AllAdviser
HomeAdvisorsHow it works?Pricing
home
Home
people
Advisors
help_outline
How it works?
payments
Pricing


Theme

Privacy Policy

Last updated: 19 June 2026

1. Introduction

The Platform is available across the entire European Union market. Personal data is processed in accordance with Hungarian law and the EU GDPR; the lead (one-stop-shop) supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). Data subjects residing in any member state of the European Union may also contact the supervisory authority or court of their own member state.

The Platform serves two main categories of users: questioners (who purchase advisory services) and advisors (who provide advisory services). Please read this Notice carefully before using the Platform; it describes in detail what personal data we process, for what purpose, on what legal basis and for how long, as well as what rights you are entitled to.

2. Details of the data controller

Data controller: Horváth Tibor György e.v.

Registered address: 1123 Budapest, Táltos u. 14. 1st floor 2.

Sole trader: Registered sole trader

Tax number: 58788307-1-43

E-mail: privacy@alladviser.eu

Data protection contact: privacy@alladviser.eu (appointment of a data protection officer is not mandatory; for data protection enquiries please contact us at the above address)

3. Categories of personal data processed

We process the following categories of personal data in the course of operating the Platform. Providing the data is necessary for registration and use of the service; without certain data, some functions of the Platform may not be available.

3.1 Registration and account data

  • Name and display name
  • E-mail address
  • Telephone number (optional, for SMS notifications)
  • Year of birth
  • Interface language and profile picture
  • Password (stored exclusively in an irreversible form encrypted with the Argon2id algorithm)
  • Login method (password, Google or Apple account), and external identifier (Google or Apple ID) in the case of social login
  • Two-factor authentication status and backup codes (encrypted), login security data (failed login attempts, lock status)

3.2 Advisor profile and financial data

  • Advisor title, introductory text, country, advisory languages and professional experience
  • Profile and gallery images
  • Billing data: company name, country, city, postcode, address, tax number and EU VAT number
  • Banking data for payouts: account holder name, bank name and IBAN (IBAN stored with AES-256-GCM encryption, masked when displayed)
  • Stripe Connect account identifier and payout settings
  • Advisor credit balance (the advisor uses credits purchased from the Platform to make booking time slots available or extend them)

3.3 Transaction and service data

  • Booking and appointment data (booked time slot, status, payment deadline)
  • Payment data: transaction amount (in EUR), status and identifier; the questioner pays directly to the advisor through the Stripe system, and all card data processing is carried out by Stripe
  • In the case of bank transfer payment, the transfer reference code and related data
  • Billing data and issued invoices (tax number, address, recipient e-mail address)
  • Messages between the questioner and the advisor
  • Online consultation connection data (room identifier, connection link)
  • Ratings, reviews and responses thereto
  • Data relating to complaints, disputes and reports

3.4 Technical data

  • The Platform stores authentication tokens (access token, refresh token) as well as language and theme settings in the browser's local storage (localStorage)
  • The language (locale) and theme (theme-mode) settings are also stored in a cookie to ensure the correct interface is displayed
  • The cookie consent setting is stored in the browser's local storage (cookieConsent)
  • During payment and bank transfer, data is temporarily stored in the browser's session storage (sessionStorage) and deleted after being read
  • Time of last activity, time of account creation and modification
  • The Platform does not use analytical (Google Analytics, Matomo, etc.) or marketing (Facebook Pixel, advertising) cookies or tracking scripts

4. Purposes of data processing

We process personal data for the following specific and lawful purposes. The purpose of processing is in each case adequate and relevant, and limited to what is necessary.

  • Account creation and management: registration, login and operation of the user account.
  • Identification and communication: identifying users and communicating with them in connection with the service.
  • Provision of advisory services: appointment booking, conducting online consultations, messaging and operation of the rating system.
  • Processing payments and payouts: processing questioner payments to advisors, purchases of advisor credits, advisor payouts and refunds, denominated in EUR, with the involvement of Stripe.
  • Billing and accounting: issuing electronic invoices and fulfilling statutory accounting obligations.
  • Security and fraud prevention: protecting the Platform and users, preventing fraud and abuse, automated content checking of advisor profiles.
  • Compliance with legal obligations: fulfilling record-keeping, accounting and regulatory obligations based on statutory requirements.
  • Complaint handling and dispute resolution: handling user complaints, disputes and reports.

