diff --git a/CONTEXT.md b/CONTEXT.md index 888b0f46..f793672d 100644 --- a/CONTEXT.md +++ b/CONTEXT.md @@ -16,6 +16,34 @@ > and holds nothing of its own; this file does hold its own content, namely the standing rulings below. +> **2026-10-09 — the closed-test legal set is PUBLISHED, before the lawyer (operator rulings, this day).** Three +> rulings, recorded together because they move R-813: **(1) no company exists yet** — the operator is named on the +> public pages as a **private person** (Nagyfenyvesi Viktor), with `info@felhom.eu` and **no postal address and no +> phone**; **(2) publish the closed-test set now, before a lawyer has seen it** — the website was collecting data with +> no notice at all, and an honest notice beats none; **(3) the full ÁSZF, the impresszum and the lawyer's review wait +> for the company and the first paying customer** (R-802, R-809). Published: `website/adatkezeles.html` → +> and `website/feltetelek.html` → , both Hungarian only; +> the text of record is `documentation/legal/{adatkezelesi-tajekoztato,feltetelek}-1.0.md`, **derived from the +> published HTML** so it cannot drift. Every page's footer carries the operator, the e-mail and both links (18 of 18, +> counted); the English footers say the legal texts are Hungarian. `site_gates.py` `NO_TWIN` now holds the two pages — +> an **unreviewed English legal text would be worse than an honest pointer**, so the absence of a twin is deliberate +> and commented. The contact form's consent text was replaced: the old one claimed „az adatokat harmadik félnek nem +> adjuk ki" while Resend, Cloudflare and Google carry the message. +> +> **Four facts were measured for this, not taken from a vendor or a README** (they are the notice's load-bearing +> claims): the site sets **zero cookies** and uses no local storage — checked in the browser *with a positive control* +> after the tracker fired, and no response carries `Set-Cookie`; the Umami beacon's exact payload (site id, screen +> size, language, title, url, referrer — **no visitor identifier**); Cloudflare is **DNS only** — the public A record +> `37.191.56.193` is not a Cloudflare address, so site traffic cannot be proxied; and `fsn1` is **Falkenstein, +> Germany** (Hetzner's own location list). Also measured: `felhom-ep0-copy-gc.timer` is **installed and ran +> successfully** (2026-10-09 08:00, exit 0) — so the „deleted within 30 days" line is now true, where on 2026-10-08 +> it was written but not switched on. +> +> **Three retentions are stated as having no deadline, on purpose** (operator confirmed): website statistics, web +> server logs and contact messages have no automatic deletion today, and the pages say so rather than promising a +> date nothing enforces. Every other period on the page is enforced by configuration and cited, or — for the 30-day +> backup deletion — by the measured job above. + > **2026-10-08 — Facebook Page: the decision home (spike `audits/SPIKE-facebook-page-api-2026-10-08.md`).** The > Felhom.eu Page is run through a Meta **system user** (`felhom-cc`) owned by the Felhom business portfolio, via the > Meta app `felhom.eu` (`2273465403490709`). Its token lives **only** in `~/.config/credentials` (`FACEBOOK_API`) on diff --git a/STATUS.md b/STATUS.md index d0f2b1ec..b9ad25f6 100644 --- a/STATUS.md +++ b/STATUS.md @@ -35,6 +35,30 @@ - **Still to prove:** the lost off-site copy alarm (Tester 1's next clean-up window, about 12 October), and the failed-restore hold (needs a scratch off-site store). +## Legal pages (2026-10-09): the website finally says what it does with people's data + +- **Two new pages are live:** (what we do with data) and + (what the free test is, and is not). Both in Hungarian, both short, both written + for a household rather than a lawyer. Every page of the site now links them at the bottom. +- **You are named on them as a private person** — Nagyfenyvesi Viktor, with the e-mail address. **No home address + and no phone number appear anywhere.** There is no company yet, and the pages say that plainly. +- **The contact form stopped telling people something untrue.** It used to say „the data is not passed to third + parties". It is: the mail services carry the message. The new text says so, and links the notice. +- **The pages promise nothing we cannot do.** Where there is no deletion deadline today — website statistics, + server logs, your e-mails to us — they say there is none, instead of inventing a date. Where a deadline is real, + it comes from the configuration, and for the 30-day backup deletion I checked the job actually ran this morning. +- **Four things I measured rather than believed:** the site sets no cookies at all; the visitor counter sends no + identifier for you; Cloudflare only answers the name, our traffic does not go through it; and the backup storage + is in Falkenstein, Germany. These are the claims the notice stands on, so I did not take anyone's word. +- **Your next click (2 minutes, unblocks the Facebook app):** Meta app → Basic settings → Privacy Policy URL = + `https://felhom.eu/adatkezeles`, Terms of Service URL = `https://felhom.eu/feltetelek`. **Switching the app to + Live is a separate decision, and still yours.** +- **Still waiting, and not published:** the full ÁSZF and the impresszum — both need company details that do not + exist yet — and **no lawyer has read any of this**. That was your decision, and it is the right way round: an + honest notice now beats no notice at all. When the company exists, the lawyer's review comes with it. +- The two parked Facebook texts (the long description, the four Messenger answers) stay parked until posting + starts, as you chose. + ## Facebook Page (2026-10-09): the details box filled in — and two things Facebook simply will not allow - **Your e-mail and phone were already on the Page** when I looked — you had set them yourself. I checked the diff --git a/documentation/backlog/OPEN-ITEMS.md b/documentation/backlog/OPEN-ITEMS.md index 8061a085..fdd45928 100644 --- a/documentation/backlog/OPEN-ITEMS.md +++ b/documentation/backlog/OPEN-ITEMS.md @@ -265,15 +265,15 @@ stopping line that lies. | **R-784** | Business & legal | P2 | **[P2-MEDIUM] SparkyFitness's licence forbids commercial use: "may not be used, directly or indirectly, in any product, service … intended for … commercial advantage … without prior written permission from the author" — and Felhom is a paid service that offers it in its catalog.** READ 2026-10-01 (`audits/visitors-2026-10-01/C/C0-license.txt`): a custom licence (GitHub: NOASSERTION), the same at the pinned tag v0.17.3 and at `main`; termination clause 7 ("cease all use"). SparkyFitness was named as wger's replacement for fitness. **Needs (operator):** (A) hide it from new installs (`lifecycle: hidden`) until the author gives written permission, and ask; (B) ask first and keep it offered meanwhile; (C) keep it. Recommended A. If nothing is decided it stays offered. **UPDATE 2026-10-02 — DECIDED (`09` §3 decision 65, option B):** SparkyFitness stays offered; the operator asks the author. The request is drafted (NOT sent): `audits/licences-2026-10-02/EMAIL-DRAFT-sparkyfitness.md` — the author publishes no e-mail; the routes are the project's Discord (private, recommended) or a GitHub Discussion. **Trigger:** no written permission before the first paying customer → `lifecycle: hidden` (a STATUS standing item). **2026-10-08: the public apps page lists SparkyFitness** (Hungarian and English), badged *Korlátozott licenc* / *Restricted licence*, as it lists Tandoor (R-789) — the box offers both today; removing the cards is one small commit if the decision goes that way. | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (send the request; the answer)** | — | — | operator | | **R-789** | Business & legal | P2 | **[P2-MEDIUM] Tandoor's licence is AGPL-3.0 WITH the Commons Clause: it forbids selling "a product or service whose value derives, entirely or substantially, from the functionality of the Software" — fees for hosting or support included.