Skip to content

Legal placeholder

GDPR Privacy Notice

How RavSolutions collects, uses, shares and protects personal data, and how you can exercise your rights under Regulation (EU) 2016/679.

Last updated
2026-08-29
Version
1.1.0
Reading time
14 min read

1. Data controller and contact details

This notice is issued by Varga Richárd E.V. (registered seat: 2030 ÉRD, VISEGRÁDI UTCA 4030/A/1; company registration number: 62764999; tax number: 92343328-1-33; EU VAT number: HU92343328; represented by Varga Richárd E.V.), the operator of the RavSolutions platform. In this notice "we", "us" and "RavSolutions" refer to that company.

You can reach us by e-mail at info@ravsolutions.eu or by phone at . Questions about this notice and every data protection request should be sent to privacy@ravsolutions.eu, a mailbox monitored specifically for this purpose.

Data protection officer: none appointed; not required under Art. 37 GDPR.

This notice describes processing under Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the applicable national data protection law, and is provided to satisfy the information duties in Articles 13 and 14 GDPR.

2. When we act as controller and when as processor

RavSolutions is a business-to-business platform. Which role we take depends on whose data is being processed, and that determines who you should address a request to.

We act as controller for data about our subscribers and their users: registration and account data, authentication data, billing and subscription data, support correspondence, marketing consent and cookie consent. We decide the purposes and means of this processing and we answer requests about it directly.

We act as processor for the content our subscribers put into the platform about their own business: their customers, jobs, comments, checklists, attachments, portal messages and activity history. For that content the subscribing organisation is the controller, we process it only on their documented instructions, and the processing is governed by a data processing agreement meeting Article 28 GDPR.

If you are a customer of one of our subscribers and received a portal link from them, please address your request to that organisation. If you send it to us, we forward it to the relevant controller without undue delay and tell you that we have done so.

3. Categories of personal data we process

Account and profile data: first name, last name, e-mail address, phone number, department, position, role in the workspace, profile picture, interface language, time zone, account status, the workspace you belong to, the account that invited you, and the creation and last login timestamps.

Authentication and technical data: a cryptographic hash of your password and never the password itself, your Google account identifier if you sign in with Google, refresh token records with a device fingerprint and expiry, IP address, browser and device information, and the server and application logs generated when you use the service.

Billing and tax data: billing name, billing address, country, postal code, city, tax number and EU VAT number, your plan, subscription and invoice records, invoice PDFs, and the customer and subscription identifiers assigned by our payment provider. We never receive or store full payment card numbers; card details are entered directly with the payment provider.

Consent and preference records: the date and version of the terms you accepted, whether you opted in to marketing e-mail and when that choice last changed, and your cookie consent choices.

Communication data: the transactional e-mails we send you, invitation messages, in-app notifications and support correspondence.

Content data processed on behalf of a subscriber: customer records (name, e-mail, phone, address, company name, tax number, notes), jobs and their status history, comments, checklist items, uploaded files and photographs, generated archives, and messages exchanged through the customer portal. Anything a subscriber types into a free-text field is included, which is why subscribers are asked not to upload special categories of data within the meaning of Article 9 GDPR.

4. Purposes of processing and legal bases

Providing the service. We process account, profile, authentication and content data to create and secure your account, run the workspace, deliver the features you subscribed to and provide support. Legal basis: performance of a contract, Article 6(1)(b) GDPR; for users added by their employer, our legitimate interest in operating the workspace on the subscriber's behalf, Article 6(1)(f) GDPR.

Billing, accounting and tax compliance. We process billing and invoice data to charge for subscriptions, issue invoices and keep accounting records. Legal basis: performance of a contract, Article 6(1)(b) GDPR, and compliance with legal obligations under tax and accounting law, Article 6(1)(c) GDPR.

Security, abuse prevention and service integrity. We process technical data, logs and authentication records to detect and prevent unauthorised access, fraud and abuse, to investigate incidents and to keep the service stable. Legal basis: our legitimate interest in the security of the service and of its users, Article 6(1)(f) GDPR. A summary of the balancing test is available on request.

Service communication and product improvement. We send operational notices about your account, subscription and security. We also measure how the website and the application are used, through Google Analytics, so that we can improve the product. Legal basis: performance of a contract for the operational messages, Article 6(1)(b) GDPR; for the measurement, your consent given on the cookie banner, Article 6(1)(a) GDPR, which you may withdraw at any time and without which nothing is measured.

