Privacy & Data Protection Policy
At Progressive Innovation LAB Kft. (PiLAB), data security, strict confidentiality, and regulatory compliance are foundational engineering commitments. This document outlines how we collect, process, and protect personal and enterprise data.
Client source code, system architectures, and proprietary data are stored on encrypted drives with strict role-based access control and enforced NDAs.
We never sell, rent, trade, or monetize your personal data or client telemetry to advertising networks or third-party data brokers.
You maintain full authority over your personal information, including the right to access, port, restrict, or permanently erase your data at any time.
Our primary server infrastructure and data processing pipelines operate within secure European Union data centers under strict EU regulations.
1. Data Controller Information
Official legal entity responsible for personal data processing on this website and in client engagements:
2. Scope of Data Collection
We process data necessary to operate our website, communicate with prospective clients, and deliver engineering services:
A. Website Telemetry & Usage Data
When accessing pilab.hu, web servers automatically log HTTP request data, including anonymized IP address, browser type, operating system version, referring URLs, and access timestamps.
B. Consultations & Form Submissions
When submitting contact forms, cost estimation requests, or consultation bookings, we process information provided explicitly by you: name, professional email address, phone number, company name, and project descriptions.
C. Enterprise Client Data & Credentials
During contracted software engineering engagements, PiLAB may access technical documentation, database schemas, repository codebases, and staging environments governed strictly by non-disclosure agreements (NDAs).
3. Legal Grounds under GDPR (Art. 6)
Every data processing operation conducted by PiLAB relies on explicit legal grounds under European law:
Processing necessary to execute software development agreements, client consulting projects, and technical deliverables.
Processing necessary to secure system infrastructure, mitigate cyber attacks, enforce access logs, and ensure business continuity.
Processing mandatory under Hungarian tax, corporate accounting, regulatory reporting, and commercial statutory laws.
Processing optional analytical cookies or opt-in newsletter communications, freely revocable at any time.
4. Technical & Organizational Safeguards
We enforce robust cybersecurity standards to prevent unauthorized access, data leakage, or loss:
5. Third-Party Sub-Processors
We engage trusted infrastructure vendors under Data Processing Agreements (DPAs) meeting GDPR Art. 28 standards:
| Provider | Processing Function | Data Location |
|---|---|---|
| Google Cloud Platform (EU) | Core cloud infrastructure, database hosting, & Vertex AI | Frankfurt, Germany / Eemshaven, Netherlands |
| Firebase (Google Ireland) | Authentication services & Cloud Functions microservices | Dublin, Ireland / Frankfurt, Germany |
| Cloudflare, Inc. | DDoS mitigation, Edge security (WAF), & CDN distribution | Global Edge Network (EU Data Residency) |
| Resend, Inc. | Transactional email notifications & contact request delivery | United States (EU Standard Contractual Clauses) |
6. Your Rights Under GDPR
Under Regulation (EU) 2016/679 (GDPR), you possess comprehensive legal rights regarding your personal information:
Right of Access (Art. 15)
Obtain confirmation as to whether your personal data is being processed and receive a complete copy of all personal records held by us.
Right to Rectification (Art. 16)
Request immediate correction of inaccurate, outdated, or incomplete personal data stored within our systems.
Right to Erasure (Art. 17)
Request the permanent deletion of your personal records ("Right to be Forgotten"), subject to mandatory legal compliance requirements.
Right to Restriction (Art. 18)
Request the restriction of data processing while the accuracy of your personal data or legal grounds are being verified.
Right to Portability (Art. 20)
Export and receive your personal data in a structured, commonly used, and machine-readable JSON or CSV format.
Right to Object (Art. 21)
Object at any time to the processing of your personal data based on legitimate interests or direct marketing communications.
7. Right to Lodge a Complaint
If you believe your personal data has been processed in violation of GDPR, you have the statutory right to file a complaint with the competent supervisory authority:
Submit a Data Protection Request
To exercise your GDPR rights, request a Data Subject Access Request (DSAR) export, or inquire about client non-disclosure agreements, reach out directly to our Data Protection Officer: