Privacy Policy

Effective: 3 August 2026 · Version: 2026-08-03

1. Purpose of this document

This privacy policy covers the processing of personal data carried out in the operation of the ControlliQ platform (the "Platform" or "ControlliQ") by Composite Solutions Hungary Korlátolt Felelősségű Társaság (company registration number: 13-09-242859; tax number: 29168950-2-13; registered seat: 2100 Gödöllő, Hős utca 11, Hungary). It applies to the controlliq.com website, to the web application available after signing in, and to the ControlliQ iOS and Android mobile applications. The purpose of this document is to inform you, in a concise, transparent and plain-language form as required by Articles 13 and 14 GDPR, about what personal data we process, for what purpose and on what legal basis, for how long, who we share it with, and what rights you have.

2. The controller and its contact details

Controller: Composite Solutions Hungary Korlátolt Felelősségű Társaság Company registration number: 13-09-242859 Tax number: 29168950-2-13 EU VAT number: HU29168950 Registered seat: 2100 Gödöllő, Hős utca 11, Hungary Represented by: Bence Támba, managing director E-mail: team@controlliq.com Data protection officer We do not carry out activities that would make the designation of a data protection officer mandatory under Article 37(1) GDPR: we are not a public authority, our core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and we do not process special categories of data or criminal conviction data on a large scale within the meaning of Articles 9 and 10 GDPR. We have therefore not appointed a data protection officer. You can reach us with any data protection question, request or complaint at team@controlliq.com; these enquiries are handled by a designated member of our team.

3. When are we a controller and when are we a processor?

ControlliQ is a financial controlling service for businesses. We therefore process personal data in two clearly distinct roles, and the rights available to you differ depending on which one applies. 1) We act as a controller for data relating to the service itself and to our relationship with you. This includes your user account, sign-in, billing and subscription, support contact, the newsletter, security logging, and your visits to the website. For these we determine the purposes and means of processing, and this policy applies to them in full. 2) We act as a processor for data that a customer business uploads or synchronises to the Platform: the content of invoices, bank statements, financial entries and the partner register. These typically also contain data about third parties — for example sole traders, contact persons and individual customers. For this data the controller is the customer business itself, which decides what to upload and how long to keep it; ControlliQ acts on that customer's instructions under the service agreement. If you appear on the invoice of a ControlliQ customer and wish to have your data erased or to access it, you should address your request to the business you have a commercial relationship with. If such a request reaches us, we do not decide on it ourselves: we forward it to the customer concerned without undue delay and assist them in fulfilling it. This division of roles does not affect our responsibility for the security of the uploaded data: the technical and organisational measures described in section 15 apply to it as well.

4. Definitions used in this policy

We use the following terms with the meaning given to them in Article 4 GDPR. Personal data: any information relating to an identified or identifiable natural person; a natural person is identifiable who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data or an online identifier. Personal data includes, among other things, name, address, telephone number, e-mail address and IP address. Processing: any operation or set of operations performed on personal data, in particular collection, recording, organisation, storage, alteration, retrieval, use, disclosure by transmission, combination, restriction, erasure and destruction. Controller: the person or organisation that determines the purposes and means of the processing of personal data. Processor: the person or organisation that processes personal data on behalf of and on the instructions of the controller. Recipient: the person or organisation to which personal data is disclosed. Data subject: the natural person to whom the personal data relates. Consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing by a clear affirmative action. Profiling: any form of automated processing of personal data used to evaluate or predict personal aspects relating to a natural person, such as their economic situation, reliability or behaviour. Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed.

