Privacy Policy
Last updated 10 July 2026
Introduction
DataCrew Kft. (8220 Balatonalmádi, Kert utca 15., tax number: 27120352-2-19, company registration number: 1909520863) (hereinafter: Service Provider, data controller) carries out its data processing activities in accordance with the provisions set out in the following information notice.
On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (27 April 2016), we provide the following information.
This privacy notice governs the processing of data on the following website: https://metamorph.ad
The privacy policy is available at the following address: https://metamorph.ad/legal/privacy
Amendments to the privacy policy shall enter into force upon publication at the above address.
The data controller and their contact details
- Name
- DataCrew Kft.
- Registered office
- 8220 Balatonalmádi, Kert utca 15., Hungary
- [email protected]
- Telephone
- +36 70 544 6727
Definitions
- “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- “data processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, communication, transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- “data controller”: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, Union or Member State law may also determine the controller or specific criteria for the designation of the controller;
- “data processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
- “recipient”: a natural or legal person, public authority, agency or any other body to whom or to which personal data are disclosed, irrespective of whether they are a third party. Public authorities which may receive personal data in the framework of a particular inquiry shall not be regarded as recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
- “the data subject’s consent”: a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
- “data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
- “profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
- “third party”: a natural or legal person, public authority, agency or any other body which is not the data subject, the controller, the processor or those persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Principles relating to the processing of personal data
Personal data:
- must be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
- collection must be for specified, explicit and legitimate purposes, and they must not be processed in a manner incompatible with those purposes; in accordance with Article 89(1), further processing for archiving in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the original purpose (“purpose limitation”);
- they must be adequate and relevant in relation to the purposes of the processing and limited to what is necessary (“data minimisation”);
- they must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes of the processing, are erased or rectified without delay (“accuracy”);
- must be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for a longer period only if the processing is carried out in accordance with Article 89(1) for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, subject to the implementation of appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of data subjects (“storage limitation”);
- processing must be carried out in such a manner that appropriate technical or organisational measures are applied to ensure the appropriate security of personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage (“integrity and confidentiality”).
The data controller is responsible for compliance with the above and must be able to demonstrate such compliance (“accountability”).
The data controller declares that its data processing is carried out in accordance with the principles set out in this section.
Data processing related to the use of the service
1. The fact of data collection, the scope of the data processed and the purpose of data processing:
| Personal data | Purpose of data processing | Legal basis |
|---|---|---|
| Surname and first name | Required for establishing contact, using the service and issuing a valid invoice. | Article 6(1)(b) of the GDPR |
| Email address | To maintain contact and to authenticate you. | Article 6(1)(b) of the GDPR |
| Telephone number | Contact purposes, more efficient coordination of matters relating to invoicing. | Article 6(1)(b) of the GDPR |
| Billing name and address, VAT number | Issuing a valid invoice, as well as drawing up the contract, determining its content, amending it, monitoring its performance, and the enforcement of related claims. | Article 6(1)(c) of the GDPR (legal obligation: Section 169(2) of Act C of 2000 on Accounting) |
| Date of subscription/registration | Performance of a technical operation. | Article 6(1)(b) of the GDPR |
| IP address at the time of subscription/registration | Performance of a technical operation. | Article 6(1)(b) of the GDPR |
We only support Google sign-in and email magic links, so we never see or store a password. Card data is entered directly with Stripe and is never stored on our servers.
2. Data subjects: all data subjects registered on the website or using the service.
3. Duration of data processing, deadline for erasure of data: if any of the conditions set out in Article 17(1) of the GDPR apply, processing continues until the data subject requests erasure. The data controller shall inform the data subject electronically of the erasure of any personal data provided by the data subject, in accordance with Article 19 of the GDPR. If the data subject’s request for erasure also covers their email address, the data controller shall also delete the email address following the notification. This does not apply to accounting documents, as these must be retained for 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting. The data subject’s contractual data may be deleted upon expiry of the civil law limitation period, based on the data subject’s request for erasure.
Accounting documents (including general ledger accounts, analytical and detailed records) must be retained in a readable form for at least 8 years, in a manner that allows them to be retrieved by reference to the accounting records.
