This policy explains what personal data Grey Technologies Kft. collects when you use this website, why we collect it, how long we keep it, and what you can do about it. It is written to be read, not to be survived. If anything here is unclear, ask us.
1. Who we are and how to contact us
Grey Technologies Kft. is the controller of the personal data described in this policy. We decide why and how it is processed.
| Legal entity | Grey Technologies Kft. |
| Registered in | Hungary |
| Company registration number | 01-09-445879 |
| Registered office | Ferenciek tere 2. Fsz., 1053, Budapest, Hungary |
| EU VAT number | HU32848865 |
| Privacy contact | info@greytechnologies.io |
| Security contact | security@greytechnologies.io |
We have not appointed a Data Protection Officer. We are not required to under GDPR Article 37: we are not a public authority, we do not carry out large-scale systematic monitoring, and we do not process special category data at scale. Privacy requests are handled by our Managing Director.
Applicable law: the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the "Info Act").
2. What this policy covers
This policy covers the public website at greytechnologies.io.
It does not cover personal data we process under a client engagement. Where we act as a processor or joint controller for a client, for example during a detection engineering or compliance advisory engagement, the relevant Master Services Agreement and Data Processing Agreement govern that processing, not this policy.
3. What we collect, why, and on what lawful basis
We collect four things. Nothing else. Each is set out below with its lawful basis under GDPR Article 6.
3.1 Contact form submissions
When you submit the contact form we receive:
- Full name (required)
- Work email address (required)
- Your message (required, free text, you decide what goes in it)
- Service interest, which of our services you ticked
- Enquiry type, what you want to do (discuss goals, see a demo, and so on)
- Timestamp, the ISO 8601 time the submission reached our server
- Country, a two-letter country code derived by Cloudflare from your IP address (
CF-IPCountry). We receive the country only. The IP address itself is not stored with your enquiry.
The form also contains a hidden decoy field that no human ever sees. Anything submitted in it is treated as automated spam and discarded without being read, stored, or delivered.
Purpose: to read your enquiry and reply to it. Lawful basis: legitimate interests (Article 6(1)(f)). Our interest is in responding to people who deliberately contact us about our services. You initiated the contact, the data is minimal, and none of it is used for anything other than replying. We consider this processing to be within your reasonable expectations. If you disagree, see section 10. Where it goes: your submission is transmitted over TLS to a Cloudflare edge function, which does two things with it. It emails your enquiry to our company inbox through Microsoft 365, and it writes a copy to Cloudflare KV storage so that a mail failure cannot lose your enquiry. That stored copy holds the fields listed above and, deliberately, not your IP address. It is deleted automatically after 90 days — see section 6.
We send you one acknowledgement. When your enquiry reaches us we email a short confirmation to the address you gave, containing a reference number and the service options you ticked. It is sent once, it is not marketing, and it does not subscribe you to anything. If you receive one you did not ask for, someone has entered your address into our form: the message deliberately contains no text written by whoever submitted it, so it cannot be used to send you anything but this notice, and you can ignore it safely. Tell us at privacy@greytechnologies.io and we will remove the enquiry.
Free text is a risk you control. Please do not put sensitive personal data, credentials, client names under NDA, or live security findings into the contact form. If you need to send us something sensitive, email security@greytechnologies.io and use our PGP key.
If the form fails. If our server cannot be reached, nothing is transmitted and nothing is stored — your message stays in the form in your browser. We then offer you the choice of copying it or opening your own email client with the fields pre-filled. Nothing is sent anywhere until you press send in your own mail application.
3.2 Anti-bot verification (Cloudflare Turnstile)
The contact form is protected by Cloudflare Turnstile. To verify that a submission is not automated, our server sends the following to Cloudflare's verification endpoint:
- Your IP address (
CF-Connecting-IP) - The single-use challenge token generated by the Turnstile widget in your browser
Your IP address is used for this verification and is not stored by us or included in the email we receive.
The Turnstile script is loaded from challenges.cloudflare.com only on the two pages that carry the contact form, the home page and the consulting page. It is not loaded on the blog, research, ARC or legal pages, so no request reaches Cloudflare from those pages at all.
