GENmarketer

Privacy Notice

Version 2.0 (English) · Effective from 13 July 2026
Related documents: Terms and Conditions · Cookie Notice

About this English version. This is the English-language version of the Hungarian Adatkezelési Tájékoztató and follows it in substance. Where a genuine discrepancy of meaning arises between the two versions, and you are a consumer, the interpretation more favourable to you applies.

1. Who processes your data?

Controller
Tibor Szántai, sole trader (egyéni vállalkozó)
Registered and postal address
Simon István utca 4/2, 4033 Debrecen, Hungary
Tax number
90986756-1-29
E-mail
info@genmarketer.hu
Website
https://genmarketer.hu/

Referred to below as the “Controller” or “GENmarketer”.

The Controller has not appointed a data protection officer, as the mandatory conditions under Article 37 GDPR are not currently met. Data protection questions and requests can be sent to info@genmarketer.hu.

2. What does this notice cover?

This notice covers processing on the following surfaces and services:

Where GENmarketer processes a Business User’s client data on that user’s documented instructions, the B2B data processing annex to the Terms also governs the relationship between the parties. For its own contractual, invoicing, security and legal enforcement purposes, GENmarketer acts as an independent controller.

3. Our principles

We process personal data only for specified, explicit and lawful purposes. We limit processing to the data and time necessary, grant access only in justified roles, and apply security measures proportionate to the risk.

We never ask for passwords, card data, API keys or OAuth tokens by e-mail. Please do not send such data in a support or feedback message either.

4. Individual processing activities

4.1. Opening the website and server logs

DataPurposeLegal basisRetention
IP address, date and time, requested URL, HTTP status, basic browser and device data, referring page, security events serving the website, debugging, prevention of attack and abuse legitimate interest: secure and functioning operation of the website, Art. 6(1)(f) GDPR as a general rule max. 90 days; extracts relating to a security incident until the end of the legal claim or proceedings

4.2. Registration and user account

DataPurposeLegal basisRetention
name, e-mail address, username, password hash, role, time of registration and last login, purchased entitlements, course and access status account creation, authentication, product access and support performance of a contract, Art. 6(1)(b) GDPR for the life of the account, then as a general rule 30 days; evidence of purchase until the limitation of contractual claims

Passwords are stored as a one-way hash, not in readable form.

4.3. Orders and contract

DataPurposeLegal basisRetention
name, e-mail, phone number if given, billing name and address, tax number, order identifier, product, price, discount, payment and fulfilment status, version and time of the Terms and digital-content statements ordering, contract, performance, withdrawal, guarantee and claim handling performance of a contract; for invoice data, legal obligation contractual data as a general rule 5 years; accounting documents and supporting data 8 years

Providing this data is necessary in order to conclude the contract. Without the mandatory data the order cannot be fulfilled.

4.4. Card payment

Card payments are provided by Stripe. GENmarketer does not receive the full card number or the security code.

DataPurposeLegal basisRetention
payer’s name and e-mail, billing data, amount, currency, transaction identifier, status, limited card characteristics, fraud-prevention signals payment, refunds, fraud prevention, accounting reconciliation performance of a contract, legal obligation, legitimate interest at GENmarketer according to contractual/accounting periods; at Stripe according to its own retention

For some operations Stripe acts as a processor; for other purposes — in particular financial, regulatory and fraud-prevention purposes — it may act as an independent controller.

4.5. Invoicing

DataPurposeLegal basisRetention
billing name and address, tax number, e-mail, product, amount, invoice identifier and fulfilment data issuing and delivering invoices, accounting and tax obligations legal obligation, Art. 6(1)(c) GDPR 8 years

Invoicing may be carried out through the Számlázz.hu system, with the involvement of KBOSS.hu Kft. (Záhony utca 7/D, 1031 Budapest, Hungary).

4.6. Knowledge Base, LearnDash and training progress

DataPurposeLegal basisRetention
account identifier, enrolment, entitlement, lessons viewed, progress, completion, downloads and technical events digital access, showing progress, support and abuse prevention performance of a contract; legitimate interest for security events for the life of the access; after it ends as a general rule 30 days, minimum contractual evidence 5 years

4.7. Coaching, consultation and bespoke services

DataPurposeLegal basisRetention
name, contact details, business and marketing brief, appointment, meeting notes, documents handed over scheduling and performing the service performance of a contract during the contract, then as a general rule 5 years

Please do not share special category data unless it is strictly necessary and has been agreed in advance.