** READ 2026-10-02 at 2.6.15 (`audits/licences-2026-10-02/TABLE.md`). Felhom charges for installing and caring for the household's apps; whether that value comes "substantially" from Tandoor is the question. **Needs (operator):** keep (the fee is for the box, not Tandoor), hide for new installs, or ask the authors. Nothing changed meanwhile. **RULED 2026-10-02 afternoon (`09` §3 decision 66):** treated like SparkyFitness — stays offered; the operator asks the authors for written permission; without it before the first paying customer Tandoor is hidden (`lifecycle: hidden`). STATUS "Before the first paying customer". | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (the request; trigger: first paying customer)** | — | — | operator | | **R-802** | Business & legal | P2 | **[P2-MEDIUM] A lawyer reviews the non-OSI licence list before the first paying customer.** Operator ruling 2026-10-02 (`09` §3 decision 66): Tandoor (R-789), SparkyFitness (R-784), Emby, n8n, Plex (kept — R-790..R-792), the EE/BUSL parts (R-793), redis 7.4 (R-794); the table is `audits/licences-2026-10-02/TABLE.md`. STATUS "Before the first paying customer". | **WAITING-ON-OPERATOR — rank P2-MEDIUM; owner: operator (trigger: first paying customer)** | — | — | operator | -| **R-813** | Business & legal | P2 | **[P2] The website collects personal data but publishes no privacy notice, no terms and no imprint.** CHECKED 2026-10-03 (read-only): `website/` holds nine Hungarian pages and one English page; none is an ÁSZF, an adatkezelési tájékoztató or an impresszum, and no page links to one (ASCII-fragment search `aszf`, `adatkezel`, `impresszum`, `impressum`, `privacy` over `website/`; positive control: the same search finds `adatkezel` in the contact form). The contact form makes the visitor tick a data-processing consent (`website/kapcsolat.html:123-128`) whose text names no controller, no retention and no rights, and links nowhere. The papers around it — contract, data-processing agreement, billing — are the intention **R-809** in `ROADMAP.md`. **2026-10-08 (website refresh): the English twins are PUBLIC since today** (`felhom.eu/en/…`, operator choice B) — **the legal pages are needed in English too**, or an English line saying the legal texts are Hungarian, linked from every English page. The English contact form translates the consent text as it is. The refresh CUT the FAQ's „önálló modell" (no row backs it, brief Part A) and LEFT the GDPR answer („nem harmadik félnél") for R-900; the English FAQ carries the same answer. | **WAITING-ON-OPERATOR — the operator writes or commissions the texts; CC drafts on request; owner: operator** **2026-10-08: first drafts written (not published, pending lawyer review R-802): `documentation/legal/` — `DRAFT-aszf.md`, `DRAFT-adatkezelesi-tajekoztato.md`, `DRAFT-impresszum.md`, `DRAFT-kapcsolat-hozzajarulas.md` (proposed consent text + link). Every fact the operator supplies is a `[[…]]` placeholder; the lawyer list and the guesses are at the end of each draft. Owner stays operator.** | — | — | operator | +| **R-813** | Business & legal | P2 | **[P2] The website collects personal data but publishes no privacy notice, no terms and no imprint.** CHECKED 2026-10-03 (read-only): `website/` holds nine Hungarian pages and one English page; none is an ÁSZF, an adatkezelési tájékoztató or an impresszum, and no page links to one (ASCII-fragment search `aszf`, `adatkezel`, `impresszum`, `impressum`, `privacy` over `website/`; positive control: the same search finds `adatkezel` in the contact form). The contact form makes the visitor tick a data-processing consent (`website/kapcsolat.html:123-128`) whose text names no controller, no retention and no rights, and links nowhere. The papers around it — contract, data-processing agreement, billing — are the intention **R-809** in `ROADMAP.md`. **2026-10-08 (website refresh): the English twins are PUBLIC since today** (`felhom.eu/en/…`, operator choice B) — **the legal pages are needed in English too**, or an English line saying the legal texts are Hungarian, linked from every English page. The English contact form translates the consent text as it is. The refresh CUT the FAQ's „önálló modell" (no row backs it, brief Part A) and LEFT the GDPR answer („nem harmadik félnél") for R-900; the English FAQ carries the same answer. | **NARROWED 2026-10-09 — the closed-test set is PUBLISHED.** Live: (`website/adatkezeles.html`) and (`website/feltetelek.html`), Hungarian only, version „Zárt teszt — 1.0 verzió, hatályos: 2026. október 9.” Text of record: `documentation/legal/{adatkezelesi-tajekoztato,feltetelek}-1.0.md`, **derived from the published HTML** so it cannot drift from the page. All 18 pages carry the operator, `info@felhom.eu` and both links in the footer (counted: 18 found = 18 with both links = 18 structurally valid); the English footers say the legal texts are Hungarian, and `site_gates.py` `NO_TWIN` holds the two pages deliberately — an unreviewed English legal text would be worse than an honest pointer. The contact form's consent text was replaced in both languages: the old one claimed „az adatokat harmadik félnek nem adjuk ki” while Resend, Cloudflare and Google carry the message. **Operator rulings 2026-10-09:** no company yet, so the operator is named as a PRIVATE PERSON (Nagyfenyvesi Viktor) with **no postal address and no phone**; publish before the lawyer, because the site was collecting data with no notice at all; and keep three retentions honestly open-ended (website statistics, web server logs, contact messages) rather than promise a date nothing enforces. Four load-bearing claims were MEASURED, not copied from a vendor or a README: zero cookies and no local storage (browser check with a positive control, after the tracker fired; no `Set-Cookie` on any response); the Umami beacon's exact payload (site id, screen, language, title, url, referrer — no visitor identifier); Cloudflare is DNS only (the public A record 37.191.56.193 is not a Cloudflare address); `fsn1` = Falkenstein, Germany. Also measured: `felhom-ep0-copy-gc.timer` is installed and ran successfully (2026-10-09 08:00, exit 0), so the „deleted within 30 days” line is now true where on 2026-10-08 it was written but not switched on. **WHAT REMAINS, which is why this is narrowed and not closed:** the full ÁSZF and the impresszum are still unpublished (they need company data that does not exist); there is no English translation of either legal text; and **no lawyer has reviewed any of it** (R-802). Owner stays operator. | — | Operator: (a) enter the two URLs in the Meta app's Basic settings — this unblocks R-915; (b) when the company exists, commission the lawyer's review (R-802) and the full ÁSZF + impresszum. If nothing is done: the closed-test set stands as published, and the Meta app cannot go Live | operator | | **R-89** | Business & legal | P4 | Retention as a per-customer **commercial** policy on the hub | READY (increment 2) | — | Policy object + reconciler → ep0 prune job; keep box tokens write-only | CC | | **R-794** | Business & legal | P4 | **[P3-LOW] redis 7.4 (RSALv2 / SSPL, not OSI) runs as a private cache in seven apps: dawarich, docmost, immich, nextcloud, outline, paperless-ngx, romm.