: sign-ins, configuration changes and operational actions are recorded in the append-only audit trail — actor, action, target, time.
  • Billing: BridgeComp itself contains no payment processing — no card data enters the platform. Subscriptions are invoiced under your agreement with us. [LEGAL REVIEW REQUIRED — BILLING RECORDS & INVOICING DATA]

Integration & automation data

You connect BridgeComp to third-party applications, APIs, databases and internal systems, and your flows move data between them. Different kinds of data are treated differently, and the distinctions matter:

  • Configuration data — stored. Your systems, groups, flows, field mappings and webhook endpoints, including the names you give them. Flow configuration is versioned, so previous configurations are retained and restorable.
  • Execution history — stored. Every job records the triggering payload and each step's request and response bodies, errors, durations and outcome. This is the product's core evidence trail — which means business data that crosses a flow is recorded in job history, inspectable for the window your plan provides. BridgeComp is not a copy of your ERP; documents pass through and are recorded, not replicated into a parallel database.
  • Correlation records — stored. Document references and line sets for orders a flow has sent, kept so confirmations can be matched line by line and duplicates prevented.
  • Automation metadata — stored. The audit trail, flow versions, alert history and job outcome statistics.
  • Transient processing. Mapping and transformation happen in memory during a job; intermediate values that are not part of a recorded step are not kept.

Connection credentials

Credentials for the systems you connect — API tokens, secrets, database passwords — are encrypted with AES-256-GCM before being written, under a key held in the deployment's environment and never in the database. No API returns a stored credential: they go in and are used to reach your systems; they do not come back out. The encryption key is validated at boot, and a database dump alone is not enough to use the credentials. Webhook tokens are stored only as SHA-256 hashes. Duplicating a connection for a test environment deliberately leaves the credentials blank.

AI processing

BridgeComp's AI features help administrators build automations. They are optional, available only to administrator roles, and flow execution never depends on them. The architecture is deliberate: AI drafts the automation; the deterministic runtime executes the approved version. Ordinary transactions are not sent through a model.

  • What is sent to the model provider: the text you type to the AI Builder or AI assistant (including the conversation so far), the name of the group you are working in, the names, kinds and identifiers of the systems in that group, the slugs of your existing flows, and the platform's own connector and mapping documentation. Note that system and group names are customer-chosen and can themselves be identifying — name a connection "Acme Production ERP" and the model provider sees that name.
  • What is never sent: credentials or secrets (field names from the connector catalogue only, never values), job payloads or execution history, the contents of your saved flow configurations, and the audit trail. Example documents shown during drafting are synthetic, generated by the model — the platform supplies no real records.
  • What is retained by BridgeComp: chat conversations are not stored on the server — they live in your browser for the session. Each AI call records only who used it, which model, and token counts, for quota and cost accounting. Prompt and response text is not stored and not logged.
  • Which providers: Anthropic and OpenAI are supported. If your organization connects its own provider account, AI traffic runs under that account and its terms; otherwise it runs under the platform's provider account. Provider retention and model-training practices are governed by the providers' own terms; we do not claim your prompts are never retained or never used for training unless that is contractually established. [CONTRACT REVIEW REQUIRED — AI PROVIDER RETENTION & TRAINING TERMS]
  • Voice input: dictation in the AI assistant uses your browser's built-in speech recognition, which may send audio to your browser vendor's speech service — that path is between your browser and its vendor, not through BridgeComp.
  • One deliberate exception: AI systems (OpenAI, Anthropic, and similar) also exist as ordinary connectors. If your organization explicitly configures a flow that targets one, that flow's mapped data goes to that provider at execution time — under your key, by your configuration, like any other target system.

Cloud vs on-premise

Where processing happens depends on the deployment model you choose. In every model the building experience is the same; what changes is whose machines do the work.

  • BridgeComp Cloud: the platform — configuration, encrypted credentials, execution engine, job history, audit trail, backups — runs on infrastructure we operate. We will tell you exactly which infrastructure and region a deployment uses; ask before your security review.
  • Private cloud: the same platform as a dedicated single-tenant instance — hosted by us in a region you choose, or on a virtual machine in your own cloud account. Data location follows the instance.
  • On-premise: the entire application — AI builder, management console, execution engine, database, job history, credentials, logs and backups — runs on machines you control. Two things leave your network, both outbound: the calls your flows make to cloud systems you connect, and — only if you enable it — the AI features' calls to the model provider as described above. Leave AI unconfigured and flows are built by hand; execution never needs it. We do not claim "your data never leaves your network": what leaves is determined by your flows and your AI configuration, and this policy tells you exactly which calls those are.

Retention

  • Backups: the deployment's database is dumped nightly and kept for 30 days; an offsite mirror is kept where configured. On-premise, backups run on your infrastructure and are yours to manage.
  • Job history and payloads: completed job records — including the payloads and per-step request/response bodies they carry — are purged automatically once they age past the deployment's retention window: 90 days unless your plan or agreement sets a different per-company value. In-flight jobs are never purged. Audit, AI-usage and demo-request records are not covered by this window and are retained until deletion is requested. [PRODUCT/LEGAL REVIEW REQUIRED — RETENTION FOR NON-JOB RECORDS]
  • Audit trail: retained for the life of the account — it is the record of who changed what.
  • AI usage records: who, when, model and token counts (no prompt text), retained for quota and cost accounting.
  • Demo requests: kept while the conversation is live; tell us if nothing comes of it and we delete it immediately.
  • Deleted accounts: at the end of a contract, deletion of the company's data is the default rather than something you must request. Deletion requests are honored from live systems; deleted data ages out of backups on the backup retention schedule.

Third parties & subprocessors

  • Systems you connect — ERPs, warehouses, storefronts, SaaS applications — receive the data your flows send them and are governed by their own privacy policies and terms. BridgeComp is the pipe you configured, not a party to those terms.
  • Infrastructure and technology providers we rely on to operate the service: hosting for managed deployments, AI model providers (Anthropic and/or OpenAI, as configured above), and an email delivery service where alert email is configured. A dedicated /subprocessors page with the named, current list is planned; no vendor will be listed there without being verified as actually in use. [LEGAL REVIEW REQUIRED — SUBPROCESSOR LIST & NOTIFICATION MECHANISM]
  • No analytics or tracking vendors. Neither this website nor the application embeds third-party analytics, advertising or session-recording services. The application sets strictly necessary cookies only: the session and its CSRF protection.

Your data, your rights

Your business data is yours. We receive only the rights needed to process automations as your flows direct, transmit data between your systems, provide and troubleshoot the service, maintain security, and meet legal obligations — and nothing here transfers ownership.

Ask us for a copy of what we hold about you or your organization, or ask us to delete it, and we will — job data, a whole company, or a demo request. Use the contact form or reach Priotech through priotech.co.il. Platform staff access tenant data only through the audited, banner-marked support mechanism described in the security overview.

Changes & contact

When this policy changes materially, account administrators are told before the change takes effect, and the date below always states the current version. Questions — including the data-processing questions a security review raises — reach us through the contact form; we would rather answer in specifics than imply.

Draft — last updated 2026-08-11 · requires legal review before production publication