Privacy Policy
1. Data controller
Controller: ZERO ONE CONCEPT KFT.. Registered office, company identifiers, privacy contact and—if applicable—data protection officer details: [TO BE COMPLETED].
2. Data we may process
Depending on enabled functions, OUTCORA may process registration email, account identifier, authentication/security metadata, subscription and invoice metadata, support correspondence, language/preferences, technical logs, and consent records. Full payment-card data should be handled by the selected payment provider rather than stored by OUTCORA.
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Account creation and service delivery | Performance of contract / steps requested before contract |
| Billing, accounting and statutory records | Legal obligation |
| Security, fraud prevention and service integrity | Legitimate interests, subject to balancing |
| Optional analytics or marketing cookies | Consent where required |
| Support communications | Contract and/or legitimate interests depending on context |
4. Processors and recipients
Authentication, hosting, email, payment, invoicing, analytics and support providers must be listed here once selected, including relevant international-transfer safeguards where applicable: [TO BE COMPLETED BEFORE LAUNCH].
5. Retention
Retention periods must be specified by data category. Account data should be retained only as long as necessary for the account and applicable legal claims; statutory accounting records follow mandatory retention rules. Detailed periods: [TO BE COMPLETED].
6. Your rights
Subject to the GDPR and applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests should be sent to [PRIVACY EMAIL]. Individuals may also lodge a complaint with the competent supervisory authority.
7. Cookies and similar technologies
Strictly necessary technologies may be used for security and account operation. Optional analytics/marketing technologies should not be activated before valid consent where consent is required. A production cookie inventory and consent-management configuration are [TO BE COMPLETED].
8. Security
OUTCORA should apply data minimization, encryption in transit, secure authentication, access control, logging and appropriate retention controls. Security measures evolve with technical risk.
9. Changes to this notice
Material changes should be dated and communicated where required. Last draft update: 9 August 2026.
