MyForge LabsHUNew project ↗
myforge-workspacecompany / privacy-policy.md

Legal

Privacy Policy

Protecting your personal data is of utmost importance to us.

Last Updated: November 15, 2023

1. Introduction and General Information

MyForge Labs (hereinafter: "we", "us", or "Company") is committed to protecting your personal data and complying with applicable data protection laws. This privacy policy provides information on how we collect, use, store, and protect your personal data when using our website, as well as your rights concerning your data.

This notice explains the website’s data flows. Visiting the website does not grant consent to optional analytics or chat.

Data Controller Details

Name: MyForge Labs Kft.
Registered Seat: 1118 Budapest, Maléter Pál utca 2., Hungary
Company Registration Number: 01-09-450429
Tax Number: 32937800-2-43
Email: 11.11@myforgelabs.com
Phone: +36 20 942 6529

Applicable Legislation

Our data protection practices are governed by the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR)
  • Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.)
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities

2. What Data We Collect and Why

Our Company may collect different types of data about you, depending on how you interact with us or use our services.

Data Collected Directly from You

Depending on which feature you use, you may provide:

  • Contact form: name, email address, selected topic, message and acknowledgement of the privacy notice.
  • Calculator and quote requests: selected services, estimated prices and the contact details provided, including a phone number if entered.
  • Newsletter: the email address entered in the subscription form.
  • NDA: name, optional company name, email address and the PDF of the accepted agreement.
  • Chat: messages you send in the conversation. Please do not provide sensitive information.

Contact and newsletter forms send their data to a Google Apps Script endpoint, together with the language, source-page address and submission time. The NDA PDF is created in your browser, then sent to our server endpoint for processing the email request.

Data Collected Automatically

Google Analytics 4 loads only after analytics consent. We can then measure page views and events related to use of the website. Our own event parameters do not include the name, email address or message entered in a form.

Consent choices are saved in your browser's local storage. The external support-chat connection starts only after separate chat consent and explicit launch. Fonts load locally.

Legal Basis for Data Collection

We process your personal data based on the following legal grounds:

  • Performance of a contract: When you contract for our services, data processing is necessary to fulfill the contract.
  • Legitimate interest: We process certain data based on our legitimate interests, such as operating our websites, developing our services, and marketing activities.
  • Consent: Sending marketing communications is based on your explicit consent.
  • Compliance with a legal obligation: In some cases, we need to process data to comply with our legal obligations (e.g., retaining billing data).

3. Use of Data

We use the data collected from you for the following purposes:

  • Providing Services: Delivering requested services, fulfilling quote requests, providing customer support.
  • Communication: Responding to your questions, informing you about changes or updates related to our services.
  • Fulfilling Contractual Obligations: Processing your orders, delivering services, invoicing.
  • Website Improvement: Analyzing the use of our website and services to improve them.
  • Marketing: Sending customized offers and information about our services, if you have consented.
  • Legal Compliance: Complying with relevant legal and regulatory requirements.
  • Security: Preventing fraud, maintaining IT security, preventing data loss.

Data Retention Period

We retain your personal data only for as long as necessary to achieve the purposes mentioned above, or as required by law:

  • Contract-related data: during the contract term and for 5 years thereafter (civil law limitation period).
  • Billing data: for 8 years according to accounting legislation.

The Cookie Policy describes browser-preference and cookie storage durations. Contact us by email with questions or deletion requests concerning information submitted through a form.

4. Sharing Data with Third Parties

We do not sell or rent your personal data to third parties. However, in certain cases, we may share your data with third parties belonging to the following categories:

Service Providers and Data Processors

The website implements these data-submission paths:

  • Google Apps Script: receiving endpoint for contact and newsletter form data.
  • Google Analytics 4: website measurement subject to analytics consent.
  • Chatwoot at mfl.support: support conversations started separately.
  • Our server-side endpoints: processing NDA PDF email requests and messages sent through the separate AI chat page.

Our own website serves the font files. Saving a marketing consent choice alone does not mean a Google Ads or Meta Pixel integration is installed.

Legal Compliance and Obligations

We may also share your data if:

  • Required by law or a court order
  • Necessary to protect our rights or property
  • Necessary to prevent or investigate fraud, abuse, or security incidents
  • Necessary to protect the vital interests of you or other individuals

Business Transfers

In the event of a business merger, acquisition, or sale of our assets, your personal data may be transferred to the new owner. In such cases, we will take all reasonable steps to ensure the new owner also complies with the provisions of this privacy policy.

International Data Transfers

Some of our service providers operate outside the European Economic Area (EEA). If we transfer your data to such countries, we apply appropriate safeguards to protect the data, such as:

  • Data transfers to countries approved by the European Commission's adequacy decisions
  • Use of EU Standard Contractual Clauses
  • Certification mechanisms and codes of conduct

5. Data Security

We are committed to protecting your personal data and take appropriate technical and organizational measures to ensure data security.

