Legal · Effective September 28, 2026 · Last updated September 28, 2026
Terms & Conditions
Terms for the provision of re:Marque
This is an unofficial translation. The Hungarian version is authoritative.
These Terms & Conditions (the “terms”) govern the relationship between the user and the operator of the re:Marque platform named in “Provider details” (the “Provider”) concerning the use of re:Marque. “User” means the natural person using the platform and the organisation on whose behalf that person acts. These terms apply only to this service. The “Acceptable use” and “Third-party websites, Browse mode and the widget” sections are particularly relevant because the service can access websites that do not belong to the Provider and may not belong to the user. Provisions that depart from standard contractual practice appear in separate boxes marked “Highlighted clause” so that the user can review them before creating an account.
1. Provider details
The re:Marque service is provided by the Provider, Galcsik Győző Korlátolt Felelősségű Társaság (registered seat: 1063 Budapest, Szív utca 16. I. em. 17. ajtó, Hungary; registered by Fővárosi Törvényszék Cégbírósága, company registration number: 01-09-389812; tax number: 27431913-2-42; chamber membership: Budapesti Kereskedelmi és Iparkamara; represented by: Galcsik Győző, managing director; email: [email protected]). The service is available at https://remarque.app and the language of the contract is Hungarian.
2. Scope of these terms and formation of the contract
re:Marque is a hosted service for finding, capturing and tracking issues on websites. The user may browse a site in the application or through a widget on the user’s own website and capture an annotated screenshot. The screenshot becomes a ticket on a board managed by the user’s team.
These terms are the entire agreement between the user and the Provider for this service. They apply only to re:Marque; a separate contract between the user and the Provider concerning another matter is outside their scope.
The user accepts these terms when the user's account is created. When accepting an invitation, before setting a password or signing in with the user's Google or Microsoft account, the user must tick a mandatory checkbox with this text: “I have read and accept the Terms & Conditions, including the highlighted clauses on limitation of liability and changes to the terms, and I have read the Privacy Policy.” The full text of both documents can be opened with one click from the checkbox label, so the user can read them before ticking it. An account cannot be created unless the checkbox is ticked. The Provider records the time of acceptance and the version of the terms accepted against the user's account. Continued use of the service constitutes acceptance of the terms then in force, subject to the limits described in “Changes to these terms”. If the user accepts the terms for an organisation, the user confirms that the user is authorised to bind it, and the term “user” also includes that organisation.
re:Marque is intended for business users. The Provider intends the service for companies, sole traders and others acting in the course of their trade, business or profession. Whether the user is a consumer depends not on a declaration but, under Polgári Törvénykönyv 8:1. § (1) bekezdés 3. pontja, on whether the user uses the service for purposes outside the user's trade, independent profession or business. An invited client may also be an individual. If the user is a consumer, the “Consumer provisions” section below also applies to the user, and the user's rights under mandatory law remain unaffected.
How the contract is concluded: a re:Marque account is created through an invitation to a team; the Provider currently creates a team for an organisation that requests one. When accepting the invitation, the user completes the form, can review and correct the information the user entered before submitting it, and ticks the checkbox described above. The contract is concluded when the account is created, which the Provider confirms immediately in the interface. The language of the contract is Hungarian. It is not a written contract for the purposes of Hungarian law, and the Provider does not file it separately; the Provider does, however, record the time of acceptance and the version accepted against the user's account. These terms remain available at this address, can be downloaded and stored, and the Provider keeps every earlier dated version. On request, the Provider will send the user the accepted version. The Provider has not subscribed to any code of conduct.
3. Accounts, teams and roles
The service is organised into teams. A team owns projects; a project holds tickets. What the user can do depends on the role the user holds in a team.
Role | What it can do |
|---|---|
Owner | All team functions: managing members, client access and integrations; creating, archiving and permanently deleting projects |
Member | Full work on the projects they are granted |
Client | Can view assigned projects and submit feedback; access to internal tickets and comments depends on project settings. |
Agent | An AI identity owned by a member — tickets and comments only |
- The user must give accurate registration details and keep them current.
- The user is responsible for all activity through the user's account and for keeping login credentials confidential. The user must notify the Provider without delay if unauthorised access to the account is suspected.
- The user can sign in with a password, or with the user's Google or Microsoft account. Signing in with a provider does not create an account on its own — it only signs the user in to an account that already exists or that the user has been invited to.
- The team owner decides who belongs to the team, what each person may do, and what happens to the team’s content. If the user joined a team someone else owns, they control that content, not the Provider.
- Client and agent accounts never use a seat. Each has its own plan limit, as large as the seat limit.
