PRIVACY POLICY
regarding the data processing in connection to the Selfmadeup service
The provider of the Selfmadeup service, SasWare Kft. (registered office: 8449 Magyarpolány, Bakony utca 23., Hungary, company registration number: 19-09-524766, tax ID number: 32674565-2-19, hereafter referred to as: Service Provider) hereby informs Users regarding the data processing conducted in relation to Selfmadeup service, its website and to the activities conducted by the Service Provider pursuant to the regulations of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereafter as: GDPR), and with Act CXII of 2011 on the right to information self-determination and the freedom on information (hereinafter as: Infotv.)
The present Privacy Policy pertains to the processing of personal data provided by the User to the Service Provider, moreover to any personal data that may be received by the Service Provider via their online platforms or by way of “cookies”.
Terms and definitions
For the purposes of the present Notice, the terms below shall mean the following:
- Personal data: any information relating to an identified or identifiable natural person (hereinafter referred to as: data subject); an identifiable person meaning one who can be identified directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person;
- Data processing: any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Data controller: the natural or legal person, government body, agency or any other organisation, which determines the purposes and means of the data processing either solely or jointly with others; if the purposes and means of the data processing is regulated by EU or state laws, such EU or state laws may set out the data processor to be appointed, or may set out the specific aspects per which the data processor is to be appointed;
- Data processor: the natural or legal person, government body, agency or any other organisation, which processes personal data on behalf of the data controller;
- Data erasure: the complete physical destruction of the media containing the data;
- Data forwarding: the making available of the data to a given third party;
- Data deletion: rendering the data incomprehensible in a way that allows for no reinstation thereof;
- User: the person visiting, browsing the Website and using the services thereon (Data subject);
- Website: the online portal operated by the Service Provider (https://selfmadeup.com/).
General provisions
The Website and the websites connected thereto may be accessed by anyone – without having to hand over their personal data – and may freely gain information thereon without restriction. Users may receive information regarding the activities of the Service Provider on the Website.
Users may opt to register in order to utilise the Selfmadeup service by filling out the applicable form and by sending it to Service Provider. By sending the completed application form to Service Provider, Users express their freely given consent to the data processing described in the present privacy policy, which is necessary for the ensuring of the provision of the Selfmadeup service.
Users are solely liable for the data handed over by them and the contents they upload, for which Service Provider expressly denies any liability.
Service Provider is entitled to amend the present privacy policy unilaterally, at any time. Service Provider issues the amendments of the present privacy policy by publishing them on the Website, in a separate menu item. Users are kindly requested to carefully consult the privacy policy upon any visit to the Website.
The present privacy policy is continuously available on the Website. Users may open, view, print or save the present privacy policy, but may not amend or alter it, this is the sole prerogative of the Service Provider.
- Categories of personal data processed by Service Provider, the purpose, legal basis, mode and timeframe of processing
The legal bases for data processing are the following:
a) GDPR Article 6 (1) a), where the processing is based on the informed consent of the data subject (hereafter referred to as: Consent);
b) GDPR Article 6 (1) b), where processing is necessary for the performance of a contract to which the data subject is party (hereafter referred to as: Conclusion of Contract)
c) GDPR Article 6 (1) c) where data processing is necessary for the fulfilment of or compliance with a legal obligation of the data controller (e.g. obligations with tax statues – hereafter referred to as: Compliance)
d) GDPR Article 6 (1) d), where processing is necessary in order to protect the vital interests of the data subject or of another natural person (hereafter referred to as: Vital Interest);
e) GDPR Article 6 (1) e), where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller (hereafter referred to as: Public Interest);
f) GDPR Article 6 (1) f) where data processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, (hereinafter referred to as: Lawful Interest)
Data processing in connection to the Website
Data collected automatically regarding the Website
| Data subject | Data category | Data source | Purpose of data processing | Legal basis of data processing | Timeframe of processing, time of deletion |
|---|---|---|---|---|---|
| User visiting the Website | Country, type and version number of browser, device and operating system used, language settings | Data subject (User) | Statistical analysis, development of Website | GDPR Article 6 (1) f), necessary for the purposes of the legitimate interests pursued by the controller | 2 years from time of visit |
| Statistical data regarding Website visits | Data subject (User) | Statistical analysis, development of Website | GDPR Article 6 (1) f), necessary for the purposes of the legitimate interests pursued by the controller | 2 years from time of visit |
Service Provider uses cookies and other various programs in order to ascertain the Website’s Users’ preferences regarding the Website, and to develop the Website based thereon. Service Provider creates anonymous statistics of the Website visits.
