Legal placeholder
Data Processing Information
How RavSolutions processes personal data as a processor on behalf of its subscribers: instructions, security, sub-processors, assistance, erasure and audit rights under Article 28 GDPR.
- Last updated
- 2026-08-29
- Version
- 1.1.0
- Reading time
- 13 min read
1. What this notice is
This notice describes the processing we carry out on behalf of our subscribers — the situation in which RavSolutions is a processor within the meaning of Article 4(8) GDPR and the subscribing organisation is the controller. It is written for that organisation, and for anyone who wants to know what happens to the data an organisation records in the platform.
The processing contract itself is clause 14 of the Terms and Conditions, which the subscriber accepts on registration; that clause is the contract required by Article 28(3) GDPR. This page sets out the same arrangement in full, and in the event of a discrepancy the wording of the Terms prevails.
Processing where we decide the purposes and means ourselves — accounts, sign-in, billing, our own e-mail and the website — is not covered here. There we are the controller, and that processing is described in the GDPR notice and in the privacy notice.
2. Controller and processor
The platform holds two kinds of data, and our role differs between them. Which role applies decides who is accountable for the processing and who has to answer a request about it.
For data about our subscribers and their users — registration and account data, authentication data, billing and subscription data, support correspondence, marketing consent and cookie consent — we are the controller. That processing is outside the scope of this notice.
For subscriber content — the records an organisation keeps in the platform about its own business: its customers, jobs, comments, checklist items, uploaded files and photographs, portal messages and activity history — the subscribing organisation is the controller and we act solely as its processor.
We are not a joint controller with our subscribers and we do not use subscriber content for purposes of our own: we do not sell or disclose it for advertising, and we do not use it to train machine learning models. The aggregated analysis mentioned in the GDPR notice concerns how the application is used, not the content stored in it.
3. Subject matter, nature, purpose and duration
Subject matter and purpose: providing the RavSolutions service to the subscriber — recording, storing and displaying customer and job data, sending portal notifications to the recipients the subscriber designates, storing uploaded files and generating archives, running the calendar feed, and giving the subscriber's users access to that content.
Nature of the processing: collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission to the recipients the subscriber selects, restriction, erasure and destruction, carried out by automated means.
Duration: the processing lasts for the term of the subscription and for the erasure period that follows it under section 13. It ends when the content is erased, except for records covered by a statutory retention obligation of ours.
We do not process subscriber content for any purpose separate from the above, and we do not initiate processing of it on our own account. Access for troubleshooting or a support request is limited to what the request requires.
4. Categories of data subjects and personal data
Categories of data subjects: the subscriber's customers and their contact persons, the recipients of customer portal links, the subscriber's own staff and users to the extent they appear inside content records — for instance as the person a job is assigned to or the author of a comment — and any other natural person the subscriber records in a free-text field.
Categories of personal data: name, e-mail address, phone number, address, company name and tax number in customer records; job titles, descriptions, status history and scheduled dates; comments, checklist items and notes; uploaded files, photographs and generated archives; the messages and views recorded through the customer portal; and the activity history showing which user did what and when.
Special categories of personal data within the meaning of Article 9 GDPR and data relating to criminal convictions and offences under Article 10 are outside the intended scope of the service. Free-text fields and file uploads make it technically possible to enter such data, which is why subscribers are asked not to; a subscriber that does so remains the controller of it and is responsible for the consequences.
We do not verify the accuracy of content records and do not correct them on our own initiative. What is recorded, and whether it is accurate and up to date, is decided by the subscriber, which bears the responsibility under Article 5(1)(d) GDPR.
5. Processing on documented instructions
We process subscriber content only on the documented instructions of the subscriber, including as regards transfers to a third country, unless Union or Member State law to which we are subject requires otherwise. In that case we inform the subscriber of that legal requirement before processing, unless the law prohibits it on important grounds of public interest (Article 28(3)(a) GDPR).
The documented instructions consist of: the Terms and Conditions, this notice, the settings and functions the subscriber uses in the application, and any further written instruction sent to privacy@ravsolutions.eu by a person authorised to represent the subscriber.
