Privacy Policy
Last updated: 2026-07-09
1. Who we are
Controller: Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) (registered address: 8200 Veszprém, Haszkovó utca 31/A 4/13, reg. no.: 59535834, e-mail: privacy@werklo.net) — "Werklo", "we".
This policy covers the personal data we process as controller: visitors of werklo.net, registered merchants (tenants) and their staff users. For the customer data of shops run on Werklo (shop buyers), the merchant — not Werklo — is the controller, and decides the purposes and means of that processing (e.g. what they sell, what checkout fields they require). Werklo acts purely as the merchant’s processor for that data, strictly on the merchant’s documented instructions, under the Data Processing Agreement (https://www.werklo.net/dpa).
If you are a buyer in a shop run on Werklo, please read that shop’s own privacy policy first: the merchant is the controller of your data, and this policy only explains Werklo’s role as the merchant’s processor and Werklo’s own processing. Requests concerning your data in a shop are best addressed to the merchant; if you send them to us, we forward them to the merchant concerned.
As processor for shop buyers, the categories of personal data we host and transmit on the merchant’s behalf are: buyer name, e-mail address and phone number; shipping and billing address; order contents and custom product specifications; payment and shipping references (not full card numbers, which Stripe alone holds); invoices issued to the buyer; and any messages the buyer sends the merchant through the shop’s chat or support tools. This data is used only to run the merchant’s shop, never for Werklo’s own purposes.
During support and troubleshooting, authorised Werklo staff may access a merchant’s tenant data — which can include shop-buyer personal data — to the extent necessary to resolve the issue. Such access happens as processing on the merchant’s documented instructions under the DPA, is limited to what the specific issue requires, and support communication itself (which may quote such data) is retained as described in Section 2.
We process personal data under Regulation (EU) 2016/679 (GDPR) and Hungarian law (Infotv.). The Hungarian version of this policy is authoritative.
2. What we process, why and on what legal basis
– Account data (name, e-mail, password hash, shop name): providing the service, contract performance — GDPR Art. 6(1)(b). Retained while your account exists.
– Billing data (invoicing name, address, tax number, subscription and payment history): issuing invoices and accounting — legal obligation, Art. 6(1)(c) (Hungarian Accounting Act: 8 years).
– Payment card data: processed exclusively by Stripe; Werklo never receives or stores card numbers.
– Support communication: handling your requests — legitimate interest, Art. 6(1)(f). Retained up to 5 years (limitation period).
– Technical logs (IP address, timestamps, requests): security, abuse prevention — legitimate interest, Art. 6(1)(f). Retained up to 30 days.
– Product e-mails about your own subscription (trial expiry, invoices, service notices): contract performance, Art. 6(1)(b). Marketing e-mails are only sent with your prior consent (Art. 6(1)(a); Hungarian Grt. 6. §) and every such e-mail includes an unsubscribe option.
– Website analytics: cookieless Umami measurement, aggregated statistics only — legitimate interest, Art. 6(1)(f). See the Cookie Policy.
Whether you must provide the data: account and billing data is a contractual requirement — without it we cannot create your account, provide the service or issue invoices; billing data is additionally a statutory requirement (invoicing and accounting law). Technical logs arise automatically from using the service. Everything else (support requests, marketing consent) is optional: not providing it only means we cannot deliver the related function, and consent can always be refused or withdrawn without affecting the service.
Where we rely on legitimate interest (support history, technical logs, analytics), the interest pursued is operating, securing and improving the service; given the limited scope and retention of this data, we have assessed that it does not override your rights and freedoms. You have the right to object to any processing based on legitimate interest at any time (see Section 7) — we then stop unless we demonstrate compelling legitimate grounds.
3. Processors and recipients (sub-processors)
The full, current sub-processor table is also published in the Data Processing Agreement at https://www.werklo.net/dpa. Summary — name, purpose, location, transfer mechanism:
Supabase Inc. (AWS eu-central-1, Frankfurt) — database, authentication, file storage — EU — no transfer needed.
