Privacy Policy
How we handle personal data — both for customers of the TivadarCMS platform and for subscribers to our product-update list.
This policy explains how we handle personal data in three situations: when you use the TivadarCMS platform as a customer, when you join our waitlist, and when you send us an enquiry through a form on this site. Each section says which of the three it applies to.
Which parts apply today. Accounts cannot be created yet, so nothing described under “platform customers” is happening: those sections describe what begins when registration opens. What is live today is the waitlist, the enquiry forms, the first-party analytics and the contact address — sections 5 to 8, and 11. Section 9 describes risk analysis that has not started; section 10 lists our processors, and the payment and invoicing entries in it belong to the platform, so they are not in use yet either.
Details of the Data Controller
- Company Name
- Belső Dániel entrepreneur
- Registered Office
- 8978 Rédics, Sziklai utca 49.,Hungary
- Company Registration Number
- 38541689
- Tax Number / VAT ID
- 66750929-1-40 / HU66750929
- Contact Email
- privacy@tivadar-cms.cloud
Platform customers — the two roles
Using the platform involves two different kinds of personal data, and we stand in a different position to each.
Your account with us. The data you give us to be our customer — identity, billing details, support conversations. Here we are the controller, and sections 3 and 4 describe it.
What you host with us. The personal data inside your own sites — your visitors, your users, your customers. We never decide what that is or use it for our own purposes; we only store and serve it so your sites work. Here you are the controller and we are your processor, under the Article 28 terms in section 8 of the Terms of Service. (Those terms are published together with account registration, which is not open yet.)
Platform customers — what we process and why
Account & identity
Name, email address, password (stored only as a hash), and the sign-in method you use. Where you register a business account: company name, address, tax and EU VAT number. Purpose: to give you access and to run the account. Legal basis: performance of our contract with you — GDPR Article 6(1)(b).
Billing & invoices
Subscriptions, orders, invoices and payment status. Card details are handled by our payment provider and never reach our servers. Purpose: to charge for the service and issue lawful invoices. Legal basis: the contract, and for the invoices themselves a legal obligation — Article 6(1)(b) and 6(1)(c).
Operating the service
Support tickets, notification preferences, and security-relevant records such as sign-in events and IP addresses. Purpose: to support you, to keep the platform secure and to investigate abuse. Legal basis: the contract, and our legitimate interest in a secure service — Article 6(1)(b) and 6(1)(f).
We do not sell personal data, and we do not use what you host with us to train anything or to profile you.
Platform customers — how long we keep it
Account and site data is kept while your account exists. After you close it — or after a subscription ends and is not renewed — it is deleted along with the site content and its backups. Export what you need before then; the Terms of Service describe the window. (Published together with account registration, which is not open yet.)
Two things outlive the account because the law requires it: invoices and their accounting records, which Hungarian tax law obliges us to retain for eight years, and any record we must keep to establish or defend a legal claim, for as long as that claim can be brought.
Waitlist — data, purpose and legal basis
What you give us
Your email address, first and last name, your professional role, and — optionally — your company name.
What we record about the submission
Your IP address, the browser and connection details your browser sends, the moment the form reached our server, and which page of ours you subscribed from — with the campaign parameters in that link, if it had any. We also record that the consent box was ticked and that the spam check passed. These are recorded by our server; they are not asked of you, and none of them identifies you beyond the address you gave us.
Purpose of Processing
To send you product updates about TivadarCMS — what has shipped and what is next. The waitlist is solely for product updates and is not used for general marketing. The submission details above serve a separate purpose: proving that consent was given, and preventing automated abuse of the form.
Legal basis — for the emails
Your explicit, voluntary consent (Article 6(1)(a) GDPR). We use double opt-in: you receive a confirmation link and nothing is sent until you follow it. You can withdraw consent at any time, and the emails stop.
Legal basis — for the submission details
Our legitimate interest in being able to prove that consent was given and in keeping the form usable against automated abuse (Article 6(1)(f) GDPR). This is a separate basis on purpose: withdrawing consent stops the emails, but the record that consent was once given has to survive it — otherwise the proof disappears exactly when it is needed.
