PRIVACY POLICY
Effective date: 12 September 2026 · Version: 2026-09-12-r2
This notice explains how SabAI handles personal data. It applies to visitors, limited-tester applicants, free-account users, purchasers, invited collaborators and people whose information is placed in a SabAI workspace.
The Free Checklist asks only for a destination country and general preparation choices. Detailed identity, relationship and photo information is requested only in the paid workspace, after the relevant notice and explicit-consent step.
1. DATA CONTROLLER
VARGA ISTVÁN BERTALAN – Sole Proprietor
Registered address: 1078 Budapest, VII. district, Murányi utca 38., ground floor, door 9, Hungary
Tax ID: 67025086-1-42 · Registration number: 42530889
Privacy and rights requests: support@sabaivisa.com
We are the controller for the processing described here. We have not appointed a data protection officer because we are not currently required to do so. The contact above handles privacy enquiries.
2. DATA WE PROCESS
Depending on the features you use, we process:
- Account and authentication data: name, email address, chosen language, account identifiers, login provider and authentication/session records. If you choose Google, LINE or email-link sign-in, that provider also processes the login under its own notice.
- Free Checklist data: destination, accommodation type, funding arrangement, checklist progress and source/attribution parameters. Legacy saved checklists may also contain an adult/minor selection from the former flow. The free flow does not request a passport number, relationship narrative or photo.
- Limited-tester application data: non-identifying fit answers about timing, destination, visit, funding, return evidence and testing readiness; an email address or LINE ID for notification; progress, consent and submission timestamps. The form does not request a name, passport number, address or uploaded image. The contact value is encrypted in the application database.
- Paid workspace data: applicant and sponsor identity/contact details, travel and accommodation plans, employment and financial context, passport details, relationship facts, invited-collaborator details and the answers needed to create drafts.
- User content: relationship photos, captions, timeline events, generated and edited drafts, album layouts and conversations with the AI tools.
- Public SabAI product-chat data: the question you type, the language selected and the short conversation context needed to answer. This public assistant does not read your account profile, paid workspace, drafts or photos.
- Special-category data: information may reveal racial or ethnic origin, religion, health, sex life or sexual orientation. We request explicit consent before processing this information in paid features. Ordinary photographs are not treated as biometric data merely because faces appear in them; SabAI does not use facial recognition or process photos to uniquely identify a person.
- Purchase and billing data: billing name, address, country, optional phone, company/tax details, product, amount, currency, coupon/partner attribution, Stripe transaction identifiers and invoice records. SabAI does not receive or store your full card number.
- Partner-programme data: referral code, attributed purchases, commission, payout details and any payout-verification image you choose to provide.
- Technical and security data: IP address and request/device information made available in ordinary server, authentication and provider logs, timestamps, error information and security events. We do not claim to create a separate browser fingerprint unless a listed provider does so under its own notice.
- Consent and preference records: onboarding consent, tester feedback commitment, tester-support workspace-access consent, the required tester-programme commitment to consider proposed marketing material, any later approval for exact material and context, Terms acceptance, cookie choices, Free Checklist email-series consent or unsubscribe choice, and the time/version associated with those choices.
Please do not provide data that is not reasonably needed for visa preparation. When you upload another person’s information, you must have authority or another lawful basis to do so and should make this notice available to that person.
3. PURPOSES AND LEGAL BASES
| Purpose | Main legal basis |
|---|---|
| Create and authenticate an account; save a checklist; provide Complete, collaboration, drafts, albums, exports and support | Performance of a contract or steps at your request — GDPR Art. 6(1)(b) |
| Process relationship details and other special-category information needed for the paid tools | Your explicit consent — GDPR Art. 9(2)(a), together with Art. 6(1)(b) |
| Take payment, issue invoices, keep accounting/tax records and answer lawful authority requests | Legal obligation — GDPR Art. 6(1)(c) |
| Prevent abuse and fraud, secure the Service, diagnose errors and establish or defend legal claims | Our legitimate interests — GDPR Art. 6(1)(f), balanced against your rights |
| Send transactional emails, account notices and requested support replies | Contract performance and/or legitimate interests — GDPR Art. 6(1)(b) or (f) |
| Send the Free Checklist requested through a Free account | Performance of a contract or steps at your request — GDPR Art. 6(1)(b) |
| Send the two optional SabAI preparation follow-ups | Your explicit, recorded consent — GDPR Art. 6(1)(a) and applicable ePrivacy rules |
| Save and assess a limited-tester application, notify the applicant and administer selected access | Steps at your request and our legitimate interest in running and improving a small product test — GDPR Art. 6(1)(b) and (f) |
| Inspect selected testers’ relevant workspace content for requested support, feedback investigation, security and product improvement | Your explicit, recorded consent; where special-category content is involved, GDPR Art. 9(2)(a), together with Art. 6(1)(a) |
| Publish an approved tester photo or relationship-album excerpt | A separate, specific consent for the exact material and context — GDPR Art. 6(1)(a), and Art. 9(2)(a) where applicable |
| Load optional analytics and marketing technologies | Your consent — GDPR Art. 6(1)(a) and applicable ePrivacy rules |
We do not sell personal data. We do not use relationship or visa-workspace data for advertising unless every identifiable person concerned has separately approved the exact material and context. We do not make solely automated decisions that produce legal or similarly significant effects. AI output assists preparation; it does not decide a visa application.
