Privacy Notice
About this English version. This is the English-language version of the Hungarian Adatkezelési Tájékoztató and follows it in substance. Where a genuine discrepancy of meaning arises between the two versions, and you are a consumer, the interpretation more favourable to you applies.
1. Who processes your data?
- Controller
- Tibor Szántai, sole trader (egyéni vállalkozó)
- Registered and postal address
- Simon István utca 4/2, 4033 Debrecen, Hungary
- Tax number
- 90986756-1-29
- info@genmarketer.hu
- Website
- https://genmarketer.hu/
Referred to below as the “Controller” or “GENmarketer”.
The Controller has not appointed a data protection officer, as the mandatory conditions under Article 37 GDPR are not currently met. Data protection questions and requests can be sent to info@genmarketer.hu.
2. What does this notice cover?
This notice covers processing on the following surfaces and services:
- https://genmarketer.hu/
- https://tudastar.genmarketer.hu/
- https://ai-csapat.genmarketer.hu/
- https://genmarketer.eu/
- the GENmarketer Knowledge Base and Skill Hub;
- downloadable skills, prompts, knowledge bases, training courses and digital products;
- consulting, coaching and customer support;
- the GENmarketer Google Ads Connector;
- the GENmarketer Meta Ads Connector;
- connectors introduced later and named in this notice or an update to it.
Where GENmarketer processes a Business User’s client data on that user’s documented instructions, the B2B data processing annex to the Terms also governs the relationship between the parties. For its own contractual, invoicing, security and legal enforcement purposes, GENmarketer acts as an independent controller.
3. Our principles
We process personal data only for specified, explicit and lawful purposes. We limit processing to the data and time necessary, grant access only in justified roles, and apply security measures proportionate to the risk.
We never ask for passwords, card data, API keys or OAuth tokens by e-mail. Please do not send such data in a support or feedback message either.
4. Individual processing activities
4.1. Opening the website and server logs
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP address, date and time, requested URL, HTTP status, basic browser and device data, referring page, security events | serving the website, debugging, prevention of attack and abuse | legitimate interest: secure and functioning operation of the website, Art. 6(1)(f) GDPR | as a general rule max. 90 days; extracts relating to a security incident until the end of the legal claim or proceedings |
4.2. Registration and user account
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| name, e-mail address, username, password hash, role, time of registration and last login, purchased entitlements, course and access status | account creation, authentication, product access and support | performance of a contract, Art. 6(1)(b) GDPR | for the life of the account, then as a general rule 30 days; evidence of purchase until the limitation of contractual claims |
Passwords are stored as a one-way hash, not in readable form.
4.3. Orders and contract
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| name, e-mail, phone number if given, billing name and address, tax number, order identifier, product, price, discount, payment and fulfilment status, version and time of the Terms and digital-content statements | ordering, contract, performance, withdrawal, guarantee and claim handling | performance of a contract; for invoice data, legal obligation | contractual data as a general rule 5 years; accounting documents and supporting data 8 years |
Providing this data is necessary in order to conclude the contract. Without the mandatory data the order cannot be fulfilled.
4.4. Card payment
Card payments are provided by Stripe. GENmarketer does not receive the full card number or the security code.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| payer’s name and e-mail, billing data, amount, currency, transaction identifier, status, limited card characteristics, fraud-prevention signals | payment, refunds, fraud prevention, accounting reconciliation | performance of a contract, legal obligation, legitimate interest | at GENmarketer according to contractual/accounting periods; at Stripe according to its own retention |
For some operations Stripe acts as a processor; for other purposes — in particular financial, regulatory and fraud-prevention purposes — it may act as an independent controller.
4.5. Invoicing
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| billing name and address, tax number, e-mail, product, amount, invoice identifier and fulfilment data | issuing and delivering invoices, accounting and tax obligations | legal obligation, Art. 6(1)(c) GDPR | 8 years |
Invoicing may be carried out through the Számlázz.hu system, with the involvement of KBOSS.hu Kft. (Záhony utca 7/D, 1031 Budapest, Hungary).
