Datenschutzerklärung
Dieses Dokument liegt nur auf Englisch vor. Die englische Fassung dient ausschließlich der Information; bei Abweichungen ist der ungarische Text maßgeblich.
Trendizz.com Kft. Version: 2026-4. Effective from: 2026-09-29.
This English version is provided for information only. In the event of any discrepancy, the Hungarian text prevails.
If you have received a business email and want it stopped
There are two routes, and the difference matters.
- Reply to the sender to say that you do not want any further emails. This stops the outreach only at the one client of ours who wrote to you: the system permanently excludes your address at that client.
- Write to [email protected] if you want your contact details removed from our database. We then delete them, so that our clients no longer receive them from us. If a client of ours happens to be writing to you, we have the outreach stopped at their end too. We do this manually, independently of the automatic detection.
Both are free of charge. We answer a request sent to us within one month at the latest. The details are in sections 4.4, 4.5 and 9.
1. Who we are and what this notice is about
Trendizz is a business search system and outreach platform for companies. We build a database from public company websites. Our clients search it to find potential business partners for themselves, and contact them from their own email address with the help of the system. The platform's artificial-intelligence assistant is called Apex.
This notice tells you whose personal data we process and of what kind, why, for how long, to whom we disclose it, and what rights you have. It is based on the European Union's General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information, the Act CVIII of 2001 on Electronic Commerce Services, and the Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.
The controller
| Item | Value |
|---|---|
| Name | Trendizz.com Korlátolt Felelősségű Társaság (hereinafter: "Provider") |
| Registered office | 2651 Rétság, Jászteleki út 12. 2.a., Hungary |
| Company registration number | 12-09-012013 (Court of Registration of the Balassagyarmat Regional Court) |
| Tax number | 27864966-2-12 |
| [email protected] | |
| Represented by | Péter Gebri, Managing Director |
| Websites | trendizz.com, apex.trendizz.com |
We have not appointed a data protection officer. On data protection matters you can reach us at the email address above.
2. Who this notice applies to
There are five groups. Find your own; we write about each of them separately in Chapter 4. By client we mean the subscriber company, and by client user its employee who logs in with an account.
- Website visitor: anyone who opens the trendizz.com or the apex.trendizz.com site.
- Prospect: anyone who requests access to the system on the demo request page or by email, or whom one of our partners recommends for a demo.
- Client user: anyone who logs in to the system with an account as an employee of a subscriber company.
- Our clients' business partners and contact persons: those whose data a client of ours processes in the system, to whom a client writes, or who reply to a client.
- Companies and contact persons appearing on public websites: those whose data, published on the company's website, enters our database.
The same person may appear in two groups: their data published on the company website is in our database (group 5), and if a client of ours writes to them, in that client's campaign as well (group 4). You can ask us to erase your data from the database, and you can stop an ongoing outreach at the sender's end with a single reply. If you write to us, we also have the outreach stopped at the sender's end.
Section 4.7 covers the data of anyone who writes to us through the contact form. We write about partner candidates and partners in a separate chapter (Chapter 5). Where a partner also has their own subscription, this same notice applies to them as a client; Chapter 5 describes the additional aspects of the partner relationship.
3. Controller or processor: our two roles
The GDPR distinguishes between the party that decides on the purpose and means of the processing (the controller) and the party that processes data on another's behalf and on that other's instructions (the processor). Trendizz works in both roles.
| Data set | Trendizz's role | Who the controller is |
|---|---|---|
| Website visitors, prospects, client users' accounts | controller | Trendizz |
| The company database built from public websites | controller | Trendizz |
| Partner candidates' and partners' data (application, selection, partner view, log of management work, commission, quality-assurance inspection) | controller | Trendizz |
| The messages of the Message Channel; insight into accounts and its log, as regards the users' data (4.8) | controller | Trendizz |
| Insight into accounts and automated checks for the purpose of preventing abuse, also as regards the data appearing in the client's correspondence and campaigns (4.8) | controller | Trendizz |
| Contact persons from our database who ended up in a client's campaign, if they did not reply, replied with a rejection or asked for the outreach to stop; the register of exclusions | controller | Trendizz |
| Address data taken over from the campaigns: whether the address is undeliverable, whether a human reply has come from it, the job title of the person who replied and the date of the observation (4.4 B) | controller | Trendizz |
| Those who replied to our client with interest, the client's own contacts, notes and tasks, and our client's correspondence with them | processor | the client company |
| The recipients of partner letters recommending Trendizz (the partner writes with our email templates, from our database) | joint controller | Trendizz and the sending partner |
The contact-person data from our database shown to our client remain ours even if our client writes to you; our client may use them only within the system, for its own campaign, and not as its own list. If you reply to our client with interest, the reply and your related data become our client's data, and our client is the controller.
