Privacy Policy

Last updated: April 2026

Version recorded at sign-up and consent: 2026-04-08

This policy describes how we process personal data in line with the GDPR/AVG. A register of sub-processors and transfer tools will be published or available on request as operations scale. Use the Contact page for access, erasure, or portability requests (see the subject line we suggest there).

Who we are

MyBrixa operates the service at mybrixa.com. The controller is the legal entity operating MyBrixa. For contact until a full legal notice is published, use the email on the Contact page.

Data we collect

We collect: (a) account data — email address, display name, locale preference; (b) usage data — modules you activate, timestamps; (c) technical data — IP address, browser type, device info, and logs for security and reliability. We do not sell your personal data.

Purposes and legal bases

We process data to run the service and perform our contract with you (GDPR Art. 6(1)(b)), to secure accounts and improve the product where proportionate (legitimate interest, Art. 6(1)(f)), for optional marketing only with your consent (Art. 6(1)(a)), for analytics only after you accept analytics cookies (Art. 6(1)(a)), and where the law requires (Art. 6(1)(c)).

Processors and data sharing

We use payment, hosting, and database services provided by partners who process data on our behalf under data-processing agreements. If you opt in, we use an analytics tool for aggregate website statistics; the analytics script is not loaded before you consent, and the provider may process data outside the EEA using approved safeguards (e.g. Standard Contractual Clauses).

Cookies and similar technologies

Essential cookies: required for sign-in, security, locale, and similar core functions (e.g. session and authentication state). Analytics: if you click “Accept analytics”, we load Google Analytics (gtag) from Google; Google may set its own cookies or identifiers. We store a first-party cookie to remember your choice (name: mbx_analytics_consent, values granted or denied). You can change your mind anytime: use “Cookie settings” in the site footer to clear the choice and see the banner again, or set your browser to block cookies (some features may not work).

Retention

We retain account data for as long as your account exists. After account deletion, we keep legally required records (e.g. accounting data) for the period required by law. Aggregated or anonymised statistics may be kept where they no longer identify you.

Your rights

Where the GDPR/AVG applies, you may have the rights in Articles 15–22, including access, rectification, erasure, restriction, portability, and objection, depending on the case. We generally respond within one month (this may be extended in complex cases, as the law allows). Contact us through the Contact page; use “Data request” in the subject for privacy messages so we can prioritise them.

International transfers

Some providers may process data in the United States or other non-EEA countries. We use approved transfer tools (such as the EU–US Data Privacy Framework where applicable, Standard Contractual Clauses, and supplementary measures as needed). You may request more detail about a specific transfer.

Supervisory authority

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or of the alleged infringement. In the Netherlands, the authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). A list of EU data protection authorities is available from the European Data Protection Board (edpb.europa.eu).