Privacy Policy
Last updated: 2026-09-27
1. Who we are
Controller: Pinkóczi Kornél egyéni vállalkozó (trading as Werklo) (registered address: 8200 Veszprém, Haszkovó utca 31/A 4/13, reg. no.: 59535834, e-mail: privacy@werklo.net), referred to below as "Werklo" or "we".
This policy covers the personal data we process as controller: visitors of werklo.net, registered merchants (tenants) and their staff users. For the customer data of shops run on Werklo (shop buyers), the merchant, not Werklo, is the controller, and decides the purposes and means of that processing (e.g. what they sell, what checkout fields they require). Werklo acts purely as the merchant’s processor for that data, strictly on the merchant’s documented instructions, under the Data Processing Agreement (https://www.werklo.net/dpa).
If you are a buyer in a shop run on Werklo, please read that shop’s own privacy policy first: the merchant is the controller of your data, and this policy only explains Werklo’s role as the merchant’s processor and Werklo’s own processing. Requests concerning your data in a shop are best addressed to the merchant; if you send them to us, we forward them to the merchant concerned.
As processor for shop buyers, the categories of personal data we host and transmit on the merchant’s behalf are: buyer name, e-mail address and phone number; shipping and billing address; order contents and custom product specifications; payment and shipping references (not full card numbers, which Stripe alone holds); invoices issued to the buyer; and any messages the buyer sends the merchant through the shop’s chat or support tools; and, where the shop collects newsletter sign-ups, the buyer’s e-mail address and name together with the record of their consent (the time it was given, the page or checkout it was given on, and a one-way hash of the IP address used, kept solely to rate-limit abuse of the sign-up form). This data is used only to run the merchant’s shop, never for Werklo’s own purposes. Where the merchant has connected an e-mail marketing provider, we transmit sign-ups to it on the merchant’s instruction; that provider is the merchant’s own processor, not a Werklo sub-processor.
Depending on the features a shop uses, we also host for the merchant: buyer accounts (name, e-mail address, phone number, sign-in sessions, saved addresses and measurement profiles); loyalty point balances; product reviews (name, e-mail address, rating and text); messages sent through contact forms on the shop’s pages; withdrawal statements sent through the shop’s withdrawal form (name, e-mail address, the order number given, any note, and the time received); live-chat conversations; files a buyer uploads for a custom piece; and the shop’s visit statistics, measured cookielessly with Umami on the merchant’s behalf and kept only as aggregates. Where a form is protected against abuse (contact forms, newsletter sign-up, withdrawal form, buyer sign-in), a one-way hash of the IP address is used for rate limiting; sign-in rate-limit records are deleted after one day.
During support and troubleshooting, authorised Werklo staff may access a merchant’s tenant data, which can include shop-buyer personal data, to the extent necessary to resolve the issue. Such access happens as processing on the merchant’s documented instructions under the DPA, is limited to what the specific issue requires, and support communication itself (which may quote such data) is retained as described in Section 2.
We process personal data under Regulation (EU) 2016/679 (GDPR) and Hungarian law (Infotv.). The Hungarian version of this policy is authoritative.
2. What we process, why and on what legal basis
– Account data (name, e-mail, password hash, shop name, and the time you confirmed you are signing up as a business): providing the service, contract performance. GDPR Art. 6(1)(b). Retained while your account exists.
– EU VAT number, if you give one: checked against the European Commission’s VIES service so that reverse charge can be applied to your subscription. Legal obligation, Art. 6(1)(c) (VAT law). Kept with your billing data.
– How you found us (the campaign or referral reference in the link you signed up through, if any): measuring which channels bring merchants. Legitimate interest, Art. 6(1)(f). Retained while your account exists.
– Billing data (invoicing name, address, tax number, subscription and payment history): issuing invoices and accounting. Legal obligation, Art. 6(1)(c) (Hungarian Accounting Act: 8 years).
– Payment card data: processed exclusively by Stripe; Werklo never receives or stores card numbers.
– Support communication: handling your requests. Legitimate interest, Art. 6(1)(f). Retained up to 5 years (limitation period).
– Technical logs (IP address, timestamps, requests): security, abuse prevention. Legitimate interest, Art. 6(1)(f). Retained up to 30 days.
– Product e-mails about your own subscription (trial expiry, invoices, service notices): contract performance, Art. 6(1)(b). Marketing e-mails are only sent with your prior consent (Art. 6(1)(a); Hungarian Grt. 6. §) and every such e-mail includes an unsubscribe option.
– Website analytics: cookieless Umami measurement, aggregated statistics only. Legitimate interest, Art. 6(1)(f). See the Cookie Policy.
