Breeze and GDPR compliance
Breeze is committed to compliance with the General Data Protection Regulation (GDPR), which has applied since 25 May 2018. We have reviewed our internal procedures and systems against it and continue to do so: compliance is an ongoing process that has to be monitored and validated rather than completed once.
Breeze is provided by Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Breeze. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), and you have the right to lodge a complaint with it or with the supervisory authority where you live. Data protection enquiries go to support@breeze.pm.
Infrastructure and data transfer
Protecting your information and your privacy is very important to Breeze. The data centres underlying the Service are accredited under ISO 27001, SOC 1 and SOC 2 / SSAE 16 / ISAE 3402, PCI DSS Level 1, FISMA Moderate and Sarbanes-Oxley. The core of the Service is hosted and managed within Amazon's secure data centres in the United States on Amazon Web Services (AWS) technology, with Heroku as the application platform. Amazon continually manages risk and undergoes recurring assessments to ensure compliance with industry standards. Not everything sits there: the AI assistant built into Breeze is served from the EU, and the Breeze MCP connector runs on servers we operate ourselves. Where each of our providers processes data is listed in Annex III of the data processing agreement.
Where personal data originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely, in this order of preference, on the EU-U.S. Data Privacy Framework and its UK Extension and Swiss-U.S. counterpart where the recipient is certified under that framework for the relevant category of data, and otherwise on the European Commission's Standard Contractual Clauses. Transfers subject to the UK GDPR are made under the Information Commissioner's International Data Transfer Addendum, and transfers subject to Swiss law under the FADP adaptations. The full mechanism, including which module of the Standard Contractual Clauses applies, is set out in our data processing agreement.
Breeze as the data processor
The client data you store in Breeze is your data subject and you are considered the data controller for this personal data. Our data processing agreement serves as the written data processing contract required by GDPR Article 28, and it takes effect automatically - you don't need to sign anything. It sits alongside the Breeze terms of service and privacy policy, and lists every subprocessor we use. Breeze will only process your client data based on your instructions as the data controller.
AI features and AI assistant connectors
Breeze has two separate AI capabilities, and they sit differently under the GDPR.
Breeze AI is built into the Service and answers questions about your work from inside it. Here we act as your processor: the prompts your users submit, the task and project content supplied as context, and any audio recorded for voice note transcription are processed on your instructions. That processing is carried out by Mistral AI SAS, a subprocessor listed in Annex III which operates in France, so no transfer outside the EEA is involved for this feature.
The Breeze MCP server lets one of your users connect an outside AI assistant such as ChatGPT or Claude to their own Breeze account. This is an integration you switch on, not a subprocessing arrangement: the connection is created by your user, it acts with exactly the permissions that user already holds in Breeze, and once data reaches the assistant it is held by that assistant's provider in its own right, under that provider's terms and privacy policy. You are responsible for your relationship with that provider, and for deciding whether your users should connect one at all. Your user chooses at connection time between view-only access and view plus the ability to make changes, and bulk changes and every deletion are previewed and wait for confirmation before anything is written.
On our side of the connector, requests are logged for 14 days for security, abuse prevention and troubleshooting, and searching by meaning is done with an embedding service we run on our own servers, so the words your users search for are not sent to any third-party AI provider. We do not use your data to train machine learning or artificial intelligence models, whether for our own purposes or for anyone else's - that applies to Breeze AI, to the connector, and to the Service generally. What each kind of connector request sends, what comes back, and what we keep is set out in our privacy policy.
Breeze as the data controller
Breeze acts as the data controller for the personal data we collect about our web app, mobile apps, and website users. We rely on four legal bases for that processing:
- Performance of a contract (Article 6(1)(b)) - creating and running your account, providing the Service, and supporting you.
- Legal obligation (Article 6(1)(c)) - financial records and the information we need to meet our accountability obligations under the GDPR.
- Legitimate interests (Article 6(1)(f)) - keeping the Service secure and available, preventing abuse and fraud, diagnosing errors and performance problems, and understanding how the Service is used so we can improve it. You can object to processing on this basis at any time.
- Consent (Article 6(1)(a)) - non-essential cookies on our website and marketing email. You can withdraw consent at any time, without affecting processing already carried out, using the "Consent preferences" link in our website footer or the unsubscribe link in any marketing message.
Breeze is committed to respecting all your rights under the GDPR as the controller for your personal data. The rights available to you, and how to exercise them, are set out in our privacy policy.
Data portability solution
Breeze has all the tools to comply with GDPR data portability and management.
- Data export - you can export your data anytime in HTML and JSON format.
- User deletion - you can delete your personal profile anytime.
Going forward
We continue to improve our procedures and systems. We'll monitor our GDPR compliance from privacy-related regulatory bodies and will adjust our systems accordingly if need. We'll update this page as necessary and if you have any question then you can reach us at support@breeze.pm
Last revised: August 18, 2026