The above data processing is the lawful business interest of the Service Provider since this serves to enable the Service Provider to improve the Website and to make it more secure. The scope of the collected data is not significant, these are only collected and processed by the Service Provider, with Service Provider collecting no behavioural preferences, and conducting no automated decision making based thereon, with no personalised offer being sent by the Service Provider to Users based thereon. Concordantly, this data processing does not affect User’s fundamental rights and freedoms adversely.
Cookies and the measurement of visits
[PROPOSAL] — this section was drafted in 2026 and was not written by a lawyer.
The Service Provider uses cookies that are strictly necessary for the operation of the Website without the User's consent (e.g. maintaining the logged-in session, security cookies). Without these the Website cannot be used.
The Website also uses Google Analytics to measure visits. This measurement is started only with the prior consent of the User: in the absence of consent the data storage of Google Analytics remains disabled, and the Service Provider processes the User's IP address in anonymised form.
The User may give their consent in the cookie notice bar displayed on the Website, and may withdraw it at any time in the same place. Refusing or withdrawing consent does not restrict the use of the Website.
The Service Provider does not carry out advertising-related data processing. Advertising storage (ad_storage), advertising user data (ad_user_data) and advertising personalisation (ad_personalization) are therefore permanently denied: there is no user choice that would enable them.
Consent may be withdrawn via the "Cookie settings" link in the footer of any page of the Website; measurement stops immediately upon withdrawal.
Data processing in connection the registering for the Selfmadeup service
Users may register by fulfilling the form provided on the Website with the personal data specified below. Provision of data is of the Users’ own volition, given by consent, and is necessary for the appropriate and high-quality provision of the contract between Service Provider and User regarding the program.
| Data subject | Data category | Data source | Purpose of data processing | Legal basis of data processing | Timeframe of processing, time of deletion |
|---|---|---|---|---|---|
| User registering for Selfmadeup | Name | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 5 years from the conclusion of the contract |
| E-mail address | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract | |
| Address | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract | |
| Username | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract | |
| Billing information | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 5 years from the conclusion of the contract | |
| Contact person for legal entity registering for Selfmadeup | Name | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract |
| E-mail address | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract | |
| Username | Data subject (User) | Performance of contract Contact keeping Identification of user | GDPR Article 6 (1) b), necessary for the performance of a contract to which the data subject is party | 6 months from the conclusion of the contract |
Data uploaded by Users into Selfmadeup
Service Provider informs Users that regarding the data uploaded by the Users into Selfmadeup during the use thereof, Service Provider shall be deemed as a data process, while Users – regarding the data uploaded by them into the storage provided to them – will be deemed as data controllers, due to the base criteria of the data processing being decided by the User, and not Service Provider, and due to Service Provider not being entitled to delete data uploaded by ths Users, with Users solely bein entitled thereto, and due to Service Provider only being authorised to process said data per the instructions of User, and Service Provider may not dispose of them by their own accord.
Service Provider:
- processes the personal data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by Union or Member State law to which the processor is subject;
- ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- takes all measures required pursuant to GDPR Article 32;
- taking into account the nature of the processing, assists the controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the controller's obligation to respond to requests for exercising the data subject's rights laid down in GDPR Chapter III;
- assists the controller in ensuring compliance with the obligations pursuant to GDPR Articles 32 to 36 taking into account the nature of processing and the information available to the processor;
- at the choice of the controller, deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data;
- makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
Services using artificial intelligence
[PROPOSAL] — this section was drafted in 2026 and was not written by a lawyer. It may not go live without legal approval.
In certain features of Selfmadeup the Service Provider uses a language model based on artificial intelligence (hereinafter: AI). The User is informed in every case that they are interacting with an AI — this is required by Article 50 of Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (hereinafter: AI Act).
