01Legal
Website Privacy Policy
- Effective
- September 7, 2026
- Version
- 1.0 (B2B Showcase & Enquiry Website)
1. Introduction & Controller Information
This Privacy Policy explains how Leveloper Informatikai és Szolgáltató Korlátolt Felelősségű Társaság (“Leveloper”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data when you visit our corporate website at leveloper.io (the “Website”), communicate with us via our contact forms or email, and interact with our online portfolio.
Data Controller Identity
- Company Legal Name: Leveloper Informatikai és Szolgáltató Korlátolt Felelősségű Társaság
- Short Name: Leveloper Kft.
- Registered Seat / Postal Address: 2483 Gárdony, Berzsenyi utca 73., Hungary
- Company Registration Authority: Székesfehérvári Törvényszék Cégbírósága
- Company Registration Number: 13-09-211486
- Tax Number: 29164341-2-07
- EU VAT Identification Number: HU29164341
- Managing Director / Legal Representative: Martin Kocsis
- Privacy & Data Protection Contact Email:
hello@leveloper.io - Phone: +36 30 914 3620
We act as an independent Data Controller under Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation — “GDPR”) and Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information of Hungary (“Infotv.”).
2. Scope of this Policy
This policy applies exclusively to personal data collected through the public website leveloper.io.
What this policy does NOT cover:
- Client Software Engineering Services: When we provide bespoke software development, maintenance, or consulting to agency partners and business clients, processing of client-controlled data is governed by our individual Master Services Agreements (MSA), Work Orders, and Data Processing Agreements (DPA).
- Third-Party External Websites: Our Website may link to third-party domains (such as client portfolio sites, GitHub repositories, or partner websites). We have no control over and assume no liability for third-party privacy practices.
3. Categories of Data We Process, Purposes, Legal Bases & Retention
We process personal data only where we have a valid legal basis under Article 6(1) GDPR.
A. Server Infrastructure & Operational Log Data
When you access our Website, our self-hosted web server automatically records technical request data.
- Data Categories: IP address, timestamp, HTTP request method, requested URL path, HTTP status code, referrer URL, user-agent string (browser type, version, operating system).
- Purpose: Delivering the Website content securely, ensuring server stability, detecting and mitigating denial-of-service (DoS/DDoS) attacks, unauthorized access attempts, and technical debugging.
- Legal Basis: Article 6(1)(f) GDPR — Legitimate Interest in operating a secure, functional, and resilient web infrastructure.
- Retention Period: Server access and error logs are retained for 14 to 30 days, after which they are automatically rotated and deleted, unless specific log entries are required for active security investigation or legal defense.
B. Contact Form Enquiries & Direct B2B Communications
When you submit a project enquiry through our contact form or write to hello@leveloper.io.
- Data Categories: Full name, business email address, company name (if provided), project budget / timeline indications (if provided), message body, metadata (timestamp of submission, language preference).
- Purpose: Responding to your request, evaluating project feasibility, conducting preliminary discovery calls, preparing proposals, and negotiating potential service agreements.
- Legal Basis:
- If you represent an entity or yourself seeking to explore a contract: Article 6(1)(b) GDPR — Taking steps at the request of the data subject prior to entering into a contract.
- General correspondence and B2B relationship management: Article 6(1)(f) GDPR — Legitimate Interest in managing business inquiries and commercial relationship building.
- Retention Period: General prospective enquiries that do not result in an active contract are retained for 12 months following the last active communication and then securely purged. If an enquiry leads to a signed agreement, communications are retained for the duration of the commercial relationship plus the statutory limitation period (general civil law limitation under Hungarian law: 5 years; accounting records: 8 years under Act C of 2000 on Accounting).
C. Spam Prevention & Form Abuse Mitigation (Google reCAPTCHA)
To protect our self-hosted infrastructure and contact endpoints from automated abuse, spam bots, and malicious flooding, we utilize Google reCAPTCHA (score-based v3 / Cloud integration).
- Data Categories: Mouse movement patterns, typing speed/rhythm, screen resolution, browser headers, installed browser plugins, Google account cookies (if logged in to Google on the device), IP address.
- Purpose: Differentiating human visitors from automated bots prior to message transmission.
- Legal Basis: Article 6(1)(f) GDPR — Legitimate Interest in defending publicly accessible web forms against automated spam and denial-of-service abuse.
- Retention: Collected data is evaluated in real-time by Google to return a risk score to our server; Leveloper does not store raw behavioral biometric profiles.
