NotSpammy — Privacy Policy
Version 1.0 — Effective: 2026-07-05 · Controller: Egységmester Kft., 2330 Dunaharaszti, Gyóni Géza köz 8., Hungary · hello@practicalapps.studio
1. Scope; roles
We are the controller for: (a) your account and funnel data, (b) scan data, (c) our own B2B outreach. Stripe is an independent controller for the checkout, payment, invoicing and tax processing it performs as merchant of record (see Stripe's privacy policy at checkout); we receive from Stripe only what we need to run your plan (customer reference, subscription status) — full card data never touches our systems.
2. What we process, why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Work email (free scan) | deliver the lite report you requested; magic-link auth | Art. 6(1)(b) | account life; unconverted free-scan emails deleted after 12 months |
| Account data (email, role) | operate your account, alerts | Art. 6(1)(b) | account life + 30 days |
| Subscription status from Stripe | plan gating, billing state | Art. 6(1)(b),(f) | account life + statutory bookkeeping where applicable (HU: 8 years, Számv. tv. 169. §) |
| Scan data of submitted domains | the Service itself | Art. 6(1)(b); residual incidental personal data in public records: Art. 6(1)(f) (see section 3) | 24 months (drift history) |
| Drift-alert emails / Slack config | alerts you configure | Art. 6(1)(b) | until you remove them |
| Product emails to customers about similar services | direct marketing to existing customers | Art. 6(1)(f) + the ePrivacy Art. 13(2) soft opt-in as transposed in the customer's country; opt-out in every message. HU customers: prior consent required (Grt. 6. §), so HU customers get an explicit marketing checkbox instead | until objection (or withdrawal, where consent-based) |
| B2B prospect data (name, role, business email, company) | one-time outreach per our legitimate-interest assessment | Art. 6(1)(f) — LIA available on request. Source (Art. 14(2)(f)): your company's own public website (contact/team page); the exact page URL is recorded per record and cited in the message | first contact within 30 days of collection or the record is deleted; 12 months from first contact if no response; suppression list kept to honor your objection |
| Support correspondence | help you | Art. 6(1)(b),(f) | 24 months |
We do not sell or share personal data with third parties for their own marketing. No automated decision-making with legal effect (Art. 22).
3. Scan data and third parties' data
Scans read public DNS/RDAP/blocklist data about domains. This is infrastructure metadata, not personal data by design; where a public record incidentally contains a personal email address, we mask it in reports and do not use it for anything else. Domain owners may opt out of scanning and request corrections — see our Scanning Policy and abuse@notspammy.com.
4. Recipients / processors
Hosting: Hostinger (EU). Payments: Stripe (independent controller, merchant of record; EU–US transfers under the EU–US Data Privacy Framework / SCCs). Report narrative generation: OpenAI, L.L.C. / Google (Gemini) (findings text only, no personal data). Transactional email: Resend, Inc. (USA) / Hostinger (EU). Encrypted backups: Hostinger (EU). Current list with roles and locations: the processors listed above. We sign Art. 28 data-processing agreements with all processors.
5. Transfers outside the EEA
Only as listed in section 4, under adequacy (EU–US DPF) or Standard Contractual Clauses with supplementary measures. Copies of safeguards available on request.
6. Your rights
Access, rectification, erasure, restriction, portability (where Art. 20 applies — i.e. to processing based on consent or contract, carried out by automated means), and objection — including an absolute right to object to direct marketing (Art. 21(2)), honored immediately and permanently. Where processing is based on consent (e.g. optional marketing cookies, HU customer marketing), you may withdraw it at any time with effect for the future. Contact hello@practicalapps.studio; we respond within one month. You may complain to the Hungarian supervisory authority (NAIH, naih.hu, ugyfelszolgalat@naih.hu) or your local authority, and you have judicial remedies (Arts. 77–79).
7. Security
EU-hosted infrastructure, encryption in transit, least-privilege access, restore-tested backups, minimal data by design (the scanner's passive allowlist is enforced in code). Breach notification per Arts. 33–34.
8. Changes
Material changes announced by email 30 days in advance; version history published.
Cookie Policy
Version 1.0 — Effective: 2026-07-05
We keep cookies minimal.
| Cookie/storage | Purpose | Type | Duration | Consent needed? |
|---|---|---|---|---|
| session / auth token | keep you signed in (magic link) | strictly necessary | session/30 days | No (ePrivacy Art. 5(3) exemption) |
| csrf | security | strictly necessary | session | No |
| cookie-choice | remember your consent choice | strictly necessary | 6 months | No |
| analytics (Umami — cookie-free, self-hosted) | aggregate usage stats | — | — | Umami uses no cookies and no cross-site identifiers |
| Stripe checkout cookies | payment/fraud prevention on Stripe-hosted pages | set by Stripe on its own domain | per Stripe policy | governed by Stripe's cookie notice at checkout |
| Meta Pixel (only if activated) | retargeting | marketing | 90 days | YES — loads only after prior opt-in consent via the banner (EU) |
No marketing cookies load before consent; refusing them never blocks the Service. Withdraw or change choices anytime via the cookie banner. More: sections 1–8 above.