Privacy Policy

Privacy Policy

How ArchiPM-Nexus collects, uses and protects your personal data

Last updated: August 15, 2026

1. Introduction

ArchiFM Operation Zrt. ("ArchiPM-Nexus", "we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclose and protect your personal data when you use our website (archipm.com), our SaaS platform, and our on-premise software solutions (collectively, the "Services"). This policy complies with: - EU General Data Protection Regulation (GDPR, Regulation 2016/679) - Hungarian Information Act (Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information) Our services are not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you are under 16, please do not use our services or provide us with any personal data.

2. Data Controller

Data Controller: ArchiFM Operation Zrt. Registered office: 1031 Budapest, Záhony utca 7., Hungary Company registration number: 01-10-143063 Tax number: 32687141-2-41 Data Protection Officer / Privacy Contact: Email: privacy@archipm.com Email: info@archipm.com For all data protection inquiries, including exercising your rights under GDPR, please contact us using the details above.

3. Data We Process

Data we collect directly from you: - Contact data: name, email address, phone number, job title/position - Company data: company name, company type, tax ID, country, industry - Message content: any information you provide in contact forms, support tickets, or communications - Account data: email, name, role, permissions, profile picture (for registered users) - Payment data: billing address, payment method details (processed by our payment providers, not stored by us) Data we collect automatically: - Usage data: IP address, browser type and version, operating system, device information, pages visited, time and date of visits, time spent on pages - Analytics data: anonymized usage patterns, feature usage statistics, error logs (anonymized where possible) - Cookie data: see our Cookie Policy for details Data we receive from third parties: - Referral data: information from partners or resellers who refer you to us - Public sources: company information from public registers (e.g., e-cgj.hu) for lead enrichment

4. Purpose of Processing

We process your personal data for the following purposes: - Respond to contact and sales requests — Contact data, company data, message content — Consent (Art. 6(1)(a)), Contract preparation (Art. 6(1)(b)) - Prepare and deliver proposals, quotes, and contracts — Contact data, company data, message content — Contract preparation (Art. 6(1)(b)) - Provide and maintain the SaaS platform service — Account data, usage data, message content — Contract performance (Art. 6(1)(b)) - Provide on-premise software support and maintenance — Account data, usage data, error logs — Contract performance (Art. 6(1)(b)) - Communicate about services, updates, and security notices — Contact data, account data — Legitimate interests (Art. 6(1)(f)) - Send marketing communications (with consent) — Contact data, company data — Consent (Art. 6(1)(a)) - Improve our services and platform functionality — Usage data, analytics data — Legitimate interests (Art. 6(1)(f)) - Ensure platform security and prevent fraud — Usage data, IP address, error logs — Legitimate interests (Art. 6(1)(f)), Legal obligation (Art. 6(1)(c)) - Comply with legal obligations (accounting, tax, regulatory) — Contact data, company data, payment data — Legal obligation (Art. 6(1)(c)) - Respond to legal requests and protect our rights — All relevant data categories — Legal obligation (Art. 6(1)(c)), Legitimate interests (Art. 6(1)(f))

5. Legal Basis for Processing

The legal bases for our processing activities under GDPR Article 6 are: - Consent (Article 6(1)(a)): When you submit the contact form, subscribe to newsletters, or opt-in to marketing communications - Contract performance (Article 6(1)(b)): To respond to requests, prepare proposals, and provide/maintain our services - Legal obligation (Article 6(1)(c)): To comply with accounting, tax, regulatory and other legal requirements - Legitimate interests (Article 6(1)(f)): To improve our services, ensure platform security, communicate about service updates, and conduct analytics You have the right to withdraw consent at any time (where processing is based on consent) by contacting us at privacy@archipm.com.