4.6. Knowledge Base, LearnDash and training progress
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| account identifier, enrolment, entitlement, lessons viewed, progress, completion, downloads and technical events | digital access, showing progress, support and abuse prevention | performance of a contract; legitimate interest for security events | for the life of the access; after it ends as a general rule 30 days, minimum contractual evidence 5 years |
4.7. Coaching, consultation and bespoke services
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| name, contact details, business and marketing brief, appointment, meeting notes, documents handed over | scheduling and performing the service | performance of a contract | during the contract, then as a general rule 5 years |
Please do not share special category data unless it is strictly necessary and has been agreed in advance.
4.8. Contact, support and complaints
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| name, e-mail, message, attachments, order data, reply and handling metadata | answering questions, technical assistance, handling complaints | performance of a contract or pre-contractual step; legitimate interest; legal obligation for consumer complaints | general enquiries max. 5 years; consumer complaints and replies 3 years |
4.9. Newsletter and direct marketing
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| name, e-mail, source and time of subscription, version of consent, open and click data, unsubscribe | newsletters, offers and content communication | consent, Art. 6(1)(a) GDPR; for electronic advertising, the applicable Hungarian rules | until unsubscribe or withdrawal of consent; evidence of consent and objection max. 5 years |
An unsubscribe link is available in every marketing e-mail, or you can request it at info@genmarketer.hu. We may keep an unsubscribed address on a minimal suppression list so that the objection continues to be honoured in future.
4.10. Skill Hub usage telemetry
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| GENmarketer user identifier, channel, layer, connector, action, skill, redacted technical detail, timestamp, rate-limit events | performing the service, debugging, capacity, security, product quality | performance of a contract; legitimate interest | 90 days |
Telemetry does not include the full task description, search term or connector request. Technical details are protected by automatic redaction; logging passwords, tokens and other secrets is prohibited.
4.11. Session and account-sharing risk signals
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| IP signal pseudonymised with a keyed hash, minimal browser/device label, client identifier, first and last detection, request count and temporal correlation | detecting unauthorised account sharing, credential abuse and attacks | legitimate interest: account, licence and system security | 90 days |
We do not store the full user-agent string for this purpose, and we do not aim to recover a User’s real IP address from the pseudonymised signal. No single IP, device or browser signal leads to automatic permanent suspension. A signal is followed by human review, and the User may comment.
The Controller’s legitimate interest is protecting the paid, seat-bound service, other customers and the infrastructure. The impact on data subjects is reduced by pseudonymisation, data minimisation, 90-day deletion and human review. You may object; the Controller will then reassess whether compelling legitimate grounds exist.
4.12. Feedback, contributions and automatic run outcomes
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| user identifier, skill/connector, type of feedback or contribution, text provided by the User, redacted technical metadata; content-free run outcome category such as partial, blocked, error or quality gap | detecting faults and quality gaps, product development, handling feedback | legitimate interest; consent may also apply to voluntary free text | 365 days, then deletion or irreversible aggregation |
A run outcome does not contain the full prompt, business brief or connector request content. Feedback goes to an internal, access-restricted inbox; it is not forwarded automatically to a public issue tracker or by e-mail.
4.13. Security events and legal claims
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| account concerned, event time, IP or session signal, log extract, action taken, communications, evidence | remediating and investigating incidents, legal claims and cooperation with authorities | legitimate interest; legal obligation | until the incident or proceedings are closed, then until the limitation of the related claim |
5. GENmarketer Google Ads Connector
5.1. Connection and permissions requested
The Google connection is made through Google’s official OAuth interface. GENmarketer may request the following scope:
https://www.googleapis.com/auth/adwords
The purpose of the scope is to let the User select their own — or lawfully delegated — Google Ads accounts, produce audits, reports and improvement recommendations from them, and, where the feature is available and separately approved, carry out a controlled preview or preparation in a paused state.
5.2. Inventory of Google data
| Data | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Google user and technical identifier of the OAuth connection | Google OAuth | establishing the connection | performance of a contract | until the connection is severed |
| access token, refresh token, scope, expiry | maintaining authorised API access | performance of a contract | until the connection is severed, revoked, the account is deleted, or it becomes invalid | |
| available customer identifiers, account names and selected account | Google Ads API | account selection and separation | performance of a contract | until the connection is severed |
| campaign, ad, keyword, setting, cost and performance data | Google Ads API | the audit, report or preparation requested by the User | performance of a contract; documented instructions for B2B client data | for the duration of the operation; saved reports until deleted by the User or for the contractual period |
| connector events and redacted errors | GENmarketer | security and debugging | legitimate interest | 90 days |
Tokens are protected by application-level access restrictions and TLS encryption in transit. Access is limited to the authorised processes and administrators needed to operate the connector.
