Neuxor.net
Services overview Services in one place For businesses Business registry systems Inventory, work and workflow tracking Production-support systems Production data and material movements Websites and web applications Company websites and web interfaces IT consulting System planning and decision support For individuals and small offices Windows installation and setup Windows install, reinstall, setup Programs, drivers, and troubleshooting Programs, drivers, software issues
✓ Reference work Browse my projects on a separate page with more detailed cards. N Neuxor Lab overview Public applications and experiments ×○ Tic-tac-toe Play against CPU or invite a user
N News and articles Useful articles, updates and practical tips about IT topics. # Forum Forum discussions are public to read; sign in to start topics and post replies.
Contact Request a quote Create account Sign in
PRIVACY

Privacy Policy

This notice explains how Neuxor processes personal data related to registration, forums, private messages, contact requests, security logging, and the GDPR inactivity lifecycle.

Last updated: July 2, 2026.

1. Data controller

The controller of the service is the natural person operating the website.

  • Name: Attila Laki
  • Capacity: private individual operator
  • Contact: info@neuxor.net

2. Applicable legislation

Processing is governed in particular by the following legal instruments:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
  • Hungarian Act CXII of 2011 on informational self-determination and freedom of information (Infotv.).
  • Electronic communications privacy rules, including ePrivacy rules applicable to cookies.

3. Categories of personal data

The following personal data may be processed when using the service:

  • Account data: email address, nickname, password hash, selected language, registration time, and last sign-in time.
  • Security and operational data: sign-in events, rate limit events, audit logs, security events, and IP-related technical log data.
  • Community content: forum topics, posts, and public activity linked to the profile.
  • Private communication: private messages, image attachments, and conversation metadata.
  • Contact form data: name, email address, subject, and message.
  • GDPR lifecycle data: inactivity warning timestamps, GDPR status, pseudonymization time, reactivation token hash, and token expiry time.
  • After GDPR cleanup, the original email address is not retained in a reversible form; only an HMAC-based email hash may remain for later reactivation matching.
  • Backup and audit data: limited log and backup data required to evidence system operation, investigate security events, and support recovery.

4. Purposes of processing

  • Creating, identifying, and maintaining user accounts.
  • Providing the forum and community features.
  • Providing private messaging functionality between users.
  • Handling and replying to incoming enquiries.
  • Supporting system security, abuse prevention, troubleshooting, rate limit protection, and auditability.
  • Managing inactive accounts, sending advance warnings, performing GDPR cleanup, and providing a secure reactivation option.

5. Legal bases for processing

  • Processing required for registration, sign-in, account management, private messages, and community features is based on providing the service and performing the user terms.
  • Acceptance of this privacy notice, sending contact requests, and using the optional language preference cookie are based on consent.
  • Logging, auditing, security event handling, abuse prevention, backup/restore, and data-minimising handling of inactive accounts are based on the controller’s legitimate interest.

6. Retention periods

  • Active account data is processed while the account exists. After 2 years of inactivity from the last sign-in, automatic GDPR cleanup may start.
  • Forum topics and posts may remain available for as long as needed for community operation. During GDPR cleanup, personal profile data linked to the user is pseudonymized and personal associations are reduced.
  • Private messages are stored while the conversation exists, until deletion, or until GDPR cleanup. During GDPR cleanup, personal message payloads and related sensitive data may be deleted or minimised.
  • Contact messages are kept for up to 1 year or until the matter is fully resolved.
  • Audit logs and security events are retained by default for 730 days. Technical logs are retained only for as long as necessary for security, troubleshooting, and operation.
  • Before the 2-year inactivity threshold, the system may send warning emails 30 days and then 7 days in advance to the last known account email address.
  • During GDPR cleanup, the email address, nickname, password hash, avatar, reset/verification tokens, and other direct identifiers are deleted or replaced with placeholder values.
  • To support reactivation, only an HMAC-based email hash may remain. The original email cannot be restored from it, and it is used only for matching.
  • Database backups are retained by default for 90 days. A pre-restore backup is created before restoration, and live data files must not be included in release ZIP packages.

7. Reactivating a GDPR-cleaned account

After GDPR cleanup, the account is no longer in a normal active state. The user may later request reactivation by entering the original email address.

  • The reactivation request always gives a neutral response, so it does not reveal whether an account exists for the submitted email address.
  • If a match exists, the system sends a time-limited reactivation token by email. The token is stored only as a hash, expires, and is deleted after use.
  • On successful reactivation, the user sets a new nickname and password, the account becomes active, the email is restored, and the email hash and token data are deleted.

8. Security measures

  • Passwords are not stored in plain text; they are stored using a strong hash. The password policy rejects overly short and common passwords.
  • Sign-in, admin sign-in, password reset, messaging, and reactivation are protected by rate limits.
  • Admin actions, important security events, failed sign-ins, exports, and maintenance operations are auditable.
  • Image uploads undergo file type and content checks. Unused or expired uploads may be removed during maintenance cleanup.

9. Processors and hosting provider

The controller may use external service providers to operate the service.

  • Hosting provider: Render (hosting infrastructure and related technical services).

10. Data subject rights

  • Right to information and access.
  • Right to rectification.
  • Right to erasure.
  • Right to restriction of processing.
  • Right to data portability.
  • Right to object to processing based on legitimate interests.
  • Right to lodge a complaint with a supervisory authority, including in Hungary the NAIH.

11. Use of cookies

The website currently uses only cookies required for operation and optional preference cookies.

Cookie name
Type
Purpose
Duration
session
essential
Maintaining a signed-in session and secure operation.
session
lang
preference
Remembering the selected interface language.
up to 1 year
cookie_consent
essential
Remembering the user's cookie choice.
up to 180 days

Essential cookies are necessary for the service to function. The language preference cookie is stored only if you accept it.

Neuxor FAQ
Quick answers
Available questions
Cookie settings

The website uses cookies required for operation. It may also use an optional cookie to remember the language setting. Read more in the Privacy Policy.

Neuxor
Project Neuxor by Laki Attila
Contact Privacy Policy Terms and Conditions info@neuxor.net