Privacy Policy

Last updated: 2026-09-01

1. The controller

Controller: [Szolgáltató cégneve / Provider's legal name] (registered address: [Székhely / Registered address]; tax number: [Adószám / Tax number]; company registration number: [Cégjegyzékszám / Company registration number]). For privacy matters write to [kapcsolat@example.hu].

This notice provides the information required by Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) about the processing for which the Provider is the controller. For the customer records our Customers keep in the system the Provider is a processor; the Data Processing Agreement covers that.

2. Two roles: controller and processor

Two kinds of personal data exist in MiniCRM, and the distinction matters.

  • Account data: the data of the person who registers and of invited users (name, email, password, phone number, sign-in details). The Provider is the controller of these, and this notice is about them.
  • Customer data: what a Customer records in its own CRM — its own customers' and partners' details. The Customer is the controller of these and the Provider is the processor. If a company keeps your data in MiniCRM, exercise your rights with that company first; the Provider will help pass the request on.

3. Data, purposes, legal bases and retention

Creating an account and providing the service — name, email address, password (stored only as an irreversible hash), language, time zone, phone number (optional), role, and the time the Terms were accepted. Legal basis: performance of a contract (Article 6(1)(b)). Retention: for the life of the account; on account deletion personal data is anonymised, on organisation deletion it is deleted for good.

Confirming or changing an email address — a single-use link valid for 24 hours, sent to the address. Legal basis: performance of a contract. Retention: until used or expired, at most 30 days.

Sign-in and sessions — the session identifier (hashed), IP address, browser identifier (user agent), time of sign-in and of last activity. Purpose: account security, and letting you see and sign out the devices you are signed in on. Legal basis: performance of a contract and the Provider's legitimate interest in preventing abuse (Article 6(1)(f)). Retention: a session lives at most 30 days, or until signed out.

Failed sign-in attempts — a counter per email address and per IP address. Purpose: stopping password guessing. Legal basis: legitimate interest. Retention: at most 2 hours.

Two-step verification — the authenticator key (encrypted) and recovery codes (hashed). Legal basis: performance of a contract; enabling it is voluntary. Retention: until switched off or the account is deleted.

Audit log — the organisation's significant actions (sign-in, password change, role change, export, deletion) with time, user id and IP address. Purpose: accountability for the organisation's administrators and investigation of security incidents. Legal basis: legitimate interest. Retention: for the life of the organisation.

Billing and subscription — the organisation's name, address and tax number, the contact's name and email, payment records. The Provider never sees or stores card numbers; the payment provider handles them. Legal basis: legal obligation (Section 169 of Act C of 2000 on Accounting) and performance of a contract. Retention: 8 years for accounting records.

Support and contact — the details given in the enquiry. Legal basis: legitimate interest or performance of a contract. Retention: 1 year after the enquiry is closed.

Service messages — non-marketing notices about the service (confirmation links, password reset, invoices, scheduled maintenance, changes to the Terms). Legal basis: performance of a contract. Marketing messages are sent only with separate, revocable consent.

4. Cookies and local storage

MiniCRM uses only strictly necessary cookies, which under Section 155(4) of Act C of 2003 on Electronic Communications (implementing the ePrivacy Directive) need no consent. No tracking, analytics or advertising cookies, and no third-party cookies, are used. The notice shown on the public pages is therefore informational; it does not ask for consent.

  • mc_session — the signed-in session identifier; at most 30 days.
  • mc_2fa — the identifier bridging the two steps of a two-step sign-in; 5 minutes.
  • mc_locale — the chosen language.

The browser's local storage holds settings that stay on the device and never reach the server: light/dark theme, which menu groups are collapsed, acknowledgement of the cookie notice, and the cart in a public web shop.

5. Recipients and processors

The Provider uses processors that access account data to the extent needed to provide the service: the hosting and infrastructure provider, the email delivery provider and — where the Customer configures one — the invoicing provider. The current list, their locations and where processing takes place are on the Subprocessors page.

On a lawful request from an authority the Provider discloses what the law requires and, unless prohibited, informs the affected Customer.

Data is stored within the European Union. Transfers to third countries take place only under an adequacy decision or standard contractual clauses (Article 46 GDPR); the Subprocessors page says where that applies.

6. Your rights

Under Articles 15–22 GDPR you may request access to your personal data, rectification, erasure, restriction of processing, object to processing, and exercise the right to data portability. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing.

Most account data can be managed directly on the profile page: name, phone number, language and time zone can be changed; the email address can be changed with confirmation; signed-in devices can be reviewed and signed out; the account can be deleted. An organisation's owner can request deletion of the whole organisation.

Other requests go to [kapcsolat@example.hu]. The Provider answers within one month of receipt; where justified that period may be extended by two months, of which you will be told.

7. Complaints

If you believe the processing of your personal data infringes the GDPR you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH; Falk Miksa utca 9–11, 1055 Budapest; postal address: 1363 Budapest, Pf. 9; phone: +36 1 391 1400; email: ugyfelszolgalat@naih.hu; website: naih.hu), or with the supervisory authority of your own member state, or bring proceedings before a court. In Hungary the claim may be brought before the regional court of your place of residence.

Please contact the Provider first: most questions are settled faster directly.

8. Security

Passwords are stored only as salted scrypt hashes. Session identifiers and single-use links are likewise stored only hashed. Credentials for external systems (mail, invoicing) are stored encrypted. The database is backed up daily and restore is tested regularly. The Security page describes the measures in detail.

In the event of a personal data breach the Provider follows Articles 33 and 34 GDPR: the supervisory authority is notified within 72 hours, and affected persons without undue delay where the breach is likely to put them at high risk.

9. Changes to this notice

The Provider updates this notice when the service or the law changes. Material changes are announced by email and within the service. The current version is always available on this page; the date at the top is when it last changed.