5.3. How we use and share Google data
We use Google user data solely to provide the clearly visible connector features requested by the User.
We do not:
- sell or rent it;
- use it for advertising to third parties;
- use it for profiling, credit assessment or surveillance across customers;
- use it to train, fine-tune or improve general-purpose AI or machine-learning models;
- transfer it to a party that would use it for its own incompatible purposes.
Access may only be given to:
- systems necessary for the feature initiated by the User;
- service providers ensuring secure operation and bound by contractual confidentiality;
- authorities acting on a legal basis;
- a recipient selected on the User’s express instruction.
Human access takes place only for support, a security incident, a legal obligation, or to resolve the User’s express request, and only to the smallest necessary extent.
Use of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
5.4. Disconnection and deletion
The User may disconnect in the Knowledge Base connector settings, revoke access among the third-party connections of their Google account, or request deletion as set out in the “Data deletion and severing connector connections” chapter of this notice. Revocation stops further access; to delete the copy stored at GENmarketer, use the GENmarketer disconnection or a deletion request.
6. GENmarketer Meta Ads Connector
6.1. Permissions requested and their purposes
ads_read- Reading campaign, ad set, ad, setting and performance data of the advertising account authorised by the User, for audit and reporting purposes.
business_management- Determining which business and advertising assets the logged-in User has lawful access to, and which account they may select.
pages_read_engagement- Reading basic and activity data of a connected Page where this is necessary to produce the advertising audit or performance assessment requested by the User.
6.2. Inventory of Meta data
| Data | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Meta user and technical identifier of the OAuth connection | Meta Login/OAuth | establishing the connection | performance of a contract | until the connection is severed |
| access token, scopes, expiry | Meta | authorised API access | performance of a contract | until severed, revoked, the account is deleted, or it expires |
| advertising account identifier, name, status, currency, time zone and country | Meta Marketing API | account discovery and selection | performance of a contract | until the connection is severed |
| campaign, ad and performance data | Meta Marketing API | audit, report and recommendations | performance of a contract; documented instructions for B2B client data | for the duration of the operation; saved reports until deleted by the User or per the contract |
| connector events and redacted errors | GENmarketer | security and debugging | legitimate interest | 90 days |
Tokens are protected by application-level access restrictions and TLS encryption in transit. Access is limited to the authorised processes and administrators needed to operate the connector.
6.3. Meta Platform Data restrictions
We use Meta data only to provide the feature requested by the User. Individual customers’ data is logically separated.
We do not:
- sell Platform Data;
- use one advertiser’s data for the benefit of another advertiser;
- combine data from several customers for profiling or retargeting;
- build audience lists from it without the User’s knowledge;
- use it to train or fine-tune general-purpose AI models;
- make it available to third parties for purposes other than providing the service.
Where the User acts on behalf of a client, they must hold that client’s authorisation and may use the data only for that client’s benefit.
6.4. Disconnection and deletion
The User may sever the connection and request deletion of related data in the Knowledge Base connector settings, in the business integration settings of their Meta account, or as set out in the “Data deletion and severing connector connections” chapter of this notice.
GENmarketer provides a public instruction URL for Meta data deletion requests. Where an automatic Meta Data Deletion Callback is in operation, the request receives a confirmation code and a status URL.
7. Web analytics, advertising measurement and social pages
7.1. Google Analytics and Google Ads measurement
Subject to consent, Google Analytics and Google Ads tools may measure site usage, campaign source and conversions. Data processed may include cookie and online identifiers, approximate location derived from IP, device and browser data, page and event data, campaign parameters, gclid/gbraid/wbraid and purchase events.
Legal basis: consent. Consent can be withdrawn at any time in the Cookie settings.
7.2. Meta Pixel and Meta Business Tools
Subject to consent, the Meta Pixel and related measurement technologies may transmit page view, checkout and purchase events, online identifiers, campaign parameters and technical data to Meta for measurement, attribution and — depending on the User’s Meta settings — advertising purposes.
In respect of the collection and transmission of this data to Meta, GENmarketer and Meta Platforms Ireland Limited may in certain cases be joint controllers; Meta may act as an independent controller for further processing of the transmitted data. The allocation of responsibilities is set out in the Meta Business Tools Terms and the Controller Addendum.
