MetamorphMetamorphBack to home

Privacy Policy

Last updated 10 July 2026

Introduction

DataCrew Kft. (8220 Balatonalmádi, Kert utca 15., tax number: 27120352-2-19, company registration number: 1909520863) (hereinafter: Service Provider, data controller) carries out its data processing activities in accordance with the provisions set out in the following information notice.

On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (27 April 2016), we provide the following information.

This privacy notice governs the processing of data on the following website: https://metamorph.ad

The privacy policy is available at the following address: https://metamorph.ad/legal/privacy

Amendments to the privacy policy shall enter into force upon publication at the above address.

The data controller and their contact details

Name
DataCrew Kft.
Registered office
8220 Balatonalmádi, Kert utca 15., Hungary
Telephone
+36 70 544 6727

Definitions

  • “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  • “data processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, communication, transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  • “data controller”: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, Union or Member State law may also determine the controller or specific criteria for the designation of the controller;
  • “data processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
  • “recipient”: a natural or legal person, public authority, agency or any other body to whom or to which personal data are disclosed, irrespective of whether they are a third party. Public authorities which may receive personal data in the framework of a particular inquiry shall not be regarded as recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
  • “the data subject’s consent”: a freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
  • “data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
  • “profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
  • “third party”: a natural or legal person, public authority, agency or any other body which is not the data subject, the controller, the processor or those persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Principles relating to the processing of personal data

Personal data:

  • must be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
  • collection must be for specified, explicit and legitimate purposes, and they must not be processed in a manner incompatible with those purposes; in accordance with Article 89(1), further processing for archiving in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the original purpose (“purpose limitation”);
  • they must be adequate and relevant in relation to the purposes of the processing and limited to what is necessary (“data minimisation”);
  • they must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes of the processing, are erased or rectified without delay (“accuracy”);
  • must be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for a longer period only if the processing is carried out in accordance with Article 89(1) for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes, subject to the implementation of appropriate technical and organisational measures required by this Regulation to safeguard the rights and freedoms of data subjects (“storage limitation”);
  • processing must be carried out in such a manner that appropriate technical or organisational measures are applied to ensure the appropriate security of personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage (“integrity and confidentiality”).

The data controller is responsible for compliance with the above and must be able to demonstrate such compliance (“accountability”).

The data controller declares that its data processing is carried out in accordance with the principles set out in this section.

Data processing related to the use of the service

1. The fact of data collection, the scope of the data processed and the purpose of data processing:

Personal dataPurpose of data processingLegal basis
Surname and first nameRequired for establishing contact, using the service and issuing a valid invoice.Article 6(1)(b) of the GDPR
Email addressTo maintain contact and to authenticate you.Article 6(1)(b) of the GDPR
Telephone numberContact purposes, more efficient coordination of matters relating to invoicing.Article 6(1)(b) of the GDPR
Billing name and address, VAT numberIssuing a valid invoice, as well as drawing up the contract, determining its content, amending it, monitoring its performance, and the enforcement of related claims.Article 6(1)(c) of the GDPR (legal obligation: Section 169(2) of Act C of 2000 on Accounting)
Date of subscription/registrationPerformance of a technical operation.Article 6(1)(b) of the GDPR
IP address at the time of subscription/registrationPerformance of a technical operation.Article 6(1)(b) of the GDPR

We only support Google sign-in and email magic links, so we never see or store a password. Card data is entered directly with Stripe and is never stored on our servers.

2. Data subjects: all data subjects registered on the website or using the service.

3. Duration of data processing, deadline for erasure of data: if any of the conditions set out in Article 17(1) of the GDPR apply, processing continues until the data subject requests erasure. The data controller shall inform the data subject electronically of the erasure of any personal data provided by the data subject, in accordance with Article 19 of the GDPR. If the data subject’s request for erasure also covers their email address, the data controller shall also delete the email address following the notification. This does not apply to accounting documents, as these must be retained for 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting. The data subject’s contractual data may be deleted upon expiry of the civil law limitation period, based on the data subject’s request for erasure.

Accounting documents (including general ledger accounts, analytical and detailed records) must be retained in a readable form for at least 8 years, in a manner that allows them to be retrieved by reference to the accounting records.

4. The identity of potential data controllers entitled to access the data, and the recipients of personal data: personal data may be processed by the data controller’s authorised staff, in accordance with the above principles.

