Privacy Policy and Data Processing Notice
Effective: September 11, 2026 | Privacy Policy and Data Processing Notice for the Preds artificial intelligence text detection service in compliance with GDPR and Hungarian privacy legislation.
1. Identification of the Data Controller
Data Controller (Service Provider):
Name: Mihály Kiss Sole Proprietorship
Registered seat: 6034 Helvécia, Gazdasági dűlő 73., Hungary
Tax number: 91730424-1-23
Email: [email protected]
Privacy inquiries: [email protected]
The Service Provider, operating the Preds service as a sole proprietorship (hereinafter: "Service Provider", "we" or "Preds"), is committed to safeguarding the personal data of its users. This Privacy Policy outlines how we collect, process, store, and protect your personal data when using the Preds service.
This document has been prepared pursuant to the General Data Protection Regulation of the European Union (GDPR – Regulation (EU) 2016/679) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).
Name: Mihály Kiss Sole Proprietorship
Registered seat: 6034 Helvécia, Gazdasági dűlő 73., Hungary
Tax number: 91730424-1-23
Email: [email protected]
Privacy inquiries: [email protected]
The Service Provider, operating the Preds service as a sole proprietorship (hereinafter: "Service Provider", "we" or "Preds"), is committed to safeguarding the personal data of its users. This Privacy Policy outlines how we collect, process, store, and protect your personal data when using the Preds service.
This document has been prepared pursuant to the General Data Protection Regulation of the European Union (GDPR – Regulation (EU) 2016/679) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).
2. Categories of Processed Personal Data
2.1 Registration and Account Information:
• Email address (mandatory, for authentication and communication)
• First name (mandatory)
• Last name (mandatory)
• Password (stored securely in salted and hashed form)
• Organization name (optional)
• Registration timestamp
• Last login timestamp
• Email verification status
When registering or signing in via Google Account, in addition to the above:
• Google account identifier (the permanent, non-transparent technical subject ID issued by Google) – used solely to link the account with Google OAuth
• Verified email address associated with the Google account
• First and last name as provided in the Google profile (used strictly to prepopulate the user profile upon account creation; modifiable in Settings)
• Organization domain name in case of Google Workspace accounts (used solely to verify authorization for domain-linked workspaces; not persisted)
• The Service Provider does not store Google access, refresh, or ID tokens, and does not query or store profile photos, contacts, calendars, or any other Google account data
In the case of Organization Accounts, in addition to the above:
• Organization name, user role (member / administrator), membership start date, and status
• In case of Enterprise Single Sign-On (SAML SSO), the permanent pseudonymous member identifier (NameID) issued by the identity provider – no additional personal attributes (name, email, groups) are requested or stored from the IdP
• Audit trail of actions performed within the organization workspace (action, technical operator ID, target, timestamp, request ID) – IP addresses and browser fingerprints are excluded from organizational audit logs
• Monthly allocated quota and consumption records
2.2 Usage Data:
• Submitted texts for AI detection (mandatory storage in encrypted form for service delivery and verification)
• Analysis metadata associated with submitted texts (hashes, normalized inputs, segment scores, repetition patterns, processing latency trace, timestamps)
• Uploaded handwriting OCR images (processed transiently in memory; images are never permanently stored) and technical processing metadata (filename, filesize, image dimensions, MIME type, model ID, token count, timestamp, status)
• Detection outputs (classification verdict, confidence scores, model version)
• API key metadata (name, creation date, last used timestamp)
• Consumption statistics (API calls, web interface detections)
• Request timestamps and source (API or web client)
• IP address (retained for security, rate limiting, and fraud prevention)
2.3 Billing Information:
• Stripe Customer ID (payment gateway identifier)
• Subscription plan tier and status
• Purchase history and transaction records
• Payment method details managed directly by Stripe (we never store credit card numbers)
2.4 Technical Information:
• Browser type and version
• Operating system
• Device category
• HTTP request logs (for debugging and system diagnostics)