- The user must be at least 16 to hold an account.
4. Operation in alpha
re:Marque operates in alpha. The service is usable and the Provider uses it daily, but it is still under development. This section sets out what this means for the user.
- Features may change, move or be withdrawn, sometimes at short notice.
- Defects may occur. If a defect causes the user to lose work, the Provider will try to correct it promptly when the user reports it, but cannot promise that this will not happen.
- There is no service level agreement and no uptime guarantee.
- The user is advised to keep a separate copy of any data whose loss would be unacceptable. “Backups and export” describes the available options.
While the service is in alpha and free, the Provider may amend these terms as they apply to business users with effect upon publication under paragraph a) of “Changes to these terms”. The stricter rule set out in “Data processing terms (GDPR Article 28)” applies to that section. The Provider will notify the user at least 30 days before the alpha period ends and standard commercial terms begin. Paragraph b) of “Changes to these terms” applies to consumers even during the alpha period; nothing in this section reduces the rights consumers have under mandatory law.
5. Plans and limits
The service is organised into tiered plans. A plan sets limits on active and archived projects, seats, agents, client accounts, storage and which features are available. The limits applying to the user's team are shown in the user's team settings.
- Seats count owners and members. Agents and client accounts each have a separate limit of the same size.
- When the user reaches a limit the Provider blocks the action that would exceed it. The Provider never deletes anything the user already has in order to enforce a limit.
- If the user moves to a smaller plan while above its limits, existing content is kept — the user simply cannot add more until the user is back within the limit.
6. Fees
The service is currently free; the Provider charges no fee. re:Marque has no payment system: the Provider does not store card details, subscriptions do not renew automatically, and the Provider cannot collect money from the user. The plan used by the user’s team during the alpha period is free of charge.
The following terms apply from the introduction of paid plans. The Provider will notify the user at least 30 days before any of them applies to the user:
- Paid plans will be invoiced in advance for the subscription period. Prices will be quoted net of VAT, added at the statutory rate.
- Invoices will be due within 15 calendar days of issue unless agreed otherwise in writing.
- Late payment carries default interest under the Hungarian Civil Code (Polgári Törvénykönyvről szóló 2013. évi V. törvény 6:155. §), and, in a business-to-business relationship, the flat-rate debt recovery charge under 2016. évi IX. törvény on Flat-Rate Debt Recovery Costs. The Provider may suspend performance until the arrears are paid.
- A subscription will not renew automatically. The Provider will send an offer for the next period at least 30 days before the current one ends, and the subscription continues only if the user accepts it.
- If a renewal goes unpaid the Provider may suspend the account, after a reminder and 15 calendar days’ grace. A suspended account’s data is kept for 30 days, during which payment restores it, and the Provider will warn the user at least 15 days before deleting anything. Non-payment 30 days into suspension ends the contract, and the export window in “Suspension and termination” then starts.
- A price change will take effect only at the user's next renewal, never inside a period the user has already paid for.
The Provider never moves the user from a free plan to a paid plan without the user’s prior consent.
7. The user’s content and the platform’s software
The user retains ownership of the user’s content. Tickets, comments, screenshots, attachments and everything else the user uploads to re:Marque remain the user’s property. The user grants the Provider only the licence needed to host, process, back up and display that content to provide the service. The licence does not extend beyond that purpose or survive closure of the account.
The Provider does not use the user's content to train machine-learning models.
The re:Marque software, its source code, architecture, interface and documentation, as well as the re:Marque name and logo, are the property of the Provider named in “Provider details”; the software is protected by szerzői jogról szóló 1999. évi LXXVI. törvény (Szjt., the Hungarian Copyright Act). Third-party components used in the software under licence remain the property of their respective rights holders and are subject to their own licence terms. Use of the service gives the user a non-exclusive, non-transferable and non-sublicensable right to use the hosted service for as long as the user's account is open. It grants no licence to the software itself or access to its source code.
- The user may not copy, reverse-engineer, modify or make derivative works of the software, except where mandatory law expressly permits it.
- The user may not resell or sublicense the service, or offer it to third parties as the user's own.
- The user may not use the service to create a competing service by copying its interface, operation or data structure.
- The user may export the user's content at any time while the user's account is open.
To the best of the Provider's knowledge, the software does not infringe any third party’s copyright or other intellectual property rights. If a third party brings a substantiated claim against the user in connection with the software, the Provider will cooperate with the user and replace the affected element with a lawful alternative within a reasonable time. The Provider's liability otherwise remains subject to “Limitation of liability”.