5. Description of the data subjects’ rights regarding data processing:

  • The data subject may request from the data controller access to, rectification, erasure or restriction of processing of personal data concerning them, and
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may request access to personal data, their erasure, rectification or restriction of processing, and data portability in the following ways:

  • by post to 8220 Balatonalmádi, Kert utca 15.,
  • by email to [email protected],
  • by telephone on +36 70 544 6727.

7. Please note that

  • the processing of your personal data is necessary for the performance of the contract,
  • you are required to provide your personal data so that we can fulfil your order,
  • failure to provide this data will result in the consequence that we will be unable to process your order.

Relayed event data

This section describes the core of the service: the Meta Pixel events that our snippet captures on our customer’s website and that we forward to Meta server-side via the Conversions API.

1. Fact of data collection, scope of data processed: the event name and timestamp, standard event parameters, the event identifier, the visitor’s IP address and user agent, the _fbp and _fbc browser identifiers, and — where the customer’s own pixel initialisation supplies them — the visitor’s email address and phone number for Meta’s advanced matching.

2. Scope of data subjects: the visitors of the website on which our customer has installed the Metamorph snippet.

3. Purpose of data collection: to relay conversion events to the customer’s Meta Pixel through the Meta Conversions API, and to report the results of that relay back to the customer.

4. Controller and processor. With regard to the event data collected on a customer’s website, the customer is the data controller and Metamorph acts as a data processor that forwards the data to Meta on the customer’s documented instruction. The customer is responsible for having a lawful basis for collecting that data and for informing their own visitors.

5. What we do not store:

  • Any personal identifier used for Meta’s matching (email address, telephone number) is hashed with SHA-256 on our server before it leaves for Meta. We never write the plaintext value to storage.
  • We do not store raw visitor personal data — no plaintext emails, phone numbers, names or addresses of the customer’s website visitors.
  • We do not use hashed identifiers to build audience profiles, and we do not sell, rent or trade any data. We do not use visitors’ data for our own advertising, and no profiling or automated decision-making takes place.
  • The Conversions API access token the customer provides is encrypted at rest (AES-256-GCM) and is never written to any log.

6. Duration of data processing, deadline for erasure of data. Every relayed event is recorded twice, with different retention periods:

  • Event statistics — booleans only (whether an email, phone, _fbp or _fbc was present), never raw personal data. These power the dashboard and are deleted automatically after 90 days.
  • API Log — the full request and response exchanged with Meta, exactly as sent (email and phone already hashed, the access token masked). It powers the API Log page and is deleted automatically after 1 day.

7. Persons authorised to access the data, recipients of personal data: the data controller’s authorised staff, and Meta Platforms Ireland Limited as the destination of the relayed events.

8. Legal basis for data processing: Article 6(1)(b) of the GDPR with regard to our contract with the customer. With regard to the website visitor, the customer as controller determines the legal basis.

Management of cookies

1. So-called “cookies used for password-protected sessions”, “security cookies”, “essential cookies” and “functional cookies” do not require prior consent from data subjects.

2. Fact of data processing, scope of data processed: unique identification number, dates, times.

3. Scope of data subjects: all data subjects visiting the website.

4. Purpose of data processing: identification of users and ensuring the secure operation of the website.

5. Our own website loads Google Tag Manager on every page. Google Tag Manager itself stores no cookie; any measurement tag configured within it that stores a cookie does so on the basis of the data subject’s consent under Article 6(1)(a) of the GDPR, where consent is required. Your Metamorph login session is stored in your browser’s local storage, not in a cookie.

6. Duration of data processing, deadline for data erasure:

Cookie typeLegal basis for data processingDuration of data processing
Session cookies or other cookies essential for the website to functionNo data processing takes place through the use of cookies.The period until the end of the relevant visitor session, i.e. it remains on the computer only until the browser is closed.
Statistical and marketing cookiesArticle 6(1)(a) of the GDPR1 day – 2 years; data processing continues until the data subject withdraws their consent.

