1. Breeze is provided by Template OÜ, a private limited company registered in the Republic of Estonia under registry code 14110689, VAT identification number EE101937247, with its registered office at Tornimäe tn 7-79, 10145 Tallinn, Estonia, trading as Breeze (the "Supplier", "Breeze", "we", "us"). Supplier is the controller of the Data identified as such in section 6, and is a processor acting on the Customer's behalf in respect of User Data (see section 11). Questions about this policy, and requests to exercise any of the rights described in section 24, may be sent to support@breeze.pm. Supplier's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).
2. This privacy policy covers how Breeze collects and treats information about its users. Anyone who visits www.breeze.pm website or downloads, saves, installs, uses or accesses, or attempts to use or access, any of Breeze's applications shall by so doing be deemed to have agreed to the terms of this privacy policy and such collection, use and other processing of data as set forth below.
3. Any capitalized terms we don’t explain here have the same meaning as in our Terms of Service (https://www.breeze.pm/terms). In this policy, “Customer” also refers to anyone who visits our website or uses any of our apps. “Supplier” means Template OÜ, identified in section 1.
4. This policy does not limit any legal rights the Supplier has for data processing.
5. Customer acknowledges that Supplier may collect information (including personal data) about Customer and End Users ("Data Subjects"): (a) during the negotiation, conclusion and modification of the agreements it concludes with Data Subjects or with parties whom the Data Subjects represent (this may include any data provided during the process of making or changing those agreements); (b) when a Data Subject fills in forms via the Service, opens a User Account, subscribes to, or unsubscribes from, a Service Plan, creates or modifies a user profile, or enters or modifies other information associated with their User Account (the information thus provided); (c) when a Data Subject visits Supplier's website (the Data Subject's IP address, geographical location, session information, browsing behaviour, certain software and hardware attributes); (d) when a Data Subject downloads, installs, updates or uninstalls the Software, or accesses or uses the Service (the location, manner, means and duration of such activity as well as other information the Data Subject may provide); and (e) when otherwise knowingly made available to Supplier (the information the Data Subject provides). When visiting Supplier's website, "cookies" may be stored within the visitor's device.
6. In terms of categories rather than circumstances, the Data described in section 5 is the following. Where Supplier is shown as processor, the Customer decides what the category actually contains and Supplier handles it only on the Customer's instructions.
| Category | What it includes | Supplier's role |
|---|---|---|
| Account and profile data | Name, email address, password (stored only as a salted hash), avatar, job title, time zone, language, notification preferences and two-factor authentication settings. | Controller |
| Team and billing data | Team name, the Service Plan subscribed to, whether it is billed monthly or annually, the date paid until, and the reference and management link identifying the team’s subscription with FastSpring, together with the amount and date of each charge and a link to the invoice FastSpring issues for it. FastSpring is the merchant of record and the seller: billing address, VAT identification number and card details are given by the Customer to FastSpring at its checkout and are not held by Supplier. | Controller |
| Usage and access data | IP address, approximate geographical location derived from it, device and browser information, session information, the pages and features used, sign-in timestamps, and audit and activity records of changes made in the Service. | Controller |
| Content placed in the Service | Anything a Customer or End User puts into projects, tasks, comments, notes, project discussion, custom fields, tags, time entries, estimates, calendar entries and file attachments - including personal data about employees, contractors, clients or other third parties that the Customer chooses to record there. This is the "User Data" of section 11. | Processor |
| Communications data | Messages sent through in-app chat, comments and project discussion, and the content of email sent to or from the Service. Support correspondence with Supplier is held by Supplier in its own right. | Processor, except support correspondence (controller) |
| AI feature data | Prompts submitted to the Breeze AI assistant built into the Service, the task and project content supplied to it as context, and audio recorded for voice note transcription. | Processor |
| AI assistant connector data | Where an End User connects an outside AI assistant, the requests that connection makes and the Breeze data returned in response, as set out in section 17. | Processor |
| Website and marketing data | IP address, device and browser information, pages visited, referring source, cookie consent choices, and membership of a mailing or similar programme where a Data Subject has subscribed. | Controller |
7. Special categories. The Service is a general-purpose project management tool and is neither designed nor intended for the processing of special categories of personal data within the meaning of Article 9 GDPR, or of personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. Customers must not place such data in the Service unless Supplier has agreed additional measures in writing.