The Provider may identify a business user as a customer by name and logo in the Provider's own marketing and will stop on written notice from the user. The Provider uses the user’s projects, tickets, screenshots, comments or other content in the Provider's own marketing or public communications only with separate written consent.
8. Acceptable use
The user must not use re:Marque to:
- Break the law, or infringe anyone’s intellectual property, privacy or other rights.
- Upload malware, or content that is unlawful, defamatory or harmful.
- Attack, overload or probe the service, or attempt to reach another team’s data.
- Circumvent plan limits, or share a single account among people who should each hold their own.
- Upload personal data the user has no lawful basis to process.
The Provider may suspend an account that breaches this section, and where the breach is serious or ongoing the Provider may do so without prior notice.
9. Third-party websites, Browse mode and the widget
Access to third-party websites. re:Marque loads third-party websites through the Provider’s servers and can place a widget on them. The user must be entitled to use this capability.
The user may only browse, capture, instrument or embed the widget on websites that the user owns, or that the user has the owner’s permission to access and test for this purpose. The user is solely responsible for holding that permission and for complying with the terms of any site the user points re:Marque at.
- Browse mode is not a general-purpose proxy or an anonymiser, and must not be used as one.
- When the user signs in to a third-party site inside Browse mode, the user gives the Provider credentials to hold on the user’s behalf. An account limited to the permissions needed to view the problem should be used; the user must not use another person’s credentials.
- The widget draws nothing for ordinary visitors to the user's site and never sends them its interface code; their browser fetches only a small loader and, on a configured environment, one hidden session check that stores nothing. It appears only for signed-in members of the project.
- Screenshots may capture other people’s personal data. The user is the controller of that data and must have a lawful basis for capturing it.
Browse mode renders the third-party page on the Provider's own origin, which makes the annotation overlay possible. The limits of this design are described in the Provider's privacy notice, including the fact that the Provider cannot guarantee complete isolation between sites browsed by one user. Browse mode should therefore be used on trusted sites. The scripts of a page loaded in Browse mode run on the Provider's origin and may set their own cookies or browser storage there, for example for that site’s own analytics. The Provider does not read or use this data; the operator of that website is responsible for it.
The Provider may block a target site, or suspend an account, where the Provider has reason to believe this section is being breached.
10. API access and AI agents
The user may create API keys so that scripts and AI agents can read and modify the user’s data. An agent is an identity created and owned by the user, who is responsible for its actions.
- A key inherits the permissions of the identity it acts as and never exceeds them.
- Everything an agent does is attributed to it and counts as the user's own act.
- The user must keep keys secret and revoke any that are no longer needed or may have leaked. The Provider shows each key once when it is created and store only its hash; the Provider cannot recover it.
- Agents must not be used to circumvent plan limits or to place load on the service beyond ordinary use.
11. Availability and maintenance
The Provider aims to keep the service continuously available, but the Provider does not guarantee 100% availability and the Provider offers no service level agreement unless one is separately agreed in writing.
- The Provider runs on third-party cloud infrastructure. The user has no direct contractual relationship with those providers.
- The Provider gives advance notice of planned maintenance where the Provider reasonably can.
- The Provider is not liable for interruptions outside the Provider's control, including failures at an infrastructure provider, denial-of-service attacks, network outages or natural disasters. The exclusion for failures at an infrastructure provider applies only to businesses; if the user is a consumer, the Provider is liable for a provider the Provider engages as if the Provider had acted itself.
12. Backups and export
The Provider keeps backups of the production database as part of operating the service. They are a disaster-recovery measure for the Provider, not a file-recovery service for the user, and they do not replace the user's own copies of anything the user cannot afford to lose.
The user can export a complete copy of any project at any time from the project menu — tickets as JSON and Markdown, plus all media. Regular export is advisable.
If data is lost the Provider will try to restore from the most recent valid backup, but the Provider cannot guarantee complete recovery.
13. Support
Support is by email at [email protected] during Hungarian business hours, and the Provider aims to answer within two business days. Support covers using the service and faults in it. It does not cover work on the user's own website, content production, or development of the user's projects.
14. Data protection
How the Provider handles personal data is set out in the Provider's privacy notice. For content uploaded to the service, the Provider acts as a processor under GDPR Article 28; the applicable provisions are in the “Data processing terms (GDPR Article 28)” section below, which forms part of these terms and constitutes a data processing agreement. The Provider does not enter into individually negotiated data processing agreements.
