Privacy policy

Effective from: 14 June 2026

1. Purpose of this policy

Alap Design & Code Bt. (the "Controller") is committed to protecting personal data, respecting the right to informational self-determination and processing data transparently.

This privacy policy explains in plain language to data subjects:

  • what personal data the Controller processes;
  • for what purposes;
  • on what legal basis;
  • how long the data is kept;
  • who can access the data;
  • which processors the Controller uses;
  • what rights data subjects have;
  • how the website uses cookies and third-party services.

This policy applies in particular to:

  • visitors to the alapdesign.hu website;
  • people who use the contact form;
  • people who enquire by email or other channels;
  • people who book appointments online;
  • the Controller's clients and customers;
  • clients' representatives and contact persons;
  • people who contact the Controller via its social media pages;
  • people who appear in the Controller's references or client reviews.

Processing is governed primarily by Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the "GDPR"), and by the applicable provisions of Hungarian law.

2. Controller details

Controller name: Alap Design & Code Bt.

Registered office: Petőfi utca 46, 2nd floor, door 22, 7623 Pécs, Hungary

Company registration number: 02-06-068000

Tax number: 20254548-2-02

Email address: [email protected]

Website: alapdesign.hu

The Controller's data protection contact can be reached at [email protected] .

Data subjects may send questions, comments and requests about data processing by post to the Controller's registered office, or by email to [email protected] .

3. Key definitions

3.1. Personal data

Any information relating to an identified or identifiable natural person.

Personal data includes, in particular, a name, email address, phone number, home address, IP address, online identifier, photograph, voice recording, and information about a person's economic, professional or other characteristics.

3.2. Data subject

The natural person to whom the personal data relates.

3.3. Processing

Any operation or set of operations performed on personal data, in particular collection, recording, organisation, storage, alteration, retrieval, use, disclosure by transmission, making available, restriction, erasure or destruction.

3.4. Controller

The natural or legal person who determines the purposes and means of processing personal data.

3.5. Processor

The natural or legal person who processes personal data on behalf of the Controller.

3.6. Recipient

The natural or legal person, public authority or other body to whom personal data is disclosed.

3.7. Consent

A freely given, specific, informed and unambiguous indication of the data subject's wishes by which they agree to the processing of their personal data.

3.8. Cookie

A small data file placed on or read from a visitor's computer, phone or other device, used to make the website work, remember user settings, measure traffic or provide other functions.

4. Principles of processing

The Controller processes personal data:

  • lawfully, fairly and transparently;
  • for specified, explicit and legitimate purposes;
  • only to the extent necessary for those purposes;
  • accurately and, where necessary, kept up to date;
  • for no longer than necessary;
  • protected by appropriate technical and organisational measures.

The Controller aims to request and process only data that is genuinely needed for the matter in hand, the service, communication or compliance with a legal obligation.

5. Contact and quote requests

Data subjects may contact the Controller through the website's contact form, by email, by phone, via social media or through other channels.

5.1. Purpose of processing

  • receiving and responding to enquiries;
  • providing information requested by the data subject;
  • preparing quotes;
  • agreeing the content and terms of the service;
  • taking steps prior to entering into a contract;
  • keeping a record of communications.

5.2. Data processed

  • name;
  • email address;
  • phone number, if provided;
  • content of the message;
  • time of the enquiry;
  • website or business details provided by the data subject;
  • subject of the quote request;
  • content of communications and correspondence;
  • any other data voluntarily provided by the data subject.

5.3. Legal basis

Where the enquiry concerns a quote, an order or preparing a contract, the legal basis is Article 6(1)(b) GDPR: taking steps at the data subject's request prior to entering into a contract.

For general enquiries not directly aimed at a contract, the legal basis is Article 6(1)(f) GDPR. The Controller's legitimate interest is responding to enquiries and conducting business communication.

5.4. Retention period

If no contract follows, the Controller keeps the enquiry and related data for no more than 12 months from the last substantive communication.

