Home Business Altegio Trust, Privacy, and Compliance: GDPR/LGPD, Security, and Governance

Altegio Trust, Privacy, and Compliance: GDPR/LGPD, Security, and Governance

Table of Contents

Introduction

This page consolidates Altegio’s core trust, privacy, security, and governance commitments in one reference for auditors, legal teams, CISOs, and procurement. It summarizes official policies and product controls and links to primary documents. See the official Privacy Policy, License/Terms, and Anti‑Corruption Policy for legally binding details. Privacy (EN), License (EN), Terms (EN), Anti‑Corruption (EN).

Roles and responsibilities (controller vs. processor)

  • Business users (your company): Data controller for your end‑customers’ data collected via Altegio (bookings, client cards, loyalty, memberships). License (EN), Privacy (EN).
  • Altegio Europe KFT: Data processor for client data on behalf of business users; data controller for user/account data (your company’s admin and staff users). Privacy (EN).
  • Regional notes: Hungarian policy and DPA materials reaffirm controller/processor split and GDPR basis. Privacy (HU), DPA/Processors (HU).

Data categories and roles

Data categoryTypical examplesRole of your companyRole of Altegio
End‑customer dataAppointment info, loyalty/memberships, messages, payments metadataControllerProcessor
Business user dataOwner/manager/staff account detailsControllerController

Legal frameworks and lawful bases

Data subject rights

Hosting, data residency, and transfers

  • EU hosting: Altegio’s infrastructure is housed in Germany with Hetzner data centers; corporate materials emphasize EU residency. About (EN), About (PT).
  • DPA storage statement: Processing/storage is performed within the EU; the DPA enumerates EU locations used. Always verify any data‑residency requirements in your order/SCCs. DPA/Processors (HU).

Sub‑processors and support providers

  • Listed sub‑processors (per DPA): Altegio Limited (technical ops), LINK Mobility Hungary (SMS), OTP Mobil (payments), Zendesk Global, Intercom Software UK (support/ticketing). DPA/Processors (HU).
  • Additional integrations (customer’s choice): Stripe, VivaWallet, MonoBank, LiqPay, PIX and other providers may process data when you connect them. Online payments docs, Finances & accounting.

Incident response and breach notification

  • Processor breach notice: Altegio must notify subscribers (controllers) in writing without delay and within 24 hours of becoming aware of a personal data incident. DPA/Processors (HU).
  • Controller duties: As controller, your organization evaluates notification to authorities/data subjects per GDPR/LGPD timelines.

Security controls and operational reliability

  • Availability and reliability: 99.98% platform uptime stated in corporate materials. About (EN).
  • Network/app protection: Corporate security mentions TLS encryption and protective layers (e.g., Cloudflare). About (RU).
  • Access control and least privilege: Granular user roles/rights for calendar, client data, finance, downloads, and user management to minimize exposure. Access rights – Calendar, Configuring user access, Users list management.
  • Audit and logging: Data‑access logs and download logs; recommend unique accounts per employee; audit trails available. Securing your data, Downloads logging.
  • Call recordings: When IP telephony is integrated, conversation recordings retained for 1 year, with reporting and downloads controlled. Reports – Calls.

Payments and PCI DSS

Cookies and tracking technologies

  • Cookie policy: Altegio uses cookies and third‑party analytics (e.g., Google Analytics) for operation, retargeting, and statistics; users can manage cookies via browser settings, noting possible functionality impact. Cookie Policy (UKR).

Governance and ethics (Anti‑Corruption)

  • Zero‑tolerance policy for bribery, corruption, and fraud applicable to all employees and business partners; strict rules for gifts, hospitality, sponsorships, political contributions, and record‑keeping; whistleblowing and non‑retaliation are mandated. Anti‑Corruption (EN).

Regional statements and social responsibility

  • Support for Ukraine and sanctions posture: Altegio publicly commits to ceasing services and cooperation in Russia/Belarus and providing support measures for Ukraine. Stand with Ukraine (EN).

Practical product controls for privacy by design

How to exercise data rights or report an issue

Document control

Appendix: quick references

What else to read?