Legal

Privacy Policy

Effective date: July 16, 2026 · Last updated: July 16, 2026

This Privacy Policy explains how Pixel Ranger Studio Kft. processes personal data in connection with the flowone.pro website and the FlowOne.PRO business platform.

FlowOne.PRO is provided exclusively to businesses, companies, public institutions, nonprofit organisations, sole traders and other professional customers. It is not offered to consumers for personal or household use.

1. Data controller

For personal data processed in connection with the flowone.pro website, customer administration, contractual relationships, billing, service security and business communications, the data controller is:

  • Full legal name: Pixel Ranger Studio Korlátolt Felelősségű Társaság
  • Short name: Pixel Ranger Studio Kft.
  • Registered office: 2721 Pilis, Attila utca 37., Hungary
  • Company registration number: 13-09-161686
  • Tax number: 24245896-2-13
  • Website: www.pixelranger.hu
  • Email: robert@pixelranger.hu

Pixel Ranger Studio Kft. is referred to in this Privacy Policy as the "Operator," "we," "us" or "our."

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data relating to:

  • visitors to the flowone.pro website;
  • persons who contact us;
  • prospective customers;
  • customer representatives;
  • customer administrators;
  • authorised users of FlowOne.PRO;
  • suppliers, contractors and business partners; and
  • persons whose data is processed for security, support, billing or contractual purposes.

This Privacy Policy does not independently determine how a Customer may process personal data contained in its mailboxes, files, calendars, projects, contacts, chats or other Customer-controlled content.

For such data, the relevant Customer generally acts as the data controller and Pixel Ranger Studio Kft. acts as a data processor.

3. Our role as controller and processor

3.1 When we act as data controller

We act as an independent data controller when we determine the purposes and means of processing, including in relation to:

  • operation and security of our public website;
  • business inquiries and commercial proposals;
  • customer and supplier administration;
  • account and subscription administration;
  • billing, accounting and taxation;
  • contractual communications;
  • technical support records;
  • fraud and abuse prevention;
  • infrastructure and security logs;
  • enforcement of our agreements;
  • establishment, exercise or defence of legal claims; and
  • compliance with legal obligations.

3.2 When we act as data processor

When FlowOne.PRO is used by a Customer to store or process email, files, projects, calendar entries, contacts, chat messages or other business content, the Customer generally determines:

  • what personal data is processed;
  • whose data is processed;
  • why the data is processed;
  • who may access the data;
  • how long the data must be retained; and
  • when the data should be deleted or exported.

In these circumstances:

  • the Customer acts as data controller;
  • we act as data processor;
  • we process the data only on documented Customer instructions, except where processing is required by law; and
  • the processing is governed by the applicable agreement and Data Processing Agreement.

We do not independently determine the business purposes for which Customer-controlled content is processed.

4. We do not routinely inspect Customer content

We do not routinely read, review, monitor, classify or analyse the content of Customer email, files, chats, projects or documents.

Our monitoring is primarily limited to technical and infrastructure information required to operate and secure the Service, such as:

  • server availability;
  • CPU, memory and storage usage;
  • service status;
  • network availability;
  • database health;
  • backup status;
  • replication status;
  • error rates;
  • authentication events;
  • security events;
  • suspected spam, malware or abuse indicators;
  • system logs; and
  • platform performance.

Automated technical systems may process message or file information where necessary to provide requested functionality, including:

  • spam and phishing detection;
  • malware scanning;
  • message routing;
  • search indexing;
  • backup and recovery;
  • delivery reporting;
  • user-configured rules;
  • security filtering; and
  • system automation.

Such automated technical processing does not mean that our employees routinely inspect Customer content.

5. When Customer content may be accessed

Authorised personnel may access limited Customer information only where reasonably necessary to:

  • investigate a technical fault;
  • respond to a support request;
  • restore data at the Customer’s request;
  • investigate suspected unauthorised access;
  • investigate spam, phishing, malware or abuse;
  • prevent harm to the Service or third parties;
  • comply with a lawful and binding authority request;
  • protect the Operator’s legal rights; or
  • perform another task expressly authorised by the Customer.

Access is limited according to role and operational necessity.

