Privacy Policy

Privacy Policy

VWCloudMobil mobile application · Effective: 14 September 2026 · Version 2.0

This policy describes the data processing practices of the VWCloudMobil mobile application. The application is the mobile extension of the software of Visual Window Kft.: it cannot be licensed on its own and may be used solely by partner companies holding a valid software licence and the employees designated by them, as well as by the company’s own staff, in support of procurement, logistics and customer management processes.

The processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, hereinafter: GDPR) and with Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the Hungarian Privacy Act, “Infotv.”).

1. The data controller

Company name Visual Window Support Hungary Korlátolt Felelősségű Társaság (limited liability company)
Short name Visual Window Kft. (hereinafter: Visual Window)
Registered seat Zirzen Janka u. 38., 1125 Budapest, Hungary
Company registration number 01-09-922684 (Company Registry Court of the Budapest-Capital Regional Court)
Tax number 14845488-2-43
Phone +36 30 310 5555
E-mail support@visualwindow.hu

With regard to the personal data processed in the application, Visual Window Kft. qualifies as the data controller, meaning that it independently determines the purposes and means of the processing.

2. Who this policy applies to

  • Partners in a contractual relationship with Visual Window Kft. who have obtained the right to use the application, together with the natural persons designated by them who hold a user account.
  • Employees of Visual Window Kft. who use the application in the performance of their duties.
  • Natural persons (e.g. customers, supplier contact persons) whose data appear in the business records managed in the application.

The application is intended exclusively for business use and is not available to consumers or to persons under the age of 18. We do not knowingly collect personal data relating to minors. If we become aware that such data has entered our systems, we delete it without delay.

3. What data we process

3.1 Login and account data

Username and password, the permission level assigned to the account, the identifier of the partner company employing the user and – where provided – the user’s name and e-mail address. Passwords are stored exclusively in encrypted (hashed) form; we have no means of decrypting them.

3.2 Push notification identifier

The push token identifier of the device (Firebase Cloud Messaging on Android, Apple Push Notification Service on iOS), which enables notifications to be sent (e.g. delivery reminders, status changes).

3.3 Camera access

The application requests camera access in order to scan QR codes. The camera image is not stored, recorded or transmitted; only the content of the scanned code is processed on the device. Camera access can be withdrawn at any time in the settings of the device’s operating system, in which case the QR code scanning function cannot be used.

3.4 Log and technical data

Data generated automatically during the operation of the application and the server system:

  • IP address, device type, the name and version of its operating system, the version number of the application;
  • login and logout timestamps, unsuccessful login attempts;
  • the audit log of operations performed in the application (which user created, modified or deleted which record, and when);
  • error and operational logs for the purpose of resolving malfunctions.

3.5 Business data

Project, order, delivery, customer and supplier records, which the user can access within the scope of their own permissions. These records may also contain data of natural persons, typically in the capacity of contact persons: name, position, telephone number, e-mail address, delivery or site address.

3.6 Contact data

Data provided in the course of support or data protection enquiries (name, e-mail address, telephone number, the content of the enquiry).

3.7 Source of the data

We receive the majority of the above data directly from you or from your device. In two cases the data does not originate from you:

  • Account data: if your user account was created by the administrator of your partner company, the basic data belonging to the account (username, name, e-mail address, permission level) was provided to us by the partner company.
  • Contact person data: the data of contact persons appearing in the business records was made available to us by the partner, customer or supplier company that designated them, typically upon conclusion of the contract or during the order process. We may also supplement this data from publicly available sources (e.g. the company register, the company’s website).

In these cases this policy serves as your information notice pursuant to Article 14 GDPR; you may at any time obtain information on the specific scope of the data processed by submitting an access request under Section 11.