• Cookie identifiers
• Email address (mandatory, for authentication and communication)
• First name (mandatory)
• Last name (mandatory)
• Password (stored securely in salted and hashed form)
• Organization name (optional)
• Registration timestamp
• Last login timestamp
• Email verification status
When registering or signing in via Google Account, in addition to the above:
• Google account identifier (the permanent, non-transparent technical subject ID issued by Google) – used solely to link the account with Google OAuth
• Verified email address associated with the Google account
• First and last name as provided in the Google profile (used strictly to prepopulate the user profile upon account creation; modifiable in Settings)
• Organization domain name in case of Google Workspace accounts (used solely to verify authorization for domain-linked workspaces; not persisted)
• The Service Provider does not store Google access, refresh, or ID tokens, and does not query or store profile photos, contacts, calendars, or any other Google account data
In the case of Organization Accounts, in addition to the above:
• Organization name, user role (member / administrator), membership start date, and status
• In case of Enterprise Single Sign-On (SAML SSO), the permanent pseudonymous member identifier (NameID) issued by the identity provider – no additional personal attributes (name, email, groups) are requested or stored from the IdP
• Audit trail of actions performed within the organization workspace (action, technical operator ID, target, timestamp, request ID) – IP addresses and browser fingerprints are excluded from organizational audit logs
• Monthly allocated quota and consumption records
2.2 Usage Data:
• Submitted texts for AI detection (mandatory storage in encrypted form for service delivery and verification)
• Analysis metadata associated with submitted texts (hashes, normalized inputs, segment scores, repetition patterns, processing latency trace, timestamps)
• Uploaded handwriting OCR images (processed transiently in memory; images are never permanently stored) and technical processing metadata (filename, filesize, image dimensions, MIME type, model ID, token count, timestamp, status)
• Detection outputs (classification verdict, confidence scores, model version)
• API key metadata (name, creation date, last used timestamp)
• Consumption statistics (API calls, web interface detections)
• Request timestamps and source (API or web client)
• IP address (retained for security, rate limiting, and fraud prevention)
2.3 Billing Information:
• Stripe Customer ID (payment gateway identifier)
• Subscription plan tier and status
• Purchase history and transaction records
• Payment method details managed directly by Stripe (we never store credit card numbers)
2.4 Technical Information:
• Browser type and version
• Operating system
• Device category
• HTTP request logs (for debugging and system diagnostics)
• Cookie identifiers
3. Legal Bases for Data Processing
3.1 Performance of a Contract (GDPR Article 6(1)(b)):
• Creation and management of user accounts
• Facilitation of Google OAuth registration and sign-in, linking Google identity to the user profile
• For organizational accounts: membership administration, SAML SSO authentication, and maintenance of organizational audit logs
• Delivery of the core Preds detection service
• Execution of AI text detection algorithms
• Optical Character Recognition (OCR) on user-uploaded handwriting images, including transmission to authorized subprocessors for this purpose
• Storage of submitted texts and associated analysis metadata (necessary for service fulfillment, maintaining submission history, and handling dispute claims)
• Customer care and technical support
3.2 Compliance with Legal Obligations (GDPR Article 6(1)(c)):
• Maintenance of statutory accounting records and invoices (8-year statutory retention)
• Tax and regulatory reporting compliance
3.3 Consent (GDPR Article 6(1)(a)):
• Marketing communications (opt-in newsletter delivery)
• Optional cookies (functional and analytics cookies)
3.4 Legitimate Interests (GDPR Article 6(1)(f)):
• System security, infrastructure integrity, and abuse prevention
• Product improvement using aggregated, anonymized metrics
• Fraud detection, credential abuse mitigation, and denial-of-service prevention (rate limiting)
• Creation and management of user accounts
• Facilitation of Google OAuth registration and sign-in, linking Google identity to the user profile
• For organizational accounts: membership administration, SAML SSO authentication, and maintenance of organizational audit logs
• Delivery of the core Preds detection service