Where reasonably possible, we use logs, metadata, system diagnostics and information provided by the Customer before accessing content.

The Customer is responsible for ensuring that any instruction authorising access is lawful.

6. Categories of personal data

Depending on how a person interacts with us or the Service, we may process the following categories of personal data.

6.1 Website and technical data

  • IP address;
  • date and time of access;
  • requested page or resource;
  • browser type and version;
  • operating system;
  • referring page;
  • device and connection information;
  • request and response information;
  • cookie or session identifiers;
  • security events; and
  • server and application logs.

6.2 Contact and business communication data

  • name;
  • business email address;
  • telephone number;
  • company or organisation;
  • job title;
  • message content;
  • attachments;
  • communication history; and
  • information voluntarily provided to us.

If you contact us through the live chat widget on our website, we process the name you provide, your email address (optional), your messages, the page the chat was started from and related technical data (IP address, browser identifier). This data is used solely to answer your inquiry and is not used for marketing without your separate consent. Inactive chat sessions are closed after 30 days, at which point the stored IP address is deleted.

6.3 Customer and contractual data

  • company name;
  • registered office;
  • billing address;
  • tax number;
  • company registration number;
  • representative details;
  • contractual contact details;
  • selected services and modules;
  • commercial proposals;
  • agreements;
  • orders;
  • licence information;
  • invoice details;
  • payment status; and
  • support and service history.

6.4 Account and user data

  • name;
  • business email address;
  • username;
  • internal account identifier;
  • Customer organisation;
  • user role;
  • permissions;
  • account status;
  • authentication information;
  • multi-factor authentication status;
  • login timestamps;
  • IP addresses;
  • device and browser information;
  • password-reset events; and
  • administrative actions.

We do not store passwords in readable form.

6.5 Support and security data

  • support requests;
  • diagnostic information;
  • system events;
  • authentication events;
  • audit logs;
  • administrative actions;
  • IP addresses;
  • abuse reports;
  • spam and phishing reports;
  • malware indicators;
  • delivery logs;
  • error reports;
  • backup and restoration records; and
  • information required to investigate an incident.

6.6 Demo account data

Where a demonstration environment is provided, we may process:

  • account information entered by the user;
  • demonstration messages;
  • test files;
  • projects;
  • settings;
  • activity information; and
  • technical logs.

Demo environments must not be used to upload confidential, sensitive or production data unless we expressly agree otherwise in writing.

6.7 Customer-controlled content

Depending on the modules used, FlowOne.PRO may process Customer-controlled content including:

  • email messages and attachments;
  • sender and recipient information;
  • contacts;
  • calendar entries;
  • files and documents;
  • projects and tasks;
  • team messages;
  • comments;
  • audit records;
  • workflow data;
  • integration data; and
  • other information submitted by or on behalf of the Customer.

For this content, the Customer normally acts as controller and we act as processor.

7. Sources of personal data

We may obtain personal data:

  • directly from the person concerned;
  • from the Customer;
  • from a Customer administrator;
  • from the person’s employer or organisation;
  • from authorised users;
  • through use of our website or Service;
  • from connected systems or integrations;
  • from technical and security systems;
  • from email senders and recipients;
  • from public company registers;
  • from contractual partners; or
  • from competent public authorities.

Where a Customer provides personal data to us, the Customer is responsible for ensuring that it has a lawful basis for doing so and has provided any required information to the affected individuals.

8. Purposes and legal bases

We process personal data for the following purposes and legal bases.

8.1 Website operation and security

Purpose:

  • delivering website content;
  • maintaining secure operation;
  • identifying faults;
  • preventing attacks;
  • maintaining logs; and
  • protecting our systems and legal interests.

Legal basis: our legitimate interests under Article 6(1)(f) GDPR.

Our legitimate interests include operating a secure, reliable and functional business website.

8.2 Responding to inquiries

Purpose:

  • responding to questions;
  • arranging demonstrations;
  • preparing commercial proposals;
  • discussing potential services; and
  • maintaining business correspondence.

Legal basis:

  • steps taken before entering into a contract under Article 6(1)(b) GDPR, where applicable; or
  • our legitimate interests in managing business communications under Article 6(1)(f) GDPR.