4.8. Contact, support and complaints

DataPurposeLegal basisRetention
name, e-mail, message, attachments, order data, reply and handling metadata answering questions, technical assistance, handling complaints performance of a contract or pre-contractual step; legitimate interest; legal obligation for consumer complaints general enquiries max. 5 years; consumer complaints and replies 3 years

4.9. Newsletter and direct marketing

DataPurposeLegal basisRetention
name, e-mail, source and time of subscription, version of consent, open and click data, unsubscribe newsletters, offers and content communication consent, Art. 6(1)(a) GDPR; for electronic advertising, the applicable Hungarian rules until unsubscribe or withdrawal of consent; evidence of consent and objection max. 5 years

An unsubscribe link is available in every marketing e-mail, or you can request it at info@genmarketer.hu. We may keep an unsubscribed address on a minimal suppression list so that the objection continues to be honoured in future.

4.10. Skill Hub usage telemetry

DataPurposeLegal basisRetention
GENmarketer user identifier, channel, layer, connector, action, skill, redacted technical detail, timestamp, rate-limit events performing the service, debugging, capacity, security, product quality performance of a contract; legitimate interest 90 days

Telemetry does not include the full task description, search term or connector request. Technical details are protected by automatic redaction; logging passwords, tokens and other secrets is prohibited.

4.11. Session and account-sharing risk signals

DataPurposeLegal basisRetention
IP signal pseudonymised with a keyed hash, minimal browser/device label, client identifier, first and last detection, request count and temporal correlation detecting unauthorised account sharing, credential abuse and attacks legitimate interest: account, licence and system security 90 days

We do not store the full user-agent string for this purpose, and we do not aim to recover a User’s real IP address from the pseudonymised signal. No single IP, device or browser signal leads to automatic permanent suspension. A signal is followed by human review, and the User may comment.

The Controller’s legitimate interest is protecting the paid, seat-bound service, other customers and the infrastructure. The impact on data subjects is reduced by pseudonymisation, data minimisation, 90-day deletion and human review. You may object; the Controller will then reassess whether compelling legitimate grounds exist.

4.12. Feedback, contributions and automatic run outcomes

DataPurposeLegal basisRetention
user identifier, skill/connector, type of feedback or contribution, text provided by the User, redacted technical metadata; content-free run outcome category such as partial, blocked, error or quality gap detecting faults and quality gaps, product development, handling feedback legitimate interest; consent may also apply to voluntary free text 365 days, then deletion or irreversible aggregation

A run outcome does not contain the full prompt, business brief or connector request content. Feedback goes to an internal, access-restricted inbox; it is not forwarded automatically to a public issue tracker or by e-mail.

4.13. Security events and legal claims

DataPurposeLegal basisRetention
account concerned, event time, IP or session signal, log extract, action taken, communications, evidence remediating and investigating incidents, legal claims and cooperation with authorities legitimate interest; legal obligation until the incident or proceedings are closed, then until the limitation of the related claim

5. GENmarketer Google Ads Connector

5.1. Connection and permissions requested

The Google connection is made through Google’s official OAuth interface. GENmarketer may request the following scope:

The purpose of the scope is to let the User select their own — or lawfully delegated — Google Ads accounts, produce audits, reports and improvement recommendations from them, and, where the feature is available and separately approved, carry out a controlled preview or preparation in a paused state.

5.2. Inventory of Google data

DataSourcePurposeLegal basisRetention
Google user and technical identifier of the OAuth connectionGoogle OAuthestablishing the connectionperformance of a contractuntil the connection is severed
access token, refresh token, scope, expiryGooglemaintaining authorised API accessperformance of a contractuntil the connection is severed, revoked, the account is deleted, or it becomes invalid
available customer identifiers, account names and selected accountGoogle Ads APIaccount selection and separationperformance of a contractuntil the connection is severed
campaign, ad, keyword, setting, cost and performance dataGoogle Ads APIthe audit, report or preparation requested by the Userperformance of a contract; documented instructions for B2B client datafor the duration of the operation; saved reports until deleted by the User or for the contractual period
connector events and redacted errorsGENmarketersecurity and debugginglegitimate interest90 days

Tokens are protected by application-level access restrictions and TLS encryption in transit. Access is limited to the authorised processes and administrators needed to operate the connector.

5.3. How we use and share Google data

We use Google user data solely to provide the clearly visible connector features requested by the User.

We do not:

Access may only be given to:

Human access takes place only for support, a security incident, a legal obligation, or to resolve the User’s express request, and only to the smallest necessary extent.

Use of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

5.4. Disconnection and deletion

The User may disconnect in the Knowledge Base connector settings, revoke access among the third-party connections of their Google account, or request deletion as set out in the “Data deletion and severing connector connections” chapter of this notice. Revocation stops further access; to delete the copy stored at GENmarketer, use the GENmarketer disconnection or a deletion request.

