GDPR & EU eIDAS Compliant Data Protection

Privacy & Data Protection Policy

At Progressive Innovation LAB Kft. (PiLAB), data security, strict confidentiality, and regulatory compliance are foundational engineering commitments. This document outlines how we collect, process, and protect personal and enterprise data.

Version 2.0
Effective: August 2026
Controller: Progressive Innovation LAB Kft.
ZeroTrust Confidentiality

Client source code, system architectures, and proprietary data are stored on encrypted drives with strict role-based access control and enforced NDAs.

No Data Monetization

We never sell, rent, trade, or monetize your personal data or client telemetry to advertising networks or third-party data brokers.

Full GDPR Rights

You maintain full authority over your personal information, including the right to access, port, restrict, or permanently erase your data at any time.

Sovereign EU Storage

Our primary server infrastructure and data processing pipelines operate within secure European Union data centers under strict EU regulations.

1. Data Controller Information

Official legal entity responsible for personal data processing on this website and in client engagements:

Company Entity
Progressive Innovation LAB Kft.
Short name: PiLAB Kft.
Tax ID: HU27552941
Headquarters & Contact
1133 Budapest, Váci út 113., Hungary

2. Scope of Data Collection

We process data necessary to operate our website, communicate with prospective clients, and deliver engineering services:

A. Website Telemetry & Usage Data

When accessing pilab.hu, web servers automatically log HTTP request data, including anonymized IP address, browser type, operating system version, referring URLs, and access timestamps.

Purpose: Network security, DDoS prevention, system diagnostics, and performance optimization.

B. Consultations & Form Submissions

When submitting contact forms, cost estimation requests, or consultation bookings, we process information provided explicitly by you: name, professional email address, phone number, company name, and project descriptions.

Purpose: Responding to requests, preparing project estimates, and pre-contractual communication.

C. Enterprise Client Data & Credentials

During contracted software engineering engagements, PiLAB may access technical documentation, database schemas, repository codebases, and staging environments governed strictly by non-disclosure agreements (NDAs).

Purpose: Software architecture, cloud infrastructure provisioning, security audits, and service delivery.

3. Legal Grounds under GDPR (Art. 6)

Every data processing operation conducted by PiLAB relies on explicit legal grounds under European law:

Art. 6(1)(b) GDPR
Performance of a Contract

Processing necessary to execute software development agreements, client consulting projects, and technical deliverables.

Art. 6(1)(f) GDPR
Legitimate Interest

Processing necessary to secure system infrastructure, mitigate cyber attacks, enforce access logs, and ensure business continuity.

Art. 6(1)(c) GDPR
Legal Obligation

Processing mandatory under Hungarian tax, corporate accounting, regulatory reporting, and commercial statutory laws.

Art. 6(1)(a) GDPR
Explicit Consent

Processing optional analytical cookies or opt-in newsletter communications, freely revocable at any time.

4. Technical & Organizational Safeguards

We enforce robust cybersecurity standards to prevent unauthorized access, data leakage, or loss:

AES-256 Storage Encryption
All client work environments and databases utilize full hardware volume encryption.
TLS 1.3 Transport Security
All data transferred between clients, browsers, and cloud microservices is encrypted in transit.
Least-Privilege IAM & 2FA
Enforced multi-factor authentication and role-based access control across all infrastructure.
Air-Gapped Deployment
Isolated, air-gapped environment options available for public sector and financial institutions.

5. Third-Party Sub-Processors

We engage trusted infrastructure vendors under Data Processing Agreements (DPAs) meeting GDPR Art. 28 standards:

ProviderProcessing FunctionData Location
Google Cloud Platform (EU)Core cloud infrastructure, database hosting, & Vertex AIFrankfurt, Germany / Eemshaven, Netherlands
Firebase (Google Ireland)Authentication services & Cloud Functions microservicesDublin, Ireland / Frankfurt, Germany
Cloudflare, Inc.DDoS mitigation, Edge security (WAF), & CDN distributionGlobal Edge Network (EU Data Residency)
Resend, Inc.Transactional email notifications & contact request deliveryUnited States (EU Standard Contractual Clauses)

6. Your Rights Under GDPR

Under Regulation (EU) 2016/679 (GDPR), you possess comprehensive legal rights regarding your personal information:

Right of Access (Art. 15)

Obtain confirmation as to whether your personal data is being processed and receive a complete copy of all personal records held by us.

Right to Rectification (Art. 16)

Request immediate correction of inaccurate, outdated, or incomplete personal data stored within our systems.

Right to Erasure (Art. 17)

Request the permanent deletion of your personal records ("Right to be Forgotten"), subject to mandatory legal compliance requirements.

Right to Restriction (Art. 18)

Request the restriction of data processing while the accuracy of your personal data or legal grounds are being verified.

Right to Portability (Art. 20)

Export and receive your personal data in a structured, commonly used, and machine-readable JSON or CSV format.

Right to Object (Art. 21)

Object at any time to the processing of your personal data based on legitimate interests or direct marketing communications.

7. Right to Lodge a Complaint

If you believe your personal data has been processed in violation of GDPR, you have the statutory right to file a complaint with the competent supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal Address: 1363 Budapest, Pf. 9.
Phone: +36 1 391 1400

Submit a Data Protection Request

To exercise your GDPR rights, request a Data Subject Access Request (DSAR) export, or inquire about client non-disclosure agreements, reach out directly to our Data Protection Officer:

Follow us
All Rights Reserved
© 2011-2026
Progressive Innovation
LAB