Privacy Policy

Last Updated: April 15, 2025

Bruno Privacy Policy

Bruno ("we", "us" or "our") is committed to protecting your privacy and ensuring the security of personal information. This Privacy Policy explains what personal data we collect, how we use and disclose it, and your rights regarding that data when you use the Bruno platform or any related services (collectively, the "Service"). Bruno operates in Canada and follows applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA). By using Bruno, you consent to the practices described in this Privacy Policy.

This Privacy Policy applies to all users of the Bruno Service, including real estate professionals using the platform and any individuals (such as clients of those professionals) whose personal information is provided to Bruno through the Service. It also applies to our website visitors if they provide personal data (for example, via a contact form). This policy does not cover any third-party websites or services that may be linked through Bruno; those are governed by their own privacy policies.

We have structured this Privacy Policy into several sections for clarity. Please read this document carefully to understand our policies and practices regarding your personal information.

Personal Information We Collect

Personal information means information about an identifiable individual. Bruno collects personal information that is necessary for the purposes of providing and improving our Service. The types of personal data we may collect include:

Account Information (User Data)

When you sign up for Bruno, we collect information such as your name, email address, phone number, company or brokerage name, professional title/role, and any profile details you provide. We also collect login credentials (such as your password, which is stored in a hashed form) and any preferences or settings you configure on your account.

Client Information

If you use Bruno to manage your clients and referrals, you may input personal information about your clients. This can include your clients' names, email addresses, phone numbers, postal addresses, and details related to their service needs or property (for example, the type of service they require, notes on their situation, or appointment details). Bruno will collect and store the client information that you enter or upload. Please ensure that you have your client's permission or a lawful basis to share their data with Bruno (see "Legal Basis and Consent" below).

Service Provider Information

Bruno's platform may contain entries for service providers (e.g. contractors or vendors). Typically, these are businesses or professionals and not personal information. However, if any of the service providers are individual persons (sole proprietors), the information (such as name, contact details, professional credentials) could be personal data. Bruno may collect this information either from the user input (when you add a provider to recommend) or from the providers themselves if they create a profile. We do not collect sensitive personal details about providers beyond contact and service-related info.

Usage Data

  • Technical Information: such as your IP address, browser type and version, device identifiers, operating system, and device type (e.g. desktop, mobile).
  • Activity Logs: details of your usage, like when you log in, features you use, pages or screens you visit, clicks and actions on the platform, and the referral shares you create.
  • Cookies and Similar Technologies: Bruno uses cookies, web beacons, or similar tracking technologies to enhance user experience and gather usage statistics. You can set your browser to refuse some cookies or alert you when cookies are being used, but this may affect platform functionality.

Support and Communication

If you contact us for support or with an inquiry, we will collect the information you choose to give us (such as your contact information and a description of your issue or question). We may also keep records of our correspondence with you. Similarly, if we reach out to you (for example, sending an email notification or responding to a support ticket), we may track your interactions with those communications (such as whether you opened an email).

We aim to limit the personal information we collect to only that which is needed for the purposes set out in this Policy. You always have the choice not to provide certain personal information; however, doing so might limit your ability to use some features of Bruno. For example, if you choose not to provide a client's contact information, you won't be able to use Bruno to email recommendations to that client.

How We Use Personal Information

Bruno uses the collected personal information for the following purposes, which are reasonable and necessary in the context of providing a B2B referral platform:

  • To Provide and Maintain the Service: We process your personal data to authenticate you when you log in, to display your content (like your list of clients or recommended providers), and to enable you to share recommendations with your clients. For example, we will use a client's email address to send them a recommendation list on your behalf if you choose to do so. We also use personal data to maintain and administer the platform (such as backing up data, preventing crashes, and securing your information).
  • To Facilitate Communication: We use contact information (your email, and your client's email if provided) to send necessary communications. This includes sending verification emails, notifications about referrals (e.g. "Your realtor has shared a list of providers with you"), updates about platform features, or important service alerts (such as security or downtime notices). We may also use your phone number if provided for account security (e.g. two-factor authentication via SMS) or urgent issues.
  • To Improve and Develop the Service: Usage data and feedback are used to understand how our users interact with Bruno so we can improve functionality and user experience. For instance, we analyze which features are most used or where users encounter errors, so we can optimize those areas. We might use aggregated data to develop new tools or features that benefit our users. Any analytics we perform on personal data are typically done in an aggregate or de-identified manner (we remove or anonymize personal identifiers) whenever feasible.
  • To Provide User Support: Information you provide in support requests (and relevant account or usage info) will be used to help resolve your issue or answer your questions. We may also use your feedback or support queries to fix problems and enhance Bruno.
  • Analytics and Usage Tracking: We use third-party analytics services (such as Google Analytics or PostHog) to collect and analyze usage information, helping us understand user behavior and preferences. These services may use cookies and similar technologies (as described above) to gather usage data and report trends. Analytics data is generally in aggregate form and does not focus on individual user identities, though some analytic tools might record user session information. We use this data internally to make informed decisions about improvements and to monitor the health of our Service.
  • Marketing and Updates (Opt-In): Bruno may occasionally send you informational newsletters, product updates, or promotional communications about new features if you have consented to such communications or if you are an existing user and applicable laws allow. For example, as a registered user, we might email you tips on using Bruno or notify you of new functionality. You will have the opportunity to opt out of marketing emails at any time by clicking the unsubscribe link in any such email or by adjusting your email preferences in your account settings. (Transactional or service-related communications, such as security alerts or password resets, cannot be opted out of, as they are necessary for service usage.)
  • Ensure Security and Prevent Misuse: We may use personal information (like account IDs and logs) to monitor for suspicious or fraudulent activity, to verify accounts, and to enforce our Terms and Conditions. This includes reviewing logs in case of suspected violations or investigating incidents. If we detect potential security threats or misuse of the Service, we may use relevant personal data to mitigate and address these issues (e.g. blocking an IP address that is hammering our server, or contacting a user if their account appears compromised).
  • Legal Compliance: We will use and disclose personal information as necessary to comply with our legal obligations. For instance, to respond to a court order or lawful request by public authorities (more details in "Disclosure" section), to meet tax and accounting requirements, or to assert our legal rights or defend against legal claims.

Bruno will not use personal information for purposes other than those described above without obtaining your consent, unless otherwise required or permitted by law. We do not engage in automated decision-making or profiling that produces legal effects concerning individuals, outside of typical filtering or sorting that occur within the platform's functionality as directed by users.

Disclosure of Personal Information

Bruno is not in the business of selling or renting personal data. We only share personal information in the ways described here, in order to provide our Service, with your consent, or as required by law. The circumstances under which we may disclose personal information include:

Service Providers (Third-Party Processors)

We employ third-party companies and individuals to facilitate our Service, perform functions on our behalf, or provide services to us (collectively, "Service Providers"). These third parties process personal information only under our instruction and for the purposes listed in this Policy. Examples include:

  • Cloud Hosting and Storage: We may host data (including your and your clients' personal info) on cloud infrastructure provided by reputable providers (e.g. Amazon Web Services or Microsoft Azure). These providers store data and backups securely on our behalf.
  • Analytics Services: As noted, we use analytics providers that may process certain usage data and device information to generate usage insights (e.g. Google Analytics processes pseudonymous user interactions).
  • CRM and Communication Tools: We might use a customer relationship management (CRM) system or email service (e.g. SendGrid, Mailchimp, or HubSpot) to manage contacts and send communications. If you receive emails from Bruno, a third-party emailing service will necessarily process your email address and the content of the email for delivery.
  • Other IT or Support Services: We could use third-party tools for things like error logging (which might capture user IDs or device info when an error occurs), or customer support ticketing systems that store your requests.

These Service Providers are given access to personal information only to the extent needed to perform their functions, and they are contractually obligated to keep the information confidential and secure. We ensure that any third party handling personal data on our behalf provides a level of protection comparable to PIPEDA requirements. Our service providers are typically bound by data processing agreements that restrict their use of personal data solely to providing services to Bruno and our users.

With Other Users (Your Clients or Team)

The Bruno platform is designed to share information at your direction. If you choose to share content or recommendations with a client (for example, by sending them a link or email through Bruno), the personal information necessary for that action will be disclosed to the intended recipient. For instance, if you prepare a recommendation list for Client A and enter Client A's email to send it, Bruno will send an email to that address, which necessarily discloses your name and the fact that you have shared information via Bruno. Likewise, any notes or messages you include in the recommendation will be visible to that client.

In summary, Bruno will disclose personal information to third parties when you intentionally use the Service to do so (i.e., sharing between users and their clients as part of the platform's functionality). We do not otherwise share your clients' information with other Bruno users or any service providers listed on the platform, unless explicitly directed by you or your client. For example, Bruno will not automatically send your client's contact info to a recommended provider unless you or the client take an action to do so.

Business Transfers

If Bruno (or its owning company) is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, personal information may be transferred to a successor or affiliate as part of that transaction. We would ensure that any such entity continues to handle your personal information in accordance with this Privacy Policy or provide notice and possibly request your consent if required by law. In the event of a change of ownership, we will strive to notify users of the transfer of personal data and the implications for privacy.

Legal Requirements and Safety

We may disclose personal information if required to do so by Canadian law or pursuant to a valid request by lawful authorities (such as a subpoena, court order, or government demand). We may also disclose personal information in the good faith belief that such action is necessary to:

  • Comply with a legal obligation or regulatory requirement.
  • Protect and defend the rights, property, or safety of Bruno, our users, or the public. This could include exchanging information with other companies and organizations for the purposes of fraud protection or investigating security breaches.
  • Investigate and respond to claims or allegations against Bruno, or to enforce our Terms and Conditions. For example, if a dispute arises and personal data is needed to address it (such as logs to show what actions were taken in the platform), we might need to share relevant data in legal proceedings.

With Consent

Aside from the cases above, if we ever need to share your personal information with a third party for a new purpose, we will do so only with your consent. For instance, if Bruno wanted to publish a user testimonial or case study that includes personal info, we would seek your approval. Or if we develop an integration that sends data to another app not covered by this Policy, we would let you opt-in to that connection.

In all cases of disclosure, we always aim to minimize the amount of personal data shared to only what is necessary for the specific purpose. When personal information is disclosed to third parties (including service providers), we take steps to ensure those parties implement appropriate privacy and security measures.

International Data Storage and Transfers

Bruno is based in Canada, but we may use cloud services or processors located in other countries (for example, the United States) to store and process data. Personal information may therefore be transferred to, or stored in, a jurisdiction outside of your own, including the USA or other countries that may have different data protection laws than Canada. In particular, data stored on cloud servers in other countries may be subject to lawful access requests by courts, law enforcement, or other authorities in those jurisdictions.

However, in all cases, Bruno will ensure protection of personal data in line with PIPEDA requirements. When personal information is transferred outside of Canada, we will rely on contractual safeguards (such as standard data protection clauses) and the policies of our service providers to ensure that your information remains protected.

By using Bruno and providing personal information, you understand and consent that your data may be stored or processed in other countries as explained. If you prefer or require your data to be stored only in Canada, please contact us to discuss any available options – we will do our best to accommodate reasonable requests, though our primary infrastructure may involve cross-border processing.

Data Retention

Bruno retains personal information only for as long as necessary to fulfill the purposes for which it was collected, or to comply with legal or business requirements. This means:

Account Data

We keep your account information and content for as long as your account is active. If you delete your account (or if we terminate it), we will initiate the process of deleting or anonymizing the personal data associated with your account. In active accounts, we may retain data until you choose to delete it (for example, you can remove or update client entries at any time).

Client and Referral Data

Information about your clients and any records of referrals or recommendations are retained so that you (and your client, if they have access) can reference them. If you delete a client's data or a referral entry, we will remove it from the active database; however, it might remain in our secured backups for a short period until those backups naturally cycle out. We periodically purge or anonymize data that is no longer needed. If you simply stop using Bruno, we may eventually delete your clients' personal information after a period of prolonged inactivity, but we will attempt to contact you before doing so.

Communications

Emails and support communications may be kept for a period of time (to allow us to reference past correspondence if you reach out again, and to improve our support processes).