Where we are a processor, the controller is our client. We carry out the automatic classification of emails, the reply suggestions and the recognition of stop-requesting replies on the client's behalf, using a method developed by Trendizz. The allocation of responsibility is set out in the Data Processing Agreement concluded with the client, which forms part of the contract; we make its substance available on request. In such cases the data subject may exercise their rights primarily at our client, but if they turn to us, we forward the request and assist with fulfilling it. Insight into accounts for quality assurance and error correction (4.8) is, as regards the client's correspondence, a processing purpose set out in the Data Processing Agreement. For insight carried out to prevent and detect abuse, however, we act as controller, in our own legitimate interest.
A partner may appear in more than one place in the table above. As regards the partner application, selection, the log of their management work carried out in the system, commission accounting and quality-assurance inspection, Trendizz is the controller. Where a partner manages the account of a client of ours, they act as Trendizz's sub-processor as regards the client's data, and as Trendizz's processor as regards the data from our database, the data of the client's users and the messages of the Message Channel. Where a partner also has their own subscription, the same applies to the campaigns run in their own account, their own contact persons and their correspondence as to any client: there the partner is the controller and Trendizz is the processor. Where the partner sends a letter recommending Trendizz with our email templates and from our database, Trendizz and the partner are joint controllers of the recipients' data. Chapter 5 describes the details.
4. What data we process, why and for how long
4.1 Website visitors
What we process. The web server's technical log records the visitor's IP address, the browser identifier string, the requested page and the time. This is needed for troubleshooting and for detecting abuse.
Cookies and browser storage. We use only cookies that are strictly necessary for operation, so we do not ask for cookie consent. We have two cookies of our own, both created only at login:
| Cookie | Purpose | Lifetime |
|---|---|---|
| access_token | identifying the logged-in session | 15 minutes |
| refresh_token | silent renewal of the session | 30 days |
Both cookies are HttpOnly and travel only over an encrypted connection. In the browser's local storage the system stores a random device identifier and interface settings (language, layout, notification decision). The device identifier is not suitable for tracking, and it is regenerated when the browser data is cleared.
What we do not do. We do not use any traffic-measurement, advertising or social tracking code, and we do not place any third-party cookies.
Legal basis. Our legitimate interest in operating the service securely (Article 6(1)(f) GDPR).
Retention. We keep the web server's and the network's technical logs for at most 90 days. Separate from this is the system's application and access log (who did what in the account, and when). Under the contract we keep this for 5 years from the termination of the contract, as evidence in payment and legal disputes.
4.2 Prospects
The system is closed; access is by invitation. Anyone who wants access applies on the demo request page of trendizz.com or by email.
What we process. The name, business email address, phone number, country and language given on the demo request page; if provided, what you write in the "How can we help?" field (up to 1,000 characters), and the time slots and week indicated for a call. We also record from which page of the website you started the request (for example the Pricing page), the time zone reported by your browser, the IP address and browser identifier of the submission, and the content of our correspondence. After submission we send an automatic confirmation email to the address given, at most one per address in any 24 hours, so that the page cannot be used to flood someone else's address with emails. For this we store the SHA-256 digest (hash) of the address and the time of the last sending. If you start the demo request through the invitation link of one of our partners, we also record which partner's link it came from; even then, we decide on the demo. If the invitation was initiated by our partner, the company's name, tax number and domain, and your name and email address, were given to us by the partner; in that case we compare the company's data with our own records. We also decide on an invitation initiated by a partner. The company is assigned to the partner not by the first use of the link but by an invitation approved by us (a demo request arriving through the invitation link counts as an invitation, and becomes an approved invitation upon approval). For the purpose of settlement with the partner, an approved invitation assigns the company to the partner for 30 days from the approval and the sending of the invitation; this may be renewed for a further 30 days by a new, approved invitation. For this we store the partner's identifier, the time of the invitation, the approval and the sending, and the expiry of the assignment. The assignment places no obligation of any kind on you. We look at the public website of the company given, to decide whether we can help.
Legal basis. Processing the application, the confirmation and making contact is a step taken at your request to prepare a contract (Article 6(1)(b)). Looking at the company's website is our legitimate interest in assessing the application. Processing the IP address, the browser data and the digest stored for the confirmation limit is our legitimate interest in filtering out abuse. Processing the data given by the partner, the comparison with our records and the assignment are our legitimate interest in assessing the invitation and in the settlement with the partner (Article 6(1)(f)).
Demo access. If you receive an invitation, you can get to know the system with free, demonstration-type access for fourteen days from the invitation (we may extend this in justified cases), and you can talk to Apex. The system then works in demo mode, with sample data. In this case we also store the login data and your conversation with Apex. The conversation may be reviewed by our staff for quality-assurance and abuse-prevention purposes, and the system may also examine it automatically; this is also stated by the Prospect Terms accepted at login. Anyone applying to be a partner (a partner candidate) receives the same demo access (Chapter 5).
Retention. If no contract comes about, we delete the data 12 months after the application, or after the demo access is closed. If a contract does come about, the data becomes part of the account data (4.3), and the data of the partner assignment becomes part of the commission settlement data (Chapter 5). We keep the digest stored for the confirmation limit and the time of the last sending for 24 hours plus a short margin, and then delete them.
4.3 Client users
Employees of the subscriber company receive an account by invitation. The account belongs to the company's subscription, and the company's administrator decides who has access.
