Privacy Policy
Effective 2026-09-11 (subject to change on legal review) · Version privacy-draft-2026-09-11
This Privacy Policy explains how Breachr OÜ handles personal data. Please read it alongside our Terms of Use and, if you run security tests through breachr, our Permission to Penetrate.
1. Who we are
breachr is operated by Breachr OÜ, a company incorporated in Estonia.
Registered name: Breachr OÜ
Registry (äriregister) code: 100010009prov.
Registered address: 1b St Hammond Street, Estoniaprov.
Contact: legal@breachr.ai
Data protection contact: dpo@breachr.ai
In this policy "breachr", "we", "us" and "our" mean Breachr OÜ. "You" means the individual whose personal data we handle.
2. The two roles we play, and why it matters
We handle personal data in two distinct roles. The role determines who decides what happens to your data, and it changes which parts of this policy apply to you.
When you use our website, book a call, or contact us, we are the controller. We decide why and how your personal data is processed. Section 3 onward applies to you.
When you run a security test through the platform, we are the processor and your organisation is the controller. Your organisation decides what is tested and what data enters the platform. We process scan data on your organisation's documented instructions under our Data Processing Agreement, which forms part of our Terms of Use and is published at breachr.ai/dpa. If you are an individual employee of a customer, your organisation's own privacy notice governs that data, not this policy.
This split is deliberate and we hold to it. We do not repurpose customer scan data as if it were ours. Section 8 sets out exactly what we do and do not do with it.
3. What we collect when we act as controller
Information you give us. Your name, work email, company, job title and anything you write to us when you book a call, open an account, contact support, or reply to us.
Account and billing information. Login identifiers, authentication data, and the billing details needed to take payment. Card data is handled by our payment providers and does not reach our servers.
Product usage information. How you and your team use the portal: pages visited, features used, actions taken, journeys through the product, device and browser information, and approximate location derived from IP. We use this to run, secure and improve breachr. Section 6 explains our analytics in detail.
Information from our website. Cookieless, aggregated analytics about site visits. We do not use advertising cookies and we do not run a consent banner for analytics, because our website analytics do not set cookies or track you across other sites. See section 6.
We do not seek special category data (health, biometrics, political views and the like) about website visitors, and we ask you not to send it to us.
4. Why we process your data, and our legal basis
What we do
Why
Legal basis (GDPR Art. 6)
Run your account and deliver the service
To provide what you signed up for
Performance of a contract
Take payment
To bill for the service
Performance of a contract
Secure the platform and prevent abuse
To keep breachr and its users safe
Legitimate interests
Understand and improve product usage
To make breachr better through product-led growth
Legitimate interests
Respond to your enquiries
To answer you
Legitimate interests / pre-contract steps
Send service and security notices
To tell you about things that affect your account
Performance of a contract / legitimate interests
Send marketing to business contacts
To tell you about breachr
Legitimate interests, with opt-out
Meet our legal and regulatory duties
Because the law requires it
Legal obligation
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded our processing is proportionate and expected. You can object at any time (section 9), and for product analytics you can opt out.
5. Where your data lives, and the one honest exception
Your breachr environment and all scan data are hosted in the European Union, on Amazon Web Services in the Frankfurt region. Scan targets, findings, evidence and reports are stored and processed within the EU.
There is one transfer we will not hide from you, because a security company that misdescribes its own architecture does not deserve your trust.
The AI reasoning layer. breachr uses an AI reasoning layer to analyse findings and reduce false positives. Where that layer calls an external model provider whose infrastructure sits outside the EU, a limited transfer occurs. Today this applies to our language-model provider, reached via OpenRouter, whose inference runs on infrastructure in the United States. That transfer is:
- limited to the minimum needed to analyse a finding, and never used to build products for anyone other than you;
- governed by the European Commission's Standard Contractual Clauses, together with the additional safeguards required following the Schrems II ruling; and
- being migrated to EU in-region routing, after which this exception falls away.
We do not make blanket claims that your data never leaves the EU, because that would not be true while this single inference hop exists. We would rather tell you precisely where the boundary is.
