PRIVACY POLICY
How RYTHM handles personal data during the Public Beta.
Effective 15 August 2026. This notice explains the current data-processing practices of RYTHM Company OS and the rights available to individuals whose personal data is processed.
CONTROLLER
Who is responsible for your data?
- Controller: Tayyebialashti Yaser E.V., individual entrepreneur (e.v.), Hungary
- Business address: 1143 Budapest, Gizella út 35, Hungary
- Tax number: 48332376-1-42
- Privacy contact: privacy@rythm-os.com
SCOPE
Data covered by this notice.
- Account and identity data such as name, email address, authentication state, and organization membership.
- Organization/workspace data that users choose to submit to RYTHM.
- Support, commercial, billing, consumer-contract, withdrawal, complaint, and security communications.
- Order or contract references, service/purchase details, withdrawal statements and timestamps, requested remedies, and refund/termination status where needed to administer consumer rights.
- Technical and security data such as timestamps, IP/network metadata, device/browser information, and service logs where generated by the platform or its providers.
- Local browser preferences used for Tour, Explain RYTHM, Experience Mode, and Solution Finder.
PURPOSES & LEGAL BASES
Why data is processed.
- To create and secure accounts, provision organizations, deliver contracted services, administer orders, and provide support — performance of a contract or steps requested before entering a contract.
- To record and administer consumer withdrawal requests, refunds, complaints, statutory contract confirmations, and dispute-resolution obligations — performance of contract and compliance with applicable legal obligations.
- To protect RYTHM, prevent abuse, maintain service integrity, and improve reliability — legitimate interests, balanced against user rights.
- To meet tax, accounting, legal, security, and regulatory obligations and establish, exercise, or defend legal claims where applicable.
- For optional communications or non-essential tracking, where introduced — consent or another lawful basis explicitly disclosed at the point of collection.
AI PROCESSING
How AI-related data may be handled.
- When a product feature invokes an AI model, relevant prompts, context, instructions, and resulting outputs may be processed by the model provider required to deliver that feature.
- RYTHM is designed around explicit human authority and does not treat AI output as an autonomous legal or executive decision by default.
- Do not submit special-category, highly sensitive, regulated, or third-party confidential data unless the applicable deployment has been reviewed and approved for that use.
- The public Demo uses synthetic data and is not intended for real customer information.
CONSUMER RIGHTS ADMINISTRATION
Withdrawal and complaint records are handled as legal-service records.
- The online withdrawal function records the consumer name, contact email, contract/order reference, withdrawal statement, submission timestamp, receipt identifier and handling status.
- Complaint handling may require contact details, order/service information, correspondence, evidence and the remedy requested.
- These records are used only to administer the consumer contract, statutory rights, refunds, dispute resolution, accounting obligations and related legal claims.
- RYTHM does not require account registration merely to use the public online withdrawal function.
PAYMENT DATA
Raw card data is not part of the current RYTHM processing baseline.
- Online payment is not yet enabled.
- Before payment is activated, the selected payment provider and related personal-data processing will be reviewed and this notice and the Subprocessor/Cookie disclosures will be updated where required.
- RYTHM intends to use a compliant payment provider so raw card numbers and card-security codes are not stored directly by RYTHM.
RECIPIENTS & PROVIDERS
Who may process data for RYTHM.
- Hosting, deployment, database, authentication, email-delivery, DNS/security, AI-model, monitoring, and other infrastructure providers used to operate the service.
- The current Public Beta processor stack and processing purposes are listed in the Subprocessor Register.
- Professional advisers, competent consumer authorities, conciliation bodies, courts, or other authorities where disclosure is legally required or reasonably necessary to protect legal rights.
- Customer-authorized integrations only where the relevant product capability and permissions are enabled.
- RYTHM does not sell personal data.
INTERNATIONAL TRANSFERS
RYTHM can be used worldwide.
- Some service providers may process data outside Hungary or the European Economic Area.
- Where GDPR transfer restrictions apply, RYTHM relies on applicable lawful transfer mechanisms made available by its providers, such as adequacy decisions, standard contractual clauses, or other permitted safeguards.
- Enterprise customers with location-specific requirements should request a data and deployment review before connecting sensitive workflows.
RETENTION
Data is kept only for justified periods.
- Account and workspace data is generally retained while the account or service relationship is active and for a limited period afterwards where needed for recovery, security, dispute handling, or legal obligations.
- Billing and transaction records may be kept for the period required by applicable tax and accounting law.
- Consumer withdrawal, complaint, refund, and contract-evidence records are retained only for the statutory/accounting/legal-claim periods that apply; records are minimized after those purposes expire.
- Security and operational logs are retained according to service configuration, provider limits, and legitimate security needs.
- Local browser preferences remain on the user’s device until cleared, replaced, or expired by application logic.
- Validated deletion and export requests follow the documented Data Requests workflow, subject to records that must be retained by law or for legal claims.
YOUR RIGHTS
Privacy rights depend on applicable law.
- Where GDPR applies, individuals may request access, correction, deletion, restriction, portability, and objection where the relevant legal conditions are met.
- Where processing is based on consent, consent may be withdrawn without affecting prior lawful processing.
- Requests may be sent to privacy@rythm-os.com or submitted using the instructions on Data Requests. Identity verification may be required before fulfilling a request.
- Individuals may also complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) or, where applicable, another competent supervisory authority.
AUTOMATED DECISIONS
Human authority remains central.
- RYTHM can generate recommendations, analyses, drafts, and agent outputs.
- RYTHM does not currently intend to make solely automated decisions about website visitors or account holders that produce legal or similarly significant effects unless that processing is specifically disclosed and legally supported.
- Product governance is designed to surface consequential work to human authority boundaries.
CHANGES
This notice can evolve with the Beta.
- Material changes will be reflected on this page with an updated effective date.
- Where law requires direct notice or renewed consent, RYTHM will provide it through an appropriate channel.
- Before online payment is activated, the payment provider, payment-data flow and any related cookies/storage will be reflected in the relevant notices.
- For contractual privacy requirements, including processor terms, review the DPA or contact legal@rythm-os.com.
PRIVACY CONTACT
Questions or data-rights request?
Do not include passwords, authentication links, API keys, or unrelated confidential information in your initial email.