Privacy Policy
Effective: September 26, 2026 · Last updated: September 26, 2026
Data Controller
Name: Regcytech Kft. Registered address: 2654 Romhány, Batthyány út 48. Email: hello@regcytech.com
When We Process Personal Data
Personal data may be provided through: the contact form, consultation booking requests, development requests and estimates, readiness/assessment tools and their consultation requests, early access and preregistration, newsletter signup, cyber incident reports, bug reports (with optional attachments), partner account and profile management, and data subject requests. The data categories, purpose, legal basis and retention status of each flow are listed in the Processing Activities table at the bottom of this page.
Session Storage, Security Logs and Analytics
Storage operations required for the website to function — such as remembering your consent choice, and security and anti-abuse protection — take place without consent. Analytics measurement starts only after your analytics consent; the actually configured providers are listed in the processor table below. Without analytics consent, no data is sent to any analytics provider. We do not use marketing tracking.
Legal Basis
The legal basis differs per flow and is shown per row in the activities table. Typically: your consent (GDPR Art. 6(1)(a)), steps preceding a contract at your request (Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)), or legitimate interest (Art. 6(1)(f)). Newsletter consent can be withdrawn at any time by unsubscribing.
Retention
Contact enquiries are retained for 2 (two) years from closure of the enquiry, after which personal data is deleted. Retention rules for the remaining flows are currently under legal review; the affected rows indicate this explicitly.
Uploaded Files and Attachments
The bug report and incident report forms may accept an optional attachment. Uploaded files are stored by our database provider (Supabase, EU region); access is limited to the internal permissions needed to handle the case. Attachment retention is likewise awaiting legal confirmation — the final rule will appear in this notice.
Data Processors
The current list of processors — including transfer status — is shown in the table below. Only providers actually in use are listed; conditionally configured providers (analytics, error monitoring) appear only while their configuration is active.
Your Rights
You have the right to: (a) access your personal data (GDPR Art. 15); (b) rectification (GDPR Art. 16); (c) erasure (GDPR Art. 17); (d) restriction of processing (GDPR Art. 18); (e) data portability (GDPR Art. 20); (f) object to processing (GDPR Art. 21). To exercise your rights, write to hello@regcytech.com.
Supervisory Authority
You may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa u. 9–11., ugyfelszolgalat@naih.hu, naih.hu.
Changes to this Policy
We reserve the right to update this Privacy Policy. Changes take effect upon publication on this website; the effective and last-updated dates appear in the document header.
Processing activities
Contact enquiry
- Data subject
- Contact form submitter
- Data categories
- Name, email address, phone number (optional), company name, message content.
- Purpose
- Answering the enquiry and coordinating.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- 2 (two) years from closure of the enquiry.
Consultation booking request
- Data subject
- Visitor requesting a consultation slot
- Data categories
- Name, email address, phone number, company name, requested slot and topic.
- Purpose
- Scheduling and preparing the consultation.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- Retention rule pending legal confirmation.
Development request and estimate
- Data subject
- Visitor sending a development request / estimate
- Data categories
- Name, email address, company name, project description, budget, estimate answers.
- Purpose
- Evaluating the request and preparing an individual offer.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- Retention rule pending legal confirmation.
Readiness assessment tool
- Data subject
- Visitor using a readiness tool
- Data categories
- Answers given in the questionnaire; for a consultation request: name, company name, email address, message.
- Purpose
- Computing and sharing the result; coordinating a consultation when requested.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- Retention rule pending legal confirmation.
Early access / preregistration
- Data subject
- Visitor registering for early access / preregistration
- Data categories
- Name, email address, company name, optional fields attached to the registration.
- Purpose
- Waitlist management and notification about availability.
- Legal basis
- Consent of the data subject (GDPR Art. 6(1)(a)).
- Retention
- Retention rule pending legal confirmation.
Newsletter
- Data subject
- Newsletter subscriber
- Data categories
- Email address, subscription status, preferences, consent timestamp and source.
- Purpose
- Sending the newsletter; subscription is double opt-in, unsubscribe anytime.
- Legal basis
- Consent of the data subject (GDPR Art. 6(1)(a)).
- Retention
- Retention rule pending legal confirmation.
Cyber incident report
- Data subject
- Contact person of an organisation reporting an incident
- Data categories
- Contact details, description of the incident and — where provided — evidence/attachment.
- Purpose
- Triaging the incident and coordinating response capacity.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- Retention rule pending legal confirmation.
- Share only what the assessment needs — do not send passwords, keys or unnecessary personal data.
Bug report
- Data subject
- Visitor or user reporting a bug
- Data categories
- Contact details, bug description, optional attachment (e.g. screenshot).
- Purpose
- Reproducing and fixing the bug.
- Legal basis
- Legitimate interest of the controller in operating the service securely (GDPR Art. 6(1)(f)).
- Retention
- Retention rule pending legal confirmation.
- Do not attach passwords, tokens or confidential data not needed to reproduce the bug.
Partner account and profile
- Data subject
- User creating a partner account
- Data categories
- Email address, identifier, name, phone number, company affiliation, profile settings.
- Purpose
- Authentication, account management, handling requests linked to the user.
- Legal basis
- Performance of the account contract (GDPR Art. 6(1)(b)).
- Retention
- Retention rule pending legal confirmation.