If a contract follows, the data may continue to be processed under the rules for contractual processing.

5.5. Consequences of not providing data

Without a name, email address and message, the Controller cannot properly respond to the enquiry.

5.6. Contact form privacy statement

Suggested wording for the contact form checkbox:

I have read and understood the Privacy Policy.

Ticking the box does not mean consent to processing; it confirms that the data subject had the opportunity to read the privacy policy.

6. Online booking

The Controller may use an Amelia-based online booking system on the website.

The booking system runs as part of the website and, as a rule, stores booking data in the database of the Controller's WordPress website.

6.1. Purpose of processing

  • booking a consultation or other appointment;
  • displaying available times;
  • confirming the appointment;
  • rescheduling or cancelling the appointment;
  • communication about the appointment;
  • sending reminders or confirmations;
  • preventing double bookings and clashes;
  • preparing and delivering the service.

6.2. Data processed

  • name;
  • email address;
  • phone number, if the booking form asks for it;
  • the service selected;
  • the date and time booked;
  • booking status;
  • notes provided by the data subject;
  • data on rescheduling or cancellation;
  • data on confirmation and reminder messages;
  • technical and log data.

6.3. Legal basis

The legal basis is Article 6(1)(b) GDPR: taking steps at the data subject's request prior to entering into a contract, and performing the service.

6.4. Retention period

The Controller keeps booking data for no more than 12 months after the appointment takes place, is cancelled or falls through.

If the booking is followed by a contract or a paid service, the data may continue to be processed under the rules for contractual, invoicing and accounting processing.

6.5. Consequences of not providing data

Without the data marked as required, the online booking cannot be completed.

7. Google Calendar and Google Meet integration

The Controller may connect the Amelia booking system to Google Calendar.

For online consultations, the system may also create a Google Meet joining link.

7.1. Purpose of processing

  • recording bookings in the calendar;
  • synchronising appointments;
  • excluding busy periods from available slots;
  • preventing clashes;
  • providing the technical means for online consultations;
  • creating and sending the Google Meet link.

7.2. Data processed or transferred

  • the data subject's name;
  • name of the service booked;
  • date and time of the booking;
  • the data subject's email address, if needed to send a calendar invitation;
  • notes provided by the data subject, if included in the calendar event;
  • the Google Meet joining link;
  • booking status.

7.3. Legal basis

The legal basis is Article 6(1)(b) GDPR: preparing and performing the service.

7.4. Retention period

An event recorded in Google Calendar may remain until it is deleted, or at most until the end of the retention period set for booking data.

7.5. Processor

Provider: Google Ireland Limited

Service: Google Calendar, Google Meet and the related technical infrastructure.

In providing its services, Google may also process data in countries outside the European Economic Area. For such transfers, Google may apply safeguards under the applicable data protection laws.

The Controller aims to include in calendar events only the data needed to manage the booking.

8. Contracts and service delivery

8.1. Purpose of processing

  • identifying the client;
  • preparing and concluding the contract;
  • delivering the ordered service;
  • communication;
  • project and task management;
  • documenting delivery;
  • handling change, support, maintenance and warranty requests;
  • fulfilling rights and obligations under the contract;
  • establishing, exercising or defending legal claims.

8.2. Data processed

  • name of the natural person;
  • company name;
  • home address or registered office;
  • tax number;
  • company registration or other registration number;
  • representative's name and position;
  • contact person's name;
  • email address;
  • phone number;
  • bank account number;
  • details of the ordered service;
  • project content and requirements;
  • the contract and its amendments;
  • correspondence about delivery;
  • documents and content provided by the client;
  • access credentials, where needed to deliver the service;
  • data on payment and delivery.

8.3. Legal basis

Where the client is a natural person, the legal basis is Article 6(1)(b) GDPR: concluding and performing the contract.

For the representative or contact person of a client that is a legal entity, the legal basis is Article 6(1)(f) GDPR. The legitimate interest of the Controller and the client is the business communication needed to perform the contract.

