1. Who is responsible for your data?
Széll Máté Csongor e.v. (H-4032 Debrecen, Kosztolányi Dezső utca 4., Hungary) is the controller. For privacy questions, a copy of applicable transfer safeguards, or to exercise your rights, email [email protected]. We have not designated a data protection officer; as an EU-established controller, we do not use an Article 27 representative.
2. What we collect and why
Waitlist
- Data
- Name, work email address, optional company name, property-count band, language, and consent details.
- Purpose
- To manage your waitlist registration, send related early-access updates, and document your consent.
- Legal basis
- Consent (GDPR Article 6(1)(a)).
Operator account and customer relationship
- Data
- Name, email address, organization membership, sign-in and security events, and support-request content.
- Purpose
- To provide access, operate and secure the service, and provide support.
- Legal basis
- Performance of a contract and our legitimate interests in protecting the service (GDPR Article 6(1)(b) and (f)).
Content uploaded to the service
- Data
- Property information, documents, images, manuals, notes, knowledge items, and any personal or security-sensitive information they contain.
- Purpose
- To create and maintain a property knowledge base and provide operator-approved guest information.
- Legal basis
- Performance of a contract (GDPR Article 6(1)(b)). The operator is responsible for lawfully sharing uploaded content with us.
Guest portal and questions
- Data
- A guest’s question, answer, feedback, and technical data associated with the guest link.
- Purpose
- To answer property-specific questions, maintain quality and security, and identify missing information.
- Legal basis
- Performance of a contract and legitimate interests (GDPR Article 6(1)(b) and (f)).
Website, security, and measurement
- Data
- Short-lived IP-address and request metadata, Turnstile verification, short-lived pseudonymous abuse-prevention identifiers, and anonymous waitlist events.
- Purpose
- To protect the website and form, prevent abuse, and understand whether the waitlist flow works.
- Legal basis
- Legitimate interests (GDPR Article 6(1)(f)).
3. Service providers and transfers
We share only the data a provider needs to perform its role. Our main current providers are:
Cloudflare
Public website delivery, DNS, TLS/CDN, DDoS and abuse protection, Turnstile, and transient waitlist-request processing. A waitlist request and network metadata, including IP address, may be processed transiently through Cloudflare’s global edge infrastructure; Cloudflare is not our persistent waitlist database.
Brevo
Storage of waitlist contact details in our selected EU-region account and delivery of waitlist and transactional email. The applicable Brevo DPA, subprocessor information, and transfer safeguards are available on request at [email protected].
PostHog Cloud EU
Limited cookieless waitlist-funnel measurement through the verified PostHog EU project and EU ingestion host. We send only four allowlisted funnel events and do not send form fields or identified people. A network connection can still provide PostHog with technical metadata; the project is configured to discard raw IP addresses processor-side.
DigitalOcean
EU-region hosting for the application, PostgreSQL database, document storage, and backups.
Google Gemini
Within the product, narrowly scoped text or image processing, embeddings, and answer generation. We send only the excerpts needed for the task and do not use provider-hosted conversation, file, or vector stores.
Some providers may process personal data outside the European Economic Area. We use the safeguards recorded for the relevant provider in our founder evidence log. To request a copy of applicable safeguards, contact [email protected].
4. How long we keep data
Waitlist and consent evidence
Until you unsubscribe or for 24 months from your latest valid waitlist signup. We do not treat email opens, clicks, or browsing as engagement that extends this period. After expiry or unsubscribe, only the minimum suppression evidence needed to prevent renewed outreach may remain.
Operator profile and membership
For the customer relationship; on its end, we normally delete personal profiles within 30 days unless law requires otherwise.
Sources and property knowledge
While the property is active; on deletion, we remove it from active use immediately and delete it within 30 days.
Guest questions, answers, and retrieval traces
90 days, then we delete or anonymize raw content and linkable identifiers.
Security and application logs
Normally 30 days; security and administration audit events for up to 12 months.
Anonymous analytics
Up to 12 months.
5. AI-assisted processing
Compasa may use AI to organize uploaded information and answer guest questions. We first retrieve approved, relevant knowledge on our own EU infrastructure, then send only the necessary text excerpts to the AI provider. We do not send email addresses, guest links, IP addresses, or booking identifiers, and we redact personal contact details where practical. Operators remain responsible for ensuring that uploaded content is lawful and appropriate to share.
7. Your rights
You may ask for access to, correction, deletion, restriction, or portability of your data, and object to processing based on legitimate interests. You may withdraw consent at any time; this does not affect processing before withdrawal. You can also unsubscribe from waitlist email using the link in the email. Send requests to [email protected]. You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH; naih.hu), or to the supervisory authority where you live, work, or believe an infringement occurred.
8. Security and changes
We use proportionate technical and organizational safeguards, including access controls, encrypted transmission, permission separation, and logging. No online system is entirely risk-free. If this notice materially changes, we will update its effective date on this page.