OUTCORA
Home
Terms of ServicePrivacy PolicyCancellation & Withdrawal
Legal

Privacy Policy

Draft version · updated 9 August 2026
Production legal draft. This document is intentionally not presented as final legal advice. Company identifiers, processors, billing mechanics and jurisdiction-specific wording marked as incomplete must be finalized before paid launch.

1. Data controller

Controller: ZERO ONE CONCEPT KFT.. Registered office, company identifiers, privacy contact and—if applicable—data protection officer details: [TO BE COMPLETED].

2. Data we may process

Depending on enabled functions, OUTCORA may process registration email, account identifier, authentication/security metadata, subscription and invoice metadata, support correspondence, language/preferences, technical logs, and consent records. Full payment-card data should be handled by the selected payment provider rather than stored by OUTCORA.

3. Purposes and legal bases

PurposeTypical legal basis
Account creation and service deliveryPerformance of contract / steps requested before contract
Billing, accounting and statutory recordsLegal obligation
Security, fraud prevention and service integrityLegitimate interests, subject to balancing
Optional analytics or marketing cookiesConsent where required
Support communicationsContract and/or legitimate interests depending on context

4. Processors and recipients

Authentication, hosting, email, payment, invoicing, analytics and support providers must be listed here once selected, including relevant international-transfer safeguards where applicable: [TO BE COMPLETED BEFORE LAUNCH].

5. Retention

Retention periods must be specified by data category. Account data should be retained only as long as necessary for the account and applicable legal claims; statutory accounting records follow mandatory retention rules. Detailed periods: [TO BE COMPLETED].

6. Your rights

Subject to the GDPR and applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests should be sent to [PRIVACY EMAIL]. Individuals may also lodge a complaint with the competent supervisory authority.

7. Cookies and similar technologies

Strictly necessary technologies may be used for security and account operation. Optional analytics/marketing technologies should not be activated before valid consent where consent is required. A production cookie inventory and consent-management configuration are [TO BE COMPLETED].

8. Security

OUTCORA should apply data minimization, encryption in transit, secure authentication, access control, logging and appropriate retention controls. Security measures evolve with technical risk.

9. Changes to this notice

Material changes should be dated and communicated where required. Last draft update: 9 August 2026.