1. The data controller and the scope of the notice
Data controller: ARKER Engineering Office Design and Consulting Limited Liability Company; short name: ARKER Engineering Office Ltd. (hereinafter: ARKER or Data Controller).
Registered office and mailing address: 7400 Kaposvár, Dózsa György Street 21.
Company registration number: 14-09-305630.
Tax number: 13153328-2-14.
Data protection contact: hello@vispertise.com.
Vispertise™ is a service and brand operated by ARKER. The notice applies to the processing of personal data relating to the vispertise.com website, the app.vispertise.com client portal, the pre-audit, the audit, orders, and related communications.
Personal data is any information relating to an identified or identifiable natural person. Data of a business company alone is not necessarily personal data, but, for example, the name of a sole proprietor, a business email address addressed to a person, or the contact person’s data may be. A pseudonymized identifier is not the same as truly anonymous data.
2. Source and scope of data
We receive data from the data subject, from the organization they represent, from payment and other technical service providers, and from public sources investigated for the purpose of the audit. These may include a business website, structured data, directories, public profiles, map-based location services, and AI responses generated during the investigation.
We may process contact and account data; name, email address, language setting; billing and payment reference data; identifiers and public business data of the audited company; audit configuration, questions, answers, source references, evaluations and reports; customer service messages; consent and contract records; as well as necessary network, session, and security data.
If data necessary for completing the order and billing is missing, the affected service cannot be provided. Refusal of optional analytics or marketing consent does not prevent the proper use of the pre-audit, the order, or the client portal.
Passwords, full bank card data, business secrets, special categories of personal data, or unnecessary third-party personal data should not be entered in the audit fields. Another person's data may only be provided with appropriate authorization and legal basis. This does not replace ARKER’s own data protection obligations.
3. Purposes and legal grounds of data processing
3.1. Inquiry, pre-audit, account, order, and fulfillment
The purpose is to provide the requested information or pre-audit, to prepare the contract, to operate the account, to link payment to the order, to prepare and deliver the audit, as well as to provide related support.
For the preparation and fulfillment of the contract with a natural person contracting in their own name, the legal basis for data processing is GDPR Article 6(1)(b). In the case of a representative or contact person of an organization, the legal basis is the legitimate interest pursuant to GDPR Article 6(1)(f): establishing and maintaining business relations, verifying representation, and fulfilling the contracted service.
The essential data of a general inquiry not related to preparation or fulfillment of a contract are processed on the basis of legitimate interest for answering the inquiry and resolving the case. When fulfilling official, consumer complaint management, or data protection obligations, the specific legal obligation applies, not general consent.
3.2. Invoicing and mandatory records
The purpose of processing invoicing data and vouchers is to fulfill accounting and tax obligations; the legal basis is GDPR Article 6(1)(c), especially obligations under Act C of 2000 on accounting. Processing of consumer complaints and the related registry is based on Section 17/A of Act CLV of 1997 on consumer protection. The legal basis for processing necessary for handling data subject requests is the fulfillment of obligations under the GDPR.
3.3. Security, abuse prevention, and legal claims
Necessary logging, authorization checks, error investigation, fraud prevention, and the enforcement or defense of legal claims are based on GDPR Article 6(1)(f). Our legitimate interest is the protection of the service, data and users, as well as the ability to verify performance and lawful operation.
3.4. Data of natural persons in public sources
If processing a natural person’s data is necessary for identifying the business or verifying its public business presence, it is carried out based on GDPR Article 6(1)(f), following documented balancing of interests. The public nature of the source alone is not a legal basis for processing. We do not use personal data that is unnecessary for the evaluation.
For personal data not obtained directly from the data subject, we provide information in accordance with Article 14 of the GDPR. The exception specified therein can only be applied if the actual conditions are met; reference to a public source does not automatically exempt the obligation to inform the data subject.
3.5. Optional analytics and notifications
The legal basis for our own visit analytics, Google Analytics, as well as onboarding and marketing notifications is the consent given for the specific purpose, pursuant to Article 6(1)(a) of the GDPR. Analytics and marketing are separate purposes. Consent may be granted and withdrawn for each purpose separately; neither is automatically implied by acceptance of the Terms and Conditions or by providing an email address.
3.6. Balancing of Interests and Use of Data for Other Purposes
When applying legitimate interest, we assess the necessity and proportionality of data processing and its impact on the rights of the data subject. Information about the essence of the assessment can be requested at the contact details provided. We will provide prior notice of any new data processing for purposes other than the original, and ensure the required legal basis.
4. External Service Providers and Recipient Categories
Employees of ARKER with the necessary authorization for task fulfillment, as well as the following service providers or categories of providers, may have access to the data. Data processor operations are regulated by appropriate contracts; an independent data controller is responsible for its own obligations. Using an external partner does not relieve ARKER of its own responsibility.