For establishing, exercising or defending legal claims, the legal basis is Article 6(1)(f) GDPR.

8.4. Retention period

The Controller keeps contract and project data until the end of the general civil law limitation period from termination or performance of the contract, as a rule 5 years.

Data in accounting records and invoices is subject to the longer retention period for accounting purposes.

8.5. Handling access credentials

For website build, maintenance, operation or development services, the Controller may receive access to, among other things:

  • the website's admin area;
  • the hosting account;
  • the domain management panel;
  • the server;
  • technical email settings;
  • third-party services;
  • analytics, advertising or social media accounts.

The Controller uses this data only on the client's instructions and only as far as needed to deliver the service.

Once the service ends, access can be removed, revoked or returned to the client.

9. Personal data provided by the client

When delivering a website, online store, app, graphic design or marketing project, the client may give the Controller content that contains personal data.

This may include in particular:

  • names of customers or employees;
  • photographs;
  • portraits;
  • contact details;
  • biographies;
  • customer reviews;
  • event footage;
  • website databases;
  • customer or user data.

Where the Controller processes this data solely on the client's instructions, it acts as a processor.

The client is responsible for ensuring that it:

  • has an appropriate legal basis for sharing the data;
  • properly informs the data subjects;
  • shares only the data that is necessary;
  • obtains the consents and permissions needed to use the data.

Where necessary, the Controller and the client conclude a separate data processing agreement.

10. Invoicing and accounting obligations

10.1. Purpose of processing

  • issuing invoices and accounting documents;
  • recording payments;
  • meeting bookkeeping and tax obligations;
  • statutory reporting;
  • sending invoices to the client;
  • reporting to the Hungarian National Tax and Customs Administration (NAV).

10.2. Data processed

  • billing name;
  • billing address;
  • tax number;
  • email address;
  • name of the service ordered;
  • service fee;
  • date of supply;
  • invoice date;
  • payment due date;
  • payment method;
  • invoice number;
  • payment-related data.

10.3. Legal basis

The legal basis is Article 6(1)(c) GDPR: compliance with a legal obligation to which the Controller is subject.

10.4. Retention period

Under Act C of 2000 on Accounting (Hungary), the Controller keeps invoices, accounting documents and the underlying data for at least 8 years.

The right to erasure does not apply to data that the law requires to be kept.

10.5. Invoicing software

The Controller uses the Számlázz.hu online invoicing system to issue invoices.

Provider: KBOSS.hu Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság

Short name: KBOSS.hu Kft.

Registered office: Záhony utca 7, 1031 Budapest, Hungary

Company registration number: 01-09-303201

Tax number: 13421739-2-41

Service: online invoicing, storing and sending invoices, and supporting the required reporting to the tax authority.

The following data may be transferred to Számlázz.hu:

  • billing name;
  • billing address;
  • tax number;
  • email address;
  • name of the service;
  • invoice amount;
  • payment and delivery data.

10.6. Bookkeeping

The Controller may use an accounting service provider to meet its bookkeeping and tax obligations.

The accounting provider may access invoices, contracts, bank data and the personal data they contain.

The accounting provider may process the data only for bookkeeping, tax and accounting tasks, subject to confidentiality.

11. Bank transfers

For payments by bank transfer, the financial institution holding the Controller's account may process:

  • the account holder's name;
  • the account number;
  • the transfer amount;
  • the transfer date;
  • the payment reference;
  • other transaction details.

The purpose is to execute, identify and record the payment.

The legal basis is performance of the contract and compliance with applicable accounting and financial legal obligations.

12. Business contact data

Where a client, partner or prospect is a legal entity, the Controller may process the data of its representatives and contact persons.

12.1. Data processed

  • name;
  • position;
  • work email address;
  • work phone number;
  • name of the organisation represented;
  • content of business communications.

12.2. Purpose of processing

  • business communication;
  • providing quotes;
  • concluding contracts;
  • performing contracts;
  • project communication;
  • administration related to invoicing and delivery.