Purpose: to stop automated abuse of the contact form. Lawful basis: legitimate interests (Article 6(1)(f)). Preventing spam and automated abuse of a public form is a recognised legitimate interest, and is expressly acknowledged in GDPR Recital 49.
3.3 Hosting and network logs
This site is hosted on Cloudflare. Serving and protecting a website necessarily involves processing request data, including IP addresses, at the network edge.
Purpose: to serve the site, keep it available, and defend it against attack. Lawful basis: legitimate interests (Article 6(1)(f)) in operating and securing our own infrastructure. Retention: governed by Cloudflare's own configuration and retention settings, see section 6.
3.4 Optional analytics (Microsoft Clarity), consent only
We use Microsoft Clarity (project ID utsjkyirv0) as optional analytics. Read section 5 before you decide. It does more than count page views.
Purpose: to understand how people move through our research and service pages. Lawful basis: consent (Article 6(1)(a)), and consent under section 155(4) of Act C of 2003 on Electronic Communications, which implements the ePrivacy Directive, for the storage and access of information on your device.
The Clarity script is not present in the page at all until you actively accept optional analytics. Declining is the default, costs you nothing, and changes nothing about how the site works. You can withdraw consent at any time through Cookie Settings in the footer.
3.5 Your consent choice
When you accept or decline optional analytics, we record that decision in your browser's localStorage, under the key gt-cookie-consent.
This is localStorage, not a cookie. The distinction matters and we state it plainly because our earlier policy got it wrong. A cookie is transmitted to a server with every matching request. A localStorage entry is not, it stays in your browser and is only read by scripts on this site. We never receive a copy of it. The record contains a schema version, whether you accepted analytics, and the timestamp of your decision.
Purpose: to remember your decision so we do not ask again on every page. Lawful basis: storing your consent choice is strictly necessary to provide a service you have requested, and is exempt from the consent requirement as strictly necessary for a service you asked for. It is a legal and practical necessity, we are required to be able to demonstrate consent under Article 7(1).
You can erase it at any time by clearing site data in your browser. The banner will then simply ask again.
4. Cookies and similar technologies
We set no advertising cookies, no cross-site tracking cookies, and no data broker tags, ever.
Typefaces are self-hosted and served from this domain. No asset request leaves for a third-party font CDN.
What actually gets stored on your device:
| What | Type | Set by | Purpose | Consent needed |
|---|---|---|---|---|
gt-cookie-consent | localStorage | This site | Remembers your analytics choice | No, strictly necessary |
| Turnstile challenge state | See 3.2 | Cloudflare | Anti-bot verification of the contact form | No, strictly necessary |
_clck | Cookie, 1 year | Microsoft Clarity | Persistent Clarity user identifier | Yes |
_clsk | Cookie, 1 day | Microsoft Clarity | Groups page views into one session | Yes |
CLID | Cookie, 1 year, set on clarity.ms | Microsoft Clarity | Identifies when Clarity first saw your browser, across any site using Clarity | Yes |
The Clarity cookies in that table are only ever set if you accept optional analytics. Decline, and none of them appear.
5. Microsoft Clarity in detail
We describe this in full because our earlier policy called it "aggregate usage measurement". That materially understated it. Clarity is a behavioural analytics product, not a page counter.
If you accept optional analytics, Microsoft Clarity may collect:
- Session recordings. Clarity reconstructs and replays your visit, the pages you moved through, where your pointer went, what you clicked, how far you scrolled, and how long you stayed. We can watch that reconstruction.
- Heatmaps aggregating clicks, scroll depth, and interaction across all visitors.
- Device and browser data, browser type, operating system, screen resolution, referring page.
- Approximate location derived from your IP address, at country or region level.
- Interaction with form fields. Clarity masks input content by default, so what you type into the contact form should not be captured. Masking is a configuration setting, not a law of physics.
Clarity is operated by Microsoft Corporation, and data collected through it is processed by Microsoft, including in the United States. See section 7.
Microsoft acts as our processor for this analytics data. Microsoft's own handling of it is additionally described in the Microsoft Privacy Statement.
You do not have to allow any of this. Decline in the banner, or withdraw later via Cookie Settings in the footer. On withdrawal we instruct Clarity to stop, and the tag is not loaded again on any subsequent page load.