Enquiry forms — data, purpose and legal basis
Four forms on this site send us an enquiry. They are separate from the waitlist: submitting one does not subscribe you to anything, and joining the waitlist does not send us an enquiry. Each form asks only for what its own row lists below — the list is generated from the same definition the forms are built from, so it cannot fall out of step with what the form on your screen actually collects.
- First name
- Last name
- Work email
- Agency or company (optional)
- What are you running today, and what is going wrong with it?
- First name
- Last name
- Work email
- Agency or company
- Client sites you run (optional)
- What are you running today, and what is going wrong with it? (optional)
- First name
- Last name
- Work email
- What are you running today, and what is going wrong with it? (optional)
- Work email
Fields marked optional may be left empty.
What we record about the submission
Your IP address, the browser and connection details your browser sends, the moment the form reached our server, and which page of ours you submitted from — with the campaign parameters in that link, if it had any. We also record that the consent box was ticked and that the spam check passed. These are recorded by our server; they are not asked of you.
Purpose of Processing
To read your enquiry and answer it, and to keep a record of the conversation it starts. Enquiries are not added to the waitlist and are not used for unrelated marketing. The submission details above serve a separate purpose: proving that consent was given, and preventing automated abuse of the form.
Legal basis — for reading and answering
Your explicit, voluntary consent (Article 6(1)(a) GDPR), given by ticking the box on the form. Where your enquiry is a step towards a contract at your own request, Article 6(1)(b) applies to that correspondence as well. You can ask us to erase an enquiry at any time.
Legal basis — for the submission details
Our legitimate interest in being able to prove that consent was given and in keeping the forms usable against automated abuse (Article 6(1)(f) GDPR). Same split, and for the same reason, as the waitlist: erasing an enquiry must not erase the evidence that it was consented to.
Product-update list — how long we keep it
What you gave us — your address, name, role and company — is kept while you are subscribed. It is deleted when you unsubscribe, or when the list is closed and the last message has been sent.
The submission details expire on a different clock, because they exist for a different reason. The IP address and browser details, which are there to keep the form usable against automated abuse, are kept for 12 months and then deleted. The record that you consented, and when, is kept for three years after your subscription ends — it is the evidence that we were allowed to write to you, and it would be worthless if it vanished the moment someone asked.
Right to Withdraw: You may withdraw your consent at any time, without giving any reason, by sending a message to privacy@tivadar-cms.cloud or by clicking the "Unsubscribe" link at the bottom of any email you receive from us.
Withdrawing stops the emails at once, and what you gave us goes with it. The record that you once consented is the single thing that outlives it, on the clock set out above — proof that disappears when it is questioned is not proof.
Use of Cookies and First-Party Analytics
Our website uses a small number of cookies. Its analytics is our own, self-hosted (first-party) software: we do not use external advertising or analytics companies, and analytics data is not passed to any third party.
Strictly Necessary Cookies
These are needed for the website to work, and your consent is not required for them. For a visitor that is one cookie, named “locale”, which remembers the language and is deleted when you close the browser. Signing in to the dashboard adds the cookies the sign-in needs. None of them is used for analytics. Your cookie choice itself is stored in your own browser.
Analytics Cookies
We record which of our pages you open, where you arrived from — the referring page, and any campaign parameters in the link you followed — how far down a page you read, how long you stayed, which links and buttons you click, and your browser, operating system and device type. All of it is tied to an identifier for your browser, held in an analytics cookie, and to your IP address. That is pseudonymous, not anonymous: we cannot put a name to it, but it is not a bare visit counter either. Nothing is recorded until you give explicit, prior consent through the cookie banner — before that, neither your browser nor our server records an analytics event. The analytics cookie is kept for up to 6 months, and after that the banner asks again.
You can withdraw your consent at any time, without giving a reason, through the “Cookie settings” link at the bottom of this page. Withdrawing deletes the analytics cookie, and nothing further is recorded from that moment. Events recorded before you withdrew are not deleted by it.
For the technical provision and security of our infrastructure (e.g., preventing DDoS attacks and unauthorized access), our servers automatically record temporary log files. These include your IP address, browser type/version, and the time of the request. This data is strictly separated from our analytics and is processed based on our legitimate interest (Article 6(1)(f) GDPR). It is not merged with other data sources and is deleted automatically after a short retention period.
