Privacy Notice
Effective date: [day] [month] 2026 Version: 1.0
1. Purpose and scope
This Privacy Notice explains how TRIANITY Kft. processes personal data in connection with:
- visits to the
upcheck.huwebsite; - enquiries and requests for a free website assessment;
- quotations and contracting;
- use of the Upcheck Monitor service;
- customer and user accounts;
- monitoring of websites and online services;
- email and Telegram notifications;
- billing and payment;
- customer support and complaints;
- and information security logging.
This Notice applies to individual customers, employees and representatives of customer organisations, account users, prospective customers and website visitors.
2. Controller details
Controller: TRIANITY Korlátolt Felelősségű Társaság
Short name: TRIANITY Kft.
Registered office: 1119 Budapest, Andor utca 21, Building C, Ground Floor 1, Hungary
Company registration number: 01-09-978184
Website: upcheck.hu
General contact: [contact email address]
Privacy requests: [privacy email address]
Postal address: 1119 Budapest, Andor utca 21, Building C, Ground Floor 1, Hungary
The Controller has not appointed a data protection officer because its activities do not currently require such an appointment.
3. Controller and processor roles
3.1. When TRIANITY Kft. acts as controller
TRIANITY Kft. acts as an independent controller in particular when processing data for:
- operation of the upcheck.hu website;
- enquiries and quotation requests;
- customer relationships and contract administration;
- management of user accounts;
- invoicing;
- service and security logs;
- customer support and complaints;
- and its own service communications.
3.2. When TRIANITY Kft. acts as processor
Where a customer provides websites, URLs, test routes, expected content markers or test-user credentials for monitoring, the roles regarding any personal data contained in monitored responses will normally be:
- the customer acts as controller;
- TRIANITY Kft. acts as processor on the customer's documented instructions.
These activities are governed in more detail by a data processing agreement forming part of the service contract.
The customer is responsible for:
- lawfully selecting the areas to be monitored;
- providing only the access strictly required;
- preventing unnecessary processing of personal data;
- and providing appropriate information to its own data subjects.
4. Processing activities
4.1. Website operation and security
Purpose: to provide a secure and reliable website, detect errors and attempted attacks, and maintain service stability.
Data processed:
- IP address;
- date and time of the request;
- requested page or route;
- HTTP method and response code;
- browser and device technical information;
- referring page;
- session identifiers;
- security events and error information.
Legal basis: the Controller's legitimate interest in operating a secure service, preventing misuse and investigating technical or security incidents.
Retention: normally 30–90 days. Relevant logs may be retained for longer where required to investigate a security incident or establish, exercise or defend legal claims.
4.2. Enquiries, monitoring requests and free assessments
Purpose: to respond to the enquiry, understand the requested monitoring scope, prepare a quotation and take steps before entering into a contract.
Data processed:
- name;
- company name;
- email address;
- telephone number;
- website or domain;
- approximate number of domains;
- technologies used;
- requested monitoring types;
- other information voluntarily included in the message.
Legal basis:
- steps taken at the request of an individual before entering into a contract;
- legitimate interests of the Controller and the represented organisation in business communications where the contact person represents a company or other organisation.
Retention:
- where a contract is concluded, as part of the contract documentation;
- where no contract is concluded, for 12 months after the enquiry is closed;
- longer where necessary for the establishment, exercise or defence of legal claims.
Submission of an enquiry form is not based on consent where processing is necessary to answer the request. Confirmation that the Privacy Notice has been read therefore does not constitute consent to data processing.
4.3. Contracting and customer management
Purpose: preparing and performing contracts, maintaining customer relationships and agreeing service configurations.
Data processed:
- customer or contact-person name;
- company name;
- position;
- email address;
- telephone number;
- billing and contractual information;
- communication history;
- subscribed service and pricing plan;
- domains and services to be monitored.
Legal basis:
- performance of a contract with an individual customer;
- legitimate interests where the data subject represents a legal entity or other organisation;
- compliance with legal obligations in relation to invoicing.
Retention: during the contractual relationship and afterwards for the limitation period applicable to civil claims, generally five years. Separate retention rules apply to accounting records.
4.4. User accounts and access management
Purpose: identifying and authenticating users, managing permissions and protecting account security.
Data processed:
- name;
- email address;
- customer or organisation affiliation;
- role and permissions;
- cryptographically hashed password;
- two-factor authentication data where enabled;
- login timestamps;
- IP addresses and security logs;
- session and device information.