** READ 2026-10-02 (`audits/licences-2026-10-02/TABLE.md`). Read as permitted (a private cache only its app uses is not Redis offered as a service — inferred). Valkey (BSD-3) or redis 8 (AGPL option) removes the question. **Needs:** a ladder step per app to valkey or redis 8, through the harness — no hurry. | **READY — rank P3-LOW; owner: CC** **Re-ranked 2026-10-03: P3→P4: the row itself says no hurry; usage read as permitted.** | — | — | CC | | **R-914** | Business & legal | P4 | **Write the Felhom Facebook Page skill from the spike's findings.** Spike 2026-10-08 (`audits/SPIKE-facebook-page-api-2026-10-08.md`): key valid, never expires; the Page (`1360018983863273`) is reached with CREATE_CONTENT/MODERATE/ANALYZE; a scheduled text post and a scheduled photo were created, read back byte-equal and deleted (removal proven). Probe `scripts/facebook/fb_probe.py`. Gap to close in the skill: a scheduled photo's publish state was not read (no `post_id` returned). **2026-10-08 (Page pictures task) — two more for the skill:** (1) **the removal proof was not a proof**: the text post's after-DELETE answer was (#10) „does not exist, cannot be loaded due to missing permission…" — that message also means a permission gap. The skill proves removal by listing the Page's scheduled posts before and after the delete (present, then absent); the operator's Planner view on 2026-10-08 showed nothing on 15 October (a different channel, by eye). (2) **pictures by API** (READ, developers.facebook.com/docs/graph-api/reference/page/picture and …/reference/page/): `POST /{page}/picture` needs the `MANAGE` task, which the robot does not have (measured task list); the cover is `POST /{page}` `cover=`, „only by the Page Admin or Page Editor with `EDIT_PROFILE`" + `business_management`. Neither names `pages_manage_metadata`. Today the pictures are uploaded by hand (`marketing/facebook/README.md`). | **READY — owner: CC** | — | Write the skill (drafts scheduled for operator review by default); read a scheduled photo back through the Page's scheduled-post listing | CC | -| **R-915** | Business & legal | P4 | **The Meta app `felhom.eu` is in development mode, so posts it makes are seen only by people with a role on the app.** READ 2026-10-08 (Meta docs, cited in the spike); not measured. MEASURED: development mode does not refuse posting (both test writes HTTP 200). Live needs display name, contact e-mail, a Terms of Service URL, an app icon, a category and the app purpose (privacy-policy and data-deletion URLs listed beside them). The robot's Page assignment, missing at first, was done by the operator the same day. | **WAITING-ON-OPERATOR** | R-813 (the Terms of Service URL) | Before real public posts: switch the app to Live in the Meta developer page. If nothing is done: posts stay invisible to the public. After Live: CC adds the Page link to the website footer (not before — a link to a Page nobody can read is worse than none) | operator | +| **R-915** | Business & legal | P4 | **The Meta app `felhom.eu` is in development mode, so posts it makes are seen only by people with a role on the app.** READ 2026-10-08 (Meta docs, cited in the spike); not measured. MEASURED: development mode does not refuse posting (both test writes HTTP 200). Live needs display name, contact e-mail, a Terms of Service URL, an app icon, a category and the app purpose (privacy-policy and data-deletion URLs listed beside them). The robot's Page assignment, missing at first, was done by the operator the same day. | **WAITING-ON-OPERATOR** | R-813 — **UNBLOCKED 2026-10-09**: the Terms of Service URL now exists | Operator, one click job: Meta app → Basic settings → **Privacy Policy URL** = `https://felhom.eu/adatkezeles`, **Terms of Service URL** = `https://felhom.eu/feltetelek`. The Live switch stays a separate operator decision. If nothing is done: posts stay invisible to the public | operator | | **R-916** | Business & legal | P4 | **The logo has no usable vector master: `website/assets/logo.svg` sets „felhom.eu" as live text in the fonts „M+ 2c" and „Vremena Grotesk", which DooPlex does not have, so every renderer here draws other letters.** SEEN 2026-10-08 (Facebook pictures task): librsvg drew the lettering in DejaVu; `fc-match` resolves the family to DejaVu Sans. The PNG (645 x 408) is the only faithful copy, which caps every picture made from it at about that size (`marketing/facebook/README.md`). | **WAITING-ON-OPERATOR** | the machine with the fonts | In Inkscape on that machine: select the lettering → Path → Object to Path → save as `website/assets/logo-master.svg`; then `marketing/facebook/build.py` can use it. If nothing is done: the PNG stays the master; larger prints will be soft | operator | -| **R-917** | Business & legal | P4 | **`COPY.md` §2, the Page's longer description (867 characters), has nowhere to go: Facebook's current Pages experience has no long-description field at all.** FOUND 2026-10-08 (Page setup task, `audits/facebook-page-setup-2026-10-08/`). Looked in four places, all on the live Page as its admin: the Page's „Névjegy" tab (Rövid áttekintés / Személyes adatok / Részletek — only a 255-character „Bemutatkozás" and the pinned category), Business Suite's „Oldal módosítása" dialog (profile picture, cover, Bemutatkozás, category, phone, e-mail, address, website, social links — and nothing else), Facebook settings → „Oldal adatai" (redirects to the same Névjegy tab) and settings → „Oldal beállítása" (name, access, type, history, status, recommendation, messaging, data sharing). MEASURED by Graph with the Page token: `description`, `general_info` and `bio` all read `null`. Writing `description` by API would need `pages_manage_metadata`; the robot key's scopes are `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile`, and the task's fences forbid adding a permission. So §2 is written, reviewed and unplaceable. **Options for the operator:** (a) leave §2 unused and let the 99-character intro plus the website carry it; (b) shorten §2 to ≤ 255 characters and make it the „Bemutatkozás" instead of §1 — but §1 was written for exactly that slot, so this is really „rewrite one of the two"; (c) publish §2 as the Page's first pinned post once the app is Live (R-915), which is where a long text actually gets read; (d) ask Meta support whether the field still exists for this Page type. Recommended (c) — the text reads like a post already. | **WAITING-ON-OPERATOR** | the choice a/b/c/d; (c) also waits on R-915 | Pick a/b/c/d. If nothing is done: §2 stays in `COPY.md` unused and the Page carries only the 99-character intro | operator | +| **R-917** | Business & legal | P4 | **`COPY.md` §2, the Page's longer description (867 characters), has nowhere to go: Facebook's current Pages experience has no long-description field at all.