GDPR & Data Protection Notice
Last updated: July 7, 2026
This notice describes how personal data is processed in connection with PromptShielder (the "Service") and this website, in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Hungarian Information Act (2011. évi CXII. törvény, "Infotv."), and related EU / EEA data protection law.
1. Data controller
Péter Horányi, egyéni vállalkozó, trading as PromptShielder.
Érc utca 4., 1032 Budapest, Magyarország
Tax number: 48986078-1-42
Email: hello@promptshielder.com
Phone: +36 20 379 6949
For all data protection questions, please write to hello@promptshielder.com.
2. Scope
This notice covers (a) the PromptShielder marketing website at promptshielder.com and (b) the in-browser PromptShielder application at /app.
3. The core fact about prompt content
PromptShielder's detection, tokenisation, and demasking run entirely inside your browser session. Prompt content and the token dictionary are never transmitted to servers operated by the data controller and are never stored on any such server. See Security Architecture for the technical description.
Because the controller does not receive, process, or have access to prompt content, no processor relationship arises with respect to prompt text and no data processing agreement (DPA) is required for that content. A DPA may still be appropriate for account data — see Section 4.
4. Categories of personal data actually processed
- Account data — email address, hashed authentication identifiers, sign-in timestamps. Processed if you create an account.
- Billing data — handled by Paddle.com Market Ltd ("Paddle") as Merchant of Record. Paddle is the independent controller of payment card data; we do not receive or store card details.
- Support correspondence — the content of emails you send to us.
- Server / access logs — technical metadata (IP address, user agent, request path, timestamp) generated at the hosting edge, retained for a short window for security and abuse prevention.
- Analytics — where enabled, aggregated usage statistics via Google Analytics with IP truncation. No prompt content is transmitted.
5. Legal bases (Art. 6 GDPR)
- Art. 6(1)(b) — contract: account creation, service delivery, billing.
- Art. 6(1)(c) — legal obligation: invoicing and tax record-keeping under Hungarian law.
- Art. 6(1)(f) — legitimate interest: security, abuse prevention, and product analytics in aggregated form.
- Art. 6(1)(a) — consent: where cookie or tracking consent is required by local law.
6. Retention
- Prompt content: never stored — not applicable.
- Account data: for the lifetime of the account, plus statutory retention periods after closure.
- Invoices / billing records: 8 years, in accordance with Hungarian Act C of 2000 on Accounting.
- Server logs: typically up to 30 days.
- Support correspondence: for as long as necessary to handle the request and any follow-up, then archived or deleted.
7. Recipients and sub-processors
- Hosting / edge infrastructure — global CDN and edge-compute provider used to deliver the site.
- Backend / authentication — managed backend platform used to store account data.
- Paddle.com Market Ltd — Merchant of Record; handles checkout, tax, and payments.
- Google Ireland Ltd — analytics, where enabled.
8. International transfers
Some sub-processors may process data outside the EEA. Where this occurs, transfers are protected by adequacy decisions, the European Commission's Standard Contractual Clauses (2021/914), and additional technical measures where appropriate.
9. Your rights (Art. 15–22 GDPR)
You have the right to:
- access your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure (Art. 17), subject to statutory retention;
- request restriction of processing (Art. 18);
- data portability for data you provided (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time where processing is consent-based;
- lodge a complaint with a supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu.
To exercise any of these rights, email hello@promptshielder.com. We respond within one month (Art. 12(3) GDPR).
10. Cookies
This site uses only cookies that are strictly necessary for the Service or, subject to consent, cookies for analytics. No advertising or cross-site tracking cookies are used.
11. Automated decision-making
We do not carry out automated decision-making with legal or similarly significant effects on you within the meaning of Art. 22 GDPR.
12. Security
Technical and organisational measures include TLS in transit, client-side-only processing of prompt content, minimal data collection, and access controls on account data. See Security Architecture.
13. Changes to this notice
We may update this notice to reflect changes in the Service or the law. The current version, with its date of last update, is always available at this URL.