Privacy Policy
Effective: 2026 · Under Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on information.
This notice describes the processing of personal data in connection with the Social Media Director service operated by Virtual Director Kft. (the “Service Provider”).
1. The data controller
Virtual Director Kft. (registered seat: Kossuth Lajos utca 103, 6792 Zsombó, Hungary; company reg. no.: 06-09-030284; tax no.: 32755235-2-06), e-mail: molnar.zoltan@virtualdirector.hu. The Service Provider is not required to appoint a Data Protection Officer; privacy questions can be addressed to the e-mail above.
2. The Service Provider’s dual role
Social Media Director is a multi-tenant SaaS, so the Service Provider processes personal data in two distinct roles:
- As a data controller for the data of subscribers (account owners and their users) — this notice applies here.
- As a data processor for the data that a subscriber (the “Tenant”) enters or manages through the system about its own audience, about individuals appearing in uploaded images, or about persons associated with its connected social accounts. For that data the Tenant is the controller and the Service Provider acts solely on its instructions, under the Data Processing Agreement (DPA).
3. Data processed, purposes, legal bases, retention
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account data (name, e-mail, password hash, company name) | Registration, sign-in, providing the service | Performance of a contract — Art. 6(1)(b) | For a reasonable period after the account is closed |
| Connected social account data: Facebook Page, Instagram and LinkedIn Page identifiers and names, and the Meta and LinkedIn access tokens (stored encrypted) | Maintaining the connection needed for publishing and analytics | Performance of a contract — Art. 6(1)(b) | Until the channel is disconnected / the account is closed |
| Content: post texts, AI prompts, uploaded and AI-generated images, scheduling data | Creating, approving, scheduling and publishing posts | Performance of a contract — Art. 6(1)(b) | Until the account is closed / a deletion request |
| Identifiers of published posts, performance/engagement analytics (from the platform API) | Analytics, reporting, AI evaluation | Performance of a contract — Art. 6(1)(b) | Until the account is closed / a deletion request |
| Balance and AI-usage transactions | Accounting of hybrid pricing | Performance of a contract — Art. 6(1)(b) | Within the statutory accounting period |
| Billing data, payment history | Payment, invoicing, statutory accounting | Legal obligation — Art. 6(1)(c) | 8 years under the Hungarian Accounting Act |
| Usage logs, IP address | Security, abuse prevention, debugging | Legitimate interest — Art. 6(1)(f) | Short, until the purpose is achieved |
| Marketing outreach (if any) | Newsletter, product information | Consent — Art. 6(1)(a) | Until consent is withdrawn |
4. Use of data obtained from social platforms
The Service Provider uses data obtained from connected platforms (Meta / Facebook / Instagram, and LinkedIn) — including access tokens, Page/profile identifiers and performance analytics — solely to provide the service to the User. This data is not sold and is not used for any purpose unrelated to the service, and it is never used for advertising targeting or sales purposes. This is consistent with the data-use restrictions of the Meta Platform Terms and the LinkedIn API Terms of Use. Access tokens are stored encrypted; when a channel is disconnected or access is revoked at the platform, the stored token is deleted.
5. Images and the persons appearing in them
Images uploaded by the User may depict identifiable persons (a likeness qualifies as personal data). For such data the User is the controller and warrants that it has an appropriate legal basis and, where necessary, the consent of the data subjects to use the images. During AI-based image and text generation, the prompts and the uploaded content are transmitted to OpenAI as a data processor (see section 6).
6. Data processors (sub-processors)
To provide the service, the Service Provider uses the following data processors:
| Processor | Activity | Location / safeguard |
|---|---|---|
| RackForest Zrt. | Server hosting (application, database) | EU / Hungary |
| OpenAI, L.L.C. / OpenAI Ireland Ltd. | AI post and image generation (processing prompts) | EU / USA (SCC). Does not train on API data. |
| Meta Platforms Ireland Ltd. | Publishing and retrieving analytics to/from Facebook/Instagram (Graph API) | EU / USA (DPF, SCC) |
| LinkedIn Ireland Unlimited Company (Microsoft) | Publishing and retrieving analytics to/from LinkedIn (Marketing / Community Management API) | EU / USA (DPF, SCC) |
| Cloudflare, Inc. | DNS, CDN, marketing-site hosting, R2 object storage (uploaded and generated images) | USA (EU-US DPF) |
| Microsoft Ireland Operations Ltd. | Transactional e-mail (Microsoft 365) | EU |
| Google LLC | Encrypted offsite backup | USA (EU-US DPF) |
| Stripe Payments Europe / Stripe, Inc. | Card payment, subscription management | EU / USA (DPF, SCC) |
| KBOSS.hu Kft. (Számlázz.hu) | Tax-compliant invoicing | EU / Hungary |
Card data is handled exclusively by Stripe (PCI-DSS); the Service Provider has no access to it.
7. Transfers to third countries
Processors operating (also) in the USA (OpenAI, Meta, Stripe, Cloudflare, Google) provide appropriate safeguards under the EU–US Data Privacy Framework and/or the European Commission’s Standard Contractual Clauses (SCC).
8. Rights of the data subject
- to information and access,
- to rectification,
- to erasure (“right to be forgotten”),
- to restriction of processing,
- to data portability,
- to object (for processing based on legitimate interest and for direct marketing),
- to withdraw consent at any time.
These rights can be exercised at molnar.zoltan@virtualdirector.hu; the Service Provider fulfils requests without undue delay, at the latest within 1 month. Deletion of the account and data is governed separately by Data & account deletion.
9. Data security
The Service Provider applies measures under Article 32 GDPR, in particular: tenant-level data isolation, encrypted transmission (HTTPS/TLS), one-way storage of passwords (hashing), encrypted storage of platform access tokens, daily encrypted backups, and access restriction.
10. Data breach
In the event of a personal data breach, the Service Provider notifies the supervisory authority without undue delay and, where feasible, within 72 hours, and — in the case of a high risk — the data subjects.
11. Remedies
A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, Falk Miksa utca 9-11, 1055 Budapest, Hungary; ugyfelszolgalat@naih.hu), or a court may be addressed.