** FOUND 2026-10-08 (Page setup task, `audits/facebook-page-setup-2026-10-08/`). Looked in four places, all on the live Page as its admin: the Page's „Névjegy" tab (Rövid áttekintés / Személyes adatok / Részletek — only a 255-character „Bemutatkozás" and the pinned category), Business Suite's „Oldal módosítása" dialog (profile picture, cover, Bemutatkozás, category, phone, e-mail, address, website, social links — and nothing else), Facebook settings → „Oldal adatai" (redirects to the same Névjegy tab) and settings → „Oldal beállítása" (name, access, type, history, status, recommendation, messaging, data sharing). MEASURED by Graph with the Page token: `description`, `general_info` and `bio` all read `null`. Writing `description` by API would need `pages_manage_metadata`; the robot key's scopes are `read_insights, pages_show_list, business_management, pages_read_engagement, pages_read_user_content, pages_manage_posts, pages_manage_engagement, public_profile`, and the task's fences forbid adding a permission. So §2 is written, reviewed and unplaceable. **Options for the operator:** (a) leave §2 unused and let the 99-character intro plus the website carry it; (b) shorten §2 to ≤ 255 characters and make it the „Bemutatkozás" instead of §1 — but §1 was written for exactly that slot, so this is really „rewrite one of the two"; (c) publish §2 as the Page's first pinned post once the app is Live (R-915), which is where a long text actually gets read; (d) ask Meta support whether the field still exists for this Page type. Recommended (c) — the text reads like a post already. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | posting starts — which waits on R-915 (the Live switch) | When posting starts: publish `COPY.md` §2 (the longer description) as the first pinned post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | | **R-919** | Business & legal | P3 | **On a phone the Facebook Page cuts the left edge of the cover: the „s” of „saját szabályaid” and the „f” of „felhom.eu” are gone.** MEASURED 2026-10-08 on the live Page in Chrome DevTools device mode, Pixel 9 (412 × 924, mobile user agent, after a reload so Facebook serves the mobile bundle): `audits/facebook-page-setup-2026-10-08/C2-phone-headline-cut-closeup.png`. The mobile Page header is **412 × 274 = 1,504:1**, so Facebook keeps our cover's full height and shows only the centre **938 px of its 1640 px width (57,2 %)** — **351 px cut from each side**. `marketing/facebook/build.py` builds to a safe area of the centre **1028 × 544** (306 px clear of each edge), which is **45 px wider per side than the phone actually shows**; the light text in `out/cover-c.png` runs from x 333 to x 997, and the left crop edge is x 351, so the first **18 px** of the text are cut. Covers A and B are built from the same safe area and will have the same edge. Two further facts this measurement establishes: **Meta's own help page is wrong about its own rendering** — it states the mobile cover is 2,4:1 where the Page header measures 1,504:1 — and the mobile profile circle is far bigger than assumed (172 px, centred, overlapping the bottom 112 px of the 274 px cover, i.e. source x 637–1030 × y 369–624 is hidden). Not re-cropped on Facebook, per the task's fence. **-- 2026-10-09, FIXED in the build:** `marketing/facebook/build.py` now takes the phone view from the measurement (`PHONE_HDR = (412, 274)` -> the centre 938 px), so SAFE is (391, 40)-(1249, 584) and the phone profile circle is the measured CENTRED box (637, 369, 393) rather than a left-anchored one. Every cover is drawn in a derived `BAND` (408, 48)-(1249, 340), and a `cap` check holds each headline's capital at >= 4 % of the cover height. The red-proof runs on EVERY build (`control_old_window`): it draws the headline where the old 640 x 360 assumption put it, x 328, and the check must reject it -- the phone's crop edge is x 351, so 23 px were cut. Against the three covers as committed at `a76207945e` the new check convicted 3 of 3 (A 23/22 px over the left/right edges, B 63/58 px plus 1017 content pixels under the phone circle, C 63/82 px plus 1778). The profile pictures are untouched -- sha256 identical before and after. **-- 2026-10-09 (operator refinements, same day):** the profile picture now carries the logo MARK only (the lettering was unreadable at 176 px; the mark grew 69 % -> 76 % of the circle, canvas 932 -> 648), and the covers set the headline the way `site.css` sets `.page-index .hero-text h1` (Bold 700, letter-spacing -0.03em, not ExtraBold 800 untracked) with „felhom.eu” drawn from the logo's OWN lettering instead of typed. No geometry changed; every R-919 check and the red-proof stand. **-- 2026-10-09 (second measurement):** a phone has TWO views and they disagree. SIGNED IN the sides are cut (confirmed on the operator's REAL phone, Chrome/Android: the window solves to x 351..1298 against the emulator's 351..1289 - the left edge to the pixel). SIGNED OUT the FULL width is shown but the cover is top-anchored and only the top 525 px survives (the bottom 99 px is cut; the file's blue top rule is still visible, which is how the side was established), with a much bigger, higher circle at x 486..1150 from y 232. `build.py` now carries both views, models the circles as DISCS rather than rectangles running to the bottom, and splits the artwork into a READ layer (must survive every view) and a DECOR layer (may be cropped or covered; the build reports the cost - B 39 %, C 62 %). The two-view geometry convicted all three then-current covers before the redraw (A 908 px under a circle, B 1715, C 1962). Covers redrawn: C is the operator's laptop idea with the dashboard at 640 px (was 370), B's motif grown to match. **-- 2026-10-09 (the APP measured):** the operator checked the live Page in Facebook Lite and in Chrome on his phone. Solved against the laptop frame, both give a visible window of x 349..1290 / 349..1291 - the LITE APP CROPS EXACTLY LIKE SIGNED-IN MOBILE WEB, and both agree with the emulator's 351..1289. Their circle is at x 645..1021 from y 451, LOWER than the emulator's 369, so that figure was pessimistic rather than wrong. Five views measured; the signed-out one stays the binding constraint. Cover C redrawn to the operator's layout (wordmark 88 px on top, gap, catchphrase) - one line, not his two, because two measured 392 text pixels behind the signed-out circle („saját szabályaid” read „saját szab”) and sizing them to fit drops the capital to the 25 px floor. | **VERIFY -- rebuilt on `main` 2026-10-09. The app IS now measured and the cover renders correctly there; what is left is the operator's look at the NEW cover in the app after uploading it.** | — | Operator: upload the rebuilt cover-c (and the profile picture if not already), then confirm in the Facebook app that the wordmark and the catchphrase are whole. Close on that word | CC | -| **R-920** | Business & legal | P4 | **The Messenger „Gyakori kérdések" automation does not exist for this Page, so `COPY.md` §5 — four questions with answers condensed from `gyik.html` — has nowhere to go.** FOUND 2026-10-09 (Page details task, `audits/facebook-page-details-2026-10-09/`). SEARCHED, not assumed absent: the create-automation catalogue („Az összes automatizálás") holds exactly THREE templates — Automatikus válasz, Távolléti üzenet, A megválaszolatlan üzenetek azonosítása (`B5-no-faq-template-all-three.jpg`); the template search for „kérdés" answers **„Nincs a keresésnek megfelelő automatizálási sablon."