8.3 Customer and contract administration

Purpose:

  • entering into and managing agreements;
  • administering customer relationships;
  • delivering services;
  • managing authorised contacts;
  • processing orders;
  • handling renewals; and
  • enforcing contractual rights.

Legal basis:

  • performance of a contract or pre-contractual steps under Article 6(1)(b) GDPR where the data subject is a party to the contract;
  • legitimate interests under Article 6(1)(f) GDPR where the Customer is a legal entity and the data relates to its representatives, employees or contacts; and
  • legal obligations under Article 6(1)(c) GDPR where applicable.

8.4 User and account administration

Purpose:

  • creating and managing accounts;
  • authenticating users;
  • assigning permissions;
  • enabling platform access;
  • maintaining security;
  • recording administrative actions; and
  • providing requested functionality.

Legal basis:

  • our legitimate interests and those of the Customer in providing and securing the business Service under Article 6(1)(f) GDPR;
  • performance of a contract under Article 6(1)(b), where applicable; or
  • processing on behalf of the Customer under the Data Processing Agreement.

8.5 Technical operation, monitoring and support

Purpose:

  • monitoring server and platform health;
  • preventing service disruption;
  • investigating technical errors;
  • providing support;
  • maintaining backups;
  • detecting unauthorised access;
  • preventing spam, malware and abuse; and
  • improving reliability and security.

Legal basis:

  • our legitimate interests in operating and protecting the Service under Article 6(1)(f) GDPR;
  • performance of contractual obligations under Article 6(1)(b), where applicable;
  • compliance with legal obligations under Article 6(1)(c); or
  • processing on the Customer’s instructions as a processor.

8.6 Billing, accounting and taxation

Purpose:

  • issuing invoices;
  • processing payments;
  • maintaining accounting records;
  • managing outstanding amounts;
  • satisfying tax requirements; and
  • responding to audits.

Legal basis: compliance with legal obligations under Article 6(1)(c) GDPR and performance of a contract under Article 6(1)(b), where applicable.

8.7 Fraud, abuse and legal claims

Purpose:

  • detecting fraud;
  • investigating misuse;
  • enforcing acceptable-use rules;
  • protecting infrastructure and email reputation;
  • responding to disputes;
  • establishing, exercising or defending legal claims; and
  • cooperating with authorities where legally required.

Legal basis:

  • legitimate interests under Article 6(1)(f) GDPR;
  • compliance with legal obligations under Article 6(1)(c); or
  • establishment, exercise or defence of legal claims.

9. Legitimate interests

Where processing is based on legitimate interests, those interests may include:

  • operating a B2B technology platform;
  • maintaining security and service availability;
  • protecting systems, users and third parties;
  • preventing fraud, spam, malware and abuse;
  • communicating with customers and prospective customers;
  • administering business relationships;
  • maintaining records of contractual communications;
  • investigating technical faults;
  • improving reliability;
  • enforcing agreements; and
  • establishing or defending legal claims.

We consider the necessity and proportionality of such processing and the reasonable expectations of the affected individuals.

10. Required information

Certain personal data is required to:

  • respond to an inquiry;
  • prepare a commercial proposal;
  • enter into an agreement;
  • create an account;
  • authenticate a user;
  • issue an invoice;
  • provide technical support;
  • secure the Service; or
  • comply with legal obligations.

Where required information is not provided, we may be unable to respond, conclude a contract, create an account or provide some or all of the Service.

11. Cookies and similar technologies

The flowone.pro marketing website does not use advertising cookies or behavioural advertising technologies unless this Privacy Policy and any applicable cookie notice are updated accordingly.

The website may use technical cookies or similar local-storage technologies strictly necessary for:

  • session management;
  • security;
  • language settings;
  • user-interface preferences;
  • login functionality; and
  • maintaining the operation of the website.

Strictly necessary technologies may be used without consent where permitted by law.

If non-essential analytics, advertising or third-party tracking technologies are introduced, they will be activated only in accordance with applicable consent requirements.

Some embedded third-party content may independently process technical information such as an IP address. Where such content is used, additional information will be provided where required.

12. Hosting and data location

Our primary Service infrastructure is intended to be located within the European Economic Area.