15. Data processing terms (GDPR Article 28)
When the Provider acts as the user’s processor, the following terms apply. They form part of these terms and constitute a data processing agreement under GDPR Article 28(3). The controller is the organisation on whose behalf the team owner uses the account; if the user uses the service on the user’s own behalf, the user is the controller. In this section, “the user” means that controller.
How this section may change. This section may be amended with the rest of these terms under “Changes to these terms”, subject to two exceptions that apply even during the alpha period. First, the Provider will make an amendment that reduces the level of protection of personal data promised here, particularly one affecting security measures, incident notification, rules for engaging sub-processors, the Provider's duties to assist, or the Provider's undertakings to return and delete data, only after giving at least 30 days’ notice by email before it takes effect. If the user objects in writing before such an amendment takes effect, it will not apply to the user, and either party may terminate the contract on its effective date; the termination provision below then governs the data. Second, amendments that increase protection or implement changes in law or regulatory requirements take effect on publication. The Provider records the version accepted by the user against the account and sends it on request.
- Subject matter and duration: providing re:Marque, for as long as the user's account is open.
- Nature and purpose: storing and displaying the issue-tracking content the user's team creates.
- Categories of data subjects: the user's staff, the user's clients, and any individuals whose personal data appears in the pages the user captures. Types of personal data: names, email addresses, usernames, avatars, any data in tickets, comments, screenshots and attachments, and cookies stored on the user's behalf in Browse mode. The service is not intended to process special categories of personal data; if such data appears on a page the user captures, the user is responsible for the legal basis for processing it.
- The Provider processes personal data only on the user's documented instructions, which the user's use of the service constitutes — unless Union or Member State law requires otherwise, in which case the Provider tells the user before processing, where that law allows the Provider to.
- The Provider informs the user without undue delay if, in the Provider's view, an instruction from the user infringes the GDPR or other data protection law.
- Everyone with access is bound by confidentiality.
- The Provider applies the technical and organisational measures described in the “Data security” section of the privacy notice, proportionate to the risks and reasonably available, in accordance with GDPR Article 32. The Provider does not guarantee any particular security outcome, especially complete protection against every attack.
- The Provider engages sub-processors under the general written authorisation the user gives by accepting these terms: only the providers listed in the “Annex: sub-processors” section. The Provider notifies the user by email at least 30 days before a planned change takes effect, whether the change is the engagement of a new sub-processor, activation of a previously announced provider or replacement of an existing one, and gives the user an opportunity to object. A provider announced in the annex does not process personal data until activated. If the user objects on reasonable data protection grounds and the Provider cannot offer an alternative, the user may terminate the affected subscription; the Provider refunds prepaid fees for the unused period pro rata. Sub-processors are subject to data protection obligations at least equivalent to those undertaken here, and the Provider is responsible for their activities.
- Taking account of the nature of the processing, the Provider assists the user, at the user's reasonable and substantiated request, with data subject requests, breach notifications and impact assessments. If this requires substantial extra work beyond the normal operation of the service, the Provider may ask the user to reimburse the Provider's costs.
- The Provider notifies the user of a personal data breach without undue delay, and in any event no later than 72 hours after becoming aware of it, and provide the information available to the Provider that the user needs to meet the user's own notification obligations.
- On termination, the Provider deletes or return the user's data at the user's choice, subject to the export window in “Suspension and termination”, unless Union or Member State law requires the Provider to store it.
- The Provider demonstrates compliance through the Provider's documentation and written responses, and make available the information necessary to demonstrate fulfilment of the obligations laid down in GDPR Article 28. An on-site or systems audit may take place only where a supervisory authority or law requires it, or where the documentation is demonstrably insufficient: no more than once a year, on at least 30 days’ prior written notice, during business hours, without undue disruption to operations, and at the requesting party’s expense.
- The Provider primarily uses data centres within the European Union. The Provider transfers data to a third country only with safeguards under GDPR Chapter V, as described in the “Recipients and international transfers” section of the privacy notice and the “Annex: sub-processors” section.
- These terms are governed by the GDPR and Hungarian law, in particular the Infotv. Matters not covered here are governed by the other provisions of these Terms & Conditions; where they conflict on data protection matters, this section prevails.
16. Suspension and termination
The user may request closure of the user's account at any time at the email address given in “Contact”; the Provider will fulfil the request without undue delay, no later than 15 days after receiving it, and confirm the closure to the user. The team owner and members may also permanently delete projects and all their contents themselves at any time in the project settings. On a free plan, closure takes effect immediately. On a paid plan, it takes effect at the end of the paid period, and fees for the unused part are not refunded except where mandatory consumer law requires it or where the user terminates because of a materially adverse amendment or an amendment to the data processing terms to which the user has objected.