** while the POSITIVE CONTROL „üzenet" returns two, so the search works and the term genuinely misses; the existing instant-reply automation carries only channel, message and media — no FAQ and no quick replies; and the business-portfolio settings have no messaging/FAQ entry. The copy is written, sourced line by line to `gyik.html` and committed as `marketing/facebook/COPY.md` §5, ready to paste unchanged the day the feature appears. **Same shape as R-917** (§2 has nowhere to go), and the same cause: Meta removed a Page field this project had planned copy for. **Options for the operator:** (a) leave §5 unused until Meta brings the feature back; (b) fold the four answers into the Messenger welcome message (§3) — it holds 500 characters and today uses 120, so one or two would fit, not four; (c) publish them as a pinned FAQ post once the app is Live (R-915); (d) ask Meta support whether the FAQ automation still exists for this Page type. Recommended (a) with (c) later — the welcome message stays short, and the website's own `gyik.html` already answers these. | **WAITING-ON-OPERATOR** | the choice a/b/c/d; (c) also waits on R-915 | Pick a/b/c/d. If nothing is done: §5 stays in `COPY.md` unused and Messenger answers with the welcome message alone | operator | +| **R-920** | Business & legal | P4 | **The Messenger „Gyakori kérdések" automation does not exist for this Page, so `COPY.md` §5 — four questions with answers condensed from `gyik.html` — has nowhere to go.** FOUND 2026-10-09 (Page details task, `audits/facebook-page-details-2026-10-09/`). SEARCHED, not assumed absent: the create-automation catalogue („Az összes automatizálás") holds exactly THREE templates — Automatikus válasz, Távolléti üzenet, A megválaszolatlan üzenetek azonosítása (`B5-no-faq-template-all-three.jpg`); the template search for „kérdés" answers **„Nincs a keresésnek megfelelő automatizálási sablon."** while the POSITIVE CONTROL „üzenet" returns two, so the search works and the term genuinely misses; the existing instant-reply automation carries only channel, message and media — no FAQ and no quick replies; and the business-portfolio settings have no messaging/FAQ entry. The copy is written, sourced line by line to `gyik.html` and committed as `marketing/facebook/COPY.md` §5, ready to paste unchanged the day the feature appears. **Same shape as R-917** (§2 has nowhere to go), and the same cause: Meta removed a Page field this project had planned copy for. **Options for the operator:** (a) leave §5 unused until Meta brings the feature back; (b) fold the four answers into the Messenger welcome message (§3) — it holds 500 characters and today uses 120, so one or two would fit, not four; (c) publish them as a pinned FAQ post once the app is Live (R-915); (d) ask Meta support whether the FAQ automation still exists for this Page type. Recommended (a) with (c) later — the welcome message stays short, and the website's own `gyik.html` already answers these. | **DEFERRED — operator chose (c) on 2026-10-09:** park the text and publish it as a post once posting starts. Not a defect, and not waiting on CC | posting starts — which waits on R-915 (the Live switch) | When posting starts: publish `COPY.md` §5 (the four Messenger FAQ answers) as one later post. If nothing is done: the text stays in `COPY.md` unused, which the operator has accepted | operator | ## Process & tooling — 23 rows (P3 3, P4 20) diff --git a/documentation/legal/DRAFT-adatkezelesi-tajekoztato.md b/documentation/legal/DRAFT-adatkezelesi-tajekoztato.md index 3e351168..e63c34c9 100644 --- a/documentation/legal/DRAFT-adatkezelesi-tajekoztato.md +++ b/documentation/legal/DRAFT-adatkezelesi-tajekoztato.md @@ -1,5 +1,7 @@ # DRAFT — Adatkezelési tájékoztató (Felhom) +> **Superseded for the closed test by `adatkezelesi-tajekoztato-1.0.md` (published 2026-10-09 at https://felhom.eu/adatkezeles); this draft remains the base for the full version.** + > **English summary.** First draft of the Felhom privacy notice, written 2026-10-08 for R-813. NOT > published, NOT legal advice, pending lawyer review (R-802). It lists what personal data Felhom > handles, where, by whom and for how long — built from the architecture documents and the code, diff --git a/documentation/legal/DRAFT-aszf.md b/documentation/legal/DRAFT-aszf.md index 486e3a4d..d106d38b 100644 --- a/documentation/legal/DRAFT-aszf.md +++ b/documentation/legal/DRAFT-aszf.md @@ -1,5 +1,7 @@ # DRAFT — Általános Szerződési Feltételek (Felhom) +> **Superseded for the closed test by `feltetelek-1.0.md` (published 2026-10-09 at https://felhom.eu/feltetelek) — only its service description was used; this draft remains the base for the full ASZF, which waits for the company and the lawyer (R-802, R-809).** + > **English summary.** First draft of the Felhom general terms (ÁSZF), written 2026-10-08 for > R-813/R-809. NOT published, NOT legal advice, pending lawyer review (R-802). It is a structured > skeleton: the service description is drawn from the architecture documents (each cited in an HTML diff --git a/documentation/legal/DRAFT-kapcsolat-hozzajarulas.md b/documentation/legal/DRAFT-kapcsolat-hozzajarulas.md index 15ac54e1..3c62fd9f 100644 --- a/documentation/legal/DRAFT-kapcsolat-hozzajarulas.md +++ b/documentation/legal/DRAFT-kapcsolat-hozzajarulas.md @@ -1,5 +1,7 @@ # DRAFT — A kapcsolatfelvételi űrlap hozzájárulási szövege +> **Superseded for the closed test: the proposed consent text was applied to website/kapcsolat.html and website/en/contact.html on 2026-10-09, with the placeholders resolved (no company — the operator as a private person; /adatkezeles is the live path, measured).** + > **English summary.** A proposed replacement for the contact form's consent checkbox text > (`website/kapcsolat.html:122-128`), written 2026-10-08 for R-813. NOT applied to the website, > NOT legal advice, pending lawyer review (R-802). The current text names no controller, no diff --git a/documentation/legal/README.md b/documentation/legal/README.md index ea3028b8..8698d700 100644 --- a/documentation/legal/README.md +++ b/documentation/legal/README.md @@ -1,7 +1,27 @@ -# Legal drafts — NOT published, NOT legal advice +# Legal texts — the closed-test set IS published; the rest are drafts. NOT legal advice. -**Status: first drafts, written 2026-10-08 by Claude Code on the operator's request (Part E of that -night's brief). Pending lawyer review. Nothing here is on the website.** +**Status, 2026-10-09: the closed-test set is LIVE.** On the operator's ruling of 2026-10-09 — *no +company exists yet; publish a closed-test set now; the full ÁSZF, the impresszum and the lawyer's +review wait for the company and the first paying customer* — two pages went onto the website: + +| Published | Live at | Source of record | +|---|---|---| +| Privacy notice | | `adatkezelesi-tajekoztato-1.0.md` | +| Closed-test terms | | `feltetelek-1.0.md` | + +The two `…-1.0.md` files are **derived from the published HTML** so the record cannot drift from the +page. Every page of the website now links both in its footer, and the contact form's consent text was +replaced with the honest one. + +**Still not published and still pending the lawyer (R-802):** the full ÁSZF, the impresszum (it needs +company data that does not exist) and any English translation of the legal texts. + +**Not legal advice.** These texts were written by an AI assistant from the system's own documents. +A lawyer decides what is legally required, what legal basis applies, and what the final text says. +They were published **before** that review, deliberately, on the operator's ruling above. + +**Status of the drafts: first drafts, written 2026-10-08 by Claude Code on the operator's request +(Part E of that night's brief). Pending lawyer review.