Üdvözlöm! Rutilo vagyok, a Zenit Programs AI-asszisztense. A honlap jóváhagyott oldalai és a központi Rutilo-adatbázis publikált tudása között keresek, és minden válaszhoz forrást is mutatok.
Zenit Programs data processing
Privacy Notice
Information about data processing related to the website, user accounts, communication and WeldExp Modules.
1. Data controller
- Name: Vidák Zoltán János
- Email: info@zenitprograms.hu, vidak.zoltan@gmail.com
- Registered location: Szeged, Hungary
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
2. Scope of this notice
This notice applies to the WordPress-independent Zenit Programs website, its own user-account system and contact facilities, and to data processing by the WeldExp Modules web application available from the website.
3. What data is processed and for what purpose?
User accounts and registration
The username, email address, display name and secure password hash provided during registration are stored to create the account, provide protected services, support login and manage account security. The original password text is not stored.
Acceptance of the privacy notice is a condition of registration. The registration button remains unavailable until acceptance is selected and all mandatory fields are valid. The fact of acceptance is not stored in a separate database field.
A new normal account is created with the USER role and pending status. The confirmation link sent by email verifies control of the email address, records the verification time, clears the confirmation token and enables login. The account becomes active on the first successful login, when the last-login time is updated and the activation deadline is cleared. The password hash created during registration remains unchanged, so no new password has to be chosen during confirmation.
Required identifiers and role information for retained accounts from the former WordPress system were migrated to the site's own Felhasznalok table. Legacy WordPress sessions, activation keys and unnecessary user metadata were not migrated.
Account confirmation and password reset
Single-use, expiring tokens are generated for confirmation and password-reset links. Only the token hash and expiry are stored in the database. The raw token is part of the emailed link and may temporarily exist in the access-protected file-based mail queue until successful delivery or expiry of the mail job. The URL containing the token may also appear in hosting or web-server access logs; token pages use Referrer-Policy: no-referrer to reduce the risk of the link being forwarded to another website. On successful use, the stored token hash and expiry are deleted. An expired token cannot be used, but an unused token hash and its expiry may remain in the database until a later login, a new confirmation or password-reset request, or deletion of the account.
Newsletter
Newsletter subscription is optional, separate from registration and disabled by default. The choice is stored as the account's newsletter setting with value 1 or 0; the time at which it was enabled is not recorded.
Consent can be withdrawn at any time by emailing info@zenitprograms.hu. Withdrawal does not affect the lawfulness of earlier processing.
Contact form
The contact form sends the name, email address, selected topic and message text to Zenit Programs by email. The website does not store these data in its own database. They may be used to answer the enquiry, provide requested trial access, handle a bug report or discuss cooperation.
WeldExp Modules – temporary browser-side work buffer
Some WeldExp Modules may use a local work buffer in the user's browser for unfinished workflows, drafts, temporary calculation data and user-interface state.
Browser-side storage mechanisms may include localStorage, sessionStorage, IndexedDB, as well as technically necessary cookies or browser-side identifiers. Data handled this way remains on the relevant device and browser profile and is not, by itself, automatically uploaded to Zenit Programs servers or databases.
The browser-side work buffer and server-side data storage are separate. Data stored in the browser can be transferred to a server-side database only when the user explicitly initiates a server-side save, ClientDB save, data upload or similar operation.
Document drafts related to ClientDB may be stored in encrypted or partly encrypted form in the browser's local storage. The system uses an internal namespace linked to the user and the current ClientDB session so that drafts belonging to different users or ClientDB databases used in the same browser profile do not become mixed.
Local data can be deleted through browser settings, through the application's corresponding functions, or by clearing browser data.
WeldExp Modules – server-side ClientDB processing
If a user connects a ClientDB database and performs a server-side save, data belonging to a document, project, register or module workflow may be stored in the connected database.
Depending on the module used, the processed data may include WPS/WPQR document data, test or measurement data, employee, welder or inspector records, equipment or inventory data, as well as technical, production, quality-assurance, calculation and documentation data.
Data stored in ClientDB is the result of a save initiated by the user and is separate from the browser-side local work buffer.
Demo ClientDB
Demo ClientDB and other shared test databases are intended only for trial, demonstration and testing. Uploaded data may be accessible to other test users or development/operations processes and may be changed or deleted.
Technical data and server logs
Hosting and web servers may process operational log data such as IP address, time, requested URL and browser identifier for security, troubleshooting and operation. Registration, login, password reset and forms are protected by CSRF protection, attempt limiting and other technical security measures.
Cookies and browser-side storage
The site's user system uses a technically necessary session cookie named zenit_site to maintain login state. It is HttpOnly, Secure over HTTPS and receives SameSite=Lax on supported PHP versions.