6. How long we keep things
| Data | Retention | Reasoning |
|---|---|---|
| Enquiry that does not lead to an engagement | 12 months from the last substantive contact, then deleted | One full annual budget cycle. Enterprise security procurement is slow, and a genuine enquiry can reasonably resurface within a year. Past that, our interest in holding your data no longer outweighs your interest in it being gone. |
| Enquiry that leads to an engagement | For the duration of the engagement, then 8 years from its end | The Civil Code (Act V of 2013) s.6:22 sets a general limitation period of 5 years for contract claims, and the Accounting Act (Act C of 2000) s.169 requires accounting records to be kept for 8 years. We need the record to defend a claim or satisfy an audit within that window. |
| Delivery backstop copy of your enquiry (Cloudflare KV) | 90 days from submission, then deleted automatically by the storage layer | Written before we attempt to email your enquiry to ourselves, so that a mail outage cannot silently lose it. It is an operational safety net, not our record of you — so it is deliberately set to expire well before the 12 months above, and it never contains your IP address. |
| Submissions rejected as spam | Not retained. Decoy-field submissions are discarded in memory and never delivered. Failed anti-bot verifications are rejected and never delivered. | Nothing legitimate to keep. |
Your consent record (localStorage) | 12 months, or until you clear your browser storage or we publish a new consent version, whichever comes first | The stored decision carries a 12-month expiry, after which the banner asks again. Consistent with NAIH and wider EU regulator expectations that consent is refreshed rather than treated as permanent. |
| Cloudflare edge and network logs | 24 hours, via the Cloudflare Dashboard UI for log retention and purge at account level. No Logpush is enabled. | Governed by Cloudflare configuration, not by us. |
| Cloudflare Turnstile verification data | Short-lived. The challenge token is single-use. Cloudflare's own retention is governed by its DPA. | 24 hours |
| Microsoft Clarity data | 1 year. This is the maximum retention period offered by Microsoft Clarity and is the value currently set in project utsjkyirv0 for both recordings and heatmaps. | Controlled by Microsoft, within limits we configure. |
When a retention period ends, data is deleted from our mailbox and any working records. Backup copies held by our providers are removed on their own cycles.
7. Who we share your data with
We do not sell your data. We do not share it with advertisers, data brokers, or marketing networks. We do not use it for marketing at all.
We use the following processors, each under a data processing agreement:
| Processor | What they do for us | What they process |
|---|---|---|
| Cloudflare, Inc. | Hosting (Pages/Workers), CDN, DDoS protection, Turnstile anti-bot, and KV storage for the 90-day delivery backstop | Request data including IP addresses; contact form contents in transit and in the stored backstop copy; your IP for Turnstile verification |
| Microsoft Corporation | Microsoft Clarity analytics, only if you consent | Session recordings, interaction data, device data, approximate location |
| Microsoft 365 | Stores and serves our company inbox, and sends both the enquiry notification to us and the acknowledgement to you | The contents of your enquiry, and your email address as the recipient of the acknowledgement |
We will also disclose personal data where we are legally required to, for example in response to a valid court order or a lawful request from a regulator or law enforcement. We will not do so voluntarily, and where we are permitted to tell you, we will.
8. International transfers
The GDPR restricts sending personal data outside the EEA unless a valid safeguard is in place.
Microsoft Clarity (United States). If you consent to optional analytics, your data is transferred to Microsoft Corporation and processed in the United States, a country without a full EU adequacy decision covering all transfers by default.
Safeguard relied upon: Microsoft's certification under the EU–US Data Privacy Framework, backed by the European Commission's Standard Contractual Clauses.
Cloudflare (global edge network). Cloudflare is a US-headquartered provider operating a globally distributed network. Requests to this site may be served from a data centre outside the EEA.
Safeguard relied upon: Cloudflare's certification under the EU–US Data Privacy Framework, backed by the European Commission's Standard Contractual Clauses.
You can request a copy of the relevant safeguard documentation from info@greytechnologies.io.
If you do not want your data transferred to Microsoft in the United States, decline optional analytics. Nothing on this site depends on them.
9. Security
We are a security company. We hold ourselves to the standard we sell.