7. List of cookies:

ServiceCookie nameExpiry timeFunction
Google Analytics 4_ga2 yearsDistinguishing unique users
Google Analytics 4_ga_<measurement-id>2 yearsStoring session state by GA4 measurement ID
Google Analytics 4_gid24 hoursShort-term user identification
Google Analytics 4_gat or _dc_gtm_<property-id>1 minuteRequest rate throttling
Google Analytics 4_gac_gb_<container-id>90 daysStoring campaign information
Google Analytics 4FPID2 yearsFirst-Party ID (HttpOnly only for sGTM)
Google Analytics 4FPLC20 hoursCross-domain tracking hash from FPID
Google Ads_gcl_au90 daysGoogle Ads conversion and click tracking
Google Ads_gcl_aw90 daysStoring Google Ads click ID (gclid)
Google Ads_gcl_dc90 daysDoubleClick campaign click information
Google Ads_gcl_gb90 daysGoogle Ads conversion linker
Google Ads_gcl_gf90 daysGoogle Floodlight tracking
Google Ads_gcl_ha90 daysGoogle Hotel Ads tracking
Google Ads_gac_<property-id>90 daysGoogle Ads campaign data in GA
Meta Pixel_fbp90 daysFirst-party cookie unique user ID
Meta Pixel_fbc90 daysClick ID storage (from fbclid parameter)
Meta Pixelfr90 days (variable)Third-party cookie retargeting (if used)
LinkedIn Insight Tagli_fat_id30 daysFirst-party click ID (in case of Enhanced Conversion)
LinkedIn Insight Tagbcookie1–2 yearsBrowser ID cookie
LinkedIn Insight Tagbscookie1–2 yearsSecure Browser ID cookie
LinkedIn Insight Taglidc24 hours (session)Session routing load balancing
LinkedIn Insight TagUserMatchHistory30 daysSynchronisation with LinkedIn Analytics
LinkedIn Insight Tagli_sugr90 daysProbabilistic user matching (non-EU)
LinkedIn Insight TagAnalyticsSyncHistory30 daysAnalytics synchronisation timestamp
LinkedIn Insight TaglangSessionLanguage settings
LinkedIn Insight Tagli_gcVariableGuest consent cookie
LinkedIn Insight Tagli_rm1 yearRemember Me feature
Microsoft AzureMicrosoftApplicationsTelemetryDeviceId1 yearAzure features
Microsoft AzureMicrosoftApplicationsTelemetryFirstLaunchTime1 yearAzure features
Consent BannerconsentMode1 yearConsent banner
Cloudflare__cf_bm30 minutesBot management — distinguishes automated traffic from human visitors
Cloudflare Turnstilecf_clearance30 minutesRecords that the CAPTCHA challenge on the contact form was passed
Cookie necessary for the basic functioning of the websiteauth_token1 weekCookie necessary for the basic functioning of the website
Cookie necessary for the basic functioning of the websitecsrf_token1 weekCookie necessary for the basic functioning of the website
Cookie necessary for the basic functioning of the websiteg_state6 monthsCookie necessary for the basic functioning of the website

Separately from the list above, the Metamorph snippet maintains its own _fbp and _fbc cookies on the customer’s own website, so that the events we relay carry those identifiers. The snippet never loads Meta’s client-side pixel script.

8. Description of data subjects’ rights regarding data processing: data subjects have the option to delete cookies via the Tools/Settings menu in their browsers, usually under the Privacy settings.

9. Most browsers allow you to configure which cookies are saved and enable specific cookies to be deleted again. If you restrict the saving of cookies on specific websites or do not allow third-party cookies, our website may, under certain circumstances, no longer be fully usable. Here you will find information on how to customise cookie settings in common browsers: Google Chrome, Microsoft Edge, Firefox, Safari.

Use of the Meta Conversions API

  • The data controller relays the conversion events fired on the customer’s website to Meta through the Meta Conversions API. The recipient is Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland), which processes the received data as an independent controller under its own terms.
  • Our snippet suppresses the client-side Meta pixel entirely — Meta’s fbevents.js is never loaded — so an event reaches Meta only through our server.
  • The reported event source URL is transmitted in a transformed, lookalike form and without the page path, so that the customer’s domain is not exposed to Meta’s domain categorisation.
  • Email addresses and telephone numbers used for advanced matching are hashed with SHA-256 on our server before transmission, as Meta’s Conversions API requires.
  • Meta’s privacy policy is available at facebook.com/privacy/policy.