- Normal login: the
zenit_sitecookie is a browser-session cookie without a fixed expiry and is normally removed when the browser closes. Authenticated state lasts 12 hours by default and, depending on settings, no longer than 7 days. - “Keep me signed in”: the persistent login cookie and authenticated state last 30 days by default and, depending on settings, no longer than 90 days.
- Logout: the server-side session and persistent cookie are deleted.
Usernames, email addresses and passwords are not stored in browser localStorage or sessionStorage. The website currently does not use its own marketing tracking, advertising profiling or analytics data collection.
Users may delete or restrict cookies and local storage in browser settings. Disabling the strictly necessary session cookie prevents login and may prevent some forms from functioning.
Local convenience settings and consent
The website uses optional local storage only after the user's consent. zenit:theme stores the appearance mode, zenit:locale the active language, zenit:weldexp:table-state the WeldExp Table Viewer state, and zenit:weldexp:query-state the Query Tables search, filtering, sorting, pagination and selection state. Stored selections may contain stable technical key values and URL parameters; these keys do not store translated labels, passwords, session identifiers, authentication tokens or password-reset tokens.
The selected consent state is stored under zenit:storage-consent for 6 months. Choosing “Necessary only” removes the optional Zenit local settings and prevents them from being stored again. The decision can be changed at any time through “Privacy settings” in the footer; clearing browser site data removes both the decision and the local settings.
Embedded and external content
External videos, images or other embedded content may behave as if the visitor had opened the external provider directly. Such providers may set their own cookies, collect data and apply their own privacy terms.
4. Legal basis for processing
- User account and application access: performance of the service requested by the user or steps prior to entering a contract – GDPR Article 6(1)(b).
- System security, logging and abuse prevention: legitimate interest in secure operation – GDPR Article 6(1)(f).
- Newsletter: voluntary consent – GDPR Article 6(1)(a).
- Contact: depending on the enquiry, pre-contractual steps or legitimate interest in responding.
- Legal obligations: where applicable, GDPR Article 6(1)(c).
5. Data transfers and processors
Personal data may be disclosed to a third party only with appropriate consent, on the basis of a legal obligation, or to the extent necessary for hosting, email and technical service providers to operate the service.
Hosting, email and technical service providers used to operate the website and related services may act as processors and may handle data only to the extent necessary to provide the service.
6. Transfers to third countries
Zenit Programs does not directly transfer personal data outside the European Union. External embedded content or services may nevertheless result in such transfers according to the provider's own processing practices.
7. Retention periods
- Unconfirmed normal account created on the website: one hour from registration.
- Migrated, not-yet-activated normal WordPress account: one year from the original WordPress registration date.
- Active normal account: until one year of inactivity from the last successful login or fulfilment of a deletion request.
- ADMIN and DEVAD accounts: no automatic expiry; retained while authorization remains or until the account is deleted.
- Confirmation/password-reset tokens: unusable after expiry and deleted from the database immediately after successful use; unused expired hashes may remain until a later login, a new token request or account deletion. Raw tokens may remain in the protected mail queue until successful delivery or job expiry and in server logs for their operational retention period.
- Newsletter setting: until withdrawal or account deletion.
- Contact email: up to one year unless law or an ongoing matter requires longer retention.
- Browser work buffer: until deleted by the user or application, browser data is cleared or the session ends.
- ClientDB data: until the user's deletion or modification operation, or termination of the service or access.
- Server logs: for the period necessary for security and operations according to hosting-provider settings.
8. Data-subject rights
Under the GDPR, a data subject may:
- request information about and access to personal data being processed;
- request rectification of inaccurate data;
- request erasure of data or restriction of processing;
- request provision of data in a portable format;
- object to processing based on legitimate interest;
- withdraw newsletter consent at any time.
Requests can be submitted to info@zenitprograms.hu. Whether a request can be fulfilled and whether mandatory retention applies depend on the circumstances of the specific case.
Complaints about unlawful processing may be submitted to the Hungarian National Authority for Data Protection and Freedom of Information:
- Website: https://naih.hu
- Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Email: ugyfelszolgalat@naih.hu
9. Data security
Personal data is protected in password-protected systems, private email accounts and hosting environments. User passwords are stored as secure hashes and short-lived confirmation/reset tokens only as hashes in the database. The temporary raw-token mail copy is kept in an access-protected file, and token pages use no-referrer to limit forwarding of the link.
ClientDB data is protected through hosting-, database- and application-level access controls, password authentication and permissions. Users are responsible for applying appropriate security measures to their own devices, browsers and credentials.
10. Automated decision-making and profiling
No automated decision-making or profiling is performed.
11. Handling data-protection incidents
In the event of a data-protection incident, the event will be investigated, necessary security measures taken and authorities or affected persons notified where required by law.
12. Updates to this notice
When processing activities or services change, the updated notice will be published on this page.
Last updated: 18 September 2026.