– Illegal content reports: if you report content or a product on a Werklo-hosted shop through the form at https://www.werklo.net/report, we process the name and e-mail address you give us, together with your report, in order to assess it, confirm receipt to you, tell you the outcome and give the merchant concerned a statement of reasons. Legal obligation, Art. 6(1)(c) (Articles 16-17 of Regulation (EU) 2022/2065, the Digital Services Act). Reports and the correspondence about them are kept for up to 5 years, as with other support correspondence.
Whether you must provide the data: account and billing data is a contractual requirement, without it we cannot create your account, provide the service or issue invoices; billing data is additionally a statutory requirement (invoicing and accounting law). Technical logs arise automatically from using the service. Everything else (support requests, marketing consent) is optional: not providing it only means we cannot deliver the related function, and consent can always be refused or withdrawn without affecting the service.
Where we rely on legitimate interest (support history, technical logs, analytics), the interest pursued is operating, securing and improving the service; given the limited scope and retention of this data, we have assessed that it does not override your rights and freedoms. You have the right to object to any processing based on legitimate interest at any time (see Section 7). We then stop unless we demonstrate compelling legitimate grounds.
3. Processors and recipients (sub-processors)
The list below is every processor we use, for both roles: the ones that handle our own controller data (your account, your billing, our e-mail) and the ones that handle shop-buyer data for a merchant. The Data Processing Agreement at https://www.werklo.net/dpa carries the narrower table that Article 28 GDPR requires: only those sub-processors that can touch shop-buyer personal data. A provider that appears here but not there is one that never receives buyer data. Name, purpose, location, transfer mechanism:
Supabase Inc. (AWS eu-west-1, Ireland), database, authentication, file storage. Data is stored in the EU. Supabase Inc. is established outside the EEA and its staff may access the service remotely for operations and support; that access is covered by the Standard Contractual Clauses in Supabase’s Data Processing Addendum.
Vercel Inc., application hosting and edge network. The application runs in Vercel’s Dublin (Ireland) region; the edge network is global. EU / US, Standard Contractual Clauses (SCCs).
Railway Corp., hosts our self-managed analytics (Umami), error tracking (GlitchTip) and uptime monitoring (Uptime Kuma) instances; we operate these tools ourselves, they are not separate sub-processors for the data they collect. Umami, Uptime Kuma and the GlitchTip application itself run in Railway’s EU (Amsterdam) region. GlitchTip’s attachment storage bucket (error report file attachments) currently runs in Railway’s US West region, since object storage buckets can’t be moved after creation. EU / US, Standard Contractual Clauses. Error capture is configured so that request bodies and personal data are excluded from error reports, and attachments are not used to store personal data; migrating this bucket to the EU is planned.
Stripe Payments Europe Ltd., platform subscription billing, EU (Ireland); onward transfers within the Stripe group are covered by Stripe’s own Data Processing Agreement (SCCs). For payments in your shop, see the Stripe Connect paragraph below.
European Commission (VIES), receives the EU VAT number you enter at sign-up so that we can check it, EU. A recipient under VAT law, not our processor.
Resend (Plus Five Five, Inc.), transactional e-mail delivery, US. SCCs.
Cloudflare, Inc., DNS, network security, EU / US. SCCs.
Szamlazz.hu / KBOSS.hu Kft., our own platform invoicing, EU (Hungary).
Eurosender SARL, 5 Place de la Gare, L-1616 Luxembourg (Luxembourg register B230321), shipping labels. Where a merchant buys a label through the platform, we buy it on Werklo’s own account with Eurosender (see Terms Section 13) and pass on the buyer’s name, delivery address, e-mail address and phone number, plus any delivery note, so that the parcel can be collected and delivered. EU (Luxembourg). No transfer outside the EEA, so no SCCs are needed. This is the one provider in the stack that receives a shopper’s address under our account rather than the merchant’s.
OpenAI Ireland Limited, optional AI first drafts of product descriptions and machine translation of storefront text, at the merchant’s request; receives only the text the merchant submits for that purpose, never buyer data. EU (Ireland): because Werklo is established in the EEA, OpenAI’s published Data Processing Addendum is entered into with its Irish entity, and any onward transfer by that entity to OpenAI affiliates outside the EEA (in particular OpenAI OpCo, LLC in the United States) is covered by OpenAI’s own Standard Contractual Clauses or an adequacy decision, not by clauses between OpenAI and Werklo. OpenAI’s published API documentation states that data sent to the OpenAI API is not used to train or improve its models unless the customer opts in, which we have not; it also states that abuse-monitoring logs are generated for all API usage and retained for up to 30 days.
