How Toko collects, uses, and protects your personal data — in accordance with GDPR and Hungarian law.
| Item | Details |
|---|---|
| Name of Data Controller | Báti Áron Gergely EV |
| Registered seat | 1125 Budapest, Kútvölgyi út 7 |
| Registration number | 60739939 |
| Tax number | 91265610-1-43 |
| Email (data protection matters) | info@aivenue.solutions |
| Website | https://mytoko.hu |
Data processing is carried out in accordance with the GDPR and the Hungarian Privacy Act (Infotv.), following the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and accountability. Accounting documents are governed by Act C of 2000 on Accounting, and payments are governed by tax legislation.
| Data processed | Legal basis | Retention |
|---|---|---|
| Email address, password (encrypted), username, social media handles | Performance of contract – Art. 6(1)(b) | For the duration of the account, then until deletion |
| Data processed | Legal basis | Retention |
|---|---|---|
| Follower count provided, social media profile data, the result of pre-screening, and the fact and outcome of the manual review | Pre-contractual step – Art. 6(1)(b); legitimate interest in the exclusivity of the Platform and fraud prevention – Art. 6(1)(f) | If approved, together with the account; if rejected, for 12 months (for legal claims and to handle repeat applications) |
Note on profiling: pre-screening is carried out using automated tools, but the final decision on acceptance is always made by a human (a member of the Service Provider's staff). Accordingly, this does not constitute solely automated decision-making producing a significant effect on the data subject within the meaning of Article 22 GDPR. See Section 9.
| Data processed | Legal basis | Retention |
|---|---|---|
| Bio text, avatar, products placed on the storefront, layout | Performance of contract – Art. 6(1)(b) | For the duration of the account |
| Data processed | Legal basis | Retention |
|---|---|---|
| Wise beneficiary details, bank account number, billing data, tax number, payment history | Performance of contract – Art. 6(1)(b); accounting and tax law obligation – Art. 6(1)(c) | Accounting documents for 8 years from issuance (Section 169 of the Accounting Act) |
| Data processed | Legal basis | Retention |
|---|---|---|
| Timestamp, pseudonymized IP address (SHA-256 + static salt), browser identifier (user agent), referrer, and the relevant creator_id and product_id | Legitimate interest in attribution (correct settlement of commission) and fraud prevention – Art. 6(1)(f) | 12–24 months, then deleted after aggregation |
Data security note: the Platform does not store the IP address in raw form; it records only its SHA-256 hash generated with a static salt, so it cannot be directly reversed. This is a data-minimization and security measure.
| Data processed | Legal basis | Retention |
|---|---|---|
| Data from strictly necessary cookies; analytics/performance data subject to consent | Strictly necessary cookies: legitimate interest – Art. 6(1)(f); analytics/functional cookies: consent – Art. 6(1)(a) | As set out in the Cookie Notice |
Details are provided in the separate Cookie Notice.
| Data processed | Legal basis | Retention |
|---|---|---|
| Email address, and the subject and delivery status of notifications (e.g. welcome email, approval, payment notice) | Performance of contract – Art. 6(1)(b). Separate consent for marketing newsletters – Art. 6(1)(a) | For the duration of the account; for newsletters, until consent is withdrawn |
| Data processed | Legal basis | Retention |
|---|---|---|
| Click and conversion patterns, ratios, geographic indicators, log of events suspected of fraud (webhook_log) | Legitimate interest of the Service Provider and the Affiliate Networks in preventing abuse – Art. 6(1)(f) | 12 months, or until the conclusion of an investigation, if any |
| Data processed | Legal basis | Retention |
|---|---|---|
| Content of the complaint, contact details, documentation of the investigation | Legal obligation (consumer complaints) – Art. 6(1)(c); and legitimate interest in pursuing legal claims – Art. 6(1)(f) | Consumer protection complaints for 5 years (Consumer Protection Act); otherwise until the limitation period expires |
For data processing, the Service Provider uses the following data processors and recipients. Agreements pursuant to Article 28 GDPR are/will be in place with the data processors.
| Recipient / data processor | Activity | Location / data transfer |
|---|---|---|
| Supabase Inc. | Database, authentication, hosting | USA / EU – see Section 5 |
| Vercel Inc. | Application hosting, edge execution | USA / EU – see Section 5 |
| Wise (Wise Payments Ltd / Wise Europe) | Payments | EU / UK |
| Resend | Transactional emails | USA – see Section 5 |
| Sentry / Better Stack / PostHog (if used) | Error tracking, logging, analytics | USA / EU – see Section 5 |
| Accountant / accounting firm | Accounting and tax tasks | Hungary |
| Affiliate Networks (Dognet, TradeTracker, Vivnetworks, Awin, Amazon, etc.) | Confirmation of conversions, tracking | Independent data controllers; transfer of sub-identifiers (subid) |
| Authorities (NAV, NAIH, courts, etc.) | Based on legal obligation | Hungary / EU |
The above list must be finalized to reflect the providers actually used; the current data processing and sub-processor terms of the cloud providers must be verified.
Certain data processors (e.g. Supabase, Vercel, Resend) may also process data in the United States or in other countries outside the EEA. Such transfers take place subject to appropriate safeguards: based on the provider's certification under the EU–US Data Privacy Framework, or through the use of standard contractual clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional measures. The data subject may request a copy of the relevant safeguards by email at the address given in Section 1.
| Data category | Retention period |
|---|---|
| Account and storefront data | For the duration of the account, then until deletion |
| Accounting documents | 8 years (Section 169 of the Accounting Act) |
| Click / attribution data | 12–24 months, then aggregation/deletion |
| Fraud screening logs | 12 months, longer if under investigation |
| Consumer complaint documentation | 5 years (Consumer Protection Act) |
| Data on rejected applications | 12 months |
Under the GDPR, the data subject has the following rights, which may be exercised by email at the address given in Section 1. The Service Provider shall comply with the request without undue delay and at the latest within one month.
Applications are pre-screened using automated tools (checking the follower-count threshold), but in every case the decision on acceptance is made by a member of the Service Provider's staff through manual review. Accordingly, this does not constitute solely automated decision-making within the meaning of Article 22 GDPR. Fraud screening likewise generates signals, but actual measures (suspension, termination) are decided by a human.
In the event of a personal data breach, the Service Provider shall assess the risk and, where the breach is likely to result in a risk, shall notify the NAIH within 72 hours of becoming aware of it (Article 33 GDPR); in the case of a high risk, the data subjects shall also be informed (Article 34). The Service Provider maintains an internal record of breaches.
The data subject may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH; 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; naih.hu; ugyfelszolgalat@naih.hu), and, in the event of an infringement of their rights, may also turn to a court. Proceedings may also be brought before the regional court (törvényszék) having jurisdiction over the data subject's place of residence or domicile.
Date: Budapest, 15 June 2026.
Data Controller: Báti Áron Gergely EV