Legal placeholder
Privacy Policy
How we handle personal data when you visit our website, write to us, create an account and subscribe to our newsletter.
- Last updated
- 2026-08-29
- Version
- 1.1.0
- Reading time
- 9 min read
1. What this notice covers
This notice explains how we handle personal data when you visit our public website, contact us by e-mail, create an account in the RavSolutions application, or subscribe to our newsletter. It follows the situations you may actually find yourself in, rather than restating a statutory checklist.
The full, article-by-article account of legal bases, retention periods, processors and transfers outside the EEA is set out in the GDPR privacy notice; cookies and the handling of consent are covered by the Cookie notice. Where this notice and the GDPR privacy notice differ, the GDPR privacy notice prevails.
This notice does not cover the data our subscribers upload to the platform about their own customers and jobs. We do not decide how that data is processed; section 8 explains who does.
2. Who processes your data
The controller is Varga Richárd E.V. (registered seat: 2030 ÉRD, VISEGRÁDI UTCA 4030/A/1; company registration number: 62764999; tax number: 92343328-1-33; represented by: Varga Richárd E.V.). General contact: info@ravsolutions.eu, phone: .
Please send privacy questions and requests to privacy@ravsolutions.eu, a mailbox we monitor for that purpose. Data protection officer: none appointed; not required under Art. 37 GDPR.
3. Visiting the website
You need no account and have to give us nothing to browse the website. The server does, however, log every request: your IP address, the time of the request, the page requested, the referring page, and the type of your browser and operating system. We need these logs to operate the service, investigate faults and repel attacks. Legal basis: legitimate interest, Article 6(1)(f) GDPR; retention: 90 days.
The website is served by RackForest Zrt. in Hungary (EU), with network and denial-of-service protection provided by Cloudflare, Inc. Your requests therefore pass through both, and both act as processors.
The site loads its typeface from the font servers of Google LLC (fonts.googleapis.com, fonts.gstatic.com), which discloses your IP address and browser details to Google. This happens when the page opens, before you have made any choice on the cookie banner.
We store the interface language you selected in your browser so that you see it again on your next visit. If you consent to the analytics category on the cookie banner, we also measure traffic and usage with Google Analytics; without that consent it is not loaded at all, and you can withdraw it at any time. We load no advertising tool. The links to our social profiles are plain links: they carry no embedded button or tracking pixel, so nothing reaches the social networks unless you click.
4. Contacting us
There is no contact form on the website: the contact page publishes a single e-mail address (info@ravsolutions.eu) and your own mail client sends the message. Nothing reaches us until you send that message.
We process incoming messages together with the data in them — your name, e-mail address and whatever you write — to answer the enquiry and follow up on it. Legal basis: steps taken at your request before entering into a contract, or performance of the contract, Article 6(1)(b) GDPR; for other enquiries, our legitimate interest in replying, Article 6(1)(f). Our correspondence is stored in a mailbox operated by Brevo.
Please do not send us health data or other special category data within the meaning of Article 9 GDPR by e-mail, as ordinary e-mail is not an end-to-end encrypted channel.
5. Registration, account and trial
Registration asks for your company name, your first and last name, your e-mail address and a password of your choosing. We never store the password itself, only a salted cryptographic hash of it. The language used on the registration form becomes the default language of the new workspace and of your account. Legal basis: performance of a contract, Article 6(1)(b) GDPR.
If you sign in with a Google account, Google Ireland Limited confirms your identity to us and we receive your e-mail address and Google account identifier from it. We have no access to, and never see, your Google password.
Registration includes accepting the terms of service and this privacy notice. We store the time of acceptance and the version of the documents accepted, because we have to be able to show what you agreed to and when. Registration cannot be completed without that acceptance. Subscribing to the newsletter is a separate, optional checkbox that is not ticked by default, and declining it does not affect your use of the service.
While you use the account we process profile data (phone number, department, position, profile picture, time zone, interface language), sign-in and security records (refresh tokens with a device identifier and expiry, time of last sign-in), and subscription and — on a paid plan — billing data. We never receive or store a full card number. Section 3 and section 4 of the GDPR privacy notice list these in detail.
6. Newsletter and marketing e-mail
We send newsletters and product marketing only if you have separately and actively opted in: through the dedicated checkbox on the registration form, or later in your profile. We use no pre-ticked boxes, and we never bundle this consent with acceptance of the terms. Legal basis: your consent, Article 6(1)(a) GDPR, together with the national rules implementing Directive 2002/58/EC.
You may withdraw consent at any time, without giving reasons and free of charge: sign in and turn off the newsletter checkbox in your profile, or write to privacy@ravsolutions.eu. Withdrawal takes effect for the future and does not affect the lawfulness of messages sent before it. We store the fact of the opt-in and the time it last changed, because Article 7(1) GDPR requires us to be able to demonstrate that consent was given.
