Privacy Policy
Last updated: 8 August 2026
This Privacy Policy informs users of the Penzum web application about the processing of their personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the GDPR) and Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the Infotv.).
This Policy is available in Hungarian, English and German via the language switcher in the top-right corner. In case of any discrepancy or interpretation dispute, the Hungarian-language text prevails.
1. Data Controller
| Controller | Simon Richárd e.v. (Hungarian sole proprietorship) |
| Tax number | 91566478-1-33 |
| Registered address | 2040 Budaörs, Kökörcsin utca 17., Hungary |
| support@penzum.app | |
| Website | penzum.app |
The data controller operates as a sole proprietor. Appointing a dedicated Data Protection Officer (DPO) is not mandatory and has not been done; for any privacy question, please contact the controller directly using the details above.
2. Principles of Processing
The controller processes personal data according to the following principles:
- Lawfulness, fairness and transparency — the legal basis for processing is identifiable in every case.
- Purpose limitation — data is collected only for specified, explicit and legitimate purposes.
- Data minimisation — only data necessary for the purpose is processed.
- Accuracy — data is kept up to date; users may amend their own data at any time.
- Storage limitation — data is not retained longer than necessary.
- Integrity and confidentiality — appropriate technical and organisational measures protect the data.
3. Personal Data Processed and Legal Bases
3.1 Data required for registration and account management
| Data category | Legal basis (GDPR) | Retention period |
|---|---|---|
| E-mail address | Performance of a contract (Art. 6(1)(b)) | 30 days from account deletion |
| Password (stored as a bcrypt hash) | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Full name | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Timestamp and version of Terms of Service acceptance | Compliance with a legal obligation (Art. 6(1)(c)) | 5 years (statute of limitations) |
3.2 Financial and tax data (core to the service)
| Data category | Legal basis (GDPR) | Retention period |
|---|---|---|
| Tax identification number | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Date of birth (for tax-allowance calculations) | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Business income (invoices) | Performance of a contract (Art. 6(1)(b)) | Until account deletion; 8 years where statutory accounting retention applies |
| Business expenses | Performance of a contract (Art. 6(1)(b)) | Until account deletion; 8 years where statutory accounting retention applies |
| Primary-employment salary data (monthly gross pay, allowances) | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Voluntary pension fund contributions | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
| Life-event log entries (e.g. marriage, birth of a child) | Performance of a contract (Art. 6(1)(b)) | Until account deletion |
3.3 Special category data — health status
Penzum lets users record a long-term illness / disability status, which Hungarian personal income tax law requires for calculating the severe-disability tax allowance. This data is a special category of personal data under Art. 9 GDPR (health data).
| Data category | Legal basis (GDPR) | Retention period |
|---|---|---|
| Long-term illness / disability status (yes/no) | Explicit consent (Art. 9(2)(a)) — a separate checkbox at the time of entry | Until withdrawal of consent or account deletion |
We process this data only if you explicitly provide it, and you may delete it at any time in Settings. Deletion does not retroactively affect tax estimates already calculated.
3.4 Payment data
Subscription fees are collected by the payment provider Stripe, Inc.Card data (number, CVV, expiry) is stored and processed exclusively by Stripe — it never reaches the controller’s own systems. The controller stores only the following data returned by Stripe:
- Stripe Customer ID
- Stripe Subscription ID
- Subscription status and current plan name
- Next billing date
Legal basis for processing payment data: performance of a contract (GDPR Art. 6(1)(b)); retention period: 5 years from the end of the contractual relationship.
3.5 Technical and log data
Vercel, Inc. and Supabase, Inc., which operate Penzum’s infrastructure, may automatically log the following technical data as part of providing the service:
- IP address (request origin)
- HTTP request metadata (timestamp, endpoint, response code)
- Browser and device type (user agent)
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — maintaining the security and stability of the service and preventing abuse. Logs are retained for a maximum of 30 days, unless a longer retention period is warranted by a security-incident investigation.
