support@kepeink.husecurity@kepeink.huLAUNCH BLOCKER — CONTROLLER IDENTITY MUST BE COMPLETED: the controller is [FULL LEGAL NAME] e.v., a Hungarian individual entrepreneur with registered address [FULL REGISTERED ADDRESS], individual-entrepreneur registration number [REGISTRATION NUMBER], and tax number [TAX NUMBER] (the Operator, we, us, or our). Do not publish this Notice until every bracketed field is replaced with the controller's true public-register information.
This Notice explains how Kepeink handles personal data under Regulation (EU) 2016/679 (GDPR) and applicable Hungarian law. It covers the public website, management dashboard, APIs, support and abuse channels, Agent distribution, billing integration, and routing service. The Terms of Service govern the Service relationship.
Kepeink is available to adult consumers and business users. This Notice also applies to visitors who connect to a Customer's public Tunnel, reporters, support contacts, and people whose personal data a Customer directs us to relay.
We act as controller when we decide why and how to process data for account authentication, contract evidence, billing reconciliation, product operation, first-party telemetry, security, abuse handling, legal compliance, support, and our own claims.
For personal data contained in traffic that a Customer instructs us to relay, the Customer normally acts as controller and we normally act as its processor, unless the Customer's activity falls outside the GDPR, for example under the personal or household exemption. Processor activity is governed by our Data Processing Addendum (DPA). The Customer is responsible for its own lawful basis, transparency, instructions, and handling of data-subject requests where those duties apply. We may become an independent controller for a narrow copy or event if we must use it for network security, abuse investigation, a binding legal obligation, or establishment or defence of legal claims.
Creem acts as merchant of record and has its own controller responsibilities for checkout, payment, tax, invoicing, refunds, fraud, and chargebacks. Other recipients and their roles are described in §5.
No Data Protection Officer has been appointed at this pre-launch stage. This is an internal assessment, not a waiver: we will reassess GDPR Article 37 if the scale, monitoring, or nature of processing changes. Privacy requests go to support@kepeink.hu.
We aim to collect only data needed for an identified operational, contractual, security, or legal purpose.
“No payload storage” does not mean no processing, no metadata, or mathematical impossibility of incidental capture. A crash dump, security investigation, Customer support material, upstream network system, or malicious compromise may create an exceptional copy. Such an event is handled under the incident, access, and retention rules below.
| Data | Purpose | GDPR basis |
|---|---|---|
| Website request data, including IP address, timestamp, host/path, protocol, response code, user agent, and security-provider signals | Deliver and secure the site; diagnose failures; rate-limit abuse | Legitimate interests in operating and securing the service (Art. 6(1)(f)) |
| Verified email address, account ID, status, timestamps | Create and administer an Account; communicate security and service notices | Steps requested before contract and contract performance (Art. 6(1)(b)); legitimate interests |
| Email challenge ID, hashed secret, expiry, attempts, source IP, and delivery event | Authenticate, prevent replay and brute force, troubleshoot delivery | Contract; legitimate interests in security |
| Session/API/Agent-token identifier, cryptographic hash, type, role, creation, use, expiry, and revocation timestamps | Authenticate and authorise users and software; investigate credential abuse | Contract; legitimate interests in security |
| Optional Google OAuth subject, verified email, authentication claims and state, if that feature is enabled and selected | Complete optional sign-in | Contract; legitimate interests in secure authentication |
| TOTP factor metadata, encrypted TOTP secret, key identifier, one-time recovery-code hashes, MFA challenge and verification events | Provide and secure multi-factor authentication | Contract; legitimate interests in security |
The browser session cookie contains a high-entropy opaque credential in plaintext in the browser; the database stores its cryptographic hash. It is marked HttpOnly, Secure, and SameSite=Lax. Do not copy it.
| Data | Purpose | GDPR basis |
|---|---|---|
| ToS and Privacy release dates and exact document SHA-256 hashes; separate Terms agreement, endpoint-authorisation/anti-proxy attestation, and Privacy Notice acknowledgement; acceptance and confirmation-email handoff times; Account and Workspace IDs, source IP, user agent, and acceptance method | Form and prove the consumer or business contract; demonstrate delivery of notices; establish authority over exposed endpoints; prevent proxy abuse; resolve disputes and legal claims | Contract (Art. 6(1)(b)); legitimate interests in contract evidence, network safety and legal claims (Art. 6(1)(f)); compliance with legal obligations where applicable (Art. 6(1)(c)) |
Acknowledging this Privacy Notice is not consent to processing. We use consent only where a feature expressly asks for it and a genuine non-detrimental choice exists. Refusing Terms acceptance prevents use of the contractual Service but does not prevent export, account security, or deletion functions.