Recipients to whom personal data is disclosed (data transfer)

Online payment

1. Activity performed by the Recipient: online payment.

2. Name and contact details of the Recipient: Stripe, Inc., 185 Berry Street, Suite 550, San Francisco, CA 94107, United States — web: https://stripe.com, email: [email protected].

3. Fact of data processing, scope of data processed: billing details, name, email address.

4. Scope of data subjects: all data subjects who choose to make a payment on the website.

5. Purpose of data processing: to process online payments, confirm transactions and carry out fraud monitoring for the protection of users.

6. Duration of data processing, deadline for erasure of data: until the online payment has been processed.

7. Legal basis for data processing: Article 6(1)(b) of the GDPR. Data processing is necessary for the performance of an online payment requested by the data subject.

8. Rights of the data subject:

  • You may obtain information about the circumstances of the data processing.
  • You have the right to receive confirmation from the data controller as to whether your personal data is being processed, and to access all information relating to the data processing.
  • You have the right to receive your personal data in a structured, commonly used and machine-readable format.
  • You have the right to have the data controller rectify any inaccurate personal data concerning you without undue delay upon your request.

Data processors used

Hosting provider

1. Activity performed by the data processor: hosting service.

2. Name and contact details of the data processor: Render Services, Inc., 525 Brannan Street, San Francisco, CA 94107, United States — [email protected], https://render.com

3. Fact of data processing, scope of data processed: all personal data provided by the data subject.

4. Scope of data subjects: all data subjects using the website.

5. Purpose of data processing: to make the website available and to ensure its proper operation.

6. Duration of data processing, deadline for erasure of data: data processing shall continue until the termination of the agreement between the data controller and the hosting provider, or until the data subject submits a request for erasure to the hosting provider.

7. Legal basis for data processing: Article 6(1)(c) and (f) of the GDPR, and Section 13/A(3) of Act CVIII of 2001. The legitimate interest is the proper operation of the website and protection against attacks and fraud.

Other data processors

We rely on a short list of trusted providers to deliver the service. Each processes data only on our instructions and under their own security and privacy commitments.

Service providerData processing operationOfficial company nameRegistered office
SupabaseAuthentication, account records and hosting of the application databaseSupabase, Inc.970 Toa Payoh North #07-04, Singapore 318992
StripeSubscription payment management and invoicingStripe Technology Europe LimitedThe One Building, 1 Lower Grand Canal Street, Dublin 2, Ireland
AWS (Amazon Web Services)Transactional and support email delivery (SES)Amazon Web Services, Inc.410 Terry Avenue North, Seattle, Washington 98109, United States
CloudflareContent delivery, DNS, bot and abuse protection, and the Turnstile CAPTCHA on our contact formCloudflare, Inc.101 Townsend St., San Francisco, California 94107, United States
Render.comOperation of the application hosting infrastructureRender Services, Inc.525 Brannan St Ste 300, San Francisco, California 94107, United States
BillzoneAutomated issuing of compliant invoicesBillzone Kft.3580 Tiszaújváros, Margit sétány 23., Hungary
Meta PlatformsDestination for the pixel events we relay via the Conversions API on your behalfMeta Platforms Ireland LimitedMerrion Road, Dublin 4, D04 X2K5, Ireland
GoogleTag management (Google Tag Manager) on our own websiteGoogle Ireland LimitedGordon House, Barrow Street, Dublin 4, D04 E5W5, Ireland

Some of these providers process data outside the European Economic Area. Where that happens, transfers are covered by the providers’ own safeguards, such as Standard Contractual Clauses.

Complaints handling

1. The fact of data collection, the scope of the data processed and the purpose of data processing:

Personal dataPurpose of data processingLegal basis
Surname and first nameIdentification, maintaining contact.Fulfilment of a legal obligation, Article 6(1)(c) of the GDPR (the relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on consumer protection)
Email addressContact purposes.Article 6(1)(c) of the GDPR
Telephone numberContact purposes.Article 6(1)(c) of the GDPR
Billing name and addressIdentification, handling of quality complaints, queries and issues arising in connection with the services ordered.Article 6(1)(c) of the GDPR

2. Data subjects: all data subjects who make a purchase on the website and raise a quality complaint or make a complaint.

3. Duration of data processing and deadline for data erasure: copies of the minutes of the complaint, the transcript and the response thereto must be retained for 3 years in accordance with Section 17/A(7) of Act CLV of 1997 on consumer protection.