4. Purposes and legal bases of the processing

Purpose Data processed Legal basis Notes
Creation of the user account, identification of the user, provision of access 3.1 Article 6(1)(b) GDPR – performance of a contract Providing the data is a condition of using the service; without it the account cannot be created.
Sending push notifications related to the operation of the service 3.2 Article 6(1)(b) GDPR Notifications relate exclusively to operational and business processes. We do not send marketing notifications.
Support of business processes (procurement, delivery tracking, customer relations) 3.5 Article 6(1)(b) GDPR Performance of the contract concluded with the partner.
Scanning QR codes with the device camera 3.3 No processing of personal data takes place The camera image is not recorded or transmitted. Device-level camera access is based on the permission granted in the operating system, which may be withdrawn at any time.
Processing of contact person data in the business records 3.5 Article 6(1)(f) GDPR – legitimate interest Legitimate interest: the practical management of the contractual relationship.
System security, prevention and detection of misuse, troubleshooting, traceability of operations 3.4 Article 6(1)(f) GDPR – legitimate interest Legitimate interest: protecting the integrity of the data and the system, ensuring accountability.
Invoicing, retention of accounting documents 3.1, 3.6 Article 6(1)(c) GDPR – legal obligation Act C of 2000, Act CXXVII of 2007.
Receiving, fulfilling and documenting data subject requests 3.6 Article 6(1)(c) GDPR Fulfilment of the obligations under Articles 12–22 GDPR.
Establishment, exercise and defence of legal claims 3.1, 3.4, 3.5 Article 6(1)(f) GDPR – legitimate interest Legitimate interest: protection of the company’s rights in the event of a legal dispute.
For processing based on legitimate interest we have carried out a balancing test, a summary of which we will make available on request through the contact details given in Section 13. You may object to such processing in accordance with Section 11.

5. Data storage and security

Data is stored on a server owned and operated by Visual Window Kft. and located in Hungary, in PostgreSQL and SQL Server databases. We do not use any external hosting or cloud service provider for storing the data, so the data does not leave the territory of the European Economic Area – with the exception of the case relating to push notifications described in Section 6.1.

In order to protect the data we apply the following technical measures:

  • communication between the application and the server takes place over an encrypted channel (TLS);
  • passwords are stored exclusively in one-way, salted hash form;
  • role-based permission management: every user has access only to the data required for their work;
  • logging of access and of material data operations;
  • regular, encrypted backups and periodic testing of recoverability;
  • firewall and network segmentation, restriction of access to the server from public networks;
  • continuous installation of security updates for the servers, the databases and the application.

As we operate the server ourselves, we also provide for its physical protection directly:

  • the server operates in a locked room protected by access control, which only designated staff members may enter;
  • uninterruptible power supply and protection against fire and overheating;
  • the data content of storage media to be scrapped is irrecoverably destroyed before disposal.

On the organisational side, our staff members with access to personal data are bound by a duty of confidentiality, their access is limited to the extent necessary for their role, and it is withdrawn without delay upon termination of their employment.

6. Processors and third parties

For the delivery of notifications the application uses the following services:

Provider Service Data transferred
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its parent company, Google LLC Firebase Cloud Messaging – Android push notifications push token, content of the notification
Apple Distribution International Ltd. (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland) and its parent company, Apple Inc. Apple Push Notification Service – iOS push notifications push token, content of the notification

These providers receive only the technical identifier necessary for delivering the notification and the content of the notification; they have no access to account data or to the business databases.

The application contains no analytics or crash reporting component – we do not use Google Analytics for Firebase, Firebase Crashlytics or any similar user tracking solution. We do not share data for advertising purposes and we do not sell personal data to third parties.

6.1 Transfers to third countries

Owing to the infrastructure of the above providers, the processing of push tokens may take place in part outside the European Economic Area, in the United States of America. The safeguards for the transfer are:

  • the adequacy decision of the European Commission of 10 July 2023 on the EU–U.S. Data Privacy Framework, under which Google LLC and Apple Inc. are certified organisations;
  • additionally, the standard contractual clauses under European Commission Implementing Decision (EU) 2021/914, together with the supplementary technical and organisational measures undertaken in the providers’ data processing agreements.

A copy of the documentation on these safeguards may be requested through the contact details given in Section 13.

6.2 Other cases

Beyond the above, we disclose personal data solely on the basis of a legal obligation, at the request of a court or authority, to the extent specified therein. We examine all such requests and comply only with lawful requests limited to what is necessary.