Depending on the Customer’s selected deployment model, data may be stored or processed on:

  • infrastructure operated by us;
  • infrastructure dedicated to the Customer;
  • infrastructure owned or controlled by the Customer; or
  • infrastructure provided by contracted hosting and data-centre providers.

The specific hosting arrangement may be described in the Customer’s individual agreement, technical documentation or Data Processing Agreement.

We do not guarantee that every technical transmission or supporting service remains entirely within Hungary.

13. International data transfers

Some service providers, device notification services, integrations or technical partners may operate outside the European Economic Area or may be part of international corporate groups.

Where personal data is transferred outside the European Economic Area, we use an available lawful transfer mechanism where required, such as:

  • an adequacy decision;
  • European Commission Standard Contractual Clauses;
  • additional contractual and technical safeguards; or
  • another transfer mechanism permitted by applicable law.

Further information about relevant safeguards may be requested using the contact details in this Privacy Policy.

Customer-selected integrations may result in data being transferred to providers selected or authorised by the Customer. The Customer is responsible for assessing such integrations where it determines their use.

14. Recipients and service providers

We do not sell personal data.

We do not provide Customer content to third parties for advertising purposes.

Personal data may be disclosed to the following categories of recipients where necessary:

  • hosting and data-centre providers;
  • infrastructure and backup providers;
  • security and monitoring providers;
  • email, messaging and notification providers;
  • domain and DNS providers;
  • accounting and invoicing providers;
  • banks and payment providers;
  • legal, tax and professional advisers;
  • software and technical support providers;
  • Customer-authorised integration providers;
  • subcontractors assisting with Service delivery;
  • competent courts, authorities and law-enforcement bodies; and
  • other recipients where disclosure is required by law.

Service providers may process personal data only for the agreed purposes and subject to applicable contractual and confidentiality obligations.

Where we act as a processor, subprocessors are used in accordance with the applicable Data Processing Agreement.

15. Disclosure to authorities

We may disclose personal data where required by:

  • applicable law;
  • a binding court order;
  • a valid authority request;
  • a legal obligation; or
  • a lawful requirement necessary to protect persons, systems or legal rights.

We do not voluntarily provide unrestricted access to Customer data.

Where legally permitted and reasonably possible, we may notify the affected Customer before responding to a request concerning Customer-controlled data.

16. Security

We use technical and organisational measures intended to provide a level of security appropriate to the relevant risks.

Depending on the Service and deployment model, these measures may include:

  • encryption in transit;
  • encryption at rest for supported systems;
  • encrypted backups;
  • access controls;
  • role-based permissions;
  • multi-factor authentication;
  • audit logging;
  • system monitoring;
  • network security;
  • malware and spam protection;
  • backup and recovery systems;
  • access restrictions;
  • infrastructure isolation;
  • software updates; and
  • incident-response procedures.

Security measures may vary depending on:

  • the selected service package;
  • deployment architecture;
  • Customer-controlled infrastructure;
  • Customer configuration;
  • technical feasibility; and
  • the individual agreement.

No internet-connected service, hosting environment, email system or storage system can be guaranteed to be completely secure, continuously available or immune from unauthorised access.

17. Customer security responsibilities

The Customer is responsible for the security and lawful use of:

  • its user accounts;
  • passwords;
  • authentication devices;
  • administrator accounts;
  • end-user devices;
  • local networks;
  • Customer-managed servers;
  • domains and DNS under its control;
  • third-party integrations selected by the Customer;
  • access permissions;
  • imported data;
  • account creation and deletion;
  • employee access; and
  • instructions given to the Operator.

The Customer must:

  • use strong and unique credentials;
  • enable available multi-factor authentication;
  • restrict administrator privileges;
  • remove access when no longer required;
  • maintain secure devices and networks;
  • notify us promptly of suspected compromise;
  • ensure that its own processing is lawful; and
  • maintain any Customer-side backups required by the applicable agreement.

We are not responsible for incidents resulting from Customer actions or omissions, compromised Customer credentials, Customer-managed infrastructure, unauthorised users, unsupported modifications or third-party services selected by the Customer, except to the extent mandatory law provides otherwise.

18. Personal data breaches

Where we act as data controller, we will assess personal data breaches and make notifications required by applicable law.

