DRAFT. This document has not yet been reviewed by a lawyer. Placeholders in [BRACKETS] must be filled in before launch.
Privacy Policy
PRIVACY POLICY
Sendawick
Last updated: [DATE]
1. Controller
[FULL NAME], sole proprietor, [ADDRESS, HUNGARY], registration number [EV REGISTRATION NUMBER], e-mail: [PRIVACY EMAIL] (the "Controller", "we"). We have not appointed a Data Protection Officer; contact the e-mail above for all privacy matters.
2. Who this Policy is for
Part A applies to people who order a Page ("Customers"). Part B applies to people a Page is about or addressed to ("Recipients"), whose data we receive from the Customer, not from them (Art. 14 GDPR). Part C applies to everyone.
PART A: CUSTOMERS
3. What we process, why and on what legal basis
| Data | Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Your e-mail address, order ID, chosen product, link lifetime | Creating and delivering your Page, sending the link and the Recipient's reply, support | (b) performance of a contract |
| Names, occasion, free-text message, uploaded photos | Generating and displaying the Page | (b) performance of a contract |
| Country, payment status, refund status (received from the Merchant of Record; we never see full card details) | Order fulfilment, refunds, accounting | (b) contract; (c) legal obligation (accounting) |
| Technical data: IP address, browser, timestamps, security logs | Security, abuse prevention, debugging | (f) legitimate interest in running a secure service |
| Support correspondence, abuse reports | Handling your requests and complaints | (b) contract; (c) legal obligation (consumer law); (f) legitimate interest |
| Marketing e-mails (only if you opt in) | Sending occasional news and offers | (a) consent, withdrawable at any time |
We do not create profiles, do not make automated decisions with legal effect about you, and do not sell personal data.
4. Special categories of data
Please do not include health information, information about sexual life or orientation, religion, political opinions or similar sensitive information in your message unless it is strictly necessary for the greeting. A message such as a declaration of love may indirectly reveal such information about you or the Recipient. We do not analyse or extract such information, we use it only to render your Page, and we delete it according to Section 8. Where you provide sensitive information about yourself, you do so on the basis of your explicit consent (Art. 9(2)(a)), which you can withdraw by asking us to delete the Page.
PART B: RECIPIENTS
5. Notice for Recipients (Art. 14 GDPR)
Someone who knows you ("the Customer") ordered a personalised greeting page from us and gave us your first name and possibly other details about you, such as shared memories and photos. We received this data from the Customer, not from you. We process it only to create, host and display the Page the Customer ordered and, if you choose to reply, to send your reply to the Customer. Legal basis: our and the Customer's legitimate interest in delivering a personal greeting (Art. 6(1)(f)), balanced against your rights; the Customer confirmed to us that they were entitled to share your details. We keep the Page for the period the Customer chose (30 days or until removal) and then delete it. Categories of data: first name, possibly surname, relationship to the Customer, memories or events described by the Customer, photos, and your optional reply. We do not use your data for any other purpose, do not contact you, and do not share it except with our service providers listed in Section 7.
You have the right to object to this processing and to ask us to remove the Page at any time: use the "Report / remove this page" link at the bottom of the Page or e-mail [PRIVACY EMAIL]. We will normally remove a Page within [48] hours of a Recipient's request. You also have the rights described in Section 10.
PART C: EVERYONE
6. Your reply on the Page
If a Recipient sends a reply through the Page (for example "Yes"), we store the reply with the Page and e-mail it to the Customer. This is done to perform the Customer's contract and in the Recipient's interest in responding.
7. Processors and other recipients of data
We use the following service providers, which act on our documented instructions under data processing agreements (Art. 28 GDPR):
- Cloudflare, Inc. (USA) and its EU affiliates: hosting, database (Cloudflare D1), file storage for photos (Cloudflare R2), content delivery, DDoS protection and security logs. We configure our database and storage with the "EU" jurisdiction so that stored data is kept in the European Union; edge processing may occur at Cloudflare locations worldwide. DPA: https://www.cloudflare.com/cloudflare-customer-dpa/
- Anthropic Ireland, Limited / Anthropic, PBC (USA): generation of the personal text of the Page from the names and message you provide. We send only the minimum needed (first names, occasion, your message); we never send your e-mail address. Anthropic does not use this data to train its models and deletes inputs and outputs within 30 days unless flagged for abuse. DPA: https://www.anthropic.com/legal/data-processing-addendum
- [E-MAIL PROVIDER NAME] ([COUNTRY]): sending transactional e-mails (order confirmation, link, Recipient reply).
- [MoR LEGAL NAME] (USA/[COUNTRY]): our Merchant of Record. For payment, invoicing, tax and fraud prevention the MoR is an independent controller of your data under its own privacy policy ([MoR PRIVACY URL]); it shares your e-mail address, country and order details with us so that we can deliver the Page.
We may also disclose data if required by law or to establish, exercise or defend legal claims, and to authorities under Regulation (EU) 2022/2065 where applicable.
8. Retention
- Page content (names, message, generated text, photos, reply): until the Page expires ([30] days for Standard) plus [7] days for backups, or, for Lifetime Pages, until the Customer or Recipient requests removal, the Service is discontinued, or [24] months of inactivity followed by notice to the Customer. Deletion is automated.
- Order record (e-mail, order ID, product, timestamps, MoR reference): [8] years, as required by Hungarian accounting law (Act C of 2000, Section 169), in a minimised form after the Page is deleted.
- Security logs: [30] days.
- Support and abuse correspondence: [3] years after closure (limitation of claims), abuse reports that led to removal: [5] years in minimised form.
- Marketing consent and e-mail: until you unsubscribe, then a suppression record only.
- AI provider: inputs and outputs deleted within 30 days (see Section 7).
9. International transfers
Our providers are headquartered in the United States. Where personal data is transferred outside the EEA, we rely on: (i) the EU-U.S. Data Privacy Framework adequacy decision for providers certified under it (currently: [Cloudflare, Inc.; check others]); and/or (ii) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) incorporated in each provider's DPA, together with supplementary measures (encryption in transit and at rest, EU data-location settings, data minimisation). You may request a copy of the relevant clauses at [PRIVACY EMAIL].
10. Your rights
Under the GDPR you may: access your data; have it corrected; have it erased; restrict processing; receive the data you gave us in a portable format; object to processing based on legitimate interest (including as a Recipient); and withdraw consent at any time without affecting earlier processing. Write to [PRIVACY EMAIL]. Because there are no accounts, please quote the order e-mail address and order ID (Customers) or the Page link (Recipients) so that we can identify the relevant data. We respond within one month.
11. Complaints
You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), 1055 Budapest, Falk Miksa utca 9-11, Hungary; postal: 1363 Budapest, Pf. 9; e-mail: ugyfelszolgalat@naih.hu; https://www.naih.hu, or with the supervisory authority of the EU country where you live or work. You may also bring a claim before the courts.
12. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider; access is limited to the Controller; Page links use long random identifiers that cannot be guessed; photos are served only through the Page link. No system is perfectly secure; if a breach is likely to result in a high risk to you, we will inform you as required by Art. 34 GDPR.
13. Children
We do not knowingly accept orders from persons under 18. If you believe a child has provided us data, contact [PRIVACY EMAIL] and we will delete it.
14. Changes
We will post the new version here with a new date. Material changes affecting existing Pages will be notified by e-mail to Customers.