4.1. Hosting and Infrastructure
netcup GmbH; address: Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany; electronic contact: impressum@netcup.com. Within the scope of storage and infrastructure tasks necessary for services operation, data processor access is possible. The German address of the company does not in itself mean that all processing and access takes place in Germany.
Service provider privacy notice: https://www.netcup.com/en/contact/data-privacy
4.2. Payment
The selected payment provider, Barion Payment Zrt. or Stripe, processes data needed for the payment. Barion acts as an independent data controller for its payment service; Stripe may act as controller or processor depending on the processing purpose. The order ID, amount, currency, item and contact data necessary for payment may be transmitted; ARKER receives the result of the transaction. ARKER does not receive the full card number or security code. Card data processing, as well as ARKER’s own order, integration, and accounting data processing, are separate operations.
Service provider’s legal and privacy documents: https://www.barion.com/hu/jogi-hatter/ ; Stripe: https://stripe.com/legal/privacy-center
4.3. Electronic Invoicing
KBOSS.hu Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság, short name KBOSS.hu Kft., operator of Számlázz.hu. Registered office: 1031 Budapest, Záhony utca 7. Published mailing address: 1031 Budapest, Záhony utca 7/D.
Billing name, address, required tax number, item, amount, and data necessary for invoice delivery may be transferred. Technical invoicing operations performed on behalf of ARKER constitute data processing; the service provider separately performs data processing connected to its own contractual or legal obligations.
Service provider privacy policy: https://www.szamlazz.hu/adatvedelem/
4.4. AI-based Measurement and Evaluation
Depending on the selected package and evaluation process, business or API services of OpenAI, Google/Gemini, Anthropic, and xAI may be used. In addition to the service providers involved in the measurement, the AI service provider performing the evaluation or compiling the report may also receive necessary data. Not every order concerns all of the listed services. The scope of data that may be transmitted is described in Section 5.
4.5. Location Identification
Depending on the function used, the Google Places service may be involved. Management of the search and location identification data necessary for location searching serves to identify the audited business. This is not for visitor measurement purposes.
4.6. Form Protection
reCAPTCHA may be used to protect against abuse and automated attacks. The technical device, browser, and interaction data necessary for protection are affected. Google’s provision of data processing and ARKER’s own data processing are separate; the use of end devices is also subject to the conditions set out in Section 8.
4.7. Google Analytics
After consent, the Google Analytics provider may process visit and technical data as specified in Section 8. Google has its own privacy notice regarding its independent service provider data processing. Analytics is not the same as the operation of Google Places or reCAPTCHA.
4.8. Mailing and Technical Intermediaries
Service providers ensuring the forwarding, delivery, and support of the system may process the necessary email address, message content, and technical data. The recipient of a transactional message is not automatically added to a marketing list.
4.9. Additional Recipient Categories
The accountant, legal and other professional advisors, and authorities may only receive data within the scope required for their tasks, legal claims, or mandatory data provision. We do not sell personal data to data brokers.
In their access request, the data subject may request identification of the actual recipients to whom their personal data have been disclosed, under the conditions set by law.
5. AI Data Processing and Nature of Analysis
The external AI service provider may receive corporate and location data necessary for the audit, the audit question, a public source excerpt, or a response to be evaluated. These may also contain personal data, such as the name of a sole proprietor or public business contact data. We do not claim that all public business data are free from personal data.
The account password and full bank card data are not AI inputs. Unnecessary personal or confidential data must be omitted from transmission. The purpose of visual analysis is the evaluation of business presentation and the visual substantiation of business information, not the biometric identification or determination of sensitive attributes of a natural person.
ARKER does not activate voluntary model training or product development data sharing concerning client data. Ordering an audit does not constitute consent for such purposes. This does not equate to an absence of all technical, security, or contractual data retention by external providers. The data management and retention terms of the utilized service must be considered according to the applicable business/API contract.
The system may produce an automated score, classification, and recommendation. These evaluate the audited business appearance and the given measurement pattern. Based on these, ARKER does not make any exclusively automated decision that would have legal effect or similarly significant impact on the data subject. The examination of the uncertainty of the outcome and any necessary fact-checking is part of the audit methodology.
6. Data transfers outside the EEA
Certain AI, analytics, and infrastructure services may involve data processing or access outside the European Economic Area, in particular the United States may also be implicated.
Personal data may only be transferred outside the EEA with an appropriate legal basis and guarantees. Ensuring adequate protection is the responsibility of ARKER. Guarantees can include a European Commission adequacy decision actually covering the given recipient and data processing, or—if lacking—particularly the Commission-approved standard contractual clauses and necessary supplementary protective measures.