Marketing e-mail. We send newsletters and product marketing only if you actively opted in. Legal basis: your consent, Article 6(1)(a) GDPR, together with the national rules implementing Directive 2002/58/EC. You may withdraw consent at any time in your profile settings or through the unsubscribe link, without affecting the lawfulness of processing carried out before withdrawal.

Establishing, exercising or defending legal claims and complying with lawful requests from authorities. Legal basis: legal obligation, Article 6(1)(c) GDPR, and legitimate interest, Article 6(1)(f) GDPR.

5. Recipients and processors

We do not sell personal data and we do not share it for third-party advertising. We disclose personal data only to the service providers listed below, each acting as our processor under a contract meeting Article 28(3) GDPR, and only as far as the stated purpose requires.

Infrastructure and storage: RackForest Zrt. hosts the application servers and the database in Hungary (EU). Cloudflare, Inc. provides the R2 object storage used for uploaded files, attachments, archives and invoice PDFs, configured for European Union, and provides network and denial-of-service protection in front of the service.

Payments and invoicing: Stripe, Inc. and Stripe Payments Europe, Ltd. process subscription payments and payment card data, acting as an independent controller for part of that processing. KBOSS.hu Kft. (szamlazz.hu) issues the invoices required by Hungarian tax law and receives the billing data printed on them.

Communication and sign-in: Brevo (Sendinblue SAS) sends transactional and marketing e-mail and receives the recipient address and the message content. Google Ireland Limited verifies your identity if you choose to sign in with Google, and, where you have consented to the analytics category, also provides the traffic and usage measurement (Google Analytics) on the website and in the application.

We may also disclose data to courts, tax authorities and law enforcement where a legal obligation requires it, and to professional advisers bound by confidentiality. Before a new processor starts processing personal data we announce it at least 30 days in advance so that subscribers can object.

6. International transfers

Our primary infrastructure — application servers, database and file storage — is located in the European Economic Area. Where a processor is confined to a specific region, that region is stated in section 5.

Some of the providers listed above are established outside the EEA or may process data outside it for support and reliability purposes. For those transfers we rely on the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 under Article 46(2)(c) GDPR, supplemented by technical and organisational measures, and on an adequacy decision where one covers the recipient, including the EU-US Data Privacy Framework for certified recipients in the United States under Article 45 GDPR.

You may request a copy of the safeguards applied to a specific transfer by writing to privacy@ravsolutions.eu.

7. How long we keep data

Account and profile data are kept for the duration of the subscription. When a user is removed the account is deactivated and its login identifiers are neutralised immediately; the remaining record is erased or anonymised within 90 days unless a longer statutory period applies.

Billing, invoice and accounting records are kept for 8 years from the end of the year they relate to, because accounting and tax law requires it. This period cannot be shortened by a request for erasure.

Content data processed on behalf of a subscriber are kept while that subscription is active. After termination the subscriber has 90 days to export the data, after which we erase it from live systems and from backups as those backups expire on their normal rotation.

Technical data, server and application logs and refresh token records are kept for 90 days, except where a particular record is held longer for an ongoing security investigation.

Consent records — terms acceptance, marketing opt-in and cookie choices — are kept for as long as the consent is relied on and for the limitation period afterwards, because Article 7(1) GDPR requires us to be able to demonstrate that consent was given.

8. Your rights

Access (Article 15 GDPR): you may ask whether we process your data, obtain a copy of it and receive the information set out in this notice in relation to your own record. Rectification (Article 16): you may have inaccurate data corrected and incomplete data completed, and most profile fields can be corrected directly in your account settings.

Erasure (Article 17): you may ask us to delete your data where it is no longer needed, where you withdraw the consent it relies on, or where you successfully object. We must refuse where retention is required by law, in particular for accounting records. Restriction (Article 18): you may ask us to freeze processing while accuracy or an objection is being examined.

Data portability (Article 20): where processing is based on consent or on a contract and is carried out by automated means, you may receive the data you provided in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible.

Objection (Article 21): you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest. Where you object to direct marketing we stop immediately and without any balancing. Withdrawal of consent (Article 7(3)): you may withdraw consent at any time and as easily as you gave it, without affecting processing carried out before the withdrawal.

These rights are not all absolute; where an exception applies we tell you which one and why. Exercising them is free of charge and we will not treat you differently for doing so.

