Legal document
Privacy notice
The following sections describe how we process personal data on the public website and in the KKVzz web application where Full AI Technology Kft. is the controller. Separate sections cover the processors we use, AI-based features and your data subject rights.
Effective: 22 June 2026 · v2026.06.22
Controller and contact
Controller: Full AI Technology Kft. (registered office: 8174 Balatonkenese, Bocskai István utca 68., Hungary; tax number: 32479078-2-19). Data protection contact: privacy@kkvzz.hu. We respond to incoming requests within a maximum of 30 days. Given the size and nature of our activities, appointing a Data Protection Officer (DPO) is not mandatory and we have not appointed one; for data protection matters please use the contact above.
Two controller roles
It is important to distinguish the capacity in which we act.
- We act as controller for the data of our own customers (subscribers, contacts), website visitors and enquirers – this notice covers that role.
- We act as processor for the personal data that the Customer (your organisation) uploads into the modules (e.g. data of their employees, customers or patients). That processing is governed by the Data Processing Agreement (DPA), where the Customer is the controller.
Categories of data processed
- Public website: cookie-free, first-party web analytics event data (see below), plus technical security log data (IP address, browser type, timestamp). The contact form also processes the data you choose to provide (see below).
- Contact form: company name (optional), name, email address, phone number (optional) and the message text.
- Account and subscription: login and ordering require an email address, name, organisation name and the selected plan; activating a subscription requires billing and payment data.
- Use of the web application: account-related roles and settings, and – if you use the AI assistant – the questions/instructions you submit and the responses generated (see “AI-based features”).
- Transactional email logs (MailerSend): metadata for sign-in/notification emails (time sent, destination, status, IP) retained for audit for 30 days.
Note: for personal data uploaded into the modules by the Customer (e.g. HR/payroll data, customer and patient data, including special categories under GDPR Article 9) the Customer is the controller and we act as processor under the DPA.
Contact form
Data submitted through the contact form on the public website is processed to respond to your enquiry and to establish a possible business relationship.
- Submitted data is forwarded to the KKVzz sales (CRM) system, where a lead record is created to handle the enquiry.
- Legal basis: GDPR Article 6(1)(f) – legitimate interest (responding to incoming enquiries), or Article 6(1)(b) as a pre-contractual step where the enquiry is a request for a quote.
- Retention: enquiry data is kept until the matter is closed, then handled according to the sales module's retention policy; in the absence of a business relationship the data is deleted or anonymised.
- Completing the form is voluntary; the name and email address are required to respond, and without them we cannot process the enquiry.
Legal bases and purposes
- GDPR Article 6(1)(b) – performance of a contract: creation of user accounts, delivery of the sign-in link, processing of orders and provision of the service.
- GDPR Article 6(1)(c) – legal obligation: retention of accounting and tax documentation.
- GDPR Article 6(1)(f) – legitimate interest: prevention of abuse, logging, incident management, service security and web analytics.
- GDPR Article 6(1)(a) – consent: where we ask for separate consent (e.g. optional marketing communications); consent can be withdrawn at any time.
Processors and data transfers
We use the following processors to provide the service. GDPR Article 28 processing terms are in place with each of them.
- Google Cloud (Google Ireland Ltd.) – application hosting and encrypted database in the EU (europe-west4 region); object storage (uploaded documents); and document recognition (Google Cloud Vision OCR) for invoices and documents.
- Google Vertex AI (Gemini, Google Ireland Ltd.) – the language model behind the AI features. Processing takes place in an EU region (europe-west4). See “AI-based features” below.
- MailerSend (MailerLite Limited, Ireland) – transactional email delivery (sign-in links, notifications). Its privacy policy describes GDPR compliance and subprocessors.
- Barion Payment Zrt. (Hungary) – processing of online card payments for subscription, AI-resource and sport-pass orders. Card data is handled directly by Barion (PCI-DSS); we never see or store it. Barion data processing.
- Error logging and web analytics: client- and server-side error reports and our first-party, cookie-free web analytics are handled in our own system operated within the EU (Google Cloud); we do not use a third-party error-monitoring or analytics service.
The processors listed here handle data within the EU (or with appropriate safeguards for the EU). Integrations the Customer may enable at their own discretion (e.g. banking, e-signature, email/ calendar sync) are governed by the DPA; any transfer to those takes place on the Customer's instruction and responsibility.
AI-based features
KKVzz offers a built-in AI assistant and AI agents (e.g. Q&A, summarisation, document recognition).
- The AI features use the Google Vertex AI (Gemini) language model, with processing in an EU region (europe-west4) – we do not transfer data outside the EU for this purpose.
- Content provided to the AI is used solely to answer that request. The model does not use our data to train itself (per Vertex AI's enterprise terms).
- Use of AI features is at the user's discretion; do not enter data into the AI assistant that is not necessary to answer the request.
- AI responses can be wrong and should be reviewed. The AI does not make solely automated decisions producing legal effects concerning the user.
First-party, cookie-free web analytics
We measure website traffic with our own privacy-conscious analytics.
- We do not set analytics or marketing cookies, and we do not store raw IP addresses.
- For statistical purposes we record irreversible, daily-rotated visitor/session hashes, the page path, the referrer domain, the country derived from the IP, and active time.
- Legal basis: GDPR Article 6(1)(f) – legitimate interest (operating and improving the service) in a proportionate, privacy-friendly manner.
Retention periods
- Access/security logs: 90 days.
- MailerSend delivery logs: 30 days.
- Contractual and accounting documents: 8 years (statutory requirement).
- Inactive user accounts: after 12 months of inactivity we delete or anonymise them as part of periodic review, unless legal obligations require longer retention. You can also delete your account yourself at any time.
Data subject rights
- Right of access and information about your stored data.
- Right to rectification and erasure. Your account (and, as an owner, your organisation) can be deleted by you in the web application (Subscription → Danger zone).
- Right to restriction of processing.
- Right to data portability: you can request the personal data tied to your account in machine-readable (JSON) format; self-service data export is also available on the Account page of the web application.
- Right to object to processing based on legitimate interest (Article 6(1)(f)); on objection we cease processing unless we have compelling legitimate grounds.
- Right to withdraw consent where processing is based on consent; withdrawal does not affect the lawfulness of prior processing.
- Right to lodge a complaint with the supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11.; ugyfelszolgalat@naih.hu; naih.hu.
Personal data breach
In the event of a personal data breach that is likely to result in a risk, we notify NAIH without undue delay and within 72 hours, and where the risk is high we also inform the affected individuals. Acting as a processor, we notify the Customer (controller) of the breach without undue delay.
Automated decision-making
We do not carry out solely automated decision-making producing legal effects concerning the data subject, or profiling, within the meaning of GDPR Article 22. AI-based features support, and do not replace, the user's decisions.
Changes to this notice
We update this notice from time to time; the current version and date are shown at the top of the document. We notify you of material changes within the web application or by email.