5. Data processing principles

Our processing complies with the principles set out in Article 5 GDPR: Lawfulness, fairness and transparency: we process personal data lawfully, fairly and in a transparent manner in relation to you. Purpose limitation: we collect data only for specified, explicit and legitimate purposes and do not process it in a manner incompatible with those purposes. Data minimisation: we process only data that is adequate, relevant and limited to what is necessary for the given purpose. Accuracy: we take reasonable steps to ensure that the data we process is accurate and, where necessary, kept up to date. Storage limitation: we keep data only for as long as necessary for the purpose. The specific retention periods for each processing activity are set out in section 6 and summarised in section 8. Integrity and confidentiality: we ensure the security of the data through appropriate technical and organisational measures. Accountability: we are responsible for compliance with the above principles and must be able to demonstrate it. This is why, for example, we record when you accepted this policy and which version of it you accepted.

6. Information by processing purpose

Below we set out, for each purpose, what data we process, on what legal basis and for how long. The retention periods stated here are enforced by automated, scheduled deletion processes in our system. ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 6.1 Registration and user account Data processed: name, e-mail address, a cryptographic hash of your password, the time your e-mail address was verified, the role and company assignment of the account, and the time at which you accepted the Terms of Service and this policy together with the version accepted. Purpose: creating your user account, identifying you, providing access to the service, and communicating with you. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Recording the time and version of your acceptance is based on the accountability principle and our legal obligation (Articles 5(2) and 7(1) GDPR). Nature of the provision: providing your name, e-mail address and password is necessary to enter into the contract. Without them we cannot create an account or provide the service. Retention: until the account is closed. After closure the account is kept in a restorable state for 30 days — this is in your interest in case of a change of mind or accidental deletion — and is then permanently erased. 6.2 Signing in with a Google or Microsoft account Data processed: the name and e-mail address received from the provider, and your account identifier at that provider. Purpose: simplified registration and sign-in. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Retention: until the account is closed, as set out in section 6.1. Note: for the sign-in itself, Google and Microsoft act as independent controllers within their own systems; they do not share your password with us. 6.3 Processing of invoices, documents and financial data Data processed: the full content of uploaded or synchronised invoices and bank statements, including the name, address, tax number and bank account number of the parties on the invoice, the line items, amounts and dates, and the document file itself. Data subjects: the business partners, contact persons, sole traders and private individuals contracting with the customer business. Purpose: providing the financial controlling service: data extraction, categorisation, reporting and bank statement reconciliation. Legal basis: for this data the customer business is the controller; ControlliQ acts as a processor on that customer's instructions (see section 3). Retention: as instructed by the customer business, at the latest until the company's ControlliQ account is permanently erased. When a company account is erased, the uploaded documents are also deleted from file storage. 6.4 Receiving invoices by e-mail Data processed: the sender's e-mail address, the subject and body of the message, and any attachments. Purpose: automatically receiving and processing invoices at the unique e-mail address assigned to your company. Legal basis: performance of a contract (Article 6(1)(b) GDPR); as regards the content of attachments, the processor role described in section 6.3. Retention: as set out in section 6.3. 6.5 Customer support and contact Data processed: name, e-mail address, the content of your message and any attachments. Purpose: answering your enquiry and investigating faults. Legal basis: performance of a contract where the enquiry relates to your use of the service (Article 6(1)(b) GDPR); otherwise our legitimate interest in responding to your request (Article 6(1)(f) GDPR). Retention: no more than 2 years from the closure of the case, after which the data is deleted. If a dispute arises from the case, we keep the data necessary for it until the claim becomes time-barred. 6.6 Account restoration requests Data processed: name, e-mail address, the text of the request, and the time and outcome of its handling. Purpose: identifying and deciding on a request to restore a deleted account. Legal basis: steps taken at your request with a view to re-establishing the contract (Article 6(1)(b) GDPR). Retention: 1 year from receipt of the request. 6.7 Register of privacy and deletion requests Data processed: the requester's e-mail address, the company identifier provided, the subject and text of the request, the dates of receipt and completion, the response and the reasons for any refusal. Purpose: handling the request within the statutory deadline and demonstrating that we have met our legal obligations. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR, in conjunction with Articles 12 and 15–22 GDPR) and the accountability principle (Article 5(2) GDPR). Retention: 3 years from the closure of the request. 6.8 Subscription, payment and invoicing Data processed: the company's billing name, address and tax number, the contact e-mail address, subscription plan and transaction details, the payment method type and the last four digits of the card number. Purpose: managing the subscription, collecting the fee and issuing the invoice. Legal basis: performance of a contract (Article 6(1)(b) GDPR); as regards keeping the issued invoice, compliance with a legal obligation (Article 6(1)(c) GDPR). Retention: issued invoices and the related accounting documents are kept for 8 years under Section 169(2) of Act C of 2000 on Accounting. We never receive or store the full card number. 6.9 Newsletter Data processed: name, e-mail address, and the time consent was given. Purpose: sending electronic newsletters and marketing messages about ControlliQ's services, news and offers. Legal basis: your consent (Article 6(1)(a) GDPR), in line with Section 6 of Act XLVIII of 2008 on Commercial Advertising. Nature of the provision: entirely voluntary. Unsubscribing does not affect your use of the service and carries no disadvantage. Withdrawal: you may withdraw your consent at any time and without giving reasons, using the unsubscribe link at the bottom of our e-mails or, once signed in, under "Newsletter" on your Profile page. Withdrawal does not affect the lawfulness of processing carried out beforehand. Retention: until consent is withdrawn. We also apply the withdrawal in our mailing system; when your account is erased, the newsletter subscription ends automatically. 6.10 Service and system messages Data processed: name, e-mail address, notification preferences, and — in the mobile app — the device's push notification identifier. Purpose: sending messages relating to the operation of the service, for example the outcome of document processing, VAT deadline reminders, and security and account notifications. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Note: these are not marketing messages and therefore do not depend on newsletter consent. The individual notification types and their channels can be configured on your Profile page. Retention: until the account is closed; the push identifier is deleted when the device is detached or the account is erased. 6.11 Security logging Data processed: IP address, user identifier, sign-in and sign-out times, technical details of the browser and operating system, and technical details of error events. Purpose: ensuring the secure operation of the Platform, preventing and investigating abuse, and resolving technical faults. Legal basis: our legitimate interest in operating the service securely and reliably (Article 6(1)(f) GDPR). In balancing those interests we took into account that logging also protects users' own data, that the data is limited to the technical minimum, that only a limited number of staff can access the logs, and that we do not use this data to evaluate you or to build profiles. Retention: the application's technical logs are automatically overwritten after 14 days. 6.12 Change history on financial data Data processed: the fact and time of changes to invoices, line items and financial entries, the previous and new values of the changed fields, and the identifier of the user who made the change. Purpose: making changes traceable within the company and clarifying erroneous or disputed modifications. Legal basis: the customer business's legitimate interest in being able to audit its own financial data (Article 6(1)(f) GDPR); in this respect ControlliQ acts as a processor. Retention: until the company account is closed. The change history is the documentary trail of the financial data: the limitation period for assessing tax and the statutory obligation to retain accounting documents may make it necessary to trace changes years back, which is why these entries are not deleted on a time basis. When a company account is permanently erased, its entire change history is erased with it. If a user's account is permanently erased, the entries remain but their link to that person is removed, so they can no longer be attributed to you. 6.13 AI assistant and AI-based document processing Data processed: the content of uploaded documents, the messages you write to the assistant, the assistant's replies, and the financial data queried. Purpose: extracting structured data from documents and answering your questions on the basis of your own financial data. Legal basis: performance of a contract (Article 6(1)(b) GDPR); as regards the content of uploaded documents, the processor role described in section 3. Retention: conversation history is kept for 24 months and then deleted automatically. When your account is permanently erased, the conversations are deleted as well. Information about the providers involved and transfers outside the EEA is set out in sections 10 and 11; automated decision-making is covered in section 9. 6.14 Website visits and measurement Data processed: IP address, browser and device details, the pages visited, the time of the visit, and identifiers stored in cookies. Purpose: operating the website, producing visitor statistics, and measuring the effectiveness of our advertising. Legal basis: for strictly necessary technologies, our legitimate interest in providing the service (Article 6(1)(f) GDPR); in all other cases, your consent (Article 6(1)(a) GDPR), in line with Section 155 of Act C of 2003 on Electronic Communications. Details: section 12.