E-mail is sent on our behalf by Brevo (Sendinblue SAS) as a processor, which receives the recipient address and the content of the message. Operational messages about your account, password, subscription and invoices are not marketing: they form part of performing the contract, so we keep sending them for as long as your account exists.
7. Cookies and consent
Strictly necessary cookies are set without consent, because sign-in, session integrity and security would not work without them. They include the “rav_consent_id” cookie, which holds nothing but a random identifier linking your browser to the consent record stored on our servers; it lasts 13 months, after which we ask you again.
Every other cookie and similar technology reaches your device only after your consent, given per category. On the cookie banner, refusing is available in the same place and takes the same number of clicks as accepting, and we use no pre-enabled toggles.
We store your choices — with the time of the decision, the consent version, a truncated IP address and a shortened browser identifier — on our servers rather than in your browser alone, so that we can demonstrate them and so that you can change them from any device. You can view, change or withdraw your choices at any time on the Cookie notice page, and in your profile once signed in.
8. Data uploaded by our subscribers
If your data is on the platform because one of our subscribers — your service provider or your employer, for instance — entered it as a customer, contact or team member, then that business is the controller. In that case we act purely as a processor on its documented instructions, under a contract meeting Article 28 GDPR, and we do not use the data for our own purposes.
Address requests for access, rectification, erasure or objection to that business. If you send such a request to us, we forward it to the controller without undue delay and let you know that we have done so.
9. Who we share your data with
We do not sell personal data and do not disclose it for third-party advertising. We engage a processor only where it is necessary to provide the service, and we conclude a contract meeting Article 28(3) GDPR with each of them.
Infrastructure and hosting: RackForest Zrt. (application servers and database, Hungary (EU)); Cloudflare, Inc. (network protection, and storage of uploaded files, attachments and invoice PDFs in R2 object storage, European Union).
Payment and invoicing: Stripe, Inc. and Stripe Payments Europe, Ltd. (subscription payments and card data); KBOSS.hu Kft. – szamlazz.hu (issuing invoices as required by Hungarian tax law). E-mail delivery: Brevo (Sendinblue SAS). Sign-in: Google Ireland Limited. Mailbox: Brevo. Typefaces: Google LLC. Traffic and usage measurement: Google Ireland Limited (Google Analytics), and only where you have consented to it.
We may disclose data to courts, tax authorities or law enforcement where the law requires it, and to our accountant and legal advisers, who are bound by professional secrecy. Transfers outside the European Economic Area and the safeguards applied to them are covered in section 6 of the GDPR privacy notice. We announce any new processor at least 30 days before it starts processing.
10. How long we keep your data
Server logs, technical data and the register of sign-in tokens: 90 days, unless an entry has to be kept longer for an ongoing security investigation. Account and profile data: for the life of the subscription, then deleted or anonymised within 90 days.
Billing, invoice and accounting records: 8 years from the end of the year they relate to, because accounting and tax law requires it; this period cannot be shortened by a request for erasure. Consent records (acceptance of the terms, the newsletter and cookies): for as long as the consent is relied on, plus the subsequent limitation period.
Data leaves our backups as those backups expire on their normal rotation. Erasure therefore takes effect immediately in the live systems and becomes complete in the backups with the next rotation.
11. Your rights
You may request access to your data and a copy of it, rectification of inaccurate data, erasure, restriction of processing and data portability; you may object to processing based on legitimate interest; and you may withdraw your consent at any time. An objection to direct marketing is always honoured, with no balancing exercise. Most profile data can also be corrected directly in your account settings.
Send your request to privacy@ravsolutions.eu or by post to 2030 ÉRD, VISEGRÁDI UTCA 4030/A/1. We answer free of charge within one month of receipt; for complex requests, or where several are pending at once, that period may be extended by up to two further months, of which we inform you within the first month together with the reasons. Sections 8 and 9 of the GDPR privacy notice set out the exact content and limits of each right.
If you are unhappy with how we handled your data or your request, please come to us first. You are also entitled to lodge a complaint with the supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) / Hungarian National Authority for Data Protection and Freedom of Information, H-1055 Budapest, Falk Miksa utca 9-11., Hungary, phone: +36 1 391 1400, e-mail: ugyfelszolgalat@naih.hu, website: https://naih.hu. Your right to an effective judicial remedy is unaffected.
12. Changes to this notice
The version number of this notice and the dates it was last updated and took effect appear in the summary box at the top of the page; please check there which version you are reading. A copy of earlier versions can be requested at privacy@ravsolutions.eu.
If this notice changes materially, we inform registered users in advance by e-mail or in the application. Where processing rests on consent, we ask for fresh consent rather than treating the earlier one as automatically still valid.