5. Legal bases for data processing

Personal data is processed on the following legal bases pursuant to Article 6 GDPR. Each processing activity is associated with an appropriate legal basis corresponding to its purpose.

  • Consent (Article 6(1)(a) GDPR): registration and the use of non-essential cookies are based on your voluntary, explicit consent. Consent may be withdrawn at any time, but withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
  • Performance of a contract (Article 6(1)(b) GDPR): processing related to the provision of advisory services, the execution of bookings, payments and payouts is necessary for the performance of the contract concluded with the user.
  • Compliance with a legal obligation (Article 6(1)(c) GDPR): the processing of billing and accounting data is based on a statutory obligation.
  • Legitimate interests (Article 6(1)(f) GDPR): maintaining the security of the Platform, preventing fraud and abuse, and ensuring network and information security are based on the legitimate interests of the data controller. Your rights and freedoms take precedence where processing would unjustifiably restrict them.

6. Data transfers and data processors

Personal data is transferred to third parties only to the extent necessary for the provision of the service, under a data processing agreement. We use the following data processors, with access limited to data necessary for the given purpose:

  • Stripe (payment and payout): processing card payments, Stripe Connect advisor accounts, payouts and refunds. Stripe processes the purchaser's e-mail address and transaction data during payment; all card data processing is carried out on Stripe's side.
  • MongoDB Atlas (database): storage and operation of the Platform's entire database (accounts, profiles, messages, invoices, etc.).
  • Amazon Web Services (AWS S3) – file storage: storage of profile and gallery images, as well as uploaded PDF documents.
  • Billingo (invoicing): issuing electronic invoices; processing partner and invoice data necessary for invoicing.
  • Twilio (SMS): delivery of SMS notifications to the telephone number, if SMS notification is enabled.
  • AI service provider (Mistral) – profile validation: automated checking of the advisor profile's name, introductory text and profile picture (filtering prohibited content and contact information).
  • Google (login): in the case of login with a Google account, processing the Google identifier, as well as the e-mail address and name derived from the token.
  • Apple (login): in the case of login with an Apple account, processing the Apple identifier.
  • VIES (EU VAT number verification): verifying the validity of EU VAT numbers through the European Commission's VIES service.

Some processors may also process data outside the EEA: Stripe, AWS and Google (United States), on the basis of the EU–US Data Privacy Framework or, failing that, the European Commission's Standard Contractual Clauses (SCC). These safeguards ensure that your data enjoys a level of protection essentially equivalent to that guaranteed within the EU.

7. Data retention periods

Personal data is retained only for as long as necessary to achieve the purpose, or for the period prescribed by law. The actual retention periods are as follows:

  • Login sessions (refresh token): 7 days.
  • Two-factor authentication and e-mail confirmation codes: 15 minutes.
  • Password reset tokens: 30 minutes.
  • Access tokens: 15 minutes; encrypted token associated with a pending registration: 15 minutes.
  • Billing and accounting data: for the retention period prescribed by law, which is typically 8 years for invoices.
  • User account data: until deletion (anonymisation) of the account; upon account deletion, identifying data (e-mail, name) is anonymised and the account is deactivated.
  • Advisor profile deletion: after deletion, the profile is retained for up to 1 year (for legal and settlement purposes), after which it is permanently and physically deleted.
  • Processing based on consent continues until consent is withdrawn, unless another legal basis (e.g. a legal obligation) justifies further retention.
  • Invoice documents (including the recipient's name, email address and postal address) are retained for the full 8-year statutory period and cannot be deleted despite an erasure request, pursuant to GDPR Article 17(3)(b).
  • In-app notifications: automatically and permanently deleted 90 days after they are created, regardless of whether they have been read.
  • Private messages: when an account is deleted, the content of messages sent by that account is irreversibly anonymised; the conversation history otherwise remains available to the other participant until they delete it or until their own account is deleted. Messages deleted by both participants are permanently and physically removed 30 days after that mutual deletion.
  • Security and audit logs: retained for the statutory retention period applicable to legal-compliance and claim-enforcement purposes (typically 8 years).

8. Rights of data subjects

Under the GDPR, you are entitled to the following rights with regard to the processing of your personal data. We will fulfil your request without undue delay, and in any event within 1 month of receipt of the request (this period may be extended by a further two months where the request is complex).