3.6 AI Advisor — data transfer to Anthropic PBC
Penzum’s “AI Advisor” feature uses the Claude artificial intelligence service operated by Anthropic PBC (USA). For every Advisor conversation, the system transmits the following data as context to the Anthropic API:
- Name, tax filing form, sole-proprietor type, date of birth, gender
- If recorded: long-term illness / disability status (see section 3.3 — special category data)
- Income, expense and tax-obligation summaries, client names, and per-client revenue concentration
- Short “durable facts” extracted by the AI from earlier conversations (e.g. a planned change of tax form)
- If the user attaches a document to the conversation (e.g. a tax-authority letter): the full content of that document, used solely to prepare that specific reply
Attached documents are not stored permanently by Penzum — the uploaded file is deleted immediately after the reply is generated. Anthropic retains commercial API traffic (including the content of attached documents) for a maximum of 30 days by default for security purposes, after which it is automatically deleted; an exception applies to content flagged by Anthropic’s automated abuse-detection systems, which Anthropic may retain longer (up to 2 years) under its own policy. Anthropic does not use input/output data to train its models without explicit permission.
The legal basis for the EU–US data transfer is the European Commission’s Standard Contractual Clauses (under Implementing Decision (EU) 2021/914), which are automatically incorporated — without a separate signature — into every commercial API customer relationship through Anthropic’s Data Processing Addendum.
Legal basis for transferring personal data to Anthropic: performance of a contract (GDPR Art. 6(1)(b)) — the AI Advisor is an optional feature that the user actively chooses to use. The explicit consent described in section 3.3 governs the transfer of special category (health) data. In the mobile app, the user must give a separate, explicit consent to this data transfer before first opening the AI Advisor — without it, the feature cannot be used on mobile.
3.7 Daily financial tips — another Anthropic PBC AI feature
On the Dashboard shown after login, Penzum displays up to 7 short, personalised financial tips per day, which are also generated by the Anthropic Claude model. For this purpose, the system transmits to the Anthropic API only aggregated financial figures (tax filing form, sole-proprietor type, year-to-date income and expense totals, VAT-exemption threshold usage, estimated tax and contribution burden, and the due dates/amounts of upcoming tax obligations) — not your name, e-mail address, or any other direct identifier. Tips are generated automatically, at most once per day per login; this feature currently cannot be individually disabled, as it is considered a core part of the Dashboard. Retention rules are the same as described in section 3.6. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
4. Data Processors
The controller uses the following processors. Processors act solely on the controller’s instructions and on the controller’s behalf:
| Processor | Activity | Location | Privacy policy |
|---|---|---|---|
| Supabase, Inc. | Database hosting, authentication | USA (EU data centre: Frankfurt) | supabase.com/privacy |
| Vercel, Inc. | Web application hosting, CDN | USA (EU data centre available) | vercel.com/legal/privacy-policy |
| Stripe, Inc. | Payment processing | USA (EU subsidiary: Stripe Payments Europe Ltd.) | stripe.com/privacy |
| Resend, Inc. | Transactional e-mail delivery | USA | resend.com/privacy |
| Anthropic PBC | AI-based features: Penzum Advisor and daily financial tips — see sections 3.6–3.7 | USA | anthropic.com/legal/privacy |
Each processor above has either Standard Contractual Clauses (SCCs) or EU–US Data Privacy Framework certification in place for EU–US data transfers.
5. Disclosure to Third Parties
The controller does not disclose personal data to third parties (other than the processors listed above), except:
- where required by law (e.g. an official authority request),
- where the data subject has given explicit consent,
- where necessary to protect the controller’s legitimate interests (e.g. to assert a legal claim).
6. Your Rights as a Data Subject
Under Chapter III of the GDPR you have the following rights regarding the processing of your personal data. To exercise your rights, write to support@penzum.app— we respond within 30 days.
6.1 Right of access (GDPR Art. 15)
You may ask whether we process your personal data and, if so, obtain a copy of it.
6.2 Right to rectification (GDPR Art. 16)
You may request correction of inaccurate or incomplete personal data. You can amend most of your data yourself on the Penzum Settings page.