7. Retention periods

Category of data Retention period Basis
Account data (username, password hash, permissions) Deleted within 30 days of the termination of the software licence or of the erasure request Purpose ceases to exist, Article 5(1)(e) GDPR
Push token Until the account is terminated, the application is uninstalled or notifications are switched off; tokens that have become invalid are deleted without delay Purpose ceases to exist
Camera image Not stored
Login, security and error logs 6 months; in the case of an ongoing breach investigation or legal dispute, until its final conclusion Legitimate interest, data minimisation
Audit log of business operations 5 years Section 6:22 of the Civil Code, accountability
Business data (project, order, contact person) 5 years from the termination of the contractual relationship Section 6:22 of the Civil Code
Accounting documents, invoices and the data supporting them 8 years Section 169(2) of Act C of 2000
Contact and support correspondence 5 years Section 6:22 of the Civil Code
Documentation of data subject requests and the responses given to them 5 years Article 5(2) GDPR – accountability
Register of personal data breaches 5 years Article 33(5) GDPR

Once the retention period has expired, we irrecoverably delete or permanently anonymise the data. Deletion from backups takes place when the backup cycle expires, but at the latest within 30 days of the erasure request; data still temporarily present in backups is not actively processed during this period.

8. Automated decision-making and profiling

The application does not carry out profiling and does not apply decision-making based solely on automated processing which would produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). The evaluation of the data displayed in the application and the taking of decisions always involve human intervention.

9. Account termination and erasure of data

The VWCloudMobil application cannot be licensed on its own: it may be used solely as an extension of the desktop software of Visual Window Kft., as part of the relevant software licence. A user account is therefore always linked to a valid software licence.

9.1 Automatic deletion upon termination of the licence

If the partner company terminates the software licence or it otherwise comes to an end, we terminate the associated user accounts automatically, without a separate request. In such a case the personal data belonging to the account is erased in accordance with Section 9.3, and you have nothing further to do.

9.2 Deletion upon request

While the licence is in force you may at any time request the termination of your own user account and the erasure of the personal data belonging to it:

Submitting a request requires neither logging in nor opening the application: the contact details above are available to anyone on this public page. As accounts are created on the basis of the partner company’s licence, deletion may also be initiated through the partner company’s administrator.

9.3 What we delete and when

We confirm receipt of the request and, following verification of your identity, we delete the following within 30 days at the latest:

  • the username and the password hash;
  • the permissions and profile data assigned to the account;
  • the push token identifier;
  • log entries linked to the account that are not subject to a statutory retention obligation.

Even after deletion we retain all data that we are required by law to retain (in particular accounting documents) and data necessary for the enforcement of legal claims – we continue to process such data solely for that purpose, for the period indicated in Section 7. Records in the business registers relating to the contractual activity of the partner company are not removed when the account is deleted, since they belong not to the user account but to the business documentation of the partner company.

Uninstalling the application from the device does not in itself terminate the user account – this requires the termination of the licence or a request under Section 9.2. Upon uninstallation, however, the push token becomes invalid and is deleted automatically from our system.

10. Handling of personal data breaches

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, the personal data processed.

In the event of a breach we follow the procedure below:

  • Reporting and recording: every detected or suspected breach is recorded without delay in the breach register.
  • Remediation: we immediately take the measures necessary to limit the damage and to restore the security of the affected systems.
  • Risk assessment: we assess the nature of the breach, the categories of data subjects and data affected, and the likely consequences.
  • Notification to the authority: we notify the Hungarian National Authority for Data Protection and Freedom of Information of the breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Article 33 GDPR).
  • Informing the data subjects: if the breach is likely to result in a high risk, we inform the data subjects without undue delay, in clear and plain language, of the nature of the breach, its likely consequences and the measures taken (Article 34 GDPR).
  • Documentation and review: we record the circumstances, effects and remedial measures of the breach, and review our security measures in the light of the lessons learned.

If you detect a personal data breach or a security weakness, please report it to support@visualwindow.hu.

