Effective from: 2025.05.21
PostInsight (hereinafter: Data Controller), as the operator of the online service available at https://postinsight.ai, powered by artificial intelligence to analyze social media posts and provide content suggestions (hereinafter: Service), hereby publishes information on its data processing activities related to the Service.Visitors to the Website and registered users (hereinafter: User), by using the Service, accept the conditions set forth in this Privacy Policy (hereinafter: Policy); therefore, please read this document carefully before providing any data.Scope of processed data:
Purpose of data processing:
The data provided during registration and credit purchase is processed for the purposes of contract formation, performance, invoicing, customer relationship management, and traceability. The system uses Facebook login, during which the Data Controller does not store passwords.Duration of data processing:
Legal basis of data processing:
Important note:
The Data Controller does not have access to the credit card data provided during credit purchases. These are handled by Stripe Payments Europe, Ltd. according to its own privacy policy:https://stripe.com/en-hu/privacyScope of processed data:
Purpose of data processing:
Operating the user account, traceability of requests, transaction tracking, and system usage support.
Legal basis: GDPR Article 6(1)(b) – performance of a contract
Scope of processed data:
Legal basis: GDPR Article 6(1)(f) – legitimate interest of the Data Controller (based on a balancing of interests)
Right to object: The User may object to the data processing at any time and request the deletion of such data.
Processed data:
Purpose:
Sending marketing information (new features, promotions, news).
Legal basis: GDPR Article 6(1)(a) – voluntary consent
Unsubscription:
Can be done at any time free of charge via the link in the newsletter or by email.
Processed data:
Legal basis: Fgytv. § 17/B – legal obligation
Retention period: 3 years
Personal data may be accessed by the Data Controller operating the PostInsight service and by the data processors it commissions to carry out certain technical operations, in accordance with applicable laws, especially the provisions of the GDPR.
Organizations involved in data processing:
The Data Controller reserves the right to involve additional data processors in the future for the technical or administrative operation of the Service. Users will be notified of such changes via an update to this Policy.
The Data Controller transfers personal data only:
Users are entitled to the following rights in relation to the processing of their personal data, which they may exercise via the contact information provided in section 1.
The User has the right to request confirmation as to whether the Data Controller is processing their personal data and, if so, to access the following information:
The Data Controller shall provide the information within 1 month of receiving the request, extendable by 2 months if necessary. The first copy is free; further copies may incur a reasonable administrative fee.
The User may request the correction, update, or completion of inaccurate, outdated, or incomplete personal data. The Data Controller shall act without undue delay.
The User may request the deletion of their personal data if:
Deletion is not required if the processing:
The User may request a restriction of processing if:
Restricted data may only be processed with the User’s consent, or for legal claims or the protection of another person’s rights.
The User may request that the Data Controller transfer their personal data, stored in a commonly used, machine-readable format, to themselves or another controller. The data will be delivered in CSV and/or PDF format upon request.
The User has the right to object at any time to the processing of their personal data based on:
In the event of an objection, the Data Controller shall no longer process the data unless it can demonstrate compelling legitimate grounds or it is necessary for legal claims.
The Data Controller shall inform all recipients of any rectification, erasure, or restriction of data processing, unless this proves impossible or involves disproportionate effort. Upon request, the User shall be informed about such recipients.
The Data Controller shall respond without undue delay, and at the latest within 1 month. This period may be extended by another 2 months if necessary.
The first response is free of charge, but a reasonable administrative fee may be charged or the request may be rejected if it is unfounded, excessive, or repetitive.
The Data Controller is committed to ensuring the security of personal data and implements all reasonable technical, organizational, and administrative measures to protect the data. In particular, the Data Controller strives to:
Data processors used by the Data Controller may access personal data only to the extent necessary to perform their tasks.
The User acknowledges that data transmission over the internet cannot be completely secure, but the Data Controller takes all reasonable measures to ensure maximum protection.
The Data Controller does not collect sensitive data, particularly regarding racial or ethnic origin, political opinions, religious or philosophical beliefs, health status, sexual orientation, or criminal record.
Data protection incident: any event resulting in the unlawful processing, alteration, deletion, unauthorized access, or loss of personal data.
The Data Controller must:
The report must include:
Incident log: The Data Controller shall record the incident and retain the log for 5 years. The log shall include:
The User may contact the Data Controller directly using the contact details in section 1 for any questions or complaints regarding data processing.
If the User believes their rights have been violated, they have the following legal remedies:
National Authority for Data Protection and Freedom of Information (NAIH)
Cookie categories and their legal basis are as follows:
Cookie Type | Legal Basis | Purpose |
---|---|---|
Necessary cookies | GDPR Article 6(1)(f) – legitimate interest | Ensuring the basic functions of the website (e.g., login, navigation, security). |
Statistical cookies | GDPR Article 6(1)(a) – consent | Collecting anonymized statistics on user behavior for website development. |
Marketing cookies | GDPR Article 6(1)(a) – consent | Displaying personalized ads, remarketing. |
These cookies are essential for the operation of the website and cannot be disabled.
Name | Purpose | Expiry |
---|---|---|
cc_consent | Storing cookie consent level | 365 days |
locale, jwt, tenant, role, uid, fname, nname, avatar, thread | User session and preference management | 365 days |
Name | Provider | Purpose | Expiry |
---|---|---|---|
_ga, _ga_* | Google Analytics | Tracking visitor behavior | 2 years |
_gid | Google Analytics | Session-level statistics | 24 hours |
_gat | Google Analytics | Throttle request rate | 1 minute |
More information about Google Analytics data processing: Google Analytics privacy page.
Name | Provider | Purpose | Expiry |
---|---|---|---|
NID, __gads, FPAU etc. | Google Ads | Displaying personalized advertisements | 6–540 days |
fbc, _fbp, datr etc. | Storing user identifiers for targeted ads | Session – 2 years |
Advertising preferences can be changed on the Google and Facebook platforms:
The website uses technologies from external advertising and analytics providers (e.g., Google, Facebook). These providers may place their own cookies on your device, which are subject to their own privacy policies. The Operator is not responsible for the data processing resulting from these.
Users can individually configure the acceptance or blocking of cookies in most browsers. Useful links for various browsers:
For matters not regulated in this Privacy Policy, the applicable Hungarian legislation shall prevail, in particular:
shall apply.
Effective date of the Policy: May 21, 2025.
Location: Budapest