8. Customer agrees and warrants to Supplier that End Users agree:
(a) to Supplier's processing of Customer Details and such other information as referenced in sections 5 and 6 (collectively, "Data") for the purposes of (i) providing the Service, (ii) improving or otherwise modifying the Service and notifying Customer and other relevant Data Subjects thereof, (iii) customising the content and/or layout of Supplier's website or the Service for the particular visitor or user, (iv) replying to the Data Subjects' communications and contacting them, (v) performing Supplier's obligations towards the Data Subject, (vi) exercising and enforcing Supplier's rights, (vii) user statistics and other Service-related analyses;
(b) that Data may be processed in the country of their domicile as well as outside it, including in any member state of the Organisation for Economic Co-operation and Development (OECD) and any country participating in the European Economic Area (EEA);
(c) that Supplier does not sell Data, does not share it for cross-context behavioural advertising, and does not use it to train machine learning or artificial intelligence models for its own purposes or for the benefit of any third party; and that Supplier will not disclose Customer Details to any third party except (i) to the service providers identified in section 12, which process Data only on Supplier's instructions and under written data protection terms, (ii) to members of its corporate group, (iii) where the individual has given clear permission, (iv) where required by law, or (v) where necessary in order to perform Supplier's obligations under the Agreement, or its statutory obligations, or to exercise its legal rights, or defend against claims or other process.
9. Supplier represents that it has implemented and will continue to employ commercially reasonable measures to ensure that Customer Details are processed securely and in compliance with the applicable law.
10. Supplier has no obligation to monitor or access its customers' accounts, but may do so in cases where such action is reasonably justified (e.g., in order to prevent illegal or harmful activity, provide customer support, or perform its legal duties).
11. In respect of User Data, the Customer is the controller and Supplier acts as a processor on the Customer's behalf. Supplier processes User Data only on the Customer's documented instructions, on the terms of the Data Processing Agreement at https://www.breeze.pm/dpa, which forms part of the Agreement and takes effect automatically. The Customer decides what User Data is placed into the Service and who may access it, and remains responsible for the accuracy and legality of that data and for having a lawful basis to process it. Any request or complaint from a data subject concerning User Data should be taken up with the Customer in charge of the relevant workspace or other part of the User Environment; where Supplier receives such a request directly, it will refer it to that Customer rather than responding itself.
12. Supplier engages a limited number of service providers in order to operate the Service. Each of them processes Data only on Supplier's instructions, only in order to provide its service to Supplier, and under written data protection terms. Where Supplier acts as a processor of User Data, these providers are the subprocessors listed in Annex III of the Data Processing Agreement, and changes to them are notified as described there. The current list is:
| Recipient | What it does for Breeze | Data it receives | Location |
|---|---|---|---|
| Salesforce, Inc. Heroku |
Application hosting platform, managed PostgreSQL database and Redis queue | All data held in the Service | United States |
| Amazon Web Services, Inc. | Underlying data centres; object storage for file attachments, avatars and backups; content delivery network; outbound email delivery | All data held in the Service | United States |
| Twilio Inc. SendGrid |
Processing of inbound email sent to the Service, so that email can be turned into tasks and comments | Sender and recipient addresses, subject lines, message bodies and attachments of email sent to Breeze addresses | United States |
| Mistral AI SAS | The Breeze AI assistant built into the Service, and voice note transcription | Only the content End Users submit to those features - prompts, the task and project content given as context, and audio recorded for transcription | France (EU) |
| Google LLC reCAPTCHA |
Abuse and bot prevention on public forms | IP address and device interaction signals of the person completing the form | United States |
| SmartBear Software Bugsnag |
Application error and crash monitoring | Diagnostic data attached to errors: user identifier and email address, request path and parameters, browser and device information, stack traces | United States |
| Scout Monitoring Scout APM |
Application performance monitoring | Request metadata, timing traces and database query patterns; incidental identifiers appearing in request paths | United States |
| Bright Market, LLC FastSpring |
Payment processing, invoicing and subscription management as merchant of record | Billing contact name, email address, billing address, VAT identification number and transaction records, which the Customer provides to FastSpring directly at its checkout as merchant of record. Card details are collected and held by FastSpring; Supplier never receives or stores them | United States |
13. Website and marketing. On its public website Supplier also uses Google Analytics (Google LLC, United States) to measure how the website is used, and Termly (Termly, Inc., United States) to record cookie consent choices. Supplier acts as a controller for this processing. A visitor can change their cookie preferences at any time through the "Consent preferences" link in the website footer.
14. Integrations the Customer switches on. The Service offers optional integrations that send data to, or receive data from, third-party services. They operate only where a Customer or an End User connects them, and the resulting data flow is an instruction given to that third party rather than processing carried out by Supplier on the Customer's behalf. That third party's own terms and privacy policy govern what it does with the data, and the Customer is responsible for its own relationship with the provider. Such integrations currently include sign-in with Google and Apple; accounting and invoicing with FreshBooks, QuickBooks and Xero; notifications and collaboration with Slack and GitHub; import and file access with Trello, Evernote and Google Drive; external calendar subscriptions published by the Customer; and AI assistants connected over the Model Context Protocol, which are described in section 17.