Every action taken in the application by a user of the workspace — creating, editing, sending a portal link, downloading, deleting — counts as an instruction from the subscriber. We do not review whether an instruction is lawful in the relationship between the subscriber and its own data subjects; that assessment belongs to the controller.
If in our opinion an instruction infringes the GDPR or other Union or Member State data protection law, we inform the subscriber without delay and may suspend the execution of that instruction until the matter is clarified (Article 28(3), second subparagraph, GDPR).
6. Confidentiality
Access to subscriber content is limited to the personnel who need it to operate the service or to handle a support request, on a least-privilege basis.
Every person authorised to access subscriber content has committed to confidentiality, and that obligation survives the end of their engagement (Article 28(3)(b) GDPR).
We do not disclose subscriber content to third parties other than the sub-processors named in section 8, unless a legal obligation binding on us requires it; in that case we inform the subscriber before disclosure, unless the law prohibits it.
7. Security of processing
We apply technical and organisational measures appropriate to the risk, as required by Articles 28(3)(c) and 32 GDPR. They include encryption in transit over TLS, storage of passwords only as salted cryptographic hashes, role-based access control, short-lived access tokens with rotating refresh tokens, expiring signed links for file downloads, and encryption at rest for stored files and backups.
The workspaces of different subscribers are separated at the data level: every content record carries the identifier of the workspace it belongs to, and queries are confined to the workspace of the signed-in user, so one subscriber's users cannot reach another subscriber's content.
Links sent to a subscriber's customers through the portal carry a randomly generated token with an expiry date, and give access to the single job they were issued for and nothing else. Download links for files are signed and expire after a short period.
Backups are taken regularly and their restoration is tested. No online service can be made absolutely secure; the measures are reviewed when the service changes materially, and the subscriber is responsible for the security of the accounts and devices in its own workspace.
8. Sub-processors
The subscriber gives a general written authorisation for us to engage further processors (Article 28(2) GDPR). We impose on each of them, by contract, the same data protection obligations as those set out in this notice, and we remain fully liable to the subscriber for their performance (Article 28(4) GDPR).
Infrastructure and storage: RackForest Zrt. operates the application servers and the database in Hungary (EU). Cloudflare, Inc. provides the R2 object storage holding uploaded files, photographs and archives, configured for European Union, and provides network and denial-of-service protection in front of the service.
E-mail delivery: Brevo (Sendinblue SAS) delivers the messages sent by the service, including the portal notifications addressed to a subscriber's customers, and for that purpose receives the recipient's address and the content of the message — which contains the name of the customer, the name of the workspace and the data of the job concerned.
The providers involved in payment and invoicing — Stripe, Inc. and Stripe Payments Europe, Ltd., and KBOSS.hu Kft. (szamlazz.hu) — process data relating to the subscription itself, where we are the controller. They do not receive subscriber content.
We announce the engagement of a new sub-processor at least 30 days before it starts processing. A subscriber who objects to the change on reasonable grounds may terminate the contract before that date; the announcement states the provider, its role and the region concerned.
Google Ireland Limited supplies the traffic and usage measurement (Google Analytics) running on the public website and in the application interface. It receives no subscriber content: it records which screens are opened and basic technical data about the browser, and it runs only for a visitor who has consented to the analytics category. In respect of that measurement we act as controller rather than as the subscriber's processor, so it is named here for completeness and not as a sub-processor of subscriber content.
9. International transfers
The infrastructure that stores subscriber content — application servers, database and file storage — is located in the European Economic Area, in the regions stated in section 8.
Some of the providers named above are established outside the EEA or may access data from outside it for support and reliability purposes. For those transfers we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 under Article 46(2)(c) GDPR, supplemented by technical and organisational measures, and on an adequacy decision where one covers the recipient, including the EU-US Data Privacy Framework for certified recipients in the United States under Article 45 GDPR.
We do not transfer subscriber content to a third country on our own initiative. A subscriber may request a copy of the safeguards applied to a particular transfer by writing to privacy@ravsolutions.eu.
