Privacy Policy
Last updated: January 8, 2026
Preamble
This Privacy Policy describes how solid.garden (operated by DÉNES SZILÁRD e.v.) collects, uses, and protects your personal information. We are committed to transparency and data protection, complying with both the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
1. Data Controller & Contact Information
1.1. Data Controller (EU GDPR): DÉNES SZILÁRD e.v. (egyéni vállalkozó), Magyarország 8171 BALATONVILÁGOS, PONTY UTCA 4, Hungarian tax number: 59835165-1-34, Email: szilard@solid.garden. As a data controller under GDPR, we are responsible for determining the purposes and means of processing personal data.
1.2. Business Contact (CCPA/CPRA): For California residents, you may contact us regarding privacy matters at solid.garden, Email: szilard@solid.garden.
1.3. Data Protection Representative: For GDPR-related inquiries, including data subject access requests, please contact us at szilard@solid.garden. We will respond to your request within 30 days as required by law.
2. Information We Collect
2.1. Personal Information: Name and contact details (email, phone); company information and job title; account credentials; billing and payment information; communication history.
2.2. Technical & Service Data: Subsurface geological data (seismic, well logs); project files and deliverables; IP address and device information; usage logs and access patterns; authentication tokens.
2.3. Special Category Data (GDPR Article 9): We do not collect special categories of personal data (health, biometric, political opinions, etc.) unless explicitly required for a project and with your separate, explicit consent. All subsurface data is treated as confidential business information, not personal data, unless it contains personal identifiers.
2.4. Sensitive Personal Information (CCPA): We do not sell or share sensitive personal information as defined by the CPRA, including government identifiers, account login credentials, precise geolocation, or communications data, except as necessary to provide our services.
3. How We Use Your Information
3.1. Service Delivery: Perform geological data analysis; generate seismic interpretations; build RGT models and facies maps; deliver project reports and visualizations; provide technical consulting.
3.2. Account Management: Create and manage user accounts; process billing and payments; authenticate user access; provide customer support; send service notifications.
3.3. Legal & Security: Comply with legal obligations; maintain audit logs; prevent fraud and abuse; enforce our Terms of Service; protect data security.
3.4. Platform Improvement: Analyze usage patterns; improve service quality; optimize performance; develop new features; conduct business analytics.
4. Legal Basis for Processing (GDPR)
4.1. Contract Performance (Article 6(1)(b)): Processing necessary to fulfill our service contract with you, including: delivering subscribed services; processing payment transactions; managing user accounts; providing customer support.
4.2. Legal Obligation (Article 6(1)(c)): Processing necessary to comply with legal requirements, including: tax accounting and record-keeping; audit trail maintenance; anti-fraud measures; regulatory reporting.
4.3. Legitimate Interest (Article 6(1)(f)): Processing for our legitimate business interests, including: platform security and fraud prevention; service quality improvement; business analytics and insights; direct marketing (with opt-out).
4.4. Consent (Article 6(1)(a)): Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing based on consent before its withdrawal. This includes: marketing communications beyond essential service updates; optional feature usage analytics; third-party integrations (e.g., Stripe payment processing).
5. Information Sharing & Third Parties
5.1. Railway Corporation (Infrastructure): Purpose is cloud hosting and infrastructure. Data includes application data and logs. Safeguards include GDPR-compliant DPA and SOC 2 Type II. Location is United States with EU-U.S. Data Privacy Framework participation. Railway Data Processing Addendum: https://railway.com/legal/dpa.
5.2. Stripe, Inc. (Payments): Purpose is payment processing. Data includes payment details (card data never stored on our servers). Safeguards include PCI DSS Level 1 and GDPR-compliant DPA. Location is United States with EU-U.S. Data Privacy Framework. Stripe Data Processing Agreement: https://stripe.com/legal/dpa.
5.3. No Data Selling: We do not sell, rent, or trade your personal information. We have not sold, and do not sell, personal information in the preceding 12 months (CCPA requirement).
5.4. Affiliates & Subcontractors: We may engage subcontractors to assist with service delivery. All subcontractors are bound by confidentiality obligations and GDPR-compliant data processing agreements.
5.5. Legal Requirements: We may disclose information if required by law, court order, or to protect our rights, property, or safety.
5.6. Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity with your consent.
5.7. CCPA/CPRA Notice: We do not sell or share personal information for monetary or other valuable consideration. However, we may share data with our service providers as described above. If you wish to limit this sharing, please contact us at szilard@solid.garden.
6. Data Storage & Security
6.1. Data Encryption: At rest: AES-256 encryption (PostgreSQL transparent data encryption); In transit: TLS 1.3 for all data transfers; Passwords: Argon2 hashing algorithm (memory-hard); Sessions: JWT tokens with short expiration.
6.2. Infrastructure Security: Multi-tenant architecture with company_id isolation; role-based access control (RBAC); comprehensive audit logging; regular security updates; penetration testing.
6.3. Data Center Locations: Railway Infrastructure operates data centers in the United States. Personal data from EU customers may be transferred to and processed in the United States under the EU-U.S. Data Privacy Framework, which the European Commission has determined provides adequate protection. For customers requiring data residency within the European Union, please contact us to discuss alternative arrangements.