6. Our Role: Controller vs. Processor

When we are the Data Controller: We act as the data controller for personal data collected through: - Our website (archipm.com) - Contact forms and sales inquiries - Marketing and communications - Our own business operations (e.g., customer relationship management) When we are the Data Processor: When you use ArchiPM-Nexus as a SaaS service or with on-premise support, we process personal data on behalf of your organization as a data processor. In such cases: - Your organization is the data controller and determines the purposes and means of processing - We process data only according to your instructions and under a Data Processing Agreement (DPA) - We do not use your data for our own purposes except as necessary to provide the service - We implement appropriate technical and organizational measures to protect your data If you are using our services as an organization, please refer to the DPA we have signed (or will sign) with your organization for detailed processor obligations. A template DPA is available upon request at privacy@archipm.com.

7. Data Sharing and Disclosure

Service Providers (Sub-processors): We engage third-party service providers to help us operate our business and deliver our services. These providers have access to personal data only to perform specific tasks on our behalf and are obligated to protect your data. Current sub-processors include: Cloud Hosting (EU), Email Services (EU), Analytics (EU/US with SCCs), Customer Support (EU/US with SCCs), Payment Processing (EU/US with SCCs), Error Monitoring (EU/US with SCCs). We maintain an up-to-date list of sub-processors at archipm.com/subprocessors, which we update quarterly. By using our services, you agree to our engagement of these sub-processors. International Data Transfers: Where personal data is transferred to third parties outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as: - Standard Contractual Clauses (SCCs) approved by the European Commission - EU-US Data Privacy Framework (DPF) certification (where applicable) - Binding Corporate Rules (BCRs) (where applicable) We do not transfer personal data to countries without adequate protection unless appropriate safeguards are implemented. Other Disclosures: We may disclose personal data in the following circumstances: - Legal requirements: To comply with legal obligations, respond to court orders, or cooperate with law enforcement - Business transfers: In connection with a merger, acquisition, or sale of assets (you will be notified via email or prominent notice on our website) - Protection of rights: To protect our rights, property, or safety, or the rights, property, or safety of others

8. Data Storage and Retention

Data Storage Location: Your personal data is stored on servers located within the European Union. We use EU-based data centers for all primary storage and processing. Retention Periods: We retain personal data only as long as necessary for the purposes described in this policy: - Contact form data: Until the request is fully resolved, plus 5 years (applicable limitation period under Hungarian law) - Account data (active users): For the duration of the service relationship - Account data (inactive users): Up to 3 years after account inactivity, then deleted or anonymized - Usage data and analytics: Up to 12 months - Marketing data (with consent): Until consent is withdrawn, plus 3 years for legitimate follow-up - Payment and billing data: 8 years (Hungarian accounting law requirement) - Error logs and security data: Up to 12 months After the retention period expires, data is securely deleted or anonymized so that it can no longer be linked to you.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Technical Measures: - Encryption in transit: TLS 1.3 for all data transmission - Encryption at rest: AES-256 encryption for stored data - Access control: Role-based access control (RBAC) and principle of least privilege - Authentication: Multi-factor authentication (MFA) and single sign-on (SSO) options - Network security: Firewalls, intrusion detection/prevention systems (IDS/IPS) - Data residency: All data stored within the EU - Audit trails: Full audit logging on all data changes and access - Regular backups: Daily encrypted backups with 30-day retention Organizational Measures: - Security policies: Documented information security policies and procedures - Employee training: Regular security and privacy awareness training for all employees - Access reviews: Periodic review of employee access rights - Incident response: Documented data breach response plan - Vendor management: Security assessments of all sub-processors - Regular audits: Internal and external security assessments (including penetration testing) For more details, see our Security page.