6. GENmarketer Meta Ads Connector

6.1. Permissions requested and their purposes

ads_read
Reading campaign, ad set, ad, setting and performance data of the advertising account authorised by the User, for audit and reporting purposes.
business_management
Determining which business and advertising assets the logged-in User has lawful access to, and which account they may select.
pages_read_engagement
Reading basic and activity data of a connected Page where this is necessary to produce the advertising audit or performance assessment requested by the User.

6.2. Inventory of Meta data

DataSourcePurposeLegal basisRetention
Meta user and technical identifier of the OAuth connectionMeta Login/OAuthestablishing the connectionperformance of a contractuntil the connection is severed
access token, scopes, expiryMetaauthorised API accessperformance of a contractuntil severed, revoked, the account is deleted, or it expires
advertising account identifier, name, status, currency, time zone and countryMeta Marketing APIaccount discovery and selectionperformance of a contractuntil the connection is severed
campaign, ad and performance dataMeta Marketing APIaudit, report and recommendationsperformance of a contract; documented instructions for B2B client datafor the duration of the operation; saved reports until deleted by the User or per the contract
connector events and redacted errorsGENmarketersecurity and debugginglegitimate interest90 days

Tokens are protected by application-level access restrictions and TLS encryption in transit. Access is limited to the authorised processes and administrators needed to operate the connector.

6.3. Meta Platform Data restrictions

We use Meta data only to provide the feature requested by the User. Individual customers’ data is logically separated.

We do not:

Where the User acts on behalf of a client, they must hold that client’s authorisation and may use the data only for that client’s benefit.

6.4. Disconnection and deletion

The User may sever the connection and request deletion of related data in the Knowledge Base connector settings, in the business integration settings of their Meta account, or as set out in the “Data deletion and severing connector connections” chapter of this notice.

GENmarketer provides a public instruction URL for Meta data deletion requests. Where an automatic Meta Data Deletion Callback is in operation, the request receives a confirmation code and a status URL.

7. Web analytics, advertising measurement and social pages

7.1. Google Analytics and Google Ads measurement

Subject to consent, Google Analytics and Google Ads tools may measure site usage, campaign source and conversions. Data processed may include cookie and online identifiers, approximate location derived from IP, device and browser data, page and event data, campaign parameters, gclid/gbraid/wbraid and purchase events.

Legal basis: consent. Consent can be withdrawn at any time in the Cookie settings.

7.2. Meta Pixel and Meta Business Tools

Subject to consent, the Meta Pixel and related measurement technologies may transmit page view, checkout and purchase events, online identifiers, campaign parameters and technical data to Meta for measurement, attribution and — depending on the User’s Meta settings — advertising purposes.

In respect of the collection and transmission of this data to Meta, GENmarketer and Meta Platforms Ireland Limited may in certain cases be joint controllers; Meta may act as an independent controller for further processing of the transmitted data. The allocation of responsibilities is set out in the Meta Business Tools Terms and the Controller Addendum.

7.3. Microsoft Clarity

Subject to consent, Microsoft Clarity may produce heatmaps, session recordings and usage statistics from clicks, scrolling, page rendering and technical data. Form fields and elements containing personal data must be masked. Clarity may only load after consent.

7.4. OptiMonk

Subject to consent, OptiMonk may carry out campaign display, A/B testing, onsite messaging and conversion measurement based on online identifiers and site usage events.

7.5. Social pages

If you interact with us on GENmarketer’s Facebook, Instagram, YouTube, LinkedIn or other social page, that platform processes your data under its own terms. For page statistics a joint controllership situation may arise. We handle your private messages until the enquiry is resolved, and in the case of a legal claim until its limitation.

Details of cookies and tracking technologies are set out in the Cookie Notice.

8. Recipients and service providers

ProviderRole and purposePlace of processing / safeguard
Hostinger International Ltd. or the contracting Hostinger legal entityhosting, database, servers, backupsEU and locations per the provider’s terms
Stripe Payments Europe, Limited, Stripe Technology Company, Limited and relevant Stripe entitiespayment, fraud prevention, financial complianceEEA and global infrastructure; DPA, SCCs or other lawful safeguard
KBOSS.hu Kft., Záhony utca 7/D, 1031 Budapest / Számlázz.hue-invoicing and deliveryHungary/EEA
MailerLite Limited, 88 Harcourt Street, Dublin 2, Irelandnewsletter, subscriptions, automated e-mailEEA; processor agreement
Google Ireland Limited, Google LLC and relevant Google entitiesAnalytics, Ads measurement, OAuth, Google Ads API, video and other Google servicesEEA and third countries; controller/processor terms depending on service, DPF and/or SCCs
Meta Platforms Ireland Limited and relevant Meta entitiesPixel, page statistics, OAuth and Marketing APIEEA and global infrastructure; joint/independent controller or processor terms, DPF and/or SCCs
Microsoft Ireland Operations Limited and Microsoft CorporationClarity web analytics and session measurementEU contracting party, US data centres possible; SCCs
OptiMonk International Zrt., Kassai út 129, 4028 Debrecenonsite campaigns, A/B testing and measurementHungary/EEA and subcontracted infrastructure
the AI or client platform chosen by the User, e.g. Claude or ChatGPTdisplaying prompts and connector results initiated by the Userper the platform’s own terms

Some WordPress, WooCommerce and LearnDash components run on our own hosting. If a licence, telemetry, cloud or support function transmits personal data to the vendor, the provider table must be extended before that function goes live.

