Privacy Policy

Privacy Policy

1. Introduction

The purpose of this Privacy Policy is to provide visitors and users of the https://rapidplugins.dev website with clear and detailed information about the processing of their personal data in accordance with the European Union General Data Protection Regulation, also known as the GDPR, and applicable Hungarian laws.

This Privacy Policy describes the data processing activities related to the operation, security, user accounts, comments, online tests and quizzes, statistics, technical plugins, and security features of the website.

2. Data Controller

The operator of the website and the controller of the processed data is:

Name: rapidplugins.dev
E-mail address: admin @ rapidplugins.dev
Website: https://rapidplugins.dev
Hosting provider: Tárhely.Eu Szolgáltató Kft.
Hosting provider contact page: https://tarhely.eu/kapcsolat

3. Categories of Processed Data and Plugin Functionality

The website uses the WordPress content management system and applies various plugins to provide certain functions. These plugins may affect the processing of visitors’ and users’ personal data in the ways described below.

3.1. Cookies

The website may place cookies in the visitor’s browser to ensure proper operation.

The website may store the visitor’s consent related to the use of cookies. This is a technically necessary cookie that does not collect personal data on its own. It only remembers whether the visitor has accepted the notice, so that it does not have to be displayed again on every page load.

The website may use caching to improve performance. This may create temporary files in the visitor’s browser or on the server in order to reduce page loading times.

If a visitor submits a comment on the website, the name, e-mail address and website address entered in the comment form may be stored in cookies. This is for convenience, so that the visitor does not have to enter the same details again when submitting another comment. These cookies may be stored for up to one year.

When visiting the login page, the system may set a temporary cookie to determine whether the browser accepts cookies. These cookies do not contain personal information and are deleted when the browser is closed.

When logging in to the website, several cookies are created to store login information and screen display preferences for the administration interface. Login cookies are usually valid for two days, while the cookie storing screen display preferences may be valid for up to one year. If the user selects the “Remember me” option, the login may remain active for a longer period, typically up to two weeks. Login cookies are removed when the user logs out.

If a user edits a post or page, an additional technical cookie may be stored in the browser. This cookie does not contain personal data. It only stores the identifier of the edited post and usually expires after one day.

3.2. Spam Filtering, Website Protection and Security Logging

To protect the website, filter spam, detect automated abuse, prevent attack attempts, identify unauthorized access attempts, and maintain secure operation, the website uses the RapidSecurity security plugin.

During its operation, RapidSecurity may log technical data for security purposes, especially the following:

  • IP address,
  • browser and device user agent,
  • time of the request,
  • requested URL or path,
  • HTTP method,
  • type of security event,
  • technical data related to login attempts,
  • blocking, banning or warning events,
  • GeoIP country information.

GeoIP country detection is used to display the estimated country associated with an IP address in security logs and protection features. This function works using a local GeoIP database and does not, by itself, involve sending visitor data to a third party.

The purpose of security logging is to protect the website and user accounts, detect attack attempts, investigate abuse, and maintain the availability, integrity and security of the website.

The legal basis for this processing is the legitimate interest of the Data Controller, namely the secure operation of the website, prevention of abuse, protection of website integrity, and defense against unauthorized access.

Security logs are retained for as long as necessary to fulfill the security purpose. Logs may be removed during regular maintenance or cleanup, unless longer retention is necessary for the investigation of a specific security incident.

3.3. Two-Factor Authentication

The website may use two-factor authentication to protect certain user accounts, especially administrator accounts or accounts with elevated permissions.

The purpose of two-factor authentication is to require, in addition to the username and password, a time-based one-time verification code during login. This increases the security of user accounts and reduces the risk of unauthorized access.

To operate two-factor authentication, the system may store a technical identifier or secret key associated with the user account. This is necessary so that the one-time code entered during login can be verified.

The one-time code entered during two-factor authentication is used only to verify the specific login process. The code is not transmitted to third parties.

The user may use a separate authenticator application to generate the verification code. The selection and use of such an application takes place on the user’s own device. The website does not have access to the data stored in the authenticator application.

The purpose of this processing is to protect user accounts and the administration area of the website. The legal basis for this processing is the legitimate interest of the Data Controller, namely the secure operation of the website and protection against unauthorized access.

3.4. Online Tests and Quizzes

The website may provide professional and educational online tests and quizzes.

Purpose of Processing

The purpose of processing is to provide access to online tests and quizzes, display feedback on the user’s knowledge level, show evaluation results, compile statistical summaries, and prevent or detect abuse such as automated submissions or cheating.

Categories of Processed Data

When using tests and quizzes, the following data may be processed:

  • name or nickname provided by the user,
  • exact date and time of completing the test,
  • test result, such as percentage score, achieved points or grade,
  • time spent completing the test,
  • technical data used to detect abuse, such as logs of suspicious activity.

Legal Basis of Processing

The legal basis for this processing is the voluntary consent of the data subject. By starting the test and providing a name or nickname, the user gives consent to the processing of the related data by implied conduct.

Retention Period

The data is stored until deletion is requested by the user or until regular database maintenance is carried out. The user may request deletion of their data at any time by contacting admin @ rapidplugins.dev.