What we process.
| Data set | Details |
|---|---|
| Identification data | name, email address, phone number, job title, profile picture, language and time zone |
| Login | login with a password is not possible; login is by a one-time code sent by email, valid for 10 minutes, and we store the code only in an irreversible form |
| Logged-in devices | per device, the browser identifier, the time of login and of last activity, the login IP address and the last five IP addresses used; at most 10 devices per user |
| Notifications | if you enable browser notifications, the subscription address and keys issued by the browser, and the device name |
| Contract acceptance | who accepted which version of the text and when, and the IP address and browser identifier of the acceptance (the evidence of the contract) |
| Role within the company | permission level, group membership, leave periods, the fact and reason of any suspension |
| Usage | which functions you used and when (the log of tasks, notes, campaign operations), the per-user volume of artificial-intelligence calls |
| Conversation with Apex | your messages written to Apex and the replies, the rolling summary of the conversations; the conversations may be reviewed by our staff as set out in section 4.8, the company's Account partner sees them in the managed account, and the system may also examine them automatically (clauses 9.6 and 14.6 of the contract) |
| Messages with the account manager | the messages and attachments exchanged, on the system's topic-based Message Channel, between your company and the party managing its account (Trendizz or Trendizz's Account partner), the original text and the translation made by the system. All communication relating to the service takes place here, including onboarding. Users cannot edit or delete a message or an attachment, only close the topic; in the event of a discrepancy, the original text prevails. Contact lists and campaign data cannot be uploaded here; they enter the system only through Apex, by import. If personal data of a campaign nevertheless ends up here, we delete it together with the campaign data (4.4); the text of the message and the trace of the attachment (its name, time and digest) remain. On the basis of a legal obligation or a well-founded data subject request, we may redact the content of a message, and we log the redaction |
| Approval requests | the log of the requests sent to you in the system for approval (for example a change to an email, a campaign, the targeting or the subscription): when they were sent, when you opened them, when a reminder went out, who accepted or rejected them and when, and when a deadline proposed in the complaint stage was deemed accepted. The log cannot be deleted, and it proves which party was waiting for the other (paragraphs (1d) and (1e) of Chapter 16 of the contract) |
| Apex's memory | facts remembered about the user and the company, and summaries of the conversations, per user and per company, so that Apex can build on earlier work when helping |
| Uploaded files | documents and images uploaded to the system |
| Newsletter | the yes or no given in the settings |
System messages. We send the invitation, the login code and the system's notifications by email from the [email protected] address. These are system messages that belong to the operation of the service, and can be turned off in the settings.
Newsletter. We send a newsletter only if you actively tick this in the settings. Without a subscription we do not send one. The consent can be withdrawn at any time, as easily as subscribing, in the settings or via the unsubscribe link in the email.
Legal basis. If you are the subscriber, the performance of the contract (Article 6(1)(b)). If you are an employee of the subscriber company, the legitimate interest of the company and of Trendizz in providing the service (Article 6(1)(f)). The security logs and the evidence of contract acceptance are our legitimate interest (Article 6(1)(f)). Processing the messages of the Message Channel and the log of approval requests is the performance of the contract, or the legitimate interest in providing the service; keeping them for 5 years is our legitimate interest in proving contractual claims (Article 6(1)(f)). The newsletter is based on your consent (Article 6(1)(a)). Processing and keeping the billing data is a legal obligation (Article 6(1)(c), Act C of 2000 on Accounting).
Retention.
| Data | For how long |
|---|---|
| Account, profile, uploaded files, conversations with Apex | for 12 months after the subscription ends, then erasure |
| Apex's memory | as long as the account exists; can be deleted on request |
| Login code | 10 minutes |
| Device session | deleted after 30 days of inactivity; the trace of a logged-out device remains for 7 days |
| Notification subscription | as long as the browser maintains it; we automatically delete an expired subscription |
| Evidence of contract acceptance and the operations log | for 5 years from the termination of the contract (the limitation period for claims) |
| Messages and attachments of the Message Channel, the log of approval requests, the log of insight | for 5 years from the termination of the contract (the limitation period for claims) |
| Volume of artificial-intelligence calls | 12 months |
| Billing data | for 8 years under the Accounting Act |
4.4 Our clients' business partners and contact persons
In this group we have two roles, so we describe it in two parts. Part A) is about those whose controller is our client: those who replied to our client with interest, and those whom our client added to the system as its own contacts. Here Trendizz is the processor. For the processing described in Part B), Trendizz itself is the controller: this covers the contact persons from our database who ended up in a client's campaign, if they did not reply, replied with a rejection or asked for the outreach to stop.
A) Processing on our client's behalf: Trendizz is the processor
Here the controller is our client. We describe what the system does, so that you can see where your data goes. The correspondence works the same way where the contact person's data comes from our database; in that case we are the controller, as set out in Part B).
Correspondence. Our client connects their own business email account to the system (with SMTP and IMAP access, or with Google or Microsoft login). Through this account the system sends out our client's emails and reads in the incoming replies. We store the full content of the emails, the attachments, the sender, the recipient and the subject, so that our client can see and manage the conversation in the system. We store the account's access data in encrypted form, and no member of staff or partner of Trendizz gets to know it.