The EU–US data privacy framework can only be relied upon in the case of a recipient who is validly certified and covered for the given data processing. The provider's US headquarters alone does not demonstrate compliance with this requirement.
The data subject may request information about the recipient used, country, specific guarantee, as well as a copy of the available guarantees at hello@vispertise.com. The conditions of data transfer are registered together with the service provider's data processing documents as applied, for the actual data processing process.
7. Data retention periods
The regular retention of personal data is restricted according to the following rules. Separate retention required for legal claims and mandatory records does not entitle further marketing or analytical use of the data.
7.1. General inquiry if no contract is concluded: 30 days from case closure; the section necessary for validated legal claims may be retained separately.
7.2. Pre-audit closed without a paid order: 30 days from completion. If an order or audit run is linked to the pre-audit, the automatic 30-day deletion does not apply; the pre-audit and its result remain linked to the order and audit evidence under the applicable retention rules. Deletion may be deferred until a still-valid access link or personal invitation expires, or while an order or related pre-audit remains in progress.
7.3. Account data: until the account exists. After account termination, data may only remain with a separate legal basis and to the extent necessary for the appropriate purpose. Account termination can be requested via email.
7.4. Audit materials and report: during the contracted access period; afterwards, the minimal part needed to verify contractual claims is kept for the period specified in the next paragraph. Full raw source material is not kept automatically; shorter license or data protection constraints for third-party content must be observed.
7.5. Contractual and performance evidence: in line with the general five-year statutory limitation period counted from due date of the claim. In case of circumstances altering limitation or ongoing claim, only data necessary for the concerned case are kept further.
7.6. Accounting vouchers and invoices: for the mandatory period under Section 169 of Act C of 2000 on accounting, at least eight years.
7.7. Consumer complaints, minutes, and substantive responses: for three years; separate retention required for legal claims occurs on a separate legal basis.
7.8. Regular raw web server logs: maximum 30 days. Data required for security events designated for investigation: maximum 365 days, except for proven necessary ongoing procedure or legal claim.
7.9. Temporary visual references and report-verification media: maximum 30 days, or until the applicable shorter provider limit.
7.10. Own analytics and server traffic summary: for the current and previous 59 calendar days according to the Europe/Budapest time zone; for withdrawal of consent, the separate rule in section 8 applies.
7.11. Google Analytics event and user data: according to configured two-month retention. This is not identical to cookie lifetime or every aggregate report retention rule.
7.12. Single launch notification: the email address and delivery record remain for the time needed to send the notification, manage opt-out and evidence consent. Opting out stops further sending but does not automatically delete the record; erasure of unnecessary data may be requested subject to the evidence purpose in section 7.13. A general marketing subscription lasts until withdrawal or the respective notification service ceases.
7.13. Minimum record needed to prove consent: for five years from closure of the last consent-based data processing, for separate evidential purposes based on legitimate interest. Despite withdrawal, this does not permit the continuation of measurement or marketing.
7.14. Backups: the current policy for regular encrypted backups retains 10 daily, 4 weekly and 4 monthly snapshots. Data deleted from the live system may remain until the relevant backup snapshot expires; separate release, recovery or legally justified evidence backups may be retained for a different period. Data remaining in a backup may not be used for new business purposes; on restoration, previous deletion requests and deadlines must be applied again.
8. Cookies, visit analytics and technical logging
8.1. Necessary storage
Technical storage required for session, security, operation of the requested function, and remembering choices is separate from optional measurement. The specific names, purposes, and lifespans of cookies and other storage are described in the Cookie Information Notice. The necessity of a storage must be judged based on its actual function.
8.2. Optional analytics
Own visit measurement and Google Analytics only start after prior analytical consent. If refused, no data transmission for this purpose takes place, including analytical signals without cookies before consent. Consent can be modified or withdrawn at any time via the Cookie Settings function in the footer.
8.3. Own visit analytics
Own measurement uses a _vispertise_visitor cookie containing a random identifier, for up to 60 days from its creation. The public website and the client portal use separate identifiers.
For the measured event, the time, the route cleared of personal or unique audit identifiers, the referrer website, language, estimated device type, and protected fingerprint of the identifier may be associated. In this analytics record, we do not store raw IP address, full referrer URL, raw browser identifier string, or client ID. Data protection rules continue to apply to the pseudonymized data.
Upon withdrawal, the own analytics cookie is deleted, new measurement stops, and previously attributable analytical events are deleted without undue delay, if there is no other legitimate retention basis. Withdrawal does not affect the lawfulness of previous data processing. Actually anonymous, non-re-identifiable aggregation may remain.