9. How to make a request

Send your request to privacy@ravsolutions.eu, or by post to 2030 ÉRD, VISEGRÁDI UTCA 4030/A/1. Tell us which right you are exercising and, if it is not obvious, which account or which data the request concerns.

We answer within one month of receipt. Where a request is complex or where several requests are pending we may extend that by up to two further months, and we tell you within the first month, stating the reason (Article 12(3) GDPR).

Requests are handled free of charge. Only where a request is manifestly unfounded or excessive, in particular because it is repetitive, may we charge a reasonable fee or refuse to act, and we explain why (Article 12(5) GDPR).

If we have reasonable doubts about the identity of the person making the request, we may ask for additional information to confirm it before we act (Article 12(6) GDPR). We do not ask for more identification than necessary and we do not use it for any other purpose.

10. Cookies and similar technologies

We store strictly necessary cookies needed for sign-in, session integrity, security and to remember your consent choices. One of them, "rav_consent_id", holds nothing but a random identifier that links your browser to your consent record; your actual choices, the time they were made and the version of the notice they were made against are stored in our database, so that we can demonstrate them and so that you can change them from any device. These cookies do not require consent because they are needed to provide the service you asked for.

Any cookie or similar technology used for analytics, marketing or non-essential functionality is set only after you have given consent, per category, and never before you interact with the consent banner. Consent is granular, never pre-ticked, and refusing is offered in the same place and with the same ease as accepting.

You can review, change or withdraw your choices at any time — on the Cookie Policy page, and, once signed in, in your profile, where the record of every decision made and the date it was made is shown to you. Withdrawing consent is as easy as giving it and takes effect immediately for future processing.

11. Automated decision-making and profiling

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR.

The platform does perform routine automated processing — generating notifications, calculating storage usage against your plan, scheduling jobs and issuing invoices — but these operations do not evaluate personal aspects of a person and do not produce effects of that kind.

12. Security of processing

We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. They include encryption in transit over TLS, storage of passwords only as salted cryptographic hashes, strict separation of each subscriber's workspace, role-based access control, short-lived access tokens with rotating refresh tokens, expiring signed links for file downloads, and encryption at rest for stored files and backups.

Access to production data is limited to the personnel who need it for operations or support, on a least-privilege basis and under a confidentiality obligation. Backups are taken regularly and their restoration is tested.

No online service can be made absolutely secure. Please protect your credentials, use a unique password, enable any additional protection we offer, and tell us immediately at privacy@ravsolutions.eu if you believe your account has been compromised.

13. Personal data breaches

We keep an internal register of personal data breaches and follow an escalation procedure covering detection, assessment, containment and notification.

Where a breach is likely to result in a risk to the rights and freedoms of natural persons we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Article 33 GDPR). Where the breach is likely to result in a high risk we also inform the affected individuals without undue delay and in plain language (Article 34 GDPR).

Where we act as processor we notify the subscriber acting as controller without undue delay after becoming aware of a breach and assist them with their own notification duties (Article 33(2) GDPR).

14. Complaints and remedies

If you are not satisfied with how we handled your data or your request, please contact us first at privacy@ravsolutions.eu. We will look at the matter again and reply.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, your place of work or the place of the alleged infringement (Article 77 GDPR). Our competent authority is Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) / Hungarian National Authority for Data Protection and Freedom of Information, H-1055 Budapest, Falk Miksa utca 9-11., Hungary, postal address H-1363 Budapest, Pf. 9., Hungary, phone +36 1 391 1400, e-mail ugyfelszolgalat@naih.hu, website https://naih.hu.

You have the right to an effective judicial remedy against a decision of a supervisory authority and against us (Articles 78 and 79 GDPR). You may bring proceedings before the courts of the Member State where we are established or where you have your habitual residence.

15. Changes to this notice

The version number, the date of the last update and the effective date of this notice are shown in the summary box at the top of this page. Check that box to see which version you are reading.

We update this notice when our processing, our processors or the applicable law change. For material changes we inform affected users in advance by e-mail or in the application, and where the processing relies on consent we ask for consent again rather than assuming the earlier one still applies.

Earlier versions are archived and a copy can be requested at privacy@ravsolutions.eu.

Cookie preferences

We use strictly necessary cookies for signing in, for security and to remember your choice. With your consent we also use Google Analytics on the public website and in the application to measure traffic and usage; it is loaded only if you accept the analytics category, and nothing at all is requested from Google before that. We use no marketing tool whatsoever.

Read Cookie Policy