12.3. Legal basis

The legal basis is Article 6(1)(f) GDPR.

The legitimate interest of the Controller and the client is having an appropriate contact person available to prepare and perform the contract.

12.4. Retention period

For the duration of the business relationship, then for no more than 5 years after the contract ends or the last substantive communication.

13. References and case studies

The Controller may present its work as references, portfolio items or case studies.

A reference may include:

  • the client's company name;
  • the client's logo;
  • screenshots of the website or design work;
  • a short project description;
  • project results;
  • the name of the client's representative;
  • the client's photo;
  • a client review or recommendation.

A legal entity's name, logo or business project is not always personal data in itself. However, if a reference contains the name, photo, opinion or other personal data of an identifiable natural person, that person's separate consent is required.

13.1. Purpose of processing

  • presenting the Controller's services;
  • building a professional reference list and portfolio;
  • marketing communication;
  • demonstrating the Controller's professional experience.

13.2. Legal basis

For references containing personal data: consent under Article 6(1)(a) GDPR.

13.3. Retention period

Until consent is withdrawn or the Controller removes the reference.

Consent can be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing before withdrawal.

13.4. Consent is voluntary

Consent to a reference can never be a condition of using the service or performing the contract.

14. Client reviews

The Controller displays a client review or recommendation with a name, photo or other personal data only if the person has consented.

14.1. Data processed

  • name;
  • position;
  • company name;
  • photo;
  • text of the review;
  • information about the project.

14.2. Purpose of processing

Presenting the Controller's services and informing prospective clients.

14.3. Legal basis

The data subject's consent under Article 6(1)(a) GDPR.

14.4. Retention period

Until consent is withdrawn or the review is removed.

15. Displaying Google reviews

The website may display public reviews of the Controller published on Google.

To display them, the website may use an external Google service or a review widget. The current website shows Google reviews and links to Google's service.

Depending on what is public on Google, the data shown may include:

  • the reviewer's name;
  • profile picture;
  • star rating;
  • review text;
  • review date.

When Google reviews are displayed, the visitor's browser may connect to Google's servers. The service may load cookies or external content that is not strictly necessary only after the required consent has been given.

16. Social media pages

The Controller may run social media pages, in particular on:

  • Facebook;
  • Instagram;
  • Pinterest;
  • LinkedIn or other professional networks.

Processing on social media pages is also subject to each platform's own privacy terms.

16.1. Data processed

  • the user's public profile name;
  • profile picture;
  • comments;
  • reactions;
  • reviews;
  • messages sent to the Controller;
  • other data the user has made public.

16.2. Purpose of processing

  • communication;
  • responding to enquiries;
  • presenting the Controller's services;
  • community communication;
  • managing comments and messages.

16.3. Legal basis

For communication initiated directly by the data subject: Article 6(1)(b) or (f) GDPR.

For voluntary activity and comments on the platform, the basis is the data subject's voluntary participation and the Controller's legitimate interest in running its social media pages.

16.4. Retention period

Data may remain available on the platform until the data subject deletes it, the Controller removes it, or the page is closed.

The Controller does not have full control over the platforms' own independent processing.

17. Web server logs and technical data

When you visit the website, the hosting provider and the website's IT systems may record technical data.

17.1. Data processed

  • IP address;
  • date and time of the visit;
  • address of the page visited;
  • browser type;
  • operating system;
  • technical device information;
  • referring page;
  • server request status;
  • error codes;
  • security events;
  • other technical log data.

17.2. Purpose of processing

  • keeping the website running;
  • detecting errors and malfunctions;
  • IT and network security;
  • detecting unauthorised access attempts and abuse;
  • investigating security incidents;
  • checking that the website works properly.

17.3. Legal basis

Article 6(1)(f) GDPR.

The Controller's legitimate interest is ensuring the website runs securely, reliably and properly.

17.4. Retention period

As a rule, server logs are kept for no more than 90 days.