To protect our forms from spam and bots, we use ALTCHA, a privacy-first, cookie-less proof-of-work solution. Because we self-host this service exclusively on our own EU infrastructure, no personal data, IP addresses, or browser fingerprints are ever shared with external third parties (unlike traditional captcha services).
Risk analysis of signups and registrations
Not happening yet. This section describes processing that begins when the risk workspace goes live. It is published before it starts, not after, so that nobody has to discover it from a flag. Nothing described below is running today.
What is analysed
The IP address a signup came from, the connection details your browser sends, and the domain half of the email address — the part after the @. The local part, the piece that identifies you, is never analysed and never sent anywhere.
Why
To prevent fraud and detect abuse. The platform provisions real infrastructure on signup: an abusive registration costs compute, and a compromised tenant can cost other tenants. Legal basis: our legitimate interest in preventing fraud and abuse (Article 6(1)(f) GDPR), which the GDPR names as a legitimate interest in Recital 47. We have carried out and documented a balancing test for it.
Sanctions screening is separate
Where we are obliged to screen against sanctions lists, that runs on a legal obligation (Article 6(1)(c) GDPR), not on the interest above. Two purposes, two bases — stating them together would misdescribe both.
Who receives anything
By default, nobody. The datasets we check against are downloaded and queried on our own EU infrastructure, so an ordinary signup discloses nothing to anyone. Only when a person investigating a specific incident asks for it do we look an IP address up with a registry (RDAP) or a reputation service (AbuseIPDB, a US provider) — an IP address only, never an email address, never automatically, and never for visitors generally.
A person decides, not the system
The analysis produces signals; a human reads them and decides. No decision about you is made solely by automated means, so the rights in Article 22 do not arise. If that ever changes, this text changes with it — before, not after.
If you are flagged
You can ask what was recorded about you and why, and ask for a flag to be reviewed, by writing to the address in section 1. Where possible the review is done by someone other than the person who raised the flag.
How long Raw observations — the IP and connection details — are kept for 12 months, the same clock as the signup details in section 7. Signals derived from them expire with them, 12 months from the last observation, so a conclusion never outlives the evidence for it. Where a person investigated and recorded a decision, that record is kept for three years, because a decision is challenged late or not at all.
Processors and sub-processors
Task: We operate our self-hosted software on their secure, EU-based servers under a strict Data Processing Agreement.
Task: Providing email hosting and communication services (Google Workspace) for direct support and general email correspondence.
Task: Payment gateway provider. Used for processing credit card payments securely for our premium hosting services. We do not store your full credit card details on our servers.
Task: Electronic invoicing provider. Used for issuing and storing legally compliant electronic invoices for processed payments.
To send out the notification emails and securely store email addresses, we use the following technical partners (data processors):
Task: Email and SMS delivery service. Used for the technical routing and reliable delivery of system notifications, subscription confirmation emails, and SMS messages.
Task: IP reputation lookup with AbuseIPDB (a US provider), on manual escalation only. An operator investigating a specific incident submits an IP address — never an email address, never automatically, and never for the general visitor population.
Your Data Protection Rights
Under the GDPR, you have the following rights:
Right of Access
You can request information about what personal data we store about you.
Right to Rectification
You can request the correction of inaccurate data (e.g., a typo in your email address).
Right to Erasure
You can request deletion of the personal data we hold about you at any time.
Right to Withdraw Consent
As detailed in Sections 7 and 8, you may withdraw consent at any time without giving any reason.
To exercise any of these rights, please contact us at privacy@tivadar-cms.cloud
Legal Remedies
Although we do our utmost to protect your data, if you believe that our data processing violates applicable data protection regulations, you have the right to file a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
Alternatively, you also have the right to lodge a complaint with a local supervisory authority or take legal action before the competent court of your Member State of residence.
Black Box Guarantee
TivadarCMS is built on the principle that your data belongs to you. All email processing runs on EU-sovereign infrastructure. No third-party analytics. No tracking pixels. No data brokering. What enters our infrastructure stays in our infrastructure.