| Data | Purpose | GDPR basis |
|---|---|---|
| Workspace IDs/names, memberships, roles, settings and status | Tenant isolation, administration and billing | Contract; legitimate interests in access control |
| Tunnel ID, public hostname/SNI, local target string, backend/TLS mode, Agent configuration and status, creator, timestamps | Provision and operate the requested reverse connection | Contract |
| Custom domain, DNS verification results, certificate names/status and ACME challenge data | Prove control, route the domain, obtain and renew TLS certificates | Contract; legitimate interests in secure encryption |
| Agent instance/session ID, version, platform, capability, selected router, connection status, source network address and operational timings | Authenticate and operate Agent sessions, select capacity, debug and secure connections | Contract; legitimate interests in reliability and security |
| Agent download/update artifact, version, request time, IP address, user agent, success/failure and integrity metadata | Distribute, secure, and troubleshoot the Agent | Contract; legitimate interests in software security |
Certificate issuance can cause domain names to appear in public Certificate Transparency logs operated by third parties. Do not request a publicly trusted certificate for a name you are not authorised to publish.
The Agent may use configured system DNS and, on resolution failure, public DNS-over-HTTPS resolvers operated by Cloudflare, Google, or Quad9. Those resolvers receive the queried edge hostname and the Agent's network address under their own notices. This fallback concerns Kepeink router discovery, not arbitrary browsing, and should be disabled or overridden in an enterprise deployment that requires private DNS policy.
| Data | Purpose | Our role / basis |
|---|---|---|
| Source and destination network addresses, public hostname/SNI, connection time and duration, router/tunnel identifiers, status/error, protocol and coarse security signals | Route, rate-limit, prevent attacks, troubleshoot and investigate abuse | Usually independent controller for network operation/security: contract with Customer and legitimate interests; may also be processor where determined by Customer instructions |
| Bytes in/out and metering windows | Apply prepaid usage, reconcile billing, audit overcharge and plan capacity | Contract; accounting/legal obligations where applicable; legitimate interests |
| Application headers and payload transiently present in terminated mode | Proxy the Customer-requested service | Processor under the DPA, unless a narrow independent legal/security purpose applies |
| Encrypted payload in passthrough mode | Relay bytes without application-layer decryption | Processor under the DPA |
We do not require a Tunnel visitor to create a Kepeink account. The Customer operating the exposed service must give the visitor its own privacy information and answer requests about Customer Content. A visitor can identify the relevant Kepeink hostname when contacting us, but we may need to refer a content request to the Customer.
| Data | Purpose | GDPR basis |
|---|---|---|
| Creem customer, checkout, order, product, subscription and refund identifiers; customer email and order state returned by Creem | Match payment to the correct Account and Workspace; provision or reverse credit; support billing disputes | Contract; legitimate interests in fraud and reconciliation; legal obligations |
| Credit grants, entitlement, source/order reference, usage debit, billing-audit comparison and adjustment | Keep an auditable usage and financial ledger | Contract; legal obligation; legitimate interests in accurate billing |
| Signed webhook payload and idempotency/error state | Reliably process each payment event once and investigate discrepancies | Contract; legitimate interests |
The Operator does not receive or store full payment-card credentials. Do not send them to support. Creem's checkout notice explains its separate processing.
| Data | Purpose | GDPR basis |
|---|---|---|
| Structured audit event: actor Account/token, Workspace, action, result, source IP, resource and allowlisted detail | Security, accountability, fraud detection, customer audit, dispute response | Legitimate interests; legal obligations where applicable |
| Application/edge log and operational metric, which may include IDs, addresses, timings and error text | Detect incidents, debug, alert, capacity plan and demonstrate operation | Legitimate interests in security and reliability |
| Allowlisted first-party page-view and UI-action names, page path, and aggregate counters | Understand whether core product flows work without advertising trackers | Legitimate interests in product operation |
| UI error message, truncated stack, component and page path submitted to our logging endpoint | Diagnose failures | Legitimate interests; users should not place secrets or personal data in UI labels or error-triggering fields |
| reCAPTCHA Enterprise token validity, action and risk score, with request context Google processes | Block automated account, activation and reporting abuse | Legitimate interests in abuse prevention |
| Support or security message, attachments, sender/recipient, timestamps and related Account/Workspace | Respond, investigate and preserve agreed actions | Contract; legitimate interests; legal claims |
| Public portal or inbound-email abuse report, reporter identity/contact, hostname/URL, allegation, evidence, headers, IP, SPF/DKIM/DMARC result, verification state and review decision | Receive, authenticate, investigate, decide and evidence reports; comply with legal duties; prevent malicious reporting | Legal obligation where applicable; legitimate interests in safety, rights protection and claims |
Please minimise personal data in reports and support messages. Do not submit special-category data, credentials, card data, or unnecessary payload copies. If evidence unavoidably includes sensitive information, clearly identify it and use the channel we provide.
