KKVzz legal information

Required legal notices

The public kkvzz.hu site displays information and illustrations and provides a contact form. The internal web application uses an external transactional email provider (MailerSend) to deliver sign-in links – the documents below describe the legal conditions for using the KKVzz service.

Legal document

Security statement

KKVzz applies several layers of technical and organisational controls to protect customer data on the website and in the web application. For delivery of sign-in emails we use an external transactional email provider (MailerSend), integrated with dedicated security controls.

Effective: 22 June 2026 · v2026.06.22

Technical measures

  • All data connections use TLS 1.2+; access to MailerSend APIs is restricted to HTTPS endpoints with IP-filtered keys.
  • Customer data is stored in the Google Cloud EU region with AES-256 server-side encryption.
  • MailerSend SPF, DKIM and DMARC records are configured to ensure authenticated email delivery.
  • Critical secrets (API keys, webhook tokens) are stored in a dedicated secret manager and rotated at least every 90 days.

Access control and logging

  • Least privilege principle: each application and MailerSend user receives only the permissions necessary for their work.
  • Multi-factor authentication (MFA) is mandatory for administrator logins.
  • API and admin actions are logged and retained for at least 1 year; MailerSend delivery logs are stored for 30 days for audit purposes.
  • Critical events automatically create notifications towards the incident management module.

MailerSend-specific controls

  • Webhook protection: signed webhook calls verify that delivery events originate from a trusted source.
  • Bounces and spam complaints are automatically added to a suppression list to reduce load and protect sender reputation.
  • MailerSend API keys are separated by environment (for example staging vs production).
  • Detailed MailerSend security description: Security Statement.

Organisational and procedural measures

  • Quarterly review of access rights and logs.
  • Formal incident reporting process: severity classification and first response within 24 hours; as a controller, notification of the supervisory authority (NAIH) within 72 hours per GDPR Article 33, and as a processor, notifying the affected Customer (controller) without undue delay.
  • Security reports can be sent to security@kkvzz.hu, following responsible disclosure principles.
  • Annual external penetration test covering the MailerSend integration as well.