Vercel Inc. — application hosting, edge network — EU / US — Standard Contractual Clauses (SCCs).
Railway Corp. — hosts our self-managed analytics (Umami), error tracking (GlitchTip) and uptime monitoring (Uptime Kuma) instances; we operate these tools ourselves, they are not separate sub-processors for the data they collect. Umami, Uptime Kuma and the GlitchTip application itself run in Railway’s EU (Amsterdam) region. GlitchTip’s attachment storage bucket (error report file attachments) currently runs in Railway’s US West region, since object storage buckets can’t be moved after creation — EU / US, Standard Contractual Clauses. Error capture is configured so that request bodies and personal data are excluded from error reports, and attachments are not used to store personal data; migrating this bucket to the EU is planned.
Stripe Payments Europe Ltd. — platform subscription billing (your own connected Stripe account, if any, is your own processor, not ours) — EU.
Resend (Plus Five Five, Inc.) — transactional e-mail delivery — US — SCCs.
Cloudflare, Inc. — DNS, network security — EU / US — SCCs.
Szamlazz.hu / KBOSS.hu Kft. — our own platform invoicing — EU (Hungary).
We notify merchants of intended sub-processor changes at least 30 days in advance, per the DPA.
We do not sell personal data and do not share it with third parties for their own marketing.
4. Security measures
TLS 1.2+ encryption in transit on all endpoints; encryption at rest for the database (managed by Supabase/AWS); application-level AES-256-GCM encryption for merchant API credentials; Row-Level Security enforcing tenant data isolation in the shared database; access to production credentials restricted to authorised personnel; payment card data is never stored on Werklo systems (handled by Stripe, PCI-DSS). Full detail in the DPA, Art. 32 section.
5. Automated decision-making and data source
We do not carry out automated decision-making or profiling within the meaning of GDPR Art. 22 that produces legal or similarly significant effects on you.
We collect personal data directly from you (registration, account use, support requests) or, for account activity, automatically through your use of the platform (see Section 2). We do not purchase or receive your personal data from third-party data brokers.
6. Data Protection Officer
Werklo has not appointed a Data Protection Officer, as one is not mandatory under GDPR Art. 37 given the scale and nature of our processing (no large-scale systematic monitoring, no large-scale processing of special categories of data). Data protection queries can still be sent to privacy@werklo.net.
7. Your rights
You may request access to, rectification, erasure or restriction of your personal data, withdraw consent at any time, and receive your data in a portable format (GDPR Art. 15-20).
Right to object (GDPR Art. 21): where processing is based on our legitimate interest (Section 2), you may object at any time on grounds relating to your particular situation. We then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Where data were to be used for direct marketing, you may object at any time without any justification and we stop that use immediately.
To exercise your rights, write to privacy@werklo.net. We respond within one month.
You can delete your account and shop yourself in the admin panel (Settings). This takes your storefront offline immediately, but your data is only permanently deleted 30 days later — log back in any time within that window to cancel the deletion. Order data that we must retain by law (8 years, Hungarian Accounting Act) is anonymised instead of deleted, whether at your request or after the 30-day window. Deleted tenants’ database backups age out and are overwritten on our standard backup rotation, typically within 35 days of deletion; uploaded files (e.g. product images) are deleted on the same schedule and their storage backups follow the same rotation, so residual backup copies are typically gone within 35 days as well.
8. Complaints
If you believe your data is processed unlawfully, you may lodge a complaint with the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu — or with the supervisory authority of your own EU member state, and you may turn to court.
9. Data breach notification
If a personal data breach affecting your data occurs, we will notify the competent supervisory authority within 72 hours where required by Art. 33 GDPR, and will notify affected merchants without undue delay so they can meet their own notification duties towards their customers.
10. Changes
We may update this policy; material changes are announced by e-mail or in the admin panel at least 15 days in advance. Current version: https://www.werklo.net/privacy.