D. Web Analytics & Measurement (Google Analytics 4 via Google Tag Manager)
Subject to your prior, explicit, affirmative consent.
- Data Categories: Pseudonymized client ID, truncated/anonymized IP address, pages visited, time spent per page, scroll depth, interaction events (e.g., clicking case studies, expanding engineering diagrams), referral source, device category.
- Purpose: Statistical analysis of website usage, identifying high-interest portfolio topics, optimizing navigation and performance.
- Legal Basis: Article 6(1)(a) GDPR — Consent. Tracking scripts are completely blocked from loading until consent is actively granted via our Consent Manager.
- Retention Period: Event-level data in GA4 is set to 14 months maximum retention.
E. Session Diagnostics, Replay & Heatmaps (Revisit.pro)
Subject to your prior, explicit, affirmative consent.
- Data Categories: Anonymized session replay recordings, cursor movement paths, clicks, viewport resizing, device viewport dimensions, UI interaction milestones.
- Special Privacy Guardrails:
- Revisit is self-hosted on Leveloper’s infrastructure in Hungary.
- Contact form input fields and identifiable personal text strings are masked on the client side prior to capture.
- Session replay recording is strictly disabled on sensitive contact submission views.
- Where optional external AI diagnostic analysis (e.g., summarization via OpenRouter) is activated, only sanitized interaction metrics and non-identifiable technical tokens are processed.
- Purpose: Diagnosing UI bottlenecks, layout bugs on specific device form factors, and improving user experience.
- Legal Basis: Article 6(1)(a) GDPR — Consent.
- Retention Period: Session recordings are automatically deleted after 30 to 90 days.
F. Conversion Tracking & B2B Remarketing (Meta Pixel & Meta Conversions API)
Subject to your prior, explicit, affirmative consent.
- Data Categories: Pseudonymized browser identifiers, hashed browser metadata, pages visited, specific conversion events (e.g., “InitiateContact” event trigger when a form is validated).
- Privacy Guardrail: Contact form message text, personal names, and unhashed plain-text email addresses are strictly excluded from Meta tracking payloads.
- Purpose: Measuring effectiveness of B2B campaigns on LinkedIn/Meta platforms, understanding audience reach across the EU.
- Legal Basis: Article 6(1)(a) GDPR — Consent.
- Retention Period: Meta retains event data according to its own platform retention cycles (typically up to 180 days for custom audiences).
4. Hosting Architecture & Data Recipients
Leveloper prioritizes infrastructure self-sovereignty. We do not use opaque third-party shared cloud platforms for our core web server.
1. Primary Hosting & Processing (Hungary / EEA)
- Web Server & Application Server: Self-hosted and directly operated by Leveloper Kft. on dedicated physical infrastructure located in Hungary (EEA).
- Revisit Instance: Self-hosted on Leveloper’s Hungarian infrastructure.
2. External Service Providers & Subprocessors (Data Processors)
We engage trusted external suppliers under strict Article 28 GDPR Data Processing Agreements:
| Provider & Entity | Service Provided | Location / Transfer Safeguard |
|---|---|---|
| Porkbun LLC (USA) | Domain Registration, Authoritative DNS, Business Email Hosting (hello@leveloper.io), Encrypted Offsite Server Backup Storage |
USA — EU-US Data Privacy Framework (DPF) / Standard Contractual Clauses (SCCs), Client-Side Backup Encryption |
| Google Ireland Limited (Ireland / EU) | Google Tag Manager, Google Analytics 4, Google reCAPTCHA v3 / Cloud | Ireland (EU) / USA (Google LLC) — DPF certification, Article 28 DPA, SCCs |
| Meta Platforms Ireland Ltd. (Ireland / EU) | Meta Pixel & Meta Conversions API (server-side conversion measurement) | Ireland (EU) / USA (Meta Platforms, Inc.) — DPF certification, Controller-to-Controller / Processor terms, SCCs |
| OpenRouter, Inc. (USA) | Routing API for external AI evaluation of anonymized diagnostic telemetry | USA — Standard Contractual Clauses; processing restricted to non-PII diagnostic tokens |
5. International Data Transfers (Transfers Outside the EEA)
Whenever personal data is transferred to a country outside the European Economic Area (EEA), we ensure an adequate level of protection in accordance with Chapter V of the GDPR by relying on:
- Adequacy Decisions (Article 45 GDPR): Specifically, the EU-US Data Privacy Framework for certified US entities (including Google LLC, Meta Platforms, Inc.).