• Execution of AI text detection algorithms
• Optical Character Recognition (OCR) on user-uploaded handwriting images, including transmission to authorized subprocessors for this purpose
• Storage of submitted texts and associated analysis metadata (necessary for service fulfillment, maintaining submission history, and handling dispute claims)
• Customer care and technical support
3.2 Compliance with Legal Obligations (GDPR Article 6(1)(c)):
• Maintenance of statutory accounting records and invoices (8-year statutory retention)
• Tax and regulatory reporting compliance
3.3 Consent (GDPR Article 6(1)(a)):
• Marketing communications (opt-in newsletter delivery)
• Optional cookies (functional and analytics cookies)
3.4 Legitimate Interests (GDPR Article 6(1)(f)):
• System security, infrastructure integrity, and abuse prevention
• Product improvement using aggregated, anonymized metrics
• Fraud detection, credential abuse mitigation, and denial-of-service prevention (rate limiting)
4. Purposes of Data Processing
We process your personal data for the following legitimate purposes:
4.1 Service Provision:
• Account registration, authentication, and credential management
• Executing AI text detection models
• Provisioning and managing API keys
• Monitoring quota balances and credit consumption
• Generating detection history logs and downloadable PDF audit reports
4.2 User Communications:
• Sending critical service updates and maintenance notifications
• Dispatching security alerts and verification codes
• Communicating subscription status and invoices
• Addressing user inquiries and support requests
• Delivering newsletters (only upon explicit prior opt-in)
4.3 Security and Compliance:
• Preventing unauthorized system access and credential stuffing
• Detecting and preventing fraudulent behavior or terms violations
• Enforcing fair usage policies and rate limiting
• Server monitoring, diagnostics, and defect resolution
• Complying with applicable legal and regulatory obligations
4.4 Service Development:
• Analyzing anonymized usage trends
• Measuring and refining AI detection model accuracy
• Optimizing user interface performance and experience
4.1 Service Provision:
• Account registration, authentication, and credential management
• Executing AI text detection models
• Provisioning and managing API keys
• Monitoring quota balances and credit consumption
• Generating detection history logs and downloadable PDF audit reports
4.2 User Communications:
• Sending critical service updates and maintenance notifications
• Dispatching security alerts and verification codes
• Communicating subscription status and invoices
• Addressing user inquiries and support requests
• Delivering newsletters (only upon explicit prior opt-in)
4.3 Security and Compliance:
• Preventing unauthorized system access and credential stuffing
• Detecting and preventing fraudulent behavior or terms violations
• Enforcing fair usage policies and rate limiting
• Server monitoring, diagnostics, and defect resolution
• Complying with applicable legal and regulatory obligations
4.4 Service Development:
• Analyzing anonymized usage trends
• Measuring and refining AI detection model accuracy
• Optimizing user interface performance and experience
5. Data Retention Periods
5.1 Active User Accounts:
• Account profile data: Retained until account deletion or after 3 consecutive years of total inactivity
• Submitted texts: Retained in encrypted form until account deletion (required for continuous access to detection history and audit verification)
• Associated analysis metadata and detection results: Retained until account deletion
• API keys: Retained until revoked by the user or until account deletion
• Google OAuth subject ID: Retained until account deletion; purged simultaneously with the profile
• Texts and results in Organization Workspaces: Retained during workspace lifespan; upon termination, exported or purged pursuant to Organization instructions (Terms Section 16.8)
• Organization uploaded documents: Original source files are deleted immediately after text extraction; extracted text is stored encrypted for up to 24 hours while verified by the member before submission
• SAML SSO NameID: Retained until membership revocation or SSO termination
• Organization audit logs: Append-only and immutable; operator IDs are preserved even after member account deletion to maintain organizational accountability
5.2 Billing Data:
• Invoices and transaction accounting records: 8 years pursuant to Hungarian accounting regulations
• Stripe payment records: Managed pursuant to Stripe's data retention policies
5.3 Technical Diagnostic Logs:
• Application error logs: 90 days
• Web access logs: 30 days
• Security incident and rate limiting logs: 2 years
5.4 Deleted Accounts:
• All personal data is permanently deleted within 30 days of an account deletion request
• Records subject to statutory retention obligations (e.g. tax invoices) are securely archived or anonymized
• Account profile data: Retained until account deletion or after 3 consecutive years of total inactivity
• Submitted texts: Retained in encrypted form until account deletion (required for continuous access to detection history and audit verification)
• Associated analysis metadata and detection results: Retained until account deletion
• API keys: Retained until revoked by the user or until account deletion
• Google OAuth subject ID: Retained until account deletion; purged simultaneously with the profile
• Texts and results in Organization Workspaces: Retained during workspace lifespan; upon termination, exported or purged pursuant to Organization instructions (Terms Section 16.8)
• Organization uploaded documents: Original source files are deleted immediately after text extraction; extracted text is stored encrypted for up to 24 hours while verified by the member before submission
• SAML SSO NameID: Retained until membership revocation or SSO termination
• Organization audit logs: Append-only and immutable; operator IDs are preserved even after member account deletion to maintain organizational accountability
5.2 Billing Data:
• Invoices and transaction accounting records: 8 years pursuant to Hungarian accounting regulations
• Stripe payment records: Managed pursuant to Stripe's data retention policies
5.3 Technical Diagnostic Logs:
• Application error logs: 90 days
• Web access logs: 30 days
• Security incident and rate limiting logs: 2 years
5.4 Deleted Accounts:
• All personal data is permanently deleted within 30 days of an account deletion request
• Records subject to statutory retention obligations (e.g. tax invoices) are securely archived or anonymized
6. Third-Party Disclosures & Data Processors
Preds never sells, rents, or trades your personal data to third parties. We engage reputable third-party processors strictly to operate and support our services:
6.1 Hosting and Infrastructure:
• Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — Server hosting, compute, and encrypted database storage.
Data location: European Union (Germany and Finland).
Governed by a Data Processing Agreement pursuant to GDPR Article 28.
Privacy Policy: https://www.hetzner.com/legal/privacy-policy/
6.2 Payment Processing:
• Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA) — Payment gateway and subscription billing.
Transfer safeguard: Standard Contractual Clauses (SCCs) approved by the European Commission — GDPR Article 46(2)(c).
Certification: PCI-DSS Level 1 certified.
Privacy Policy: https://stripe.com/privacy
*Note:* Credit card numbers are handled directly by Stripe; Preds never touches or stores payment card numbers.
6.3 Edge Security and CDN:
• Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) — Reverse proxy, DDoS protection, and SSL termination.
Processed data: IP addresses, HTTP headers, request metadata during transit.
Transfer safeguard: Standard Contractual Clauses (SCCs) — GDPR Article 46(2)(c).
Privacy Policy: https://www.cloudflare.com/privacypolicy/
6.4 Monitoring & Diagnostics:
• Error monitoring and telemetry tools operated under GDPR Article 28 DPAs; personal details are stripped or anonymized.
6.5 Handwriting OCR Processing:
• Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Parent company: Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Gemini API optical character recognition for handwriting.
Purpose: Converting handwritten Hungarian text on uploaded images into machine-readable text to serve as detection input.
Transmitted data: The uploaded image file and technical transcription prompts. No user names, emails, account IDs, or IP addresses are transmitted.
Legal basis: Performance of contract (GDPR Art. 6(1)(b)).
Safeguards & Policies: Google commits that submitted content on paid enterprise API tiers is never used to train foundational AI models. Google Data Processing Addendum and EU-U.S. Data Privacy Framework apply.
Preds storage: The image file is deleted immediately after transcription completes; only technical metadata is retained.
User Warning: Do not upload images containing sensitive category personal data (health, biometric, political) under GDPR Article 9.
6.6 Transactional Email Delivery:
• Twilio Inc. / SendGrid (101 Spear Street, San Francisco, CA 94105, USA) — Delivery of verification emails, password resets, security alerts, and system notices.
