HUEN

Legal notice

Privacy policy

Available at: https://siteflow.hu/adatkezelesi-tajekoztato/. Amendments to this policy take effect upon publication at the address above. Last updated: July 2026.

Introduction

FIEDLER ATTILA (1191 Budapest, Kisfaludy utca 16. 10. em. 30., tax number: 59604273-1-43, company registration number/registration number: 57651444) (hereinafter: Service Provider, controller) agrees to be bound by the following policy: we provide the following information in accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (27 April 2016, General Data Protection Regulation, "GDPR") on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation 95/46/EC.

This privacy policy governs data processing on the following website: https://siteflow.hu/

The controller and contact details

Name: Fiedler Attila
Registered office: 1191 Budapest, Kisfaludy utca 16. 10. em. 30.
Email: info@siteflow.hu
Phone: +36 20 381 2463

Definitions

  1. "personal data": any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
  2. "processing": any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction;
  3. "controller": the natural or legal person, public authority, agency, or other body that, alone or jointly with others, determines the purposes and means of processing personal data;
  4. "processor": a natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller;
  5. "recipient": a natural or legal person, public authority, agency, or other body to which personal data is disclosed, whether or not a third party;
  6. "consent of the data subject": any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which the data subject, through a statement or clear affirmative action, signifies agreement to the processing of personal data relating to them;
  7. "personal data breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;
  8. "profiling": any form of automated processing of personal data involving the use of personal data to evaluate, analyze, or predict certain personal characteristics relating to a natural person.

Principles governing the processing of personal data

Personal data is processed in accordance with the following principles: lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality. The controller is responsible for complying with these principles and must be able to demonstrate such compliance ("accountability").

Data processing related to operating the service

1. The fact of data collection, categories of data processed, and purposes of processing

Personal dataPurpose of processingLegal basis for processing
First and last nameContact, identification, providing a quote, and entering into a contract.Article 6(1)(b) of the GDPR (performance of a contract or taking steps before entering into a contract).
Email addressPrimary communication channel, sending quotes, contracts, invoices, and other project documents.Article 6(1)(b) of the GDPR.
Phone numberSecondary communication, discussing urgent matters or issues requiring quick coordination regarding the project or contract.Article 6(1)(b) of the GDPR.
Billing name and addressIssuing legally compliant invoices, creating and administering the contract, and enforcing claims arising from it.Article 6(1)(c) of the GDPR (compliance with a legal obligation under Act C of 2000 on Accounting).
IP address used when visiting the websiteEnsuring the technical operation of the service, IT security, and detecting and preventing attacks against and misuse of the website.Section 13/A (3) of Act CVIII of 2001 on Electronic Commerce Services (Elker tv.).

Categories of data subjects: website visitors, people requesting quotes, and clients using the service.

Duration of processing and deadline for deleting data: the Service Provider retains data submitted through the website's forms (contact, quote request) for 365 days from submission and then deletes it automatically, unless the data subject requests deletion earlier or the data results in a contract/invoice. If any of the conditions set out in Article 17(1) of the GDPR applies, processing continues until the data subject requests deletion. Accounting records are an exception, as this data must be retained for 8 years under Section 169 (2) of Act C of 2000 on Accounting. The data subject's contractual data may be deleted at the data subject's request after the civil-law limitation period expires.

Persons authorized to access the data: personal data may be processed by the controller and its authorized staff.

Rights of data subjects: the data subject may request access to, correction, deletion, or restriction of processing of personal data relating to them from the controller and has the right to data portability and to withdraw consent at any time. This may be done by mail (1191 Budapest, Kisfaludy utca 16. 10. em. 30.), email (info@siteflow.hu), or phone (+36 20 381 2463).

Legal basis for processing: Article 6(1)(b) of the GDPR; Section 13/A (3) of the Elker tv.; for invoicing under accounting laws, Article 6(1)(c) of the GDPR; for enforcing claims arising from a contract, the 5-year limitation period under Section 6:22 of the Civil Code (Act V of 2013).

Processing is necessary to perform the contract and provide a quote. Providing personal data is mandatory for performing the contract; without it, handling the inquiry and providing the service is not possible.