The period below is the normal maximum, not a promise to keep every item for that long. We may delete sooner when no longer needed. We may preserve a narrowly scoped record beyond the normal period while a documented legal hold, authority request, security incident, debt, or dispute is active; we review holds periodically.
| Data | Normal retention |
|---|---|
| Pending/live Account and Workspace personal data | For the Account relationship. Deletion immediately revokes access and pseudonymises the email; remaining personal residue is deleted or anonymised after a 30-day operational grace period |
| Used or expired email, MFA and token-reveal challenges | About 1 day after use or expiry; an unverified abuse-report challenge may remain for expiry plus 7 days |
| Active, expired and revoked credential metadata | For the Account relationship and up to the 30-day deletion grace; plaintext secrets are not retained server-side after one-time display |
| Clickwrap and endpoint-authorisation acceptance evidence | Normally 5 years after the contractual relationship ends, reflecting the ordinary civil-claims period, and longer only for a documented live claim or mandatory rule |
| Structured audit log | 24 months; Account purge earlier removes actor linkage, source IP and marked personal detail for that user |
| Central application and edge logs | 14 days, subject to an earlier storage-cap eviction; security evidence may be extracted to a restricted case file |
| Operational time-series metrics | 30 days in identifiable operational form, then deleted or aggregated where useful |
| Processed billing webhooks | About 30 days; unresolved/deferred records normally 14 to 90 days depending on status |
| Financial and usage ledgers needed for Hungarian accounting | 8 years; direct user links are severed where possible after Account deletion |
| Live Tunnel and custom-domain configuration | For the Workspace; serving state is removed on eligible Account/Workspace deletion |
| Archived Tunnel hostname/provenance | Until the end of the applicable legal-claims and abuse-prevention period; the current pre-launch system requires a bounded deletion/anonymisation job before public launch and must not rely on indefinite identity-linked retention |
| Free-trial abuse-prevention value | A keyed/peppered email-derived value may be retained while free trials remain vulnerable to repeat abuse; the direct Account link is removed on purge and necessity is reviewed annually |
| Support and abuse case | Normally up to 5 years after closure if needed for claims or repeat-abuse evidence; manifestly irrelevant material is removed sooner |
| Backups | Rolling encrypted/immutable copies normally up to 90 days; deletion takes effect in the live system first and ages out of backups unless restoration is required, in which case deletion is re-applied |
The operator retention map is maintained in docs/data-retention.md. A production retention setting must not silently exceed this Notice.
We disclose the minimum data needed to suppliers that operate part of the Service, to professional advisers bound by confidentiality, to a successor under appropriate safeguards, and to authorities or third parties where lawfully required or necessary to protect rights. We do not give a Customer the identity of a Tunnel visitor except through the Customer's own service flow or where legally justified.
| Recipient | Function and typical data | Location / role |
|---|---|---|
| Hetzner Online GmbH | EU compute, storage and networking; service data, traffic and logs | Germany/Finland; processor/subprocessor |
| Cloudflare, Inc. and group entities | Authoritative DNS, CDN/WAF for web and management, email routing, object storage/backups; requests, identifiers and logs | Global including United States; processor/subprocessor for many functions |
| Armitage Labs OÜ (Creem) and its providers | Merchant of record, checkout, payment, tax, invoice, refund, fraud and chargeback | EEA/other locations; mainly independent controller for buyer transaction, recipient for Service fulfilment |
| Amazon Web Services EMEA SARL / affiliates (Amazon SES) | Transactional email and delivery events | EEA/global; processor/subprocessor |
| Zoho group (ZeptoMail) | Transactional email failover | EEA/global; processor/subprocessor |
| Google Ireland Limited / Google LLC | reCAPTCHA Enterprise and optional Google sign-in | EEA/United States/global; processor or independent controller depending on function |
| Internet Security Research Group (Let's Encrypt) | Publicly trusted TLS certificate issuance; domain names, ACME data and public certificate logs | United States/global; independent recipient/certificate authority |
| Cloudflare, Google and Quad9 public resolvers | Agent router-discovery DNS fallback; queried hostname and Agent network address | Global; independent recipients under their notices |
The precise contracted entity, location, and downstream subprocessor can change. We maintain a dated subprocessor list and give Customers notice of a new subprocessor where required by the DPA or consumer contract rules. Before launch, the Operator must execute and retain appropriate data-processing terms with each processor actually enabled.
