Privacy Notice
Information about how Velixa processes personal data, the purposes and legal bases of processing, data recipients, retention periods and the rights of data subjects.
1. Identity and contact details of the Controller
The controller responsible for the processing activities described in this Privacy Notice is:
| Full legal name | Istráb Attila, sole proprietor |
|---|---|
| Trading name | Velixa |
| Registered office | Kossuth Lajos utca 73., 2735 Dánszentmiklós, Hungary |
| Registration number | 58856350 |
| Tax number | 48965770-1-33 |
| EU VAT number | HU48965770 |
| Privacy contact | privacy@velixa.eu |
| Customer support | support@velixa.eu |
| Website | https://velixa.eu |
| Telephone | +36308204430 |
The controller is hereinafter referred to as the Controller, Service Provider or Velixa.
2. Purpose and scope of this Privacy Notice
This Privacy Notice explains how Velixa collects, uses, stores, transfers and protects personal data in connection with:
- the public Velixa website;
- contact and sales enquiries;
- registration and trial accounts;
- subscriptions and contractual relationships;
- customer and user accounts;
- customer support;
- billing and payments;
- security and audit logging;
- legal document acceptances;
- cookie choices;
- marketing communications;
- analytics and advertising technologies;
- artificial intelligence features;
- the Velixa web and mobile applications.
This Notice applies where Velixa determines the purposes and essential means of processing and therefore acts as a controller.
Where Velixa processes personal data entered into the Velixa SaaS environment by a Customer on the Customer's documented instructions, the Customer generally acts as controller and Velixa acts as processor. Such processing is governed by the separate Data Processing Agreement.
3. Definitions
For the purposes of this Privacy Notice:
- Personal Data means any information relating to an identified or identifiable natural person.
- Data Subject means the natural person to whom the Personal Data relates.
- Processing means any operation performed on Personal Data, including collection, recording, organisation, storage, alteration, retrieval, consultation, use, disclosure, restriction, erasure or destruction.
- Customer means a business, sole proprietor, institution or other organisation using or intending to use the Velixa Service.
- User means a natural person authorised by a Customer to use the Velixa Service.
- Customer Data means data entered, uploaded, generated or made available by the Customer or its Users within the Velixa Service.
- Processor means a person or organisation processing Personal Data on behalf of a controller.
- Sub-processor means a further processor engaged by a processor.
- GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council.
4. Data protection principles
Velixa processes Personal Data in accordance with the applicable data protection principles. Personal Data shall be:
- processed lawfully, fairly and transparently;
- collected for specified, explicit and legitimate purposes;
- adequate, relevant and limited to what is necessary;
- accurate and kept up to date where necessary;
- retained for no longer than necessary;
- protected by appropriate technical and organisational measures;
- processed in a manner that supports accountability and traceability.
5. Sources of Personal Data
Velixa may obtain Personal Data from the following sources:
- directly from the Data Subject;
- from the Customer represented by the Data Subject;
- from a Customer administrator or authorised User;
- from registration, contact and support forms;
- from subscription, billing and payment processes;
- from the use of the website and the Service;
- from security, login and audit logs;
- from integrations activated by the Customer;
- from publicly available business registers and sources;
- from service providers involved in payments, billing, security, communications or technical operation.
Where a Customer provides Personal Data relating to its employees, representatives, customers, contacts or partners, the Customer is responsible for ensuring that the disclosure and processing of such data is lawful.
6. Categories of Personal Data
6.1. Identification and business data
- name;
- company or organisation name;
- position and organisational role;
- customer or account identifier;
- representation or authorisation details;
- sole proprietor or company registration information.
6.2. Contact details
- business e-mail address;
- telephone number;
- postal or billing address;
- preferred language;
- communication preferences.
6.3. Account and authentication data
- user identifier;
- e-mail address used for login;
- password hash;
- account status;
- roles and permissions;
- two-factor authentication status;
- trusted device and session information;
- password reset and e-mail confirmation events.
6.4. Subscription and contractual data
- selected subscription plan;
- activated modules and add-ons;
- number of Users;
- subscription and trial dates;
- contract status;
- legal document versions accepted;
- cancellation and termination information;
- customer support and contractual correspondence.