Passwords are not stored in readable form. They are stored using a modern one-way cryptographic hashing process.
Legal basis: performance of a contract or legitimate interests in the case of organisational users.
Retention: while the account remains active. Necessary audit and security logs may normally be retained for up to 90 days after account closure, or longer where required in connection with a dispute or security incident.
4.5. Monitoring of websites and online services
Purpose: to monitor the availability and essential behaviour of websites, domains and business-critical routes selected by the customer.
Monitoring may include:
- HTTP and HTTPS availability;
- HTTP status codes;
- response times;
- redirects;
- HTTPS certificate validity and expiry;
- presence or absence of customer-defined text or content markers;
- detection of technical error messages;
- incident and recovery records.
Data processed:
- domains and URLs;
- DNS and network data;
- IP addresses;
- certificate information;
- response codes and response times;
- technical response headers;
- check results;
- limited response excerpts or fingerprints where necessary;
- incident and recovery information;
- custom monitoring rules.
Monitoring is not intended to identify, profile or track visitors to the monitored websites.
Legal basis and roles:
- performance of the service contract for customer and configuration information;
- where personal data appears in monitored responses, TRIANITY Kft. normally acts as processor on the customer's documented instructions.
Retention:
- detailed check results: [for example, 90 days];
- aggregated availability data: [for example, 24 months];
- incident and recovery history: [for example, 24 months];
- following termination of the contract: no more than [30/90] days, except where data must be retained for legal claims or statutory obligations.
Specific retention periods may also be defined by the applicable service package or customer agreement.
4.6. Monitoring authenticated or restricted pages
Where monitoring requires authentication, the customer must provide a dedicated test account with the minimum permissions necessary.
Upcheck does not request, and the customer must not provide:
- passwords belonging to real end users;
- payment card details;
- health data or other special-category data;
- administrative access not required for monitoring;
- direct access to a live customer database,
unless a separate written agreement, risk assessment and appropriate security measures have first been established.
4.7. Email and Telegram notifications
Purpose: to send incident, recovery, certificate-expiry, diagnostic and service-operation notifications.
Data processed:
- recipient name;
- email address;
- Telegram user, group or chat identifier;
- notification preferences;
- delivery status;
- content of system notifications;
- sending and error information.
Legal basis: performance of a contract or legitimate interests where the recipient is nominated by a customer organisation.
Operational, security, incident and recovery notifications are service messages rather than marketing communications and therefore do not require separate marketing consent.
Where Telegram is used, messages and recipient identifiers are transmitted through Telegram's service infrastructure. The customer decides whether to enable this optional notification channel.
Retention: notification settings for the duration of the service; delivery logs normally for 90 days; incident-related notification history for the retention period applicable to the relevant incident.
4.8. Billing and payments
Purpose: calculating charges, issuing invoices, accounting and complying with statutory obligations.
Data processed:
- name or company name;
- billing address;
- tax number;
- email address;
- purchased service;
- amount payable;
- payment method;
- payment and invoice identifiers.
Legal basis: performance of a contract and compliance with legal obligations.
Retention: accounting records and the data supporting them are retained for at least eight years in accordance with applicable accounting law.
The Controller does not process or store full payment card details. Where online card payment is available, card data is processed by the selected payment service provider.
4.9. Customer support, tickets and complaints
Purpose: handling questions, technical reports and complaints and documenting the action taken.
Data processed:
- name;
- email address;
- telephone number;
- customer and account identifiers;
- relevant domain or service;
- correspondence and message contents;
- attachments;
- technical and diagnostic data;
- outcome of the case.
Legal basis:
- performance of a contract;
- compliance with legal obligations;
- legitimate interests where processing is necessary for legal claims.
Retention:
- general support matters: 24 months after closure;
- consumer complaints and responses: for the period required by applicable consumer-protection law;
- legal disputes: until the final resolution or expiry of the relevant claim.
4.10. Backups
The Controller creates backups to ensure service availability, integrity and recoverability.
Data deleted from active systems may remain in backups for a limited period. Such data is not restored during ordinary operations and is removed when the relevant backup cycle expires.
Retention: [actual backup retention period, for example 30 or 90 days].
4.11. Marketing communications
The Controller sends advertising or newsletter messages only on the basis of separate, freely given consent.
Data processed: name, email address, date of consent and technical information required to demonstrate consent.
Legal basis: consent.
