Privacy Notice

LAUNCH BLOCKER — CONTROLLER IDENTITY MUST BE COMPLETED: the controller is [FULL LEGAL NAME] e.v., a Hungarian individual entrepreneur with registered address [FULL REGISTERED ADDRESS], individual-entrepreneur registration number [REGISTRATION NUMBER], and tax number [TAX NUMBER] (the Operator, we, us, or our). Do not publish this Notice until every bracketed field is replaced with the controller's true public-register information.

This Notice explains how Kepeink handles personal data under Regulation (EU) 2016/679 (GDPR) and applicable Hungarian law. It covers the public website, management dashboard, APIs, support and abuse channels, Agent distribution, billing integration, and routing service. The Terms of Service govern the Service relationship.

Kepeink is available to adult consumers and business users. This Notice also applies to visitors who connect to a Customer's public Tunnel, reporters, support contacts, and people whose personal data a Customer directs us to relay.

1. Our roles

We act as controller when we decide why and how to process data for account authentication, contract evidence, billing reconciliation, product operation, first-party telemetry, security, abuse handling, legal compliance, support, and our own claims.

For personal data contained in traffic that a Customer instructs us to relay, the Customer normally acts as controller and we normally act as its processor, unless the Customer's activity falls outside the GDPR, for example under the personal or household exemption. Processor activity is governed by our Data Processing Addendum (DPA). The Customer is responsible for its own lawful basis, transparency, instructions, and handling of data-subject requests where those duties apply. We may become an independent controller for a narrow copy or event if we must use it for network security, abuse investigation, a binding legal obligation, or establishment or defence of legal claims.

Creem acts as merchant of record and has its own controller responsibilities for checkout, payment, tax, invoicing, refunds, fraud, and chargebacks. Other recipients and their roles are described in §5.

No Data Protection Officer has been appointed at this pre-launch stage. This is an internal assessment, not a waiver: we will reassess GDPR Article 37 if the scale, monitoring, or nature of processing changes. Privacy requests go to support@kepeink.hu.

2. Principles and what we do not do

We aim to collect only data needed for an identified operational, contractual, security, or legal purpose.

“No payload storage” does not mean no processing, no metadata, or mathematical impossibility of incidental capture. A crash dump, security investigation, Customer support material, upstream network system, or malicious compromise may create an exceptional copy. Such an event is handled under the incident, access, and retention rules below.

3. Data, purposes, and legal bases

3.1 Website, registration, and authentication

Data Purpose GDPR basis
Website request data, including IP address, timestamp, host/path, protocol, response code, user agent, and security-provider signals Deliver and secure the site; diagnose failures; rate-limit abuse Legitimate interests in operating and securing the service (Art. 6(1)(f))
Verified email address, account ID, status, timestamps Create and administer an Account; communicate security and service notices Steps requested before contract and contract performance (Art. 6(1)(b)); legitimate interests
Email challenge ID, hashed secret, expiry, attempts, source IP, and delivery event Authenticate, prevent replay and brute force, troubleshoot delivery Contract; legitimate interests in security
Session/API/Agent-token identifier, cryptographic hash, type, role, creation, use, expiry, and revocation timestamps Authenticate and authorise users and software; investigate credential abuse Contract; legitimate interests in security
Optional Google OAuth subject, verified email, authentication claims and state, if that feature is enabled and selected Complete optional sign-in Contract; legitimate interests in secure authentication
TOTP factor metadata, encrypted TOTP secret, key identifier, one-time recovery-code hashes, MFA challenge and verification events Provide and secure multi-factor authentication Contract; legitimate interests in security

The browser session cookie contains a high-entropy opaque credential in plaintext in the browser; the database stores its cryptographic hash. It is marked HttpOnly, Secure, and SameSite=Lax. Do not copy it.

3.2 Contract and endpoint-authorisation evidence

Data Purpose GDPR basis
ToS and Privacy release dates and exact document SHA-256 hashes; separate Terms agreement, endpoint-authorisation/anti-proxy attestation, and Privacy Notice acknowledgement; acceptance and confirmation-email handoff times; Account and Workspace IDs, source IP, user agent, and acceptance method Form and prove the consumer or business contract; demonstrate delivery of notices; establish authority over exposed endpoints; prevent proxy abuse; resolve disputes and legal claims Contract (Art. 6(1)(b)); legitimate interests in contract evidence, network safety and legal claims (Art. 6(1)(f)); compliance with legal obligations where applicable (Art. 6(1)(c))

Acknowledging this Privacy Notice is not consent to processing. We use consent only where a feature expressly asks for it and a genuine non-detrimental choice exists. Refusing Terms acceptance prevents use of the contractual Service but does not prevent export, account security, or deletion functions.

