Legal · Effective 28 August 2026 · Last updated 28 August 2026

Privacy Policy

How GG Client Portal handles personal data

This policy explains what we collect when you use GG Client Portal, why we collect it, how long we keep it and what you can ask us to do about it. It is written to be read, not to be survived. If anything here is unclear, ask us and we will explain it, and if the answer is that the policy is badly written, we will fix the policy.

1. Who we are

GG Client Portal is operated by Galcsik Győző Korlátolt Felelősségű Társaság ("we", "us"), a company registered in Hungary. We are the data controller for the personal data described below.

Detail

Value

Legal name

Galcsik Győző Korlátolt Felelősségű Társaság

Registered seat

1063 Budapest, Szív utca 16. I. em. 17. ajtó, Hungary

Company registration number

01-09-389812

Tax number

27431913-2-42

Represented by

Győző Galcsik, managing director

Email

gyozo@galcsik.hu

Phone

+36 20 254 6481

We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Privacy questions go to the email address above and are handled by the managing director.

2. Two different roles: controller and processor

This distinction decides who you exercise your rights against, so it comes before everything else.

We are the controller for almost everything in the portal. That covers the data about the people who hold accounts (your name, email address, credentials, preferences and how you use the portal), and it covers our own records of the work we do for your organisation: projects, tracked hours, invoices, prepaid budgets, the billing details we invoice to, and the activity log. Those records exist because we did the work and invoiced it, and we keep them as our own business and accounting records. This policy governs all of that.

We are a processor for one thing only: personal data about other people that your organisation puts into the portal. If a ticket, a comment or an attachment names your customers or staff, your organisation is the controller for that data. We process it only on your organisation's instructions, under the terms of "Processing on your behalf" below and our Terms of Service.

Our own staff, who administer the portal, can see every team. That is not a separate role in the data-protection sense: the portal is our record of the work we do for you, and we are the ones doing it.

If you are an employee or client of an organisation that uses the portal and you want content it uploaded removed, ask that organisation; they decide what happens to it. We will help them act, but we will not overrule them on their own data.

3. What we collect, and why

Category

Purpose

Legal basis

Retention

Account data: name, email address, hashed password, optional profile photo, roles and capabilities, notification preferences, preferred language, invitation status and who invited you, and your sign-in sessions

Creating and running your account; authenticating you

Performance of a contract (Art. 6(1)(b))

For as long as we work with your organisation, then deleted within 12 months of the end of that relationship, or earlier on request. Sessions expire after 24 hours

Sign-in with Google or Microsoft: the stable account identifier that provider issues for you, and your name if your account had none. Signing in this way also tells Google or Microsoft that you use the portal; they handle that under their own privacy policy, as an independent controller

Signing you in without a password

Performance of a contract (Art. 6(1)(b))

Until you disconnect the provider, or the account is deleted

Team data: team name, who belongs to it and in which role, and your organisation's billing details (billing email, billing address, tax number, currency, payment terms), entered by us or by your team

Running the team; issuing invoices to the right entity

Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for the billing details

Billing details 8 years, as Hungarian accounting law requires; the rest with the account

Work records: projects and their progress, tracked hours and what they were spent on, invoices we issued (as PDFs), prepaid budgets and their drawdown

Showing you the work we do for you and what it costs; our own record of that work

Performance of the service contract with your organisation (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for hours, invoices and budgets, which are our accounting records

8 years, as Hungarian accounting law requires

Tickets and comments: what you write, who wrote it, when, and the files you attach

Asking for and delivering the work; the support record for each project

Performance of a contract (Art. 6(1)(b)). For personal data about other people inside them: processed for your organisation, see "Two different roles"

For the life of the project relationship, then deleted within 12 months

Notifications: the ticket titles, hours, names and invoice details each one mentions

Telling you what changed

Performance of a contract (Art. 6(1)(b))

With the account

Activity log: every create, update and delete in the portal and every login, with the acting user, a one-line summary and a before/after snapshot of the record

An audit trail of who changed what; security

Legitimate interest (Art. 6(1)(f)) in an accurate record of the work and in keeping the portal secure

For the life of the project relationship, then deleted within 12 months

API keys: the keys that let a script or AI tool you connect reach your data over MCP

Programmatic access you have explicitly enabled

Performance of a contract (Art. 6(1)(b))

Until you revoke the key

Technical logs kept by our hosting provider: IP address, browser user agent, request time, path, response status, error traces. The portal itself records none of these

Security, abuse prevention, diagnosing faults

Legitimate interest (Art. 6(1)(f)) in keeping the portal secure

Up to 30 days

The activity log is visible to our own administrators only, as a timeline per team. No IP address and no browser identifier is stored anywhere in the portal; the only place they exist is the hosting provider's request log in the last row.