** These files are working drafts for register rows **R-813** (the website collects personal data but publishes no privacy notice, no terms and no imprint — owner: operator) and **R-802** (the lawyer's @@ -11,6 +31,8 @@ review before the first paying customer — owner: operator). The wider set of b | File | What it is | |---|---| +| `adatkezelesi-tajekoztato-1.0.md` | **PUBLISHED** — the privacy notice as it stands on the website | +| `feltetelek-1.0.md` | **PUBLISHED** — the closed-test terms as they stand on the website | | `DRAFT-aszf.md` | Általános Szerződési Feltételek — a structured skeleton; business terms are placeholders | | `DRAFT-adatkezelesi-tajekoztato.md` | Adatkezelési tájékoztató — built from the architecture documents and the code, each line cited | | `DRAFT-impresszum.md` | Impresszum — placeholders only | @@ -27,6 +49,7 @@ review before the first paying customer — owner: operator). The wider set of b must change with it. - **Nothing is published until the operator says so.** Publishing means a website change (`website/` is served from `main` by git-sync), a link from every page footer, and the contact form's consent - text replaced — none of which is done here. + text replaced. All three were done on 2026-10-09 **for the closed-test set only**, on the operator's + word. The ÁSZF and the impresszum are still unpublished, and the rule still holds for them. - Each draft ends with the list of points the lawyer must check and every point where the draft had to guess. diff --git a/documentation/legal/adatkezelesi-tajekoztato-1.0.md b/documentation/legal/adatkezelesi-tajekoztato-1.0.md new file mode 100644 index 00000000..be51c572 --- /dev/null +++ b/documentation/legal/adatkezelesi-tajekoztato-1.0.md @@ -0,0 +1,278 @@ +# Adatkezelesi tajekoztato — AS PUBLISHED, 1.0 + +> **This is the text as published**, derived from `website/adatkezeles.html` on 2026-10-09 so the record cannot +> drift from the page. Live at . Base draft: `DRAFT-adatkezelesi-tajekoztato.md` (kept). +> **Not legal advice** — written by an AI assistant from the system's own documents; a lawyer +> still decides what is legally required (R-802). Published before that review on the +> operator's ruling of 2026-10-09. + +--- + +**Zárt teszt — 1.0 verzió, hatályos: 2026. október 9.** + +## 1. Ki kezeli az adataidat? + + + +- **Név:** Nagyfenyvesi Viktor — magánszemélyként. A Felhom ma még nem cég. +- **E-mail:** [info@felhom.eu](mailto:info@felhom.eu) +- **Adatvédelmi tisztviselő:** nincs kijelölve. + +Az alábbiakban: **Felhom** vagy **mi**. + +## 2. Kétféle szerepünk van + +**Az egyik:** a weboldal látogatóinak, a kapcsolatfelvételi űrlap kitöltőinek és +a zárt teszt résztvevőinek adatait mi kezeljük. Erről szól ez a tájékoztató. + +**A másik:** a nálad lévő szerveren tárolt adatok (fényképek, dokumentumok, +alkalmazásadatok) a tieid. Azokat mi csak üzemeltetjük, felügyeljük és mentjük. +Ahol ez a tájékoztató ezeket érinti (mentés, hozzáférés), azt azért írjuk le, hogy lásd, +mi történik velük. Külön adatfeldolgozási megállapodás a zárt teszt alatt még nincs. + + + +## 3. A weboldal (felhom.eu) + +### 3.1 Sütik: egyet sem használunk + +A weboldal **egyetlen sütit sem helyez el** a böngésződben, és nem használ +helyi tárolót sem. Ezt 2026. október 9-én megmértük: a böngészőben a sütik, a +localStorage és a sessionStorage +üresek maradtak az oldal betöltése és a látogatottság-mérés lefutása után is, és egyetlen +válasz sem küldött sütit. + + + +### 3.2 Látogatottság-mérés + +Azt mérjük, hány oldalmegtekintés történik. Az eszköz az **Umami**, amelyet +**mi magunk üzemeltetünk** a saját szerverünkön (a `stats.felhom.eu` +címen). Az adatok nem jutnak külső elemző céghez. + +A böngésződ ezeket küldi el egy oldalmegtekintéskor (megmérve, 2026. október 9.): + +- a weboldal saját azonosítója (nem a tiéd), +- a képernyő mérete, +- a böngésző nyelve, +- az oldal címe és webcíme, +- a hivatkozó oldal, ha máshonnan érkeztél. + +Ezen felül a kiszolgálónk — mint minden webkiszolgáló — látja az **IP-címedet** +és a böngésződ azonosítóját; a program ezekből országot és böngészőtípust állapít meg. +A böngésződ nem küld rólad egyedi azonosítót. + + + +**Meddig:** a mérőprogramban ma **nincs beállítva automatikus törlés**, +tehát a statisztika határozatlan ideig megmarad. Ezt őszintén leírjuk, mert nem akarunk olyan +határidőt ígérni, amit semmi nem tart be. + + + +**Jogalap:** jogos érdek (GDPR 6. cikk (1) f) — hogy lássuk, használják-e az oldalt. + +### 3.3 Szervernaplók + +A weboldalt kiszolgáló program (nginx) a kéréseket naplózhatja, köztük az IP-címedet. Külön +naplózási vagy megőrzési beállítást nem adtunk meg, tehát az alapértelmezés működik, és +**megőrzési időt erre sem állítottunk be**. + + + +### 3.4 Külső tartalom és a DNS + +A weboldal nem tölt be külső betűtípust, külső szkriptet, beágyazott videót vagy hirdetést. +A saját mérőprogramunkon kívül semmi nem töltődik be máshonnan. + + + +A `felhom.eu` névfeloldását (DNS) a **Cloudflare** végzi, de +**csak névfeloldást**: a weboldal forgalma nem halad át a Cloudflare-en. +Ezt megmértük — a `felhom.eu` nyilvános címbejegyzése a mi saját kiszolgálónkra +mutat, nem a Cloudflare hálózatára. + + + +## 4. Kapcsolatfelvételi űrlap és e-mail + +**Mit adsz meg:** a nevedet, az e-mail-címedet, a választott tárgyat, az üzenetet +és a csatolt fájlokat (legfeljebb 5 fájl, összesen 20 MB). + + + +**Mire használjuk:** hogy válaszoljunk neked. + +**Hogyan jut el hozzánk:** a böngésződ elküldi a saját kis programunknak, az +e-mailt a **Resend** levélküldő szolgáltatás továbbítja az +`info@felhom.eu` címre, ahová a leveleket a **Cloudflare Email Routing** +viszi tovább egy **Gmail**-postafiókba. Ott olvassuk el. Ha közvetlenül írsz az +`info@felhom.eu` címre, ugyanez az út érvényes, a Resend nélkül. + + + +**Meddig:** amíg a megkeresésed le nem zárul, és utána is, amíg a levelezésünkben +marad. **Automatikus törlés ma nincs beállítva.** Ha szeretnéd, hogy töröljük a +leveledet, írj az [info@felhom.eu](mailto:info@felhom.eu) címre, és töröljük. + +**Jogalap:** a hozzájárulásod (GDPR 6. cikk (1) a). Ha árajánlatot kérsz, a +szerződéskötést megelőző lépés is lehet a jogalap (6. cikk (1) b). + +## 5. A Facebook-oldalunk és a Messenger + +Van egy Facebook-oldalunk: `facebook.com/felhom.eu`. Ha meglátogatod vagy írsz +nekünk a Messengeren, a Meta a saját szabályai szerint kezeli az adataidat — ezt mi nem tudjuk +megváltoztatni. + +Az oldal **látogatottsági statisztikájáért** („Oldalelemzések") a Meta és mi +**közös adatkezelők** vagyunk a GDPR 26. cikke szerint. Mi csak összesített +számokat látunk, azt nem, hogy ki járt az oldalon. A Messengeren küldött üzenetedet +elolvassuk, és ugyanúgy kezeljük, mint egy e-mailt. + +- A Meta kiegészítése az Oldalelemzésekről: +[facebook.com/legal/terms/page_controller_addendum](https://www.facebook.com/legal/terms/page_controller_addendum) +- A Meta adatkezelési szabályzata: +[facebook.com/privacy/policy](https://www.facebook.com/privacy/policy/) + + + +## 6. A zárt teszt résztvevőinek adatai a központi rendszerünkben + +A szervered rendszeresen jelentést küld a központi rendszerünknek +(`hub.felhom.eu`), hogy lássuk, minden rendben van-e. Ezeket tároljuk: + +- **Azonosítód, neved, domained, e-mail-címed, nyelved** — amíg törölünk téged a rendszerből. + +- **A