An accountant, lawyer, IT contributor or authority may only receive data necessary for their task and legal basis.

9. International transfers

Some providers may process data outside the EEA, in particular in the United States. In such cases the transfer may be based on:

Where necessary we apply supplementary technical and organisational measures. Further information about the applicable safeguard can be requested at info@genmarketer.hu.

10. Data security

Proportionate to the risk, we apply in particular:

We document any personal data breach. Where the breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the risk is high we also inform the data subject, unless a statutory exception applies.

11. Automated decision-making

We do not take decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.

The system may produce an account-sharing, rate-limit or security risk signal. This is not a final decision: human review can be requested at info@genmarketer.hu before or after any substantive restriction — and immediately in the case of an urgent security measure.

12. Your rights

You have the right to:

Withdrawal of consent does not affect the lawfulness of processing carried out beforehand.

You can send your request to info@genmarketer.hu. To protect your identity and account we may ask for reasonable identification, but we never ask for a password or token.

We respond without undue delay, as a general rule within one month. For complex or multiple requests the period may be extended by a further two months; we inform you of this within the first month.

13. Data deletion and severing connector connections

13.1. What deletion can be requested?

You may request in particular:

13.2. Self-service disconnection

Where the feature is available, choose “Disconnect” in the Knowledge Base connector settings. GENmarketer then deletes the active authentication data for that connector and the account list stored to operate the connection.

You can also revoke access on the platform side:

Platform-side revocation prevents further API access but does not necessarily delete reports or log entries previously stored lawfully at GENmarketer. To delete those, use self-service disconnection or an e-mail request.

13.3. Deletion request by e-mail

Send your request to info@genmarketer.hu with the subject “Data deletion request”.

For quick identification, please give:

Do not send passwords, access tokens, API keys, card data or other secret authentication data.

If the request does not come from the e-mail address associated with the account, we may ask for proportionate identity verification to protect the account and other data subjects.

13.4. Deadline and confirmation

We answer the request without undue delay, as a general rule within one month. For complex or multiple requests the period may be extended by a further two months; we inform you of this and of the reason within the first month.

For a valid and identified request we delete or invalidate the operational connector credentials without undue delay. We confirm:

13.5. What is not deleted immediately?

Immediate full deletion cannot be applied where retention is necessary for:

In such cases we restrict the data to those further purposes and record the reason and duration of retention. Invoice data retained by law may not be used for marketing or connector operation after a deletion request.

13.6. Consequences of account deletion

Account deletion may terminate Knowledge Base, Skill Hub, update and support access. The licence for a lawfully downloaded copy, withdrawal, refunds and mandatory consumer rights are governed by the Terms and Conditions.

13.7. URL to be used in the Meta App Dashboard

The public URL of the Meta data deletion instructions is:

https://genmarketer.hu/adatkezelesi-tajekoztato/#adattorles

That page is available over HTTPS without login or geographic restriction, and remains the canonical address registered with Meta. This English chapter is a translation of it and is provided for convenience. If an automatic Meta Data Deletion Callback is built later, its dynamic status page is not a separate legal policy but a technical confirmation of that process.

14. Complaints and remedies

Please write to info@genmarketer.hu first, so that we can investigate the matter directly.

A complaint may be made to the Hungarian supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for Data Protection and Freedom of Information)
Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
E-mail: ugyfelszolgalat@naih.hu
Phone: +36 1 391 1400
Website: https://www.naih.hu/

If you are resident in another EEA country, you may also lodge a complaint with the supervisory authority of your own country of residence or place of work.

You may also go to court; where the statutory conditions are met you may bring proceedings before the court of your place of residence or stay.

15. Children

GENmarketer services are not designed for children. A person under eighteen may use a paid service only with the involvement of their legal representative. If we become aware that we are processing children’s data without a legal basis, we delete it.

Microsoft Clarity may not be used on a surface specifically directed at persons under eighteen.

16. Changes to this notice

We update this notice when there is new processing, or a change of provider, scope, law or technology. We give information about material changes affecting registered users through an appropriate channel, in advance where necessary.

The version and effective date are shown at the top of the page. Earlier versions can be requested at info@genmarketer.hu.