6.3 Right to erasure (“right to be forgotten”, GDPR Art. 17)
You may request deletion of your personal data where its processing is no longer necessary, where you have withdrawn consent, or where you object to processing and no lawful ground for retention exists. Please note that data processed under a statutory obligation (e.g. billing data during the statutory accounting-retention period) cannot be deleted before that period expires.
Your account — and with it the majority of your processed data — can be deleted on the Penzum Settings page.
6.4 Right to restriction of processing (GDPR Art. 18)
You may request restriction of processing, for example while you contest the accuracy of your data (until accuracy is verified), or while an objection to processing (see 6.6) is being assessed.
6.5 Right to data portability (GDPR Art. 20)
You can export your Penzum data (income, expenses, primary-employment data) in a machine-readable format (CSV/JSON) from the Settings menu. For portability requests, we can also send the data by e-mail.
6.6 Right to object (GDPR Art. 21)
You may object to processing based on legitimate interest (e.g. log data, security processing). The controller will then assess whether its legitimate interest overrides your interests.
6.7 Withdrawing consent
Where processing is based on consent (e.g. processing of special category health data), you may withdraw your consent at any time — this does not affect the lawfulness of processing carried out before the withdrawal.
7. Data Security
The controller applies the following technical and organisational measures to protect personal data:
- Encryption in transit: all communication takes place over HTTPS/TLS.
- Encryption at rest: the database (Supabase / PostgreSQL) stores data on encrypted disks.
- Password security: passwords are stored as bcrypt hashes; plaintext passwords are never recorded.
- Access control: Row Level Security (RLS) rules ensure every user can access only their own data.
- Administrative access: server-side operations use a service-role key accessible only from server-side code; the key never reaches the client.
- Two-factor authentication: 2FA is enabled on the controller’s infrastructure access.
8. Data Breaches
In the event of a personal data breach (e.g. unauthorised access, data leak), the controller notifies the supervisory authority (NAIH) within 72 hours under GDPR Art. 33 if the breach poses a risk to data subjects. If the breach poses a high risk, affected users are also notified under GDPR Art. 34.
9. Cookies
Penzum uses the following types of cookies:
| Cookie name / type | Purpose | Legal basis | Expiry |
|---|---|---|---|
| Session cookies | Maintaining logged-in state (Supabase Auth JWT) | Performance of a contract | Deleted on browser close / max. 7 days |
| Security cookies (CSRF protection) | Protection against cross-site request forgery | Legitimate interest | End of session |
| Google Analytics 4 (_ga, _ga_*) | Measuring site usage, only on public (logged-out) pages — landing page, blog, features/pricing, sign-up, onboarding | Consent (accept/reject in the cookie banner) | Max. 13 months |
On its public, logged-out pages (landing page, blog, features/pricing page, sign-up, onboarding) Penzum uses Google Analytics 4 to measure traffic, only with your consent (Consent Mode) — if you decline in the cookie banner, no measurement takes place. No analytics script runs in the logged-in user interface (the dashboard and the pages beneath it), so no tracking related to your financial data occurs there.
10. Right to Lodge a Complaint with a Supervisory Authority
If you believe that the processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
| Authority | Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
| Address | Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., Hungary |
| ugyfelszolgalat@naih.hu | |
| Website | https://naih.hu |
If your request to the controller is refused, you may also seek judicial remedy under the Hungarian Civil Code and the Infotv.
11. Automated Decision-Making and Profiling
Penzum does not carry out automated individual decision-making within the meaning of GDPR Art. 22. Tax estimates and calculations are for informational purposes only; no decision with legal or similarly significant economic effect is automatically attached to them.
12. Changes to this Policy
The controller reserves the right to amend this Policy. For material changes, users are notified by e-mail and/or an in-service notice at least 30 daysbefore the change takes effect. Continued use of the Service after the amended Policy takes effect constitutes acceptance; a user who does not accept the change is entitled to delete their account.
The current version of this Policy is always available at penzum.app/privacy.