Data processing agreement

In short: When you use Breeze, you are the controller of the personal data in your projects and we are your processor. This page is our GDPR Article 28 contract. It is already in force - you do not need to sign anything. See the subprocessor list.

Parties and status of this agreement

This Data Processing Agreement (the “DPA”) is entered into between:

Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Breeze (the “Processor”, “Breeze”, “we”, “us”);

and the Customer identified in the applicable Breeze account (the “Controller”, “Customer”, “you”),

each a “Party” and together the “Parties”.

How this DPA takes effect

1. This DPA is incorporated into and forms part of the Breeze Terms of Service (the “Agreement”). It is pre-signed by Breeze and takes effect automatically, without any further signature or notice, for every Customer that acts as a controller of personal data subject to Data Protection Law and that uses the Service on or after the effective date stated at the foot of this page.

2. If your procurement process requires an executed copy, the owner of your Breeze team can accept this agreement while signed in to Breeze. Breeze will produce a countersigned copy showing both parties' details, which can be printed or saved as a PDF. An executed copy records the same terms as this page and does not change them.

3. Order of precedence. In the event of any conflict between this DPA and the Terms of Service or the Privacy Policy, this DPA prevails in respect of the processing of Customer Personal Data. For the avoidance of doubt, this DPA governs Breeze's role as processor of the data you place in the Service, and supersedes any statement elsewhere in the Agreement to the effect that Breeze does not act as a processor of that data.

1. Definitions

1.1. “Data Protection Law” means all laws applicable to the processing of personal data under this DPA, including Regulation (EU) 2016/679 (the “GDPR”), the Estonian Personal Data Protection Act, the GDPR as incorporated into the law of the United Kingdom (the “UK GDPR”) and the Swiss Federal Act on Data Protection (the “FADP”), in each case as applicable.

1.2. “Customer Personal Data” means personal data contained in Customer Data that Breeze processes on the Customer's behalf in the course of providing the Service.

1.3. “Customer Data” means all content and data that the Customer or its End Users submit to, store in, or generate through the Service - including projects, tasks, comments, notes, time entries, custom fields, attachments and calendar entries.

1.4. “End User” means any individual the Customer authorises to use the Service under the Customer's account, including employees, contractors, clients and guests.

1.5. “Service” means the Breeze project management service made available at breeze.pm and its subdomains, together with the Breeze mobile applications and API.

1.6. “Subprocessor” means any processor engaged by Breeze to process Customer Personal Data.

1.7. “SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.

1.8. The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach” and “supervisory authority” have the meanings given to them in the GDPR.

2. Roles and scope

2.1. Customer as controller. As between the Parties, the Customer is the controller of Customer Personal Data and Breeze is the processor. The Customer determines the purposes and means of the processing, decides what personal data is placed into the Service, and decides who may access it.

2.2. Breeze as controller. Breeze acts as a controller in its own right for account, billing, security and website data it collects about its customers and their users - for example account registration details, invoices, authentication logs, support correspondence and website analytics. That processing is described in the Privacy Policy and is outside the scope of this DPA.

2.3. Subject matter and duration. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

2.4. Special categories. The Service is a general-purpose project management tool and is not designed or intended for the processing of special categories of personal data within the meaning of Article 9 GDPR, or of personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. The Customer must not submit such data to the Service unless the Parties have agreed additional measures in writing.

3. Breeze's obligations as processor

3.1. Documented instructions. Breeze will process Customer Personal Data only on documented instructions from the Customer, including with regard to transfers to a third country. The Agreement, this DPA, and the Customer's use and configuration of the Service through its features and settings together constitute the Customer's complete and final documented instructions.

3.2. Breeze will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless prohibited from doing so by law. Breeze is not obliged to carry out an instruction it considers unlawful.

3.3. Processing required by law. Where Breeze is required by Union or Member State law to process Customer Personal Data other than on the Customer's instructions, Breeze will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

3.4. Confidentiality. Breeze will ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality, and will limit access to those personnel who need it to provide, secure or support the Service.