Legal and Backup Retention

We may retain certain information for longer if we are obliged to do so for legal reasons. For example, if a law requires us to keep certain records for a set time (such as financial records or records of consent), we will comply. We may also retain information as needed to resolve disputes, enforce our agreements, or protect our legal rights. Even after you delete your account or personal data, we might retain data for a limited time in backups or archives that are not immediately active. We secure any retained data and isolate it from routine use.

Once personal information is no longer necessary or relevant for the identified purposes, or once you request deletion (and we have no other legal basis to keep it), we will either securely delete, destroy, erase, or anonymize the information. We strive to ensure that our retention practices comply with PIPEDA's principles of limiting use, disclosure, and retention.

Protection of Personal Information (Security)

Bruno takes the security of personal information seriously. We implement administrative, technical, and physical safeguards that are appropriate to the sensitivity of the personal data in our custody. These measures are designed to protect your personal information against loss or theft, as well as unauthorized access, use, copying, disclosure, alteration, or destruction. Some of the security practices we employ include:

  • Encryption: We use encryption to protect data in transit and at rest. For example, our website and app use HTTPS (TLS encryption) for all data transfer, and sensitive data in our databases is encrypted or hashed (like passwords).
  • Access Controls: We restrict access to personal information to employees, contractors, and service providers who need to know that information in order to operate, develop, or improve our Service. Those who have access are bound by strict confidentiality obligations. Our staff are trained on the importance of privacy and are required to adhere to our privacy and security policies.
  • Network and System Security: Our servers are protected by firewalls and monitoring systems. We regularly update our software and apply security patches to address potential vulnerabilities. We may employ intrusion detection and prevention systems to alert us of suspicious activities.
  • Testing and Assessments: We periodically test and assess our security measures (for example, through security audits or penetration testing by qualified experts) to ensure our systems are robust.
  • Data Minimization: We only collect information that we truly need, which helps reduce the risk in case of any security issue. We also strive to anonymize or pseudonymize data when full details are not required for the operation (for instance, using unique user IDs internally instead of easily identifiable info in logs when feasible).
  • Incident Response: Bruno has a data breach response plan. In the event of a security breach that affects personal information, we will act promptly to contain the issue, assess the scope, and notify affected parties and authorities as required by law. PIPEDA requires us to report certain breaches to the Privacy Commissioner of Canada and to notify individuals if there is a risk of significant harm; we are committed to fulfilling these obligations.

Despite our efforts, no security measures are completely infallible. The transmission of information via the internet is not entirely secure, so we cannot guarantee absolute security of data. It is important that you also play a role in keeping your information safe: use a strong, unique password for Bruno, do not share your login credentials, and notify us immediately if you suspect any unauthorized access to your account. We will support users in recovering from any security incidents to the best of our ability.

Your Rights and Choices

As a user of Bruno, or as an individual whose information is stored on Bruno, you have certain rights and choices regarding your personal data. We are committed to respecting these rights in accordance with Canadian law:

Access and Accuracy

You have the right to access personal information we hold about you and to request corrections if you believe it is inaccurate or incomplete. Bruno users can access and update some of their information directly through their account profile (for instance, update your name or contact details). For any personal data not accessible via the platform (or if you are an individual who doesn't have a Bruno login, such as a client whose info was added by a user), you can make an access request by contacting us (see Contact Us section below). We will provide you with the personal information we have about you within a reasonable time, and if you find any inaccuracies, we will correct or update it upon verification. In certain situations, we might not be able to provide access to all information (for example, if it involves another person's data or there are legal restrictions), but we will explain any denial of access and provide a point of contact for further inquiry.

Withdrawal of Consent

Where you have provided consent for our collection, use, or disclosure of personal information, you have the right to withdraw your consent at any time (subject to legal or contractual restrictions). For example, if you initially allowed us to use your email for marketing communications, you can opt out as described above. If you are a client of a Bruno user and you previously consented to have them input your information into Bruno, you can ask that user (or us) to remove your data. Withdrawing consent for certain uses of data may mean we can no longer provide you with certain services. If you withdraw consent for your own data as a Bruno user, we might have to deactivate your account if that information is essential to providing the Service. We will inform you if such is the case.

