Compliance
Last updated: 2026-06-01. Owner: Cagdas Arda — privacy@brewyard.ai.
Brewyard is operated by Fincard Ltd (England and Wales). This page summarises the four pillars enterprise buyers and Anthropic Partner Network reviewers ask about. Business customers can request the full evidence pack, including our DPIA and Anthropic terms mapping, at privacy@brewyard.ai.
1.GDPR
UK GDPR + EU GDPR-compliant. Brewyard acts as data processor for project content, agent prompts/responses, and stored API credentials, and as data controller for billing identifiers, account identifiers, and operational telemetry.
- Data controller
- Fincard Ltd, England and Wales. Contact: privacy@brewyard.ai.
- Sub-processors
- Full Article 28 list with legal entity, region, DPA URL, and certifications at /sub-processors. 14-day written notice before any material change.
- DPA template
- Customers on paid plans receive Brewyard's standard Data Processing Addendum on request. Email privacy@brewyard.ai with your legal entity name; we send the countersignature flow within two business days.
- Data subject rights
- Self-service export and delete are wired into
/dashboard/account(closed beta — admin-only at launch, self-service in Phase 3). Until then, email privacy@brewyard.ai and we respond within the GDPR 30-day window. - Breach notification
- 72-hour notification to the ICO and affected customers in the event of a personal data breach, per UK GDPR Art 33/34. Our incident runbook is reviewed quarterly.
2.DPIA
Brewyard's Data Protection Impact Assessment classifies the BYO-key model, the per-user runtime sandbox, and the audit-logging posture as low residual risk after mitigations. The DPIA is filed internally and reviewed each time a sub-processor or data flow changes.
- Scope
- Account data, workspace metadata, agent prompts/responses, Anthropic API credentials. Card data is explicitly out of scope — it never touches Brewyard infrastructure (Stripe handles the redirect).
- Risk vocabulary
- Sub-processor outage, credential leak from KV, runtime cross-tenancy, model-output exfiltration. Each carries a documented mitigation and an owner. See the DPIA in the repo for the full table.
- Architectural evidence
- The full data-flow diagram, including the load-bearing "user's own key in the header" edge to Anthropic, is at /data-flow.
3.UK region
All Brewyard compute and storage runs in Azure UK South (London). Everything Brewyard stores stays in that region. What the runtime sends to Anthropic on your own key is a separate layer with a separate contract behind it — pillar 4 sets the two apart.
- Compute
- Azure Container Apps revisions (Next.js BFF, FastAPI, per-user TeamForge runtime) all deployed to UK South. No cross-region failover at launch — that change would trigger a sub-processor notice and a DPIA refresh.
- Storage
- Postgres Flexible Server (UK South), Azure Key Vault (UK South) with RBAC-only access and every read written to an audit log, Azure Files mount (UK South). Database backups stay in the UK: in UK South, with a geo-redundant copy in the paired UK West region.
- Outbound calls that leave the region
- By design, two: (a) the per-user runtime calling
api.anthropic.comwith the customer's own credentials — governed by the customer's direct Anthropic contract; and (b) transactional email via Resend (US, EU-US DPF certified). Both are listed at /sub-processors.
Evidence
4.Where your data actually sits
Three different things happen to the material you put into Brewyard, and two different contracts govern them. Keeping them apart is the point of this section: one sentence about “where the data is” would be either wrong or useless.
- Layer 1 — what Brewyard stores
- Your workspaces, briefs, agent output, files and audit trail. These are stored in Azure UK South (London). If we ever open an EU region, this page will say so on the day it changes. This layer sits under our agreement with you: our Data Processing Agreement, our sub-processor list, our data-flow diagram. It is the layer Brewyard can make commitments about, and the only one.
- Layer 2 — what travels to Anthropic
- To run a team, the runtime sends your brief and the agents’ working context to
api.anthropic.comusing the Anthropic API key you connected. That traffic authenticates as you — your Anthropic account, your rate limits, your bill — and it is processed by Anthropic in the United States. Brewyard runs the call on your behalf as an operator-agent; the contract behind it is your own with Anthropic, not ours. - Layer 3 — what Anthropic keeps
- Anthropic stores and retains API traffic under its own terms with you. We deliberately state no retention periods here: they are Anthropic’s to set and to change, and a figure copied onto this page would be a promise we cannot keep on someone else’s behalf. Read them at the source — Anthropic’s privacy centre and its commercial terms.
- The record that the key is yours
- Anthropic’s terms do not allow sharing API credentials, so when you connect a key you confirm it belongs to your own Anthropic Console account. That confirmation is not a checkbox that disappears: the timestamp and the exact version of the wording you agreed to are written to the key’s row, with an audit entry for every submission and every rotation. If anyone asks who authorised the traffic in layer 2, the answer is a record rather than a recollection.
Contact
Compliance, DPA, security questionnaire, or vendor-due-diligence questions go to privacy@brewyard.ai. Two-business-day response target.