Cookie management

Prior consent is not required for the use of "necessary" and "security" cookies because they are essential to the website's basic operation. In contrast, using "functional" and "statistical" cookies requires your express prior consent, which is managed through the cookie settings panel displayed on the website.

Categories of data processed: unique identification number, dates, times. Categories of data subjects: all data subjects who visit the website.

Cookie typeLegal basis for processingDuration of processing
Session cookies and other cookies strictly necessary for the website to functionSection 13/A (3) of the Elker tv.Until the browser is closed.
Statistical and marketing cookiesArticle 6(1)(a) of the GDPR.1 day – 2 years, or until consent is withdrawn.

Rights of data subjects: consent to non-essential cookies may be changed or withdrawn at any time through the cookie settings panel displayed on the website. Cookies can also be deleted manually from the browser's Tools/Settings menu.

Browser-specific settings: Google Chrome · Microsoft Edge · Mozilla Firefox · Apple Safari

Use of Google Ads conversion tracking

This section concerns data processing planned by the Service Provider for the future—the processing described here will not take place until tracking is actually implemented.

The controller plans to use the "Google Ads" online advertising program, including Google's conversion tracking service (Google Ireland Limited, Ireland, and its parent company Google LLC, USA). When a User reaches the website through a Google ad, a cookie required for conversion tracking is placed on their computer. Each Google Ads client receives a different cookie, so Users cannot be tracked across client websites. The information is used to compile conversion statistics—the controller does not receive data that can directly identify the User, such as a name or email address.

Under Google Consent Mode v2, the ad_user_data and ad_personalization cookie types are based on the data subject's consent; the controller ensures that the appropriate consent can be given and withdrawn through its cookie banner. Consent may be withdrawn at any time through the cookie settings panel; this does not affect the lawfulness of processing carried out before consent was withdrawn. More information: https://policies.google.com/privacy

Use of Google Analytics

This section concerns data processing planned by the Service Provider for the future—the processing described here will not take place until tracking is actually implemented.

The website plans to use the Google Analytics web analytics service in the future (Google Ireland Limited, Ireland, and its parent company Google LLC, USA), which uses cookies to analyze website usage. The legal basis for using the service is your freely given prior consent, which you may give or withdraw at any time through the cookie settings panel. You can also prevent cookies from being stored through your browser settings; in that case, some website features may not be fully available.

If Google Ads and Google Analytics services are activated, data may also be transferred to Google LLC, based in the USA. The legal basis for such transfers is the European Commission's adequacy decision (EU–US Data Privacy Framework, "Data Privacy Framework"), details of which are available at: https://www.dataprivacyframework.gov/. The controller notes that the validity of this legal basis may be affected by international court proceedings; current status information is available on the website above and through notices issued by the NAIH.

Complaint handling

Personal dataPurpose of processingLegal basis for processing
First and last name, email address, phone numberIdentification and communication.Article 6(1)(b) of the GDPR.
Billing name and addressIdentification and handling quality complaints, questions, and problems related to the service provided.Article 6(1)(b) of the GDPR.

Categories of data subjects: all data subjects who use the service and raise a quality concern or submit a complaint. Duration of processing: copies of the complaint record, transcript, and response must be retained until the end of the general limitation period under the Civil Code (5 years).

Recipients to whom personal data is disclosed

Processors

To support its own processing activities and fulfill its obligations under contracts with data subjects and applicable laws, the controller uses the following processors:

Processing activityName of processorContact details
Hosting servicesSybell Informatika Kft.1138 Budapest, Tomori utca 34. 2. emelet, hello@sybell.hu
Online invoicingBillingo Technologies Zrt.1133 Budapest, Árbóc utca 6. III. emelet, hello@billingo.hu
Web analytics (planned, currently inactive)Google Ireland Ltd. / Google LLCGordon House, Barrow Street, Dublin 4, Ireland

Social media

The fact of data collection, categories of data processed: the name registered on Facebook and LinkedIn and the user's public profile picture. Categories of data subjects: all data subjects registered on Facebook or LinkedIn who have "liked"/followed the Service Provider's social media page or contacted the controller through it. Purpose of data collection: sharing and promoting the website's content and services. Legal basis for processing: the data subject's freely given consent.