6. Analytics, and why there is no cookie banner
Website analytics (Umami Cloud). We measure website traffic with Umami, a cookieless, privacy-first analytics tool. It does not set cookies, does not create a persistent identifier for you, and does not track you across other websites. Because it does not store or access information on your device in a way that requires consent, we do not show a cookie banner for it.
Product analytics (PostHog EU). Inside the portal we record how the product is used, so that we can improve it. This is product-led growth: we watch where users get stuck, which features help, and how journeys flow, then we fix and build accordingly. We do this on the EU-hosted region of PostHog.
We hold ourselves to a hard limit here, and we want you to know it precisely. Our product analytics never capture your scan targets, target URLs, credentials, findings, reports, or any customer data. Every input field, credential field and findings view is masked at the point of capture and never reaches the analytics tool. We record how you move through the product, not the security-sensitive content you put into it. We rely on legitimate interests for this, and you can opt out at any time by contacting legal@breachr.ai.
7. How long we keep it
We keep personal data only as long as we need it.
Account data: for as long as your account is active, then for up to [RETENTION PERIOD, e.g. 12 months] after closure, unless we must keep it longer for legal reasons.
Scan data: as instructed by your organisation under the Data Processing Agreement, then deleted or crypto-shredded (section 9).
Billing records: for the period required by Estonian and EU accounting and tax law, typically [7 years].
Audit and security logs: in an append-only store for [RETENTION PERIOD], for security, dispute resolution and regulatory evidence.
Marketing contacts: until you opt out.
8. What we do, and never do, with scan data
This is the section our customers read most closely, so we have made it plain.
We never sell your scan data. Not your targets, not your findings, not your reports, not anything that identifies you or your systems. Not to anyone, for any price.
We never use your scan data for our own commercial purposes beyond delivering the service to you, except as described in the next paragraph, which does not use your data at all in any identifying form.
Aggregated, anonymised industry insight. We may create aggregated, anonymised and statistical insight derived from platform activity. This insight never identifies you, your systems, your findings or your customers, and it cannot be reversed to do so. We may use it to improve breachr, to produce industry benchmarks, and to support regulators and industry bodies in strengthening the cyber resilience of the financial sector. Your raw scan data, your findings, your reports and anything that identifies you or your systems play no part in this once anonymised, and are never sold, shared or used for any other purpose. The right to create these anonymised datasets is set out in our Terms of Use and Data Processing Agreement (breachr.ai/dpa).
9. Your rights
Under the GDPR you have the right to access your data, to correct it, to erase it, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it. You also have the right to object to direct marketing at any time.
To exercise any right, contact dpo@breachr.ai. We respond within one month.
Erasure and our crypto-shred approach. Some of our security and audit records are held in append-only stores that, by design, cannot have individual rows deleted, because deletability would destroy their integrity as evidence. To honour erasure without weakening that integrity, we encrypt customer data with keys unique to each customer and, on a valid erasure request, we destroy the relevant key. The underlying record becomes permanently unreadable and unrecoverable by anyone, including us. This achieves erasure in substance: the data can never again be rendered into personal data. We will explain, on request, which data we can hard-delete and which we crypto-shred.
You have the right to complain to a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). You may also complain to the authority in your own country.
10. Sub-processors
We use a small set of trusted service providers to run breachr. Our current sub-processors, what they do, and where they process data, are listed at breachr.ai/subprocessors. We keep that list current and give notice of changes as required by our Data Processing Agreement.
11. Security
We hold ourselves to the standard we sell. Data is encrypted in transit and at rest, access is least-privilege and logged, keys are managed in a dedicated key-management service, and we keep an append-only audit trail of security-relevant events. No security is absolute, and we do not pretend otherwise, but we build breachr to the posture we would expect of a firm we tested.
12. Children
breachr is a business tool sold to financial institutions. It is not directed at anyone under 18 and we do not knowingly collect their data.
13. Changes
We may update this policy. When we make a material change we will update the version and date above and, where appropriate, tell you directly. The version in force is always the one published here.
14. Contact
Questions about this policy or your data: dpo@breachr.ai
General legal contact: legal@breachr.ai
Breachr OÜ, 1b St Hammond Street, Estoniaprov., Estonia.