Safeguards: GDPR Article 28 DPA and EU-U.S. Data Privacy Framework / SCCs.
6.7 Web Analytics:
• Google Ireland Limited — Google Analytics 4 (GA4).
Applied only upon prior explicit opt-in consent through our cookie banner (GDPR Article 6(1)(a)).
6.8 Google Sign-In (Independent Controller):
• When signing in via Google, Google acts as an independent controller under its own privacy policy. Only basic OpenID Connect attributes (subject ID, verified email, profile name) are retrieved via PKCE-secured server flows.
6.9 Organizational Workspaces:
• For organizational accounts, the Organization acts as Data Controller for all uploaded documents and generated results, while Preds acts as Data Processor under Terms Annex 2.
6.10 SAML SSO Identity Providers:
• Enterprise SSO integrations process strictly the pseudonymous NameID assertion from your organization's IdP.
6.11 Statutory Disclosures:
• Personal data is disclosed to law enforcement or administrative authorities solely when required by mandatory law or binding court orders.
6.1 Hosting and Infrastructure:
• Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) — Server hosting, compute, and encrypted database storage.
Data location: European Union (Germany and Finland).
Governed by a Data Processing Agreement pursuant to GDPR Article 28.
Privacy Policy: https://www.hetzner.com/legal/privacy-policy/
6.2 Payment Processing:
• Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA) — Payment gateway and subscription billing.
Transfer safeguard: Standard Contractual Clauses (SCCs) approved by the European Commission — GDPR Article 46(2)(c).
Certification: PCI-DSS Level 1 certified.
Privacy Policy: https://stripe.com/privacy
*Note:* Credit card numbers are handled directly by Stripe; Preds never touches or stores payment card numbers.
6.3 Edge Security and CDN:
• Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA) — Reverse proxy, DDoS protection, and SSL termination.
Processed data: IP addresses, HTTP headers, request metadata during transit.
Transfer safeguard: Standard Contractual Clauses (SCCs) — GDPR Article 46(2)(c).
Privacy Policy: https://www.cloudflare.com/privacypolicy/
6.4 Monitoring & Diagnostics:
• Error monitoring and telemetry tools operated under GDPR Article 28 DPAs; personal details are stripped or anonymized.
6.5 Handwriting OCR Processing:
• Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), Parent company: Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Gemini API optical character recognition for handwriting.
Purpose: Converting handwritten Hungarian text on uploaded images into machine-readable text to serve as detection input.
Transmitted data: The uploaded image file and technical transcription prompts. No user names, emails, account IDs, or IP addresses are transmitted.
Legal basis: Performance of contract (GDPR Art. 6(1)(b)).
Safeguards & Policies: Google commits that submitted content on paid enterprise API tiers is never used to train foundational AI models. Google Data Processing Addendum and EU-U.S. Data Privacy Framework apply.
Preds storage: The image file is deleted immediately after transcription completes; only technical metadata is retained.
User Warning: Do not upload images containing sensitive category personal data (health, biometric, political) under GDPR Article 9.
6.6 Transactional Email Delivery:
• Twilio Inc. / SendGrid (101 Spear Street, San Francisco, CA 94105, USA) — Delivery of verification emails, password resets, security alerts, and system notices.
Safeguards: GDPR Article 28 DPA and EU-U.S. Data Privacy Framework / SCCs.
6.7 Web Analytics:
• Google Ireland Limited — Google Analytics 4 (GA4).
Applied only upon prior explicit opt-in consent through our cookie banner (GDPR Article 6(1)(a)).
6.8 Google Sign-In (Independent Controller):
• When signing in via Google, Google acts as an independent controller under its own privacy policy. Only basic OpenID Connect attributes (subject ID, verified email, profile name) are retrieved via PKCE-secured server flows.
6.9 Organizational Workspaces:
• For organizational accounts, the Organization acts as Data Controller for all uploaded documents and generated results, while Preds acts as Data Processor under Terms Annex 2.