3.3 Workspaces, Tunnels, Agents, and certificates

Data Purpose GDPR basis
Workspace IDs/names, memberships, roles, settings and status Tenant isolation, administration and billing Contract; legitimate interests in access control
Tunnel ID, public hostname/SNI, local target string, backend/TLS mode, Agent configuration and status, creator, timestamps Provision and operate the requested reverse connection Contract
Custom domain, DNS verification results, certificate names/status and ACME challenge data Prove control, route the domain, obtain and renew TLS certificates Contract; legitimate interests in secure encryption
Agent instance/session ID, version, platform, capability, selected router, connection status, source network address and operational timings Authenticate and operate Agent sessions, select capacity, debug and secure connections Contract; legitimate interests in reliability and security
Agent download/update artifact, version, request time, IP address, user agent, success/failure and integrity metadata Distribute, secure, and troubleshoot the Agent Contract; legitimate interests in software security

Certificate issuance can cause domain names to appear in public Certificate Transparency logs operated by third parties. Do not request a publicly trusted certificate for a name you are not authorised to publish.

The Agent may use configured system DNS and, on resolution failure, public DNS-over-HTTPS resolvers operated by Cloudflare, Google, or Quad9. Those resolvers receive the queried edge hostname and the Agent's network address under their own notices. This fallback concerns Kepeink router discovery, not arbitrary browsing, and should be disabled or overridden in an enterprise deployment that requires private DNS policy.

3.4 Tunnel visitors, traffic, and metering

Data Purpose Our role / basis
Source and destination network addresses, public hostname/SNI, connection time and duration, router/tunnel identifiers, status/error, protocol and coarse security signals Route, rate-limit, prevent attacks, troubleshoot and investigate abuse Usually independent controller for network operation/security: contract with Customer and legitimate interests; may also be processor where determined by Customer instructions
Bytes in/out and metering windows Apply prepaid usage, reconcile billing, audit overcharge and plan capacity Contract; accounting/legal obligations where applicable; legitimate interests
Application headers and payload transiently present in terminated mode Proxy the Customer-requested service Processor under the DPA, unless a narrow independent legal/security purpose applies
Encrypted payload in passthrough mode Relay bytes without application-layer decryption Processor under the DPA

We do not require a Tunnel visitor to create a Kepeink account. The Customer operating the exposed service must give the visitor its own privacy information and answer requests about Customer Content. A visitor can identify the relevant Kepeink hostname when contacting us, but we may need to refer a content request to the Customer.

3.5 Billing

Data Purpose GDPR basis
Creem customer, checkout, order, product, subscription and refund identifiers; customer email and order state returned by Creem Match payment to the correct Account and Workspace; provision or reverse credit; support billing disputes Contract; legitimate interests in fraud and reconciliation; legal obligations
Credit grants, entitlement, source/order reference, usage debit, billing-audit comparison and adjustment Keep an auditable usage and financial ledger Contract; legal obligation; legitimate interests in accurate billing
Signed webhook payload and idempotency/error state Reliably process each payment event once and investigate discrepancies Contract; legitimate interests

The Operator does not receive or store full payment-card credentials. Do not send them to support. Creem's checkout notice explains its separate processing.

3.6 Logs, first-party telemetry, support, and abuse

Data Purpose GDPR basis
Structured audit event: actor Account/token, Workspace, action, result, source IP, resource and allowlisted detail Security, accountability, fraud detection, customer audit, dispute response Legitimate interests; legal obligations where applicable
Application/edge log and operational metric, which may include IDs, addresses, timings and error text Detect incidents, debug, alert, capacity plan and demonstrate operation Legitimate interests in security and reliability
Allowlisted first-party page-view and UI-action names, page path, and aggregate counters Understand whether core product flows work without advertising trackers Legitimate interests in product operation
UI error message, truncated stack, component and page path submitted to our logging endpoint Diagnose failures Legitimate interests; users should not place secrets or personal data in UI labels or error-triggering fields
reCAPTCHA Enterprise token validity, action and risk score, with request context Google processes Block automated account, activation and reporting abuse Legitimate interests in abuse prevention
Support or security message, attachments, sender/recipient, timestamps and related Account/Workspace Respond, investigate and preserve agreed actions Contract; legitimate interests; legal claims
Public portal or inbound-email abuse report, reporter identity/contact, hostname/URL, allegation, evidence, headers, IP, SPF/DKIM/DMARC result, verification state and review decision Receive, authenticate, investigate, decide and evidence reports; comply with legal duties; prevent malicious reporting Legal obligation where applicable; legitimate interests in safety, rights protection and claims

Please minimise personal data in reports and support messages. Do not submit special-category data, credentials, card data, or unnecessary payload copies. If evidence unavoidably includes sensitive information, clearly identify it and use the channel we provide.

