Skip to content
BeeAssist AI

Legal

Privacy Policy

Effective from 15 July 2026

This English version is provided for convenience. In case of any discrepancy, the Hungarian version prevails.

1. Data controller

Name: Mészáros Zsolt, sole trader
Registered address: 3000 Hatvan, Czóbel Béla út 15., Hungary
Tax number: 57686051-1-33
Email: info@beeassistai.com
(the “Provider”)

The Provider is not required to appoint a Data Protection Officer under Art. 37 GDPR; for privacy matters, contact the email address above.

2. Important: we act in two different roles

a) As a data controller we process data of our own customers (users of registered accounts), our website visitors and people who contact us. Sections 3–5 apply.

b) As a data processor we handle data our customers (“Subscribers”) enter or collect while using the service — e.g. messages and contact details of visitors chatting in the widget embedded on the Subscriber’s website, emails arriving to the Subscriber’s connected mailbox, or sales leads recorded in their pipeline. For such data, the controller is the given Subscriber; we process it on their instructions under the data-processing terms of our ToS (Section 6). If you chatted on one of our customers’ websites or emailed them, please contact that company first with privacy requests.

3. Processing where we are the controller

Processing / data Purpose Legal basis (Art. 6(1)) Retention
Account registration and login: email, (optional) name and password as bcrypt hash, timestamp of ToS acceptance, email verification timestamp, login (magic-link) tokens stored only as hashes Account creation, authentication, sign-in (b) performance of contract For the life of the account. Unverified, never-used accounts are auto-deleted after 7 days. Login tokens expire after 30 minutes.
Billing data: name/company, address, tax number, issued invoices Invoicing, accounting obligations (c) legal obligation (Hungarian Accounting Act) 8 years (Sec. 169 Accounting Act)
Contact form and email: name, email, message Answering enquiries, quoting (a) consent / (b) pre-contractual steps 1 year after the case is closed
Product support (built-in support channel): requester email, request and reply content, optionally the attached test conversation Troubleshooting, customer support (b) performance of contract For the life of the account
Website analytics (own, cookie-free solution): pseudonymised visitor ID (salted SHA-256 hash of IP + user agent), masked IP (last segment removed), user agent, page path, referrer, optionally country/region/city Traffic statistics, improving the website (f) legitimate interest (operation, improvement) Statistics use a rolling 90-day window
Bot protection (Cloudflare Turnstile) at registration and sign-in: verification of the Turnstile token and IP address Preventing abuse (bot sign-ups, spam) (f) legitimate interest (security) For the duration of the check
Security logs: suspicious requests, rate-limit hits with IP address Protecting the service, detecting abuse (f) legitimate interest (security) Up to 12 months
Service-operation logs: technical log of AI calls (model used, token counts, call content) for debugging and cost accounting Operations, debugging, quota accounting (f) legitimate interest / (b) contract For the life of the account

For processing based on legitimate interest we performed a balancing test; you may object as described in Section 8.

4. Cookies and local storage

The website and the service do not use cookies and do not use third-party analytics or advertising services (e.g. Google Analytics). Traffic is measured with our own cookie-free solution described in Section 3.

Data strictly necessary for the service is kept in the browser’s localStorage — solely for functional purposes, which does not require consent:

  • the sign-in session and language preference in the admin interface,
  • the ongoing conversation ID and the open/closed state in the chat widget so conversations survive page navigation.

5. Recipients, processors, transfers

We do not sell personal data and do not share it for marketing. To deliver the service we use the following processors / independent controllers:

Provider Activity / data transferred Location, safeguards
Hetzner Online GmbH Server infrastructure (hosting) — all data stored in the service Germany (EU)
OpenAI, LLC Running AI models (text generation and embeddings): texts needed for processing — chat messages, relevant knowledge-base excerpts, email bodies — via API. OpenAI does not train models on API data. USA — EU-US Data Privacy Framework certification and/or Standard Contractual Clauses
Cloudflare, Inc. CDN/proxy in front of web traffic and Turnstile bot protection (IP address, traffic metadata) USA — DPF certification and/or SCCs
Brevo (Sendinblue SAS) Delivery of transactional email (sign-in links, notifications, quotes): recipient address and message content France (EU)
KBOSS.hu Kft. (Számlázz.hu) Invoice issuing — only if the Subscriber enables it in their own account (buyer name, address, email, line items) Hungary (EU)
ipwho.is Optional geolocation for traffic statistics (country/region/city from IP) — only when the feature is enabled May be outside the EU — only for the duration of the lookup

We disclose data to authorities or courts only where legally required.

6. Our role as processor (Subscriber data)

Subscribers typically process the following end-user personal data in the service, for which they are the controller and we are the processor:

  • Chat conversations: the full content of messages written in the widget and on the demo page, plus the email/phone the visitor voluntarily provides (for callbacks, escalation);
  • Emails: sender, subject and body of messages arriving to the connected mailbox, and AI-drafted replies;
  • Sales data: leads’ name, email, phone, company; buyer details on quotes;
  • Knowledge base: documents, website content and product data uploaded by the Subscriber.

We process this data solely to provide the service, on the Subscriber’s instructions; detailed processing terms (subject-matter, duration, nature, sub-processors, deletion) are set out in the data-processing chapter of the ToS. Text excerpts required to generate AI answers are transferred to OpenAI as listed in Section 5.

Subscribers are responsible for properly informing their own data subjects (e.g. their website visitors) and for having a valid legal basis.

7. Data security

Our technical and organisational measures under Art. 32 GDPR include:

  • encrypted transport (TLS/HTTPS, HSTS) on all surfaces;
  • passwords stored only as bcrypt hashes; login tokens and API keys only as SHA-256 hashes;
  • per-customer (tenant) data isolation and role-based access control (admin / editor / chat-only);
  • firewall, intrusion protection (fail2ban), rate limiting, bot protection (Turnstile);
  • automatic daily database backups with 14-day rotation, kept within the server infrastructure;
  • security event logging and monitoring.

In case of a data breach we follow Arts. 33–34 GDPR: notification to the Hungarian DPA within 72 hours where required, and notification of affected individuals in high-risk cases.

8. Your rights

Under Arts. 15–21 GDPR you have the right to:

  • access the data we hold about you and obtain a copy,
  • request rectification of inaccurate data,
  • request erasure (“right to be forgotten”),
  • request restriction of processing,
  • receive your data in a portable, machine-readable format (data portability),
  • object to processing based on legitimate interest,
  • withdraw consent at any time (without affecting prior processing).

Send requests to info@beeassistai.com; we respond within 30 days (extendable by 60 days in justified cases). If your request concerns data controlled by one of our Subscribers (Section 2/b), we will forward it to them or direct you to them.

You may lodge a complaint with the Hungarian supervisory authority (NAIH — Falk Miksa u. 9–11, 1055 Budapest, Hungary; naih.hu) or with your local supervisory authority, or seek judicial remedy.

9. Miscellaneous

We do not carry out automated decision-making producing legal effects, nor profiling. The service is not directed at persons under 16.

We may update this policy from time to time; the current version is always available on this page, and we notify users of material changes by email or in-app.

Prepared in accordance with Regulation (EU) 2016/679 (GDPR) and Hungarian Acts CXII of 2011 and CVIII of 2001. Last updated: 15 July 2026.