6.10 SAML SSO Identity Providers:
• Enterprise SSO integrations process strictly the pseudonymous NameID assertion from your organization's IdP.
6.11 Statutory Disclosures:
• Personal data is disclosed to law enforcement or administrative authorities solely when required by mandatory law or binding court orders.
7. Data Subject Rights (GDPR Rights)
Under the GDPR, you are entitled to exercise the following fundamental rights:
7.1 Right of Access (GDPR Article 15):
You have the right to obtain confirmation as to whether personal data concerning you is being processed, and to receive a detailed copy of such data.
7.2 Right to Rectification (GDPR Article 16):
You can update your personal information at any time in your account Settings, or request adjustments by contacting [email protected].
7.3 Right to Erasure / "Right to be Forgotten" (GDPR Article 17):
You may request the permanent deletion of your account and personal data. Deletion is initiated via Settings → Delete Account or by emailing [email protected], and completes within 30 days.
7.4 Right to Restriction of Processing (GDPR Article 18):
You have the right to request restriction of processing where data accuracy is contested or processing is unlawful.
7.5 Right to Data Portability (GDPR Article 20):
You are entitled to receive your personal data in a structured, commonly used, and machine-readable format (JSON/ZIP export).
7.6 Right to Object (GDPR Article 21):
You have the right to object to processing based on legitimate interests at any time.
7.7 Right to Withdraw Consent (GDPR Article 7):
Consent given for marketing or optional cookies may be withdrawn at any time with immediate effect for the future.
7.8 Right to Lodge a Complaint with a Supervisory Authority (GDPR Article 77):
You have the right to lodge a formal complaint with the lead supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Phone: +36 1 391 1400
Email: [email protected]
Website: https://naih.hu
7.9 Right to an Effective Judicial Remedy (GDPR Article 79):
You may initiate judicial proceedings before the competent regional court of the controller's seat or your habitual residence.
7.10 Automated Decision-Making and Profiling (GDPR Article 22):
Preds performs automated statistical text analysis to estimate the likelihood of AI generation. This analysis applies exclusively to the submitted text and does not evaluate personal character or produce legally binding automated decisions on individuals. You have the right to request human review of results by contacting [email protected].
7.1 Right of Access (GDPR Article 15):
You have the right to obtain confirmation as to whether personal data concerning you is being processed, and to receive a detailed copy of such data.
7.2 Right to Rectification (GDPR Article 16):
You can update your personal information at any time in your account Settings, or request adjustments by contacting [email protected].
7.3 Right to Erasure / "Right to be Forgotten" (GDPR Article 17):
You may request the permanent deletion of your account and personal data. Deletion is initiated via Settings → Delete Account or by emailing [email protected], and completes within 30 days.
7.4 Right to Restriction of Processing (GDPR Article 18):
You have the right to request restriction of processing where data accuracy is contested or processing is unlawful.
7.5 Right to Data Portability (GDPR Article 20):
You are entitled to receive your personal data in a structured, commonly used, and machine-readable format (JSON/ZIP export).
7.6 Right to Object (GDPR Article 21):
You have the right to object to processing based on legitimate interests at any time.
7.7 Right to Withdraw Consent (GDPR Article 7):
Consent given for marketing or optional cookies may be withdrawn at any time with immediate effect for the future.
7.8 Right to Lodge a Complaint with a Supervisory Authority (GDPR Article 77):
You have the right to lodge a formal complaint with the lead supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Phone: +36 1 391 1400
Email: [email protected]
Website: https://naih.hu
7.9 Right to an Effective Judicial Remedy (GDPR Article 79):
You may initiate judicial proceedings before the competent regional court of the controller's seat or your habitual residence.
7.10 Automated Decision-Making and Profiling (GDPR Article 22):
Preds performs automated statistical text analysis to estimate the likelihood of AI generation. This analysis applies exclusively to the submitted text and does not evaluate personal character or produce legally binding automated decisions on individuals. You have the right to request human review of results by contacting [email protected].
