Privacy Policy

Last updated: June 2026

This is a starting template. Have it reviewed by legal counsel and replace every [bracketed] detail with your company information before relying on it.

1. Controller

The data controller is [Company legal name], [registered address], reachable at [contact email]. This policy explains what we collect and your rights under the GDPR.

2. What we collect

We process the following data:

  • Account: email, name (optional), password (hashed), and how you heard about us.
  • Security: two-factor settings, sign-in activity (IP, user agent, timestamps).
  • Billing: subscription status and plan; card payments are handled by Stripe — we do not store your card number.
  • Exchange keys: API keys you connect, encrypted at rest; used only to read your account and place orders you request.

3. Why we process it (legal bases)

  • To provide the service and your account — performance of a contract.
  • To process payments and issue invoices — contract and legal obligation.
  • To secure accounts and prevent abuse — legitimate interest.
  • For optional marketing emails — your consent, withdrawable at any time.

4. Sharing and processors

We share data only with processors that help us run the service, including [Stripe] (payments), [Billingo] (invoicing), our email provider, and our hosting provider. They process data on our instructions under appropriate agreements. We do not sell your data.

5. Retention

We keep account data while your account is active and as required for legal/accounting purposes (e.g. invoices). When you delete your account, we erase your profile, exchange keys, billing link, and activity, except records we must retain by law.

6. Your rights

You have the right to access, rectify, export, and delete your data, to restrict or object to processing, and to withdraw consent. You can export or delete your data yourself from Account → Settings → Privacy & data, or contact [contact email]. You may also lodge a complaint with your local data protection authority (in Hungary, the NAIH).

7. Security

We protect data with encryption at rest for sensitive fields (including exchange keys), hashed passwords, optional two-factor authentication, and access controls. No system is perfectly secure, but we take reasonable measures to safeguard your information.

8. Cookies

We use essential cookies to keep you signed in and to operate the site. We do not use them for advertising. Where required, we ask for your consent before non-essential cookies.

9. Changes

We may update this policy; material changes will be communicated where appropriate. Questions about your data: [contact email].