Skip to content
W4U

Privacy Policy

Last updated: 2026-05-15

This is a generic template that must be tailored to the specific operations of [CÉGNÉV]. Legal review is recommended before production use.

[CÉGNÉV] (the “Controller”) is committed to protecting personal data. This policy is based on Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) and Act CXII of 2011 on informational self-determination and freedom of information.

1. Controller details

Controller: [ADATKEZELŐ NEVE]

Registered office: [SZÉKHELY]

Tax number: [ADÓSZÁM]

Company registration number: [CÉGJEGYZÉKSZÁM]

E-mail: [E-MAIL CÍM]

Phone: [TELEFONSZÁM]

The Controller is not required to appoint a dedicated data protection officer; for data protection matters please use the e-mail address above.

2. Purpose and scope

This policy transparently explains what personal data the Controller processes, for what purpose, on what legal basis and for how long when you visit the website and use the services.

3. Principles of processing

The Controller processes personal data lawfully, fairly and transparently, for limited purposes, in line with data minimisation, accurately, stored for a limited time, ensuring appropriate integrity and confidentiality (Article 5 GDPR).

4. Data processed, purposes and legal bases

Contact (contact form): name, e-mail address, subject and message content. The purpose is to answer the enquiry; the legal basis is the data subject’s consent (Article 6(1)(a) GDPR).

Conclusion and performance of a contract: contact person’s name, contact details and data required for performance. Legal basis: performance of a contract (Article 6(1)(b) GDPR).

Invoicing and accounting: invoice data is processed for compliance with a legal obligation (Article 6(1)(c) GDPR, under Act C of 2000 on Accounting).

Website operation and security: technically necessary log data and cookies are processed based on the Controller’s legitimate interest (Article 6(1)(f) GDPR).

5. Retention period

Data processed based on consent is kept until the purpose is achieved, but no longer than the withdrawal of consent.

Contractual and accounting data is stored for the retention period prescribed by law (accounting documents for at least 8 years under the Accounting Act).

6. Processors and data transfers

The Controller may use processors (e.g. hosting and infrastructure provider, e-mail provider, accountant) to provide the service, which process data solely on the Controller’s instructions.

Personal data is stored within the European Union/European Economic Area and is not transferred to a third country unless appropriate safeguards under the GDPR are in place.

7. Rights of the data subject

Under the GDPR the data subject has the following rights:

  • the right of access to their processed data,
  • the right to rectification of inaccurate data,
  • the right to erasure (“to be forgotten”),
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object to processing based on legitimate interest,
  • the right to withdraw consent at any time free of charge (without affecting the lawfulness of processing before withdrawal).

8. Data security measures

The Controller ensures the security of personal data and prevents unauthorised access through technical and organisational measures proportionate to the risk (e.g. encrypted transmission, access control, regular backups, logging).

9. Remedies

In case of infringement of their rights, the data subject may contact the Controller at [E-MAIL CÍM]. The data subject may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9-11., ugyfelszolgalat@naih.hu) or turn to court.

10. Use of cookies

The website uses cookies and local storage to operate and to provide the user experience. Strictly necessary cookies are essential for the basic functions of the website; cookies beyond these (e.g. statistical) are used only with the data subject’s prior consent. Consent can be changed at any time in the cookie settings.

Name Purpose Lifetime Type
XSRF-TOKEN Protection against cross-site request forgery (CSRF). Session Necessary
session cookie Maintains the session and form state. Session (approx. 2 hours) Necessary
cookie_consent (local storage) Remembers the cookie consent choice. Until withdrawn Necessary
statistics cookies Anonymous traffic statistics (with consent only). Up to 12 months Statistical

11. Changes to this policy

The Controller reserves the right to unilaterally amend this policy. The policy in force is always available on the website; the Controller will provide notice of material changes on the website.

Cookies on this site

We use cookies to make the site work and — with your permission — to measure traffic. You can change your choice at any time. Privacy policy