If a security incident or abuse is suspected, related data may be kept longer, for as long as needed to investigate or pursue legal claims.

18. Hosting and email services

Website hosting and some domain-related technical services are provided by Tárhely.Eu.

Provider: Tárhely.Eu Szolgáltató Korlátolt Felelősségű Társaság

Short name: Tárhely.Eu Kft.

Registered office: Ormánság utca 4, 10th floor, 241, 1144 Budapest, Hungary

Company registration number: 01-09-909968

Tax number: 14571332-2-42

Processing activities:

  • web hosting;
  • storing the website database;
  • managing server logs;
  • backups;
  • domain-related technical services;
  • email services, where Tárhely.Eu also provides email.

The hosting provider may technically access data submitted through the website, booking data, server logs and email, to the extent needed to provide its service.

19. Email

In email correspondence, the Controller processes:

  • the names of sender and recipient;
  • their email addresses;
  • the subject line;
  • the message content;
  • attachments;
  • when the email was sent and received;
  • technical message data.

The purpose is communication, handling matters, providing quotes, and preparing and performing contracts.

Depending on the content of the communication, the legal basis is:

  • Article 6(1)(b) GDPR;
  • Article 6(1)(c) GDPR;
  • or Article 6(1)(f) GDPR.

The Controller keeps emails until the end of the retention period for the matter concerned.

20. Web analytics – Google Analytics

The website may use Google Analytics 4 to measure traffic and analyse how the website is used.

Google Analytics may place or read statistics cookies only if the visitor has consented in advance.

20.1. Purpose of processing

  • measuring website traffic;
  • analysing how visitors use the website;
  • identifying the most visited pages;
  • detecting technical and usability issues;
  • improving the website's content and user experience;
  • producing aggregate statistics.

20.2. Data processed

  • cookie identifiers;
  • approximate location;
  • technical information derived from the IP address;
  • device type;
  • browser and operating system;
  • screen size;
  • pages visited;
  • time and duration of the visit;
  • referring page;
  • events and interactions on the website.

20.3. Legal basis

Consent under Article 6(1)(a) GDPR.

Visitors can withdraw consent at any time in the cookie settings.

20.4. Retention period

Based on the Controller's settings, Google Analytics keeps event-level user data for no more than 14 months.

Some Google Analytics cookies may stay on the visitor's device for a different period, as shown in the cookie table.

20.5. Provider

Provider: Google Ireland Limited

In providing the service, Google may also process data outside the European Economic Area, with appropriate transfer safeguards.

21. Use of cookies

21.1. Purpose of cookies

The website may use cookies and similar technologies:

  • to make the website work properly;
  • to remember cookie settings;
  • to improve security;
  • to measure traffic;
  • to produce statistics;
  • to display external content and features.

21.2. Strictly necessary cookies

Strictly necessary cookies are needed for the website to work, for security, or for a service the visitor has explicitly requested.

They do not require prior consent.

These may include in particular:

Cookie name Purpose Retention
cookielawinfo-checkbox-necessary Stores the setting for necessary cookies 11 months
cookielawinfo-checkbox-functional Stores the choice for functional cookies 11 months
cookielawinfo-checkbox-performance Stores the choice for performance cookies 11 months
cookielawinfo-checkbox-analytics Stores the choice for analytics cookies 11 months
cookielawinfo-checkbox-advertisement Stores the choice for marketing cookies 11 months
cookielawinfo-checkbox-others Stores the choice for other cookies 11 months
viewed_cookie_policy Records the choice regarding the cookie notice 11 months
CookieLawInfoConsent Stores detailed cookie settings 11 months

The cookie management tool currently used on the website shows several such consent cookies with an 11-month duration.

21.3. Statistics cookies

Statistics cookies help the Controller understand how visitors use the website.

These may include:

Cookie name Provider Purpose Typical retention
_ga Google Analytics Distinguishing visitors and statistical measurement up to 2 years
_ga_<ID> Google Analytics Maintaining session and measurement state up to 2 years
_gid Google Analytics, if used Distinguishing visitors up to 24 hours

Statistics cookies can only be activated after the data subject's prior consent.

