Legal
Privacy Policy
Effective from 15 July 2026
This English version is provided for convenience. In case of any discrepancy, the Hungarian version prevails.
1. Data controller
Name: Mészáros Zsolt, sole trader
Registered address: 3000 Hatvan, Czóbel Béla út 15., Hungary
Tax number: 57686051-1-33
Email: info@beeassistai.com
(the “Provider”)
The Provider is not required to appoint a Data Protection Officer under Art. 37 GDPR; for privacy matters, contact the email address above.
2. Important: we act in two different roles
a) As a data controller we process data of our own customers (users of registered accounts), our website visitors and people who contact us. Sections 3–5 apply.
b) As a data processor we handle data our customers (“Subscribers”) enter or collect while using the service — e.g. messages and contact details of visitors chatting in the widget embedded on the Subscriber’s website, emails arriving to the Subscriber’s connected mailbox, or sales leads recorded in their pipeline. For such data, the controller is the given Subscriber; we process it on their instructions under the data-processing terms of our ToS (Section 6). If you chatted on one of our customers’ websites or emailed them, please contact that company first with privacy requests.
3. Processing where we are the controller
| Processing / data | Purpose | Legal basis (Art. 6(1)) | Retention |
|---|---|---|---|
| Account registration and login: email, (optional) name and password as bcrypt hash, timestamp of ToS acceptance, email verification timestamp, login (magic-link) tokens stored only as hashes | Account creation, authentication, sign-in | (b) performance of contract | For the life of the account. Unverified, never-used accounts are auto-deleted after 7 days. Login tokens expire after 30 minutes. |
| Billing data: name/company, address, tax number, issued invoices | Invoicing, accounting obligations | (c) legal obligation (Hungarian Accounting Act) | 8 years (Sec. 169 Accounting Act) |
| Contact form and email: name, email, message | Answering enquiries, quoting | (a) consent / (b) pre-contractual steps | 1 year after the case is closed |
| Product support (built-in support channel): requester email, request and reply content, optionally the attached test conversation | Troubleshooting, customer support | (b) performance of contract | For the life of the account |
| Website analytics (own, cookie-free solution): pseudonymised visitor ID (salted SHA-256 hash of IP + user agent), masked IP (last segment removed), user agent, page path, referrer, optionally country/region/city | Traffic statistics, improving the website | (f) legitimate interest (operation, improvement) | Statistics use a rolling 90-day window |
| Bot protection (Cloudflare Turnstile) at registration and sign-in: verification of the Turnstile token and IP address | Preventing abuse (bot sign-ups, spam) | (f) legitimate interest (security) | For the duration of the check |
| Security logs: suspicious requests, rate-limit hits with IP address | Protecting the service, detecting abuse | (f) legitimate interest (security) | Up to 12 months |
| Service-operation logs: technical log of AI calls (model used, token counts, call content) for debugging and cost accounting | Operations, debugging, quota accounting | (f) legitimate interest / (b) contract | For the life of the account |
For processing based on legitimate interest we performed a balancing test; you may object as described in Section 8.
4. Cookies and local storage
The website and the service do not use cookies and do not use third-party analytics or advertising services (e.g. Google Analytics). Traffic is measured with our own cookie-free solution described in Section 3.
Data strictly necessary for the service is kept in the browser’s localStorage — solely for functional purposes, which does not require consent:
- the sign-in session and language preference in the admin interface,
- the ongoing conversation ID and the open/closed state in the chat widget so conversations survive page navigation.
5. Recipients, processors, transfers
We do not sell personal data and do not share it for marketing. To deliver the service we use the following processors / independent controllers:
| Provider | Activity / data transferred | Location, safeguards |
|---|---|---|
| Hetzner Online GmbH | Server infrastructure (hosting) — all data stored in the service | Germany (EU) |
| OpenAI, LLC | Running AI models (text generation and embeddings): texts needed for processing — chat messages, relevant knowledge-base excerpts, email bodies — via API. OpenAI does not train models on API data. | USA — EU-US Data Privacy Framework certification and/or Standard Contractual Clauses |
| Cloudflare, Inc. | CDN/proxy in front of web traffic and Turnstile bot protection (IP address, traffic metadata) | USA — DPF certification and/or SCCs |
| Brevo (Sendinblue SAS) | Delivery of transactional email (sign-in links, notifications, quotes): recipient address and message content | France (EU) |
| KBOSS.hu Kft. (Számlázz.hu) | Invoice issuing — only if the Subscriber enables it in their own account (buyer name, address, email, line items) | Hungary (EU) |
| ipwho.is | Optional geolocation for traffic statistics (country/region/city from IP) — only when the feature is enabled | May be outside the EU — only for the duration of the lookup |
We disclose data to authorities or courts only where legally required.
6. Our role as processor (Subscriber data)
Subscribers typically process the following end-user personal data in the service, for which they are the controller and we are the processor:
- Chat conversations: the full content of messages written in the widget and on the demo page, plus the email/phone the visitor voluntarily provides (for callbacks, escalation);
- Emails: sender, subject and body of messages arriving to the connected mailbox, and AI-drafted replies;
- Sales data: leads’ name, email, phone, company; buyer details on quotes;
- Knowledge base: documents, website content and product data uploaded by the Subscriber.
We process this data solely to provide the service, on the Subscriber’s instructions; detailed processing terms (subject-matter, duration, nature, sub-processors, deletion) are set out in the data-processing chapter of the ToS. Text excerpts required to generate AI answers are transferred to OpenAI as listed in Section 5.
Subscribers are responsible for properly informing their own data subjects (e.g. their website visitors) and for having a valid legal basis.
7. Data security
Our technical and organisational measures under Art. 32 GDPR include:
- encrypted transport (TLS/HTTPS, HSTS) on all surfaces;
- passwords stored only as bcrypt hashes; login tokens and API keys only as SHA-256 hashes;
- per-customer (tenant) data isolation and role-based access control (admin / editor / chat-only);
- firewall, intrusion protection (fail2ban), rate limiting, bot protection (Turnstile);
- automatic daily database backups with 14-day rotation, kept within the server infrastructure;
- security event logging and monitoring.
In case of a data breach we follow Arts. 33–34 GDPR: notification to the Hungarian DPA within 72 hours where required, and notification of affected individuals in high-risk cases.
8. Your rights
Under Arts. 15–21 GDPR you have the right to:
- access the data we hold about you and obtain a copy,
- request rectification of inaccurate data,
- request erasure (“right to be forgotten”),
- request restriction of processing,
- receive your data in a portable, machine-readable format (data portability),
- object to processing based on legitimate interest,
- withdraw consent at any time (without affecting prior processing).
Send requests to info@beeassistai.com; we respond within 30 days (extendable by 60 days in justified cases). If your request concerns data controlled by one of our Subscribers (Section 2/b), we will forward it to them or direct you to them.
You may lodge a complaint with the Hungarian supervisory authority (NAIH — Falk Miksa u. 9–11, 1055 Budapest, Hungary; naih.hu) or with your local supervisory authority, or seek judicial remedy.
9. Miscellaneous
We do not carry out automated decision-making producing legal effects, nor profiling. The service is not directed at persons under 16.
We may update this policy from time to time; the current version is always available on this page, and we notify users of material changes by email or in-app.
Prepared in accordance with Regulation (EU) 2016/679 (GDPR) and Hungarian Acts CXII of 2011 and CVIII of 2001. Last updated: 15 July 2026.