6.4. Security Measures Summary: We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including pseudonymization and encryption of personal data (GDPR Article 32).
7. Your Privacy Rights
7.1. GDPR Rights (EU/UK/EEA): Right of Access (Article 15) – request confirmation and copy of your personal data; Right to Rectification (Article 16) – correct inaccurate or incomplete data; Right to Erasure (Article 17) – request deletion of your data ("right to be forgotten"); Right to Restriction (Article 18) – limit how we use your data; Right to Data Portability (Article 20) – receive your data in a structured format; Right to Object (Article 21) – object to processing based on legitimate interest; Right to Withdraw Consent – remove consent at any time; Right to Lodge a Complaint – contact supervisory authority (Hungarian NAIH).
7.2. CCPA/CPRA Rights (California): Right to Know – what categories of personal information we collect, use, and share; Right to Delete – request deletion of your personal information; Right to Correct – correct inaccurate personal information; Right to Opt-Out – opt-out of the sale or sharing of personal information; Right to Limit Use – limit use of sensitive personal information; Right to Non-Discrimination – not be discriminated against for exercising rights; Right to Data Portability – receive data in a readily usable format.
7.3. How to Make a Request: Contact us at szilard@solid.garden with: your name and email address; specific rights you wish to exercise; identification of the relevant data (if applicable); proof of identity (for access requests). We will respond within 30 days (GDPR) or 45 days (CCPA), extendable by an additional 45 days if necessary, with notice.
7.4. Authorized Agents: You may designate an authorized agent to make a request on your behalf. We may require the agent to provide proof of your written authorization to act on your behalf.
7.5. Verification Process: We will verify your identity before fulfilling access, deletion, or portability requests to prevent unauthorized disclosure of personal information.
8. Cookies & Tracking Technologies
8.1. Essential Cookies: Required for authentication, security, and core functionality. These cannot be disabled. Includes session tokens, CSRF tokens, user preferences, and session management.
8.2. Functional Cookies: Remember your preferences and settings to improve your experience, including UI preferences, form data, recent items, and dashboard settings.
8.3. Analytics Cookies: Help us understand how you use our services to improve performance, including page views, user flows, performance metrics, and geographic data. Optional and can be disabled.
8.4. Your Cookie Choices: You can manage cookie preferences through your browser settings. Note that disabling essential cookies may affect service functionality. We also honor Global Privacy Control (GPC) signals as an opt-out preference.
8.5. Third-Party Cookies: Stripe sets cookies during payment processing. Railway sets infrastructure and deployment cookies. We do not allow advertising networks to place cookies on our site. We do not sell your browsing data.
9. International Data Transfers
9.1. EU-U.S. Data Privacy Framework: Our service provider Railway Corporation participates in the EU-U.S. Data Privacy Framework (DPF) as certified by the U.S. Department of Commerce. Personal data from the EU may be transferred to the United States under the DPF, which provides appropriate safeguards for EU personal data. For more information about Railway's DPF certification, see https://railway.com/legal/privacy.
9.2. Standard Contractual Clauses (SCCs): Where we transfer data outside the EEA in reliance on SCCs (Article 46 GDPR), we have implemented the European Commission's Standard Contractual Clauses with our service providers to ensure adequate protection.
9.3. UK International Data Transfer Agreement (IDTA): For transfers from the United Kingdom, we use the UK IDTA or addendum to the SCCs, as appropriate.
10. Data Retention Periods
10.1. Active Projects: Data retained while project is active and for 8 years thereafter (Hungarian tax law requires 8-year business record retention).
10.2. Completed Projects: Subsurface data deleted after 30 days. Personal data retained for legal/tax purposes for 8 years from completion.
10.3. Prospective Leads: Contact information retained for 2 years from last interaction, unless you request earlier deletion.
10.4. Deletion & Anonymization: Upon request or at the end of retention periods, we securely delete or anonymize personal data. Backup copies are deleted according to our backup rotation schedule (7-day retention for automated backups).
11. Children's Privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16 without parental consent, we will take steps to delete that information. Parents or guardians who believe their child has provided personal information without consent should contact us at szilard@solid.garden.
12. Changes to This Policy
12.1. We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations.
12.2. Material changes will be communicated by: posting the updated policy on our website; updating the "Last updated" date at the top; sending email notification to registered users (for significant changes).
12.3. Version History: January 8, 2026 – Comprehensive privacy policy converted to traditional legal format (GDPR + CCPA/CPRA compliant).
13. Contact Supervisory Authorities
If you believe our processing of your personal information infringes GDPR or other data protection laws, you have the right to lodge a complaint with a supervisory authority.
Hungary (NAIH): Nemzeti Adatvédelmi és Információszabadság Hatóság, 1125 Budapest, Szilágyi Dezső square 3., Phone: +36 1 391-1400, Email: ugyfelszolgalat@naih.hu, Website: www.naih.hu.
California (CPPA): California Privacy Protection Agency, 2000 02nd Street, Suite 300, Sacramento, CA 95814, Email: info@cppa.ca.gov, Website: www.cppa.ca.gov.
14. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact:
DÉNES SZILÁRD e.v.
Magyarország 8171 BALATONVILÁGOS, PONTY UTCA 4
Hungarian tax number: 59835165-1-34
Email: szilard@solid.garden