Privacy Notice

Effective and last updated: 17 August 2026

1. Data controller

Possible Solutions Kft. is the controller of personal data processed through The Private Twenty (registered office: 8200 Veszprém, Viola utca 2, Hungary; company registration number: 19-09-522132; EU VAT number: HU29264324).

Privacy requests: curator@theprivatetwenty.com. No data protection officer has been appointed because the Operator has determined that one is not currently required.

2. Application data

When you apply, we process the Instagram profile you provide, proposed commitment amount, application status, submission time and pseudonymous visitor/session references. We use this information to review eligibility, prevent abuse, contact you about the decision and take steps at your request before a possible contract.

The legal basis is taking pre-contractual steps requested by you and our legitimate interests in operating a safe, genuinely curated private community. No payment is taken during application. The Instagram profile is encrypted at rest; a keyed, irreversible comparison value is also stored for security and duplicate detection.

If an application is declined, its application record is deleted without undue delay after the decision has been communicated. Approved application and contact data is normally retained for up to 90 days, unless it becomes necessary for the active membership, a contract, legal compliance or a dispute.

3. Membership and public placement

For approved members, we may process the agreed display name, pseudonym, logo, image, Instagram link, contact detail, short description, numbered position, placement level, activation status and Signal participation preference.

This processing is necessary to perform the membership contract. Public disclosure is limited to the content the member selects and approves. Anonymous placement is available. Public content remains available for the service term or until valid removal, correction or legal action requires otherwise.

Submitted display content is not used in Meta advertising or unrelated promotion without separate, specific permission.

4. Payments, invoicing and accounting

Approved applicants may be asked for name, billing address, tax/VAT details where applicable, email, amount, payment status and transaction references. Stripe processes the payment; Billingo is used to issue the official accounting invoice. We do not receive or store full payment-card details.

Payment processing is necessary to perform the contract. Invoice and accounting data is processed to comply with Hungarian tax and accounting obligations and is retained for at least eight years, or longer where another mandatory rule or legal proceeding requires it.

5. First-party analytics

Our own analytics records pseudonymous visitor and session identifiers, page path and title, arrival and last-activity times, duration, exit state and selected interaction states. Interaction events may record modal opening/closing, field focus, whether typing started, acceptance flow, submission attempts and success/error states. Analytics does not copy the values typed into form fields.

Attribution data may include the referring domain and URL path without arbitrary query parameters, landing path, UTM source/medium/campaign/content/term, traffic-source classification and a keyed, irreversible hash of an advertising click identifier. We also record whether visible browser activity verified the visit, allowing likely automated traffic to be separated from human activity. Known bots and link-preview crawlers are excluded where technically identifiable.

Analytics supports security, bot filtering, service improvement, campaign measurement and conversion analysis. The legal basis is our legitimate interests in protecting and improving the service and understanding paid campaign performance. Analytics records are retained for up to 90 days and then deleted or irreversibly aggregated.

6. Cookies and local identifiers

The website uses a secure session cookie for security, CSRF protection, rate limiting and form operation. It expires after approximately 30 minutes of inactivity. A first-party pseudonymous visitor cookie named tpt_visitor may persist for up to one year to distinguish returning browsers without storing a directly identifying value.

These cookies are not used for third-party advertising, cross-site tracking or remarketing. You can block or delete cookies in your browser, but blocking the secure session cookie may prevent the application form or admin security functions from working correctly.

7. Communications, complaints and legal claims

Instagram is used only for application-related contact, not marketing. Email is used for contractual, privacy, complaint and legal communication. Signal is used for optional member communication and operational notices.

Complaint, refund and dispute records are retained for as long as reasonably necessary to resolve the matter and establish, exercise or defend legal claims. This may exceed 90 days where required by an applicable limitation period or legal obligation.

8. Recipients and service providers

Personal data is accessible only where necessary to the Operator and authorised providers, including:

  • Rackhost Zrt. — hosting, domain/DNS and email services in Hungary;
  • Stripe — payment processing and payment communications;
  • Billingo — statutory invoicing and accounting records;
  • Meta/Instagram — application communication initiated through Instagram;
  • Signal — optional private member communication;
  • professional advisers, accountants, courts, regulators and authorities where legally necessary.

Each independent third-party service also processes information under its own terms and privacy notice. We do not sell personal data and do not use Meta Pixel, Google Analytics or third-party remarketing on this website.

9. International transfers

The website database is hosted in Hungary, but use of Stripe, Instagram/Meta and Signal may involve processing or transfer outside the European Economic Area. Encryption does not by itself eliminate such a transfer.

Where GDPR transfer restrictions apply, providers state that they use recognised safeguards such as adequacy decisions, the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as applicable. Their current notices should be consulted before using those services: Stripe Privacy Policy, Instagram Privacy Policy, and Signal Privacy Policy.

10. Security

We use access controls, encrypted transport, secure cookies, CSRF protection, request limiting, security headers, prepared database statements and encryption at rest for submitted Instagram profiles. Visitor, session and click identifiers are protected with keyed cryptographic hashing.

No internet service can guarantee absolute security. If a personal-data breach creates a legal notification duty, we will notify the competent authority and affected individuals as required.

11. Your rights

Subject to the GDPR and applicable law, you may request access, correction, deletion, restriction, portability and, where applicable, withdrawal of consent. You may object to processing based on legitimate interests, including first-party analytics. Some rights are limited where data must be retained for accounting, legal claims or other legal obligations.

Send requests to curator@theprivatetwenty.com. We may request proportionate information to verify identity and normally respond within one month as required by the GDPR.

You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) at www.naih.hu, or with the supervisory authority of your habitual residence, workplace or the place of an alleged infringement.

12. Automated decisions and children

Applications are decided manually. We do not use solely automated decision-making that produces legal or similarly significant effects. The service is not intended for anyone under 18.

13. Updates

We may update this Notice when processing, providers or legal requirements change. The current version and effective date are published on this page. Material changes affecting active members will normally be communicated through the available member contact channel.