Draft · effective 11 September 2026

Privacy notice

Launch action required. Replace every bracketed item with the actual operator and processor information and obtain Hungarian/EU legal review before offering the product to customers. This draft does not itself establish compliance.

1. Who controls your data

The controller is [operator legal name], registered at [registered address], registration number [number], tax number [number] (“DMX.HU”, “we”, “us”). Contact: hello@dmx.hu. Data protection contact or DPO, if appointed: [details].

2. Scope

This notice covers the public DMX.HU website, the authenticated lighting console, account administration, support, security logging, Art-Net output and the optional LightKnight bridge. It does not govern third-party services that you independently configure or operate.

3. Data we process

Activity and dataPurpose and legal basisRetention
Public page requests. Requested page, request time, a per-request reference and a short-lived pseudonymous visit identifier. Public traffic measurement does not use a browser identifier, advertising ID, fingerprint or cross-site history.Service security, abuse prevention, capacity planning and aggregate traffic measurement. Legitimate interests under GDPR Article 6(1)(f): operating and protecting the service. The identifier is deliberately limited so it cannot be used to follow a browser over time.30 days, followed by deletion. Aggregate statistics that no longer relate to an identifiable person may be kept longer.
Infrastructure logs. Limited technical request and security data may include IP address, time, requested resource, response information and basic browser information.Delivering requests, troubleshooting, incident response and defending the service. Legitimate interests under GDPR Article 6(1)(f), and legal obligation where a specific law requires preservation.Normally no more than 15 days, unless a security incident or lawful request requires restricted preservation.
Account data. Email address, display name, account permissions and status, authentication information, login time and policy acceptance records.Creating and operating your account and performing the service contract, GDPR Article 6(1)(b); security and administration, Article 6(1)(f); and applicable legal obligations, Article 6(1)(c).While the account exists, then [define account deletion and legally required retention period].
Access-control data. Limited network, device and session information, access timestamps, security actions and audit records. This may include an IP address or a shortened part of it where needed to control or investigate access.Authentication, access control, misuse detection and incident investigation. Contract performance and legitimate interests in service security.Authentication lasts up to 12 hours. Session-security records are deleted 30 days after expiry or revocation. Audit records: [insert justified retention period].
Console content. Saved shows, fixture and cue information, playback settings, output configuration and service status.Providing the requested console, Article 6(1)(b). Operational diagnostics and service integrity, Article 6(1)(f).For the account lifetime and [insert backup/deletion period]. Temporary running services may end after disconnection without deleting saved content.
Integration data. The destination, selected resource and access credential supplied when you configure an external integration.Providing the integration you request, Article 6(1)(b).Until you remove the saved credential, close the account, or [insert inactive-account deletion period].
Communications and transactions. Messages, support history, quotation and billing information if you contact us or purchase a service.Responding to you, taking pre-contractual steps, performing a contract, meeting tax/accounting duties, and establishing or defending legal claims.[Insert support, invoicing and statutory accounting periods.]

We conservatively treat the limited visit identifier as pseudonymous personal data while it is retained. It is not represented as fully anonymous merely because identifying information has been reduced.

4. Cookies and browser storage

Public visitors receive no analytics, advertising or visitor-identification cookie, and the site does not use browser storage for traffic measurement. The server records page requests as described above. If you sign in, the console sets strictly necessary authentication and anti-forgery cookies. See the cookie notice for the exact inventory.

5. Recipients and international transfers

Access is limited to authorized operator personnel and processors needed to host, secure, back up and support the service: [list hosting provider, data-centre country, backup provider, email/support provider and each processor’s role]. We do not sell personal data or use it for cross-site advertising.

If data is transferred outside the EEA, we will identify the destination and use an applicable adequacy decision, Standard Contractual Clauses with supplementary measures, or another lawful safeguard: [insert actual transfer details and how to obtain a copy]. Destinations configured by console users must be systems they are authorized to use.

6. Automated controls

Automated security controls may limit excessive requests or end invalid sessions. Administrators may suspend accounts for security or misuse. We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

7. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. Contact hello@dmx.hu. We may need proportionate information to verify a request.

You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11, Hungary, www.naih.hu, or another competent supervisory authority.

8. Security and your responsibilities

We use proportionate technical and organizational safeguards designed to protect accounts, stored content and credentials. No internet service is completely secure. Keep credentials private, restrict network access, and do not place unnecessary personal data in show names or configuration fields.

9. Changes and contact

We will date material revisions and provide additional notice where required. Questions and rights requests may be sent to hello@dmx.hu.