Privacy policy
The netorigo.com site is operated by Mediaorigo International Ltd. (Hong Kong). This notice describes how personal data is processed in accordance with the GDPR ((EU) 2016/679) and applicable law; Hungarian customer relations and operations are supported by Mediaorigo's Hungarian partner, Nortinia Kft.
Data controller: Mediaorigo International Ltd. (Hong Kong Special Administrative Region) — Email: info@mediaorigo.com. Mediaorigo is a Hong Kong-headquartered technology company that develops and licenses AI-powered business platforms.
EU representative (GDPR Art. 27): Mediaorigo International Ltd. Hungarian Representative Office — 1125 Budapest, Városkúti út 17., Hungary — Tax no.: 27413254-1-43. Data subjects located in the EU may also address data-protection matters to the EU representative. The Hungarian operations and contracting partner is Nortinia Kft. (1125 Budapest, Városkúti út 17/B., company reg. no.: 01-09-390508).
Data processed: contact and quote-request fields submitted through the site (name, email, phone, company, message), and technical data (IP address, browser, visit data) for operation and security.
Legal basis: for contact and newsletter, consent (GDPR Art. 6(1)(a)); for quote requests and pre-contractual steps, performance of a contract (Art. 6(1)(b)); for site security and improvement, legitimate interest (Art. 6(1)(f)); for statutory obligations, Art. 6(1)(c).
Processors: for operation we use hosting, error-tracking (Sentry) and bot-protection (Cloudflare Turnstile) providers, and for the AI features, speech and language-model providers — each under a data-processing agreement pursuant to GDPR Art. 28.
Transfers to third countries: as the controller is located in Hong Kong and some providers operate outside the European Economic Area (EEA), personal data is transferred outside the EEA only with appropriate safeguards under Chapter V of the GDPR (an adequacy decision of the European Commission or the Standard Contractual Clauses, SCC), and supplementary measures where necessary. A copy of the safeguards is available at info@mediaorigo.com.
Retention: contact data is kept until the purpose is fulfilled but no longer than 24 months, or until consent is withdrawn (whichever comes first); data required by law is kept for the mandatory period.
Data security: we apply technical and organisational measures appropriate to the risk (GDPR Art. 32), in particular encryption in transit, access control and logging. In the event of a personal-data breach — where the statutory conditions are met — we notify the competent supervisory authority within 72 hours, and data subjects too where the risk is high (GDPR Arts. 33–34).
Automated and AI-based features: the outputs of the AI assistant available on the site are generated probabilistically, are informational, and do not produce a solely automated decision with legal effects concerning the data subject (GDPR Art. 22). Human involvement is available for any material matter.
Children: the service is not directed at children under 16; we do not knowingly collect data relating to children under 16.
Data-subject rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent at any time. Requests are accepted at info@mediaorigo.com (or via the EU representative) and answered within 30 days.
Remedies: the data subject may lodge a complaint with the supervisory authority of their habitual residence; in Hungary, the National Authority for Data Protection (NAIH) — 1055 Budapest, Falk Miksa u. 9-11., ugyfelszolgalat@naih.hu — and may also go to court.
Google user data (Google Calendar integration)
Business users of the Netorigo platform may voluntarily connect their Google Calendar to Netorigo to keep bookings and events in two-way sync. The connection is established through Google's OAuth 2.0 consent flow and is limited to: the Google account email address (to identify the connection), reading the calendar list (to select the target calendar), managing the app-created "Netorigo" calendar, and creating, updating and deleting calendar events for booking synchronisation.
From the Google account we process only what the integration needs: the OAuth access and refresh tokens (stored encrypted with AES-256-GCM), the connected account's email address, and the identifiers of the synchronised calendar events. We do not access Gmail messages, Drive files or contacts.
Netorigo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, and do not transfer it to third parties; humans access it only with the data subject's explicit consent (e.g. for a support request), for security purposes, or where required by law.
Access can be revoked at any time by disconnecting the calendar in Netorigo — the stored token is deleted immediately — or in the Google account security settings (myaccount.google.com/permissions). Upon disconnection, or on request (info@mediaorigo.com), the stored Google data is deleted.