Legal documents
Breakcold · Legal
Privacy policy
Last updated · September 3, 2026
How Breakcold collects and uses personal data, and how to exercise your privacy rights.
On this page
- 1. Who we are and when this policy applies
- 2. Data we handle and where it comes from
- 3. Our purposes and legal bases
- 4. Connected accounts, Google data and AI
- 5. Website cookies and optional tools
- 6. Who receives information
- 7. International processing
- 8. Retention and deletion
- 9. Your rights and how to exercise them
- 10. Security and changes to this policy
1. Who we are and when this policy applies
Breakcold is operated by Logike SAS, SIRET 90230339500021, 128 rue de la Boétie, 75008 Paris, France. You can contact us at support@breakcold.com for privacy requests or contact@breakcold.com for company enquiries. This policy explains our handling of personal data when you visit our website, contact us, or administer or use a Breakcold account.
Logike SAS acts as controller when it determines why and how data is used for its own account administration, billing, business communications, website operation and security. When an organization puts contacts, emails or other information into its workspace, it normally determines those purposes. We process that customer content on its instructions under our Data Processing Addendum. If that organization is itself a processor, we act as its subprocessor.
This notice is information about data handling, not consent to every use described here. Connecting an integration, accepting a service contract or browsing the website does not authorize unrelated advertising or remove your data protection rights.
Our processing is subject to the GDPR and, where applicable, the French Data Protection Act, Law No. 78-17 of 6 January 1978, as amended.
2. Data we handle and where it comes from
- Information you provide: name, professional contact details, company, account settings, subscription and billing information, requests, support messages and attachments. Payment processing may also involve payment and tax information handled by our payment provider.
- Information from your organization: invitations, workspace membership, permissions and information an administrator or colleague supplies when managing access.
- Technical information: IP address, browser and device details, timestamps, pages or features used, delivery events, error information and security logs. Optional website measurement and advertising are governed by your cookie choices.
- Connected services and customer content: authorized email and social communications, contact records, tasks, notes, files, media, audio, transcriptions, AI inputs and outputs, and integration identifiers or credentials. The information processed depends on features enabled and permissions granted.
- Other sources: service providers may supply authentication results, billing status, support context or requested enrichment results. A customer may import professional information from public websites or other sources. The customer is responsible for the lawful collection and required notice for content it controls.
Information about a named professional remains personal data even when a business email address, profile or telephone number is public. Public availability does not itself authorize unrestricted collection, outreach, profiling or reuse. Where we obtain controller data indirectly, we provide the source and other required information within the applicable time limit, normally within one month and earlier at the first communication or disclosure when required.
Information needed to establish an account, authenticate access, answer a request or issue a legally required invoice must be supplied for those activities to work. Optional fields and optional integrations may be left unused. Please avoid sending sensitive personal information in ordinary support messages.
3. Our purposes and legal bases
The following applies to processing for which Logike SAS is controller. Contract necessity applies when you are personally party to the relevant contract; it does not automatically cover every employee of a business customer.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Account and service administration | Identity, business contact details, membership, permissions and service communications. | Performance of our contract with you, or legitimate interests in administering the organization’s subscription and supporting its authorized users. |
| Billing and records | Billing identity, subscription, invoice, tax and transaction information. | Contract performance for charging an individual contracting customer; legal obligations for accounting and tax records; legitimate interests for business account administration and payment recovery. |
| Support and enquiries | Contact details, messages, relevant account information and attachments. | Steps at your request before a contract or performance of that contract, where applicable; otherwise legitimate interests in responding and helping business users. |
| Security and reliability | Authentication information, technical logs, IP and device details, error context and incident evidence. | Legitimate interests in preventing misuse and maintaining secure, reliable services; legal obligations where a specific duty applies. |
| Business communications | Professional contact details, correspondence and marketing preferences. | Consent where required; otherwise legitimate interests for relevant professional communications permitted by applicable law, with a simple right to object. |
| Optional website services | Website activity and identifiers used by analytics, marketing or support tools. | Consent for optional browser storage/access and associated optional processing, as explained in the cookie policy. Necessary preference storage supports operation of your choices. |
| Disputes and legal requests | Relevant account, payment, correspondence and incident records. | Legal obligations for binding requests; legitimate interests in obtaining advice and establishing, exercising or defending legal claims. |
When we rely on legitimate interests, we consider the purpose, necessity and effect on people and limit the processing accordingly. You can ask us for information about that assessment and object on grounds relating to your situation. Direct marketing objections will be honored without requiring you to explain your situation. A customer chooses the lawful basis for processing its CRM content; our service contract is not a lawful basis for that customer’s collection or outreach.