Data Processors and Storage

The data is stored in the website’s own database on the server of the hosting provider. Data related to online tests and quizzes is not transmitted to third parties.

3.5. User Accounts and Avatars

If a visitor is a registered user of the website, the system processes the data necessary for operating the user account.

The website may allow users to upload a profile picture, also known as an avatar. The uploaded image is stored on the server and may appear in public areas of the website, such as next to comments or on a user profile page.

If a registered user uploads an image to the website, it is advisable to avoid uploading image files that contain GPS location data in their EXIF metadata. Visitors may be able to download publicly available images from the website and extract such location data from them.

Access to certain content may be restricted. The system stores the user’s permission level, meaning which content and functions the user may access, as well as technical information related to login.

When a comment is submitted, in addition to the data entered in the comment form, the commenter’s IP address and browser user agent may also be collected in order to filter spam and protect the security of the website.

An anonymized string generated from the e-mail address, commonly referred to as a hash, may be transmitted to the Gravatar service if this function is used on the website. The privacy policy of the Gravatar service is available at: https://automattic.com/privacy/.

After a comment is approved, the content of the comment and the related profile picture may be displayed publicly.

3.6. Statistics and Page Views

The website may record the number of views of posts and pages in order to measure visitor activity.

For technical reasons, such as preventing repeated counting by the same user within a short period, the system may temporarily record the IP address or use a cookie to identify the visit.

These data are not linked to a personal user profile.

3.7. Search and Navigation

When using the live search function on the website, the search terms entered by the visitor are processed in order to display search results.

Searches may be logged for the purpose of improving the service, developing content and better understanding user needs, but they are not linked to identified natural persons.

3.8. Other Technical Plugins

Other convenience and technical plugins may operate on the website. These generally do not collect personal data independently, but support the display, usability or operation of the website, for example by providing code highlighting, sliders, navigation elements, a “back to top” button or similar technical functions.

3.9. Embedded Content from Other Websites

Posts available on the website may include embedded content from external sources, such as videos, images, articles or other elements.

Embedded content from external websites behaves in the same way as if the visitor had directly visited the external website.

These external websites may collect data about visitors, place cookies, use third-party tracking codes, and monitor user interaction with the embedded content, especially if the visitor has a user account with the external service and is logged in there.

3.10. Sharing of User Data

The website transmits personal data to third parties only if this is necessary for the operation of the website, required by law, or based on the consent of the data subject.

The hosting provider may have access to data stored on the server as a data processor in order to provide, maintain and operate the hosting service.

If a user requests a password reset, the IP address may be included in the password reset e-mail.

4. How Long Personal Data Is Retained

If a visitor submits a comment, the comment and its metadata may remain in the system for an indefinite period. The purpose of this is to recognize and approve subsequent comments automatically, instead of placing each one in the moderation queue.

For registered users of the website, personal data is also stored in their user profile. Users may view, edit or delete their personal data at any time, except that they cannot change their username. Website administrators may also view and edit this information.

Security logs and technical event logs are retained for as long as necessary for the secure operation of the website. In the case of a specific security incident, abuse or attack attempt, the relevant log entries may be retained for a longer period if necessary for investigation.

Data related to online tests and quizzes is stored until deletion is requested by the user or until regular database maintenance is carried out.

5. Purposes and Legal Bases of Processing

The main purposes of processing are:

  • operating the website,
  • improving user experience,
  • communication,
  • managing comments and user accounts,
  • providing online tests and quizzes,
  • spam filtering,
  • website protection,
  • security logging,
  • providing two-factor authentication,
  • preventing abuse, attack attempts and unauthorized access.

The legal basis for processing may be:

  • the consent of the data subject, for example when accepting cookies, registering an account or completing an online test,
  • performance of a contract or taking steps at the request of the user, where the use of a website function requires this,
  • the legitimate interest of the Data Controller, especially in relation to website security, spam protection, prevention of attacks, security logging and protection of user accounts,
  • compliance with a legal obligation, where the retention or transmission of certain data is required by law.

6. Rights of the Data Subject

Under the GDPR and applicable Hungarian data protection laws, the data subject has the right to:

  • request information about the processing of their personal data,
  • request access to the personal data being processed,
  • request rectification of their personal data,
  • request deletion of their personal data, also known as the right to be forgotten, unless deletion is excluded by a legal obligation or legitimate interest,
  • request restriction of processing,
  • object to the processing of their personal data,
  • withdraw consent where the processing is based on consent,
  • request the export of personal data in a file if they have a registered account or have submitted comments.

The data subject may also request the deletion of personal data previously provided. This does not apply to data that we are required or justified to retain for administrative, legal or security reasons.

Requests related to data processing may be submitted to admin @ rapidplugins.dev.

7. Right to Lodge a Complaint

If the data subject believes that the processing of their personal data violates applicable data protection laws, they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.

Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
Website: https://www.naih.hu
E-mail: [email protected]

8. Changes to This Privacy Policy

The Data Controller reserves the right to modify this Privacy Policy if changes occur in the operation of the website, the plugins used, the legal environment or the data processing practices.

The current version is always available on the website.