Where we act as data processor, we will notify the relevant Customer without undue delay after becoming aware of a confirmed personal data breach affecting data processed on that Customer’s behalf, as required by the applicable Data Processing Agreement and applicable law.

The Customer, as controller, is responsible for:

  • assessing the risks to affected individuals;
  • deciding whether notification to a supervisory authority is required;
  • deciding whether affected individuals must be informed;
  • providing legally required notices; and
  • complying with controller obligations.

We may provide reasonable assistance as required by the applicable Data Processing Agreement.

A technical event, attempted attack, security alert or service interruption does not automatically constitute a personal data breach.

19. Limitation of responsibility

We take reasonable measures to secure and operate the Service, but we do not guarantee that:

  • unauthorised access will never occur;
  • every cyberattack can be prevented;
  • every vulnerability will be detected before exploitation;
  • Customer data will never be corrupted or lost;
  • third-party systems will remain secure or available;
  • messages will always be delivered;
  • every backup will contain every individual item;
  • Customer-controlled devices or infrastructure will remain secure; or
  • the Service will be continuously available without interruption.

To the fullest extent permitted by applicable law, we are not responsible for loss, damage, disclosure, alteration, unavailability or destruction of data resulting from:

  • Customer actions or omissions;
  • weak, reused, disclosed or compromised credentials;
  • Customer users or administrators;
  • Customer-selected access permissions;
  • Customer-controlled infrastructure;
  • Customer-controlled devices or networks;
  • unsupported changes or configurations;
  • Customer-selected integrations;
  • external service providers outside our reasonable control;
  • malware introduced by the Customer or its users;
  • unlawful Customer content;
  • authority action;
  • force majeure;
  • internet or telecommunications failures;
  • attacks that could not reasonably have been prevented; or
  • a failure by the Customer to maintain backups where backup responsibility belongs to the Customer.

Nothing in this Privacy Policy excludes or limits obligations or liability that cannot lawfully be excluded or limited under the GDPR or other applicable law.

Any contractual limitation of liability is governed by the applicable Terms and Conditions and individual Customer agreement.

20. Data retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, legal obligations, contractual requirements, security requirements and legal claims.

Typical retention periods include the following.

20.1 Website and server logs

Website, application and routine technical logs are generally retained for up to 90 days.

Logs may be retained longer where necessary to:

  • investigate a security incident;
  • investigate abuse;
  • resolve a technical problem;
  • comply with law; or
  • establish or defend a legal claim.

20.2 Business inquiries

General inquiries and related correspondence may be retained for up to one year after the matter is closed.

Information may be retained longer where:

  • a contractual relationship follows;
  • the correspondence is relevant to a legal claim;
  • longer retention is required by law; or
  • continued retention is reasonably necessary for business administration.

20.3 Customer and contractual records

Customer contacts, agreements, orders and contractual communications may be retained for the duration of the business relationship and thereafter for the period required to establish, exercise or defend legal claims.

20.4 Accounting records

Invoices and accounting records are retained for the period required by applicable Hungarian accounting and tax laws.

20.5 Account information

Account and user information is generally retained for the duration of the active account or Customer relationship.

Limited account, audit and security information may be retained after account closure where necessary for:

  • security;
  • fraud prevention;
  • dispute resolution;
  • contractual enforcement; or
  • legal compliance.

20.6 Support records

Support requests and related technical information may be retained for the duration of the Customer relationship and for a reasonable period afterward to document work performed, recurring problems and contractual compliance.

20.7 Demo account data

Demo account content is deleted regularly, typically within 30 days, unless a different period is communicated to the user.

Demo data may be deleted at any time without prior notice.

Users must not rely on demo environments for permanent storage.

20.8 Customer-controlled content

Customer-controlled content is retained according to:

  • the Customer’s instructions;
  • the applicable agreement;
  • configured retention settings;
  • the selected service package; and
  • applicable law.

Following termination, Customer content may be:

  • made temporarily available for export;
  • deleted from active systems;
  • retained for a limited transition period; or
  • deleted according to the contractual termination procedure.

Unless otherwise agreed, the Customer is responsible for exporting required content before termination.