7. Where the data comes from if we did not receive it from you

Some of the data we hold does not come directly from you. Under Article 14 GDPR we inform you of the following. If you are not a ControlliQ user but a business partner, contact person or customer of one of our customers, data about you may reach the system from the following sources: • invoices and bank statements uploaded or e-mailed in by our customer; • the NAV Online Invoice system, from which our customer synchronises their own incoming and outgoing invoices; • the Billingo and Számlázz.hu invoicing systems, where our customer uses them; • the European Commission's public VIES database, when an EU VAT number is verified. The categories of data processed this way are: name, company name, registered seat or address, tax number, EU VAT number, bank account number, and the details of the transaction shown on the invoice. In these cases the controller is the customer of ours with whom you have a commercial relationship; ControlliQ acts as a processor (see section 3). You should therefore exercise your rights primarily with them. If you do not know which business is involved, write to us and we will help you identify it. Please note that if, as a user, you enter the data of another natural person — for example a colleague, accountant or contact person — into the Platform, it is for you to ensure that you have an appropriate legal basis for doing so and that the person concerned receives the necessary information.

8. Retention periods at a glance

Processing — Retention period User account and related data — until the account is closed, then 30 days for restoration, then permanent erasure Company account and uploaded financial data — until the company account is closed, then 30 days, then permanent erasure including from file storage Subscription invoices and accounting documents — 8 years from issue (Section 169 of Act C of 2000) Data needed to establish or defend legal claims — until the end of the general limitation period, i.e. 5 years (Section 6:22 of the Civil Code) Customer support enquiries — 2 years from closure of the case Account restoration requests — 1 year Generated executive report PDFs — 6 months, after which the file is deleted (the report can be regenerated at any time) Register of privacy and deletion requests — 3 years from closure Change history on financial data — until the company account is closed, then erased together with the company account Application technical logs — 14 days AI assistant conversations — 24 months EU VAT number verifications — 12 months Newsletter — until consent is withdrawn Cookies — until the expiry stated in section 12 Where legislation requires a longer retention period, the statutory period prevails. When a retention period expires, the data is deleted by automated, scheduled processes. Data disappears from backups when the backup cycle expires and in any event within a further 30 days; if a backup is restored, the deletions are applied again.

9. Automated decision-making, profiling and artificial intelligence

ControlliQ does not take decisions about you based solely on automated processing which produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR, and it does not carry out profiling. The Platform uses artificial intelligence for two purposes: 1) Document processing. It automatically extracts data from uploaded invoices and bank statements — for example the invoice number, dates, amounts, partner name and line items. The result is shown on the Platform, where the user can check, correct or discard it. The AI output is therefore a suggestion, not a final decision. 2) AI assistant. It answers users' questions on the basis of their own company's financial data. The assistant informs and summarises, but does not independently carry out any operation that would produce legal effects for a data subject. During AI processing, data is transmitted to the relevant providers (see sections 10 and 11). According to those providers' publicly available documentation, data sent through their APIs is not used by default to train their models. We ourselves do not use your data to train any artificial intelligence model, whether our own or a third party's. The AI features do not perform behavioural analysis, creditworthiness assessment, scoring or automatic rejection.

