Draft — pending legal review
This document is a working draft and is not yet effective. It has not been reviewed or approved by a lawyer and does not yet govern your use of Bright Ears.
Last updated: June 14, 2026
Who we are
Bright Ears Co., Ltd., a Thailand-registered controller
Bright Ears is an AI back office for wedding and event performer businesses. The contracting entity and data controller for this service is Bright Ears Co., Ltd., a company registered in Thailand (registration number 0105550096659). References to “Bright Ears”, “we”, “us” and “our” mean that entity.
Our home data-protection regime is Thailand’s Personal Data Protection Act (PDPA). Because Bright Ears Co., Ltd. is established in Thailand, the company is its own local presence under the PDPA. We also comply with the other regimes that apply to the people whose data we handle — the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and equivalent laws in Canada, Australia and elsewhere — as set out below.
The short version
The three roles we play
Privacy law assigns responsibility by role. Bright Ears sits in three roles depending on the data, and it is worth being precise about which is which:
- Your account data — we are the controller. The information you give us to run your subscription. This policy governs that data.
- Your leads’ and end-clients’ data — you are the controller, we are the processor. The inquiries and conversations that flow through the product. You (the performer business) decide the purposes; we handle that data only on your instructions, under the Data Processing Addendum. This privacy policy does not govern that data — the DPA does.
- Scraped venue and contact data for the proactive Hunt — we are the controller. When our venue-finding agent gathers publicly available business contact information about venues and event organisers, Bright Ears determines the purpose (helping our customers reach relevant venues) and is therefore the controller for that data. We carry our own lawful basis, our own transparency duty and our own deletion path for it — all set out below.
What we collect
The data we hold, and why
We collect the following categories of personal data:
- Account data (we are controller). Your name, email, business name, authentication credentials (via Clerk), billing details (held by Stripe — we do not store full card numbers), business profile, packages and rate card, voice samples, gig calendar and timezone, and your contact preferences. We use this to provide and bill the service.
- Leads’ contact details and inquiry content (you are controller; we process). Names, email addresses, phone numbers, event dates, venues and the free-text content of the inquiries and conversations that arrive at your forwarding address. We process this to parse, triage, draft replies, send messages on your behalf and run follow-up sequences.
- Scraped venue and contact details (we are controller). Where you enable the proactive Hunt, we gather publicly available business contact information about venues and event organisers — business names, public business email addresses (found on the venue’s own website or in public listings), websites, and the occasional named events/booking contact where a public source states one. We do not collect names from LinkedIn (we store only a profile link for the owner to use). See the indirect-collection notice below.
- Usage logs and AI/LLM cost records. Technical logs of how the product is used, and records of our processing cost per account. Our usage-cost table stores token counts only (no message content). The prompts and completions themselves transit our AI gateway (OpenRouter) to generate parses, triage decisions and drafts, and may contain the lead/inquiry or scraped content above; they are retained only transiently for that purpose (see Retention).
- Mailbox-send authorisation (optional). If you connect your own Google mailbox so the Hunt can send from it, we use a minimal-scope, send-only authorisation (gmail.send). We do not read your inbox; the token is stored encrypted.
Legal bases
The legal grounds we rely on, by regime
The applicable basis depends on both the data and the law that applies to the person. For identified bases under the GDPR (EU/UK), the PDPA and equivalents:
- Performance of a contract. Processing your account data to deliver the service and take payment (PDPA s.24(3); GDPR Art 6(1)(b)).
- Legitimate interests.Securing the service, debugging, fraud prevention, and measuring AI quality and cost (GDPR Art 6(1)(f); PDPA s.24(5)). And — for the proactive Hunt — processing publicly available business contact data to send relevant B2B outreach about our customers’ services. We have carried out a documented Legitimate Interest Assessment (LIA)for that scraped-contact cold outreach, weighing our and our customers’ interest in reaching relevant venues against each recipient’s rights and reasonable expectations, and we always honour an objection or opt-out (see below). You may request a summary of the LIA at info@brightears.io.