3.5. No monitoring of content. Breeze does not routinely access, monitor or review the contents of Customer accounts. Access occurs only where reasonably necessary - for example to provide support the Customer has requested, to investigate a security incident, to prevent illegal or harmful activity, or to comply with a legal obligation.

3.6. No sale of data. Breeze does not sell Customer Personal Data, does not share it for cross-context behavioural advertising, and does not use it to train machine learning or artificial intelligence models for its own purposes or for the benefit of any third party.

4. Security

4.1. Breeze will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR. The measures in force are described in Annex II and further at breeze.pm/security.

4.2. Breeze may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of security of the Service.

4.3. Customer responsibilities. The Customer is responsible for its own use of the Service, including safeguarding account credentials, configuring roles and permissions appropriately, managing which End Users and guests have access to which projects, deciding whether to make projects or reports public, and promptly removing access for people who no longer need it.

5. Subprocessors

5.1. General authorisation. The Customer grants Breeze general authorisation to engage Subprocessors for the purposes of providing the Service. The Subprocessors engaged as at the effective date of this DPA are listed in Annex III.

5.2. Terms imposed on Subprocessors. Breeze will enter into a written agreement with each Subprocessor imposing data protection obligations that offer a level of protection substantially equivalent to those in this DPA, and will remain fully liable to the Customer for the performance of each Subprocessor's obligations.

5.3. Changes and notice. Breeze will give the Customer at least thirty (30) days' notice before adding or replacing a Subprocessor. Notice will be given by updating Annex III on this page and by email to the account owner's registered address.

5.4. Objection. The Customer may object to a proposed new Subprocessor on reasonable data protection grounds by writing to support@breeze.pm within thirty (30) days of the notice. The Parties will discuss the objection in good faith. If Breeze cannot make the Service reasonably available without the objected-to Subprocessor, the Customer may terminate the affected subscription by written notice, and Breeze will refund any fees prepaid for the period after termination. This is the Customer's sole and exclusive remedy for such an objection.

5.5. Breeze may replace a Subprocessor without advance notice where the change is required to address a serious security risk or where the existing Subprocessor ceases to provide the relevant service, in which case Breeze will notify the Customer as soon as reasonably practicable.

6. International transfers

6.1. The Service is hosted in the United States. By using the Service the Customer instructs Breeze to transfer Customer Personal Data to the United States and to the other locations identified in Annex III.

6.2. Where Customer Personal Data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country that is not the subject of an adequacy decision, the transfer is made under one of the following, in this order of preference:

  • the EU-U.S. Data Privacy Framework and its UK Extension and Swiss-U.S. counterpart, where the recipient is certified under that framework for the relevant category of data; or
  • the SCCs, Module Two (controller to processor) where the Customer is a controller and Module Three (processor to processor) where the Customer is itself a processor, which are hereby incorporated into this DPA by reference and completed as set out in clause 6.3.

6.3. Where the SCCs apply:

  • the Customer is the data exporter and Breeze is the data importer;
  • the optional docking clause in Clause 7 applies;
  • in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in clause 5.3 above;
  • in Clause 11, the optional independent dispute resolution provision does not apply;
  • in Clause 17, the governing law is the law of the Republic of Estonia;
  • in Clause 18(b), the forum for disputes is the courts of the Republic of Estonia;
  • Annexes I, II and III to the SCCs are populated by Annex I, Annex II and Annex III of this DPA respectively.

6.4. UK transfers. Transfers subject to the UK GDPR are made under the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, which is incorporated by reference and completed using the information in this DPA.

6.5. Swiss transfers. For transfers subject to the FADP, references in the SCCs to the GDPR are read as references to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term “Member State” is read so as not to deprive data subjects in Switzerland of the right to bring proceedings in their place of habitual residence.

7. Data subject rights

7.1. The Service gives the Customer direct control over Customer Personal Data. Through the Service the Customer can access, correct, export and delete data without needing to involve Breeze, including exporting data in HTML and JSON format and deleting user profiles and projects.

7.2. Taking into account the nature of the processing, Breeze will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests to exercise data subject rights under Chapter III of the GDPR.