Artificial intelligence in the correspondence. The system automatically classifies incoming emails: important or noise, and what the reply's intent is (interest, rejection, a request to stop). The purpose of the classification is to organise the emails and to help with replying; we do not build a content profile, and the classification has no legal effect on you. At our client's request the system also drafts a reply suggestion. For this, the content of the email is processed by the language model provider listed in Chapter 6. The individual reply suggested by Apex is always approved by our client.
What goes out automatically. The campaign emails, the reminders and the template replies preset by the client (for example the confirmation of a stop) are sent by the system on the basis of our client's pre-approved templates and process, without separate approval for each email. Even then the sender is our client, from their own address.
Contact persons and notes. Our client can record contact persons in the system (name, email, phone, job title, photo, links, notes, the status of the relationship). The system logs who modified what and when.
If you have received an email from a client of ours. The sender is our client, from their own address. If you do not want any further emails from this sender, it is enough to reply. The system recognises the stop-requesting reply and permanently excludes your address at this client of ours. A single reply stops only this one sender; the system keeps the exclusion permanently. If you would also like your contact details deleted from our database, or the reply did not produce a result, write to [email protected]. We then delete your data, and have the outreach stopped manually at the sender's end, independently of the automatic detection. We do this without undue delay.
Retention. We keep the client's data for 12 months after the subscription ends, then delete it; at the client's request we delete it earlier too. On leaving, the client receives their own data on request: the data of those who replied with interest and of the contacts they loaded themselves, the contact-person entries, notes and tasks, and the correspondence with these persons. The client does not receive the data of contact persons from our database who did not reply, replied with a rejection or asked for the outreach to stop. The fact of the exclusion remains even after the erasure, so that the ban stays in force.
B) What Trendizz processes as controller
Contact persons from our database who ended up in a campaign. If our client selected you from our database (4.5), your contact-person data remain ours after the campaign as well, and we are the controller, if you did not reply, replied with a rejection or asked for the outreach to stop. Our client may use these only within the system, for its own campaign, not as its own list, and does not receive them on leaving either. We keep the rejection and the request to stop, so that the exclusion stays in force. The legal basis is our legitimate interest and our clients' legitimate interest in business outreach (Article 6(1)(f)), as in section 4.5. We keep the campaign data for 12 months after the client's subscription ends, and the exclusion permanently.
Address data from the campaigns. From our clients' campaigns we take over only the following, for the accuracy of our database and the deliverability of emails: whether the address is undeliverable (bounced email), whether a human reply has come from the address, the observed job title of the person who replied, and the date of the observation. We do not take over the content of the emails, or whether the reply was interested or a rejection. We keep these for 24 months from the last observation, after which they are deleted automatically. No client of ours can recognise the results of another client's campaigns, and we do not use these data to rank contact persons for another client. Where the data comes from a person whose controller is our client (Part A)), our client has authorised the taking over in its contract with us; we are the controller of the data taken over. The legal basis is our legitimate interest (Article 6(1)(f)): the accuracy of the database, the deliverability of emails, and that the recipient does not repeatedly receive emails at a wrong address. We receive these data not from you but from our clients' campaigns (the source under Article 14(2)(f) GDPR).
Statistics. We produce aggregated statistics on the reply rate that cannot be linked to a company name or a person.
4.5 Companies and contact persons appearing on public websites
This is the part that affects the most people who have never heard of us. Here Trendizz is the controller.
Where the data comes from. All the data we store about a company comes from the company's own, publicly accessible website: from the home page, from the contact, about, services and imprint-type pages, and from the structured data published by the company on the site. The list of websites to be processed is compiled from two sources: public, free domain registries, and links found on already-processed websites that point to other companies' websites. From neither source do we take any personal or content data, only the address of the website. The exception is the address data described in Part B) of section 4.4 (whether the address is undeliverable, whether a human reply has come from it, the job title of the person who replied and the date of the observation), which comes from our clients' campaigns. We do not use purchased address lists, social networks or company registers.
What we store.
| Data set | Details |
|---|---|
| About the company | company name, address, country, geographic coordinate, the website's address and language, a short summary of the activity, industry classification, product categories, the website's technical characteristics |
| About contact persons | at most three contact persons per website: name, email address, phone number, job title, and which part of the site the data comes from |
We do not store the full text, images or screenshot of the website. The system processes the text, extracts the summary and the data above, and discards the rest.
What we use it for. Our clients search this database for companies whose products or services their own might be useful to, and make contact in their own name, for a business purpose. We show the data to our clients only within the system. There is no bulk release, download or resale.
Legal basis. Our legitimate interest and our clients' legitimate interest in business outreach (Article 6(1)(f)); we have recorded the legitimate interests assessment in a separate document. The substance of the legitimate interests assessment is:
- the data was published by the company itself, for the purpose of business outreach;
- we store only the public business contact details, never any private data;
- the outreach relates to the company's business activity;
- unless it has asked for them itself, a company typically receives at most six emails a year from one client of ours; if it replies, the sequence stops, and if a substantive discussion with the sender begins, any further correspondence is part of that discussion;
- the outreach can be stopped at any time with a single reply.
