Legal document
Security statement
KKVzz applies several layers of technical and organisational controls to protect customer data on the website and in the web application. For delivery of sign-in emails we use an external transactional email provider (MailerSend), integrated with dedicated security controls.
Effective: 22 June 2026 · v2026.06.22
Technical measures
- All data connections use TLS 1.2+; access to MailerSend APIs is restricted to HTTPS endpoints with IP-filtered keys.
- Customer data is stored in the Google Cloud EU region with AES-256 server-side encryption.
- MailerSend SPF, DKIM and DMARC records are configured to ensure authenticated email delivery.
- Critical secrets (API keys, webhook tokens) are stored in a dedicated secret manager and rotated at least every 90 days.
Access control and logging
- Least privilege principle: each application and MailerSend user receives only the permissions necessary for their work.
- Multi-factor authentication (MFA) is mandatory for administrator logins.
- API and admin actions are logged and retained for at least 1 year; MailerSend delivery logs are stored for 30 days for audit purposes.
- Critical events automatically create notifications towards the incident management module.
MailerSend-specific controls
- Webhook protection: signed webhook calls verify that delivery events originate from a trusted source.
- Bounces and spam complaints are automatically added to a suppression list to reduce load and protect sender reputation.
- MailerSend API keys are separated by environment (for example staging vs production).
- Detailed MailerSend security description: Security Statement.
Organisational and procedural measures
- Quarterly review of access rights and logs.
- Formal incident reporting process: severity classification and first response within 24 hours; as a controller, notification of the supervisory authority (NAIH) within 72 hours per GDPR Article 33, and as a processor, notifying the affected Customer (controller) without undue delay.
- Security reports can be sent to security@kkvzz.hu, following responsible disclosure principles.
- Annual external penetration test covering the MailerSend integration as well.