Data subject request
- Data subject
- Person exercising data subject rights
- Data categories
- Data needed to identify the requester and the content of the request.
- Purpose
- Serving data subject requests (access, erasure etc.).
- Legal basis
- Compliance with a legal obligation — handling data subject rights requests (GDPR Art. 6(1)(c)).
- Retention
- Retention rule pending legal confirmation.
Analytics (after consent)
- Data subject
- Website visitor (only with analytics consent)
- Data categories
- Device characteristics, page-usage events, coarse session metadata.
- Purpose
- Measuring site usage. Only after analytics consent, towards the configured provider.
- Legal basis
- Consent of the data subject (GDPR Art. 6(1)(a)).
- Retention
- Retention rule pending legal confirmation.
Error monitoring
- Data subject
- Website visitor / user
- Data categories
- Technical error data: stack traces, request metadata, anonymised identifiers.
- Purpose
- Detecting and fixing technical failures.
- Legal basis
- Legitimate interest of the controller in operating the service securely (GDPR Art. 6(1)(f)).
- Retention
- Retention rule pending legal confirmation.
Security logs and rate limiting
- Data subject
- Every visitor
- Data categories
- Keys derived from IP/email, request-count metadata, server logs.
- Purpose
- Abuse protection and rate limiting on the forms.
- Legal basis
- Legitimate interest of the controller in operating the service securely (GDPR Art. 6(1)(f)).
- Retention
- Retention rule pending legal confirmation.
Transactional email
- Data subject
- Person sending an enquiry or holding an account
- Data categories
- Recipient email address and the transactional message content.
- Purpose
- Sending confirmations and system messages — not marketing.
- Legal basis
- Handling a pre-contractual enquiry — steps taken at the data subject’s request and legitimate interest (GDPR Art. 6(1)(b) and (f)).
- Retention
- Retention rule pending legal confirmation.
Data processors
The following providers take part in processing personal data. Only providers actually in use are listed.
- Vercel Inc.Infrastructure
- Purpose
- Serving the website and application, CDN.
- Data categories
- Technical log data (IP address, request metadata).
- Transfer
- Compute runs in an EU region (fra1); the provider is US-based.
- SupabaseData storage
- Purpose
- Database hosting — storage of enquiries, account data and business records.
- Data categories
- Contact details, company data, enquiry content, account identifiers.
- Transfer
- Database hosted in an EU region.
- ClerkIdentity
- Purpose
- Sign-in and account management. Authorisation is decided by our own database.
- Data categories
- Email address, identifier, sign-in metadata.
- Transfer
- US-based provider; contractual safeguards are set out in the provider terms.
- ResendCommunication
- Purpose
- Sending transactional email (confirmations, notifications).
- Data categories
- Recipient email address and message content.
- Transfer
- US-based provider; contractual safeguards are set out in the provider terms.
- LoopsCommunication
- Purpose
- Managing newsletter subscriptions and sending the newsletter.
- Data categories
- Email address, subscription status and preferences.
- Transfer
- US-based provider; contractual safeguards are set out in the provider terms.
- UpstashAbuse protection
- Purpose
- Abuse protection: rate limiting on public forms. Stores a derived identifier only, never message content.
- Data categories
- A key derived from IP address and email address, held briefly.
- Transfer
- EU-region instance where configured.
- PostHogAnalytics
- Purpose
- Product analytics, funnels and selective, masked session replay on public pages — loaded only after analytics consent.
- Data categories
- Pseudonymous usage events (page, device class, referrer category, market/language), a pseudonymous account identifier for signed-in users, and masked session recordings on public pages (no form values).
- Transfer
- PostHog EU Cloud — the EU region (Frankfurt) is selected.
| Processor | Purpose | Data categories | Transfer |
|---|---|---|---|
| Vercel Inc.Infrastructure | Serving the website and application, CDN. | Technical log data (IP address, request metadata). | Compute runs in an EU region (fra1); the provider is US-based. |
| SupabaseData storage | Database hosting — storage of enquiries, account data and business records. | Contact details, company data, enquiry content, account identifiers. | Database hosted in an EU region. |
| ClerkIdentity | Sign-in and account management. Authorisation is decided by our own database. | Email address, identifier, sign-in metadata. | US-based provider; contractual safeguards are set out in the provider terms. |
| ResendCommunication | Sending transactional email (confirmations, notifications). | Recipient email address and message content. | US-based provider; contractual safeguards are set out in the provider terms. |
| LoopsCommunication | Managing newsletter subscriptions and sending the newsletter. | Email address, subscription status and preferences. | US-based provider; contractual safeguards are set out in the provider terms. |
| UpstashAbuse protection | Abuse protection: rate limiting on public forms. Stores a derived identifier only, never message content. | A key derived from IP address and email address, held briefly. | EU-region instance where configured. |
| PostHogAnalytics | Product analytics, funnels and selective, masked session replay on public pages — loaded only after analytics consent. | Pseudonymous usage events (page, device class, referrer category, market/language), a pseudonymous account identifier for signed-in users, and masked session recordings on public pages (no form values). | PostHog EU Cloud — the EU region (Frankfurt) is selected. |
Controller contact for privacy questions: hello@regcytech.com. No data protection officer has been appointed — the statutory conditions requiring one do not apply to our current operations.