7.3. Microsoft Clarity
Subject to consent, Microsoft Clarity may produce heatmaps, session recordings and usage statistics from clicks, scrolling, page rendering and technical data. Form fields and elements containing personal data must be masked. Clarity may only load after consent.
7.4. OptiMonk
Subject to consent, OptiMonk may carry out campaign display, A/B testing, onsite messaging and conversion measurement based on online identifiers and site usage events.
7.5. Social pages
If you interact with us on GENmarketer’s Facebook, Instagram, YouTube, LinkedIn or other social page, that platform processes your data under its own terms. For page statistics a joint controllership situation may arise. We handle your private messages until the enquiry is resolved, and in the case of a legal claim until its limitation.
Details of cookies and tracking technologies are set out in the Cookie Notice.
8. Recipients and service providers
| Provider | Role and purpose | Place of processing / safeguard |
|---|---|---|
| Hostinger International Ltd. or the contracting Hostinger legal entity | hosting, database, servers, backups | EU and locations per the provider’s terms |
| Stripe Payments Europe, Limited, Stripe Technology Company, Limited and relevant Stripe entities | payment, fraud prevention, financial compliance | EEA and global infrastructure; DPA, SCCs or other lawful safeguard |
| KBOSS.hu Kft., Záhony utca 7/D, 1031 Budapest / Számlázz.hu | e-invoicing and delivery | Hungary/EEA |
| MailerLite Limited, 88 Harcourt Street, Dublin 2, Ireland | newsletter, subscriptions, automated e-mail | EEA; processor agreement |
| Google Ireland Limited, Google LLC and relevant Google entities | Analytics, Ads measurement, OAuth, Google Ads API, video and other Google services | EEA and third countries; controller/processor terms depending on service, DPF and/or SCCs |
| Meta Platforms Ireland Limited and relevant Meta entities | Pixel, page statistics, OAuth and Marketing API | EEA and global infrastructure; joint/independent controller or processor terms, DPF and/or SCCs |
| Microsoft Ireland Operations Limited and Microsoft Corporation | Clarity web analytics and session measurement | EU contracting party, US data centres possible; SCCs |
| OptiMonk International Zrt., Kassai út 129, 4028 Debrecen | onsite campaigns, A/B testing and measurement | Hungary/EEA and subcontracted infrastructure |
| the AI or client platform chosen by the User, e.g. Claude or ChatGPT | displaying prompts and connector results initiated by the User | per the platform’s own terms |
Some WordPress, WooCommerce and LearnDash components run on our own hosting. If a licence, telemetry, cloud or support function transmits personal data to the vendor, the provider table must be extended before that function goes live.
An accountant, lawyer, IT contributor or authority may only receive data necessary for their task and legal basis.
9. International transfers
Some providers may process data outside the EEA, in particular in the United States. In such cases the transfer may be based on:
- an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the recipient is certified;
- standard contractual clauses adopted by the European Commission;
- a derogation under Article 49 GDPR, strictly on its own conditions.
Where necessary we apply supplementary technical and organisational measures. Further information about the applicable safeguard can be requested at info@genmarketer.hu.
10. Data security
Proportionate to the risk, we apply in particular:
- TLS encryption in transit;
- role- and user-based access;
- hashing of passwords;
- restricted access to connector credentials and separation of secrets from source code;
- logical separation of customer and tenant data;
- minimal and redacted logging;
- pseudonymisation of session and abuse signals;
- backup, restore and updates;
- incident and vulnerability management;
- periodic review of access rights.
We document any personal data breach. Where the breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high we also inform the data subject, unless a statutory exception applies.
11. Automated decision-making
We do not take decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.
The system may produce an account-sharing, rate-limit or security risk signal. This is not a final decision: human review can be requested at info@genmarketer.hu before or after any substantive restriction — and immediately in the case of an urgent security measure.
12. Your rights
You have the right to:
- request information and access;
- request rectification of inaccurate data;
- request erasure where there is no further legal basis;
- request restriction of processing;
- withdraw your consent at any time;
- object to processing based on legitimate interest;
- request data portability for automated processing based on contract or consent;
- contest a significant decision based solely on automated processing;
- lodge a complaint and go to court.
Withdrawal of consent does not affect the lawfulness of processing carried out beforehand.