The named business addresses published on the website for the purpose of making contact are likewise used only for contact relating to the company's business activity, and anyone who indicates that they do not want outreach will not receive any more from that particular sender. Where the law of the recipient's country requires prior consent for electronic outreach between businesses, Apex warns our client about this and asks for documented consent. The decision to send is taken by our client as controller, and the responsibility for sending rests with them.
Information. We did not receive the data from you, so under Article 14 GDPR we inform you by means of this notice. As the public websites contain the data of several million companies, we cannot notify everyone individually. If a client of ours sends you an email, you can see from the email itself who is contacting you and why.
Updating and retention. We reprocess the websites regularly, whenever the processing is running, and adjust the stored data to the public content. As long as the website is public, we keep the data. We regularly review websites that have become unreachable, and delete the contact-person data of pages that have been unreachable for a long time, at least 12 months. If you object, we delete your contact-person data, and it does not return to the database after the erasure.
How the data is prepared. The data above is extracted from the text of the website by a language model. This processing runs either on infrastructure we operate or at the artificial-intelligence providers listed in Chapter 6, under the conditions described there. The finished company summary may be passed to the language model providers listed in Chapter 6 for verifying the search and for translation. We determine the coordinate of the locality partly from our own database and partly using the OpenStreetMap service; for this we send only the name of the locality and the country.
4.6 Trendizz's own outreach
For acquiring our own clients we too use the database above and our own system: we contact companies from our own address, with the same rules that apply to our clients. In this case we process the data referred to in section 4.5 and your reply, on the basis of legitimate interest (Article 6(1)(f)). You can stop it with a single reply, and we permanently exclude your address. Partner letters recommending Trendizz are covered in Chapter 5 (Partner letters recommending Trendizz).
4.7 Contact form
What we process. If you write to us on the contact page of trendizz.com: the name, email address, company name, chosen topic and message you give, the language of the interface, and the IP address and browser identifier of the submission.
Purpose. Answering the message.
Legal basis. Our legitimate interest in answering the enquiries we receive (Article 6(1)(f)); where the message precedes the conclusion of a contract, a step taken at your request to prepare a contract (Article 6(1)(b)).
Recipients. We forward the message to the Trendizz mailbox belonging to the chosen topic (invite@, support@, partners@, billing@, privacy@, security@ or [email protected]), through the email sending service of Amazon Web Services (Chapter 6).
Retention. 12 months, after which we delete it.
4.8 Insight into accounts
What we see. Designated members of our staff may enter any client or partner account at any time, but only for a specific reason: a client's request or complaint, an automatic alert from the system, an error report or a random quality-control sample. They look only at the content that the reason requires. This may include the content of sent and received emails, the messages and attachments of the Message Channel (including messages between the partner and the client), the Apex conversations, the campaigns, the contact persons and the tasks. Our staff member responsible for partners may also look into the partner's own account, partner demo account and manager account, and into the accounts of the clients the partner manages. The system may also check the same content automatically with artificial intelligence; for this, the content may be passed to the language model providers listed in Chapter 6.
Purpose. Ensuring the quality of the service, correcting errors, support, and preventing and detecting abuse (for example unlawful or misleading correspondence, or use of the system contrary to its intended purpose).
Legal basis. For the data of users and partners, our legitimate interest in the quality of the service and in preventing abuse (Article 6(1)(f)). For the client's data (Part A) of section 4.4), we act as processor for insight carried out for quality assurance, error correction and support; this is a processing purpose set out in the Data Processing Agreement concluded with the client. For the contact-person data from our database (Part B) of section 4.4), we are the controller. For insight and automated checks carried out to prevent and detect abuse, we are an independent controller, on the basis of our legitimate interest (Article 6(1)(f); Chapter 3).
Limits. Only a staff member who needs it for their task may look into an account. We log every instance of insight: who entered which account, when and for what reason, what they modified or downloaded, which of their requests the system denied, and when an automated check ran. The content seen is subject to confidentiality, and we use it only for the purposes above. An automated check has no legal effect in itself; a member of our staff decides on any action (Chapter 8). The client receives the log for its own account on request.
Retention. We keep the log of insight for 5 years from the termination of the contract; the retention rules of sections 4.3 and 4.4 apply to the content of the account.
5. Partner candidates and partners
Trendizz also works with partners: a partner refers clients to us and, where their partnership extends to it, also manages those clients' accounts. Even then the client contracts with Trendizz, with its own account, its own data and its own mailbox; by default the account is managed by Trendizz. There are three types of partnership:
- Referral partner: introduces Trendizz and hands over an invitation link. They do not enter any client's account and do not see client data.
- Account partner: manages the accounts of the clients they look after from a free-of-charge manager account. No emails can be sent from the manager account, and it holds no contact records of its own.
- Market entry partner: with their own subscription, from their own account, also wins clients for their own business, and manages the accounts of the clients they bring in.