15. Supplier keeps Data only for as long as it is needed for the purposes described in section 8, or for as long as the law requires it to be kept. The following periods apply:
| Data | How long it is kept |
|---|---|
| Account and profile data: name, email address, password hash, avatar, job title, time zone, language, notification preferences and two-factor authentication settings | For as long as the User Account exists. Deleted when the End User deletes their profile, or when the account is cancelled |
| Content placed in the Service: projects, tasks, comments, notes, custom fields, tags, time entries, estimates, calendar entries and file attachments | For the term of the Agreement. Cancelling the Service deletes it immediately and irrevocably; there is no post-termination retrieval window, so anything to be kept must be exported before cancelling |
| Encrypted backups | Residual copies may persist for a limited period after deletion and are overwritten in the ordinary course of the backup rotation. Until then they are used only for restoration and business continuity |
| Audit and activity records, and authentication events including sign-in time and originating IP address | For as long as the User Account exists, as part of that account's audit trail |
| Server request logs | Kept briefly for security, abuse prevention and troubleshooting, and then deleted. On the Breeze MCP connector service described in section 17, this period is 14 days |
| Error and performance diagnostics held by Bugsnag and Scout APM | For the retention period operated by those services, and used only to diagnose faults and performance problems |
| Subscription and payment records | Subscription state and the FastSpring references identifying it are kept for as long as the team’s account exists, and afterwards only so far as is needed to resolve a billing dispute or to meet Supplier’s own statutory obligations. FastSpring, as merchant of record, holds the underlying payment, invoice and tax records under its own retention policy |
| Support correspondence | For as long as is needed to handle the request, and for a reasonable period afterwards so that related enquiries can be understood in context |
| Website analytics | For the retention period configured on Supplier's Google Analytics property |
| Membership of a mailing or similar programme | Until the Data Subject unsubscribes |
16. Where Supplier is required by law to retain Data for longer than the periods above, it will continue to protect that Data and will process it only to the extent, and for the period, that the law requires.
17. What this is. Supplier operates a Model Context Protocol ("MCP") server at mcp.breeze.pm which allows an End User to connect an outside AI assistant - for example ChatGPT (provided by OpenAI), Claude (provided by Anthropic), or any other assistant that supports the standard - to their Breeze account, and then to ask about their work and make changes to it by chatting. The connection is optional and does not exist unless an End User creates it. Nothing is disclosed to an AI assistant until an End User connects one and signs in through Breeze's OAuth authorisation screen. Connecting an assistant is an integration the Customer switches on, in the sense of section 14.
18. What the connection can reach. The connection acts as the End User who authorised it, and is bound by exactly the permissions that End User already holds in Breeze; it can reach no project, task or person that the End User could not reach in the Service itself. At the point of connection the End User chooses between view-only access and view plus the ability to make changes. Creating several records at once, and every deletion, are two-step actions: the server returns a preview of what would change and writes nothing until the assistant sends back a confirmation.
19. What is sent, and what comes back. The assistant sends the server the words the End User typed for a search, together with the identifiers and filters needed to locate records; where the End User granted the ability to make changes, it also sends the content the End User dictated. The server returns the matching Breeze data. In summary:
| What the End User asks for | What the assistant sends | What Breeze returns |
|---|---|---|
| Who they are signed in as, and who is on their team | Nothing beyond the request itself | The End User's name, email address, team, role and permission flags, and the names and email addresses of the team members and project collaborators visible to them |
| Projects, tasks and checklists | Record identifiers and filters such as project, list, assignee, dates and tags | Project and task names, descriptions, lists, statuses, due dates, assignees, tags, custom fields and checklist items |
| Comments and project discussion | Record identifiers | The text of comments and discussion messages, with their authors and timestamps |
| Time and estimates | Record identifiers and date ranges | Logged time entries and estimates, and who recorded them |
| Search | The words typed by the End User, whether an exact phrase or a description in their own words | The tasks, comments, projects and other records that match |
| Activity | Record identifiers, date ranges and types of change | A record of what changed, when, and who changed it |
| Creating, changing, deleting and restoring records - only where the End User granted the ability to make changes | The content the End User dictated - task and checklist names, descriptions, comment and message text, durations and dates - and the identifiers of the records to be changed | A preview of what would change and, after the End User confirms, a report of what was changed |
20. What happens at the assistant's end. Once data has been returned to an AI assistant it is held by the provider of that assistant - OpenAI in the case of ChatGPT, Anthropic in the case of Claude, and so on - and what that provider does with it is governed by that provider's own terms and privacy policy, not by this one. Supplier is not a party to that relationship and does not control it. Data Subjects are encouraged to read the assistant provider's policy before connecting, in particular what it retains and whether it uses conversation content to train models, and to grant view-only access where the ability to make changes is not needed.
