YOUR DATA & PRIVACY
This statement explains how BR2, SIA (BR²SEC) processes and safeguards your personal data.
1. Data Controller & Contact Details
The data controller responsible for personal data processing is BR2, SIA (registration number: 50203765211, legal address: Staiceles iela 1 k-1 - 35, Riga, LV-1035, Latvia), hereinafter referred to as "BR²SEC", "We", or "Us".
If you have questions regarding this Privacy Policy or personal data processing, contact our Data Protection Officer at [email protected] or [email protected].
2. Personal Data Processed & Legal Grounds
We process personal data under GDPR requirements for the following specific purposes:
- Inquiry Handling & Support (GDPR Art. 6(1)(b) & (f)): Full name, work email, phone, organization, and scoping details submitted via forms. Transmitted over encrypted HTTPS connections to internal CMS/CRM systems.
- Security Service Delivery & Contract Execution (GDPR Art. 6(1)(b)): Client representative contact details for penetration testing, audits, and advisory engagements.
- Web Security & DDoS Protection (GDPR Art. 6(1)(f)): IP addresses, request logs, and user-agent metadata processed by Cloudflare security edge to prevent cyber threats.
- Statutory Accounting & Legal Duties (GDPR Art. 6(1)(c)): Contracts, invoices, and accounting records maintained under Latvian statutory retention laws.
3. Data Recipients & Safeguards
BR²SEC maintains strict confidentiality. Personal data is never sold or disclosed to third parties for marketing purposes.
Data is shared solely with trusted infrastructure processors (such as Cloudflare Inc. for edge security and CDN performance) governed by Data Processing Agreements (DPAs) incorporating EU Standard Contractual Clauses (SCCs).
4. Retention Periods
Inquiries and contact records are retained for 12 months from the last communication date unless converted into an active service contract. Executed contracts and accounting records are stored for 10 years pursuant to Latvian accounting laws. Server security logs are automatically purged after 30 days.
5. Your GDPR Rights & Supervisory Authority
Under GDPR, you hold the right to request access, rectification, erasure, restriction, objection to processing, and data portability.
Submit data subject requests to [email protected]. You reserve the right to lodge complaints with the Data State Inspectorate (DVI) of Latvia (Elijas street 17, Riga, LV-1050, email: [email protected]).