As a partner candidate. Anyone who wishes to become a partner applies on the partner application page of trendizz.com. We process the name, business email address, phone number, company name, website (if any), country and chosen partnership given there, and what the applicant writes about their line of business; for the Market entry partnership, the target market indicated as well. We process the source page, the time slots and week indicated for a call, the time zone, the IP address and the browser identifier, and the confirmation email in the same way as for prospects (section 4.2). After the application a member of our staff presents the system at a meeting; we store the steps of the selection process and notes of the conversations. The candidate receives the same demo access as a prospect client (section 4.2). We do not hold an exam.
The partner's access. Every partner sees in the system their invitation link, the status of the companies they have referred and their commission statement. In this view only the data necessary for the settlement is shown about a referred company: the company name, the status of the contract, the charges and the commission items. Referral and Account partners additionally receive demo access without expiry (a partner demo account), with sample data, without live sending and without real client data, and may also present the sample data to third parties. Our staff may review the Apex conversations held in the partner demo account as set out in section 4.8, and we keep them for 12 months after the partner agreement ends. We share the partner's name, company and country with the client the partner brought in.
When the partner manages a client's account. The Account partner from their manager account, and the Market entry partner from their own account, crosses over into the company of the client they manage in the system's dedicated working mode. The client's company belongs to the client, not a sub-account of the partner. In doing so, the partner acts on behalf of Trendizz, as Trendizz's sub-processor, in accordance with the client's instructions; they process the contact-person data from our database (Part B) of section 4.4), the data of the client's users and the messages of the Message Channel as Trendizz's processor. They see only the data of the clients they manage, but for those clients the whole client account, within the system: among other things the target group, the campaigns and their emails, the contact persons, the tasks and the Apex conversations. They may not export the data from the system, move it into another account (including their own), or use it for their own or anyone else's purposes, and they may not contact the client's prospects. They do not receive the mailbox password or access credentials. The client's account may be managed only by a named person approved by Trendizz, with their own access. The partner undertakes a written confidentiality and data processing obligation, and Trendizz is responsible for their activity. Before a new external partner receives access to the client's account, we give the name, company and country of the person managing the account on the Message Channel. The client may object within five working days on data protection grounds or because of a conflict of interest; in that case the account is managed by another partner or by Trendizz. The partner and the client correspond about the service on the system's topic-based Message Channel (4.3). We log the modifications, downloads and denied requests made by the partner in the client's company; the client receives the log on request.
Add-on services. A partner may provide the client with add-on services (for example telephone follow-up or appointment setting) in their own name and for their own account. Where they use the client's data stored in the system for this, they may do so only within the system, with access granted by the client and revocable at any time, and may not export the data; in this respect they act as the client's processor. A Referral partner does not receive access to the client's data for this either.
The partner's own subscription. A Market entry partner has their own subscription, which they manage themselves, and any partner may also bring in their own company as a subscriber. The same rules apply to the campaigns run in the own account, to the own contact persons and to the correspondence as to any client: there the partner is the controller, Trendizz is the processor, and sections 4.3 and 4.4 govern.
Inspection. The insight described in section 4.8 also applies to the partner. Designated members of our staff may, partly with an automated tool, for the reasons and to the extent set out in section 4.8, look into the partner's own account and into the accounts of the clients the partner manages, including the content of emails, the messages between the partner and the client, and the partner's Apex conversations. We log every instance of insight, and the content seen is subject to confidentiality.
Commission settlement. For the commission we record the partner's invitations approved by us, their time and their 30-day assignment period, and whether the contract came about within the assignment period (4.2). We process the charges of the referred companies, the commission items, and the partner's invoicing and payout data. The partner issues one invoice to us per month for the commission and uploads it to the System. We pay the commission by bank transfer to the bank account the partner provides; for this, our account-holding bank receives the partner's name, bank account number and the amount paid.
Affiliated undertakings. When concluding the partner agreement, the partner makes a declaration of its affiliated undertakings. These are the undertakings in which it has majority control, or which are controlled with majority influence by its member, its executive officer or a close relative of these. The declaration is required because these undertakings may belong to the partner as clients but do not count towards meeting the partner conditions. From the declaration we process the name and identifier of the affiliated undertaking, the nature of the relationship and, where the relationship exists through a person, the name of that person and their relationship to the partner. The legal basis for the partner's data is the performance of the partner agreement (Article 6(1)(b)), and for other persons named in the declaration, our legitimate interest in the correctness of the commission settlement (Article 6(1)(f)); the source of the data is the partner. The retention rule for partner data applies to it.
Partner letters recommending Trendizz. Our partners may also recommend Trendizz to companies in a letter sent under their own name, marked "Trendizz Partner", using our email templates and our database under section 4.5: a Market entry partner from their own account, a Referral partner or an Account partner from the free-of-charge Trendizz recommendation account provided for this purpose. For the data of the recipients of such a letter, Trendizz and the sending partner are joint controllers (Article 26 GDPR). Trendizz is responsible for the legal basis of the processing (legitimate interest, Article 6(1)(f)), for ensuring that such a letter is sent only to countries where cold business email is permitted, for the email templates, for the central exclusion list, for informing the recipients and for handling data-subject requests. The partner may not deviate from the template, keeps their mailbox secure, forwards to us any unsubscribe or request they receive within one working day, and uses the data for nothing else. You may address your request to either of us; the single contact point is [email protected]. Where the partner writes to win clients for their own business, the partner is the controller and Trendizz the processor (see above, The partner's own subscription).