Either party may terminate immediately for material breach that the other has not remedied within 15 days of being asked to. The Provider may suspend or terminate immediately for a serious breach of “Acceptable use” or “Third-party websites, Browse mode and the widget”.
After termination the user may request an export of the user's data for 15 days. After that the Provider deletes it in line with the retention periods in the Provider's privacy notice.
17. Warranties and disclaimers
The Provider provides the service with reasonable skill and care, and the Provider will deal with defects reported to the Provider within a reasonable time. Beyond that, and to the extent the law permits, the service is provided as-is: the Provider does not warrant that it will be uninterrupted or error-free, or that it will find every defect on a website the user tests with it.
Nothing here limits any statutory warranty that cannot be excluded, including the conformity rights a consumer has for digital services.
18. Limitation of liability
Highlighted clause: limitation of liability. If the Provider performs defectively, the user is primarily entitled to rectification: the Provider will correct a defect in the service the Provider expressly undertook to provide at the Provider's own expense and within a reasonable time. Beyond that, as against a business user and to the extent Hungarian law permits, the Provider's total liability arising out of or in connection with the service is limited to the net fees the user paid the Provider in the 12 months before the event giving rise to the claim, or EUR 100, whichever is higher. The minimum amount applies when the service is free and the user has paid no fees. This liability cap does not apply to a consumer; the consumer paragraph below and “Consumer provisions” govern the Provider's liability to consumers. The user expressly accepts this provision by ticking the checkbox when creating the user's account.
As against a business user, the Provider is not liable for:
- Content supplied by the user or the user's team, and its lawfulness.
- Loss caused by third-party services, including infrastructure providers, domains and external APIs.
- The user's use of Browse mode or the widget on a site the user was not entitled to access.
- Defects caused by the user's or a third party’s intervention, or by use of the service contrary to its intended purpose.
- Breach of contract caused by a circumstance outside the Provider's control that was unforeseeable when the contract was concluded (force majeure), if the Provider could not reasonably have been expected to avoid the circumstance or prevent the damage.
- Lost economic benefit, indirect or consequential loss, including lost profit, business interruption and loss of data, beyond what is stated above.
The liability cap and exclusion list above, including the exclusions of lost economic benefit and indirect and consequential loss, do not apply to a consumer. The Provider's liability to a consumer is governed by the Polgári Törvénykönyv: for defective performance, the consumer is primarily entitled to rectification; the Provider is released from liability if the Provider proves that the breach was caused by a circumstance outside the Provider's control that was unforeseeable when the contract was concluded and that the Provider could not reasonably have been expected to avoid or to prevent the damage (6:142. §); for loss beyond damage to the subject matter of the service, including lost economic benefit, the Provider compensates the consumer to the extent that the loss was foreseeable as a possible consequence of the breach when the contract was concluded (6:143. §); and the Provider is liable for a contributor it engages, including an infrastructure provider, as if the Provider had acted itself (6:148. §).
Nothing in these terms excludes or limits liability that cannot lawfully be excluded. Under Polgári Törvénykönyv 6:152. §, the Provider does not limit liability for breach of contract caused intentionally or resulting in harm to human life, bodily integrity or health; claims that consumers have under mandatory law are likewise unaffected.
The user indemnifies the Provider against third-party claims arising from the user's content, or from the user's use of the service in breach of “Acceptable use” or “Third-party websites, Browse mode and the widget”. This does not apply to consumers.
19. Confidentiality
Each party keeps the other’s business secrets confidential. The Provider uses the user's data, content and business information only to run the service, and disclose it to no one except the sub-processors listed in “Annex: sub-processors”, recipients the user directs the Provider to send it to, including a GitHub repository the user connects for issue, branch and pull-request synchronisation or a BugHerd project the user connect, or where the law requires. GitHub and BugHerd are customer-directed integrations under the user's own agreements with those providers, as described in the privacy notice section “Recipients and international transfers”. The naming right in “The user’s content and the platform’s software” is the only exception, and the user can switch it off. The duty of confidentiality survives termination of the contract without any time limit. It does not apply where disclosure is required by law, a court or an authority; in that case, the Provider notifies the other party before disclosure if the law permits.
When the GitHub mirror is enabled, an issue the Provider creates in the user's repository serves its screenshot and attachments from a view-only public link created for that ticket. Anyone who obtains the link can open the ticket without signing in, including its description, screenshot, attachments and comments that are not internal. The privacy notice section “Recipients and international transfers” provides details. If this is unacceptable for a project, the mirror must remain off.
