Privacy Policy
How Brunos handles personal data, who else processes it, and what you can ask us to do with it.
Effective 2026-08-01 · CMH Media Agency
Who we are
Brunos is operated by CMH Media Agency. This policy covers the Brunos application and the marketing site. It does not cover the advertising platforms you connect — those remain governed by your own agreements with them.
Written notices and requests reach us at privacy@cmhmediaagency.com, which is monitored and is the fastest route to a person.
What we hold
Enumerated rather than summarised, so you can check it against what the product actually asks you for.
| Name | Purpose | What it covers |
|---|---|---|
| Account identity | So you can sign in and your colleagues can see who you are | Email address, name, profile picture, preferred language and timezone, whether the terms were accepted and when, and whether marketing email was opted into. |
| Workspaces | So the product knows which organisation it is showing | Workspace name, URL slug, logo, website and default language. Nothing about a person. |
| Membership | So the right people reach the right workspace, and no one else does | Which workspaces an account belongs to, its role in each, and when it joined. |
| Invitations | So a colleague can be added, and the invitation cannot be reused | The invited email address, the role offered, who sent it, and whether it was redeemed. Codes expire after 14 days. |
What we deliberately do not hold
This is load-bearing rather than reassuring: it is what makes the retention and deletion sections below true.
- Advertising credentials. Access tokens are sealed by the broker and never stored by Brunos.
- Campaigns, ad sets, ads, creatives or performance metrics. These are read on demand from the connected platform and not copied.
- Payment card details. Brunos does not process payments directly.
- The contents of a connected advertising account beyond what is displayed in response to a request.
When you view campaign performance in Brunos, the figures are read from the connected platform at the moment you ask and are not copied into our database. Closing the page leaves no copy behind.
Why we hold it
- To provide the service — your identity and workspace membership are what let you sign in and see the right data. Without them there is no product.
- To keep it secure — sign-in records and audit information let us detect unauthorised access to a workspace.
- To contact you about the service — outages, security notices and changes to these terms. This is not marketing and cannot be opted out of while you hold an account.
- Marketing, only if you opt in — recorded explicitly, and withdrawable at any time without affecting anything above.
The legal basis for each purpose
- Performance of a contract — account identity, workspaces and membership. Without them there is no service to provide.
- Legitimate interests — security records and the approval ledger. Our interest is running the service safely and being able to say who authorised a change to an advertising account; we have weighed that against your interest in not being over-recorded, which is why the ledger holds the decision and not the conversation around it.
- Consent — marketing email, and only that. Withdrawable at any time with no effect on anything above.
- Legal obligation — records we are required to retain, kept separately from your profile.
Cookies
Brunos sets the cookies it needs to keep you signed in and to protect the sign-in form. They are strictly necessary: without them the application cannot tell one request from another, so there is nothing to consent to and nothing to switch off short of not using the product.
We do not set advertising or cross-site tracking cookies, and we do not embed third-party trackers in the application.
Children
Brunos is a business tool and is not directed at anyone under 18. We do not knowingly collect data from children; if you believe we have, tell us and we will delete it.
Who else processes it
These parties process data on our behalf and under contract. The second is the one most likely to be missing from a policy like this, and it matters most: Argus is not a hosting vendor. It holds the sealed advertising credential and performs every call to an advertising platform on your workspace’s behalf.
| Name | Purpose | What it covers |
|---|---|---|
| Supabase | Authentication and database hosting | Account identity, workspace membership and invitations. All application data at rest. |
| Argus (CMH Media Agency) | Advertising analytics broker | The sealed advertising-platform credential, and the questions asked of it. Argus performs every call to an advertising platform on the workspace's behalf and returns the results; Brunos never holds the credential itself. |
| Meta Platforms, Inc. | Advertising platform | Requests to read and modify the advertising accounts a workspace has explicitly connected, made under the authorisation that workspace granted. |
| Google LLC | Optional sign-in provider | Only the sign-in exchange, and only if a user chooses Google rather than an email and password. Name, email address and profile picture are received from it. |
| Slack Technologies | Optional alerting channel | Messages a workspace has configured Brunos to send, and the channel they are sent to. Only if the Slack integration is connected. |
We do not sell personal data, and we do not share it with advertisers or data brokers.
Advertising accounts you connect
Connecting an advertising account authorises Brunos to read it, and — where you grant that permission separately — to make changes to it. The authorisation is issued by the platform, sealed by our broker, and never stored by Brunos itself.
You can withdraw it at any time from the Integrations screen. Doing so revokes the authorisation with the platform and destroys our copy. It does not require deleting your account.
Where Brunos proposes a change to an advertising account, that change is applied only after an explicit human approval, and we record who approved it.
How long we keep it
- Account and workspace data: for as long as the account exists, and up to 30 days after deletion while it clears backups.
- Invitations: 14 days, after which the code expires and is no longer redeemable.
- Security and audit records: retained where we are legally required to, separated from your profile.
Your rights
You can ask us to show you what we hold, correct it, delete it, or export it. You can object to processing and withdraw consent. We will not charge you for this and we will not make you explain why.
Deletion has its own page with the exact process: brunos.cmhmediaagency.com/data-deletion.
For anything else, email privacy@cmhmediaagency.com. We acknowledge within 2 business days and respond within 30 days.
Security
Data is encrypted in transit and at rest. Access between workspaces is separated at the database level rather than in application code, so a bug in our software cannot show one customer another’s data. Advertising credentials are held sealed by our broker and are not readable by Brunos.
International transfers
Our processors operate infrastructure outside your country, so your data may be transferred and processed elsewhere.
Where a transfer leaves a country whose law restricts it, we rely on the safeguards that law provides — an adequacy decision where one covers the destination, and the European Commission’s Standard Contractual Clauses, or the equivalent instrument for your jurisdiction, where one does not. Each processor named above is engaged under a written agreement carrying those terms.
You can ask us which countries your workspace’s data is processed in at privacy@cmhmediaagency.com. We answer with the current regions rather than a list that goes stale in this document.
Changes
We will tell you before a material change takes effect, by email to the address on your account. Continuing to use Brunos after that date means the updated policy applies.
Contact
Privacy questions and requests: privacy@cmhmediaagency.com.
If you believe we have handled your data wrongly, tell us first — we would rather fix it than be told about it by a regulator. You keep the right to complain to the data protection authority of the country where you live or work, and doing so does not require our agreement or affect anything else you have asked us for.