Legal basis. Processing the application is a step taken to prepare a contract, and the partner work, the partner view and the commission are the performance of the partner agreement (Article 6(1)(b)); for the settlement data, a legal obligation (Article 6(1)(c)); for the quality-assurance inspection and the abuse filtering of applications, legitimate interest (Article 6(1)(f)).
Retention. If no partner relationship comes about, 12 months; if it does, 12 months after the relationship ends or, if later, after the last commission payout; the settlement data, 8 years under the Accounting Act. We keep the Apex conversations held in the partner demo account for 12 months after the partner agreement ends. If we did not approve an invitation initiated by a partner, or it did not lead to a demo, we delete the data of the invitation (the invitee's name and email address, and the company's data) 12 months after the invitation; beyond that we keep only the data of an invitation that led to a contract. We keep the other data of the partner assignment and the declaration of affiliated undertakings together with the partner data, under the rule above. The retention rules of sections 4.3 and 4.4 apply to the data of the partner's own account.
6. Who we share data with
We do not sell the data and do not pass it to any third party for their own purposes. The following providers work on our behalf, according to our instructions, or in order to fulfil a legal obligation that applies to us, and we have a data processing contract with each of them.
Anthropic Ireland, Limited (Ireland; the processing takes place partly in the United States). Language model: Apex conversations and memory, writing and proofreading campaign emails, selecting recipient addresses, analysing incoming replies (classification, contact extraction, address reputation), language detection, the reply suggestion, the checking of searches, the translation of company summaries, the automated quality-assurance and abuse-prevention checks of accounts (4.8) and, where it runs there, extracting company data from public websites (4.5). What it receives: the messages the user writes to Apex; Apex's memory (rolling summaries and remembered facts); email drafts, the client's company profile and uploaded company material; the content of the processed emails, including the text of incoming replies and the sender's signature; the data of the target company's contact persons from the database (email address, name, job title); the search criteria, the company summaries from the database and the text of the processed public websites; for the automated checks, the content of the account checked (emails, messages, conversations). Anthropic does not use the data received in this way to train its models, and by default it retains the content of the call for at most 30 days, after which it deletes it.
OpenAI Ireland Ltd. (Ireland; the processing takes place partly in the United States). For the same tasks, as the primary model for some sub-tasks and otherwise as a fallback model. What it receives: the same as Anthropic. OpenAI does not use the data received in this way to train its models, and by default it retains the content of the call for abuse monitoring for at most 30 days, after which it deletes it.
Amazon Web Services EMEA SARL (Luxembourg, data centre: Frankfurt). Sending system messages (invitation, login code, notification, confirmation of demo requests and partner applications), and forwarding messages sent through the contact form to the Trendizz mailbox belonging to the topic (4.7). What it receives: the recipient's email address and the message; for the form, the sender's name, email address, company name and message.
Cloudflare, Inc. (United States). Serving trendizz.com and the static files of the interface, storing the encrypted backups, and storing previously uploaded profile pictures. What it receives: the technical data of visitor traffic; the backup is encrypted, in a European data centre, and Cloudflare cannot read it.
KBOSS.hu Kft. (Számlázz.hu, Hungary). Issuing invoices and submitting the invoices to the tax authority. What it receives: the billing data (company name, address, tax number, the email address of the invoice recipient).
Stripe Payments Europe, Ltd. (Ireland). Collecting the subscription fee by card. What it receives: company name, billing address, tax number, and the payer's name, email address and phone number; only Stripe sees the card data.
Google LLC and Microsoft Ireland Operations Ltd. Only if the client chooses the Google or Microsoft login to connect their mailbox. The client authorises the connection in their own account; these are the client's own email providers, and their data stays with the client's provider.
OpenStreetMap Foundation (Nominatim, United Kingdom). Geocoding of localities for the database. What it receives: only the name of the locality and the country.
A proxy provider with a registered office in the European Union. The network route for downloading public websites. What it receives: the traffic of the downloaded public pages; we name the provider as a category, because its identity is a trade secret and the GDPR permits indicating the category of recipients.
Pushover LLC (United States). Delivering internal operational alerts to our staff's devices. What it receives: the company name and the type of event; we do not put person names into the alerts.
Browser notification service (Google, Apple or Mozilla, depending on the browser). Delivering the notification to the device. What it receives: the encrypted notification text.