4. Connected accounts, Google data and AI
An integration processes the information needed for the functions you authorize, such as synchronizing contacts, displaying and sending communications or organizing CRM activity. Review the permission screen before connecting an account. Disconnecting access or revoking permissions at the provider prevents further authorized retrieval but does not automatically erase records already imported; request deletion from your workspace administrator or our support team as appropriate.
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve appropriate user-facing features. It is not used for advertising, retargeting or building generalized AI or machine-learning models. Transfers and human access are limited to the purposes and exceptions permitted by that policy, including necessary service delivery, security, legal obligations and specifically authorized access.
Where a customer uses AI, audio transcription or summarization, the inputs needed for that request and resulting outputs may pass to the relevant providers identified in the Data Processing Addendum. This is feature-dependent processing on the customer’s instructions, not permission to repurpose mailbox contents for advertising or general model training. AI outputs may be inaccurate and should be reviewed before use. Customers remain responsible for decisions they make about people using those outputs.
Depending on the connection method you select, a social integration may require session cookies, access tokens or other authentication material from the account you authorize. These credentials allow the requested connection, synchronization or communication functions. They are personal and security-sensitive data and are restricted to those purposes. Disconnect the integration to stop its further use and contact support for deletion of retained connection data. This authentication material is separate from optional advertising cookies on our website.
5. Website cookies and optional tools
Our Cookie Policy explains the available choices. Optional website analytics uses Plausible and PostHog; the Marketing category enables Google Ads, Meta, FirstPromoter and automatic loading of YouTube video previews and players; optional support uses Crisp. These categories are controlled separately. Refusing optional categories does not prevent access to the legal pages. You can also choose to load an individual blocked video without changing your saved preferences.
Your preference is saved in the browser for six months and can be changed through the website’s cookie settings. The preference belongs to that browser: clearing storage or using another browser or device may require a new choice. Withdrawal stops future optional loading under that choice; it does not reverse processing already performed lawfully or automatically erase information held by a provider. See the cookie policy for the effects and limitations of withdrawing a choice.
6. Who receives information
Authorized members of your organization can access workspace information according to their permissions. Our personnel and service providers receive information needed for their assigned functions: infrastructure, authentication, billing, transactional communications, support, monitoring and requested enrichment or AI processing. The provider inventory describes the product providers and their functions; the cookie policy covers optional website tools.
A provider may act as our processor for a defined service and as an independent controller for a separate activity, such as its own statutory payment checks. Connected third-party platforms also apply their own policies to their services. Inclusion in an inventory does not authorize every provider to receive every category of data.
We may disclose relevant information to professional advisers, competent authorities where legally required, or parties involved in a proposed corporate transaction subject to appropriate confidentiality and data protection arrangements. A transaction does not remove existing purpose restrictions or transfer safeguards.
7. International processing
Logike SAS is established in France. Provider locations and access arrangements depend on the service and configuration; this policy does not promise that all processing remains in a particular country. Remote access from another country can also be a transfer.
Where a transfer outside the European Economic Area requires a safeguard, we use an applicable adequacy decision or an appropriate transfer mechanism, such as the European Commission’s standard contractual clauses, with an assessment and supplementary measures where necessary. The customer DPA addresses processor transfers. Contact support@breakcold.com for information about the safeguard applicable to your data or a copy, with justified redactions to protect confidential information.
8. Retention and deletion
We retain controller data only while needed for the stated purpose, taking account of the relationship, the record’s sensitivity, operational need, legal duties and relevant limitation periods. Account administration records are kept during the relationship and then limited to what is needed for closure, legal records or claims. Support and security records are retained according to the issue, investigation and proportionate evidential need, not indefinitely by default.
