Privacy Policy
Last updated 12 September 2026
1. Who is responsible for your data
PINTERIOR DESIGN SRL, trading as Capacity Brain, company registration number J2026029937004, Str. Leon Cehovschi, nr. 20A, Sadova, Suceava, 727470, Romania, is the data controller for personal data processed through Capacity Brain. Where the EU General Data Protection Regulation applies, we act as controller for account and service data, and as processor-like host for the business content you choose to enter about your own clients and collaborators.
This policy is written to GDPR-grade transparency standards and applies internationally. Individual rights and obligations described here apply where, and to the extent, the relevant law applies to you.
2. Data we collect
- account name and email address;
- authentication information (password hashes held by our authentication provider, sign-in sessions, sign-in provider identifiers);
- workspace name and business configuration such as working hours, buffers and thresholds;
- team member and collaborator records you create, including names, roles and rates;
- project, phase, service, schedule and pipeline information you enter;
- subscription status, plan, billing period and payment-provider identifiers;
- support requests and product feedback you send us;
- non-identifying product usage events (which screen or action, never client names, notes, rates or money values);
- technical information such as browser and device type, IP address where technically required, and security and error logs;
- cookie and local-storage identifiers strictly needed to keep you signed in.
We do not collect or store full card numbers. Card and payment details are handled by Paddle as Merchant of Record.
3. Confidential business information
Capacity Brain is designed for commercially sensitive planning data: collaborator rates, internal costs, project values, profitability estimates and schedules. We process this data to provide the service to you, keep it isolated to your workspace, and do not sell it or use it for advertising.
4. Why we process data
- to create and operate your account and workspace;
- to authenticate you and keep sessions secure;
- to perform capacity, workload, cost and profitability calculations you request;
- to manage subscriptions, entitlement and billing status;
- to prevent fraud, abuse and unauthorised access;
- to provide support and respond to your messages;
- to maintain, debug and improve the service;
- to comply with legal and accounting obligations.
5. Legal bases (where GDPR or similar law applies)
- Performance of a contract — providing the application, your subscription and support;
- Legitimate interests — security, fraud prevention, service reliability and product improvement, balanced against your rights;
- Legal obligation — record keeping and responding to lawful requests;
- Consent — only where we ask for it, for example optional communications. You can withdraw consent at any time.
6. Service providers we use
- cloud hosting and application infrastructure;
- managed database, authentication and file storage;
- Paddle, as Merchant of Record, for checkout, subscription billing and tax handling;
- transactional email delivery for account and subscription messages;
- error and availability monitoring.
We do not use advertising networks or marketing trackers. Providers act on our instructions under contract, and may only process data as needed to deliver their service. We also share data with professional advisers or authorities where required by law.
7. International transfers
Our providers may process information in countries other than your own, including outside the EEA. Where GDPR applies and data is transferred to a country without an adequacy decision, we rely on the transfer mechanism offered by the relevant provider, such as standard contractual clauses where that provider makes them available.
8. Retention
We keep personal data only as long as needed for the purposes above. Account and workspace data is kept while your account exists, and for a limited period after a subscription ends so you can resubscribe or export it, after which it is deleted or anonymised. Records we must keep for legal, tax or dispute purposes are retained for the period applicable law requires. Security and error logs are kept for a short period appropriate to their purpose.
9. Security
We apply reasonable technical and organisational measures, including encryption in transit, encrypted storage at our infrastructure provider, per-workspace access isolation enforced on the server, role-based permissions, least-privilege access for administrators and audit logging of sensitive actions. No system can be guaranteed completely secure. We do not claim ISO 27001, SOC 2, HIPAA or PCI certification of our own.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent. To exercise a right, contact us through the Contact & Support page. We may need to verify your identity, and we respond within the period applicable law requires — within one month where GDPR applies.
11. Complaints
If you are in the EEA you may lodge a complaint with your local data protection supervisory authority. As we are established in Romania, the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) is competent for us, but this does not restrict your right to complain to the authority in your own country where applicable law allows.
12. Cookies and similar technologies
Capacity Brain uses only strictly necessary cookies and browser storage: keeping you signed in, keeping your session secure, and remembering interface state such as whether the navigation is expanded. We do not use advertising, marketing or third-party analytics cookies, so no consent banner is presented. Usage measurement inside the application is limited to non-identifying product events stored in your own workspace.
If we ever introduce optional analytics or marketing cookies, we will publish a Cookie Policy and ask for consent before loading them where consent is legally required.
13. Children
Capacity Brain is a professional business tool and is not intended for children. We do not knowingly collect data from children.
14. Automated recommendations
The product produces calculations, scores and recommendations — for example collaborator suitability or capacity warnings — to support your judgement. These are shown with the figures behind them and never make a binding decision about a person. Final decisions remain with you as the user.
15. Region-specific supplements
This policy is the global baseline. Where additional obligations apply to us in a specific jurisdiction — for example California or other U.S. states, the United Kingdom, Canada or Australia — we will add a supplement to this policy for that region rather than replacing it. We do not claim compliance with a regime before confirming that it applies to us.
16. Changes
We may update this policy. The current version is always published here with its date, and we give notice of material changes by email or in the application.