4. The identity of potential data controllers entitled to access the data, and the recipients of personal data: personal data may be processed by the data controller’s authorised staff, in accordance with the above principles.
5. Description of the data subjects’ rights regarding data processing:
- The data subject may request from the data controller access to, rectification, erasure or restriction of processing of personal data concerning them, and
- the data subject has the right to data portability and to withdraw consent at any time.
6. The data subject may request access to personal data, their erasure, rectification or restriction of processing, and data portability in the following ways:
- by post to 8220 Balatonalmádi, Kert utca 15.,
- by email to [email protected],
- by telephone on +36 70 544 6727.
7. Please note that
- the processing of your personal data is necessary for the performance of the contract,
- you are required to provide your personal data so that we can fulfil your order,
- failure to provide this data will result in the consequence that we will be unable to process your order.
Relayed event data
This section describes the core of the service: the Meta Pixel events that our snippet captures on our customer’s website and that we forward to Meta server-side via the Conversions API.
1. Fact of data collection, scope of data processed: the event name and timestamp, standard event parameters, the event identifier, the visitor’s IP address and user agent, the _fbp and _fbc browser identifiers, and — where the customer’s own pixel initialisation supplies them — the visitor’s email address and phone number for Meta’s advanced matching.
2. Scope of data subjects: the visitors of the website on which our customer has installed the Metamorph snippet.
3. Purpose of data collection: to relay conversion events to the customer’s Meta Pixel through the Meta Conversions API, and to report the results of that relay back to the customer.
4. Controller and processor. With regard to the event data collected on a customer’s website, the customer is the data controller and Metamorph acts as a data processor that forwards the data to Meta on the customer’s documented instruction. The customer is responsible for having a lawful basis for collecting that data and for informing their own visitors.
5. What we do not store:
- Any personal identifier used for Meta’s matching (email address, telephone number) is hashed with SHA-256 on our server before it leaves for Meta. We never write the plaintext value to storage.
- We do not store raw visitor personal data — no plaintext emails, phone numbers, names or addresses of the customer’s website visitors.
- We do not use hashed identifiers to build audience profiles, and we do not sell, rent or trade any data. We do not use visitors’ data for our own advertising, and no profiling or automated decision-making takes place.
- The Conversions API access token the customer provides is encrypted at rest (AES-256-GCM) and is never written to any log.
6. Duration of data processing, deadline for erasure of data. Every relayed event is recorded twice, with different retention periods:
- Event statistics — booleans only (whether an email, phone, _fbp or _fbc was present), never raw personal data. These power the dashboard and are deleted automatically after 90 days.
- API Log — the full request and response exchanged with Meta, exactly as sent (email and phone already hashed, the access token masked). It powers the API Log page and is deleted automatically after 1 day.
7. Persons authorised to access the data, recipients of personal data: the data controller’s authorised staff, and Meta Platforms Ireland Limited as the destination of the relayed events.
8. Legal basis for data processing: Article 6(1)(b) of the GDPR with regard to our contract with the customer. With regard to the website visitor, the customer as controller determines the legal basis.
Use of the Meta Conversions API
- The data controller relays the conversion events fired on the customer’s website to Meta through the Meta Conversions API. The recipient is Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland), which processes the received data as an independent controller under its own terms.
- Our snippet suppresses the client-side Meta pixel entirely — Meta’s fbevents.js is never loaded — so an event reaches Meta only through our server.
- The reported event source URL is transmitted in a transformed, lookalike form and without the page path, so that the customer’s domain is not exposed to Meta’s domain categorisation.
- Email addresses and telephone numbers used for advanced matching are hashed with SHA-256 on our server before transmission, as Meta’s Conversions API requires.
- Meta’s privacy policy is available at facebook.com/privacy/policy.
Recipients to whom personal data is disclosed (data transfer)
Online payment
1. Activity performed by the Recipient: online payment.
2. Name and contact details of the Recipient: Stripe, Inc., 185 Berry Street, Suite 550, San Francisco, CA 94107, United States — web: https://stripe.com, email: [email protected].
