NotSpammy — Privacy Policy

Version 1.0 — Effective: 2026-07-05 · Controller: Egységmester Kft., 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary · hello@practicalapps.studio

1. Scope; roles

We are the controller for: (a) your account and funnel data, (b) scan data, (c) our own B2B outreach. Stripe is an independent controller for the checkout, payment, invoicing and tax processing it performs as merchant of record (see Stripe's privacy policy at checkout); we receive from Stripe only what we need to run your plan (customer reference, subscription status) — full card data never touches our systems.

2. What we process, why, and on what legal basis

DataPurposeLegal basis (GDPR)Retention
Work email (free scan)deliver the lite report you requested; magic-link authArt. 6(1)(b)account life; unconverted free-scan emails deleted after 12 months
Account data (email, role)operate your account, alertsArt. 6(1)(b)account life + 30 days
Subscription status from Stripeplan gating, billing stateArt. 6(1)(b),(f)account life + statutory bookkeeping where applicable (HU: 8 years, Számv. tv. 169. §)
Scan data of submitted domainsthe Service itselfArt. 6(1)(b); residual incidental personal data in public records: Art. 6(1)(f) (see section 3)24 months (drift history)
Drift-alert emails / Slack configalerts you configureArt. 6(1)(b)until you remove them
Product emails to customers about similar servicesdirect marketing to existing customersArt. 6(1)(f) + the ePrivacy Art. 13(2) soft opt-in as transposed in the customer's country; opt-out in every message. HU customers: prior consent required (Grt. 6. §), so HU customers get an explicit marketing checkbox insteaduntil objection (or withdrawal, where consent-based)
B2B prospect data (name, role, business email, company)one-time outreach per our legitimate-interest assessmentArt. 6(1)(f) — LIA available on request. Source (Art. 14(2)(f)): your company's own public website (contact/team page); the exact page URL is recorded per record and cited in the messagefirst contact within 30 days of collection or the record is deleted; 12 months from first contact if no response; suppression list kept to honor your objection
Support correspondencehelp youArt. 6(1)(b),(f)24 months

We do not sell or share personal data with third parties for their own marketing. No automated decision-making with legal effect (Art. 22).

3. Scan data and third parties' data

Scans read public DNS/RDAP/blocklist data about domains. This is infrastructure metadata, not personal data by design; where a public record incidentally contains a personal email address, we mask it in reports and do not use it for anything else. Domain owners may opt out of scanning and request corrections — see our Scanning Policy and abuse@notspammy.com.

4. Recipients / processors

Hosting: Hostinger (EU). Payments: Stripe (independent controller, merchant of record; EU–US transfers under the EU–US Data Privacy Framework / SCCs). Report narrative generation: OpenAI, L.L.C. / Google (Gemini) (findings text only, no personal data). Transactional email: Resend, Inc. (USA) / Hostinger (EU). Encrypted backups: Hostinger (EU). Current list with roles and locations: the processors listed above. We sign Art. 28 data-processing agreements with all processors.

5. Transfers outside the EEA

Only as listed in section 4, under adequacy (EU–US DPF) or Standard Contractual Clauses with supplementary measures. Copies of safeguards available on request.

6. Your rights

Access, rectification, erasure, restriction, portability (where Art. 20 applies — i.e. to processing based on consent or contract, carried out by automated means), and objection — including an absolute right to object to direct marketing (Art. 21(2)), honored immediately and permanently. Where processing is based on consent (e.g. optional marketing cookies, HU customer marketing), you may withdraw it at any time with effect for the future. Contact hello@practicalapps.studio; we respond within one month. You may complain to the Hungarian supervisory authority (NAIH, naih.hu, ugyfelszolgalat@naih.hu) or your local authority, and you have judicial remedies (Arts. 77–79).

7. Security

EU-hosted infrastructure, encryption in transit, least-privilege access, restore-tested backups, minimal data by design (the scanner's passive allowlist is enforced in code). Breach notification per Arts. 33–34.

8. Changes

Material changes announced by email 30 days in advance; version history published.

Cookie Policy

Version 1.0 — Effective: 2026-07-05

We keep cookies minimal.

Cookie/storagePurposeTypeDurationConsent needed?
session / auth tokenkeep you signed in (magic link)strictly necessarysession/30 daysNo (ePrivacy Art. 5(3) exemption)
csrfsecuritystrictly necessarysessionNo
cookie-choiceremember your consent choicestrictly necessary6 monthsNo
analytics (Umami — cookie-free, self-hosted)aggregate usage statsUmami uses no cookies and no cross-site identifiers
Stripe checkout cookiespayment/fraud prevention on Stripe-hosted pagesset by Stripe on its own domainper Stripe policygoverned by Stripe's cookie notice at checkout
Meta Pixel (only if activated)retargetingmarketing90 daysYES — loads only after prior opt-in consent via the banner (EU)

No marketing cookies load before consent; refusing them never blocks the Service. Withdraw or change choices anytime via the cookie banner. More: sections 1–8 above.

Home · Terms of Service · Scanning Policy