You can send your request to info@genmarketer.hu. To protect your identity and account we may ask for reasonable identification, but we never ask for a password or token.
We respond without undue delay, as a general rule within one month. For complex or multiple requests the period may be extended by a further two months; we inform you of this within the first month.
13. Data deletion and severing connector connections
13.1. What deletion can be requested?
You may request in particular:
- deletion of your GENmarketer user account and profile;
- deletion of the Google Ads Connector connection, tokens, connected account list and stored connector data;
- deletion of the Meta Ads Connector connection, tokens, connected account list and stored connector data;
- deletion of all connector data;
- deletion of newsletter, feedback or support data where there is no further legal basis;
- rectification or deletion of a specific item of data identified by you.
13.2. Self-service disconnection
Where the feature is available, choose “Disconnect” in the Knowledge Base connector settings. GENmarketer then deletes the active authentication data for that connector and the account list stored to operate the connection.
You can also revoke access on the platform side:
- in your Google account, under third-party apps and access settings;
- in your Meta/Facebook account, under Business Integrations settings.
Platform-side revocation prevents further API access but does not necessarily delete reports or log entries previously stored lawfully at GENmarketer. To delete those, use self-service disconnection or an e-mail request.
13.3. Deletion request by e-mail
Send your request to info@genmarketer.hu with the subject “Data deletion request”.
For quick identification, please give:
- the e-mail address associated with the GENmarketer account;
- whether you are requesting Google, Meta, full account or other deletion;
- if known, the name of the order or connector.
Do not send passwords, access tokens, API keys, card data or other secret authentication data.
If the request does not come from the e-mail address associated with the account, we may ask for proportionate identity verification to protect the account and other data subjects.
13.4. Deadline and confirmation
We answer the request without undue delay, as a general rule within one month. For complex or multiple requests the period may be extended by a further two months; we inform you of this and of the reason within the first month.
For a valid and identified request we delete or invalidate the operational connector credentials without undue delay. We confirm:
- receipt of the request;
- the identification step, where needed;
- completion of the deletion or any lawful restriction on it;
- when a Meta callback is used, the confirmation code and status URL.
13.5. What is not deleted immediately?
Immediate full deletion cannot be applied where retention is necessary for:
- invoicing, accounting or another legal obligation;
- an ongoing fraud, chargeback or security investigation;
- the establishment, exercise or defence of legal claims;
- protecting the rights of another person;
- anonymised or irreversibly aggregated data that is no longer personal data.
In such cases we restrict the data to those further purposes and record the reason and duration of retention. Invoice data retained by law may not be used for marketing or connector operation after a deletion request.
13.6. Consequences of account deletion
Account deletion may terminate Knowledge Base, Skill Hub, update and support access. The licence for a lawfully downloaded copy, withdrawal, refunds and mandatory consumer rights are governed by the Terms and Conditions.
13.7. URL to be used in the Meta App Dashboard
The public URL of the Meta data deletion instructions is:
https://genmarketer.hu/adatkezelesi-tajekoztato/#adattorles
That page is available over HTTPS without login or geographic restriction, and remains the canonical address registered with Meta. This English chapter is a translation of it and is provided for convenience. If an automatic Meta Data Deletion Callback is built later, its dynamic status page is not a separate legal policy but a technical confirmation of that process.
14. Complaints and remedies
Please write to info@genmarketer.hu first, so that we can investigate the matter directly.
A complaint may be made to the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for
Data Protection and Freedom of Information)
Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
E-mail: ugyfelszolgalat@naih.hu
Phone: +36 1 391 1400
Website: https://www.naih.hu/
If you are resident in another EEA country, you may also lodge a complaint with the supervisory authority of your own country of residence or place of work.
You may also go to court; where the statutory conditions are met you may bring proceedings before the court of your place of residence or stay.
15. Children
GENmarketer services are not designed for children. A person under eighteen may use a paid service only with the involvement of their legal representative. If we become aware that we are processing children’s data without a legal basis, we delete it.
Microsoft Clarity may not be used on a surface specifically directed at persons under eighteen.
16. Changes to this notice
We update this notice when there is new processing, or a change of provider, scope, law or technology. We give information about material changes affecting registered users through an appropriate channel, in advance where necessary.
The version and effective date are shown at the top of the page. Earlier versions can be requested at info@genmarketer.hu.