3. Fact of data processing, scope of data processed: billing details, name, email address.
4. Scope of data subjects: all data subjects who choose to make a payment on the website.
5. Purpose of data processing: to process online payments, confirm transactions and carry out fraud monitoring for the protection of users.
6. Duration of data processing, deadline for erasure of data: until the online payment has been processed.
7. Legal basis for data processing: Article 6(1)(b) of the GDPR. Data processing is necessary for the performance of an online payment requested by the data subject.
8. Rights of the data subject:
- You may obtain information about the circumstances of the data processing.
- You have the right to receive confirmation from the data controller as to whether your personal data is being processed, and to access all information relating to the data processing.
- You have the right to receive your personal data in a structured, commonly used and machine-readable format.
- You have the right to have the data controller rectify any inaccurate personal data concerning you without undue delay upon your request.
Data processors used
Hosting provider
1. Activity performed by the data processor: hosting service.
2. Name and contact details of the data processor: Render Services, Inc., 525 Brannan Street, San Francisco, CA 94107, United States — [email protected], https://render.com
3. Fact of data processing, scope of data processed: all personal data provided by the data subject.
4. Scope of data subjects: all data subjects using the website.
5. Purpose of data processing: to make the website available and to ensure its proper operation.
6. Duration of data processing, deadline for erasure of data: data processing shall continue until the termination of the agreement between the data controller and the hosting provider, or until the data subject submits a request for erasure to the hosting provider.
7. Legal basis for data processing: Article 6(1)(c) and (f) of the GDPR, and Section 13/A(3) of Act CVIII of 2001. The legitimate interest is the proper operation of the website and protection against attacks and fraud.
Other data processors
We rely on a short list of trusted providers to deliver the service. Each processes data only on our instructions and under their own security and privacy commitments.
| Service provider | Data processing operation | Official company name | Registered office |
|---|---|---|---|
| Supabase | Authentication, account records and hosting of the application database | Supabase, Inc. | 970 Toa Payoh North #07-04, Singapore 318992 |
| Stripe | Subscription payment management and invoicing | Stripe Technology Europe Limited | The One Building, 1 Lower Grand Canal Street, Dublin 2, Ireland |
| AWS (Amazon Web Services) | Transactional and support email delivery (SES) | Amazon Web Services, Inc. | 410 Terry Avenue North, Seattle, Washington 98109, United States |
| Cloudflare | Content delivery, DNS, bot and abuse protection, and the Turnstile CAPTCHA on our contact form | Cloudflare, Inc. | 101 Townsend St., San Francisco, California 94107, United States |
| Render.com | Operation of the application hosting infrastructure | Render Services, Inc. | 525 Brannan St Ste 300, San Francisco, California 94107, United States |
| Billzone | Automated issuing of compliant invoices | Billzone Kft. | 3580 Tiszaújváros, Margit sétány 23., Hungary |
| Meta Platforms | Destination for the pixel events we relay via the Conversions API on your behalf | Meta Platforms Ireland Limited | Merrion Road, Dublin 4, D04 X2K5, Ireland |
| Tag management (Google Tag Manager) on our own website | Google Ireland Limited | Gordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland |
Some of these providers process data outside the European Economic Area. Where that happens, transfers are covered by the providers’ own safeguards, such as Standard Contractual Clauses.
Complaints handling
1. The fact of data collection, the scope of the data processed and the purpose of data processing:
| Personal data | Purpose of data processing | Legal basis |
|---|---|---|
| Surname and first name | Identification, maintaining contact. | Fulfilment of a legal obligation, Article 6(1)(c) of the GDPR (the relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on consumer protection) |
| Email address | Contact purposes. | Article 6(1)(c) of the GDPR |
| Telephone number | Contact purposes. | Article 6(1)(c) of the GDPR |
| Billing name and address | Identification, handling of quality complaints, queries and issues arising in connection with the services ordered. | Article 6(1)(c) of the GDPR |
2. Data subjects: all data subjects who make a purchase on the website and raise a quality complaint or make a complaint.