11. Your rights

In connection with the processing you have the following rights:

  • Access (Article 15 GDPR): you may request information as to whether we process your personal data and, if so, request a copy of the data processed and of the circumstances of the processing.
  • Rectification (Article 16): you may request the correction of inaccurate data and the completion of incomplete data.
  • Erasure (Article 17): you may request the erasure of your data if it is no longer necessary to process it, if you have objected to the processing and there are no overriding legitimate grounds, or if the processing was unlawful.
  • Restriction of processing (Article 18): you may request the restriction of processing, for example where you contest the accuracy of the data, for the period needed to verify accuracy.
  • Data portability (Article 20): you may request the data you have provided and which is processed on the basis of the performance of a contract in a structured, commonly used, machine-readable format, or request its transmission to another controller.
  • Objection (Article 21): on grounds relating to your particular situation, you may object at any time to processing based on legitimate interest. In such a case we cease the processing, unless there are compelling legitimate grounds which override your interests, or the processing is necessary for the establishment, exercise or defence of legal claims.
  • Withdrawal of consent (Article 7(3)): where the processing is based on consent (for example device-level camera or notification permissions), you may withdraw it at any time, free of charge. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
  • Not to be subject to automated decision-making (Article 22): as set out in Section 8, we do not apply such decision-making.

11.1 Submitting requests and the deadline for our response

You may submit your request through any of the contact details given in Section 13, primarily at support@visualwindow.hu.

  • We respond to requests without undue delay and in any event within 1 month of receipt.
  • This deadline may be extended by a further 2 months taking into account the complexity or the number of the requests. We inform you of any extension and of the reasons for it within 1 month of receipt of the request.
  • Information and action are provided free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, we may charge a reasonable fee or refuse to act on the request; we always give reasons for any refusal.
  • Where we have reasonable doubts concerning the identity of the applicant, we may request further information necessary to confirm it.
  • If we do not take action on the request, we inform you of this – indicating the reasons for the refusal and the available remedies – within the 1-month deadline referred to above.
  • We provide our response in a form matching that in which the request was submitted, primarily by electronic means, unless you request otherwise.

12. Remedies

We ask that you first turn directly to us with any complaint – we aim to resolve any issues as quickly as possible. Irrespective of this, you have the following remedies available:

12.1 Complaint to the supervisory authority

In the event of an infringement of your rights, you may lodge a complaint with the Hungarian supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11., 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 1 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu

If your habitual residence or place of work is in another EU Member State, you may also lodge your complaint with the supervisory authority there (Article 77 GDPR).

12.2 Judicial remedy

Under Article 79 GDPR and Section 23 of the Hungarian Privacy Act you may also turn to the courts. At your choice, you may bring the action before the regional court competent for your domicile or place of residence; in the case of a domicile in Budapest this is the Budapest-Capital Regional Court (Markó u. 27., 1055 Budapest). The court hears the case out of turn. Information on the competence of the regional courts is available at birosag.hu.

12.3 Compensation and damages for non-material harm

If you have suffered damage as a result of the processing, or your personality rights have been infringed, you may claim compensation or damages for non-material harm under Article 82 GDPR and Section 2:52 of the Hungarian Civil Code.

13. Contact

Visual Window Kft.
Visual Window Support Hungary Korlátolt Felelősségű Társaság
Zirzen Janka u. 38., 1125 Budapest, Hungary
Phone: +36 30 310 5555
General e-mail: support@visualwindow.hu

14. Applicable legislation

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.)
  • Act V of 2013 on the Civil Code
  • Act C of 2000 on Accounting
  • Act CXXVII of 2007 on Value Added Tax
  • Act CVIII of 2001 on Electronic Commerce Services

15. Amendments to this policy

We review and update this policy from time to time. We inform users of any amendments through the application or on this page; in the case of material changes, also by direct notice a reasonable time before they take effect. The version in force at any given time is available on this page. Earlier versions may be requested through the contact details given in Section 13.

 
Hungarian Centrum

Visual Window Support Hungary Kft.
1125 Budapest, Zirzen Janka u. 38.
Tel: +36 30 310 5555 | Fax: +36 1 700 4550
Email:  

European Commercial Centrum

Visual Window Software Solutions s.r.o.
M.R. Štefánika 2/9, 945 01 Komárno

Email:  

Facebook Twitter Youtube RSS
Visual Window Design By Newconcept