  • Right of access: you may request information as to whether we are processing your personal data and, if so, you may access that data as well as information relating to its processing.
  • Right to rectification: you may request the rectification of inaccurate personal data relating to you, or the completion of incomplete data.
  • Right to erasure ('right to be forgotten'): you may request the erasure of your personal data if the purpose of processing has ceased, or if you have withdrawn your consent and there is no other legal basis for processing.
  • Right to restriction of processing: in certain cases, you may request restriction (blocking) of processing.
  • Right to object: you may object to processing based on legitimate interests, and at any time, free of charge, to processing for direct marketing purposes.
  • Right to data portability: you may request that data you have provided to us be received in a structured, commonly used and machine-readable format, or transmitted to another data controller.
  • Right in relation to automated decision-making and profiling: you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
  • Right to withdraw consent: you may withdraw your consent to processing based on consent at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

To exercise your rights or for any data protection enquiry, the data controller can be reached at privacy@alladviser.eu. Modification or deletion of personal data may also be initiated through the Platform settings.

9. Data security

We apply appropriate technical and organisational measures to protect personal data, ensuring an adequate level of security against unauthorised access, alteration, transfer, disclosure, deletion or destruction, as well as accidental loss and damage.

  • Encrypted (TLS/HTTPS) data transmission between the Platform and users.
  • Passwords stored exclusively in an irreversible form using the Argon2id algorithm.
  • Two-factor authentication (2FA) available for account protection.
  • Banking IBAN data stored with AES-256-GCM encryption, masked when displayed.
  • Access restriction: personal data is accessible only to authorised persons who need it for the performance of their duties.
  • Login security measures: limiting failed login attempts and account locking in the event of abuse.
  • In the event of a personal data breach, where the breach is likely to result in a risk to the rights and freedoms of natural persons, the data controller will notify the supervisory authority (NAIH) without undue delay and at the latest within 72 hours, and will communicate the breach to the data subjects where necessary.

10. Cookies

The Platform uses strictly necessary cookies and local storage (to remember the interface language and theme, and to maintain the logged-in state). The Platform does not use analytical or marketing cookies or tracking scripts. Certain features (e.g. Google and Apple login, and Stripe payment) may set essential third-party cookies necessary for their operation. Detailed information about the use and management of cookies can be found in the Cookie Policy.

11. Protection of children's data

The Platform is an information society service. In the case of a child below the age of 16, processing of personal data is lawful only if and to the extent that consent is given or authorised by the person who holds parental responsibility for the child. Individual EU member states may set this age threshold differently, between 13 and 16 years; the relevant national regulation of the applicable member state is governing. The Platform does not knowingly collect personal data from children under the age of 16 without appropriate parental consent.

12. Amendments to this Notice

The data controller reserves the right to amend this Notice at any time, in particular in the event of changes in legislation or changes to the service. The amended Notice takes effect upon its publication on the Platform. Users will be informed in an appropriate manner of material changes. We recommend that you review the current version of this Notice periodically.

13. Remedies and complaints

If you consider that the processing of your personal data infringes statutory requirements, you are entitled to lodge a complaint with the supervisory authority. The lead (one-stop-shop) supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH). However, a data subject residing in any member state of the European Union may also contact the supervisory authority of the member state of their habitual residence, place of work or place of the alleged infringement, and may also seek judicial remedy.

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9-11.

Phone: +36 1 391 1400

E-mail: ugyfelszolgalat@naih.hu

Website: www.naih.hu

14. Contact

For data protection enquiries, requests or complaints, you may contact us at the following addresses:

  • Data controller: Horváth Tibor György e.v.
  • Registered address: 1123 Budapest, Táltos u. 14. 1st floor 2.
  • Data protection e-mail: privacy@alladviser.eu
  • General customer service: info@alladviser.eu
  • Data protection contact: privacy@alladviser.eu
  • Phone: +36 30 744 0290

Related documents

descriptionTerms of ServicecookieCookie Policy
AllAdviser

Find the perfect advisor for online consultation

Quick links
AdvisorsHow it works?PricingFAQContact
Legal
Terms of ServicePrivacy PolicyCookie PolicyCookie settings
Contact
info@alladviser.eu

© 2026 AllAdviser. All rights reserved