4. Retention

The period below is the normal maximum, not a promise to keep every item for that long. We may delete sooner when no longer needed. We may preserve a narrowly scoped record beyond the normal period while a documented legal hold, authority request, security incident, debt, or dispute is active; we review holds periodically.

Data Normal retention
Pending/live Account and Workspace personal data For the Account relationship. Deletion immediately revokes access and pseudonymises the email; remaining personal residue is deleted or anonymised after a 30-day operational grace period
Used or expired email, MFA and token-reveal challenges About 1 day after use or expiry; an unverified abuse-report challenge may remain for expiry plus 7 days
Active, expired and revoked credential metadata For the Account relationship and up to the 30-day deletion grace; plaintext secrets are not retained server-side after one-time display
Clickwrap and endpoint-authorisation acceptance evidence Normally 5 years after the contractual relationship ends, reflecting the ordinary civil-claims period, and longer only for a documented live claim or mandatory rule
Structured audit log 24 months; Account purge earlier removes actor linkage, source IP and marked personal detail for that user
Central application and edge logs 14 days, subject to an earlier storage-cap eviction; security evidence may be extracted to a restricted case file
Operational time-series metrics 30 days in identifiable operational form, then deleted or aggregated where useful
Processed billing webhooks About 30 days; unresolved/deferred records normally 14 to 90 days depending on status
Financial and usage ledgers needed for Hungarian accounting 8 years; direct user links are severed where possible after Account deletion
Live Tunnel and custom-domain configuration For the Workspace; serving state is removed on eligible Account/Workspace deletion
Archived Tunnel hostname/provenance Until the end of the applicable legal-claims and abuse-prevention period; the current pre-launch system requires a bounded deletion/anonymisation job before public launch and must not rely on indefinite identity-linked retention
Free-trial abuse-prevention value A keyed/peppered email-derived value may be retained while free trials remain vulnerable to repeat abuse; the direct Account link is removed on purge and necessity is reviewed annually
Support and abuse case Normally up to 5 years after closure if needed for claims or repeat-abuse evidence; manifestly irrelevant material is removed sooner
Backups Rolling encrypted/immutable copies normally up to 90 days; deletion takes effect in the live system first and ages out of backups unless restoration is required, in which case deletion is re-applied

The operator retention map is maintained in docs/data-retention.md. A production retention setting must not silently exceed this Notice.

5. Recipients and subprocessors

We disclose the minimum data needed to suppliers that operate part of the Service, to professional advisers bound by confidentiality, to a successor under appropriate safeguards, and to authorities or third parties where lawfully required or necessary to protect rights. We do not give a Customer the identity of a Tunnel visitor except through the Customer's own service flow or where legally justified.

Recipient Function and typical data Location / role
Hetzner Online GmbH EU compute, storage and networking; service data, traffic and logs Germany/Finland; processor/subprocessor
Cloudflare, Inc. and group entities Authoritative DNS, CDN/WAF for web and management, email routing, object storage/backups; requests, identifiers and logs Global including United States; processor/subprocessor for many functions
Armitage Labs OÜ (Creem) and its providers Merchant of record, checkout, payment, tax, invoice, refund, fraud and chargeback EEA/other locations; mainly independent controller for buyer transaction, recipient for Service fulfilment
Amazon Web Services EMEA SARL / affiliates (Amazon SES) Transactional email and delivery events EEA/global; processor/subprocessor
Zoho group (ZeptoMail) Transactional email failover EEA/global; processor/subprocessor
Google Ireland Limited / Google LLC reCAPTCHA Enterprise and optional Google sign-in EEA/United States/global; processor or independent controller depending on function
Internet Security Research Group (Let's Encrypt) Publicly trusted TLS certificate issuance; domain names, ACME data and public certificate logs United States/global; independent recipient/certificate authority
Cloudflare, Google and Quad9 public resolvers Agent router-discovery DNS fallback; queried hostname and Agent network address Global; independent recipients under their notices

The precise contracted entity, location, and downstream subprocessor can change. We maintain a dated subprocessor list and give Customers notice of a new subprocessor where required by the DPA or consumer contract rules. Before launch, the Operator must execute and retain appropriate data-processing terms with each processor actually enabled.