6.5. Billing and payment data
- billing name and address;
- tax number and EU VAT number;
- invoice data;
- transaction identifier;
- payment method;
- payment status;
- amount, currency and payment date;
- information concerning failed or overdue payments.
Velixa does not normally receive or store complete bank card details. Card data is entered and processed within the payment service provider's secure environment.
6.6. Technical, security and usage data
- IP address;
- date and time of access;
- browser and operating system information;
- device and session identifiers;
- successful and unsuccessful login attempts;
- security events and alerts;
- audit log entries;
- API and integration events;
- pages, modules and functions used;
- error messages and diagnostic information.
6.7. Communication and support data
- the content of enquiries and support requests;
- messages exchanged with Velixa;
- attachments voluntarily provided;
- support case status and resolution;
- technical information required for troubleshooting.
6.8. Cookie and consent data
- cookie consent identifier;
- random visitor identifier;
- selected cookie categories;
- language code;
- policy and consent-text version;
- date and time of the choice;
- withdrawal or modification of a previous choice.
6.9. AI-related data
Where a User activates or uses an AI feature, Velixa may process:
- the User's prompt or instruction;
- the business context selected for the operation;
- the AI-generated response or recommendation;
- technical usage and token information;
- the status of the AI operation;
- User approval, rejection or feedback;
- related audit and security information.
Users should not enter passwords, authentication secrets, complete payment-card data or unnecessary sensitive Personal Data into AI prompts.
7. Purposes and legal bases of processing
| Purpose | Personal Data concerned | Legal basis |
|---|---|---|
| Operating and displaying the public website | IP address, technical request data, browser information and security logs | Legitimate interests in operating a secure, functional and reliable business website |
| Responding to contact and sales enquiries | Name, company, contact details and message content | Taking steps at the request of the Data Subject prior to entering into a contract, or legitimate interests in business communication |
| Registration and creation of a trial account | Identification, company, contact and account data | Taking steps prior to entering into a contract and performance of the requested trial service |
| Creating and administering subscriptions | Customer, User, subscription and contractual data | Performance of a contract |
| User authentication and access management | Login identifiers, password hash, roles, permissions, sessions and 2FA data | Performance of a contract and legitimate interests in preventing unauthorised access |
| Billing, accounting and taxation | Billing, invoice, tax and transaction data | Performance of a contract and compliance with legal obligations |
| Processing online payments | Transaction identifier, amount, currency, payment status and billing information | Performance of a contract |
| Providing customer support | Contact data, support messages, attachments, technical and account information | Performance of a contract and legitimate interests in resolving technical and customer-service issues |
| Security monitoring, fraud prevention and incident investigation | IP address, account, device, session, login, audit and security-event data | Legitimate interests in protecting the Service, Customers, Users and Personal Data, and compliance with applicable legal obligations |
| Recording acceptance of legal documents | User, Customer, document version, content hash, timestamp and technical acceptance data | Performance of a contract, compliance with legal obligations and legitimate interests in proving contractual acceptance |
| Recording and respecting cookie choices | Consent identifier, selected categories, policy version, language and timestamp | Compliance with legal obligations and legitimate interests in demonstrating and respecting the visitor's choice |
| Loading optional analytics or marketing technologies | Online identifiers, device, usage, campaign and conversion data | The Data Subject's prior consent |
| Sending newsletters or promotional communications | Name, e-mail address, company and communication preferences | Consent, or another legal basis permitted by the applicable electronic-marketing rules |
| Providing AI-powered functionality | Prompt, selected business context, generated output, approval and technical usage data | Performance of a contract and legitimate interests in ensuring secure, auditable operation |
| Establishing, exercising or defending legal claims | Contractual, communication, payment, security and evidentiary data | Legitimate interests in enforcing and defending legal rights |
8. Contractual requirement to provide Personal Data
Certain Personal Data is required for registration, subscription, billing, authentication or the performance of the contract.
Where required information is not provided, Velixa may be unable to:
- create or activate an account;
- enter into or perform the contract;
- issue a legally compliant invoice;
- process a payment;
- provide access to the Service;
- verify a representative's authority;
- respond effectively to a support request.