With comment synchronisation on, every comment on a mirrored ticket is copied to the issue, including comments written by people who have no account with the Provider. Someone the user hands a share link to, and a BugHerd commenter who matched nobody on the user's team, both reach the user's repository the same way a team member does. The Provider attributes each of them by the display name they gave and never by their email address, and where the only name the Provider holds is an email address the Provider publishes no name at all. The user is responsible for telling people with whom the user shares a ticket that their replies may be copied to a repository, because the user chooses the destination. If this is unacceptable for a project, comment synchronisation or the mirror must be turned off.
An internal ticket or note is hidden from that project’s clients inside re:Marque unless project settings allow their access to internal content. It is not a rule about GitHub. Internal tickets and notes stay out of the user's repository unless the user switches on “Sync internal tickets” for that project, which is off by default; once it is on, everyone who can see the repository can read them, and the issues of a public repository can be indexed by search engines. An internal ticket’s issue is then a full issue like any other: it carries the screenshot and the attachments, through the same view-only link that needs no sign-in. The Provider warns the user in the settings when the repository is public or its visibility is unknown, but the choice of destination, and the consequences of it, are the user's.
20. Consumer provisions
Most of the Provider's customers are businesses, but an invited user may also be an individual. If the user uses the service for purposes outside the user's trade, independent profession or business, the user is a consumer under Polgári Törvénykönyv 8:1. § (1) bekezdés 3. pontja, and the following provisions apply in addition to those above. In the event of a conflict, this section and mandatory consumer protection law, including the rules on unfair terms in consumer contracts in Polgári Törvénykönyv 6:104. §, prevail over the other provisions of these terms. The liability cap and exclusion list for businesses in “Limitation of liability”, including the exclusions of lost economic benefit and indirect and consequential loss, do not apply to a consumer. The Provider is liable to a consumer under the Polgári Törvénykönyv: for defective performance, the Provider first provides rectification; the Provider is released from liability only for a circumstance outside its control that was unforeseeable when the contract was concluded and could not be avoided or prevented (6:142. §); the Provider compensates loss beyond damage to the subject matter of the service and lost economic benefit to the extent foreseeable when the contract was concluded (6:143. §); the Provider is liable for a contributor it engages as if the Provider had acted itself (6:148. §); and the Provider does not limit liability for an intentional breach or a breach causing harm to human life, bodily integrity or health (6:152. §). Even during the alpha period, the Provider amends these terms as they apply to consumers only under paragraph b) of “Changes to these terms”: for the reasons listed there, with at least 15 days' prior notice by email. Neither the consumer's silence nor continued use of the service constitutes acceptance of an amendment.
- The service is currently free, so the right of withdrawal has no application at present. If the user takes out a paid subscription in the future, under 45/2014. (II. 26.) Korm. rendelet the user may withdraw from it as a distance contract without giving a reason within 14 days of concluding the contract. If the user asks the Provider to start the service within that period, the user must pay a proportionate amount for the service received before withdrawal. To withdraw, a clear statement sent to the email address in “Provider details” is sufficient.
- Defective performance: while the service is free, the Provider processes account data and technical logs solely to provide and secure the service, including compliance with the Provider's obligation under GDPR Article 32, and for no other purpose. Accordingly, the contract is outside the scope of 373/2021. (VI. 30.) Korm. rendelet on the detailed rules for contracts between consumers and businesses concerning the sale of goods and the supply of digital content and digital services (1. § (3) bekezdés), while the statutory warranty rules of the Polgári Törvénykönyv apply to contracts for consideration. The user nevertheless has the right to the defect correction the Provider undertakes in “Warranties and disclaimers”. If the user pays for the service in the future, the user will have the statutory warranty rights under the Polgári Törvénykönyv and 373/2021. (VI. 30.) Korm. rendelet: the user may request rectification; if that is impossible or the Provider does not undertake it, the user may seek a proportionate price reduction and, ultimately, withdraw from the contract.
The user may submit a complaint to [email protected]; the Provider will respond to the substance of a written complaint within 30 days. If the Provider cannot resolve it between the parties, the user may turn to a conciliation board (békéltető testület): the Budapesti Békéltető Testület competent for the Provider's registered seat (1016 Budapest, Krisztina krt. 99. I. em. 111.; mailing address: 1253 Budapest, Pf. 10.; telephone: +36 1 488 2131; [email protected]) or the board competent for the user's domicile or place of residence. The Provider is obliged to cooperate in its proceedings. The user may also initiate proceedings before the consumer protection authority (the government office competent for the user's domicile) or a court.
