Privacy Policy (C)

Introduction

The application is developed and operated by BMSoft1024, and its purpose is to provide services to registered users with authentication and cloud backup.

This privacy policy describes what data the application processes, for what purpose and on what legal basis.

Data Controller

What data does the application process?

1. Registration and authentication (Firebase Authentication)

  • Email address (as user identifier)
  • Hashed password and authentication tokens (handled by Firebase Authentication)
  • Login events (successful/failed login, timestamp)

2. Application usage events

  • Feature usage events: which parts of the application were used, what operations were initiated
  • These events serve for debugging, performance improvement and secure operation of the service

3. User data and documents (Google Drive)

Currently:

  • User data and documents are saved to the user's own Google Drive storage, the application accesses them through the Google Drive API
  • The content of documents is physically stored in the user's Google account, not on BMSoft1024's own server

In future versions (if implemented):

  • The system may store document metadata (file name, type, timestamp) in the application database for better search and management
  • We will update the specific data processing description if the feature expands

4. Data sharing between users

  • The application may allow a user to share certain data or messages with another user
  • This is always tied to your active action (e.g., "share" button), and only the designated recipients have access to the received data

Purpose and legal basis of data processing

Data processingPurposeLegal basis
Registration, loginAccount creation, useContract performance
Usage eventsDebugging, serviceLegitimate interest / contract
Google Drive backupSecurity backup, syncConsent + contract
Data sharingFeature provisionConsent (specific action)

Data processors and data transfers

Firebase (Google LLC)

  • Service: authentication, events and possibly other backend functions
  • Role: data processor, according to Google Cloud "Data Processing and Security Terms" contractual terms
  • Possible data center location: including USA, with lawful data transfer through SCCs and Data Privacy Framework

Google Drive (Google LLC)

  • Service: storage of user documents and files in the user's Google account
  • BMSoft1024 receives permission to manage specified folders/files on behalf of the user, but physical storage occurs on Google infrastructure

Data retention

  • Account data (email, authentication record): for the duration of the account, within reasonable time (e.g., 30 days) upon deletion request
  • Usage events: for a limited time, typically a few months (e.g., 90 days), for the duration necessary for debugging
  • Google Drive backups and documents: until you delete them in your own Google account or turn off sync

User rights

Your rights include, among others:

  • request access to your data stored by us
  • request correction or deletion
  • request restriction of data processing
  • object to certain data processing
  • file a complaint with the competent authority
  • data portability (GDPR)

EU users (GDPR): The competent supervisory authority is the data protection authority in your country. In Hungary: NAIH (https://www.naih.hu). For more information, visit: European Data Protection Board

US users (CCPA - California): California users have rights including: access, deletion, opt-out of sale, non-discrimination. For more information, visit: California Attorney General - CCPA

Chinese users (PIPL): Rights under China's Personal Information Protection Law (PIPL). For more information, visit: Cyberspace Administration of China

Other countries: You may exercise your rights in accordance with applicable data protection laws in your country. For more information, please contact us: privacy@bmsoft1024.com

You can send your requests to privacy@bmsoft1024.com, and we will respond within 30 days if possible.

Security

  • Communication takes place over HTTPS (encrypted connection)
  • We limit access through authorization management, only authenticated access is allowed to user accounts

Modifications

We may update this policy from time to time, especially when new features (e.g., additional cloud services) are added to the application.

The current version is always available on the official website and/or the legal page accessible from the application.