Home Docs Log in

Privacy Policy

Effective: 2026-03-08 · English translation of the Hungarian Adatvédelmi elvek published on glc-rag.hu, adapted to also cover mcp.glc-rag.hu.

This privacy notice explains in plain language how we process personal data when you use the glc-rag.hu website and related services, including the MCP platform at mcp.glc-rag.hu (together: the “Service”).

1. Data controller

The controller is glcMEDIA Kereskedelmi és Fejlesztő Korlátolt Felelősségű Társaság.

Contact: pergel@pergel.hu · Support: support@glc-rag.hu

Full company and operator details are on the Imprint page.

2. Categories of personal data

2.1. Account and login data

  • user ID and organisation/tenant ID
  • password only in hashed/encrypted form
  • email address (registration or contact)
  • role, permission level and account status
  • technical metadata related to the account

2.2. Profile and contact data

  • display name, profile identifier
  • bio/professional description, if provided
  • contact details, website and social links
  • profile image, if uploaded

2.3. Facebook and social integrations

  • Facebook Page ID, page name and basic profile data
  • access tokens for page management, reading comments and publishing replies
  • post and comment text that the system reads, processes, displays or publishes as replies
  • technical, sync and configuration data related to the page

Processing may occur via the Meta (Facebook) platform API. Meta may also act as an independent controller under its own policies during Facebook login, page selection and related platform actions.

2.4. Documents, content and projects

  • uploaded documents (e.g. PDF, DOCX, TXT and other files)
  • document metadata (title, scope, status, created/updated times)
  • projects, tasks, quotes, knowledge-base items and other content
  • reply templates, master-data groups, settings and other user content

2.5. Webshop and product data

  • feed configurations, URLs, formats and related technical settings
  • product data loaded from external feeds/integrations and made searchable in the Service

2.6. Billing and payment data

  • billing name and address
  • tax number, where relevant
  • transaction and payment data
  • records related to balance top-ups, purchases and invoicing

2.7. Technical and log data

For secure operation, troubleshooting, abuse prevention and legal obligations, technical and log data may be generated, including IP address, device/browser data, system events, error reports, audit trails, API calls, access events and other technical metadata.

2.8. LLM and AI-related processing

The Service may use large language models (LLMs) and other AI services for chat, answer generation, document processing, search, RAG, summarisation, classification, labelling and other automated text processing.

Texts, questions, instructions, uploaded documents and extracted/generated excerpts may be transmitted to external AI/LLM provider APIs. Multiple AI providers may be used depending on configuration, performance or cost optimisation. Data may be processed in third-party systems and may be transferred outside the European Union.

The User is responsible for ensuring that uploaded or submitted content does not include personal data, trade secrets or other confidential information that the User is not entitled to process, transmit or use within the Service.

3. Purposes of processing

  • creating and managing user accounts, identification and authorization
  • operating, providing, customising and improving the Service
  • managing documents, knowledge bases, projects, tasks and other content
  • connecting Facebook pages, receiving/analysing comments and publishing replies
  • loading, searching and processing webshop/product data
  • billing, payment handling, balance top-up and related financial administration
  • customer support and system messages
  • security, abuse prevention, incident handling and logging
  • legal obligations (especially accounting, tax and retention)
  • statistics, operations and analytics where a lawful basis exists
  • providing AI/LLM features (chat, generation, search, document processing)

4. Legal bases

  • Contract performance — GDPR Art. 6(1)(b) — providing the Service, account management, integrations and features
  • Legitimate interests — GDPR Art. 6(1)(f) — security, audit, logging, troubleshooting, abuse prevention and operations
  • Consent — GDPR Art. 6(1)(a) — where law or the nature of the service requires it
  • Legal obligation — GDPR Art. 6(1)(c) — especially accounting, tax and retention duties

5. Retention

  • account data: for the life of the account and thereafter as needed for legal obligations
  • billing/transaction data: for the retention period required by accounting and tax law
  • Facebook/other integration data: while the connection lasts, and as required by law or technically necessary
  • technical/audit logs: as needed for security, auditability and legal obligations
  • uploaded documents/content: for the life of the account, until deletion request or contract end, unless law requires longer retention

6. Processors and platforms

We may use external providers, including:

  • Meta (Facebook) — login, page connection, reading comments, publishing replies and related APIs
  • hosting, infrastructure and cloud providers — servers, databases, security and storage
  • billing and payment providers — transaction processing, invoicing and financial administration
  • LLM/AI providers — chat, generation, RAG, search, document processing and other AI features
  • other integration partners where required by specific features

These providers may have their own privacy terms. Where they act as independent controllers, their own notices apply.

7. International transfers

Personal data are primarily processed within the EU, but transfers outside the EU may occur when using certain providers (including Meta platforms, international cloud providers and AI/LLM providers). Transfers are made with appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission and other measures required by law.

8. Security

The Controller applies appropriate technical and organisational measures, considering the nature, scope, context and purposes of processing and the risks involved. Measures may include access control, logging, role-based authorization, encryption, password protection, backups, monitoring and incident response.

9. Automated processing and AI answers

The Service may use AI-based automated text processing, search and answer generation. AI-produced answers, suggestions and summaries are generated automatically; accuracy, completeness, error-free nature or fitness for a particular purpose is not guaranteed.

The Service does not make solely automated decisions that produce legal effects concerning the User or similarly significantly affect the User.

10. Data subject rights

  • right to information
  • right of access
  • right to rectification
  • right to erasure
  • right to restriction of processing
  • right to data portability
  • right to object
  • right to withdraw consent where processing is based on consent

Requests may be sent to pergel@pergel.hu or support@glc-rag.hu.

11. Remedies

If you believe processing of your personal data violates applicable law, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

1055 Budapest, Falk Miksa utca 9–11.
www.naih.hu

12. Changes to this notice

The Controller may amend this privacy notice. The current version takes effect upon publication on these legal pages and/or glc-rag.hu.

Hungarian original on glc-rag.hu

Operator: GLC-RAG

Privacy Policy · Terms of Use · Imprint · Support · Partners