8.4. Google Analytics
Google Analytics may process page and event data, browser and device characteristics, as well as network information related to operation, after consent. We do not send account ID, name, email address, or unique audit report content as analytical event parameters.
Upon withdrawal, we stop new data transmission, and take measures for the deletion of attributable data according to applicable laws and the provider’s deletion tools. We handle the lifetime of Google cookies and retention of event data separately. Enabling analytics does not result in advertising personalization or data sharing for marketing purposes.
8.5. Server traffic aggregation
To understand operation and load, a daily, cleaned traffic summary may be prepared from necessary server logs on the basis of legitimate interest. The summary does not retain the IP address, cookie identifier, client identifier, full referrer URL, or sensitive path segment, and we do not link separate requests from the same browser. Logging of personal data and truly anonymous aggregation remain separate.
8.6. Barion fraud prevention
During the operation of Base Barion Pixel related to payment, Barion, as an independent data controller, may process technical device and browser data, IP address, visit event, cookie data, or browser fingerprint for fraud prevention purposes. Barion’s data processing for this purpose may be based on legitimate interest. This alone does not replace the separate legal basis or, where applicable, consent required for storage or access on the terminal device.
Regardless of consent, only operation that is demonstrably necessary for the requested payment and its security may be applied. ARKER does not send Barion marketing consent or marketing events. The actual cookies, lifespans and provider disclosures are available in the Cookie Information Notice. Rights related to Barion's data processing may also be exercised directly with Barion.
9. Data security and authorizations
We apply technical and organizational safeguards appropriate to the risks: task-based access, access control, secure data transmission, necessary logging, backup, and incident management. We do not promise complete technical risk-freeness; this does not reduce our legal obligations concerning data security and incident management.
The user must protect their own login data and access links. We do not use non-public reports as marketing references without separate authorization from the Client or other appropriate legal basis.
10. Rights of the data subject and handling of requests
10.1. The data subject may, under the statutory conditions, request access and copies, rectification, deletion, or limitation of processing. Deletion does not extend to data whose further processing is necessary due to a legal obligation or other applicable statutory exemption. ARKER will inform about this reason.
10.2. Data portability under GDPR conditions may be requested for data provided by the data subject and processed automatically based on consent or contract. This does not provide a right to data of other persons, nor to ARKER’s entire internal methodology or software. The applicable scope of the right is determined by law.
10.3. The data subject may object to data processing based on legitimate interests for reasons related to their own situation. They may object to direct marketing purposes at any time. Consent may be withdrawn as easily and without disadvantage as it was given; withdrawal does not affect the lawfulness of processing prior to withdrawal.
10.4. Requests may be submitted to hello@vispertise.com or to the ARKER mailing address. For identification purposes, we only request additional data in case of legitimate doubt and to the necessary extent. The evaluation of the request is not generally subject to the submission of a copy of an identity document.
10.5. We will provide information about the measures taken without undue delay, and at the latest within one month from the receipt of the request. In the case of complex or numerous requests, this may be extended by up to an additional two months; we will inform you of the reasons for the delay and the extension within the first month. In case of rejection, we provide reasons and legal remedy information. We will respond electronically to electronic requests where possible, unless the data subject requests otherwise.
10.6. As a general rule, administration is free of charge. In the case of manifestly unfounded or excessive requests, a reasonable fee or refusal in accordance with the GDPR conditions may be applied; justification for this must be provided by ARKER. The exercise of rights may only be restricted to protect the rights or legal claims of another person in accordance with applicable regulations.
11. Complaint and judicial remedy
The data subject may submit a complaint to the National Authority for Data Protection and Freedom of Information (NAIH).
Head office: 1055 Budapest, Falk Miksa utca 9–11.
Mailing address: 1363 Budapest, Pf. 9.
E-mail: ugyfelszolgalat@naih.hu.
Phone: +36 1 391 1400.
Website: naih.hu.
Prior contacting of ARKER is not a prerequisite for the right to submit a complaint to the authority. The data subject may also turn to the courts; the procedure is governed by the GDPR and the applicable Hungarian procedural rules. This notice does not restrict the enforcement options arising from residence or habitual place of stay as provided by law.
12. Minors, individual data processing, and changes
The paid service is not intended for persons under 18 years of age. Targeted data collection for minors or special categories of data is not part of the service.
If, based on a separate order, ARKER processes personal data on behalf of and under the instruction of the client, the roles of data controller and data processor are governed by a separate agreement. This notice does not substitute for a data processing agreement.
The notice will be adjusted to changes in actual data processing. We will inform you appropriately of significant changes; the modification itself does not create a new legal basis and does not substitute the necessary consent. The retention of previous contractual documents for evidential purposes is separate from this.