Features using AI:
| Feature | What it does | What it processes |
|---|---|---|
| Digitalisation survey | Maps the User's business process in the form of a conversation and produces an operational model, form and document draft from it | The text provided by the User in the conversation |
| Assistant | Answers the User's questions regarding the use of the system and prepares operations at the User's request | The User's question and the system data required for the operation |
The conversation may contain personal data. While describing their process, the User may name colleagues, clients or partners. The Service Provider asks the User to provide only as much personal data as is strictly necessary to understand the process, and where possible to use a role (e.g. "technician", "client") instead of a name.
| Data subject | Categories of processed data | Purpose of data processing | Legal basis of data processing | Duration of data storage |
|---|---|---|---|---|
| User using the AI feature | The content of the conversation (the text provided by the User and the AI's response) | Provision of the service: producing the operational model, form and document; making the conversation resumable | GDPR Article 6(1)(b): necessary for the performance of a contract. In the case of a User who is not logged in, steps taken prior to entering into a contract pursuant to GDPR Article 6(1)(b) | For a logged-in User, for the lifetime of the user account (the conversation is deleted together with the account). For a User who is not logged in, the text of the conversation is stored solely in the User's own browser and is not transferred to the Service Provider's server; only technical data related to the conversation (identifier, timestamp, AI capacity used) remains on the server, which the Service Provider deletes automatically after a maximum of 30 days from the start of the conversation |
| User using the AI feature | The content of the conversation in anonymised form | Development of the service and preparation of industry process templates | GDPR Article 6(1)(a): the express, separately given consent of the User. This consent is not a condition of using the service and may be withdrawn at any time | Until the withdrawal of the consent; the anonymised pattern containing no personal data may be used thereafter as well |
Undertakings of the Service Provider in relation to AI
- The Service Provider does not use the User's data for the training, fine-tuning or reinforcement learning of any language model, and requires the same from the AI sub-processor engaged by it.
- The Service Provider contracts with the AI sub-processor on terms under which the sub-processor does not store the content of the conversation beyond the time necessary for processing.
- The text of the conversation is not transferred for the development purpose set out in the second table. Only the structural data produced from the conversation (the steps of the process, the types of roles, the field types) may be used — free text in which personal data may occur may not. A template is never built from the data of a single identifiable User or client, only from patterns aggregated from several sources.
- The Service Provider logs the fact of the granting and the withdrawal of the consent, together with its time and the text displayed to the User.
Limitations of AI
The content produced by the AI may be incorrect or incomplete. The Service Provider asks the User to verify the operational model, form and document proposed by the AI before use. The Service Provider assumes no liability for the correctness of the content produced by the AI.
The AI does not take decisions producing legal effects concerning the User or similarly significantly affecting them based solely on automated processing within the meaning of GDPR Article 22: the AI produces a proposal which the User accepts or rejects.
Data controller and data processors
Regarding the data specified under point III. 1-2., the data controller is the Service Provider:
SasWare Kft.
Registered seat: 8449 Magyarpolány, Bakony utca 23.
Registrar: Court of Registration of the Veszprém Tribunal
Company reg. no.: 19-09-524766
Tax ID no.: 32674565-2-19
E-mail address: saswarekft@gmail.com
On behalf of the Service Provider, the data of the User may be accessed by the employees of service provider to the extent that is necessary for the carrying out of their tasks. Access rights to personal data are regulated in a strict internal policy.
Data processors
Service Provider engages various enterprises for the processing and storing of User’s data, with whom Service Provider concludes data processing agreements. The following data processors conduct data processing regarding the User’s data:
[PROPOSAL] — the table below was drafted in 2026 and was not written by a lawyer. The registered offices of the data processors and the data processing agreements concluded with them must be verified against the actual contracts.
