Legal · privacy

Privacy Policy

Effective: June 5, 2026 · prometisone.com

This policy describes how data submitted through the Prometis One website and contact form is collected, stored and processed.

1. Data Controller

CompanySilio Digitális Médiaügynökség Kft.
Registered office8411 Veszprém, Kőalja utca 1., Hungary
Contact emailhello@silio.io
Websitehttps://prometisone.com

The data controller is not required to appoint a Data Protection Officer (DPO) as it does not carry out large-scale processing of special category data and is not a public authority. For data protection inquiries, please contact us at the email address above.

3. Scope of Data Collected

The following data is collected through the contact form:

DataTypeRequiredDescription
NamePersonal dataYesName of the data subject
EmailPersonal dataYesFor follow-up communication
CompanyBusiness dataNoEmployer of the data subject
RoleBusiness dataNoPosition of the data subject
AI challenge typeNon-personalYesSubject of interest (AI readiness / MVP / business problem / AEO-GEO / other)
DescriptionDepends on contentYesFree-text description of the challenge

The following technical data is logged automatically:

DataDescription
Submission timeDate and time of form submission
Source pageThe subpage from which the form was submitted
ReferrerThe preceding URL reported by the browser (if available)
User-AgentBrowser/device identifier (e.g. "Chrome 125 / macOS")
Submission languageWhether the form was filled out on the Hungarian or English interface

Special categories: We do not collect health, political, religious, biometric or any other special category data.

4. Data Retention Period

Data submitted via the contact form is retained for 1 (one) year from the date of submission. Inactive inquiries that have not led to a business relationship are deleted when the 1-year period expires.

If an inquiry leads to an active business relationship, data is retained according to the applicable statutory retention obligations (e.g. accounting laws).

5. Data Processors

The data controller uses the following data processors:

5.1 Supabase (database & hosting)

CompanySupabase Inc.
Headquarters970 Toa Payoh North, Singapore (global)
Data centerFrankfurt, Germany (EU Central-1 region)
RoleDatabase provider — stores inquiry data in a PostgreSQL database
GDPR complianceData is stored within the EU (Germany); subject to EU GDPR
DPASupabase DPA (available at supabase.com/privacy)

5.2 Vercel (web application hosting)

CompanyVercel Inc.
RoleHosts the prometisone.com website and API endpoints
GDPR complianceVercel SCCs and DPA, available at vercel.com/legal/privacy-policy

Data processors may only process data according to the data controller's instructions and for the purposes defined by the data controller; they may not use the data for their own purposes.

6. Third-Party Data Transfers

We do not transfer data outside the European Union, nor to third parties for marketing or profiling purposes. We do not sell, rent or share personal data with advertisers or other third parties. Exception: if a competent authority (e.g. court, NAIH) orders data disclosure based on a lawful request.

7. Profiling and Automated Decision-Making

We do not carry out profiling and do not use automated decision-making that would have legal effects on or significantly affect the data subject (GDPR Art. 22).

8. Cookies

prometisone.com currently does not use tracking or analytics cookies. Technically necessary session data (e.g. language preference) may be stored temporarily on the user's device, but this data is not shared with third parties and cannot be used for personal identification.

If we introduce an analytics tool (e.g. Google Analytics, Plausible) in the future, this policy will be updated and data subjects will be informed.

9. Data Security

The following technical and organizational measures are in place to protect data:

  • Encryption: data is transmitted via HTTPS and stored encrypted in the database
  • Access control: inquiry data is accessible only to the authenticated admin user (Row Level Security / RLS)
  • Insert permissions: the public API can only insert data via the service role key; direct user inserts are not possible
  • Rate limiting: the API endpoint has IP-based rate limiting to prevent abuse
  • Bot protection: a honeypot field filters out automated submissions
  • Data minimization: only data necessary to respond to the inquiry is stored

10. Rights of the Data Subject

Under the GDPR, you have the following rights:

RightDescription
Right of access (Art. 15)You may request information about whether we process your data, and if so, what data and for what purpose
Right to rectification (Art. 16)You may request correction of inaccurate data or completion of incomplete data
Right to erasure (Art. 17)You may request deletion of your data if the purpose of processing has ceased or you withdraw consent
Right to restriction (Art. 18)You may request that processing be restricted (e.g. if accuracy is contested)
Right to data portability (Art. 20)You may request your data in a machine-readable format (e.g. JSON/CSV)
Right to object (Art. 21)You may object to processing if legitimate interest is the legal basis
Withdrawal of consent (Art. 7)Consent may be withdrawn at any time; this does not affect the lawfulness of prior processing

How to exercise your rights: send your request by email to hello@silio.io. We will respond within 30 days.

11. Right to Lodge a Complaint

If you believe that the processing of your data does not comply with the GDPR, you may file a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

  • Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
  • Phone: +36 (1) 391-1400
  • Email: ugyfelszolgalat@naih.hu
  • Web: naih.hu

12. Changes to This Policy

The data controller reserves the right to amend this policy. Data subjects will be notified of changes on the website; in case of material changes the effective date will be updated.

Silio Digitális Médiaügynökség Kft. — Veszprém, 2026. June 5.