4. SPECIAL-CATEGORY CONSENT
Paid onboarding asks separately for explicit consent before sensitive relationship information or photos are processed. Consent is voluntary and can be withdrawn at any time in the account controls or by emailing support@sabaivisa.com. Withdrawal does not affect processing already lawfully carried out, but functions that require the information will stop and you may need to delete or replace affected content.
The workspace owner must ensure that an invited partner or any identifiable person shown or described has been informed and that their data is uploaded lawfully. Do not upload intimate, medical, religious or other sensitive material unless it is genuinely relevant and you are authorised to do so.
5. AI PROCESSING
SabAI sends only the information needed for the requested public product-chat, drafting, translation-assistance or album-review operation to OpenAI API services. Depending on the function, this can include the public-chat question and recent chat context, instructions, selected profile facts, draft text, captions or reduced image representations used for review. Do not place personal, visa-case or other unnecessary information in the public product chat.
The public product chat is stateless on SabAI: its messages are kept only in the current browser page memory and are not written to the SabAI account database. Each request is sent with OpenAI response storage disabled. OpenAI’s separate abuse-monitoring or service-level retention can still apply under its API data controls. The public chat has no access to account data and is restricted to explaining SabAI’s verified product features and price; it does not provide visa advice or create documents.
OpenAI acts as a processor for API requests under the applicable service and data-processing terms. OpenAI states that business/API data is not used to train its models by default unless the customer opts in. Abuse-monitoring and application-state retention can still apply depending on the API service and account configuration. Current details are available in OpenAI’s API data controls.
6. PROCESSORS AND RECIPIENTS
We use providers only where needed to run the Service, under the applicable contracts and safeguards:
- Hostinger — production web hosting, MySQL database, email delivery and associated operational/security logs;
- Cloudflare — private object storage and delivery of uploaded media;
- OpenAI Ireland and its subprocessors — requested AI features;
- Stripe — checkout, payment processing, fraud controls and payment records;
- KBOSS.hu / Szamlazz.hu — electronic invoicing and legally required invoice reporting;
- Google and LINE — authentication only when you choose that provider;
- Google Analytics, Meta and Trustpilot — only when the relevant optional cookie category is allowed, except when you follow an ordinary external link;
- professional advisers, courts, regulators or law-enforcement bodies where disclosure is legally required or necessary to establish or defend a legal claim.
We do not give visa authorities access to your workspace and do not submit documents on your behalf.
7. INTERNATIONAL TRANSFERS
Some providers or their subprocessors may process data outside the European Economic Area. Where the destination is not covered by an EU adequacy decision, we rely on an approved transfer mechanism such as the European Commission’s Standard Contractual Clauses and, where appropriate, supplementary safeguards. A copy or description of the relevant safeguard can be requested at support@sabaivisa.com, subject to lawful redactions.
8. STORAGE, SECURITY AND ACCESS
We apply measures appropriate to the risk, including encrypted transport, access controls, private object storage, access-controlled same-origin media delivery, server-side authorisation checks and encryption at rest for selected high-risk profile fields such as passport and direct contact identifiers. Temporary signed provider links may be used in limited internal or administrative flows. No online service can guarantee absolute security.
The account owner and invited collaborator can access information in their shared workspace. Do not invite someone who should not see the full paid workspace. Provider personnel and subprocessors may access data only as needed to operate, secure or support their services and under applicable confidentiality duties.
9. RETENTION AND DELETION
- Free and paid workspace data is kept while the account is active or retained so that saved and post-expiry read/download access can be provided. You may delete the account at any time. Account deletion removes the profile, drafts, conversations, album records and stored media from active SabAI systems, subject to technical completion and the legal records below.
- OpenAI conversation objects linked to the account are requested for deletion when the account-deletion flow completes; the provider’s documented deletion cycle then applies.
- Public product-chat messages are not stored in the SabAI database or browser storage and disappear from the interface when the page is reloaded. OpenAI’s provider-side retention, where applicable, follows its API data controls.