Retention: until consent is withdrawn. The minimum information required to demonstrate the withdrawal may be retained until the expiry of applicable legal claims.
Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Cookies and local storage
The upcheck.hu website may use cookies and browser-side storage required for:
- maintaining user sessions;
- authentication;
- security and CSRF protection;
- remembering language settings;
- storing light or dark appearance preferences;
- remembering cookie preferences.
Strictly necessary cookies are used to provide the requested electronic service and on the basis of the Controller's legitimate interests.
Non-essential analytics or marketing cookies may only be placed after prior consent. Where no such cookies are in use, the cookie-management interface should clearly state this.
A separate cookie notice or settings interface may list each cookie, its provider, purpose and expiry period.
6. Processors and recipients
The Controller may use the following categories of recipients:
-
Server and infrastructure provider [Provider name, address and country] Purpose: provision of server, network or data-centre infrastructure.
-
Email infrastructure provider [Self-hosted infrastructure or provider name] Purpose: transmission of service and customer messages.
-
Telegram messaging service Provider: Telegram Messenger Inc. or the current operator of the relevant service. Purpose: transmission of Telegram notifications requested by the customer.
-
Invoicing service provider [Provider name and address] Purpose: issuing and delivering invoices.
-
Accountant or accounting provider [Provider name and address] Purpose: supporting compliance with accounting and tax obligations.
-
Payment service provider [Provider name and address] The provider receives data only where the customer selects its payment method.
-
Legal and information-security advisers Access is provided only where necessary to handle a legal claim, security incident or technical problem and subject to appropriate confidentiality obligations.
Personal data is disclosed to courts, authorities or other public bodies only where required by law and based on a valid request.
7. International transfers
The Controller aims to keep personal data within the European Economic Area.
The use of certain optional external services, particularly Telegram or some payment providers, may involve a transfer of personal data to a third country.
Such transfers take place only where an appropriate GDPR transfer mechanism applies, for example:
- an adequacy decision adopted by the European Commission;
- standard contractual clauses;
- or another safeguard recognised by the GDPR.
8. Automated decision-making
Upcheck may use automated technical rules to determine whether a check has succeeded or failed, whether an incident should be opened and when a recovery notification should be sent.
This automation forms part of the technical monitoring service. The Controller does not carry out solely automated decision-making or profiling relating to natural persons that produces legal or similarly significant effects.
9. Data security
The Controller applies technical and organisational measures appropriate to the risks of processing, including:
- encrypted HTTPS connections;
- access and permission controls;
- individual user accounts;
- cryptographic password hashing;
- two-factor authentication where appropriate;
- logging and investigation of security events;
- network- and application-level protection;
- backups;
- encrypted backups where appropriate;
- regular updates of the application and its dependencies;
- limited retention periods;
- and confidentiality obligations for authorised personnel.
10. Data-subject rights
Data subjects may:
- request information about the processing of their personal data;
- request access to and a copy of their data;
- request correction of inaccurate data;
- request restriction of processing;
- request erasure where the statutory conditions are met;
- withdraw consent at any time;
- object to processing based on legitimate interests;
- request data portability in applicable cases;
- lodge a complaint with a supervisory authority;
- and seek a judicial remedy.
The right to erasure does not apply where retention is required to comply with a legal obligation or to establish, exercise or defend legal claims.
11. Handling data-subject requests
Requests may be submitted to:
Email: [privacy email address] Postal address: TRIANITY Kft., 1119 Budapest, Andor utca 21, Building C, Ground Floor 1, Hungary
The Controller responds without undue delay and no later than one month after receipt.
This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. The Controller will provide information about the extension and its reasons within the initial one-month period.
Where reasonably necessary, the Controller may request further information to verify the identity of the requester. The exercise of data-subject rights is generally free of charge.
12. Complaints and judicial remedies
Data subjects may lodge a complaint with:
Hungarian National Authority for Data Protection and Freedom of Information Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary Postal address: 1363 Budapest, P.O. Box 9, Hungary Telephone: +36 1 391 1400 Email: ugyfelszolgalat@naih.hu
Data subjects may also bring proceedings before a competent court if they consider that the processing of their personal data is unlawful.
13. Amendments
The Controller may amend this Notice, particularly where:
- the service changes;
- a new processor is engaged;
- applicable law changes;
- or processing practices are modified.
The current version is available on upcheck.hu. Where a change materially and adversely affects users, the Controller will also provide appropriate notice, for example through the user interface or by email.