21. Changes to these terms
The Provider may amend these terms where a change in law or regulatory practice warrants it; where the Provider changes, adds or withdraws a feature; where necessary for security or to prevent abuse; where the cost of providing the service changes; or where a provision needs clarification or correction. The procedure and notice period depend on whether the user is a business or a consumer and whether the service is free or paid, as set out in paragraphs a), b) and c) below. Amendments to “Data processing terms (GDPR Article 28)” are also subject in every case to the stricter rule in that section.
Highlighted clause: a) amendments for businesses during the alpha period. While the service is in alpha and free, the Provider may amend these terms as they apply to business users at any time, and an amendment takes effect when published at this address. The exception is “Data processing terms (GDPR Article 28)”: the Provider may reduce the level of protection in that section only after giving at least 30 days' prior notice as described there. The Provider will notify account holders by email or in the app where reasonably possible; the Provider publishes every version with an effective date and version number. If the user does not accept an amendment, the user may stop using the service and request closure of the user's account; continued use of the service constitutes acceptance of the amended terms. The user expressly accepts this provision by ticking the checkbox when creating the user's account.
b) Amendments for consumers at all times. As against a consumer, including during the alpha period, the Provider amends these terms only for the reasons listed above. The Provider notifies the consumer by email at least 15 days before the amendment takes effect and states what is changing. Neither the consumer's silence nor continued use of the service constitutes acceptance of the amendment. If the consumer does not accept it, the consumer may terminate the contract free of charge before it takes effect; the Provider then closes the consumer's account.
c) Amendments during paid periods. From the introduction of paid plans, the Provider amends these terms as they apply to all users only for the reasons listed above. The Provider notifies account holders by email at least 30 calendar days before an amendment takes effect and states what is changing; the consumer's notice period then increases from 15 to 30 days. An amendment does not apply retroactively to a period already paid for. If the user does not accept an amendment, the user may terminate the contract before it takes effect. Continued use afterwards by a business user constitutes acceptance; under paragraph b), continued use by a consumer does not. An amendment materially adverse to the user takes effect for the user's team only at the start of the next paid period. If the user terminates because of such an amendment, the Provider refunds the fees for the unused part of the period already paid for, pro rata.
This section does not affect a consumer’s rights under mandatory law. Each version is published at this address with its effective date, in a form the user can download and store. The Provider sends a copy of the version accepted by the user on request.
22. Governing law and disputes
These terms are governed by Hungarian law, in particular the Civil Code (Polgári Törvénykönyvről szóló 2013. évi V. törvény), the Copyright Act (szerzői jogról szóló 1999. évi LXXVI. törvény) and the Act on Electronic Commerce Services (elektronikus kereskedelmi szolgáltatásokról szóló 2001. évi CVIII. törvény). In consumer relationships, the Consumer Protection Act (fogyasztóvédelemről szóló 1997. évi CLV. törvény) and 45/2014. (II. 26.) Korm. rendelet also apply. The Provider excludes the application of private international law conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods.
The parties seek to settle disputes primarily through negotiation. If negotiations do not resolve a dispute, the Hungarian court with jurisdiction and competence shall hear it.
If the user is a consumer, this does not deprive the user of the protection of mandatory provisions of the law of the user's country of residence, nor of the user's right to bring proceedings before the user's local courts.
If any provision of these terms is held invalid, the rest remains in force and the invalid provision is replaced by the lawful term closest to its intended effect.
The parties communicate primarily by email and accept statements made by email as written communications. The Provider may use contributors to provide the service, including the sub-processors named in “Annex: sub-processors”; as regards consumers, the Provider is liable for those contributors as if the Provider had acted itself, while “Limitation of liability” applies as regards businesses.
23. Contact
Questions about these terms may be sent to [email protected], or by post to the Provider at the registered seat given in “Provider details”.
24. Annex: sub-processors
This annex has two parts. The first lists the sub-processors the Provider currently engages to deliver the service. The second lists providers announced in advance that the Provider may engage in the future; they process no personal data until activated. Each entry states the purpose for which the Provider engages or would engage that provider; not every provider processes data for every account. No provider processes personal data on the Provider's behalf without a data processing agreement under GDPR Article 28. This list is current as of the date at the top of the page.
Sub-processors currently engaged. The Provider currently engages the following sub-processors to deliver the service:
- Railway Corp. (United States), the service’s hosting provider under 2001. évi CVIII. törvény 4. § on electronic commerce services. Registered address: 2093 Philadelphia Pike #1330, Claymont, DE 19703, Egyesült Államok; email: [email protected]. Purpose: application hosting and managed PostgreSQL database. Data processed: all service data. Location: servers in the European Union (Netherlands). Safeguard: Standard Contractual Clauses forming part of Railway’s data processing agreement.