4. Description of the data subjects’ rights regarding data processing:

  • The data subject may request from the data controller access to their personal data, the rectification, erasure or restriction of processing of such data, and
  • the data subject has the right to data portability and to withdraw consent at any time.

5. The data subject may request access to, erasure, rectification or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post to 8220 Balatonalmádi, Kert utca 15.,
  • by email to [email protected],
  • by telephone on +36 70 544 6727.

6. Please note that

  • the provision of personal data is based on a legal obligation,
  • the processing of personal data is a prerequisite for the conclusion of the contract,
  • you are obliged to provide your personal data so that we can process your complaint,
  • failure to provide data will result in us being unable to handle the complaint you have submitted to us.

Customer relations and other data processing

  • Should any questions arise whilst using the data controller’s services, or should the data subject encounter any issues, they may contact the data controller via the methods provided on the website.
  • The data controller will process the data provided in emails and messages, together with the enquirer’s name and email address, as well as any other personal data provided voluntarily, for no longer than two years after the data was provided.
  • We will provide information regarding data processing not listed in this notice at the time the data is collected.
  • In the event of an exceptional request from a public authority, or a request from other bodies authorised by law, the Service Provider is obliged to provide information, disclose data, transfer data, or make documents available.
  • In such cases, the Service Provider shall disclose personal data to the requesting party — provided that the latter has specified the exact purpose and scope of the data — only to the extent strictly necessary to fulfil the purpose of the request.

Rights of data subjects

1. Right of access

You have the right to receive confirmation from the data controller as to whether your personal data is being processed, and if such processing is taking place, you have the right to access your personal data and the information listed in the Regulation.

2. Right to rectification

You have the right to have the data controller rectify inaccurate personal data concerning you without undue delay upon your request. Taking into account the purposes of the processing, you have the right to request that incomplete personal data be completed, including by means of providing a supplementary statement.

3. Right to erasure

You have the right to request that the data controller erases personal data concerning you without undue delay, and the data controller is obliged to erase personal data concerning you without undue delay under certain conditions.

4. The right to be forgotten

Where the data controller has made the personal data public and is obliged to erase it, the data controller shall, taking into account available technology and the cost of implementation, take all reasonable steps — including technical measures — to inform data controllers processing the data that you have requested the deletion of links to, or copies or replicas of, the personal data in question.

5. Right to restriction of processing

You have the right to obtain from the controller restriction of processing where one of the following conditions is met:

  • You contest the accuracy of the personal data; in this case, the restriction applies for a period enabling the data controller to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the data, requesting instead that its use be restricted;
  • the controller no longer needs the personal data for the purposes of the processing, but you require it for the establishment, exercise or defence of legal claims;
  • you have objected to the processing; in this case, the restriction applies for as long as it has not been established whether the controller’s legitimate grounds override your legitimate grounds.

6. Right to data portability

You have the right to receive the personal data concerning you, which you have provided to a data controller, in a structured, commonly used, machine-readable format, and you have the right to transmit those data to another controller without hindrance from the controller to whom you have provided the personal data.

7. Right to object

In the case of data processing based on legitimate interests or public authority powers as legal grounds, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data, including profiling based on the aforementioned provisions.

8. Objection in the case of direct marketing

Where personal data are processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such purposes, including profiling, insofar as it is related to direct marketing. If you object to the processing of personal data for the purposes of direct marketing, the personal data may no longer be processed for that purpose.

9. Automated decision-making in individual cases, including profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

The previous paragraph does not apply where the decision:

  • is necessary for the conclusion or performance of a contract between you and the data controller;
  • is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  • is based on your explicit consent.

Time limit for action

The data controller shall inform you of the measures taken in response to the above requests without undue delay, but in any event within 1 month of receipt of the request.

If necessary, this may be extended by 2 months. The data controller shall inform you of any extension of the deadline, stating the reasons for the delay, within 1 month of receiving the request.

If the data controller does not take action in response to your request, then without delay, but no later than one month from receipt of the request, the data controller shall inform you of the reasons for the failure to act, as well as of your right to lodge a complaint with a supervisory authority and to seek judicial remedy.