Personal Data requested solely for optional marketing, analytics or personalisation purposes is not required for the basic use of the Service.
9. Velixa as processor of Customer Data
Customers may use the Velixa Service to process Personal Data relating to their own employees, customers, prospects, contacts, suppliers and business partners.
In relation to such Customer Data:
- the Customer generally acts as Controller;
- Velixa generally acts as Processor;
- Velixa processes the data on the Customer's documented instructions;
- the Customer determines the purposes and legal bases of processing;
- the Customer is responsible for informing the affected Data Subjects;
- the detailed terms are governed by the Velixa Data Processing Agreement.
A Data Subject wishing to exercise rights relating to Customer Data should normally contact the relevant Customer first. Velixa assists the Customer in fulfilling such requests in accordance with the Data Processing Agreement.
10. Recipients and service providers
Personal Data may be disclosed only where necessary for the relevant purpose, the operation of the Service, compliance with a legal obligation or the protection of legitimate rights.
| Recipient or provider | Purpose | Data concerned | Role |
|---|---|---|---|
| Rackforest Informatikai Kereskedelmi, Szolgáltató és Tanácsadó Zrt. | Server, VPS, database, storage, backup, hosting and e-mail infrastructure | Data hosted or transmitted through the Velixa infrastructure, system logs, databases, documents, backups and messages | Processor or sub-processor, depending on the processing activity |
| KBOSS.hu Kft. – Számlázz.hu | Electronic invoicing and delivery of invoices | Customer identification, billing, tax, invoice and contact data | Processor or independent controller depending on the relevant statutory and contractual activity |
| SimplePay Zrt. | Online payment processing | Transaction, payment, amount, currency, billing and technical payment information | Independent controller or payment-service recipient in accordance with its own terms |
| OpenAI Ireland Limited | Provision of AI functionality through the OpenAI API | Prompts, selected business context, generated responses and technical metadata required for the relevant AI operation | Processor or sub-processor in relation to Customer Data processed through AI features |
| Google Ireland Limited | Website analytics, advertising, conversion measurement or related services where activated | Online identifiers, device, usage, campaign and conversion information | Processor, joint controller or independent controller depending on the activated service |
| Meta Platforms Ireland Limited | Advertising, campaign measurement and audience services where activated | Online identifiers, device, event, campaign and conversion information | Joint controller, processor or independent controller depending on the activated service |
| Microsoft Ireland Operations Limited | Website analytics, Microsoft Clarity, advertising and conversion measurement where activated | Online identifiers, device, website usage, interaction and conversion information | Processor or independent controller depending on the activated service |
| LinkedIn Ireland Unlimited Company | B2B advertising, campaign measurement and audience analysis where activated | Online identifiers, device, campaign and conversion information | Joint controller, processor or independent controller depending on the activated service |
| Professional advisers, auditors, accountants and legal representatives | Compliance, accounting, auditing and the establishment or defence of legal claims | Data necessary for the relevant professional service | Independent controller or processor depending on the engagement |
| Courts, authorities and other legally authorised bodies | Compliance with a legal obligation, binding decision or lawful request | Data specified in the applicable request or required by law | Authorised recipient |
Analytics and marketing providers listed above are used only where the relevant service has actually been activated. Technologies requiring consent shall not be loaded before the visitor has made the required choice.
11. International transfers
Velixa aims to process Personal Data within the European Economic Area wherever reasonably possible.
Certain service providers or their sub-processors may process Personal Data outside the European Economic Area.
In such cases, the transfer shall take place only where an appropriate legal transfer mechanism is available, including:
- an adequacy decision of the European Commission;
- the European Commission's Standard Contractual Clauses;
- binding corporate rules;
- another transfer mechanism or safeguard recognised by applicable data protection law.
Where required, Velixa or the relevant provider may assess the circumstances of the transfer and implement supplementary contractual, technical or organisational safeguards.
Such measures may include:
- data minimisation;
- encryption in transit;
- access restrictions;
- pseudonymisation;
- logging and monitoring;
- limited retention periods.