Deletion (Right to Erasure)

You can request that we delete your personal information from our records. For Bruno account holders, the primary way to do this is by deleting your account through the platform or by contacting us to request account deletion. This will remove your personal profile info from active use. For clients whose data is in Bruno, you can ask the Bruno user who added you to delete your entry, or contact us directly to assist. Please note that deletion requests are subject to certain limitations: we may retain some information as required by law or for legitimate business purposes (as described in Data Retention). However, we will inform you of what data may remain and for what reason, if such a situation arises.

Accountability and Challenging Compliance

Bruno is accountable for the protection of personal information under its control. We have appointed a Privacy Officer (see contact below) who is responsible for overseeing compliance with this Privacy Policy and applicable privacy laws. If you have questions, concerns, or complaints about our privacy practices, you have the right to contact us and we will investigate and respond. We are committed to resolving any issues and honoring your rights. If you are not satisfied with our handling of a privacy concern, you may also contact the Office of the Privacy Commissioner of Canada (OPC) or your provincial privacy commissioner (if applicable) to file a complaint or seek further guidance.

Portability

Under certain circumstances, you may request a copy of personal information that you provided to us in a structured, common format (this is more commonly a right under laws like the EU's GDPR; PIPEDA doesn't explicitly guarantee data portability, but Bruno will assist with reasonable requests when possible, such as providing an export of your client list if you need it).

Preferences and Opt-Outs

As mentioned, you can opt out of marketing emails. You also may control cookies through your browser settings (affecting analytics tracking). If your browser sends a "Do Not Track" signal, we currently do not respond differently to that signal, but we only use your data as described here. We do not sell personal data, so there is no need to opt out of sale (and Canadian law currently does not have a "do not sell" registry akin to some other jurisdictions).

We will never discriminate against someone for exercising their privacy rights. Any requests related to personal data rights can be sent to us through the contact information below. We may need to verify your identity before processing certain requests (to ensure that we are protecting the correct person's data). Verification might involve confirming account details or requesting additional information as needed. We will respond to your request within a reasonable timeframe, and in any event as required by law (usually within 30 days for access requests under PIPEDA, with possible extension if needed, which we would communicate to you).

Children's Privacy

Bruno is a business-oriented service not intended for use by children. We do not knowingly collect personal information from individuals under the age of 13 (and in most cases, Bruno's user base is professional adults). If you are under 13, please do not use Bruno or provide any personal information. We advise all users not to add personal details of anyone under 13 into the platform unless absolutely necessary and done in compliance with law (for example, if a minor is a client, ensure proper parental consent).

If we become aware that we have inadvertently collected personal data from a child under 13 without appropriate consent, we will take steps to delete such information from our records.

Updates to this Privacy Policy

Bruno may update or change this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make changes, we will revise the "Last Updated" date at the top of this Policy. If we make any material changes, we will provide a prominent notice, which may include notifications within the Bruno platform or sending an email to registered users, to inform you of the update.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of Bruno after any changes to this Policy signifies your acceptance of the updated terms (to the extent permitted by law). If you do not agree with the changes, you should cease using the Service and you may request that we remove your personal data.

Contact Us

Bruno welcomes questions, requests, and feedback regarding this Privacy Policy and our privacy practices. If you would like to access or correct your information, or if you have a privacy-related concern or complaint, please contact our Privacy Officer at:

Email: privacy@mybruno.ca

Mail:

Bruno Inc.
9328 15 Sideroad Milton
Milton, Ontario, Canada
L9T 2X9

When contacting us, please provide sufficient information for us to verify your identity (if applicable) and to understand your request. We will respond to privacy inquiries as promptly as possible.

If you feel that we have not addressed your privacy questions or concerns satisfactorily, you have the right to contact the Office of the Privacy Commissioner of Canada (OPC) for further assistance or to lodge a complaint. The OPC can be reached at 1-800-282-1376 or www.priv.gc.ca. If you are in Quebec, Alberta, or British Columbia, you may also contact your provincial privacy commissioner, as PIPEDA may not apply to intra-provincial activities in those provinces which have their own private-sector privacy laws.

Thank you for trusting Bruno with your professional needs and your personal data. We are dedicated to maintaining that trust by safeguarding privacy and being transparent about our practices.

This service is powered by Bruno

Terms and Conditions Privacy Policy