1. General Provisions
Details and Contact Information of the Data Controller
- Name/Company Name
- Vipulse Technology Kft.
- Registered Office
- H-1054 Budapest, Szabadság tér 7., Bank Center, Gránit Tower, 1st floor
- Tax Number
- 32541661-2-13
- Company Registration Number
- 01-09-452175
- D-U-N-S
- 30-132-2002
- info@vipulsetech.com
The operator of the website www.vipulsetech.com, Vipulse Technology Kft. (H-1054 Budapest, Szabadság tér 7., Bank Center, Gránit Tower, 1st floor) (hereinafter: "Data Controller"), acknowledges the binding nature of this legal notice upon itself and undertakes to ensure that all related data processing activities comply with this Policy and applicable legislation in force.
2. Categories of Personal Data Processed, Purpose, Legal Basis and Duration of Data Processing
The Data Controller applies data processing principles in compliance with applicable data protection legislation, including in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation - GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
- Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.).
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.
2.1. Data of Visitors to the Website www.vipulsetech.com
- Purpose of data processing
- To monitor proper functioning of the service and prevent misuse during website visits.
- Legal basis of data processing
- Legitimate interest under Article 6(1)(f) GDPR and Section 13/A (3) of Act CVIII of 2001.
- Categories of personal data processed
- Date and time, IP address, visited page address, previously visited page address, and operating system/browser data.
- Duration of data processing
- 30 days from the date of visiting the website.
This section describes visitor request data used to operate the website. Optional analytics is separate and is described in the Cookie Policy.
2.2. Essential storage and optional analytics
The Cookie Policy is the authoritative description of browser storage on this website. Essential storage supports requested website functions. Optional analytics is used only after a valid current Accept all choice.
- Essential storage
- The versioned cookie-choice record, the 30-day chat identity cookie set after you start a chat, and the form rate-limit identifier in local storage. These are listed by name in the Cookie Policy.
- Optional analytics
- Google Analytics 4, Microsoft Clarity, and Vercel Web Analytics load and send requests only after Accept all. Rejecting non-essential cookies or accepting essential cookies only prevents this optional analytics.
- Legal basis of data processing
- Optional analytics is used only after Accept all. Essential storage is used to provide the requested website functions listed in the Cookie Policy.
Duration of data processing:
- Essential storage durations are listed in the Cookie Policy, including the 30-day chat identity cookie and the versioned consent record.
- Optional Google Analytics cookies are configured for a maximum of 13 months from when they are first set.
- Microsoft Clarity storage is set only after Accept all. First-party names include _clck and _clsk. Microsoft may also set third-party cookies such as CLID. Durations follow Microsoft's current documentation.
- Vercel Web Analytics does not set a cookie. After Accept all it sends a cookieless page-view request.
Names, purposes, withdrawal, and masking details are in the Cookie Policy.
2.3. Website Forms and Newsletter
When you submit a contact inquiry, career application, or newsletter subscription on www.vipulsetech.com, the Data Controller stores the submitted data in a secure PostgreSQL database and uses email delivery services to notify the relevant Vipulse team.
Career applications
- Purpose of data processing
- To evaluate employment applications and contact applicants regarding open roles at Vipulse.
- Legal basis of data processing
- Consent under Article 6(1)(a) GDPR and recruitment steps prior to entering into an employment contract under Article 6(1)(b) GDPR.
- Categories of personal data processed
- Full name, email address, phone number, languages spoken, education, experience, previous work experience, interests, and uploaded CV/resume file (PDF, DOC, or DOCX, up to 5 MB).
- Duration of data processing
- 12 months from submission unless the applicant is hired or a longer retention period is required by law.
Website chat conversations
- Purpose of data processing
- To identify the visitor, preserve the requested conversation across visits, respond to the inquiry, and deliver a closed-session transcript to the Vipulse sales team.
- Legal basis of data processing
- Consent under Article 6(1)(a) GDPR and steps prior to entering into a contract under Article 6(1)(b) GDPR.
- Categories of personal data processed
- First name, surname, company, phone number, email address, website language, message content, timestamps, browser identifier, IP address, user agent, and the generated PDF transcript.