- Cloudflare, Inc. (United States). Purpose: DNS, CDN and DDoS protection and object storage for uploaded files (R2). Data processed: traffic metadata, IP addresses and all uploaded files, including screenshots and attachments. Location: EU edge processing; file storage in the European Union (Western Europe). Safeguard: certification under the EU-US Data Privacy Framework and Standard Contractual Clauses.
- Resend (Plus Five Five, Inc., United States). Purpose: sending notification and digest emails. Data processed: recipient name and email address and notification content. Location: United States. Safeguard: certification under the EU-US Data Privacy Framework; its data processing agreement also includes Standard Contractual Clauses.
Sub-processors announced in advance. The Provider does not currently engage the following providers; listing them gives advance notice under GDPR Article 28(2). A provider announced in advance does not process personal data until the Provider activates its engagement. The Provider notifies account holders of activation by email at least 30 days before engagement, through the usual channel under “Data processing terms (GDPR Article 28)”. The user has the same right to object and terminate as when a new sub-processor is engaged. Until activation, the provider is not listed among the recipients in the privacy notice.
- Hetzner Online GmbH (Germany). Purpose: cloud servers, hosting and backups. Data processed: all service data if a system or backup instance runs there. Location: data centres in the European Union. Safeguard: no transfer to a third country; EU data processing agreement.
- Vercel Inc. (United States). Purpose: hosting and edge delivery of web interfaces. Data processed: traffic metadata and IP addresses for the interface served there, and data processed by any application component running there. Location: United States, with EU edge processing. Safeguard: certification under the EU-US Data Privacy Framework (verified on 2026 September 25) and Standard Contractual Clauses.
- Twilio Inc. (SendGrid, United States). Purpose: delivery of transactional emails. Data processed: recipient name and email address, and message content. Location: United States. Safeguard: Standard Contractual Clauses.
- Amazon Web Services (Amazon Web Services EMEA SARL, Luxembourg; Amazon Web Services, Inc., United States). Purpose: cloud infrastructure and hosting. Data processed: all service data if a system or storage instance runs there. Location: the region the Provider configures, primarily in the European Union. Safeguard: Standard Contractual Clauses.
- Google Cloud Platform (Google Cloud EMEA Ltd, Ireland; Google LLC, United States). Purpose: cloud infrastructure. Data processed: data processed by any system component running there. Location: European Union and United States. Safeguard: Standard Contractual Clauses.
- OpenAI (OpenAI Ireland Ltd, Ireland, for EEA customers; OpenAI OpCo, LLC, United States). Purpose: artificial intelligence features. Data processed: content the user submits to such a feature. Location: United States. Safeguard: Standard Contractual Clauses; OpenAI does not appear on the official EU-US Data Privacy Framework list (verified on 2026 September 8).
- Anthropic (Anthropic Ireland, Limited, Ireland, for EEA customers where applicable; Anthropic PBC, United States). Purpose: artificial intelligence features. Data processed: content the user submits to such a feature. Location: United States. Safeguard: Standard Contractual Clauses.
Processor for the Provider's own correspondence. Google Workspace (Google Ireland Ltd, Ireland; Google LLC, United States) hosts the [email protected] mailbox. In this capacity, Google is the Provider's processor, with the Provider acting as controller, for its own legal, privacy and customer support correspondence, including the content, sender and recipient of emails sent to and by the Provider. Google is not a sub-processor of content the user uploads to the service and has no access to tickets, comments, screenshots or attachments stored in the service. Location: European Union and United States. Safeguard: Standard Contractual Clauses. This processing is covered by the privacy notice.
Google and Microsoft are not sub-processors when acting as sign-in providers. If the user signs in with a Google or Microsoft account, the provider the user chose (Google LLC or Google Ireland Ltd; Microsoft Corporation or Microsoft Ireland Operations Ltd, respectively) acts as an independent controller, as described in “Accounts, teams and roles” and “Data processed, purposes, legal bases and retention periods” in the privacy notice. GitHub and BugHerd are not sub-processors either: they receive data only if the user connects them, and then act as recipients chosen by the user and on the user’s instructions, as described in “Confidentiality” and “Recipients and international transfers” in the privacy notice.
This list may change. Before engaging a new sub-processor, activating a provider announced in advance or replacing an existing sub-processor, the Provider notifies the user under “Data processing terms (GDPR Article 28)” by email at least 30 days in advance; the user may object. The Provider is responsible for the sub-processors' activities.