10. Recipients and processors

Your data may be accessed, to the extent necessary for their duties, by designated members of our team working in support, operations and development roles, who are bound by confidentiality and have limited, role-based access. In addition, we use the providers listed below. Processors act on our instructions, and we have concluded a written data processing agreement under Article 28 GDPR with each of them. INFRASTRUCTURE AND STORAGE • Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg) — cloud file storage for uploaded documents. Storage location: European Union, Frankfurt (eu-central-1) region. • Composite Solutions Hungary Kft.'s self-hosted monitoring system (monitoring.composite.hu) — logging of application errors and performance data. Storage location: European Union. DOCUMENT PROCESSING AND ARTIFICIAL INTELLIGENCE • Mistral AI SAS (15 rue des Halles, 75001 Paris, France) — optical character recognition and structured data extraction. Processing location: European Union. • Anthropic, PBC (548 Market Street, San Francisco, CA 94104, USA) — text processing in the AI assistant and in verification steps. • OpenAI OpCo, LLC (3180 18th St., San Francisco, CA 94110, USA) — document and text processing, and data extraction from bank statements. E-MAIL AND MESSAGING • Mailgun Technologies Inc. (San Antonio, Texas, USA) — receiving and technically processing inbound invoice e-mails. • MailerLite Limited (Vilnius, Lithuania) — sending newsletters and managing the subscriber list. • Google Ireland Limited — Firebase Cloud Messaging: delivering push notifications to the Android app. • Apple Distribution International Ltd. (Ireland) — Apple Push Notification service: delivering push notifications to the iOS app. PAYMENT AND INVOICING • Stripe, Inc. and Stripe Payments Europe, Ltd. — card payment processing and subscription management. • Billingo Technologies Zrt. — issuing the invoice for the ControlliQ subscription fee. WEBSITE, MEASUREMENT AND CONSENT MANAGEMENT Apart from the consent manager, the following are activated only if you give your consent (see section 12). • CookieYes Limited (United Kingdom) — managing cookie consent and recording your choice. • Google Ireland Limited — Google Analytics 4: visitor statistics. • Meta Platforms Ireland Limited — Meta Pixel: measuring the effectiveness of our advertising. • Hotjar Ltd. (Malta) — analysing the use of the public website. It does not run in the application after sign-in. AUTHENTICATION • Google Ireland Limited and Microsoft Ireland Operations Limited — signing in with a Google or Microsoft account, if you choose to. INDEPENDENT CONTROLLERS The following organisations do not act on our instructions but as controllers in their own right, under their own privacy policies: • the Hungarian National Tax and Customs Administration (NAV) — the NAV Online Invoice system; • Billingo Technologies Zrt. and KBOSS.hu Kft. (Számlázz.hu) — in operating their own invoicing systems; • the European Commission — the VIES EU VAT number verification system; • Google, Microsoft and Apple — in operating their own account and device systems. CONNECTED AI CLIENTS ControlliQ allows you, at your own discretion, to connect an external artificial intelligence client — such as the Claude.ai or ChatGPT application — to your account. If you enable this, that provider can query your company's financial data on your behalf. Only you can create this connection and you can revoke it at any time. The connected provider acts under its own privacy policy, over which we have no influence, so we recommend reviewing it before connecting. Beyond the above we do not disclose your data to third parties and we never sell it to anyone for marketing purposes. Disclosure may be mandatory where required by law — for example in response to a request from an authority or a court.

11. Transfers outside the European Economic Area

Some of our providers operate outside the European Economic Area (EEA), so in certain cases data is transferred outside the EEA. Transfers to the United States occur when we use the following providers: Anthropic, OpenAI, Mailgun, Stripe and — subject to your consent — certain services of Google, Meta and Hotjar. These transfers are based on an appropriate safeguard under Chapter V GDPR: the standard contractual clauses adopted by the European Commission (SCCs) or, where the provider holds a valid certification, the adequacy decision under the EU–US Data Privacy Framework. The following do not constitute transfers to a third country: • processing carried out by Mistral AI, which takes place in France; • storage of documents in the Frankfurt (eu-central-1) region of Amazon S3; • our monitoring system, which we operate ourselves within the European Union. You may request further information about the safeguards applied, and a copy of them, at team@controlliq.com. Where necessary, we may redact trade secrets or security information relating to the provider from that copy.