8. Data Security
Preds enforces state-of-the-art security measures to safeguard your information:
8.1 Technical Security Controls:
• End-to-end encrypted transport (HTTPS / TLS 1.3)
• Strong cryptographic hashing of passwords (salted hashes)
• Encrypted database storage at rest
• Secure API key token hashing and masked displays
• Rate limiting, brute-force mitigation, and CSRF token protection
8.2 Organizational Controls:
• Strict principle of least-privilege administrative access
• Periodic code audits and vulnerability assessments
• Automated dependency and patch management
• Documented security incident response protocols
8.3 Infrastructure Safeguards:
• ISO 27001 certified European data center facilities
• Automated daily encrypted backups
• Disaster recovery and business continuity plans
8.4 Breach Notification:
In the event of a personal data breach posing high risk to individuals, we notify the competent supervisory authority (NAIH) and affected users within 72 hours as mandated by GDPR Articles 33 and 34.
8.1 Technical Security Controls:
• End-to-end encrypted transport (HTTPS / TLS 1.3)
• Strong cryptographic hashing of passwords (salted hashes)
• Encrypted database storage at rest
• Secure API key token hashing and masked displays
• Rate limiting, brute-force mitigation, and CSRF token protection
8.2 Organizational Controls:
• Strict principle of least-privilege administrative access
• Periodic code audits and vulnerability assessments
• Automated dependency and patch management
• Documented security incident response protocols
8.3 Infrastructure Safeguards:
• ISO 27001 certified European data center facilities
• Automated daily encrypted backups
• Disaster recovery and business continuity plans
8.4 Breach Notification:
In the event of a personal data breach posing high risk to individuals, we notify the competent supervisory authority (NAIH) and affected users within 72 hours as mandated by GDPR Articles 33 and 34.
9. Cookie Policy
9.1 Strictly Necessary Cookies:
Essential for core site functions, authentication, and security. Cannot be switched off:
• Session cookie: Maintains your authenticated state
• CSRF token: Defends against cross-site request forgery attacks
• Language preference: Remembers your selected language ('hu' or 'en')
9.2 Functional Cookies:
Enhance ease of use; require user consent:
• "Remember me" token: Preserves your login session across browser restarts (90 days)
• Theme selection: Remembers light/dark mode preference
9.3 Analytics Cookies:
We use Google Analytics 4 (GA4) only with your explicit consent:
• Provider: Google Ireland Limited
• Cookie names: _ga, _ga_[container-id]
• Purpose: Tracking page visits, navigation flows, and usage trends to improve user experience
• Anonymization: IP anonymization is enforced by default
• Legal basis: Voluntary consent (GDPR Article 6(1)(a))
9.4 Marketing Cookies:
Preds currently does not use third-party advertising or retargeting cookies.
Managing Cookies:
You can modify your cookie choices anytime via the "Cookie preferences" link in the footer or through your browser settings.
Essential for core site functions, authentication, and security. Cannot be switched off:
• Session cookie: Maintains your authenticated state
• CSRF token: Defends against cross-site request forgery attacks
• Language preference: Remembers your selected language ('hu' or 'en')
9.2 Functional Cookies:
Enhance ease of use; require user consent:
• "Remember me" token: Preserves your login session across browser restarts (90 days)
• Theme selection: Remembers light/dark mode preference
9.3 Analytics Cookies:
We use Google Analytics 4 (GA4) only with your explicit consent:
• Provider: Google Ireland Limited
• Cookie names: _ga, _ga_[container-id]
• Purpose: Tracking page visits, navigation flows, and usage trends to improve user experience
• Anonymization: IP anonymization is enforced by default
• Legal basis: Voluntary consent (GDPR Article 6(1)(a))
9.4 Marketing Cookies:
Preds currently does not use third-party advertising or retargeting cookies.
Managing Cookies:
You can modify your cookie choices anytime via the "Cookie preferences" link in the footer or through your browser settings.
