Privacy Policy

Last updated: January 1, 2026

1. Operator

The operator of personal data is NIS2 Platform. Contact for privacy questions: privacy@kyberbezpecnost.cloud

2. What data we collect

When using our platform, we may collect the following data: Registration data: • Name and surname • Email • Company name • Company ID (IČO) • Business sector Assessment data: • Answers to NIS2 readiness questions • Evaluation results Technical data: • IP address • Browser type • Cookies (see section 6)

3. Purpose of processing

We process your data for the following purposes: • Providing platform services • Generating customized compliance documents • Invoicing and accounting • Communication regarding services • Improving services and user experience

4. Legal basis for processing

We process your data based on: • Contract performance - providing ordered services • Legitimate interest - improving services • Legal obligation - accounting, invoicing • Consent - marketing communication (if granted)

5. Data sharing

We may share your data with the following third parties: • GoCardless - payment processing • Supabase - data storage (EU servers) • OpenAI - document generation (without personal data) • Resend - email sending All partners are bound by strict data protection agreements.

6. Cookies

We use the following types of cookies: Necessary cookies: • Authentication and security • Language settings Analytical cookies (optional): • Traffic measurement • Service improvement You can change cookie settings in your browser.

7. Your rights

You have the right to: • Access your data • Correct incorrect data • Delete data ("right to be forgotten") • Data portability • Object to processing • Withdraw consent To exercise your rights, contact us at: privacy@kyberbezpecnost.cloud

8. Data retention

We retain your data for: • Registration data - for the duration of the account + 3 years • Invoice data - 10 years (legal obligation) • Assessment data - for the duration of the account After the period expires, data is securely deleted.

9. Security

We protect your data using: • Encryption in transit (TLS/SSL) • Encryption at rest • Access controls • Regular security audits In case of a security breach, we will inform you in accordance with GDPR.

10. Contact and complaints

For questions or complaints, contact us: Email: privacy@kyberbezpecnost.cloud You also have the right to file a complaint with a supervisory authority.