Legal · Compliance landing page
Privacy Policy
Last updated: April 29, 2026 · Effective date: April 29, 2026
This Privacy Policy explains how Rebelframes Kft. (“AIWorkFluency”, “we”, “us”) collects, uses, and protects personal data when you use this website and the AIWorkFluency compliance training service. We are the controller of the personal data described below within the meaning of the EU General Data Protection Regulation 2016/679 (“GDPR”).
For full company details see the Imprint.
1. What we collect
1.1 You give us
- Contact form data: name, email, phone number, and any free-text notes you submit through the “Let’s talk” form on this site.
- Account data (when you become a customer): company name, billing details, the names and work email addresses of staff assigned to training tracks, the role/track they are assigned to.
- Service data: answers, response times, scores and timestamps generated as your staff complete weekly lessons.
1.2 We collect automatically
- Technical data: IP address, browser type, device type, pages viewed, referrer, language. Used in aggregate to operate and secure the service.
- Cookies: strictly necessary cookies for session and security only. We do not run third-party advertising or behavioral tracking cookies on this landing page.
2. Why we use it (purposes & legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Respond to “Let’s talk” submissions | Pre-contractual measures at your request — Art. 6(1)(b) |
| Deliver the training service and generate the Compliance Folder | Performance of contract — Art. 6(1)(b) |
| Maintain audit-grade evidence of staff training (Article 4 of the EU AI Act) | Compliance with legal obligation — Art. 6(1)(c) |
| Service security, fraud prevention, troubleshooting | Legitimate interests — Art. 6(1)(f) |
| Marketing communication (only if you opt in) | Consent — Art. 6(1)(a) |
3. Who receives the data
We share personal data only with sub-processors that operate under a written data processing agreement compliant with GDPR Art. 28. Our current sub-processors are:
- Supabase (database & auth) — hosting in EU regions.
- Resend (transactional email delivery for form notifications and lesson dispatch).
- Hosting infrastructure — EU-located VPS for the application server.
- Anthropic and/or Google (AI processing) — used to evaluate submitted free-text answers and generate personalised training content. Data is transferred under SCCs; these providers do not use API-submitted data to train their models.
The current list and security posture are described in our Security overview.
4. How long we keep it
- Contact form submissions: 24 months from receipt, or until you ask us to delete them — whichever is sooner.
- Active customer account data: for as long as the account is active.
- Training records and Compliance Folder: for the duration of the contract plus 12 months after cancellation, so the customer retains an exportable evidence trail.
- Operational logs: 90 days, then deleted.
- Accounting and billing records: 8 years, as required by Hungarian tax law (Act C of 2000, §169).
5. International transfers
Where a sub-processor stores data outside the European Economic Area, transfers are protected by Standard Contractual Clauses (Commission Decision 2021/914) plus supplementary measures where required.
6. Your rights
Under GDPR Articles 15–22 you have the right to:
- Access the personal data we hold about you (Art. 15).
- Correct inaccurate or incomplete data (Art. 16).
- Have your data erased (Art. 17), subject to legal retention obligations.
- Restrict or object to processing (Art. 18, 21).
- Data portability for data you provided (Art. 20).
- Withdraw consent at any time, where consent is the basis.
To exercise any of these rights, email privacy@aiworkfluency.com. We respond within 30 days.
7. Complaints
If you believe we have processed your data unlawfully, you may lodge a complaint with the Hungarian data protection authority:
NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság
1055 Budapest, Falk Miksa utca 9-11.
naih.hu
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to active customers at least 30 days before they take effect. The current version is always at this URL, with the “Last updated” date at the top.