Invite friends
For abuse prevention, we retain keyed mailbox identifiers and a signed random browser marker. Browser observations are kept for 90 days; eligibility history is retained while participating and for 12 months after account closure. Minimal email opt-out records remain while the opt-out applies. Your inviter sees only the milestones you accepted sharing, never your text or detection results. See the privacy notice for other account data.
10. International Data Transfers
10.1 Primary Storage Location:
All core Preds user data, databases, and inference systems are hosted within the European Union (Germany and Finland).
10.2 Transfers to Third Countries:
Certain subprocessors (such as Stripe, Cloudflare, SendGrid, and Google) are based in or operate servers in the United States. Where personal data is transferred outside the EU/EEA, transfers rely upon:
• European Commission Adequacy Decisions under the EU-U.S. Data Privacy Framework (GDPR Article 45)
• Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Decision (EU) 2021/914 (GDPR Article 46(2)(c))
10.3 Vendor Due Diligence:
We ensure that all non-EU processors provide equivalent data protection safeguards and have executed formal Data Processing Agreements.
All core Preds user data, databases, and inference systems are hosted within the European Union (Germany and Finland).
10.2 Transfers to Third Countries:
Certain subprocessors (such as Stripe, Cloudflare, SendGrid, and Google) are based in or operate servers in the United States. Where personal data is transferred outside the EU/EEA, transfers rely upon:
• European Commission Adequacy Decisions under the EU-U.S. Data Privacy Framework (GDPR Article 45)
• Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Decision (EU) 2021/914 (GDPR Article 46(2)(c))
10.3 Vendor Due Diligence:
We ensure that all non-EU processors provide equivalent data protection safeguards and have executed formal Data Processing Agreements.
11. Protection of Children's Privacy
The Preds service is accessible to users aged 10 and older.
Pursuant to GDPR Article 8 and Hungarian legislation:
• Users aged 16 or older may register and consent to data processing independently.
• Users aged 10 to 15 may use the service only with the verifiable consent of a parent or legal guardian.
• Children under 10 years of age are strictly prohibited from registering or submitting data.
If we learn that personal data of a child under 10 has been collected without authorization, we will immediately and permanently purge such data. Parents or guardians may contact us at [email protected] with any inquiries.
Pursuant to GDPR Article 8 and Hungarian legislation:
• Users aged 16 or older may register and consent to data processing independently.
• Users aged 10 to 15 may use the service only with the verifiable consent of a parent or legal guardian.
• Children under 10 years of age are strictly prohibited from registering or submitting data.
If we learn that personal data of a child under 10 has been collected without authorization, we will immediately and permanently purge such data. Parents or guardians may contact us at [email protected] with any inquiries.
12. Amendments to this Privacy Policy
We reserve the right to amend this Privacy Policy to reflect technical, legal, or operational developments:
• Minor updates: Published directly on this website.
• Substantive changes: Communicated via email to registered users at least 30 days prior to their effective date.
The effective date and revision stamp are always prominently displayed at the top of this document.
• Minor updates: Published directly on this website.
• Substantive changes: Communicated via email to registered users at least 30 days prior to their effective date.
The effective date and revision stamp are always prominently displayed at the top of this document.
13. Contact Information
For any inquiries regarding data protection or to exercise your GDPR rights, please contact our privacy desk:
Data Protection Desk:
Mihály Kiss Sole Proprietorship
Email: [email protected]
Mailing address: 6034 Helvécia, Gazdasági dűlő 73., Hungary
Response Timeframe:
We respond to all verified data subject requests within 30 days pursuant to GDPR Article 12(3).
Data Protection Desk:
Mihály Kiss Sole Proprietorship
Email: [email protected]
Mailing address: 6034 Helvécia, Gazdasági dűlő 73., Hungary
Response Timeframe:
We respond to all verified data subject requests within 30 days pursuant to GDPR Article 12(3).
Effective: September 11, 2026 | Last updated: September 11, 2026