- Consent. Where a regime requires prior consent for a given activity (for example, cold email to recipients in jurisdictions such as Germany, Austria or Canada under our outreach rules), we either obtain it or do not carry out that activity automatically.
- Legal obligation. Where we must keep records (e.g. tax, accounting) or respond to lawful requests (GDPR Art 6(1)(c); PDPA s.24(6)).
- Processor instructions / your legal basis. For your leads’ data, we process on your documented instructions; you, as controller, are responsible for the lawful basis (see the DPA).
Indirect collection
Notice to people whose details we scraped (GDPR Art 14 / PDPA)
If you are an individual at a venue or event business and we have collected your business contact details from a public source rather than from you directly, this notice applies to you. It is the transparency information required by Article 14 of the GDPR and the equivalent PDPA duty for indirectly-collected data.
- Who holds your data: Bright Ears Co., Ltd. (Thailand), as controller. Contact info@brightears.io.
- What we hold:your business name and role where stated, a public business email address, your venue’s website, and short factual notes drawn from public sources (e.g. that the venue runs DJ nights).
- Source:publicly accessible web pages — the venue’s own website, public business listings, and press coverage — located via a search API. We only store an email address that literally appears on a page we fetched; we never guess or generate one.
- Why and on what basis:to introduce a relevant performer’s services to your venue (B2B outreach), relying on our legitimate interests backed by the LIA above.
- How long: see the retention periods below; scraped contacts are reviewed and purged on the schedule there, and immediately on a valid objection.
- Your rights: access, rectification, erasure, restriction, and — importantly — an absolute right to object to direct marketing. You can object or opt out in one step: reply to any outreach message and tell us, or email info@brightears.io. We will stop and add you to our suppression list.
Cold outreach
The proactive Hunt, and your right to object / opt out
Where a customer enables the Hunt, Bright Ears drafts and (with the customer’s approval, or via per-source automation they set) sends B2B pitches to venues and organisers using the publicly available business contact data above, relying on legitimate interests and the applicable electronic-marketing rules. Sending is governed by our per-recipient jurisdiction rules and our Acceptable Use & Anti-Spam Policy.
Anyone who receives this outreach can object to, or opt out of, further messages at any time — the right to object to direct marketing is absolute. Every outreach message identifies the sender and carries a clear opt-out, and a reply, a booking, a “dead” status or an opt-out hard-stops the sequence immediately. To opt out of all Bright Ears outreach across all customers, email info@brightears.io.
California
Your CCPA / CPRA rights (California residents)
For California residents, this is our notice at collection and our statement of practices under the California Consumer Privacy Act, as amended by the CPRA.
- We do NOT sell or share your personal information — not for money and not for cross-context behavioural advertising. Because we do not sell or share, we do not offer a “Do Not Sell or Share My Personal Information” link (one would falsely imply a sale takes place). We still honour browser Global Privacy Control (GPC) signals as an opt-out where applicable.
- Categories collected and purposesare described in “What we collect” above; this serves as the notice at collection.
- Your rights: to know, access, correct, delete, and to limit use of sensitive personal information, with no discrimination for exercising them. To make a request, email info@brightears.io.
- At our current scale Bright Ears is below the CCPA business thresholds, so many CCPA obligations do not yet apply to us — but we follow the practices above regardless. We will update this section if our scale crosses those thresholds.
Representatives
Our EU and UK representatives
Bright Ears is established in Thailand. We currently offer the service to customers in Thailand, the wider Asia-Pacific region and the United States, and we do not actively direct it at, or market it to, individuals in the EU or the UK. We have therefore not appointed Article 27 representatives at this time. If our activities grow to the point that the EU or UK GDPR requires it, we will appoint the required EU and UK representatives and name them here.
We have not appointed a Data Protection Officer: our core activities do not involve large-scale systematic monitoring of individuals or large-scale processing of special-category data, so a DPO is not mandatory at our current scale. We keep this under review, and privacy queries are handled by the contact below.
