Legal

Privacy policy

Effective from: 1 August 2026

1. Controller

1.1 The controller is cybbrio s.r.o., Company ID 19674121, registered office at Příkop 843/4, Zábrdovice, 602 00 Brno, Czech Republic, registered in the Commercial Register kept by the Regional Court in Brno, file no. C 135625 (the "controller"). All personal data processed by the controller is treated as strictly confidential and handled in line with Czech and EU data protection law.

1.2 The controller processes personal data under Act No. 110/2019 Coll., on personal data processing, and Regulation (EU) 2016/679 ("GDPR").

1.3 Personal data is collected among other channels through the website at https://www.cybbrio.cz.

2. Data we process

  1. Handling enquiries (e-mail, phone). Data: name, e-mail, phone, content of the message. Recipients: our e-mail and hosting providers. Retention: 3 years from the last communication; for concluded contracts as required by law.
  2. Performance of a contract. Data: identification, contact and billing data, data required to deliver the service. Retention: for the term of the contract and afterwards as required by law.
  3. Accounting and tax duties. Data: billing and payment data. Retention: 10 years under tax and accounting rules.
  4. Website operation and security. Data: IP address and technical data in server logs. Legal basis: legitimate interest in network and information security. Retention: 6 months at most.
  5. Traffic measurement (consent only). If introduced, the tool, scope and retention will be listed here. Legal basis: consent.

2.2 Data is processed for as long as necessary to secure the rights and obligations arising from our relationship, for the period required by law, or for the period covered by your consent.

2.3 Processing is both manual and automated. There is no automated decision-making or profiling with legal effects.

3. Confidentiality and security

3.1 Our work produces security findings about clients' systems. All information obtained during an engagement is confidential, protected by contractual secrecy and shared only with people working on the engagement.

3.2 We apply technical and organisational measures proportionate to the risk: access control, multi-factor authentication, encryption at rest and in transit, environment separation, logging and regular review of permissions.

4. Your rights

You have the right of access, rectification and erasure, restriction of processing, data portability, the right to object to processing based on legitimate interest, the right to withdraw consent at any time and the right to an explanation. You may also lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7.

5. Transfers to third countries

We process personal data primarily within the European Union. Where a transfer to a third country occurs (for example a font or cloud provider), it is based on standard contractual clauses or another appropriate safeguard under Chapter V of the GDPR.

6. Questions

For data protection questions write to info (at) cybbrio.cz. Security issues with this website should follow our vulnerability disclosure policy.