Privacy Policy
Last updated: January 1, 2026
1. Operator
The operator of personal data is NIS2 Platform.
Contact for privacy questions: privacy@kyberbezpecnost.cloud
2. What data we collect
When using our platform, we may collect the following data:
Registration data:
• Name and surname
• Email
• Company name
• Company ID (IČO)
• Business sector
Assessment data:
• Answers to NIS2 readiness questions
• Evaluation results
Technical data:
• IP address
• Browser type
• Cookies (see section 6)
3. Purpose of processing
We process your data for the following purposes:
• Providing platform services
• Generating customized compliance documents
• Invoicing and accounting
• Communication regarding services
• Improving services and user experience
4. Legal basis for processing
We process your data based on:
• Contract performance - providing ordered services
• Legitimate interest - improving services
• Legal obligation - accounting, invoicing
• Consent - marketing communication (if granted)
5. Data sharing
We may share your data with the following third parties:
• GoCardless - payment processing
• Supabase - data storage (EU servers)
• OpenAI - document generation (without personal data)
• Resend - email sending
All partners are bound by strict data protection agreements.
6. Cookies
We use the following types of cookies:
Necessary cookies:
• Authentication and security
• Language settings
Analytical cookies (optional):
• Traffic measurement
• Service improvement
You can change cookie settings in your browser.
7. Your rights
You have the right to:
• Access your data
• Correct incorrect data
• Delete data ("right to be forgotten")
• Data portability
• Object to processing
• Withdraw consent
To exercise your rights, contact us at: privacy@kyberbezpecnost.cloud
8. Data retention
We retain your data for:
• Registration data - for the duration of the account + 3 years
• Invoice data - 10 years (legal obligation)
• Assessment data - for the duration of the account
After the period expires, data is securely deleted.
9. Security
We protect your data using:
• Encryption in transit (TLS/SSL)
• Encryption at rest
• Access controls
• Regular security audits
In case of a security breach, we will inform you in accordance with GDPR.
10. Contact and complaints
For questions or complaints, contact us:
Email: privacy@kyberbezpecnost.cloud
You also have the right to file a complaint with a supervisory authority.