Security of data processing

The data controller and the data processor shall take technical and organisational measures appropriate to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of security appropriate to the risk, including, where applicable:

  • the pseudonymisation and encryption of personal data;
  • ensuring the ongoing confidentiality, integrity, availability and resilience of the systems and services used for the processing of personal data;
  • in the event of a physical or technical incident, the ability to restore access to personal data and the availability of the data in a timely manner;
  • a procedure for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of data processing.

The data controller implements the following specific measures:

  • All connections to the service are served over TLS.
  • Meta Conversions API access tokens are stored encrypted at rest with AES-256-GCM; the plaintext token is never written to a log or to the API Log.
  • The application database enforces default-deny row-level security, so a tenant can only reach their own rows.
  • Access to production data is limited to the people who need it to operate the service, and is protected by individual credentials.
  • Data stored using information technology is stored so that it can be irreversibly deleted upon expiry of the applicable retention period.
  • Documents processed on paper are stored in a secure, lockable, dry room, and are destroyed using a document shredder or by a specialist document-destruction organisation.

No system is perfectly secure, but we work to protect your data with appropriate technical and organisational measures.

Informing the data subject of a data breach

If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall inform the data subject without undue delay.

The information provided to the data subject must describe the nature of the data breach clearly and in plain language; the name and contact details of the data protection officer or other contact person providing further information must be provided; the likely consequences of the data breach must be described; and the measures taken or planned by the controller to address the data breach must be described, including, where appropriate, measures to mitigate any adverse consequences arising from the data breach.

The data subject need not be informed if any of the following conditions are met:

  • the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the data affected by the personal data breach, in particular those measures — such as the use of encryption — which render the data unreadable to persons not authorised to access the personal data;
  • following the data breach, the controller has taken further measures to ensure that the high risk to the rights and freedoms of data subjects is unlikely to materialise in the future;
  • providing the information would require a disproportionate effort. In such cases, data subjects must be informed through publicly available information or by taking similar measures that ensure data subjects are informed in an equally effective manner.

If the data controller has not yet notified the data subject of the personal data breach, the supervisory authority may, after assessing whether the personal data breach is likely to result in a high risk, order that the data subject be informed.

Notification of a data breach to the supervisory authority

The data controller shall notify the competent supervisory authority of the data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of the data breach, to the supervisory authority competent pursuant to Article 55, unless the data breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, the reasons for the delay must also be provided.

Review in the case of mandatory data processing

If the duration of mandatory data processing, or the periodic review of its necessity, is not determined by law, a local government decree, or a binding legal act of the European Union, the data controller shall review, at least every three years from the start of data processing, whether the processing of personal data by the data controller or by a data processor acting on its behalf or on its instructions is necessary for the fulfilment of the purpose of the data processing.

The controller shall document the circumstances and results of this review, retain this documentation for ten years following the completion of the review and make it available to the National Authority for Data Protection and Freedom of Information (hereinafter: the Authority) upon request.

Complaints procedure

Complaints regarding any potential infringement by the data controller may be lodged with the National Authority for Data Protection and Freedom of Information:

Authority
National Authority for Data Protection and Freedom of Information (NAIH)
Address
1055 Budapest, Falk Miksa utca 9-11.
Postal address
1363 Budapest, PO Box 9.
Telephone
+36 1 391 1400
Fax
+36 1 391 1410

Changes to this policy

We may update this policy as the service evolves. When we make material changes we will update the date at the top of this page and, where appropriate, notify you by email.

Contact

Questions about privacy or your data? Email us at [email protected] or use our contact form.

Closing remarks

In preparing this information document, we have taken into account the following legislation and recommendations:

  • On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (GDPR) (27 April 2016);
  • Act CVIII of 2001 — on certain issues relating to electronic commerce services and information society services (in particular Section 13/A);
  • Act XLVII of 2008 — on the prohibition of unfair commercial practices towards consumers;
  • Act XLVIII of 2008 — on the fundamental conditions and certain restrictions of commercial advertising (in particular Section 6);
  • Act XC of 2005 on freedom of electronic information;
  • Act C of 2003 on electronic communications (specifically Section 155a);
  • Opinion No. 16/2011 on the EASA/IAB Recommendation on Good Practice in Behavioural Online Advertising;
  • Recommendation of the National Authority for Data Protection and Freedom of Information on data protection requirements for prior information.

Balatonalmádi, 10 July 2026.