szerver állapotjelentései** (gépnév, processzor-, memória- és lemezhasználat, hőmérséklet, +a telepített alkalmazások neve és állapota, a mentések állapota) — **90 nap**. + +- **Események** (például „a mentés nem sikerült") — **90 nap**. + +- **Alkalmazásonkénti erőforrás-statisztika** — **90 nap**. + +- **Alkalmazásnaplókból kiszűrt hibaüzenetek**, kitakarva — az utolsó előfordulás után **30 nap**. + +- **Naplórészlet, csak ha külön kérjük**, kitakarva — alkalmazásonként a legutóbbi kettő, és a törlésedkor törlődik. + +- **Diagnosztikai naplócsomag, csak külön kérésre** — **72 óra**. + +- **A kiküldött értesítések naplója** — a törlésed után **1 évig**, aztán törlődik. +Amíg aktív vagy, erre nincs megőrzési idő. + +- **A visszaállítások és a szervertörlés naplója** — ezt **nem töröljük**, hogy utólag is elszámoltatható legyen, ki mit tett. + +- **A mentésed titkosító kulcsa, a helyreállító kódoddal lezárva** — amíg törölünk téged. + +- **A szerver vészhelyzeti konzoljelszava, titkosítva** — amíg a szervert töröljük. + + +**A kulcsletétről, egyszerűen:** a mentésed kulcsát csak lezárt formában tároljuk. +Kinyitni csak a **helyreállító kódoddal** lehet, ami nálunk nincs meg. Ha elveszíted +ezt a kódot, a távoli mentésed nem nyitható ki — mi sem tudjuk kinyitni. + + + +A központi rendszer adatbázisáról éjjelente mentés készül, titkosítva, a távoli mentőszerverünkre. +Ott **14 napi és 8 heti** példány marad meg, a nálunk tárolt másolatban **8 heti**. +Ezért egy törölt résztvevő adatai a mentésekben eddig az ideig még megtalálhatók. + + + +**Jogalap:** a veled kötött megállapodás teljesítése (GDPR 6. cikk (1) b); a naplók megőrzésére jogos érdek (6. cikk (1) f). + +## 7. A szervered adatainak távoli mentése + +A szervereden lévő adatokról távoli mentés készül. **A mentés nálad, a szerveren +titkosítódik, mielőtt elhagyja az otthonodat.** Sem a tárhely üzemeltetője, sem mi nem +tudjuk elolvasni a tartalmát. + + + +- **Alkalmazásonkénti fájlmentés** — **Hetzner Storage Box**, +Falkenstein, Németország. 7 napi, 4 heti és 6 havi példány marad meg. A fiókod +visszaállításakor törlődik. + +- **Teljes szervermentés** — a saját távoli mentőszerverünkre, amely a +**Hetzner Cloud** nürnbergi (Németország) telephelyén fut. A legutóbbi 2 heti +példány marad meg; a törlésedkor törlődik. + +- **Ennek másolata a saját szerverünkön** — továbbra is titkosítva, 8 heti példány. +A törlésed után **legfeljebb 30 napon belül** törlődik; ezt egy naponta futó +feladat végzi. + + +## 8. Hozzáférés a szerveredhez + +Őszintén: **rendszergazdai (root) hozzáférésünk van minden szerverhez, amit kezelünk.** +Ez kell a frissítésekhez, a mentések ellenőrzéséhez és a hibák javításához. Ezzel a hozzáféréssel +a szervereden tárolt adatok elérhetők. Csak üzemeltetésre és hibaelhárításra használjuk. + + + +A fájljaid és az alkalmazásaid adatai **nem kerülnek át** a központi rendszerbe. +Oda csak a 6. pontban felsorolt állapotadatok jutnak el, és — külön kérésre, kitakarva — +naplórészletek. + + + +## 9. Az alkalmazásaid elérése az interneten + +A szervereden futó alkalmazásokat a **Cloudflare Tunnel** szolgáltatáson keresztül +lehet elérni az internetről. **A titkosított kapcsolat a Cloudflare hálózatán végződik**, +vagyis ezeknek az alkalmazásoknak a forgalma áthalad a Cloudflare rendszerén. (Ez más, mint a +weboldalunk: a felhom.eu forgalma nem megy át rajta — lásd a 3.4 pontot.) + + + +## 10. Kik látják még az adataidat + +- **Resend** — e-mail-küldés. Látja: a címzett e-mail-címét és a levél tartalmát. +- **Cloudflare** — a felhom.eu névfeloldása; a @felhom.eu címre érkező levelek +továbbítása; az alkalmazásaid internetes elérése. Látja: a továbbított leveleket és az +alkalmazások forgalmát. +- **Google (Gmail)** — az `info@felhom.eu` postafiókja. Látja: a +beérkező leveleket, köztük az űrlap üzeneteit. +- **Hetzner** (Németország) — a titkosított mentések tárolása. Csak titkosított +adatot lát. +- **Meta** — csak akkor, ha a Facebook-oldalunkat használod (5. pont). + +A Resend, a Cloudflare, a Google és a Meta nemzetközi szolgáltatók, amelyek adatot az Európai +Gazdasági Térségen kívül is kezelhetnek. Hogy pontosan hol és milyen garanciával, azt a saját +adatkezelési tájékoztatójuk írja le. + +## 11. A jogaid + +Bármikor kérheted tőlünk, hogy: + +- **megmondjuk, milyen adatot kezelünk rólad** (hozzáférés), +- **javítsuk**, ha valami hibás (helyesbítés), +- **töröljük** az adataidat (törlés), +- **korlátozzuk** a kezelését, amíg egy vitát tisztázunk, +- **odaadjuk neked** géppel olvasható formában (adathordozhatóság), +- **tiltakozz** a jogos érdeken alapuló kezelés ellen, +- **visszavond a hozzájárulásodat** — ettől a korábbi kezelés nem lesz jogellenes. + +Hogyan kérd: írj az [info@felhom.eu](mailto:info@felhom.eu) címre. +**Egy hónapon belül válaszolunk** (GDPR 12. cikk (3)). + +## 12. Ha panaszod van + +Panasszal a felügyeleti hatósághoz fordulhatsz: + +- **Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)** +- Cím: 1055 Budapest, Falk Miksa utca 9-11. +- Postacím: 1363 Budapest, Pf.: 9. +- Telefon: +36 (1) 391 1400 +- E-mail: [ugyfelszolgalat@naih.hu](mailto:ugyfelszolgalat@naih.hu) +- Web: [naih.hu](https://naih.hu) + + + +Bírósághoz is fordulhatsz. + +## 13. A tájékoztató változásai + +Ha változik, amit csinálunk, ezt a tájékoztatót is módosítjuk, és a tetején lévő verziószámot +megemeljük. A zárt teszt résztvevőinek a lényeges változásról e-mailt küldünk. + +A szolgáltatás feltételeit a [Feltételek](/feltetelek) oldal írja le. diff --git a/documentation/legal/feltetelek-1.0.md b/documentation/legal/feltetelek-1.0.md new file mode 100644 index 00000000..e47d88b0 --- /dev/null +++ b/documentation/legal/feltetelek-1.0.md @@ -0,0 +1,120 @@ +# A zart teszt feltetelei — AS PUBLISHED, 1.0 + +> **This is the text as published**, derived from `website/feltetelek.html` on 2026-10-09 so the record cannot +> drift from the page. Live at . Base draft: `DRAFT-aszf.md (service description only)` (kept). +> **Not legal advice** — written by an AI assistant from the system's own documents; a lawyer +> still decides what is legally required (R-802). Published before that review on the +> operator's ruling of 2026-10-09. + +--- + +**Zárt teszt — 1.0 verzió, hatályos: 2026. október 9.** + +## 1. Ki vagyunk + + + +A Felhomot **Nagyfenyvesi Viktor** magánszemélyként működteti. A Felhom ma még +**nem cég**. Elérhetőség: [info@felhom.eu](mailto:info@felhom.eu). + +## 2. Mi ez + +Ez egy **ingyenes zárt teszt** egy otthoni szerver szolgáltatásról. Néhány magyar +háztartással próbáljuk ki, hogy működik-e a gyakorlatban. Nem termék, amit megvettél — egy +teszt, amiben részt veszel. + +## 3. Mit kapsz a teszt alatt + + + +- Egy **otthoni szervert beállítunk** nálad, és működőképes állapotba hozzuk. + +- **Alkalmazásokat telepítünk** rá a katalógusunkból, a vezérlőpulton keresztül. + +- Az alkalmazások **elérhetők lesznek az interneten** is. + +- **Figyeljük a szervert.** Ha baj van, szólunk. + +- **Mentés készül** több szinten: a szerveren, és titkosítva egy távoli tárhelyen is. +A részleteket az [Adatkezelési tájékoztató](/adatkezeles) 7. pontja írja le. + +- **Frissítjük** az alkalmazásokat és a rendszert, jellemzően éjszaka, egy általad +beállítható időablakban. + + +## 4. Mit nem ígérünk + +Ezt fontos elolvasni, mert egy teszt nem ugyanaz, mint egy kész szolgáltatás. + +- **Nincs díj** a teszt alatt — se tőled, se felénk. Árat nem ajánlunk és nem kérünk. +- **Nem ígérünk rendelkezésre állást.