Legal

Privacy Policy

How we handle your personal data in GrantCortex.

Last updated: 2026-07-19 · v7

1. Data Controller

Data controller: Szabó István Márió, 6400 Kiskunhalas.

Privacy and general inquiries: info@grantcortex.eu.

Website: grantcortex.eu · MCP endpoint: mcp.grantcortex.eu.

2. What data we process

The email+password account and the contact features process the following personal data on the server:

2.1 Account data

  • email address (the account identifier, stored lowercased),
  • password hash — we NEVER store your password, only the one-way scrypt hash,
  • display name (optional),
  • email-verification status, consent version and timestamp (evidence that you accepted the terms/policy),
  • plan, account-creation and last-login times,
  • security counters: failed-login count and any account-lockout time,
  • if you use Google sign-in: the Google subject id (google_sub).

2.2 Sessions

  • the SHA-256 hash of the session token (the token itself is not stored),
  • IP address and browser User-Agent (device recognition and the "log out other devices" feature),
  • creation and expiry times.

2.3 Authentication tokens

Email-verification and password-reset link tokens are likewise stored only as a hash (SHA-256), single-use, with an expiry.

2.4 Tester / API keys

For issued API/tester keys we keep a key identifier and the issue/revocation status.

2.5 Contact

If you use the contact form, your name, email, and message are processed to coordinate with you. Email addresses from earlier waitlist sign-ups are kept solely to notify you about the service launch, for at most 12 months or until you request deletion.

2.6 Browser storage (localStorage)

Up to two functional localStorage keys are written in your browser (gcx-lang, gcx-cookie-ack); signed-in accounts additionally use two strictly necessary first-party cookies (gc_web_session, gc_web_csrf). Details on the Cookies & local storage page.

2.7 Web-server logs

Our web server (reverse proxy) writes one short technical access-log row per HTTP request: timestamp, IP address, requested path, response status code, and the browser User-Agent header. Purpose: security, abuse prevention, and debugging; lawful basis: legitimate interest (GDPR Art. 6(1)(f)). Log rows contain no content (no form data or request bodies), are continuously overwritten by automatic rotation, and we keep no persistent log archive.

MCP server request log (audit log)

When you call the MCP endpoint (mcp.grantcortex.eu) with a tester key, the server writes one technical log row per request. This is metadata only:

  • timestamp (request start, UTC)
  • the calling account / token identifier
  • the name of the tool called
  • HTTP method, path and response status code
  • response latency
  • IP address and the client User-Agent header

Why: security and abuse prevention (rate limiting, detecting unauthorised access), debugging and capacity planning. Lawful basis: legitimate interest (GDPR Art. 6(1)(f)).

Retention: log rows are automatically deleted daily after roughly 90 days (auto-purge).

What we NEVER store: the content of your tool calls. Your search terms, your questions and the text of the documents you retrieve are never written to the log — nor anywhere else on the server. The log records that a call happened, not what you asked.

Semantic search runs locally on our EU server (a local embedding model). The content of your MCP tool calls is NOT sent to any third-party AI provider (e.g. OpenAI).

3. Lawful basis (GDPR Art. 6)

  • Creating an account and providing the service: contract / pre-contract (Art. 6(1)(b)).
  • Audit log, security, abuse prevention: legitimate interest (Art. 6(1)(f)).
  • Newsletter (if any): consent (Art. 6(1)(a)), withdrawable at any time.
  • Compliance with a legal obligation: Art. 6(1)(c).

Beyond transactional email (verification, password reset, contact), we currently send NO marketing messages. If we introduce a newsletter, we will ask for separate, explicit consent.

4. EU AI Act positioning

The GrantCortex MCP server provides deterministic eligibility calculations and source-cited search results; it does not automatically replace human decision-making. Classification: EU AI Act · limited-risk. Should we introduce a surface where an AI assistant interacts with you directly, we will clearly disclose it (AI Act Art. 50(1)).

5. Processors and data transfers

To operate the service we use carefully selected processors (GDPR Art. 28):

ProcessorRoleLocation / safeguard
Hetzner Online GmbHHosting / server infrastructureEU (Germany/Finland)
Resend, Inc.Transactional email deliveryUSA — transfer safeguard: SCC + EU-US Data Privacy Framework, DPA
Google (OAuth) — if enabledGoogle sign-inUSA — SCC / DPF (only if enabled)

For transfers to the USA, the safeguards under GDPR Art. 44–49 (Standard Contractual Clauses / SCC and EU-US Data Privacy Framework certification) ensure an adequate level of protection.

6. Your rights

  • Right of access (GDPR Art. 15)
  • Right to rectification (GDPR Art. 16)
  • Right to erasure / "right to be forgotten" (GDPR Art. 17)
  • Right to restriction of processing (GDPR Art. 18)
  • Right to data portability (GDPR Art. 20)
  • Right to object (GDPR Art. 21)
  • Rights related to automated decision-making and profiling (GDPR Art. 22)

Submit requests to info@grantcortex.eu; we will respond within 30 days. You can delete your account yourself on the Account page; deletion cascades to your sessions.

Audit-log export: to exercise the right of access (Art. 15) and data portability (Art. 20) you can request a CSV export of the log rows tied to your own tester key by emailing info@grantcortex.eu. The export is produced from our per-key audit-CSV facility and contains only the metadata listed above — never tool-call content.

7. Retention

  • Account data: for the life of the account, deleted within a reasonable period after a deletion request / account deletion.
  • Audit log: roughly 90 days (auto-purge).
  • Sessions: deleted automatically on expiry.
  • Authentication tokens: single-use, short expiry.
  • Contact messages: up to 12 months after the inquiry is closed, or until a deletion request.
  • Web-server logs: continuously overwritten by automatic rotation; no persistent archive.
  • localStorage: you can clear it any time in your browser.

8. Security (GDPR Art. 32)

Our technical and organisational measures include: scrypt password hashing, storing session and link tokens only as hashes, failed-login throttling and account lockout, request-level rate limiting, TLS encryption for all traffic, and daily backups. Details on the Security page.

9. Personal data breach

In the event of a personal data breach we notify the supervisory authority without undue delay and within 72 hours (GDPR Art. 33), and — where the breach is likely to result in a high risk to your rights — we inform you as well (GDPR Art. 34).

10. Third parties and tracking

No third-party analytics, ad networks, or tracking SDKs are embedded in the website. We measure site traffic with a self-hosted, cookieless Umami analytics instance running on our own EU server: it collects only aggregate statistics (page views, approximate location at country/region/city level, referrer, device type), stores no raw IP addresses — visitors are distinguished by a monthly-rotating, irreversible technical identifier —, shares nothing with third parties, and honours the “Do Not Track” setting. Details: Cookies & local storage page. The MCP server aggregates data from publicly available EU/national portals — those operate under their own privacy policies.

11. Cookies and local storage

We use only functional localStorage, no tracking cookies. Details and a clearing guide: Cookies & local storage page.

12. Changes

Material changes to this policy will be posted on this page with an updated "Last updated" date.

13. Supervisory authority

You have the right to lodge a complaint with the competent data protection authority. In Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11, naih.hu.

Related pages