12. Retention periods
Velixa retains Personal Data only for the period necessary for the relevant purpose, contractual relationship, legal obligation, security requirement or legal claim.
| Data or processing activity | General retention rule |
|---|---|
| Contact and sales enquiries | Until the enquiry is resolved and thereafter for the period reasonably necessary for follow-up, unless a contract is concluded or a legal claim requires longer retention |
| Registration and trial-account data | For the duration of the trial and the period required for account closure, security, fraud prevention and possible subscription activation |
| Subscription and contractual data | For the duration of the contractual relationship and thereafter for the applicable limitation and claims-management period |
| Invoices and accounting documents | For the retention period required by applicable accounting and tax legislation |
| Payment transaction information | For the period necessary for payment processing, reconciliation, accounting, fraud prevention and legal claims |
| User-account and authentication data | For the lifetime of the account and thereafter for the period required for secure deactivation, incident investigation and legal claims |
| Security, login and audit logs | For the period defined in the applicable security and log-retention policy, extended where necessary for an incident, investigation or claim |
| Support cases | Until the case is resolved and thereafter for the period reasonably necessary for service history, quality assurance and legal claims |
| Legal-document acceptance records | For the duration of the contractual relationship and the period required to prove the acceptance and applicable contract terms |
| Cookie-consent records | Until the choice is replaced or withdrawn and thereafter for the period necessary to demonstrate compliance |
| Marketing data | Until consent is withdrawn, an objection is made or the relevant marketing purpose ends |
| AI prompts and generated outputs stored as Customer Data | According to the Customer's use, deletion actions, configured retention and the Customer Data lifecycle of the Service |
| Technical AI usage and audit data | For the period necessary for billing, security, abuse prevention, troubleshooting and auditability |
| Customer Data after termination | Generally available for export for 30 days after termination, followed by deletion from live systems |
| Customer Data in backups | May remain in isolated backups for up to a further 90 days after deletion from live systems, according to backup cycles |
Data may be retained for a longer period where required by law, a binding authority or court decision, an ongoing investigation, an unresolved security incident or the establishment, exercise or defence of legal claims.
13. Security of Personal Data
Velixa applies technical and organisational measures appropriate to the nature, scope, context and purposes of processing and the related risks.
Such measures may include:
- HTTPS/TLS-encrypted data transmission;
- role- and permission-based access control;
- two-factor authentication;
- individual User accounts;
- tenant and database separation;
- login, security and audit logging;
- session and device management;
- restricted administrative access;
- regular backups;
- security updates and vulnerability management;
- incident detection and response procedures;
- controlled development and deployment processes;
- confidentiality obligations for authorised personnel.
No information system can guarantee absolute security. Velixa therefore continuously reviews and develops its safeguards according to the risks, technology and operation of the Service.
14. Artificial intelligence features
14.1. Operation of AI features
Velixa may provide AI-assisted analysis, summaries, recommendations, forecasts, drafting tools and proposed business actions.
AI features may process only the information required for the operation selected or initiated by the User.
14.2. Human review
AI-generated results are informational and advisory in nature. They may be inaccurate, incomplete or unsuitable for a particular business situation.
Users must review AI-generated results before relying on them for business, financial, legal, accounting, employment, safety-related or other significant decisions.
14.3. Changes to Customer Data
Where an AI feature proposes creating, modifying, transmitting or deleting Customer Data, Velixa may require explicit User approval before the proposed operation is executed.
14.4. External AI provider
Velixa may use the OpenAI API provided in the EEA data protection context by OpenAI Ireland Limited.
Only the information necessary for the selected AI operation should be transmitted to the AI provider. The processing is also subject to the applicable contractual and data-processing safeguards.
14.5. No solely automated significant decisions
Velixa does not intend to make decisions producing legal effects or similarly significant effects on individuals solely through automated AI processing without meaningful human involvement.
15. Cookies and similar technologies
The Velixa website uses cookies and may use similar technologies for:
- secure website operation;
- protection against forged requests;
- remembering cookie choices;
- optional functionality;
- analytics;
- advertising and conversion measurement.
Necessary cookies may be used without optional consent where they are required for the operation or security of the website.