10. Your Data Protection Rights

Under the GDPR, you have the following rights regarding your personal data: - Right of access (Article 15): Request a copy of your personal data - Right to rectification (Article 16): Request correction of inaccurate or incomplete data - Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten") - Right to restriction of processing (Article 18): Request limitation of processing in certain circumstances - Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format - Right to object (Article 21): Object to processing based on legitimate interests or direct marketing - Right to withdraw consent: Withdraw consent at any time (where processing is based on consent) - Right to lodge a complaint: File a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, naih.hu) How to Exercise Your Rights: You can exercise your rights by: - Email: privacy@archipm.com - Postal address: ArchiFM Operation Zrt., 1031 Budapest, Záhony utca 7., Hungary - Through the platform: Access, update, and export your personal data directly through your account settings We will respond to your request within 30 days of receipt. In complex cases, this period may be extended by up to 60 days, and we will notify you of any such extension. We do not charge a fee for exercising your rights, except in cases of manifestly unfounded or excessive requests, where we may charge a reasonable fee or refuse to act.

11. Cookies

What are Cookies? Cookies are small text files stored on your device when you visit our website. They help us provide a better user experience, analyze site traffic, and understand how you use our services. Types of Cookies We Use: - Essential cookies: Necessary for website functionality (e.g., session management, security) — Session to 1 year - Analytics cookies: Help us understand how visitors use our website (anonymized) — Up to 2 years - Functional cookies: Remember your preferences (e.g., language, cookie consent) — Up to 1 year - Marketing cookies: Used for targeted advertising (only with your consent) — Up to 2 years Cookie Consent: We use a cookie consent banner when you first visit our website. You can: - Accept all cookies: Allow all cookie types - Reject all cookies: Allow only essential cookies - Customize: Choose which cookie categories to allow You can change your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website. Managing Cookies: You can control cookies through your browser settings. Most browsers allow you to view and delete individual cookies, block third-party cookies, block all cookies (may affect website functionality), and clear cookies when you close your browser. Note: Blocking certain cookies may affect the functionality of our website.

12. Data Breaches

Regulatory Notification: In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. Customer Notification: If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will notify affected data subjects without undue delay (Article 34 GDPR). For B2B customers: In addition to regulatory notifications, we will notify affected customers without undue delay (typically within 24-48 hours) of becoming aware of a breach that may impact their data. We will: - Provide details of the nature of the breach - Describe the categories and approximate number of data subjects and records affected - Provide the name and contact details of our DPO or privacy contact - Describe the likely consequences of the breach - Describe the measures taken or proposed to address the breach and mitigate its effects We will cooperate fully with customers in their internal incident response and provide all necessary information to fulfill their own notification obligations. Our Commitment: We maintain a documented data breach response plan and conduct regular incident response drills to ensure we can respond quickly and effectively to any security incident.

13. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals, as defined in Article 22 of the GDPR. Any analytics or machine learning features in our platform (e.g., predictive maintenance, usage recommendations) are used for operational and service improvement purposes only and do not make decisions that significantly affect you without human intervention. If we introduce any automated decision-making features in the future, we will update this policy and provide you with information about the logic involved, as well as the significance and envisaged consequences of such processing.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. How We Notify You: - Website posting: We will post the updated policy on this page with a new "Last updated" date - Email notification: For material changes, we will notify you via email (if you have provided one) - Platform notification: For significant changes affecting our services, we may notify you through the ArchiPM-Nexus platform Your Continued Use: Your continued use of our services after the effective date of the updated policy constitutes your acceptance of the changes. If you do not agree with the updated policy, please discontinue use of our services and contact us to discuss your options. We recommend reviewing this policy periodically to stay informed about how we protect your data.

15. Contact Us

If you have any questions, concerns, or requests about this Privacy Policy or our data protection practices, please contact us: Email: privacy@archipm.com Email: info@archipm.com Postal address: ArchiFM Operation Zrt. 1031 Budapest, Záhony utca 7. Hungary Supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH) Website: naih.hu Email: ugyfelszolgalat@naih.hu We will respond to your request within 30 days of receipt.

16. Additional Resources

- Data Processing Agreement (DPA) Template — Available upon request - Sub-processors List — Updated quarterly - Security Overview — Our security measures and certifications - Cookie Policy — Detailed information about cookies - Terms of Service — Our terms of use This Privacy Policy is written in English and Hungarian. In case of any discrepancy, the English version shall prevail.