One category does not come from you. When we, or a team owner in your organisation, invite you to the portal, we receive your email address before you have any relationship with us. We use it only to deliver and manage that invitation, on the basis of our legitimate interest in letting the people we work with bring in their colleagues (Art. 6(1)(f)). An invitation link is valid for 7 days; one that is never accepted expires, and we delete the record within 30 days after that. This paragraph is the notice Article 14 GDPR requires, and writing to us at the address in "Contact" will stop it.

Tickets and attachments can contain other people's personal data. If you paste customer records, names or email addresses into a ticket, or attach a file that holds them, that personal data is stored in the portal and travels in the notification emails about that ticket. Your organisation is the controller for it and is responsible for having a lawful basis to put it there. Please do not upload more than the work needs.

4. What we do not do

We think this is worth stating plainly, because it is unusual enough to be a feature:

  • No third-party analytics. There is no Google Analytics, no Plausible, no PostHog, no Mixpanel, no Segment, no Hotjar.
  • No advertising or marketing trackers, and no advertising cookies.
  • No third-party error-reporting or session-replay service.
  • No profiling, and no automated decision-making that produces legal effects under Article 22 GDPR.
  • We do not sell personal data, and we do not share it for anyone else's marketing.
  • We do not use your content to train machine-learning models.

5. Cookies and browser storage

We set only what the portal needs to work: cookies that are strictly necessary, and storage that remembers preferences you set yourself. We run no analytics, tracking or advertising cookies at all. That is why there is no cookie banner: nothing here needs your consent, and the team and language entries are written only when you yourself switch; the theme entry records your current choice, 'automatic' until you change it.

Name

Type

Purpose

Lifetime

payload-token

Cookie (HttpOnly, SameSite=Lax)

Keeps you signed in

24 hours

portal-current-team

Cookie

Remembers which team you were last working in

1 year

portal-locale

Cookie

Remembers the language you chose, when you switch away from the one your domain implies

1 year; set only when you switch language

portal-oauth

Cookie (HttpOnly, SameSite=Lax, Secure)

Holds the single-use state for a Google or Microsoft sign-in while you are away at the provider

10 minutes, and cleared the moment you come back

payload-theme

Cookie

Remembers light, dark or automatic theme for signed-in users (also read by the admin panel)

1 year

theme-preference

localStorage

Remembers light, dark or automatic theme in the portal

Until cleared

6. Sub-processors

We use a small number of providers to run the service. Each is bound by a data processing agreement under Article 28 GDPR. This list is current as of the date at the top of this page.

Provider

Role

Location

Data reached

Railway Corp. (USA)

Application hosting and managed PostgreSQL database

Servers in the European Union (Netherlands); the provider is US-established, so transfers rely on the Standard Contractual Clauses in Railway's data processing agreement

All portal data

Cloudflare, Inc. (USA)

File storage (R2) and DNS for the portal hostnames

Files stored in Western Europe; EU-US Data Privacy Framework and Standard Contractual Clauses

Uploaded files: profile photos, ticket and comment attachments, invoice PDFs. The portal hostnames point straight at our hosting provider, so no page traffic passes through Cloudflare

Resend (Plus Five Five, Inc., USA)

Sending notification emails

United States; certified under the EU-US Data Privacy Framework, with Standard Contractual Clauses in its data processing agreement

Recipient name and email address, and the content of each notification: ticket and comment text, hours, invoice details and the names of attached files

Every provider in this table is used for every account. We will tell customers before we add or replace one, so that there is time to object.

If you object on reasonable data-protection grounds and we cannot offer you an alternative, you may stop using the portal and ask us to close your account. What that means for the work itself is a matter for your service contract with us.

Google, Microsoft and the tools you connect are not our sub-processors. When you sign in with Google or Microsoft, that provider processes the sign-in as an independent controller under its own privacy policy; we receive only the result. When you create an API key and give it to a script or AI tool, that tool reads your data at your direction, under your own agreement with its provider. We have no contract with it, and you are responsible for the lawfulness of that onward transfer. No key exists unless you create one.