French accounting documents and supporting invoices are retained for ten years from the close of the relevant financial year, as described by Service Public. This does not justify retaining all CRM content for ten years. Marketing data is removed from active campaigns when you unsubscribe; a minimal suppression record may remain to honor your objection.
Customers determine the retention of workspace content subject to the DPA. Deletion requests must cover the relevant workspace or record; canceling billing, disconnecting an integration and deleting content are different actions. Legally required records are isolated from ordinary use. Backup copies are subject to restricted access and the applicable deletion lifecycle, with deletion instructions reapplied if a backup is restored. Ask support for the applicable export and deletion arrangements.
The following periods apply to the corresponding features in the Breakcold application at us.breakcold.com and eu.breakcold.com. They describe specific copies, not a general retention period for every account, provider or backup.
| Data or copy | Period and starting point | What happens at the end |
|---|---|---|
| Deleted CRM record snapshots | 30 days from deletion. An authorized user can permanently delete a restoration snapshot sooner. | Scheduled cleanup removes expired snapshots. This does not delete copies in the original connected service. |
| Generated CSV export files | Available to download for seven days after the export completes. | Expired downloads are refused and the generated file is scheduled for cleanup. The original CRM records remain subject to their own lifecycle. |
| CSV import working rows | Scheduled cleanup applies 90 days after an import finishes, fails or is cancelled. | Working rows are removed. CRM records created by the import remain until separately deleted. |
| Breakcold copies of calling recordings and voicemail | The workspace selects 30, 90, 180 or 365 days, measured from the time the copy is stored. The default is 90 days. | Scheduled cleanup removes expired copies. This setting does not determine retention of meeting recordings, transcripts or copies held by the source calling provider. |
| DPA compliance records | Five years after termination of the DPA. | Retain only the instructions, agreements, requests and evidence needed to demonstrate compliance. This is not permission to retain all workspace content for five years. |
Removing a workspace from the app does not itself confirm permanent erasure of all stored data and provider copies. For complete workspace erasure, return of data or confirmation of completion, contact support@breakcold.com with the workspace concerned. We handle the request under the DPA and applicable data protection rights. Billing cancellation, workspace removal and revocation of a connected account are separate actions.
9. Your rights and how to exercise them
- You may request access and a copy, correction, erasure or restriction where the relevant conditions apply. Data portability applies to eligible data you provided and that is processed by automated means on consent or contract grounds.
- You can withdraw consent at any time without affecting earlier lawful processing. You can object to legitimate-interest processing based on your situation and object to direct marketing at any time, including associated profiling.
- You have protections concerning decisions based solely on automated processing that produce legal or similarly significant effects, subject to the conditions and exceptions in applicable law. This policy does not authorize such decisions about you.
Write to support@breakcold.com, identifying the relevant account or processing and your request. We may ask for proportionate additional information if we reasonably need to verify identity; a copy of an identity document is not routinely required. Requests are normally free. Any exceptional fee or refusal must meet the legal conditions and will be explained.
We respond without undue delay and normally within one month. If complexity or the number of requests makes an extension necessary, we may extend by up to two further months and will explain the reason within the first month. If we cannot act, we will explain why and the available complaint and judicial remedies. See the CNIL’s guidance on response times.
For customer-controlled workspace content, contact that customer first. If you contact us, we help route the request and assist the customer under the DPA. You may complain to the CNIL or the competent supervisory authority, including where you live or work in the EEA. Contacting us first is helpful but is not a condition for a complaint.
Where French law applies, you may also give instructions about the retention, deletion and disclosure of your personal data after your death. Send these instructions to support@breakcold.com. The applicable rules are explained in the CNIL guidance on data after death.
10. Security and changes to this policy
We apply safeguards appropriate to the data and risks, including controlled access, protection of credentials, secure transmission and incident handling. Our contractual security commitments for customer content appear in the DPA. No online service can eliminate every risk, and this policy does not claim a particular certification or an absolute security guarantee.
We update this policy when our processing or applicable requirements change. The date above identifies this version. For material changes affecting how we use your information, we provide appropriate notice; if a new use requires consent, publication of an updated notice does not replace that consent. Read the other documents in our legal center for the terms governing particular services.