- Standard Contractual Clauses (Article 46(2)(c) GDPR): Incorporating the European Commission’s approved standard contractual clauses into vendor agreements with supplementary technical measures (e.g., client-side encryption of backup archives prior to transmission to Porkbun storage, IP anonymization, client-side input masking).
6. Cookies and Tracking Technologies
Our Website uses cookies and local storage tokens.
- Strictly Necessary Cookies & Tokens: Required for essential site functionality, security (e.g., CSRF protection tokens, reCAPTCHA validation, saving your cookie preference state). These do not require prior consent under Hungarian Act C of 2003 on Electronic Communications (§ 155(4)) and Article 5(3) of the ePrivacy Directive.
- Non-Essential Cookies (Analytics, Replay, Advertising): Used solely if you give prior, active consent.
For a full technical inventory of cookie names, storage durations, and granular toggle controls, please consult our dedicated Cookie & Tracking Policy.
7. Data Security Measures
Under Article 32 GDPR, Leveloper implements comprehensive technical and organizational measures (TOMs), including:
- Transport Encryption: Strict HTTPS enforcement with modern TLS cipher suites and HSTS enabled.
- Access Control: Principle of least privilege; multi-factor authentication (MFA) enforced on all administrative systems, DNS consoles, and server access points.
- Credential Hygiene: Stored in dedicated password management vaults; zero credentials hardcoded in public source repositories.
- Encrypted Backups: Offsite backup archives are encrypted with strong cryptographic standards prior to leaving the primary server environment.
- Isolation of Test & Production Environments: No live personal data copied to unencrypted local development machines without documented necessity and timely destruction.
8. Your Data Subject Rights Under GDPR
As an individual located in the EU/EEA, you have the following enforceable rights regarding your personal data:
- Right of Access (Article 15 GDPR): You have the right to obtain confirmation as to whether your personal data is being processed, and to receive a copy of that data along with processing details.
- Right to Rectification (Article 16 GDPR): You have the right to request the correction of inaccurate or incomplete personal data without undue delay.
- Right to Erasure / “Right to be Forgotten” (Article 17 GDPR): You may request the deletion of your personal data where it is no longer necessary for the original purposes, where consent has been withdrawn and no other legal basis exists, or where processing was unlawful.
- Right to Restriction of Processing (Article 18 GDPR): You may request that we suspend active processing of your data while accuracy is contested or in the event of an ongoing legal claim.
- Right to Data Portability (Article 20 GDPR): You have the right to receive data provided based on consent or contract in a structured, commonly used, machine-readable format.
- Right to Object (Article 21 GDPR): You have the right to object at any time, on grounds relating to your particular situation, to processing based on Legitimate Interests (Article 6(1)(f) GDPR).
- Right to Withdraw Consent (Article 7(3) GDPR): Where processing relies on consent, you may withdraw your consent at any time with future effect via our on-site Cookie Settings manager or by emailing
hello@leveloper.io. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. - Right Not to be Subject to Automated Decision-Making (Article 22 GDPR): We do not carry out automated decision-making or profiling that produces legal effects concerning you.
How to Exercise Your Rights
To exercise any of your rights, send a written request to:
- Email:
hello@leveloper.io - Postal Address: Leveloper Kft., 2483 Gárdony, Berzsenyi utca 73., Hungary
We will respond to your request without undue delay and at the latest within one (1) month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of requests. We do not charge a fee for standard requests.
9. Supervisory Authority & Remedies
If you believe that our processing of your personal data infringes the GDPR or applicable Hungarian data protection laws, you have the right to lodge a complaint with the competent supervisory authority:
Hungarian Supervisory Authority
- Authority Name: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Postal Address: 1363 Budapest, Pf. 9., Hungary
- Phone: +36 (1) 391-1400
- Email:
ugyfelszolgalat@naih.hu - Website: https://naih.hu
You also have the right to bring an action before the competent regional court (Törvényszék in Hungary). At your election, the lawsuit may be instituted before the court having jurisdiction over your place of residence or habitual stay.
If you reside in another EU Member State, you may also lodge a complaint with your local national data protection authority.
10. Updates to this Privacy Policy
We may amend this Privacy Policy from time to time to reflect changes in our Website functionality, legal obligations, or technical infrastructure. Any revised version will be published on this page with an updated Effective Date. Where changes are material, we will provide prominent notice on our Website.