PRIVACY POLICY

Your Privacy Matters

At GoodBreach, we're committed to protecting your personal information and being transparent about how we collect, use, and safeguard your data.

Last updated: October 8, 2025

Introduction

Effective Date: 4/11/2025

GoodBreach Technologies Ltd (“we”, “our”, or “us”) is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the GoodBreach mobile application, website, and related services (together, the “Services”). GoodBreach is currently in closed beta testing with approximately 20 participants. This limited testing phase allows us to refine our platform before wider release. During this period, we follow the principles of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, even though we are not yet registered with the Information Commissioner’s Office (ICO). Our commitment is to ensure privacy, transparency, and user trust are foundational to how we design and deliver our Services. Once the product moves beyond beta, we will complete full regulatory registration and update this policy accordingly. GoodBreach helps young adults (ages 16–30) develop better financial habits through AI-driven behavioural nudges, social savings challenges, and open banking insights. Our platform analyses your spending behaviour to suggest mindful saving opportunities, such as reducing non-essential spending and participating in group challenges with friends or the wider community.

Definitions

Personal Data

Information that can identify you directly or indirectly, such as your name, email address, account information, or online identifiers.

Special Category Data

Sensitive data that receives extra protection under law, including health, biometric, or philosophical belief information. GoodBreach does not collect special category data.

Open Banking Data

Account and transaction data accessed through regulated Account Information Service Providers (AISPs) under your explicit consent.

Data We Collect

A. Information You Provide Directly

During the beta phase, GoodBreach may collect and process the following categories of data: Account details: name, email address, phone number, and password. Optional profile details: photo, username, savings goals, and preferences. Feedback or responses to in-app surveys or beta testing forms.

B. Information Accessed via Open Banking (with your explicit consent)

If you choose to connect a bank account, we securely access: Account balance and transaction history Merchant information and spending categories Frequency and amount of discretionary spending (e.g., coffee, food delivery, entertainment) This data helps generate AI-powered insights and personalised savings nudges. Note: Open Banking data is used solely to help you track spending patterns and identify saving opportunities. We do not initiate, authorize, or execute any financial transactions on your behalf.

C. Automatically Collected Data

Device identifiers, IP address, and app usage metrics Behavioural analytics (e.g., feature usage, session frequency) During closed beta testing, we use minimal tracking to understand how the app is being used and to identify technical issues. We do not collect special category (sensitive) data such as health information, biometric data, or details about your beliefs or personal circumstances.

How We Use Your Data

We process your personal data to: Provide and improve our beta app and its core functionalities Deliver AI-driven spending insights and savings suggestions Enable participation in challenges, community goals, and leaderboards Communicate updates, product improvements, and feedback opportunities Ensure compliance with data protection principles and prevent misuse Prepare for full regulatory compliance and future ICO registration "We will never sell, rent, or trade your personal information to third parties"

Legal Bases for Processing

As we operate under beta testing, we process personal data under the following legal bases: Consent: You choose to connect your bank account, share data, or join challenges. Legitimate Interest: To operate, test, and improve the beta platform securely. Contractual Necessity: To provide the Services you signed up for. Legal Obligation (future): Once regulated, we will process data under compliance requirements such as AML/KYC. Other Users: When you participate in challenges or community features, certain information (such as your username, profile photo, and challenge progress) may be visible to other participants. You can control your visibility settings in the app. You can withdraw consent anytime via the app or by emailing founder@goodbreach.com

Behavioural Insights and Notifications

GoodBreach shows you insights about your spending patterns to help you track your habits and reach your savings goals. These may include: Summaries of your spending by category Suggestions for areas where you might save more Invitations to join optional savings challenges These insights are automatic suggestions based on your transaction data and app usage. They're designed to help you manage your money better, but they are not financial advice. You're always in control - all savings tracking is voluntary and virtual only. You can turn off notifications in your app settings or contact us at founder@goodbreach.com

Data Sharing

We share your data only when necessary and under strict confidentiality agreements with: Open Banking Provider: To securely access your transaction data Cloud Hosting Services (e.g., AWS, Azure): For encrypted data storage Analytics and Feedback Tools: To improve beta performance All partners are required to comply with UK GDPR standards and handle your data securely.

Data Retention

We retain your data only as long as necessary to: Operate and evaluate the beta program Maintain your account and user experience Meet potential legal and technical obligations In general, we retain beta user data for up to 12 months after collection or account deletion, unless required for compliance or debugging. Once beta testing concludes, inactive user data will be securely deleted or anonymised.

Security Measures

We implement appropriate technical and organizational measures to protect your personal data, including: Encryption of data in transit and at rest Access controls and authentication Regular security assessments Secure development practices However, as we are in closed beta testing, our security infrastructure is still being refined. We cannot guarantee absolute security but are committed to following industry best practices.

Your Rights

Under UK data protection law, you have the right to: Access your personal data Request correction of inaccurate data Request deletion (“right to be forgotten”) Restrict or object to processing Request data portability Withdraw consent at any time During beta testing, all data protection queries should be directed to our founder at founder@goodbreach.com. We aim to respond within 30 days of receiving your request.

International Data Transfers

We primarily store and process your data within the United Kingdom (UK) and the European Economic Area (EEA). However, some members of our development and technical support team are based in India and may have limited access to personal data when required to maintain or improve our Services during the closed beta phase. Current safeguards during beta testing: Access is restricted to essential development and support personnel only All team members have signed confidentiality agreements Data is encrypted in transit and at rest using industry-standard protocols Access is granted on a need-to-know basis for specific development tasks Please note: As we are in closed beta testing, we have not yet implemented formal Standard Contractual Clauses (SCCs) or regular audit processes. We are working toward full data protection compliance as we prepare for public launch. By participating in this closed beta, you acknowledge and accept these current data transfer arrangements. Before full launch, we will implement comprehensive international data transfer safeguards including SCCs and formal audit procedures to ensure full compliance with UK GDPR requirements.

Beta Testing Notice

As a closed beta participant, you understand that: The app is in active development and may contain bugs or errors Features and functionality may change without notice Your feedback is valuable and may be used to improve the product The service may be discontinued or modified at any time during beta Data practices may evolve as we move toward full launch

Cookies and Analytics

We use cookies and similar technologies to: Remember your preferences and settings Analyze app usage and performance Improve user experience During closed beta, we use minimal analytics. You can manage cookie preferences through your device settings. Important: GoodBreach operates as a financial tracking and goal-setting tool only. We do not hold, transfer, or process real money. All savings recorded in the app are virtual records for your personal tracking purposes. No actual funds are moved from your bank accounts through our Services.

Questions: About Your Privacy?

If you have any questions about this Privacy Policy or how we handle your data, please don't hesitate to contact us.