21. What Supplier's connector keeps. The connector service records the requests it receives, including the search words and dictated content passed with them, in its server log; those logs are kept for 14 days and are used only for security, abuse prevention and troubleshooting. On its own database the service also stores a short-lived confirmation token for each two-step change - the name of the operation and the identifiers of the records concerned - which is valid for ten minutes and is deleted when it is used or when it expires, and a per-End-User count of how many changes have been made in the current hour, which is discarded after a day. The OAuth access token issued for the connection is stored until it expires or is revoked. Supplier keeps no other record of connector traffic, and the data itself continues to live in the Service rather than being copied anywhere new.
22. Meaning-based search. Where an End User asks an assistant to find something by describing it rather than by its exact wording, the search words are converted into a numeric representation by an embedding service that Supplier runs on its own servers. Those search words are not sent to any third-party AI provider for that purpose. Supplier does not use content reached through the connector to train machine learning or artificial intelligence models.
23. Ending the connection. An End User may disconnect Breeze at any time in the AI assistant's own connector settings, which revokes that connection's access to the Service. A request to revoke a connection at the Breeze end may be sent to support@breeze.pm.
24. Upon Customer's request, Supplier will grant Customer access to, or, at Supplier's option, provide Customer with a statement of, all Personal Data that Supplier maintains about Customer, unless such information is otherwise reasonably available to Customer or Supplier is legally prohibited from disclosing such records. If any such Personal Data prove to be incorrect or misleading, Customer can ask us to correct it, or correct it themselves if they have permission and access. Registered Customers can access and correct certain of their Customer Details through the Service by visiting their personal profile page. For the avoidance of doubt, Customer acknowledges that this section applies only to "Personal Data that Supplier maintains about Customer" in Supplier's capacity as controller, and not to User Data, which Supplier stores and processes solely as the Customer's processor and on the Customer's instructions (see section 11 and the Data Processing Agreement).
25. In all cases where Supplier is allowed to disclose Customer Details to third parties, it will, as far as possible, take reasonable measures to ensure that the person to whom disclosure is made grants the respective Data Subject rights that are substantially similar to those set forth herein with respect to the processing of such Customer Details (including the right to be informed about the data maintained on the Data Subject and the right to correct or have corrected incorrect or misleading information).
26. Depending on where a Data Subject is located, they may also have the right to ask Supplier for a copy of the Personal Data it holds about them; to have inaccurate data corrected; to have data erased; to have processing restricted; to object to processing carried out on the basis of Supplier's legitimate interests; to receive their data in a portable, machine-readable form; to withdraw consent where processing is based on consent, without affecting processing already carried out on that basis; and to lodge a complaint with a data protection supervisory authority. Supplier's lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). These rights apply to Personal Data for which Supplier is the controller; a request concerning User Data is handled by the Customer that controls the relevant workspace, as described in section 11.
27. Much of this can be done without contacting Supplier at all. A Data Subject can review and correct their own details on their profile page, export their data in HTML and JSON format from within the Service, delete their user profile, delete individual projects, and cancel the account, which deletes its Content immediately. Marketing email carries an unsubscribe link in every message. Cookie preferences on the public website can be changed at any time through the "Consent preferences" link in the footer. Anything else may be requested at support@breeze.pm, and Supplier will respond within the period required by applicable law, and within one month where the GDPR applies.
28. If a Data Subject participates in Supplier's mailing or similar programme, Supplier may use their Customer Details to send them information about products, services, promotions and events that Supplier believes may be of interest to them. Any subscription to any such programme may be cancelled at will.
29. Supplier may send registered Customers certain communications relating to the Service, such as (e.g.) service announcements and administrative messages, without offering such Customers the opportunity to opt out of receiving them.
30. Supplier asks that all requests, enquiries, complaints and other communications that Customer wishes to address to Supplier with respect to this privacy policy or Data processing be submitted via the feedback feature of Supplier's website, or that such communications be sent to the following email address: support@breeze.pm.
31. Any dispute that may arise between Customer and Supplier or between an End User and Supplier in connection with this privacy policy or Supplier's data processing activities shall be subject to the jurisdiction specified in the respective Supplier's Terms of Service.
32. Supplier may amend or repeal this privacy policy at any time by posting a revised privacy policy or a new policy document in its place. If such revised or new policy includes a significant change to the way that Customer Details may be treated, Supplier will notify registered Customers of the fact that its privacy policy has changed by sending such Customers an email to the address associated with their User Account, or by posting a prominent notice on the Service.
Last revised: August 18, 2026