- All traffic to this site is served over TLS. The contact form is submitted over TLS and never over plaintext HTTP.
- The contact endpoint validates and length-limits every field server-side, and strips control characters, so nothing submitted can forge downstream mail headers.
- Anti-bot verification fails closed. If the verification secret is not configured, every submission is rejected rather than allowed through.
- We apply data minimisation by design. We keep the country code, not your IP address. We use your IP only in transit for anti-bot verification.
- Analytics are not loaded until you consent. The tag is absent from the document, not merely inert.
- Access to the inbox receiving enquiries is limited to people who need it, and protected by multi-factor authentication.
No system is perfectly secure. If we suffer a personal data breach that is likely to result in a risk to your rights and freedoms, we will report it to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) within 72 hours of becoming aware of it, as required by Article 33. Where the risk is high, we will tell you directly and without undue delay.
If you have found a vulnerability in this site, see section 14.
10. Your rights
Under the GDPR you have the following rights. They are free to exercise. We will respond within one month, and will tell you if we need to extend that (we may extend by two further months for complex requests, under Article 12(3)).
- Access (Article 15), get a copy of the personal data we hold about you, and be told how we use it.
- Rectification (Article 16), have inaccurate data corrected, or incomplete data completed.
- Erasure (Article 17), have your data deleted. This is not absolute; we may keep what we need to establish, exercise, or defend a legal claim.
- Restriction (Article 18), have us pause processing while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20), receive data you gave us in a structured, machine-readable format. This applies to processing based on consent or contract.
- Object (Article 21), object to processing based on legitimate interests, including our handling of your enquiry. You do not have to give a reason, though telling us your grounds helps us weigh it. If you object, we stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Withdraw consent (Article 7(3)), withdraw consent to optional analytics at any time. It is as easy to withdraw as it was to give: open Cookie Settings in the footer and decline. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
- Not be subject to automated decision-making (Article 22), see section 12.
To exercise any of these, email info@greytechnologies.io. We may ask you to confirm your identity, but only to the extent needed to be sure we are not disclosing your data to someone else.
11. Complaints
If you think we have handled your data badly, tell us first at info@greytechnologies.io. We would rather fix it than argue about it.
You also have the right to complain directly to the supervisory authority. In Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH):
- Website: naih.hu
- Telephone: +36 1 391 1400
- Post: Nemzeti Adatvédelmi és Információszabadság Hatóság, 1055 Budapest, Falk Miksa utca 9-11., Hungary
You do not have to come to us first. If you are elsewhere in the EEA, you may instead complain to the supervisory authority in your country of residence, work, or where the alleged infringement took place.
12. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22.
We do not profile you. We do not score you. Every enquiry is read by a person.
The only automated step in the process is the anti-bot verification described in section 3.2, which determines whether a form submission is likely to be automated. If it wrongly rejects you, the site tells you so and you can retry, or email us directly at info@greytechnologies.io.
13. Children
This website is aimed at organisations and the professionals who work in them. It is not directed at children, and we do not knowingly collect personal data from anyone under 18.
If you believe a child has submitted personal data through this site, contact us at info@greytechnologies.io and we will delete it.
14. Security researchers
We welcome responsible disclosure. Our policy, contact details, and PGP key fingerprint are published at /.well-known/security.txt, and the full policy in section 8 of our Terms of Service.
Report vulnerabilities to security@greytechnologies.io. Please read the acceptable use section of our Terms of Service first, it sets out what testing is and is not in scope.
15. Changes to this policy
We update this policy when what we do changes, and when the law changes.
The effective date at the top always reflects the current version. If we make a change that materially affects your rights or introduces a new purpose for processing, we will make it prominent, and where the change requires your consent, we will ask for it again rather than assume it. Continuing to use the site after a purely clarifying change means the updated policy applies.
We recommend reviewing this policy at least annually. We review it at least annually ourselves.
16. Contact
| Purpose | Address |
|---|---|
| Privacy questions and rights requests | info@greytechnologies.io |
| Security vulnerability reports | security@greytechnologies.io |
| Postal | Grey Technologies Kft., Ferenciek tere 2. Fsz., 1053, Budapest, Hungary |