** A szerver leállhat, és előfordulhat, hogy nem +vesszük észre azonnal. +- **Nem ígérünk válaszidőt.** Igyekszünk gyorsan segíteni, de határidőt nem vállalunk. +- **Nem garantáljuk, hogy minden fájl visszaállítható.** Mentés készül, és teszteljük +is, de egy teszt alatt bármi elromolhat. + +**Ezért kérünk valamit:** amit nem veszíthetsz el, abból tarts meg egy saját +másolatot magadnál is. Ne a teszt legyen az egyetlen helye. + +## 5. Hozzáférünk a szerveredhez + +**Rendszergazdai (root) hozzáférésünk van a szerverhez.** Ez kell a frissítésekhez, +a mentés ellenőrzéséhez és a hibák javításához. Ezzel a szerveren lévő adatok elérhetők. Csak +üzemeltetésre és hibaelhárításra használjuk. + + + +A veszélyes, adatvesztéssel járó műveletekhez a rendszerünk külön aláírást kér, és a szerver +maga kezdeményezi a kapcsolatot felénk. + + + +## 6. A mentésed kulcsa nálad van + +A távoli mentésed titkosítva készül. A kulcsát egy **helyreállító kód** zárja, amit +csak te ismersz — nálunk nincs meg, és nem tudjuk pótolni. **Ha elveszíted, a távoli +mentésed nem nyitható ki.** Tedd el jól. + + + +## 7. Az alkalmazások nem a mieink + +A katalógusunkban mások által írt, nyílt forráskódú programok vannak. Ezeket nem mi adjuk el és +nem mi írtuk; mindegyikre a **saját licencfeltételei** vonatkoznak, és azok rád is +érvényesek. + + + +## 8. Az adataid a tieid + +A szervereden lévő adatok és alkalmazások a tieid. Nem tartjuk vissza őket: a teszt után is +visszaállíthatók a helyreállító kódoddal. + + + +## 9. Ha ki akarsz szállni + +**Bármikor abbahagyhatod**, indoklás nélkül. Írj egy e-mailt az +[info@felhom.eu](mailto:info@felhom.eu) címre, és leállítjuk. + +Ami ezután az adataiddal nálunk történik: + +- a teljes szervermentésed a mentőszerverünkön a törléseddel **törlődik**; +- ennek nálunk tárolt másolata **legfeljebb 30 napon belül** törlődik — ezt egy +naponta futó feladat végzi; + +- a kiküldött értesítések naplója a törlésed után **1 évig** marad meg, aztán törlődik; +- a visszaállítások és a szervertörlés naplóját **megőrizzük**, hogy utólag is +látható legyen, ki mit tett. + +A részletes lista az [Adatkezelési tájékoztató](/adatkezeles) 6. és 7. pontjában van. + +## 10. Ha változnak a feltételek + +Ezek a feltételek változhatnak. Ha lényeges változás lesz, a teszt résztvevőinek +**előtte e-mailt küldünk**, és a tetején lévő verziószámot megemeljük. + +## 11. Kapcsolat + +[info@felhom.eu](mailto:info@felhom.eu) — adatkezelés: +[Adatkezelési tájékoztató](/adatkezeles). diff --git a/scripts/site_gates.py b/scripts/site_gates.py index 2808c995..f4e38d00 100644 --- a/scripts/site_gates.py +++ b/scripts/site_gates.py @@ -59,7 +59,11 @@ URL = {"index.html": "/", "alkalmazasok.html": "/alkalmazasok", "technologiak.ht os.path.join("en", "download.html"): "/en/download"} # Pages with no twin, BY NAME: the hidden prices page stays Hungarian only (brief 2026-10-08), and the 404 page # is served at whatever URL was wrong — it carries one English line instead of a twin. -NO_TWIN = {"szolgaltatasok-nonpublic.html", "404.html"} +# adatkezeles/feltetelek have NO English twin ON PURPOSE (2026-10-09, R-813): the legal texts are +# Hungarian only, and every English page's footer says so and links the Hungarian page. A twin would +# be an English legal text nobody has reviewed — worse than an honest pointer. If an English version +# is ever written and reviewed, move them into TWINS and add both URLs above. +NO_TWIN = {"szolgaltatasok-nonpublic.html", "404.html", "adatkezeles.html", "feltetelek.html"} PAGES = list(TWINS) + list(TWINS.values()) + sorted(NO_TWIN) EN_PAGES = set(TWINS.values()) diff --git a/website/404.html b/website/404.html index 639c4c9e..a51f0d1c 100644 --- a/website/404.html +++ b/website/404.html @@ -6,7 +6,7 @@ Az oldal nem található | Felhom.eu - + @@ -57,6 +57,7 @@ + + + +
+ + + +
+ +
+ + + + \ No newline at end of file diff --git a/website/alkalmazasok.html b/website/alkalmazasok.html index 6d46402f..4d696a0e 100644 --- a/website/alkalmazasok.html +++ b/website/alkalmazasok.html @@ -43,7 +43,7 @@ } - + @@ -1235,6 +1235,7 @@ diff --git a/website/assets/site.css b/website/assets/site.css index 325b348c..96394081 100644 --- a/website/assets/site.css +++ b/website/assets/site.css @@ -1,4 +1,4 @@ -/* ============================================================ +/* ============================================================ felhom.eu — site.css v1 (design system v2, TASK-D3) One shared stylesheet for all seven pages. Canonical tokens: documentation/design/design-system.md. Bump ?v= in the pages @@ -2069,3 +2069,17 @@ footer p { color: var(--text-2); font-size: 0.9rem; } .dash-shot figcaption { margin-top: 10px; color: var(--text-2); font-size: 0.95rem; line-height: 1.5; } .dash-shot figcaption strong { color: var(--text-1); } @media (max-width: 700px) { .dash-grid { grid-template-columns: minmax(0, 1fr); } } + +/* --- legal pages (adatkezeles, feltetelek): a readable prose column -------- */ +.legal { max-width: 760px; } +.legal h2 { font-size: 1.45rem; font-weight: 700; margin: 40px 0 14px; letter-spacing: -0.01em; } +.legal h3 { font-size: 1.1rem; font-weight: 600; margin: 26px 0 10px; color: var(--text-1); } +.legal p { color: var(--text-2); line-height: 1.75; margin-bottom: 14px; } +.legal ul { margin: 0 0 16px 22px; } +.legal li { color: var(--text-2); line-height: 1.75; margin-bottom: 9px; } +.legal strong { color: var(--text-1); } +.legal code { font-size: 0.93em; color: var(--text-1); } +.legal a { color: var(--blue); } +.legal-version { padding: 12px 16px; border: 1px solid var(--line); border-radius: var(--radius); } +.legal-callout { padding: 16px; border: 1px solid var(--blue); border-radius: var(--radius); } +.nowrap { white-space: nowrap; } diff --git a/website/biztonsagimentes.html b/website/biztonsagimentes.html index 76e1f9b1..5b0cc799 100644 --- a/website/biztonsagimentes.html +++ b/website/biztonsagimentes.html @@ -37,7 +37,7 @@ } - + @@ -264,6 +264,7 @@ - + @@ -1235,6 +1235,7 @@ diff --git a/website/en/backups.html b/website/en/backups.html index 3171f27e..5f81876f 100644 --- a/website/en/backups.html +++ b/website/en/backups.html @@ -37,7 +37,7 @@ } - + @@ -264,6 +264,7 @@ @@ -126,7 +126,7 @@
Your consent to the use of your details is needed.
@@ -174,6 +174,7 @@ diff --git a/website/en/download.html b/website/en/download.html index 275b5038..91250fc7 100644 --- a/website/en/download.html +++ b/website/en/download.html @@ -24,7 +24,7 @@ - + @@ -97,6 +97,7 @@ - + @@ -950,6 +950,7 @@ diff --git a/website/en/index.html b/website/en/index.html index 7bbcc285..d46ba498 100644 --- a/website/en/index.html +++ b/website/en/index.html @@ -54,7 +54,7 @@ } - + @@ -532,6 +532,7 @@ - + @@ -443,6 +443,7 @@ + + + +
+ + + +
+ +
+ + + + \ No newline at end of file diff --git a/website/gyik.html b/website/gyik.html index 407554ac..ffe8fb54 100644 --- a/website/gyik.html +++ b/website/gyik.html @@ -363,7 +363,7 @@ } - + @@ -950,6 +950,7 @@ diff --git a/website/index.html b/website/index.html index 0778ab6b..213a7d2c 100644 --- a/website/index.html +++ b/website/index.html @@ -54,7 +54,7 @@ } - + @@ -532,6 +532,7 @@ @@ -126,7 +126,7 @@
Az adatkezelési hozzájárulás szükséges.
@@ -174,6 +174,7 @@ diff --git a/website/letoltes.html b/website/letoltes.html index 2b39e748..afe7d7e3 100644 --- a/website/letoltes.html +++ b/website/letoltes.html @@ -24,7 +24,7 @@ - + @@ -97,6 +97,7 @@ - + @@ -443,6 +443,7 @@