TypeSafe AI, Inc., 255 California St, Suite 1300, San Francisco, CA 94117, US, optional AI matching of spreadsheet columns when a merchant imports their own product or stock file. It receives the column headings and up to five example values per column; columns that our filter recognises as contact details travel as a heading only. The file itself is never uploaded and the provider creates nothing in the shop. The filter recognises e-mail addresses, phone numbers and street addresses, but not personal names, because a "Name" column is also the commonest product-name heading there is. So a merchant who imports an order export in the belief that it is a product list can send up to five buyer names. US. Standard Contractual Clauses (Module 3 for data we pass on as a merchant’s processor, Module 2 for our own), under the provider’s published Data Processing Addendum. TypeSafe’s published privacy policy states that it will not train or fine-tune any AI or machine-learning model on customer prompts or other Input.
We notify merchants of intended sub-processor changes at least 30 days in advance, per the DPA.
Payments in a shop: the merchant’s own Stripe account is connected to Werklo through Stripe Connect. Buyers pay into the merchant’s own Stripe account; Werklo, as the Connect platform, creates those payments on the merchant’s instructions and receives their status (paid, refunded, disputed) to show on the order screens. Stripe processes the payments under its own terms with the merchant and is not our sub-processor. Other providers a merchant connects themselves are not in this list either: their invoicing provider (Szamlazz.hu, Fakturoid), their e-mail marketing provider (e.g. Mailchimp), and the social accounts they connect for publishing posts (Pinterest, Instagram, Facebook, Threads). Each of those runs on a credential the merchant holds, under the merchant’s own contract with that provider.
We do not sell personal data and do not share it with third parties for their own marketing.
4. Security measures
TLS 1.2+ encryption in transit on all endpoints; encryption at rest for the database (managed by Supabase/AWS); application-level AES-256-GCM encryption for merchant API credentials; Row-Level Security enforcing tenant data isolation in the shared database; access to production credentials restricted to authorised personnel; payment card data is never stored on Werklo systems (handled by Stripe, PCI-DSS). Full detail in the DPA, Art. 32 section.
5. Automated decision-making and data source
We do not carry out automated decision-making or profiling within the meaning of GDPR Art. 22 that produces legal or similarly significant effects on you.
We collect personal data directly from you (registration, account use, support requests) or, for account activity, automatically through your use of the platform (see Section 2). If a merchant invites you to their shop as staff, we receive your e-mail address, and the role you are given, from that merchant; we use it to send the invitation and, once you accept, to run your staff account. We do not purchase or receive your personal data from third-party data brokers.
6. Data Protection Officer
Werklo has not appointed a Data Protection Officer, as one is not mandatory under GDPR Art. 37 given the scale and nature of our processing (no large-scale systematic monitoring, no large-scale processing of special categories of data). Data protection queries can still be sent to privacy@werklo.net.
7. Your rights
You may request access to, rectification, erasure or restriction of your personal data, withdraw consent at any time, and receive your data in a portable format (GDPR Art. 15-20).
As a merchant you can also download your shop’s data yourself at any time, in a portable format, under Settings > Export your data in the admin panel.
Right to object (GDPR Art. 21): where processing is based on our legitimate interest (Section 2), you may object at any time on grounds relating to your particular situation. We then no longer process the data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms. Where data were to be used for direct marketing, you may object at any time without any justification and we stop that use immediately.
To exercise your rights, write to privacy@werklo.net. We respond within one month.
You can delete your account and shop yourself in the admin panel (Settings). This takes your storefront offline immediately, but your data is only permanently deleted 30 days later. Log back in any time within that window to cancel the deletion. Order data that we must retain by law (8 years, Hungarian Accounting Act) is anonymised instead of deleted, whether at your request or after the 30-day window. Deleted tenants’ database backups age out and are overwritten on our standard backup rotation, typically within 35 days of deletion; uploaded files (e.g. product images) are deleted on the same schedule and their storage backups follow the same rotation, so residual backup copies are typically gone within 35 days as well. The invoice itself is not anonymised: it is an accounting document, and it is retained intact, with the buyer’s name and address on it, for the full 8 years (Számviteli tv. 169. § (2); for electronic invoices, in electronic form, Áfa tv. 179. § (2)). Uploaded files are deleted from our file storage; stored invoice PDFs are excluded from that deletion for the same reason.
8. Complaints
If you believe your data is processed unlawfully, you may lodge a complaint with the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu, or with the supervisory authority of your own EU member state, and you may turn to court.
9. Data breach notification
If a personal data breach affecting your data occurs, we will notify the competent supervisory authority within 72 hours where required by Art. 33 GDPR, and will notify affected merchants without undue delay so they can meet their own notification duties towards their customers.
10. Changes
We may update this policy; material changes are announced by e-mail or in the admin panel at least 15 days in advance. Current version: https://www.werklo.net/privacy.