12. Cookies and similar technologies

A cookie is a small data file that a website places on your device and that your browser stores for a defined period. How we ask for your consent We use strictly necessary cookies when the website opens, because the service would not work without them. Every other technology — statistical and marketing solutions — is activated only after you have given your prior consent. These scripts remain blocked until then, so no data reaches the measurement providers before consent is given, and refusing has the same effect. Giving and refusing consent are equally a single click on the cookie banner. You can change or withdraw your choice at any time using the "Cookie settings" link in the website footer. Withdrawal does not affect the lawfulness of processing carried out beforehand. Cookies in use STRICTLY NECESSARY — no consent required, legal basis: legitimate interest (Article 6(1)(f) GDPR) • controlliq-session — maintaining your signed-in session and security checks. Provider: ControlliQ. Expiry: 2 hours, or when the browser is closed. • XSRF-TOKEN — protection against cross-site request forgery. Provider: ControlliQ. Expiry: 2 hours. • cookieyes-consent — remembering your cookie choice so that you are not asked again on every page. Provider: CookieYes. Expiry: 1 year. STATISTICAL — only with consent, legal basis: consent (Article 6(1)(a) GDPR) • _ga, _ga_* — distinguishing visits and visitor devices for visitor statistics. Provider: Google (Google Analytics 4). Expiry: up to 2 years. Third country: USA. • _hjSession*, _hjSessionUser* — analysing use of the website in aggregate form. Provider: Hotjar. Expiry: 30 minutes and 1 year respectively. Runs only on the public website, not in the application after sign-in. MARKETING — only with consent, legal basis: consent (Article 6(1)(a) GDPR) • _fbp — measuring the effectiveness of our advertising and building advertising audiences. Provider: Meta. Expiry: 3 months. Third country: USA. The list shown in the cookie banner reflects the actual state at any given time; if we introduce a new provider, we ask for fresh consent for it. Browser settings You can also manage or delete cookies in your browser settings. Please note that if you block strictly necessary cookies, some features of the Platform will not be available. • Google Chrome: https://support.google.com/chrome/answer/95647 • Mozilla Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer • Microsoft Edge: https://support.microsoft.com/help/17442 • Safari: https://support.apple.com/en-us/HT201265

13. Information specific to the mobile applications

The ControlliQ iOS and Android applications use the same account and the same data as the web interface. Below we describe only what is specific to mobile. Device permissions • Camera — used solely to scan invoices and documents, at the moment you start a scan. We process the image for the purpose of document upload, as described in section 6.3. • Photo library (iOS) — for selecting and uploading documents you already have. • Notifications — for delivering service and system messages (section 6.10). You can withdraw these permissions at any time in your device settings. The application does not request or collect location data, contacts or microphone access, and it does not use advertising-identifier-based tracking. Push notifications To deliver notifications we store your device's unique push identifier. This identifier relates to the device rather than to you personally, but we associate it with your account. Messages are delivered by Google Firebase Cloud Messaging on Android and by the Apple Push Notification service on iOS. Crash reporting and stability If the application crashes, we receive a crash report through Google Firebase Crashlytics containing the device model, the operating system version and the technical circumstances of the fault. The purpose is to fix defects in the application; the legal basis is our legitimate interest in stable and secure operation (Article 6(1)(f) GDPR). The Android application additionally collects basic, aggregated usage statistics through Firebase Analytics for the purpose of improving the application. Document scanning The Android application uses Google's ML Kit document scanner. This scanning and image recognition step takes place locally on the device; the document is not transmitted at that point. Deleting your account from the app You can delete your account directly from the application on the Profile screen, exactly as you can on the web.

14. Children's data

ControlliQ is a business service provided to companies. It is not directed at children, and we do not target people under the age of 16 either with the service or with our marketing communications. We do not knowingly collect personal data from anyone under the age of 16. If we become aware that such data has entered our systems, we delete it without undue delay. If you believe that we are processing the data of a child under 16, please let us know at team@controlliq.com.