Core hosting is intended to remain in the EEA, but global network, security, payment, certificate, email, and support providers may process data outside the EEA. For a restricted transfer we use the mechanism applicable to the recipient and transfer, such as an adequacy decision, the EU–US Data Privacy Framework only where the exact recipient is currently certified for the relevant data, or European Commission Standard Contractual Clauses with a transfer assessment and supplementary measures.
We do not claim a transfer mechanism without verifying it. You may request information about the applicable safeguard at support@kepeink.hu; confidential commercial terms may be redacted.
The management dashboard uses the strictly necessary first-party session cookie described in §3.1 and browser localStorage for limited user-interface state such as theme and cross-tab authentication status. The session has a sliding lifetime of up to 14 days subject to a 90-day hard cap, unless revoked earlier.
The marketing and legal pages use system fonts and do not contact Google Fonts. Kepeink does not set advertising cookies or use third-party advertising analytics. When reCAPTCHA is loaded for a protected action, Google may read or set its own device/browser data for abuse detection. Optional Google sign-in contacts Google only when the user selects that method. Where a non-essential storage technology is added, it must be disabled until any legally required consent mechanism is implemented.
Rate limits, credential checks, fraud rules, reCAPTCHA scoring, routing authorisation, credit cut-off, and security heuristics can automatically allow, reject, delay, or temporarily quarantine activity. An abuse report is queued for human review and does not suspend a Tunnel merely because the reporter authenticated an email address. A verified urgent technical security signal or binding legal requirement may trigger a proportionate emergency restriction.
These controls are intended to protect the contract and systems and are not used to infer sensitive traits. Where an automated restriction materially affects a Customer, the Customer can request human review at support@kepeink.hu. We record the principal signal and outcome. We do not presently make solely automated decisions producing legal or similarly significant effects about individual persons within GDPR Article 22; this assessment will be revisited before expanding fraud or identity scoring.
Measures include tenant-scoped authorisation, high-entropy credentials stored as hashes, encryption of designated secrets, TLS, signed Agent releases, least-privilege service identities, network segmentation, rate limits, encrypted backups, monitoring, audit events, credential rotation, and incident procedures. Details may be limited where disclosure would reduce security.
The single founder is the initial privileged administrator. Production access must use an individually attributable account, multi-factor authentication, a trusted operator host, least privilege, and logging; shared administrator credentials and routine direct database browsing are prohibited. Emergency access is time-limited, documented, and reviewed. Support personnel must not inspect Customer Content merely out of curiosity or convenience.
No system is perfectly secure. Report suspected vulnerability or compromise to security@kepeink.hu. Do not access data or degrade the Service while testing without written authorisation.
If a personal-data breach occurs, we contain and assess it, document the decision, notify the competent supervisory authority within GDPR deadlines where required, and notify affected persons where the legal risk threshold is met. A processor Customer is notified without undue delay under the DPA.
Subject to GDPR conditions and exceptions, an individual has rights to:
Account users can export data and request deletion in the dashboard. Other requests can be sent to support@kepeink.hu. We may verify identity and authority, particularly where a request concerns another person's Workspace or a Tunnel visitor. We normally respond within one month, extendable where GDPR permits. A Customer is responsible for requests about Customer Content where it is controller; as processor we provide reasonable assistance under the DPA.
The Hungarian supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). Current contact and online filing information is at https://www.naih.hu/ and https://www.naih.hu/ugyfelszolgalat-kapcsolat. You may also complain to the authority in another EU Member State where GDPR permits.
Erasure does not apply to data we must retain for a legal obligation or need to establish, exercise, or defend legal claims. We will restrict such retained data to that purpose.
Kepeink Accounts are available only to people aged 18 or over and are not directed to children. We do not knowingly create Accounts for children. Customer Content may contain a child's data only where the Customer has a lawful basis and complies with applicable child-privacy rules. Do not use Kepeink for such processing if the risk cannot be lawfully managed. Contact us if a child appears to have created an Account.
We publish a new dated release when this Notice materially changes and provide dashboard or email notice where appropriate. A Privacy Notice is acknowledged, not accepted as consent. Historical dated copies and their hashes are retained with contract evidence.
Questions, rights requests, and complaints: support@kepeink.hu.
Security reports: security@kepeink.hu.
Formal postal requests: [FULL LEGAL NAME] e.v., [FULL REGISTERED ADDRESS].