7.3. If Breeze receives a request from a data subject relating to Customer Personal Data, Breeze will not respond to the request itself except to confirm that the request should be directed to the Customer, and will forward the request to the Customer without undue delay.

8. Personal data breaches

8.1. Breeze will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data.

8.2. The notification will describe, to the extent known at the time and to the extent Breeze is able to provide it: the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the breach and mitigate its effects; and a contact point for further information. Where the information cannot be provided at once, it will be provided in phases without further undue delay.

8.3. Breeze will take reasonable steps to contain and remediate the breach, and will cooperate with the Customer and provide reasonable assistance with any notification the Customer must make to a supervisory authority or to data subjects.

8.4. A notification under this clause is not an acknowledgement by Breeze of fault or liability.

9. Impact assessments and prior consultation

9.1. Taking into account the nature of the processing and the information available to it, Breeze will provide the Customer with reasonable assistance with data protection impact assessments under Article 35 GDPR and with prior consultation of supervisory authorities under Article 36 GDPR, in each case solely in relation to the processing of Customer Personal Data by Breeze.

10. Return and deletion of data

10.1. The Customer may export Customer Data at any time during the term of the Agreement using the export features of the Service.

10.2. Cancellation deletes your data immediately. As set out in the Terms of Service, cancelling the Service results in the immediate and irrevocable deletion of Customer Content. The Customer should export any data it wishes to keep before cancelling. Breeze does not offer a post-termination retrieval window and cannot recover data once an account has been cancelled.

10.3. Residual copies of Customer Personal Data may persist in routine encrypted backups for a limited period after deletion, and are overwritten in the ordinary course of the backup rotation. Until they are overwritten, Breeze continues to protect such copies in accordance with this DPA and does not process them for any purpose other than restoration and business continuity.

10.4. Breeze may retain Customer Personal Data to the extent required by Union or Member State law, and in that case will continue to protect it and will process it only to the extent and for the period required by that law.

11. Audits and information

11.1. Breeze will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the information published at breeze.pm/security, and the compliance certifications and reports of its infrastructure Subprocessors.

11.2. Breeze will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Such audits are subject to the following, to the extent permitted by Data Protection Law:

  • the Customer gives at least thirty (30) days' written notice;
  • audits take place during normal business hours, no more than once in any twelve (12) month period, except where required by a supervisory authority or following a personal data breach affecting the Customer;
  • the auditor is not a competitor of Breeze and is bound by confidentiality obligations;
  • the audit is limited to Breeze's own systems and processes, does not extend to the data centres or systems of Subprocessors, and does not grant access to the data of any other customer;
  • the Customer bears its own costs and reimburses Breeze's reasonable costs for time spent beyond the provision of existing documentation.

11.3. The Parties agree that the information and documentation described in clause 11.1 will ordinarily satisfy the Customer's audit rights, and that an on-site inspection will be exercised only where that information is demonstrably insufficient.

12. Customer obligations

12.1. The Customer warrants that it has a valid legal basis for the processing of Customer Personal Data, that it has provided all notices and obtained all consents required under Data Protection Law, and that its instructions to Breeze comply with Data Protection Law.

12.2. The Customer is responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it acquired it.

12.3. The Customer must not submit to the Service any personal data whose sensitivity or regulatory status exceeds what a general-purpose project management tool is designed to handle, including the categories described in clause 2.4.

12.4. Where the Customer is itself a processor acting on behalf of a third-party controller, the Customer warrants that it has that controller's authorisation to engage Breeze as a subprocessor on the terms of this DPA.

13. Term, liability and governing law

13.1. Term. This DPA takes effect on the date the Customer first uses the Service on or after the effective date below, and continues for as long as Breeze processes Customer Personal Data. Clauses that by their nature should survive termination do so.

13.2. Liability. Each Party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under Data Protection Law, including a data subject's rights under Articles 79 and 82 GDPR.

13.3. Changes. Breeze may update this DPA where necessary to reflect a change in Data Protection Law, in the Subprocessors it engages, or in the Service. Breeze will notify the Customer of material changes by email to the account owner's registered address and by updating the effective date below.