10. Requests from data subjects
Requests concerning subscriber content — access, rectification, erasure, restriction, objection, portability — are answered by the subscriber as controller. We do not answer them on the merits, because we are not entitled to decide about data that is not ours.
If such a request reaches us we forward it to the subscriber concerned without undue delay and tell the person that we have done so and to whom (Article 28(3)(e) GDPR).
We assist the subscriber by appropriate technical and organisational measures in fulfilling requests. An authorised user of the workspace can retrieve, correct and delete individual records and download uploaded files directly in the application; where a request cannot be fulfilled with those functions, we help on request.
The «Your data» export on the profile page serves a signed-in user's own request addressed to us as controller. It is not a route for a subscriber's customer to obtain a copy, and it does not export the content of a workspace.
11. Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to us, we assist the subscriber in complying with its obligations under Articles 32 to 36 GDPR (Article 28(3)(f) GDPR).
For a data protection impact assessment or a prior consultation with the supervisory authority we provide, on request, a description of the processing operations, the measures set out in section 7, the sub-processor list in section 8, the transfer safeguards in section 9 and the retention periods in section 13.
We provide this assistance as part of the service and do not charge separately for it.
12. Personal data breaches
We notify the subscriber without undue delay after becoming aware of a personal data breach affecting its content (Article 33(2) GDPR). We keep an internal register of breaches and follow an escalation procedure covering detection, assessment, containment and notification.
The notification describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed to address it. Where the information cannot be provided all at once, we provide it in phases without undue further delay.
Notifying the supervisory authority under Article 33(1) GDPR and communicating the breach to the data subjects under Article 34 GDPR is the subscriber's duty as controller. We assist with the information available to us, but we do not make the notification in the subscriber's place.
13. Return and erasure of data
During the subscription the subscriber can retrieve its data from the application at any time: records can be viewed and edited, uploaded files and images downloaded, and calendar data obtained through the ICS feed. We do not offer a function that exports the whole content of a workspace into a single file.
Within 90 days of the contract ending we erase the content of the workspace. Within that period the subscriber may request earlier erasure in writing. After erasure the data cannot be restored, so the subscriber should retrieve what it needs before the period expires.
Erasure takes effect in the live systems immediately; copies held in backups disappear as those backups expire on their normal rotation, and until then they are not used for any other purpose.
Billing and accounting records are kept for 8 years, and technical and security logs for 90 days, on the basis of our own legal obligations as controller. Those periods are not affected by an erasure instruction relating to subscriber content.
14. Audits and demonstrating compliance
We make available to the subscriber the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and we allow for and contribute to audits, including inspections, conducted by the subscriber or an auditor mandated by it (Article 28(3)(h) GDPR).
Where the request can be satisfied by documentation already held — this notice, the description of the measures in section 7, the sub-processor list, or a provider's certificate or audit report — we provide that first.
An on-site inspection requires reasonable advance notice, normally 30 days, takes place during business hours in a way that does not disrupt the operation of the service, and the auditor must be bound by confidentiality. An audit may not extend to the data of another subscriber or to information covered by the confidentiality obligation owed to a third party.
15. What the subscriber is responsible for
As controller the subscriber determines the purposes and means of the processing of content: it decides what is recorded, on what legal basis, who may see it and how long it is kept in the service.
The subscriber is responsible for informing its own data subjects under Articles 13 and 14 GDPR, for having a legal basis for the processing, and for answering requests addressed to it. This notice does not substitute for the subscriber's own privacy notice.
The subscriber administers the user accounts of its workspace: it grants and withdraws access, assigns roles, and removes users who no longer need access. We do not decide who may see a workspace.
The subscriber is asked not to record special categories of data in the service, and to send portal links only to the addresses their recipients gave for that purpose.
16. Changes to this notice
We keep this notice up to date with the service. The version number and effective date at the top of the page show which text is in force; earlier versions are available on request.
A change affecting the substance of the processing — a new sub-processor, a new purpose, a change of region — is announced at least 30 days before it takes effect, in the manner described in section 8.
Questions about this notice and instructions relating to the processing should be sent to privacy@ravsolutions.eu. Data protection officer: none appointed; not required under Art. 37 GDPR.