20.9 Backups

Deleted information may remain in protected backup copies until the relevant backup expires under the normal backup-retention cycle.

Backups are not ordinarily modified to remove individual records immediately.

Backup data is restricted and is used primarily for disaster recovery, continuity and security purposes.

21. Data accuracy

We take reasonable steps to keep personal data accurate where we act as controller.

Customer administrators are responsible for maintaining the accuracy of user, account and organisation information submitted through the Service.

The Customer is responsible for the accuracy and lawfulness of Customer-controlled content.

22. Data subject rights

Subject to the conditions and limitations of the GDPR, individuals may have the right to:

  • receive information about processing;
  • request access to personal data;
  • request correction of inaccurate data;
  • request completion of incomplete data;
  • request erasure;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain data in a portable format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority; and
  • seek a judicial remedy.

These rights are not absolute. A request may be limited or refused where permitted or required by law, including where processing is necessary for:

  • legal obligations;
  • contractual records;
  • security;
  • fraud prevention;
  • protection of third-party rights; or
  • establishment, exercise or defence of legal claims.

23. Exercising rights

Requests concerning personal data for which Pixel Ranger Studio Kft. acts as controller may be submitted to robert@pixelranger.hu.

We may request information necessary to verify the identity and authority of the requester.

We generally respond within one month, subject to any lawful extension available for complex or numerous requests.

Requests are generally processed free of charge. A reasonable fee may be charged, or action may be refused, where a request is manifestly unfounded or excessive, particularly because of its repetitive nature, where permitted by law.

24. Requests concerning Customer-controlled data

Where personal data is contained in a Customer’s mailbox, files, contacts, calendar, projects, chats or other Customer-controlled content, the request should normally be submitted directly to that Customer.

Examples include requests from:

  • an employee concerning an employer-provided mailbox;
  • a former employee concerning company records;
  • a recipient concerning an email stored by a Customer;
  • a project participant concerning Customer-managed project data; or
  • a contact whose information is stored in a Customer address book.

In such cases, the Customer is normally responsible for deciding how the request should be handled.

We will not independently delete, disclose, modify or export Customer-controlled content without:

  • instructions from the relevant Customer;
  • a valid legal requirement; or
  • another lawful basis.

Where appropriate, we may forward the request to the relevant Customer or inform the requester that the Customer should be contacted.

25. Automated processing

FlowOne.PRO may use automated technical processes including:

  • spam detection;
  • phishing detection;
  • malware scanning;
  • security filtering;
  • message routing;
  • automatic rules;
  • search indexing;
  • workflow automation;
  • authentication-risk analysis; and
  • Customer-configured actions.

These processes are used to provide, protect and automate the Service.

We do not use Customer content to train artificial-intelligence or machine-learning models.

As an independent controller, we do not normally use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning an individual.

Customers are responsible for Customer-configured automation and for determining whether their use of automated functionality complies with applicable law.

26. Children

FlowOne.PRO is a B2B platform and is not directed to children.

We do not knowingly offer individual consumer accounts to children.

A Customer may process information relating to minors only where the Customer has a lawful basis and complies with all applicable legal requirements. In such circumstances, the Customer acts as controller and remains responsible for that processing.

27. Supervisory authority and remedies

Individuals may lodge a complaint with the Hungarian supervisory authority:

  • Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság — NAIH)
  • Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
  • Postal address: 1363 Budapest, Pf. 9., Hungary
  • Website: www.naih.hu

Individuals may also seek a judicial remedy before a competent court.

We encourage individuals to contact us first so that we have an opportunity to investigate and resolve the issue.

28. Changes to this Privacy Policy

We may update this Privacy Policy where necessary to reflect:

  • changes to the Service;
  • changes to processing activities;
  • new infrastructure or service providers;
  • legal or regulatory developments;
  • security requirements; or
  • changes to our business operations.

The current version will be published on this page with an updated revision date.

Where a change materially affects existing Customer relationships, we may also provide notice through email, the Service or another appropriate communication channel.

Contact

For questions, privacy requests or concerns relating to this Privacy Policy, contact Pixel Ranger Studio Kft., 2721 Pilis, Attila utca 37., Hungary — robert@pixelranger.hu