| Name and address of data processor | Purpose of data processing | Categories of processed data |
|---|---|---|
| Microsoft Ireland Operations Limited (One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland) | Hosting and database services: operating the Service, storing Users' data and uploaded files, search service | All data listed in the present Privacy Policy |
| Microsoft Ireland Operations Limited (Azure OpenAI Service) | Operating the features using artificial intelligence (see the section "Services using artificial intelligence") | The text provided by the User in the conversation |
| Brevo SAS (106 boulevard Haussmann, 75008 Paris, France) | Sending system messages and notification e-mails (e.g. registration confirmation, password reset, invitation) | Name, e-mail address, content of the message |
| Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) | Preparing visitor statistics for the development of the Website (Google Analytics) — only with the User's consent | Anonymised IP address, browser and device data, visit events on the Website |
Data forwarding
The Service Provider is entitled and obligated to hand over personal data in their possession and lawful storage to the competent authorities where they are compelled to by applicable law or a final authority decision. For any such data forwarding, and for any consequences thereto, the Service Provider may not be held liable. No other data forwarding is conducted by the Service Provider
Data transfer to a third country
[PROPOSAL] — this section was drafted in 2026 and was not written by a lawyer.
The Service Provider stores and processes the Users' data in the Microsoft Azure cloud service. The vast majority of the processing takes place within the territory of the European Union: the operation of the Service, the storage of uploaded files, the search service and the features using artificial intelligence all run in EU data centres (West and North Europe).
Exception: the database containing the Users' data currently runs within the territory of the United States of America (Azure "South Central US" region). To that extent the User's data is transferred outside the European Union.
The legal basis of the data transfer is the adequacy decision of the European Commission (EU–US Data Privacy Framework), provided that the data processor is certified under that framework; in the absence thereof, the standard contractual clauses (SCC) adopted by the European Commission, together with the necessary supplementary safeguards.
⚠️ To be clarified before go-live / for the lawyer:
1. Verified (Azure Resource Manager API, 2026-08-06): of the entire resource set, only the SQL server runs outside the EU (southcentralus). Azure OpenAI (westeurope), Blob Storage and AI Search (northeurope), and the App Services (westeurope) are all in the EU.
2. Moving the database to an EU region is in progress (SMU-793). If this happens before go-live, this section can be omitted and the notice can state that processing takes place exclusively within the EU.
3. The transfer mechanism under the contract with Microsoft must be clarified for as long as the database remains in the US.
Automated decision-making, profiling
Service Provider does not conduct automated decision-making or profiling regarding the data processed per the present Privacy Policy.
The features using artificial intelligence produce a proposal for the User (operational model, form, document draft), which the User accepts or rejects. This does not qualify as a decision based solely on automated processing within the meaning of GDPR Article 22.
Data privacy directives observed by Service Provider
The Service Provider respects the legally protected rights of their Users and of those who visit the online interfaces operated by them.
The personal data that is directly necessary for the usage of the services of the Service Provider is processed by the Service Provider per the consent of the data subjects, and strictly for the purposes pertaining thereto. The Service Provider uses the personal data of the Users specified under point III hereto only per the means and purposes set out in the present Privacy Policy.
The Service Provider as data controller undertakes to process the data in their possession per the provisions of the GDPR, of the Infotv. and other relevant legal regulations, and the regulations of the present Privacy Policy, and to refrain from making them available to any third parties not including those specified in the present Privacy Policy. The use of statistical compilations of data that do not contain the names or identifying data of Users in any way serve as an exception to the present point, as these do not constitute data processing, nor data forwarding.
The Service Provider shall, in certain situations – e.g. official court or police inquiries, legal procedures regarding copyright, property or other disputes or the suspicion thereof concerning infringements upon the lawful interest of the Service Provider, the endangerment of their provision of services, as well as per court or authority warrants –, as well as based on the User’s prior express consent, make User’s data available to third parties.
The Service Provider shall make every reasonable effort to ensure that the processing and management of the Users’ data is given the protection set out by applicable law.
Protection of personal data
The Service Provider complies with their obligations deriving from the applicable privacy regulations by:
- safely storing and deleting them;
- not collecting or storing excess amounts of data;
- protecting personal data from loss, violation, unauthorised access or publication, as well as ensuring that adequate technical measures are in place, protecting personal data.
The Service Provider carries out adequate technical and organisational measures in order to protect the Users’ personal data from accidental or unlawful destruction, loss or modification, as well as unlawful communication or access – especially where network communication thereof is a part of the processing –, and to protect data form any unlawful form of processing.
Accordingly, the Service Provider emplaces various levels of access rights over the data, which ensures that the data are only accessed by persons having adequate clearance, who are required to access the data in order to carry out their job or to fulfil their related obligations.