- Payment, invoice, accounting and partner-payout records are retained for the period required by Hungarian tax and accounting law, generally eight years for accounting documents.
- Security and dispute records are kept only as long as reasonably necessary for fraud prevention, system security or the establishment, exercise or defence of claims, taking account of applicable limitation periods.
- Cookie choices and attribution data remain until replaced, withdrawn, cleared from the browser or no longer needed for the stated purpose.
- Free Checklist email preferences are kept while needed to send the opted-in series or honour an unsubscribe request. A minimal suppression record may remain so we do not resume emails after an unsubscribe.
- Limited-tester applications are kept while needed to select, run and document the tester programme, handle follow-up and resolve disputes, then deleted or de-identified when no longer needed. You may request deletion before selection; a minimal record may remain where needed to document consent withdrawal, prevent abuse or establish legal claims.
Deletion from provider backups can follow the provider’s secure backup-rotation cycle. We may retain a minimal suppression or transaction record where necessary to comply with law, prevent fraud or document a rights request. We do not use retained legal records to recreate a deleted workspace.
10. COOKIES, LOCAL STORAGE AND TRACKING
Necessary browser storage supports language, authentication, security, checklist continuity and your consent choice. Optional analytics helps us understand aggregate website use. Optional marketing technologies can measure campaigns, retain a referral code or display third-party widgets. Analytics and marketing technologies are not loaded until the relevant consent is given.
| Technology | Category and typical duration | Purpose |
|---|---|---|
| Auth.js session, CSRF and callback cookies | Necessary; session or authentication lifetime | Sign-in, account security and return path |
sabai_locale cookie/local storage | Necessary; cookie up to 1 year, local value until cleared | Remember English or Thai |
sabai_cookie_consent | Necessary local storage; until changed or cleared | Remember category choices and policy version |
| Checklist setup in local storage | Necessary; until saved to the account, replaced or cleared | Preserve unfinished checklist choices through sign-in |
| Limited-tester application key in local storage | Necessary; until cleared | Resume an unfinished application without asking for an account or identity details |
| One-time event markers in local storage | Analytics; until cleared | Prevent duplicate funnel events after analytics consent |
| First/last UTM attribution storage | Analytics; first touch until cleared, last touch for the browser session | Attribute visits and funnel events |
sabai_ref | Marketing; up to 30 days | Attribute an eligible partner referral |
| Google Analytics, Meta Pixel and Trustpilot technologies | Analytics or marketing; provider-controlled duration | Audience measurement, campaign measurement and review widget |
You can accept, reject or select optional categories in the banner and change them later using Cookie Preferences in the footer. Withdrawal affects future loading and does not make earlier consent-based processing unlawful. You can also clear browser storage; this may sign you out or reset saved preferences. Following a link to an external site causes that site’s own privacy and cookie terms to apply.
11. YOUR RIGHTS
Subject to the conditions in the GDPR, you may request access, correction, deletion, restriction, data portability, or object to processing based on legitimate interests. You may withdraw consent at any time and may lodge a complaint with a supervisory authority. Where processing is based on consent or contract and carried out by automated means, data portability may apply.
Send a request to support@sabaivisa.com from the account email where possible. We may ask for proportionate identity verification and will not request more data than needed. We answer without undue delay and normally within one month. The period may be extended by up to two further months where the GDPR permits; if so, we will explain the extension within the first month. Requests are normally free, but the GDPR permits a reasonable fee or refusal for manifestly unfounded or excessive requests.
12. COMPLAINTS
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9–11, Hungary; www.naih.hu; ugyfelszolgalat@naih.hu. You may also contact the supervisory authority of your habitual residence, place of work or the place of the alleged infringement, and you retain the right to seek a judicial remedy.
13. PERSONAL-DATA BREACHES
We assess and document personal-data breaches. We notify the competent supervisory authority without undue delay and, where feasible, within 72 hours unless the breach is unlikely to create a risk to individuals’ rights and freedoms. We notify affected individuals without undue delay when the breach is likely to create a high risk, subject to the exceptions in the GDPR.
14. CHILDREN
SabAI accounts and purchases are for people aged 18 or older. A parent or guardian may include a minor applicant’s necessary information in the workspace for visa preparation. Do not allow a minor to create or control an account. Contact us if you believe a child has provided data directly without proper authority.
15. CHANGES TO THIS NOTICE
We may update this notice when our processing, providers or legal duties change. The current version and effective date appear above. We will give a prominent in-product or email notice of material changes where appropriate. If a new purpose requires consent, continued use alone will not count as consent; we will ask separately.
16. CONTACT
For privacy questions or to exercise a right, email support@sabaivisa.com. Contract and provider details are available in the Terms and Conditions and Legal Notice.