Joint processing by Facebook / Meta

The controller maintains a Facebook/Meta profile for its business activities. Processing for statistical purposes on Facebook is carried out jointly by the controller and Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland); details are provided in the Page Insights Controller Addendum: https://www.facebook.com/legal/terms/page_controller_addendum. The controller communicates by private message on social media only if you contact it there. Processing continues until consent is withdrawn or, for message exchanges, for no more than 2 years.

Client relationships and other processing

If you have a question or encounter a problem while using the service, you may contact the controller through the methods listed on the website (phone, email, social media). The controller deletes received emails, messages, and personal data voluntarily provided in them no later than 2 years after the data is provided, unless the matter results in a contract or another legal basis requires a longer retention period, such as complaint handling or invoicing.

Partner program—data collection through intermediary referrals

The controller operates a partner program under which contracted intermediary partners may provide the controller with the contact details (name, company name, phone number, email address) of potential clients interested in website development services. Categories of data subjects: all potential clients whose data is provided to the controller by an intermediary partner. Purpose of processing: making contact and providing a quote. Legal basis for processing: the data subject's consent (Article 6(1)(a) of the GDPR), or the legitimate interests of the controller and the partner in offering the service (Article 6(1)(f) of the GDPR).

Joint processing: during the stages of identifying potential clients, making initial contact, and transferring data, the controller and the intermediary partner are joint controllers under Article 26 of the GDPR because the controller determines the target client group and the content of the outreach, while the partner makes the actual contact independently using its own resources. For all subsequent processing after the data is received (providing a quote, entering into a contract, performance, invoicing), the controller acts as an independent controller. The information required under Article 13 of the GDPR is provided primarily by the intermediary partner when the data is collected. Under Article 26(3) of the GDPR, you may exercise your rights against either controller—the controller's contact details are provided at the beginning of this policy.

Duration of processing: if the quote does not result in a contract, the controller deletes the data received from the intermediary partner after no more than 365 days.

Rights of data subjects

  • Right of access: you may obtain confirmation of whether your data is being processed and access the data.
  • Right to rectification: you may request the correction of inaccurate data without undue delay.
  • Right to erasure: you may request the deletion of your data under specified conditions.
  • Right to be forgotten: if data that has been made public must be deleted, the controller will take reasonable steps to inform other controllers.
  • Right to restriction of processing: you may request that processing be restricted in specified cases.
  • Right to data portability: you may request that your data be provided in a structured, machine-readable format.
  • Right to object: you may object at any time to processing based on legitimate interests.
  • Automated decision-making: no automated decision-making, including profiling, takes place during processing.

Deadline for action

The controller will inform you of action taken on your request without undue delay and no later than 1 month after receiving it; this period may be extended by an additional 2 months if necessary.

Data security

Taking into account the state of the art, implementation costs, the nature and scope of processing, and the level of risk, the controller applies appropriate technical and organizational measures to ensure data security, including access restrictions, regular backups, antivirus protection, and password-protected access.

Personal data breaches

If a personal data breach is likely to result in a high risk to the rights of natural persons, the controller will inform the data subject without undue delay and report the breach to the competent supervisory authority within 72 hours where possible.

Right to lodge a complaint

Complaints concerning a potential violation by the controller may be lodged with the Nemzeti Adatvédelmi és Információszabadság Hatóság:

Nemzeti Adatvédelmi és Információszabadság Hatóság
1055 Budapest, Falk Miksa utca 9–11.
Mailing address: 1363 Budapest, Pf. 9.
Phone: +36-1-391-1400
Email: ugyfelszolgalat@naih.hu

Regardless of the above, you also have the right to take legal action directly before a court if your rights are infringed (Article 79 of the GDPR). At the data subject's discretion, proceedings may also be brought before the court with jurisdiction over their permanent or temporary place of residence.


Final provisions

The following legislation and guidance were considered when preparing this policy: Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR); Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information; Act CVIII of 2001 on Electronic Commerce Services; Act XLVII of 2008 on the Prohibition of Unfair Business-to-Consumer Commercial Practices; Act C of 2003 on Electronic Communications; the recommendation of the Nemzeti Adatvédelmi és Információszabadság Hatóság on the data protection requirements for prior notice.

Scroll to Top