1. Scope and roles
This policy explains how BREAIX may process personal data when someone visits the public site, contacts the team, creates an account, participates in onboarding or uses the platform. A specific customer agreement or data processing addendum may define additional responsibilities for a particular service.
Depending on the activity, BREAIX may act as a controller for its own business and security purposes, or as an operator/service provider acting on documented instructions from a customer. The final version of this policy will identify the applicable role for each processing activity and jurisdiction.
2. Data and purposes
The categories may include identification and professional details, company and role information, contact data, account and authentication records, documents submitted for validation, communications, activity logs, device information and information needed to manage a commercial relationship.
BREAIX may use those data to provide and secure the service, authenticate users, validate organizations, manage permissions, respond to requests, maintain records, improve reliability, detect misuse, comply with legal obligations and communicate about the relationship. The legal basis and retention period depend on the purpose, the data involved and the applicable law.
- Purpose limitation: data is used for a defined and legitimate operational purpose.
- Data minimization: only information reasonably needed for that purpose should be requested.
- Accountability: decisions about collection, access, retention and deletion should be documented.
3. Sharing and international processing
BREAIX may share information with service providers that host, secure, support or operate parts of the platform, with professional advisers when necessary, with counterparties to the extent a user authorizes or the workflow requires it, and with public authorities when legally required or necessary to protect rights and safety.
When data moves across borders, BREAIX will apply the safeguards required by the applicable data protection law, taking account of the purpose, sensitivity, recipient, contractual protections and available technical measures. No transfer should be understood as a promise that every country provides the same level of protection as the user's country.
4. Retention, security and incidents
Data is kept for as long as it is needed for the stated purpose, the commercial relationship, security and audit needs, or a legal obligation. When the applicable period ends, BREAIX will delete, anonymize or securely restrict the data, subject to lawful exceptions such as dispute preservation or regulatory records.
BREAIX uses technical and administrative measures designed to protect confidentiality, integrity and availability. No internet service can guarantee absolute security. If a confirmed incident creates the legally relevant risk threshold, BREAIX will follow the applicable assessment, notification and mitigation process.
5. Rights and requests
Subject to the applicable law, individuals may have rights to confirmation, access, correction, deletion, portability, information about sharing, review of certain decisions, objection or restriction, and withdrawal of consent where consent is the basis. Some rights have conditions and exceptions.
Requests should be submitted through the contact channel with enough information to verify identity and locate the relevant relationship. BREAIX may need to ask for clarification or route a request to the responsible customer when it acts only on that customer's instructions.