3. Duration of data processing and deadline for data erasure: copies of the minutes of the complaint, the transcript and the response thereto must be retained for 3 years in accordance with Section 17/A(7) of Act CLV of 1997 on consumer protection.
4. Description of the data subjects’ rights regarding data processing:
- The data subject may request from the data controller access to their personal data, the rectification, erasure or restriction of processing of such data, and
- the data subject has the right to data portability and to withdraw consent at any time.
5. The data subject may request access to, erasure, rectification or restriction of processing of personal data, as well as data portability, in the following ways:
- by post to 8220 Balatonalmádi, Kert utca 15.,
- by email to [email protected],
- by telephone on +36 70 544 6727.
6. Please note that
- the provision of personal data is based on a legal obligation,
- the processing of personal data is a prerequisite for the conclusion of the contract,
- you are obliged to provide your personal data so that we can process your complaint,
- failure to provide data will result in us being unable to handle the complaint you have submitted to us.
Customer relations and other data processing
- Should any questions arise whilst using the data controller’s services, or should the data subject encounter any issues, they may contact the data controller via the methods provided on the website.
- The data controller will process the data provided in emails and messages, together with the enquirer’s name and email address, as well as any other personal data provided voluntarily, for no longer than two years after the data was provided.
- We will provide information regarding data processing not listed in this notice at the time the data is collected.
- In the event of an exceptional request from a public authority, or a request from other bodies authorised by law, the Service Provider is obliged to provide information, disclose data, transfer data, or make documents available.
- In such cases, the Service Provider shall disclose personal data to the requesting party — provided that the latter has specified the exact purpose and scope of the data — only to the extent strictly necessary to fulfil the purpose of the request.
Rights of data subjects
1. Right of access
You have the right to receive confirmation from the data controller as to whether your personal data is being processed, and if such processing is taking place, you have the right to access your personal data and the information listed in the Regulation.
2. Right to rectification
You have the right to have the data controller rectify inaccurate personal data concerning you without undue delay upon your request. Taking into account the purposes of the processing, you have the right to request that incomplete personal data be completed, including by means of providing a supplementary statement.
3. Right to erasure
You have the right to request that the data controller erases personal data concerning you without undue delay, and the data controller is obliged to erase personal data concerning you without undue delay under certain conditions.
4. The right to be forgotten
Where the data controller has made the personal data public and is obliged to erase it, the data controller shall, taking into account available technology and the cost of implementation, take all reasonable steps — including technical measures — to inform data controllers processing the data that you have requested the deletion of links to, or copies or replicas of, the personal data in question.
5. Right to restriction of processing
You have the right to obtain from the controller restriction of processing where one of the following conditions is met:
- You contest the accuracy of the personal data; in this case, the restriction applies for a period enabling the data controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the data, requesting instead that its use be restricted;
- the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims;
- you have objected to the processing; in this case, the restriction applies for as long as it has not been established whether the controller’s legitimate grounds override your legitimate grounds.
6. Right to data portability
You have the right to receive the personal data concerning you, which you have provided to a data controller, in a structured, commonly used, machine-readable format, and you have the right to transmit those data to another controller without hindrance from the controller to whom you have provided the personal data.
7. Right to object
In the case of data processing based on legitimate interests or public authority powers as legal grounds, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data, including profiling based on the aforementioned provisions.
8. Objection in the case of direct marketing
Where personal data are processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such purposes, including profiling, insofar as it is related to direct marketing. If you object to the processing of personal data for the purposes of direct marketing, the personal data may no longer be processed for that purpose.
9. Automated decision-making in individual cases, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
The previous paragraph does not apply where the decision:
- is necessary for the conclusion or performance of a contract between you and the data controller;
- is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
- is based on your explicit consent.
Time limit for action
The data controller shall inform you of the measures taken in response to the above requests without undue delay, but in any event within 1 month of receipt of the request.
If necessary, this may be extended by 2 months. The data controller shall inform you of any extension of the deadline, stating the reasons for the delay, within 1 month of receiving the request.
If the data controller does not take action in response to your request, then without delay, but no later than one month from receipt of the request, the data controller shall inform you of the reasons for the failure to act, as well as of your right to lodge a complaint with a supervisory authority and to seek judicial remedy.
