Parlo

Legal

Privacy Notice

Effective: October 4, 2026

We describe what personal data we process, what we use it for, how long we keep it, who we share it with, and what your rights are. This notice follows the GDPR and Hungarian data protection law.

1. Controller

  • Name: Szentiványi András Szilveszter e.v.
  • Registered office: 2800 Tatabánya, Előd vezér utca 18.
  • Registration number: 56933738
  • Tax number: 58441406-1-31
  • Privacy questions: andras@szentivanyi.dev

Hereinafter "we" or "the Provider".

2. Whose data does this notice cover?

  • Users: people who register for Parlo (freelancers, agencies and their staff). For their data we are the controller.
  • Visitors: people who open our website.
  • Clients: the Users' clients and their contacts who reach the portal through a link or the "Client login" page, with a one-time code sent to their email. Their data is uploaded and managed by the User; we act as processor on the User's behalf. If you are a client with a question about your data, please contact the business that sent you the link first. Details: data processing terms.

3. What data do we process, why, and for how long?

  • Registration and account
    • Data: name, email address, password (stored encrypted), business name, language, time of accepting the Terms
    • Legal basis: performance of contract – Art. 6(1)(b) GDPR
    • Retention: until the account is deleted, then up to 30 days in backups
  • Inviting team members
    • Data: the invitee's email address, the inviter's name
    • Legal basis: performance of contract – Art. 6(1)(b) GDPR
    • Retention: until the invitation is accepted, up to 7 days
  • Providing the service
    • Data: clients, projects, topics, messages, tasks, approvals and files created in the account
    • Legal basis: performance of contract – Art. 6(1)(b) GDPR
    • Retention: until the account is deleted, or until the User deletes them
  • System notifications
    • Data: name, email address, notification content
    • Legal basis: performance of contract – Art. 6(1)(b) GDPR
    • Retention: until the account is deleted
  • Subscription and invoicing
    • Data: billing name, address, tax number, payment details (card data is handled only by Stripe; we see at most the card type and last 4 digits)
    • Legal basis: legal obligation – Art. 6(1)(c) GDPR, section 169 of Hungarian Act C of 2000 on accounting
    • Retention: 8 years from the invoice date
  • Security and abuse prevention
    • Data: IP address, browser type, login times, failed login attempts
    • Legal basis: legitimate interest – Art. 6(1)(f) GDPR: protecting the service and the accounts
    • Retention: up to 90 days
  • Support
    • Data: name, email address, content of the correspondence
    • Legal basis: legitimate interest – Art. 6(1)(f) GDPR, or performance of contract
    • Retention: 2 years after the case is closed
  • Running the website
    • Data: in server logs: IP address, time, page opened, browser
    • Legal basis: legitimate interest – Art. 6(1)(f) GDPR: operational security
    • Retention: up to 30 days
  • Visitor statistics
    • Data: on the public pages: page opened, where you came from, browser and device type, country. Measured with self-hosted Plausible, without cookies. IP addresses are not stored, and visitors cannot be identified one by one.
    • Legal basis: legitimate interest – Art. 6(1)(f) GDPR: knowing which pages are useful
    • Retention: kept only as aggregated statistics

Where we rely on legitimate interest, we have weighed that it does not override your rights. We will send you the assessment on request.

4. Who has access to the data? (processors)

We do not sell data and do not share it for advertising. We use the following partners to run the service:

  • Hetzner Online GmbH
    • Task: hosting, servers, database, file storage
    • Location: European Union
  • Cloudflare, Inc.
    • Task: sending system emails
    • Location: United States (see section 5)
  • Stripe Payments Europe, Ltd. (Ireland)
    • Task: card payments, subscriptions
    • Location: European Union, some data in the United States
  • Cloudflare, Inc.
    • Task: delivering and protecting the website traffic (CDN, DNS, firewall), receiving emails sent to us and replies to notifications
    • Where: global network, United States (see section 5)
  • KBOSS.hu Kft. (Számlázz.hu)
    • Task: issuing and keeping the subscription invoices
    • Where: Hungary

We disclose data to authorities only when required by law, upon an official request.

5. Transfers outside the EU

If a partner processes data outside the European Economic Area, this happens only with appropriate safeguards: certification under the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses (SCC).

6. How do we protect the data?

  • The site is only available over an encrypted (HTTPS) connection.
  • Passwords and the keys of client links, login codes and invitations are stored only as one-way hashes.
  • Opening the client portal needs a one-time code, valid for 10 minutes, emailed to the client. A leaked link on its own opens nothing.
  • Uploaded files are not public; they are only available through short-lived signed links.
  • Every business sees only its own data.
  • We make regular backups and limit access to the people who need it.

7. Your rights

  • Access: you can ask what data we hold about you and request a copy.
  • Rectification: you can ask us to correct inaccurate data. You can also change your account data in the settings.
  • Erasure: you can ask us to delete your data. You can also delete your account in the settings. Data we must keep by law (e.g. invoices) is kept until the end of the retention period.
  • Restriction: you can ask us, in certain cases, to only store but not use your data.
  • Portability: you can request your data in a machine-readable format.
  • Objection: you can object to processing based on legitimate interest.

Send your request to andras@szentivanyi.dev. We reply within one month; where justified this may be extended by two months, and we will tell you.

8. Complaints and remedies

If you feel your rights have been infringed, please write to us first so we can resolve it. You can also lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa utca 9–11., Hungary Postal address: 1363 Budapest, Pf. 9. Web: naih.hu · Email: ugyfelszolgalat@naih.hu

You may also go to court, including the court of your place of residence.

9. Automated decision-making

We do not make decisions about you based solely on automated processing, and we do not profile you.

10. Cookies

We only use cookies that are needed for the site to work. Details: cookie policy.

11. Changes

If we change this notice materially, we will also notify Users by email. The current version is always available on this page.

We only use cookies needed for the site to work (login, security). No tracking, no ads. Details