Privacy Policy

Effective: 2026 · Under Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on information.

This notice describes the processing of personal data in connection with the Social Media Director service operated by Virtual Director Kft. (the “Service Provider”).

1. The data controller

Virtual Director Kft. (registered seat: Kossuth Lajos utca 103, 6792 Zsombó, Hungary; company reg. no.: 06-09-030284; tax no.: 32755235-2-06), e-mail: molnar.zoltan@virtualdirector.hu. The Service Provider is not required to appoint a Data Protection Officer; privacy questions can be addressed to the e-mail above.

2. The Service Provider’s dual role

Social Media Director is a multi-tenant SaaS, so the Service Provider processes personal data in two distinct roles:

3. Data processed, purposes, legal bases, retention

DataPurposeLegal basisRetention
Account data (name, e-mail, password hash, company name)Registration, sign-in, providing the service Performance of a contract — Art. 6(1)(b)For a reasonable period after the account is closed
Connected social account data: Facebook Page, Instagram and LinkedIn Page identifiers and names, and the Meta and LinkedIn access tokens (stored encrypted)Maintaining the connection needed for publishing and analyticsPerformance of a contract — Art. 6(1)(b) Until the channel is disconnected / the account is closed
Content: post texts, AI prompts, uploaded and AI-generated images, scheduling data Creating, approving, scheduling and publishing posts Performance of a contract — Art. 6(1)(b)Until the account is closed / a deletion request
Identifiers of published posts, performance/engagement analytics (from the platform API) Analytics, reporting, AI evaluationPerformance of a contract — Art. 6(1)(b) Until the account is closed / a deletion request
Balance and AI-usage transactionsAccounting of hybrid pricing Performance of a contract — Art. 6(1)(b)Within the statutory accounting period
Billing data, payment historyPayment, invoicing, statutory accounting Legal obligation — Art. 6(1)(c)8 years under the Hungarian Accounting Act
Usage logs, IP addressSecurity, abuse prevention, debugging Legitimate interest — Art. 6(1)(f)Short, until the purpose is achieved
Marketing outreach (if any)Newsletter, product information Consent — Art. 6(1)(a)Until consent is withdrawn

4. Use of data obtained from social platforms

The Service Provider uses data obtained from connected platforms (Meta / Facebook / Instagram, and LinkedIn) — including access tokens, Page/profile identifiers and performance analytics — solely to provide the service to the User. This data is not sold and is not used for any purpose unrelated to the service, and it is never used for advertising targeting or sales purposes. This is consistent with the data-use restrictions of the Meta Platform Terms and the LinkedIn API Terms of Use. Access tokens are stored encrypted; when a channel is disconnected or access is revoked at the platform, the stored token is deleted.

5. Images and the persons appearing in them

Images uploaded by the User may depict identifiable persons (a likeness qualifies as personal data). For such data the User is the controller and warrants that it has an appropriate legal basis and, where necessary, the consent of the data subjects to use the images. During AI-based image and text generation, the prompts and the uploaded content are transmitted to OpenAI as a data processor (see section 6).

6. Data processors (sub-processors)

To provide the service, the Service Provider uses the following data processors:

ProcessorActivityLocation / safeguard
RackForest Zrt.Server hosting (application, database)EU / Hungary
OpenAI, L.L.C. / OpenAI Ireland Ltd.AI post and image generation (processing prompts) EU / USA (SCC). Does not train on API data.
Meta Platforms Ireland Ltd.Publishing and retrieving analytics to/from Facebook/Instagram (Graph API)EU / USA (DPF, SCC)
LinkedIn Ireland Unlimited Company (Microsoft)Publishing and retrieving analytics to/from LinkedIn (Marketing / Community Management API)EU / USA (DPF, SCC)
Cloudflare, Inc.DNS, CDN, marketing-site hosting, R2 object storage (uploaded and generated images)USA (EU-US DPF)
Microsoft Ireland Operations Ltd.Transactional e-mail (Microsoft 365)EU
Google LLCEncrypted offsite backupUSA (EU-US DPF)
Stripe Payments Europe / Stripe, Inc.Card payment, subscription management EU / USA (DPF, SCC)
KBOSS.hu Kft. (Számlázz.hu)Tax-compliant invoicingEU / Hungary

Card data is handled exclusively by Stripe (PCI-DSS); the Service Provider has no access to it.

7. Transfers to third countries

Processors operating (also) in the USA (OpenAI, Meta, Stripe, Cloudflare, Google) provide appropriate safeguards under the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses (SCC).

8. Rights of the data subject

These rights can be exercised at molnar.zoltan@virtualdirector.hu; the Service Provider fulfils requests without undue delay, at the latest within 1 month. Deletion of the account and data is governed separately by Data & account deletion.

9. Data security

The Service Provider applies measures under Article 32 GDPR, in particular: tenant-level data isolation, encrypted transmission (HTTPS/TLS), one-way storage of passwords (hashing), encrypted storage of platform access tokens, daily encrypted backups, and access restriction.

10. Data breach

In the event of a personal data breach, the Service Provider notifies the supervisory authority without undue delay and, where feasible, within 72 hours, and — in the case of a high risk — the data subjects.

11. Remedies

A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, Falk Miksa utca 9-11, 1055 Budapest, Hungary; ugyfelszolgalat@naih.hu), or a court may be addressed.