7. International transfers

Your portal data is stored on servers in the European Union. That is not the whole picture, though: every provider in the table above is established in the United States, and access from there counts as a transfer even when the servers are in the EU. Those transfers rely on the European Commission's Standard Contractual Clauses, and additionally on the EU-US Data Privacy Framework where the provider is certified under it, together with the supplementary measures the Clauses require. Write to us and we will send you a copy of the clauses that apply.

8. How we protect data

  • All traffic is served over HTTPS.
  • Passwords are stored only as salted hashes. API keys are stored encrypted and the portal shows a key only once, at creation.
  • The portal is multi-tenant by team: every read and write is scoped to the teams you belong to, enforced in the data access layer rather than only in the interface.
  • Repeated failed sign-in attempts temporarily lock the account.
  • Access to production systems is limited to the managing director.
  • Endpoints that fetch a URL on your behalf are guarded against requests to internal and private network addresses.

No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected customers without undue delay.

9. Keeping and deleting data

Retention periods for each category are in the table in "What we collect, and why". There is no self-service deletion or export in the portal; both happen on request, by email to the address in "Contact". In addition:

  • Your account, and the tickets, comments, attachments and activity log of your projects, are kept for as long as we work with your organisation and deleted within 12 months after that relationship ends. Ask, and we delete them sooner.
  • Tracked hours, invoices, prepaid budgets and billing details are our accounting records. We keep them for 8 years, as Hungarian accounting law requires, even after everything else is gone.
  • An invitation that is never accepted expires after 7 days, and we delete the record within 30 days after expiry.
  • The request logs at our hosting provider are kept for up to 30 days.
  • You can ask for a copy of your data at any time, including after your account closes, for as long as we still hold it. We provide it as JSON and PDF within one month.

10. Your rights

Under the GDPR you have the right to:

  • Access your personal data and obtain a copy (Art. 15).
  • Have inaccurate data corrected (Art. 16).
  • Have your data erased (Art. 17).
  • Restrict how we process it (Art. 18).
  • Receive it in a portable, machine-readable form (Art. 20).
  • Object to processing based on our legitimate interests (Art. 21).
  • Withdraw consent at any time, where we relied on consent, without affecting processing already carried out.

To exercise any of these, write to gyozo@galcsik.hu. We answer within one month. If a request is complex, or you make several, we may extend that by up to two further months; we will tell you within the first month if we need to, and why. Where we act as a processor rather than a controller, we will pass your request to the organisation that controls the data and support them in answering it.

You may also complain to the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., Hungary, ugyfelszolgalat@naih.hu, naih.hu. If you live in another EU country you may complain to your local authority instead.

Independently of any complaint to an authority, you may take the matter to court. In Hungary that is the county court (törvényszék), and you may choose the court for your own domicile or residence rather than ours.

11. Processing on your behalf (Article 28)

Where we act as your processor, the following terms apply, and together with our Terms of Service they form the data processing agreement between us. We will also sign a separate DPA on request.

These processor terms are not ours to rewrite at will. They may only be changed through the amendment procedure in our Terms of Service: 30 days' notice, with the right to terminate if you do not accept the change.

  • Subject matter and duration: providing the portal to your organisation, for as long as it uses it.
  • Nature and purpose: storing and displaying the tickets, comments and attachments your organisation's team creates.
  • Categories of data subject: your staff, your own clients, and any individuals whose personal data appears in what you write or attach.
  • We process personal data only on your documented instructions, which your use of the service constitutes, unless Union or Member State law requires otherwise, in which case we tell you before processing, where that law allows us to.
  • We tell you without delay if, in our view, an instruction of yours infringes the GDPR or other data protection law.
  • Everyone with access is bound by confidentiality.
  • We apply the technical and organisational measures in "How we protect data", as Article 32 requires.
  • We engage only the sub-processors listed in "Sub-processors", and will give notice before changing them.
  • We assist you with data subject requests, breach notification, and impact assessments, as far as the nature of the processing allows.
  • We notify you of a personal data breach without undue delay and at the latest within 72 hours of becoming aware of it.
  • On termination we delete or return that data at your choice, within the periods in "Keeping and deleting data".
  • We make available the information needed to demonstrate compliance and allow for audits.

12. Children

The portal is a tool for the businesses we work with and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to us and we will delete it.

13. Changes to this policy

We may update this policy. If a change materially affects your rights we will tell account holders by email at least 30 days before it takes effect. The date at the top of the page always reflects the current version.

14. Contact

Questions about this policy or about your data: gyozo@galcsik.hu, or write to Galcsik Győző Korlátolt Felelősségű Társaság, 1063 Budapest, Szív utca 16. I. em. 17. ajtó, Hungary.