- Duration of data processing
- The browser identity cookie expires after 30 days. Conversation records are retained for up to 24 months after closure unless an active business relationship or legal obligation requires longer retention.
Contact / quote inquiries
- Purpose of data processing
- To respond to business inquiries, quote requests, and general contact messages.
- Legal basis of data processing
- Consent under Article 6(1)(a) GDPR and steps prior to entering into a contract under Article 6(1)(b) GDPR.
- Categories of personal data processed
- Full name, company name, email address, phone number, inquiry topic, and message content.
- Duration of data processing
- 24 months from submission, unless a longer retention period is required by law or an active business relationship.
Newsletter subscriptions
- Purpose of data processing
- To send company news and updates to subscribers who opt in via the website footer.
- Legal basis of data processing
- Consent under Article 6(1)(a) GDPR.
- Categories of personal data processed
- Email address.
- Duration of data processing
- Until the subscriber asks Vipulse to stop by emailing info@vipulsetech.com.
These website features currently use Neon for database storage, Resend for transactional email, Vercel for website hosting, and Meta WhatsApp Cloud API for closed-session PDF delivery. Optional Google Analytics, Microsoft Clarity, and Vercel Web Analytics load only after Accept all. Google, Microsoft, Vercel, and Meta may process data outside the EEA. Questions about a specific transfer can be sent to info@vipulsetech.com.
2.4. Other Data Processing
Courts, public prosecutors, investigating authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, and other authorized bodies may contact the Data Controller for information, disclosure, transfer, or document availability where legally justified.
Personal data are disclosed only to the extent strictly necessary to achieve the request purpose, and only where the requesting authority specifies the exact purpose and scope of requested data.
3. Method of Storage of Personal Data and Security of Data Processing
Taking into account state of the art, implementation costs, and risk characteristics, the Data Controller and its processors implement technical and organizational safeguards appropriate to the level of risk.
Personal data are protected against unauthorized access, alteration, transmission, disclosure, deletion, destruction, accidental loss, damage, and inaccessibility from technology changes.
- Confidentiality: access is limited to authorized persons.
- Integrity: information accuracy and processing completeness are protected.
- Availability: authorized users can access required information and tools when needed.
4. Rights of the Data Subject and Legal Remedies
Data subjects may request information, rectification, erasure (unless mandatory processing applies), withdrawal of consent, restriction of processing, data portability, and may object to processing via the contact details above.
4.1. Right to Information
Articles 13, 14, 15-22, and 34 GDPR information is provided in concise, transparent, intelligible, and accessible language.
4.2. Right of Access
Data subjects can request confirmation, access, and a copy of processed personal data; reasonable fees may apply for additional copies.
4.3. Right to Rectification
Data subjects may request correction of inaccurate data and completion of incomplete data.
4.4. Right to Erasure
Data subjects may request erasure where Article 17 GDPR grounds apply, subject to legal exceptions.
4.5. Right to Restriction of Processing
Data subjects may request processing restriction under Article 18 GDPR conditions.
4.6. Right to Data Portability
Data subjects may receive provided personal data in a structured, commonly used, machine-readable format and transfer it.
4.7. Right to Object
Data subjects may object to processing based on legitimate interests/public authority, including direct marketing and profiling.
4.8. Automated Decision-Making, Including Profiling
Data subjects have rights under Article 22 GDPR regarding solely automated decision-making.
4.9. Right to Withdraw Consent
Consent can be withdrawn at any time without affecting prior lawful processing.
4.10. Procedural Rules
Requests under Articles 15-22 GDPR are handled without undue delay and within one month, extendable by two months when necessary.
Information is generally provided free of charge unless requests are manifestly unfounded or excessive.
5. Legal Remedies
5.1. Right to Judicial Remedy
In case of rights infringement, data subjects may initiate proceedings against the Data Controller before the competent court (registered office of defendant or domicile of data subject). Proceedings are expedited and exempt from fees in personal data protection cases.
5.2. Data Protection Authority Procedure
Complaints may be lodged with the National Authority for Data Protection and Freedom of Information:
- Name: National Authority for Data Protection and Freedom of Information
- Registered Office: 1055 Budapest, Falk Miksa utca 9-11.
- Postal Address: 1363 Budapest, P.O. Box 9.