Back to home

Privacy & Cookie Policy

Version 1.0 · Part A: Privacy Policy · Part B: Cookie Policy · Effective [●] 2026

We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and Act No. 110/2019 Coll., on the processing of personal data.

Part A — Privacy Policy

1. Who is responsible for your data

1.1The controller of your personal data is [Breca s.r.o.], ID No. (IČO): [●], registered office: [●], e-mail: [●] (“Breca”, “we”). We process personal data in accordance with the GDPR and Act No. 110/2019 Coll., on the processing of personal data.

1.2We have not appointed a data protection officer. For anything concerning your personal data, contact us at the e-mail address above.

2. Who this Policy applies to

2.1This Policy applies to visitors of the Website, persons who complete the free assessment, business contacts and representatives of our clients and prospective clients, and anyone who communicates with us. Our services are directed at businesses; the personal data we process is therefore primarily professional contact data of company representatives.

3. What we process, why, and on what legal basis

The table below summarises the categories of personal data we process, the purposes, the legal bases and how long we keep the data.

3.2Providing your data is voluntary; however, without the necessary data we cannot deliver your assessment output, respond to you, or perform an engagement. The assessment is designed to collect information about your company, not about individuals. Please do not include personal data of third parties in free-text answers.

3.3Where you object to processing based on our legitimate interests, we will stop unless we demonstrate compelling legitimate grounds. An objection to direct marketing is always absolute: we will stop immediately.

Data categoryPurposeLegal basisRetention
Contact and identification data — name, business e-mail, company, role, billing detailsResponding to enquiries; delivering assessment results; concluding and performing engagements; invoicing and accountingArt. 6(1)(b) GDPR (contract / pre-contractual steps); Art. 6(1)(c) GDPR (accounting and tax obligations)Duration of the relationship; invoicing and tax records up to 10 years where required by tax and accounting laws
Assessment responses — your answers about your company’s activities, licensing status and jurisdictions (designed to be business information, not personal data)Generating your assessment output; preparing a tailored follow-up, proposal or engagement based on your indicated interestArt. 6(1)(b) GDPR (providing the assessment you requested); Art. 6(1)(f) GDPR (legitimate interest in following up on your expressed interest)12 months from submission, unless an engagement follows; then per the engagement records
Marketing data — business e-mail, your interactions with our e-mails and contentSending regulatory insights, updates and offers relevant to your roleArt. 6(1)(a) GDPR (consent), or Art. 6(1)(f) GDPR for existing clients with an opt-out in line with Act No. 480/2004 Coll.Until you object or withdraw consent; at most 3 years after your last interaction with us
Business contact data obtained from public sources — public regulatory registers (e.g. NCA CASP registers, the FCA register), company websites, professional networksInitial B2B outreach about services relevant to your company’s regulatory positionArt. 6(1)(f) GDPR (legitimate interest in offering relevant B2B services); notice under Art. 14 GDPR is given at first contact by reference to this Policy12 months from collection if there is no response; immediately upon your objection
Technical and usage data — IP address, device and browser data, pages visited, cookie identifiersOperating, securing and improving the Website; measuring aggregate usageArt. 6(1)(f) GDPR (operation and security); Art. 6(1)(a) GDPR for non-essential cookies (see Part B)Server logs up to 12 months; cookies per the table in Part B
Communication records — e-mails, call and meeting notesHandling communication; keeping records of what was discussed and agreedArt. 6(1)(b) and 6(1)(f) GDPRUp to 3 years after the communication, or the duration of the engagement to which it relates

4. AI-assisted processing and automated decisions

4.1Assessment responses and engagement inputs may be processed using large-language-model services accessed via API (currently Anthropic’s Claude API) in order to generate structured outputs and draft reports. Our AI providers are engaged on terms under which the data submitted via API is not used to train their models.

4.2The free assessment output is generated automatically from your answers; it is informational only and produces no legal or similarly significant effect on any individual. All paid deliverables are reviewed and approved by a human before delivery. We do not carry out automated decision-making within the meaning of Art. 22 GDPR.

5. Who receives your data

5.1We share personal data only with service providers (processors) that support the running of Breca, under data-processing agreements pursuant to Art. 28 GDPR: [Resend, Inc.] (USA — e-mail delivery), Anthropic, PBC (USA — AI processing under Section 4), [analytics provider], and our accounting and professional advisers. We may disclose data to public authorities where required by law. We never sell personal data.

5.2If a paid engagement exceptionally requires us to process personal data on your behalf (for example, data of your customers contained in documents you provide), we act as your processor and a separate data-processing agreement will be concluded before such processing starts.

6. How long we keep data

6.1Retention periods are set out in the table in Section 3. As a general principle, we keep personal data no longer than necessary for the stated purpose and then delete or anonymise it; longer retention applies only where a legal obligation (in particular tax and accounting laws) or the establishment, exercise or defence of legal claims requires it.

7. Your rights

7.1You have the right to access your personal data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests (including direct marketing), and to withdraw consent at any time with effect for the future.

7.2To exercise any right, e-mail us at [●]. We may need to verify your identity, and we will respond within one month (extendable by two further months for complex requests, in which case we will inform you).

7.3You also have the right to lodge a complaint with the Czech supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, www.uoou.gov.cz; or with the supervisory authority of your habitual residence or place of work.

8. How we protect data

8.1We apply technical and organisational measures appropriate to the risk, including encrypted transmission (TLS), access controls and the principle of data minimisation, and we engage only providers offering sufficient guarantees under Art. 28 GDPR. No internet transmission is entirely secure; please contact us immediately if you suspect any misuse of your data.

9. Changes to this Policy

9.1We may update this Policy from time to time. The current version, with its effective date, is always available on the Website; material changes will be announced on the Website or by e-mail.

Part B — Cookie Policy

1. What cookies are

1.1Cookies are small text files stored on your device by websites you visit. Similar technologies (local storage, pixels, SDKs) are treated the same way in this Policy; “cookies” refers to all of them.

Breca is not a law firm and does not provide legal advice. Outputs are for information and internal preparedness only.