15. Data security

We apply technical and organisational measures proportionate to the risk in order to protect personal data. In particular: • encrypted transmission (HTTPS/TLS) between the Platform and your device; • role-based access control: every user and staff member can access only the data needed for their task; • logical separation of each customer business's data, so that one customer cannot access another's; • optional two-factor authentication for user accounts; • passwords stored only as a one-way, irreversible hash; • encrypted storage of credentials for external systems, such as NAV technical keys; • logging of access and of changes made to financial data; • rate limiting against abusive and automated access attempts; • regular backups and regular testing of restoration; • confidentiality obligations for staff with access to personal data. Please note that the security of your account also depends in part on you: please use a strong password that you do not use elsewhere, and enable two-factor authentication.

16. Handling personal data breaches

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the personal data processed. In the event of a breach we proceed as follows: 1. Immediately upon detection we investigate the circumstances of the incident, the categories of data and the number of data subjects affected, and take the measures needed to mitigate the harm. 2. We record the breach in our register under Article 33(5) GDPR, documenting the facts, its effects and the remedial action taken. 3. Where the breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware of it. 4. Where the breach is likely to result in a high risk, we also inform the data subjects without undue delay, describing in plain language the nature of the breach, its likely consequences and the measures we recommend. Where we act as a processor, we report the breach to the customer business concerned without undue delay so that they can meet their own notification obligation as controller.

17. Your rights and how to exercise them

You have the following rights in relation to our processing of your personal data. Right of access — you may ask for confirmation as to whether we process your personal data and, if so, obtain access to it and to information about the processing. Right to rectification — you may ask us to correct inaccurate data and complete incomplete data. You can also change your account details yourself on the Profile page. Right to erasure ("right to be forgotten") — you may ask us to erase your data where it is no longer necessary for the purpose for which it was collected; where you withdraw your consent and there is no other legal basis; where you object to the processing and there is no overriding legitimate ground; or where the processing is unlawful. Erasure does not extend to data we are required by law to keep — for example accounting documents. Right to restriction of processing — in the cases set out in Article 18 GDPR you may ask us to store your data but otherwise not process it. Right to data portability — you may receive the data you provided that we process by automated means on the basis of consent or a contract, in a structured, commonly used, machine-readable format, and ask for it to be transmitted to another controller. Right to object — on grounds relating to your particular situation, you may object at any time to processing based on legitimate interests. Right to withdraw consent — you may stop processing based on consent at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out beforehand. How to exercise your rights You may submit your request to team@controlliq.com, and a request to delete your account may also be submitted on the Profile page after signing in or via the form at controlliq.com/data-deletion. We will comply with your request without undue delay and in any event within one month of receiving it. Where the request is complex, or where we receive a large number of requests, this period may be extended by a further two months; we will inform you of the extension and its reasons within the first month. Handling your request is free of charge. If we have reasonable doubts about the identity of the person making the request, we may ask for additional information to identify you — but only to the extent necessary. We generally do not ask for a copy of an identity document for this purpose. If we do not comply with your request, we will inform you within the above period, stating the reasons for the refusal and your right to lodge a complaint with the supervisory authority and to seek a judicial remedy. Remedies If you believe that our processing infringes your rights, please contact us first — most questions can be clarified quickly. You may also lodge a complaint with the supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH) Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary Postal address: 1363 Budapest, Pf. 9, Hungary Telephone: +36 30 484 2226 E-mail: ugyfelszolgalat@naih.hu Website: https://naih.hu You may also bring proceedings before a court. At your choice, the action may be brought before the regional court of your place of residence or place of stay.

18. Changes to this policy

We may amend this policy from time to time, for example when we introduce a new feature, engage a new provider, or in response to changes in the law. In the event of a material change — in particular a new processing purpose, a new legal basis, a new processor or a new transfer to a third country — we will inform you by e-mail or through a notice shown on the Platform before the change takes effect. Minor, clarifying changes are indicated by updating the effective date and version number shown at the top of this document. If we intend to use your data for a purpose other than the one for which it was collected, we will inform you separately before that new processing begins.

Ready to get started?

Sign up now and experience secure invoice management.

Register