Who helps us
Sub-processors and service providers
We use the following service providers to operate Bright Ears. Each handles personal data only as needed to provide its service to us, under contract:
- Postmark — transactional and outbound/inbound email delivery for the reactive product.
- OpenRouter — AI/LLM gateway that routes prompts to language models for parsing, triage and drafting.
- Render — application hosting and managed PostgreSQL database.
- Clerk — authentication and session management.
- Stripe — subscription billing and payment processing (Stripe-hosted checkout and customer portal).
- Serper / Google Search — search API used to find publicly available venue/contact information for the Hunt.
- Google (Gmail API, OAuth) — send-only access to your own mailbox, where you connect one for the Hunt.
We keep this list current. If we add a sub-processor that materially changes how data is handled, we will update this page. The full processor-side terms, change-notice and objection rights are in the Data Processing Addendum.
Where data goes
International transfers from Thailand
Several of our providers process data outside Thailand, including in the United States and the EU. Thailand’s PDPC has not published an adequacy whitelist of approved destination countries, so we do not rely on adequacy. Instead, every cross-border transfer is made under appropriate safeguards — primarily the Standard Contractual Clauses(with the UK Addendum where UK data is involved) together with each provider’s own transfer mechanism. You can ask us for detail on the safeguards in place for a given provider.
How long
Retention periods
We keep personal data only as long as needed for the purpose it was collected for:
- Account data: for the life of your account, then deleted or anonymised within 90 days of account closure, except records we must keep for tax/accounting law (retained for the statutory period, typically up to 5–7 years, then deleted).
- Leads’ / end-client data: retained per your instructions and the DPA for the term of your subscription, then deleted or returned at your choice; on account closure, deleted or anonymised within 90 days unless you ask for an export first.
- AI/LLM prompt & completion content: not stored in our database. It transits the gateway only to produce the result and is held transiently; our gateway’s logs are configured for a short retention window (target ≤30 days) after which they are purged. Our own usage-cost table stores token counts only — no message content.
- Scraped venue/contact data: retained only while a contact remains a live prospect; reviewed and purged when stale (target: removed within 12 months of last activity), and deleted promptly on a valid objection or opt-out. Opt-out/suppression records are kept (minimal: an email and a reason) for as long as needed to keep honouring the opt-out.
Your rights
Access, correction, deletion and how to request (DSAR path)
Depending on where you live, you may have the right to access, correct, delete, port, restrict or object to the processing of your personal data, to withdraw consent, and (for scraped contacts) an absolute right to object to direct marketing. To exercise any of these — including a data subject access request (DSAR) or an erasure request — email info@brightears.io. We respond within the timeframe required by applicable law (for example, 30 days under the GDPR/UK GDPR, extendable where permitted; without undue delay under the PDPA). We may need to verify your identity first.
If your data was given to a performer business that uses Bright Ears (i.e. you are their lead or client), that business is the controller; we will route your request to them and assist them as their processor. For data where Bright Ears is the controller — your account data and scraped venue contacts — we action the request directly.
If something goes wrong
Data breaches
If a personal data breach occurs that is likely to result in a risk to people’s rights, we will notify the relevant authority within 72 hoursof becoming aware of it — the Thai PDPC under the PDPA, and the competent GDPR supervisory authority where EU/UK data subjects are affected — and will inform affected individuals where the law requires. As a processor for your leads’ data, we notify you without undue delay so you can meet your own obligations.
Cookies
Cookies and similar technologies
Bright Ears uses strictly-necessary cookies only — primarily authentication/session cookies set by Clerk and security cookies (e.g. CSRF protection). We do not use advertising or cross-site tracking cookies, and our payment and checkout pages are Stripe-hosted (their cookies are set on Stripe’s domain, not ours). See the Cookie Policy for the per-cookie detail.
Contact
How to reach us
Questions about this policy, or about how your data is handled, can be sent to info@brightears.io. EU and UK data subjects may also contact our respective representatives named above. You also have the right to lodge a complaint with the Thai PDPC or your local supervisory authority.