6. International transfers

Core hosting is intended to remain in the EEA, but global network, security, payment, certificate, email, and support providers may process data outside the EEA. For a restricted transfer we use the mechanism applicable to the recipient and transfer, such as an adequacy decision, the EU–US Data Privacy Framework only where the exact recipient is currently certified for the relevant data, or European Commission Standard Contractual Clauses with a transfer assessment and supplementary measures.

We do not claim a transfer mechanism without verifying it. You may request information about the applicable safeguard at support@kepeink.hu; confidential commercial terms may be redacted.

7. Cookies, local storage, and external resources

The management dashboard uses the strictly necessary first-party session cookie described in §3.1 and browser localStorage for limited user-interface state such as theme and cross-tab authentication status. The session has a sliding lifetime of up to 14 days subject to a 90-day hard cap, unless revoked earlier.

The marketing and legal pages use system fonts and do not contact Google Fonts. Kepeink does not set advertising cookies or use third-party advertising analytics. When reCAPTCHA is loaded for a protected action, Google may read or set its own device/browser data for abuse detection. Optional Google sign-in contacts Google only when the user selects that method. Where a non-essential storage technology is added, it must be disabled until any legally required consent mechanism is implemented.

8. Automated controls and human review

Rate limits, credential checks, fraud rules, reCAPTCHA scoring, routing authorisation, credit cut-off, and security heuristics can automatically allow, reject, delay, or temporarily quarantine activity. An abuse report is queued for human review and does not suspend a Tunnel merely because the reporter authenticated an email address. A verified urgent technical security signal or binding legal requirement may trigger a proportionate emergency restriction.

These controls are intended to protect the contract and systems and are not used to infer sensitive traits. Where an automated restriction materially affects a Customer, the Customer can request human review at support@kepeink.hu. We record the principal signal and outcome. We do not presently make solely automated decisions producing legal or similarly significant effects about individual persons within GDPR Article 22; this assessment will be revisited before expanding fraud or identity scoring.

9. Security and administrator access

Measures include tenant-scoped authorisation, high-entropy credentials stored as hashes, encryption of designated secrets, TLS, signed Agent releases, least-privilege service identities, network segmentation, rate limits, encrypted backups, monitoring, audit events, credential rotation, and incident procedures. Details may be limited where disclosure would reduce security.

The single founder is the initial privileged administrator. Production access must use an individually attributable account, multi-factor authentication, a trusted operator host, least privilege, and logging; shared administrator credentials and routine direct database browsing are prohibited. Emergency access is time-limited, documented, and reviewed. Support personnel must not inspect Customer Content merely out of curiosity or convenience.

No system is perfectly secure. Report suspected vulnerability or compromise to security@kepeink.hu. Do not access data or degrade the Service while testing without written authorisation.

If a personal-data breach occurs, we contain and assess it, document the decision, notify the competent supervisory authority within GDPR deadlines where required, and notify affected persons where the legal risk threshold is met. A processor Customer is notified without undue delay under the DPA.

10. Your rights

Subject to GDPR conditions and exceptions, an individual has rights to:

Account users can export data and request deletion in the dashboard. Other requests can be sent to support@kepeink.hu. We may verify identity and authority, particularly where a request concerns another person's Workspace or a Tunnel visitor. We normally respond within one month, extendable where GDPR permits. A Customer is responsible for requests about Customer Content where it is controller; as processor we provide reasonable assistance under the DPA.

The Hungarian supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). Current contact and online filing information is at https://www.naih.hu/ and https://www.naih.hu/ugyfelszolgalat-kapcsolat. You may also complain to the authority in another EU Member State where GDPR permits.

Erasure does not apply to data we must retain for a legal obligation or need to establish, exercise, or defend legal claims. We will restrict such retained data to that purpose.

11. Children

Kepeink Accounts are available only to people aged 18 or over and are not directed to children. We do not knowingly create Accounts for children. Customer Content may contain a child's data only where the Customer has a lawful basis and complies with applicable child-privacy rules. Do not use Kepeink for such processing if the risk cannot be lawfully managed. Contact us if a child appears to have created an Account.

12. Changes and contact

We publish a new dated release when this Notice materially changes and provide dashboard or email notice where appropriate. A Privacy Notice is acknowledged, not accepted as consent. Historical dated copies and their hashes are retained with contract evidence.

Questions, rights requests, and complaints: support@kepeink.hu.

Security reports: security@kepeink.hu.

Formal postal requests: [FULL LEGAL NAME] e.v., [FULL REGISTERED ADDRESS].