Rights of the User
Pursuant to the data protection legislation in place, the data subject is entitled to:
- request access to their personal data,
- request corrections regarding their personal data,
- request deletion of their personal data,
- request the restriction of their personal data,
- object to the processing of their personal data,
- request the porting of their personal data,
revoke their consent regarding data processing
- file a complaint regarding any grievances.
a) Right of access
The data subject is entitled to receive feedback from the data controller on whether their personal data is being processed or not, and if so, to request access to their personal data.
The data subject is entitled to request copies of their personal data being processed. For the purposes of identification, the data controller may request additional information from the subject, and – with the exception of the first copy being handed out – to charge any warranted administrative fees that further copies may entail.
b) Right of correction
The data subject is entitled to request any of their erroneous personal data to be rectified by the data controller. Based on the given data processing purpose, the data subject may be entitled to request incomplete personal data to be amended.
c) Right of deletion („right to be forgotten”)
The data subject is entitled to request the data controller to delete their personal data, and the data controller shall delete these. In any such case, the data controller will not be able to provide any further services to the User.
d) Right of restriction
The data subject is entitled to request the restriction of their personal data. In this case, the data controller shall mark the affected personal data, which shall only be processed for certain specific purposes.
e) Right to objection
The data subject is entitled to object at any time, for any reasons of their own, to the processing of their personal data per Article 6 (1) e) or f) of the general data protection regulation, including the profiling based on said regulations, and to request that the data controller no longer process their personal data.
Moreover, where the User’s data is processed by the Service Provider per lawful interest, User is entitled to object to their data being processed per this basis.
Additionally, User is entitled to request human intervention in specific cases of automated decision making. We inform Users that data controller employs no automated decision-making mechanisms.
f) Right to data portability
The data subject is entitled to request that their given personal data be provided to them in an articulated, widely recognised, computer readable format (i.e. digital format) from the data processor, and is entitled moreover – where technically possible – to request these data to be forwarded to another data controller without the Service Provider hindering this.
g) Right to revoke consent
Where the processing of User’s personal data is conducted per their consent, User may revoke their consent at any time via the link found in newsletters, or by changing their website-profile or mobile device settings. Revocation of consent does not affect the legality of consent-based data processing conducted prior to the revocation of consent.
If User revokes their consent given to the Service Provider, the services provided by the Service Provider may partially or wholly be unavailable to be provided.
h) Right to file a complaint with the supervisory authority
If the User believes that their personal data have been infringed upon, they may file a complaint with the local data privacy supervisory authority, primarily per their residence, their place of work or in the member state where the purported breach had taken place.
In Hungary, they may also turn to the National Authority for Data Protection and Freedom of Information: H-1055, Hungary, Budapest, Falk Miksa utca 9-11.; telephone: +36-1 391-1400; telefax: +36-1 391-1410; e-mail: ugyfelszolgalat@naih.hu).
Contact keeping
Should the User wish to exercise their data privacy rights or to lodge a complaint, they may contact the Service Provider’s appointed colleague via an e-mail sent to the e-mail address below. Moreover, User may seek out the Service Provider by way of mail sent to the postal address below.
E-mail: saswarekft@gmail.com
Postal address: 8449 Magyarpolány, Bakony utca 23.
Miscellaneous provisions
In case of any data privacy incidents, the Service Provider shall notify the supervising authority per the applicable legal regulations, within 72 hours from having gained knowledge of the incident; and shall keep records thereof. The Service Provider shall notify Users thereof in cases specified by law.
The data processor shall regularly check their online platforms and the information published thereon and shall make every reasonable effort to ensure the information thereon are current and factual. However, User may find information on these online platforms that are out of date. The Service Provider accepts no material liability for this information.
Visitors of the Service Provider’s online platforms and Users may visit other websites from the Service Provider’s online platforms that are not operated by the Service Provider. The Service Provider accepts no liability regarding the correctness of data found thereon, the contents of these pages, and for the security of any data provided there by visitors of the Service Provider’s online platforms and Users. Thus, when using these websites, please take special care in consulting the privacy policies of the respective operating companies found thereon.
The present Privacy Policy shall enter into force on [TO BE FILLED IN: date of entry into force].