Trendizz's Account partners and Market entry partners. Where a partner manages a client's account, the partner processes the client's data as the Provider's sub-processor. From their manager account or their own account, respectively, they cross over into the company of the managed client and manage the campaigns within the system; the client's company belongs to the client, not a sub-account of the partner. What it receives: the whole client account within the system, without export, and without the mailbox password or access credentials. We log their modifications, downloads and denied requests; they may not move the data into another account or use it for their own purposes. We name the person managing the account before access is granted, and the client may object. The partner works in the European Economic Area, the United Kingdom or Switzerland. Safeguard: confidentiality and data processing obligations in the partner agreement and in the Managed Annex (M.6) of the contract concluded with the client.
Beyond this, our clients are recipients of the data: we show them the company data referred to in section 4.5 within the system. Partners may receive data as set out in Chapter 5, and authorities may receive data on the basis of legislation applicable to us.
Transfers outside the European Union. With the language model providers, it is their European subsidiary that contracts with us, and the processing takes place partly in the United States. The transfer is made on the basis of the European Commission's Standard Contractual Clauses (SCCs), which are contained in the providers' data processing agreement. At Cloudflare, we process the technical data of visitor traffic on the basis of the European Commission's Standard Contractual Clauses (SCCs); the backup is in a European data centre, encrypted, and the key is held solely by us. The browser notification is delivered by the provider chosen by the browser (Google, Apple or Mozilla), which may involve a transfer to the United States; the content of the notification is encrypted and the provider does not read it. For a partner working in the United Kingdom or Switzerland, the transfer is based on the European Commission's adequacy decision. Internal alerts to Pushover LLC go to the United States, on the basis of the adequacy decision under the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses (SCCs). You can request a copy of the safeguards at [email protected].
7. Where we store the data, and how we protect it
- The database and the uploaded files are on our own, self-operated servers at our own premises, in Hungary. The static files of the interface are served by Cloudflare's network; the client data stays on our own servers.
- All connections are encrypted (TLS). We store mailbox credentials in encrypted form. We store the login code in an irreversible form.
- Access is role-based: every user sees only the data of their own company and group. For quality assurance, error correction, support or abuse prevention, a designated Trendizz staff member may log into the client's account for a specific reason, and may then also view the emails and messages stored in the system to the extent the reason requires (4.8). We log the login, its reason, and the modifications, downloads and denied requests made in this way (who, when, why, at which company, and which operation); the client receives the log on request.
- The backup is made daily, we store it in encrypted form, and we keep it for at most 6 months. After deletion or the expiry of the retention period, we delete the data from the primary systems without delay and from the backups through rotation, within 6 months at the latest; until then it is accessible from the backup only for the purpose of restoration.
- In the event of a personal data breach, as required by law we notify the supervisory authority within 72 hours, and, if the breach entails a high risk to you, we notify you as well.
8. Automated processing and artificial intelligence
The system uses artificial intelligence to classify incoming emails, write reply suggestions, search for companies and run Apex conversations. The classification helps to sort emails and to reply, and has no legal effect on you. A human decides on the individual reply suggested by Apex and on any change to a contact person's data. The system sends campaign emails and pre-set template replies on the basis of our client's approved templates and process (section 4.4). The recognition of a reply requesting a stop and the exclusion of the address are done in your interest. The automated checks of accounts (4.8) serve quality assurance and the prevention of abuse; they have no legal effect in themselves, and a member of our staff decides on any action. We do not make solely automated decisions that produce legal effects concerning you or similarly significantly affect you. On request, we provide further information about the method of classification.
9. Your rights
Under the GDPR, you may request:
- information and access: what data of yours we process, and a copy of it;
- rectification: if the data is inaccurate; we align the database data with your website;
- erasure: if the data is no longer needed, or you object, or you withdraw your consent;
- restriction: while we clarify a dispute, we only store the data;
- data portability: the data you have provided that is processed on the basis of a contract or consent, in a machine-readable form;
- withdrawal of consent: you can stop processing based on consent (for example the newsletter) at any time; the withdrawal does not affect the lawfulness of processing carried out beforehand;
- objection: against processing based on legitimate interest. We fulfil an objection to outreach for direct marketing purposes in every case, unconditionally, and we delete your data. For other processing based on legitimate interest, we may retain data only in exceptional cases recognised by law (for example, to enforce a legal claim), of which we will inform you.
Send the request to [email protected], or by post to our registered office. We may verify your identity before replying. We reply within one month at the latest; in justified cases this may be extended by two months, of which we will notify you. Fulfilling the request is free of charge.
If you feel that we have infringed your rights, you can lodge a complaint with the supervisory authority. In Hungary:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
| Address | 1055 Budapest, Falk Miksa utca 9–11. |
| Postal address | 1363 Budapest, Pf. 9. |
| Phone | +36 1 391 1400 |
| [email protected] | |
| Web | naih.hu |
You may also lodge your complaint with the supervisory authority of another EU Member State of your habitual residence, your place of work, or the place of the alleged infringement. You may also go to court; you can bring the action before the regional court of your place of residence as well.
10. Children
The service is intended for businesses. We do not knowingly process the data of a person under sixteen; if we become aware of such data, we delete it.
11. Changes to this notice
We update this notice from time to time, if the service or the law changes. The current version is always available on this page, with the date of entry into force in the header. We also notify users who have an account about material changes within the system.