13.4. Severability. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force and effect.

13.5. Governing law and jurisdiction. This DPA is governed by Estonian law and disputes are resolved as set out in the Terms of Service, save that where the SCCs apply, clauses 17 and 18 of the SCCs prevail in respect of the matters they govern.

13.6. Contact. Data protection enquiries, including subprocessor objections and audit requests, should be sent to support@breeze.pm.

Annex I - Details of the processing

This annex populates Annex I to the SCCs where those clauses apply.

A. List of Parties

Data exporter: the Customer, as identified in its Breeze account. Role: controller (or processor, where the Customer acts on behalf of a third-party controller). Contact: the account owner's registered email address. Activities relevant to the transfer: use of the Service for project management.

Data importer: Template OÜ (trading as Breeze), Tornimäe tn 7-79, 10145 Tallinn, Estonia. Role: processor. Contact: support@breeze.pm. Activities relevant to the transfer: provision, hosting, support and maintenance of the Service.

B. Description of the transfer

Subject matter Provision of the Breeze project management service to the Customer.
Duration The term of the Agreement, plus the limited period described in clause 10.3 for backup rotation.
Nature and purpose Hosting, storage, transmission, indexing, search, backup, display and other processing necessary to make the Service available to the Customer and its End Users, together with support, security monitoring and troubleshooting at the Customer's request.
Categories of data subjects The Customer's End Users (employees, contractors, administrators and guests); the Customer's own clients and contacts where the Customer records them in the Service; any other individual the Customer or its End Users choose to reference in Customer Data.
Categories of personal data
  • Account and profile data: name, email address, password hash, avatar, job title, time zone, language, notification preferences, two-factor authentication settings.
  • Usage and access data: IP address, approximate location derived from IP address, device and browser information, sign-in timestamps, audit and activity records.
  • Content data: any personal data the Customer or its End Users place in projects, tasks, comments, notes, custom fields, tags, time entries, estimates, calendar entries and file attachments.
  • Communications data: messages sent through in-app chat and comments, and the content of email sent to or from the Service.
The content categories are determined by the Customer, not by Breeze.
Sensitive data None is intended or required. See clause 2.4.
Frequency of transfer Continuous, for the duration of the Agreement.
Retention For the term of the Agreement. Deleted immediately on cancellation, subject to clauses 10.2 to 10.4.
Onward transfers To the Subprocessors listed in Annex III, for the purposes and periods stated there.

C. Competent supervisory authority

Where the SCCs apply and the data exporter is established in the European Union, the competent supervisory authority is that of the Member State in which the data exporter is established. Where the data exporter is not established in the EU but has appointed a representative under Article 27 GDPR, it is the authority of the Member State in which the representative is established. Breeze's own lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

Annex II - Technical and organisational measures

This annex populates Annex II to the SCCs where those clauses apply. Further detail is published at breeze.pm/security.

