Privacy Policy
Last updated: May 20, 2026
1. Introduction and Data Controller
In accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (General Data Protection Regulation, hereinafter: GDPR), the following information is provided regarding data processing in connection with the getdispatchy.com website and the Dispatchy email marketing and automation software.
By using the Website and the application, the data subject declares that they have reached the age of 16. Persons under the age of 16 may not register on the Website, use the service, or subscribe to the newsletter, given that under Article 8(1) of the GDPR, the validity of their declaration of consent to data processing requires the permission of their legal representative. The Data Controller is unable to verify the age and eligibility of the consenting person, so the data subject warrants that the data provided is genuine.
Data Controller Details
- Name: SYNTAX-ENCODE Kft.
- Headquarters: 8105 Pétfürdő, Móricz Zs.u.17., Hungary
- Premises: 8105 Pétfürdő, Liszt Ferenc utca 9., Hungary
- Company Registration Number: 19-09-517832
- Tax Number: 25290569-2-19
- E-mail: adatvedelem@getdispatchy.com
2. Scope of the Policy
- Temporal scope: This Policy is effective from May 20, 2026, until further notice or withdrawal. The Data Controller reserves the right to modify the information, notifying users on the website 15 days before the changes take effect.
- Personal scope: Applies to the Data Controller (SYNTAX-ENCODE Kft.), visitors using the Dispatchy system, registered clients (Workspace owners), and their representatives and subscribers.
- Material scope: Applies to all personal data processed electronically by the Data Controller in the SaaS software infrastructure and on the getdispatchy.com internet portal and subpages.
3. Data Processing, Purpose, Legal Basis, and Duration
| Type of Data Processing | Purpose | Legal Basis | Processed Data | Retention Period |
|---|---|---|---|---|
| Workspace Account Registration | Providing SaaS service, operating the administration interface, authentication. | Performance of a contract | Name, email address, password (encrypted). | Until account deletion, or 5 years after the termination of the contractual relationship. |
| Managing Subscribers (Mailing Lists) | Sending email campaigns and automations on behalf of the user (as Data Controller). | Data Processing Agreement | Email address, name, language, custom metadata, interaction history (opens, clicks). | Until deletion by the Workspace owner, or upon account termination. |
| Billing Information | Invoicing the value of purchased plans and services. | Legal obligation | Billing name, address, tax number (for companies). | Strictly 8 years in accordance with the Accounting Act. |
| Online Card Payment | Secure processing of subscription transactions in the Stripe system. | Performance of a contract | Cardholder name, email address, transaction amount, identifier. | 8 years from payment (accounting certification). |
| Contact and Support | Answering and resolving inquiries, complaints, and support tickets. | Consent of the data subject | Name, email address, message content, screenshots. | 30 days after answering the question, 3 years in case of a complaint. |
* In the absence of mandatory data, the Data Controller cannot provide the service.
4. Profiling
The Data Controller informs the Data Subjects that during the operation of the Dispatchy platform, it does NOT carry out profiling or automated decision-making on Workspace owners. In the case of subscribers (Mailing Lists), the system allows Workspace owners to create dynamic segments (e.g., "opened the email"), but the purpose and means of this profiling and data processing are entirely determined by the Workspace owner (as Data Controller), with Dispatchy solely providing the technical platform (as Data Processor).
5. Data Processors
In order to operate the Dispatchy cloud-based software securely, stably, and lawfully, the Data Controller uses external partners (Data Processors).
| Name of Data Processor | Activity | Scope of Transmitted Data |
|---|---|---|
| Amazon Web Services EMEA SARL | AWS SES - Providing email sending infrastructure and delivery. | Subscribers' email addresses, email contents, delivery logs. |
| Stripe Payments Europe, Ltd. | Online credit card acceptance and subscription management. | Name, email address, transaction amount (Dispatchy does not store card data). |
| Neon, Inc. | Secure cloud-based Serverless PostgreSQL database service. | All database records managed by Dispatchy. |
| Vercel Inc. | Software application hosting, static and dynamic cloud infrastructure. | IP address, browser type, traffic metadata (to serve the website). |
| Functional Software, Inc. (Sentry) | Application-level error tracking, performance monitoring. | Metadata of error messages, IP address, browser data. |
6. Data Transfer
The Dispatchy platform does not transfer or sell personal data to third parties other than the above Data Processors (advertising agencies, data brokers, etc.), unless required by a court or administrative decision.
7. Cookie Management
The Dispatchy website and application use cookies in the visitor's browser to ensure the basic operation of the system and to remember settings.
- Account session: Identification of the user's logged-in session (essential).
- next-intl-locale: Remembering your chosen interface language.
- Stripe Cookies: For the secure handling of payment processes (essential).
8. Rights of Data Subjects and Remedies
Under the GDPR, you may exercise the following rights during the entire duration of data processing at the contact details of the Data Controller (adatvedelem@getdispatchy.com):
- Right of access: You may request information about data processing.
- Right to rectification: You may request the correction of your data.
- Right to erasure: You may request the deletion of your data (unless precluded by law, e.g., invoices).
- Right to data portability: You may request the release of your personal data in a machine-readable format.
Legal Remedies
If you believe that the processing of your personal data has violated the provisions of the GDPR, you can file a report with the authority:
- National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- E-mail: ugyfelszolgalat@naih.hu | Website: www.naih.hu
9. Security of Data Processing
During the design and operation of the Dispatchy platform, the Data Controller ensures the protection of the processed personal data with the highest level of technical and organizational precautions:
- Confidentiality: All data transmission is secured with strong, modern SSL/TLS encryption between the browser and the servers.
- Data Integrity: User passwords are stored exclusively with one-way, secure (bcrypt) hashing. Even the company's employees cannot access raw passwords.
- Availability: Redundant backup of cloud servers and databases ensures quick recovery.
Although 100% security of data transmitted over the internet cannot be technologically guaranteed, SYNTAX-ENCODE Kft. takes all reasonable precautions to avoid data leaks, and in the event of an incident, informs the data subjects within the deadline prescribed by the GDPR.