Technical Measures

To protect data, we implement the following security measures:

  • SSL/TLS encryption on our website and during data transmission
  • Use of firewalls and intrusion detection systems
  • Data encryption at rest
  • Regular security backups
  • Regular software updates and application of security patches
  • Access control to personal data (principle of least privilege)

Organizational Measures

In addition to our technical solutions, we apply the following organizational measures:

  • Regular data protection training for our employees
  • Employee data protection and confidentiality obligations
  • Development of data protection processes and procedures
  • Regular internal data protection audits
  • Development and adherence to an incident response protocol

Handling Data Breaches

In the event of a data breach (e.g., unauthorized access, data leak, data loss), we take the following steps:

  • Immediate investigation of the incident
  • Assessment and mitigation of the incident's impact
  • Notification of the incident to the supervisory authority (NAIH - Hungarian National Authority for Data Protection and Freedom of Information) within 72 hours if it poses a risk to the rights of natural persons
  • Direct notification of affected individuals if the incident poses a high risk to their rights and freedoms
  • Documentation of the incident and implementation of necessary measures to prevent future incidents

Although we are committed to protecting your data, it's important to know that data transmission over the internet can never be 100% secure. Therefore, we encourage you to take precautions to protect your personal data (e.g., using strong passwords, secure internet connections).

6. Use of Cookies

Analytics, marketing and chat choices are handled separately. GA4 does not load without analytics consent; the Chatwoot connection starts only after separate chat consent and use of the chat button.

mfl-consent stores the choice in your browser's localStorage, with no automatic expiry. GA4 uses _ga and _ga_<id> cookies; their actual expiry depends on service and browser settings.

Use Privacy in the bottom bar to change or withdraw your choice. Stopping services that have already loaded may reload the page. A marketing preference alone does not mean an advertising pixel is installed.

Read the Cookie Policy for local storage and offline-cache details.

mfl.ide.layout.v1: Stores panel sizes, the selected sidebar, terminal view, layout, content zoom, interface density and theme in your own browser. It contains no form text or command history and is not sent to a server.

7. User Rights Regarding Data

Under applicable data protection laws (especially GDPR), you have various rights regarding your personal data:

  • Right of access: You have the right to request information about whether we process your personal data and, if so, access to that data.
  • Right to rectification: You have the right to request the correction of inaccurate personal data and the completion of incomplete data.
  • Right to erasure ('right to be forgotten'): Under certain circumstances, you have the right to request the deletion of your personal data (e.g., if the data is no longer necessary for the purpose for which it was collected).
  • Right to restriction of processing: Under certain circumstances, you have the right to request that we restrict the processing of your personal data (e.g., if you contest the accuracy of the data).
  • Right to data portability: You have the right to receive the personal data we process about you in a structured, machine-readable format and to transmit this data to another controller.
  • Right to object: You have the right to object to the processing of your personal data if it is based on legitimate interest or public authority, including profiling.
  • Rights related to automated decision-making and profiling: You have the right not to be subject to a decision based solely on automated processing that significantly affects you.
  • Right to withdraw consent: If our data processing is based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Exercising Your Rights

To exercise your rights, please contact us at 11.11@myforgelabs.com or via the contact methods listed below. We will respond to your request within 30 days; in exceptional cases, this period may be extended by an additional 60 days, of which we will inform you.

Right to Lodge a Complaint

If you feel that our data processing does not comply with legal requirements, you can lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság - NAIH)
Postal address: 1363 Budapest, Pf.: 9.
Address: 1055 Budapest, Falk Miksa utca 9-11.
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: https://naih.hu/

You are also entitled to turn to the courts if your rights are violated. The case falls within the competence of the regional court, which may also be the court of your residence or place of stay, at your choice.

8. Changes to the Privacy Policy

We may update our privacy policy from time to time to reflect changes in legal requirements, our practices, or the introduction of new services. The current privacy policy will always be available on our website.

In case of significant changes, we will post a notice on our website and, where appropriate, inform affected individuals via email. We recommend that you regularly review our privacy policy to stay informed about how we handle your data.

Last updated date of the privacy policy: November 15, 2023.

Previous Versions

Previous versions of the privacy policy are available upon request. If you would like to view previous versions, please write to us at 11.11@myforgelabs.com.

9. Contact Us

If you have any questions, comments, or requests regarding our privacy policy or data processing practices, please contact us using the following methods:

Email: 11.11@myforgelabs.com
Phone: +36 30 848 4733
Postal Address: MyForge Labs Kft., 1118 Budapest, Maléter Pál utca 2., Hungary

Contact details of our Data Protection Officer:
Email: dpo@myforgelabs.com
Phone: +36 30 848 4733

We aim to respond to all inquiries as soon as possible, but no later than 30 days.

LOCAL DEMO

❯ bmad Research · Gemini + NotebookLM

README.mdKGC-BérlésPoparchStraborBPSETEXTURA SalonFoxxiKinda · BalanceAjánlat-radarKözösSolutionsThe teamStart a projectClaude CodeCodexGeminiBMADVisual Studio CodePlaywrightGitNotebookLMObsidian / Vault 11.11Agent skillsDiscordProject atlasDelivery labKnowledge network & fleetERP · coming soonWorkspace settings

Esc · close