Security of data processing
The data controller and the data processor shall take technical and organisational measures appropriate to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk, including, where applicable:
- the pseudonymisation and encryption of personal data;
- ensuring the ongoing confidentiality, integrity, availability and resilience of the systems and services used for the processing of personal data;
- in the event of a physical or technical incident, the ability to restore access to personal data and the availability of the data in a timely manner;
- a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of data processing.
The data controller implements the following specific measures:
- All connections to the service are served over TLS.
- Meta Conversions API access tokens are stored encrypted at rest with AES-256-GCM; the plaintext token is never written to a log or to the API Log.
- The application database enforces default-deny row-level security, so a tenant can only reach their own rows.
- Access to production data is limited to the people who need it to operate the service, and is protected by individual credentials.
- Data stored using information technology is stored so that it can be irreversibly deleted upon expiry of the applicable retention period.
- Documents processed on paper are stored in a secure, lockable, dry room, and are destroyed using a document shredder or by a specialist document-destruction organisation.
No system is perfectly secure, but we work to protect your data with appropriate technical and organisational measures.
Informing the data subject of a data breach
If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall inform the data subject without undue delay.
The information provided to the data subject must describe the nature of the data breach clearly and in plain language; the name and contact details of the data protection officer or other contact person providing further information must be provided; the likely consequences of the data breach must be described; and the measures taken or planned by the controller to address the data breach must be described, including, where appropriate, measures to mitigate any adverse consequences arising from the data breach.
The data subject need not be informed if any of the following conditions are met:
- the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the data affected by the personal data breach, in particular those measures — such as the use of encryption — which render the data unreadable to persons not authorised to access the personal data;
- following the data breach, the controller has taken further measures to ensure that the high risk to the rights and freedoms of data subjects is unlikely to materialise in the future;
- providing the information would require a disproportionate effort. In such cases, data subjects must be informed through publicly available information or by taking similar measures that ensure data subjects are informed in an equally effective manner.
If the data controller has not yet notified the data subject of the personal data breach, the supervisory authority may, after assessing whether the personal data breach is likely to result in a high risk, order that the data subject be informed.
Review in the case of mandatory data processing
If the duration of mandatory data processing, or the periodic review of its necessity, is not determined by law, a local government decree, or a binding legal act of the European Union, the data controller shall review, at least every three years from the start of data processing, whether the processing of personal data by the data controller or by a data processor acting on its behalf or on its instructions is necessary for the fulfilment of the purpose of the data processing.
The controller shall document the circumstances and results of this review, retain this documentation for ten years following the completion of the review and make it available to the National Authority for Data Protection and Freedom of Information (hereinafter: the Authority) upon request.
Complaints procedure
Complaints regarding any potential infringement by the data controller may be lodged with the National Authority for Data Protection and Freedom of Information:
- Authority
- National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9-11.
- Postal address
- 1363 Budapest, PO Box 9.
- Telephone
- +36 1 391 1400
- Fax
- +36 1 391 1410
- [email protected]
Changes to this policy
We may update this policy as the service evolves. When we make material changes we will update the date at the top of this page and, where appropriate, notify you by email.
Contact
Questions about privacy or your data? Email us at [email protected] or use our contact form.
Closing remarks
In preparing this information document, we have taken into account the following legislation and recommendations:
- On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (GDPR) (27 April 2016);
- Act CVIII of 2001 — on certain issues relating to electronic commerce services and information society services (in particular Section 13/A);
- Act XLVII of 2008 — on the prohibition of unfair commercial practices towards consumers;
- Act XLVIII of 2008 — on the fundamental conditions and certain restrictions of commercial advertising (in particular Section 6);
- Act XC of 2005 on freedom of electronic information;
- Act C of 2003 on electronic communications (specifically Section 155a);
- Opinion No. 16/2011 on the EASA/IAB Recommendation on Good Practice in Behavioural Online Advertising;
- Recommendation of the National Authority for Data Protection and Freedom of Information on data protection requirements for prior information.
Balatonalmádi, 10 July 2026.