Privacy Policy
Last updated June 2026
A transparent summary of the personal-data processing connected to the Aion service (aionagent.app) — based on Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). Effective: 12 June 2026.
1. The data controller
This notice applies to the processing carried out for the service operating under the Aion brand (aionagent.app). The controller:
| Name | Kapás Bence, sole proprietor (egyéni vállalkozó) |
| Brand | Aion |
| Registered seat | 4200 Hajdúszoboszló, Szívós utca 24, Hungary |
| Mailing address | 8600 Siófok, Kennedy Ferenc utca 13 A/1, Hungary |
| hello@aionagent.app | |
| Phone | +36 30 390 6392 (not a recorded line) |
| Website | https://www.aionagent.app |
| Tax number | 57226255-1-34 |
| Registration number | 55831640 |
| Statistical code | 57226255-6201-231-09 |
| Hosting provider | Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) |
| DPO | No data protection officer is appointed — there is no legal obligation to do so. |
2. General information
The controller processes personal data only in the categories of data subjects listed in this notice, and strictly for the stated purposes. Aion is an autonomous software-engineering product; this website presents the product and operates its waitlist, contact form, user accounts, and licensing.
The controller does not carry out automated decision-making or profiling within the meaning of Article 22 GDPR. Providing data is voluntary; however, without contact and billing details we cannot perform a contract concluded with you.
3. Legal bases of processing
- Performance of a contract — GDPR Art. 6(1)(b). Processing account, licensing, and customer-contact data needed to provide the service you signed up for.
- Legitimate interest — GDPR Art. 6(1)(f). Operating, securing, and improving the Site (server logs, abuse prevention), and answering messages you send us.
- Legal obligation — GDPR Art. 6(1)(c). Retention required by accounting and tax law (Hungarian Accounting Act, VAT Act).
- Consent — GDPR Art. 6(1)(a). Joining the waitlist, voluntarily submitting the contact form, and any non-functional (analytics, marketing) cookies.
4. What we process, why, and for how long
Waitlist signups
- Purpose. The email address you submit to request early access, together with basic technical request data (IP address, country, browser user-agent) recorded for abuse prevention — so we can contact you about availability.
- Legal basis. Consent — GDPR Art. 6(1)(a), which you may withdraw at any time.
- Retention. Until the waitlist is fulfilled or you ask us to delete your data, whichever comes first.
Contact-form messages
- Purpose. The name, company, email address, and message you voluntarily provide on the /contact page — to respond, prepare an offer, or arrange an introductory conversation.
- Legal basis. Consent (GDPR Art. 6(1)(a)) given by deliberately reaching out, and legitimate interest (GDPR Art. 6(1)(f)) in answering professionally.
- Retention. At most 24 months from the inquiry, or until you withdraw consent. If a contract is concluded, the data moves to the customer-contact category.
Accounts and authentication
- Purpose. The email address and authentication credentials of your Aion account (managed by our authentication provider, Supabase) — to let you sign in and manage your plan and license keys.
- Legal basis. Performance of a contract — GDPR Art. 6(1)(b).
- Retention. Until you delete your account, subject to statutory retention duties for billing records.
Billing, payments and licensing
- Purpose. Billing details of the subscribing customer, subscription and payment status (processed by Stripe — we never see or store full card numbers), and the license keys we issue — to provide paid plans, issue invoices, and meet accounting obligations.
- Legal basis. Performance of a contract (GDPR Art. 6(1)(b)) and legal obligation (GDPR Art. 6(1)(c) — Accounting Act, VAT Act).
- Retention. 8 years under Act C of 2000 on Accounting.
Server logs and security
- Purpose. Like most websites, our hosting provider processes basic request data (IP address, browser type, timestamps) to deliver and secure the Site.
- Legal basis. Legitimate interest — GDPR Art. 6(1)(f).
- Retention. Short, rolling retention defined by the hosting provider.
Cookies
- Purpose. Functional cookies necessary for the Site to operate, and — only with your explicit consent given on the cookie banner — any analytics cookies. Details in the Cookie Policy.
- Legal basis. Functional cookies: legitimate interest (GDPR Art. 6(1)(f)). Analytics cookies: consent (GDPR Art. 6(1)(a)); without consent none are set.
- Retention. Functional: session or at most 12 months. Analytics: per the provider's settings, only after opt-in. Consent can be withdrawn at any time.
5. Cookies
The Site uses functional cookies required for its operation. Analytics cookies are loaded only with your explicit consent, given on the cookie banner shown when you first open the Site — choosing “Necessary only” keeps them off. We do not use advertising or remarketing cookies. The full inventory, durations, and withdrawal options are in the Cookie Policy.
6. Who can access your data
Personal data is accessed by the controller (Kapás Bence e.v.) and his contracted staff and agents — only to the extent necessary for their tasks, under written confidentiality obligations. Access is role-based, and administrative actions are logged.
7. Data transfers and processors
To operate the service, the controller uses processors in the following main categories. A written data-processing agreement (DPA) is in place with every processor; customers may request their own DPA.
- Hosting and infrastructure. Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) — serves the website, the waitlist store, and the contact form. Transfers outside the EU rely on the EU–US Data Privacy Framework and SCCs.
- Database and authentication. Supabase — stores account, content, and authentication data, with DPF/SCC safeguards for any non-EU transfer.
- Payments. Stripe — processes subscription payments as an independent controller for card data; we receive only payment status and billing metadata. DPF/SCC safeguards apply.
- Business email. Google Workspace (Google Ireland Ltd.) — our correspondence with you. EU/EEA region with DPF-based transfer where applicable.
- Accounting. An external accountant for bookkeeping and tax compliance — billing and financial data only.
- Website analytics. None currently enabled. If introduced, it will run only with your consent, under DPF/SCC safeguards.
Transfers to third countries
Where any of the above providers transfers data outside the EU/EEA, it happens exclusively with the appropriate safeguards of Chapter V GDPR — EU–US Data Privacy Framework certification or the European Commission’s Standard Contractual Clauses (SCCs).
8. Your rights
- Right to information. Clear, accessible information about the essential elements of the processing (who processes what, why, how, and for how long).
- Right of access. Confirmation whether we process data about you, and if so, which data.
- Right to rectification. Correction or completion of inaccurate data.
- Right to erasure. Deletion of your data — within the limits of statutory retention duties (e.g. accounting records).
- Right to restriction. In certain cases — e.g. contested accuracy — you may request that processing be restricted.
- Right to data portability. Receiving the data you provided in a structured, machine-readable format (e.g. CSV, JSON) and transmitting it to another controller.
- Right to object. You may object at any time to processing based on legitimate interest.
- Right to withdraw consent. Consent-based processing (waitlist, contact form, analytics cookies) can be withdrawn at any time; withdrawal does not affect the lawfulness of prior processing.
You can exercise these rights verbally, in writing, by post, or by emailing hello@aionagent.app. We respond substantively within 30 days of receiving the request.
9. Complaints and supervisory authority
If you have a complaint about our processing, we recommend contacting the controller first — we have 30 calendar days to investigate and respond. If you maintain your complaint after our response, you may turn to the courts or to the Hungarian supervisory authority:
| Authority | Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) |
| Postal address | 1530 Budapest, Pf.: 5., Hungary |
| Address | 1125 Budapest, Szilágyi Erzsébet fasor 22/C |
| Phone | +36 (1) 391-1400 |
| ugyfelszolgalat@naih.hu | |
| Website | https://naih.hu |
10. Changes to this notice
The controller reserves the right to amend this notice unilaterally. The current version is always available at aionagent.app/privacy. In case of material changes, affected customers are also notified by email. Effective from publication.