Optional functional, analytics and marketing technologies are activated only on the basis of the visitor's prior choice where consent is required.
Detailed information is available in the Cookie Notice .
16. Direct marketing
Velixa may send newsletters, product updates, invitations, promotional messages or similar marketing communications where a valid legal basis exists.
A recipient may unsubscribe or object to further direct marketing at any time by:
- using the unsubscribe function in the message;
- contacting privacy@velixa.eu ;
- changing the available communication settings.
Unsubscribing from marketing does not prevent Velixa from sending essential contractual, security, billing or service messages.
17. Rights of Data Subjects
Subject to the conditions and limitations of applicable law, a Data Subject may have the following rights:
17.1. Right of access
The Data Subject may request confirmation as to whether Personal Data concerning them is being processed and may request access to such data and related information.
17.2. Right to rectification
The Data Subject may request the correction of inaccurate Personal Data and the completion of incomplete data.
17.3. Right to erasure
The Data Subject may request the erasure of Personal Data where the applicable legal conditions are met.
The right to erasure does not apply where processing remains necessary, for example, for compliance with a legal obligation or the establishment, exercise or defence of legal claims.
17.4. Right to restriction of processing
The Data Subject may request restriction of processing where the accuracy, lawfulness, necessity or an objection to the processing is under consideration.
17.5. Right to data portability
Where processing is based on consent or contract and is carried out by automated means, the Data Subject may be entitled to receive the Personal Data they provided in a structured, commonly used and machine-readable format.
17.6. Right to object
The Data Subject may object, on grounds relating to their particular situation, to processing based on legitimate interests.
The Data Subject may object to processing for direct-marketing purposes at any time.
17.7. Right to withdraw consent
Where processing is based on consent, the Data Subject may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
17.8. Rights relating to automated decision-making
Where applicable, the Data Subject may request human intervention, express their point of view and contest a decision based solely on automated processing that produces legal or similarly significant effects.
17.9. Right to lodge a complaint
The Data Subject may lodge a complaint with the competent data protection supervisory authority.
18. Exercising Data Subject rights
Requests may be submitted to:
The request should contain sufficient information to identify:
- the person submitting the request;
- the relevant account, Customer or processing activity;
- the right the person wishes to exercise;
- the Personal Data concerned.
Velixa may request additional information where reasonably necessary to verify identity and prevent unauthorised access to Personal Data.
Velixa responds without undue delay and within the period required by applicable data protection law.
Where the request relates to Customer Data processed by Velixa on behalf of a Customer, Velixa may forward the request to the relevant Customer or direct the Data Subject to that Customer.
19. Supervisory authority
A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information.
| Authority | Hungarian National Authority for Data Protection and Freedom of Information |
|---|---|
| Hungarian name | Nemzeti Adatvédelmi és Információszabadság Hatóság |
| Short name | NAIH |
| Address | 1055 Budapest, Falk Miksa utca 9–11., Hungary |
| Postal address | 1363 Budapest, P.O. Box 9., Hungary |
| Telephone | +36 1 391 1400 |
| ugyfelszolgalat@naih.hu | |
| Website | https://www.naih.hu |
The Data Subject may also bring proceedings before a competent court in accordance with applicable law.
20. Processing relating to children
Velixa is a business software service intended for companies, sole proprietors, institutions and their authorised professional Users.
The Service is not directed at children, and Velixa does not knowingly offer subscriptions to children.
Where a Customer uses the Service to process Personal Data relating to children, the Customer is responsible for ensuring the lawfulness, necessity and appropriate safeguards of that processing.
21. Changes to this Privacy Notice
Velixa may amend this Privacy Notice, particularly where:
- the Service or its modules change;
- new processing activities are introduced;
- service providers or recipients change;
- retention or security practices change;
- applicable law or regulatory guidance changes;
- the Notice requires clarification or correction.
The current version number and effective date are displayed with the document.
Where a change materially affects Data Subjects, Velixa may provide additional notice through the website, the Service, e-mail or another appropriate communication channel.
22. Contact
Questions, requests and privacy-related complaints may be submitted to:
Technical and account-related support requests may be submitted to:
