Privacy
Privacy Policy
Last updated: 14 June 2026
This Privacy Policy describes how Datadeft Kft. (“we”, “us”, “CeleraTax”) collects, uses, and protects personal data in connection with the CeleraTax service. It is provided in accordance with Regulation (EU) 2016/679 (GDPR) and Regulation (EU) 2023/2854 (EU Data Act).
1. Controller and Processor Roles
1.1 Data Processor
When business customers use CeleraTax to collect accounting documents, reconcile bank transactions and invoices, send reminders, or prepare month-end workflows, we generally act as a Data Processor under Article 28 GDPR.
- We process customer data on behalf of and under the documented instructions of the customer.
- The customer determines the purposes and means of processing.
- Processing is governed by a Data Processing Agreement (DPA) where applicable.
1.2 Data Controller
We act as Data Controller for our own account, billing, communication, support, security, and website data.
2. Data We Process, Legal Basis, and Retention
| Data category | Examples | Role and legal basis | Retention |
|---|---|---|---|
| Account data | Names, work email addresses, company details, roles, access records. | Controller. GDPR Art. 6(1)(b) contract performance; Art. 6(1)(f) service administration and security. | For the contract term, then up to 2 years after account closure unless a longer legal claim or compliance period applies. |
| Billing data | Invoices, payment records, tax number, EU VAT ID, billing contacts. | Controller. GDPR Art. 6(1)(c) legal obligation; Art. 6(1)(b) contract performance. | 8 years under Hungarian accounting document retention rules. |
| Uploaded accounting documents | Invoices, receipts, bank statements, attachments, document metadata. | Processor for customer workspaces. Processed under customer instructions and the DPA. The customer determines its own GDPR legal basis. | For the subscription term, plus a 30-day retrieval period after termination unless the Order Form or DPA sets a different period. |
| Bank and reconciliation data | Transaction dates, amounts, counterparties, matching status, reconciliation notes. | Processor for customer workspaces. Processed under customer instructions and the DPA. | For the subscription term, plus a 30-day retrieval period after termination unless the Order Form or DPA sets a different period. |
| Reminder and contact data | Client contact email addresses, message templates, reminder status, deadlines, delivery metadata. | Processor for customer-configured reminders. For our direct demo and support communications: Controller under Art. 6(1)(b), Art. 6(1)(f), or Art. 6(1)(a) where consent is used. | Customer workspace data follows the subscription/DPA retention period. Direct marketing contacts are retained until withdrawal or 24 months after the last meaningful interaction. |
| Logs and security data | Audit logs, user actions, authentication events, IP-derived security metadata, system logs. | Controller for platform security and service integrity under Art. 6(1)(f); Processor where logs relate to customer workspace activity. | Generally 12 months, unless longer retention is required for security investigation, legal claims, or customer contractual obligations. |
Where we act as Processor, the customer remains responsible for determining the appropriate legal basis for its own processing activities.
3. How We Use Data
- Provide, maintain, secure, and improve CeleraTax.
- Collect documents, support reconciliation, track readiness, and send customer-configured reminders.
- Provide dashboards, exports, audit trails, and support.
- Process billing and comply with legal obligations.
- Communicate service, security, and contractual notices.
4. Data Sharing and Sub-processors
We do not sell personal data. We share data only with vendors needed to operate CeleraTax, comply with law, protect rights, or fulfil contractual obligations.
- AWS EMEA SARL - cloud infrastructure, compute, storage, and delivery in eu-central-1, Frankfurt, Germany.
- Additional sub-processors, if any, will be documented before production onboarding.
We aim to give customers reasonable prior notice before engaging new material sub-processors.
5. International Transfers
Production customer data is intended to be processed and stored in Germany, within the European Union, unless otherwise agreed in writing. If transfers outside the EU/EEA become necessary, we will use appropriate safeguards such as European Commission Standard Contractual Clauses.
6. Data Security
- Encryption in transit and at rest where supported by the underlying infrastructure.
- Least-privilege access controls and workspace-level permissions.
- Audit logging and operational monitoring.
- Backup, retention, and deletion procedures appropriate to the service plan.
- Incident response processes aligned with GDPR notification duties.
7. Data Subject Rights
Individuals may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent under GDPR.
For data processed on behalf of a CeleraTax customer, please contact that customer as Data Controller. We will assist the customer according to our DPA. For data where Datadeft Kft. is controller, contact us at privacy@celeratax.eu.
8. Data Portability and Switching
In line with EU Data Act principles, we aim to provide exports of customer data in structured, commonly used, machine-readable formats such as CSV or JSON, subject to product availability and contractual terms.
9. Cookies and Tracking
- Essential cookies may be used for authentication, security, and site functionality.
- We do not use Google Analytics, Facebook Pixel, or third-party advertising scripts on the landing page.
- Customer workspaces may use session cookies required for secure operation.
10. Contact and Complaints
Privacy contact: privacy@celeratax.eu
DPA contact: dpa@celeratax.eu
Hungarian data subjects may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH): naih.hu.