Measure Description
Encryption in transit All access to the Service is over HTTPS with TLS. HTTP requests are redirected to HTTPS and HSTS is enforced. Connections to the database and to internal services are encrypted.
Encryption at rest Database storage, file attachments in object storage and backups are encrypted at rest by the infrastructure providers. Passwords are stored as salted bcrypt hashes and are never stored or transmitted in plain text. Two-factor authentication secrets are stored encrypted.
Access control - Customer Per-user accounts with individual credentials; role-based permissions at workspace and project level; granular control over which End Users and guests can see which projects; optional two-factor authentication; single sign-on via Google and Apple; session management and sign-out.
Access control - Breeze personnel Access to production systems is limited to the small number of personnel who require it, is protected by multi-factor authentication, and is granted on a least-privilege basis. Access is revoked promptly when no longer required. Personnel are bound by confidentiality obligations.
Tenant separation Customer accounts are logically separated at the application layer. Every request is scoped to the authenticated user's team, workspace and project permissions.
Physical security Hosted in Amazon Web Services data centres, which operate multi-layered physical access control including perimeter controls, video surveillance, intrusion detection and multi-factor access for staff, with all access logged and audited. Breeze personnel have no physical access to the hardware.
Certifications of infrastructure providers The data centres underlying the Service are accredited under ISO 27001, SOC 1 and SOC 2 / SSAE 16 / ISAE 3402, PCI DSS Level 1, FISMA Moderate and Sarbanes-Oxley.
Resilience and availability The platform maintains redundancy to avoid single points of failure, replaces failed components automatically, and operates across multiple data centres. In an outage, applications and databases are redeployed from current system images and restored from backups.
Backup and restoration Continuous protection through write-ahead logging, with logs shipped to multi-data-centre, high-durability storage. Databases can be recovered to within seconds of their last known state. Backups are encrypted and access-controlled.
Logging and monitoring Application error monitoring, performance monitoring and audit trails of changes to Customer Data. Authentication events are recorded, including sign-in time and originating IP address.
Secure development Framework-level protection against common web vulnerabilities including SQL injection, cross-site scripting, cross-site request forgery and clickjacking. Dependencies are kept current and security updates applied. Changes are reviewed before release.
Abuse prevention CAPTCHA on public forms, rate limiting, and input sanitisation on user-supplied content.
Data minimisation and deletion Self-service export in HTML and JSON; self-service deletion of user profiles, projects and accounts; immediate deletion of Customer Content on cancellation.
Subprocessor governance Written data protection terms with each Subprocessor, assessment before engagement, and the published list and change-notification process in clause 5.

Annex III - Subprocessors

This annex populates Annex III to the SCCs where those clauses apply. It lists the Subprocessors that may process Customer Personal Data. Changes are notified in accordance with clause 5.3.

Infrastructure

Subprocessor Purpose Data processed Location
Salesforce, Inc.
Heroku
Application hosting platform, managed PostgreSQL database and Redis queue All Customer Personal Data United States
Amazon Web Services, Inc. Underlying data centres; object storage for file attachments, avatars and backups; content delivery network; outbound email delivery All Customer Personal Data United States

Service features

Subprocessor Purpose Data processed Location
Twilio Inc.
SendGrid
Processing of inbound email sent to the Service, so that email can be turned into tasks and comments Sender and recipient addresses, subject lines, message bodies and attachments of email sent to Breeze addresses United States
Mistral AI SAS AI assistant and voice note transcription Only the content the Customer's End Users submit to AI features - prompts, the task and project content given as context, and audio recorded for transcription France (EU)
Google LLC
reCAPTCHA
Abuse and bot prevention on public forms IP address and device interaction signals of the person completing the form United States

Operations and support

Subprocessor Purpose Data processed Location
SmartBear Software
Bugsnag
Application error and crash monitoring Diagnostic data attached to errors: user identifier and email address, request path and parameters, browser and device information, stack traces United States
Scout Monitoring
Scout APM
Application performance monitoring Request metadata, timing traces and database query patterns; incidental identifiers appearing in request paths United States
Bright Market, LLC
FastSpring
Payment processing, invoicing and subscription management as merchant of record Billing contact name, email address, billing address, VAT identification number and transaction records. Card details are collected and held by FastSpring; Breeze never receives or stores them United States

Not subprocessors: integrations you switch on

Breeze offers optional integrations that send data to, or receive data from, third-party services. These operate only when the Customer or an End User connects them, and the data flow is an instruction given by the Customer to that third party, not a subprocessing arrangement by Breeze. The Customer is responsible for its own relationship with those providers, and their terms and privacy policies govern what they do with the data.

Such integrations currently include:

  • Sign-in: Google, Apple
  • Accounting and invoicing: FreshBooks, QuickBooks, Xero
  • Notifications and collaboration: Slack, GitHub
  • Import and files: Trello import, Evernote, Google Drive
  • Calendars: external calendar subscriptions published by the Customer

Breeze as controller

Breeze also uses vendors for processing in which it acts as a controller in its own right rather than as the Customer's processor - for example website and product analytics (Google Analytics), consent management on the marketing website (Termly), and marketing attribution. These are not subprocessors of Customer Personal Data and are outside the scope of this DPA. They are covered by the Privacy Policy.

Effective and last revised: August 16, 2026.