21.4. Functional and third-party content cookies

Third-party services such as Google reviews, Google Maps, Google Calendar, Google Meet or social media features may use additional technical data and cookies.

The website may load these only if:

  • the service is strictly necessary for a feature the data subject requested; or
  • the data subject has consented in advance to the relevant cookies and external content.

21.5. Marketing cookies

The website uses marketing or advertising cookies only if the data subject has consented in advance.

If no marketing or remarketing system is active on the website, no such cookies are set.

21.6. Giving and withdrawing consent

In the cookie banner, visitors can:

  • accept all cookies;
  • reject all cookies that require consent;
  • choose which cookies to allow by category.

Refusing consent does not prevent basic use of the website, but some convenience, statistics or third-party features may not be available.

Consent can be withdrawn or changed at any time using the cookie settings on the website.

Cookies that require consent cannot load before the visitor makes a choice.

22. Suggested cookie banner text

We always use the cookies needed for the website to work. We activate statistics, functional and marketing cookies and third-party services only with your consent. You can change your choice at any time in the cookie settings.

On the first layer of the cookie banner, the following options should be shown with equal prominence:

  • Reject all
  • Settings
  • Accept all

23. Processors and recipients

In its processing activities, the Controller may use in particular the following processors and categories of recipients:

23.1. Hosting and email provider

Tárhely.Eu Szolgáltató Kft.

Role:

  • web hosting;
  • server operation;
  • database storage;
  • backups;
  • email;
  • technical logging.

23.2. Invoicing provider

KBOSS.hu Kft. – Számlázz.hu

Role:

  • issuing invoices;
  • storing invoice data;
  • sending invoices electronically;
  • supporting tax authority reporting.

23.3. Google services

Google Ireland Limited

Services concerned may include:

  • Google Analytics;
  • Google Calendar;
  • Google Meet;
  • Google reviews;
  • Google Maps;
  • other Google-based technical services.

23.4. Accountant

The Controller's accounting service provider at any given time.

Role:

  • bookkeeping;
  • tax returns;
  • accounting records;
  • statutory reporting.

23.5. Financial institutions

The banks holding the accounts of the Controller and the data subject, and financial service providers involved in executing payments.

23.6. Authorities and courts

Under a legal obligation or official request, data may be transferred in particular to:

  • the National Tax and Customs Administration (NAV);
  • the police;
  • the courts;
  • other authorities acting under the law.

23.7. Professional contributors

For certain projects, the Controller may engage subcontractors, developers, designers, or legal, marketing or IT specialists.

Personal data may be shared with them only where needed for the task and where they have accepted appropriate confidentiality and data protection obligations.

24. Transfers to third countries

Some international providers, in particular Google and social media platforms, may process personal data in countries outside the European Economic Area.

The basis for such transfers may be in particular:

  • an adequacy decision of the European Commission;
  • standard contractual clauses adopted by the European Commission;
  • the EU–US Data Privacy Framework, where its conditions are met;
  • other appropriate safeguards recognised by the GDPR.

Details of third-party providers' processing can be found in their own privacy policies.

25. Automated decision-making and profiling

The Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.

The Controller does not carry out profiling of data subjects with significant legal effects.

Aggregate statistics from Google Analytics are not used as the basis for individual decisions with legal effects on data subjects.

26. Data security

The Controller applies appropriate technical and organisational measures to protect personal data in particular against:

  • unauthorised access;
  • unauthorised alteration;
  • unauthorised transfer;
  • disclosure;
  • erasure or destruction;
  • accidental loss;
  • damage;
  • becoming inaccessible due to changes in the technical environment.

Measures may include in particular:

  • encrypted HTTPS connections;
  • access control and permission management;
  • strong passwords and multi-factor authentication;
  • regular software updates;
  • backups;
  • security and firewall services;
  • regular access reviews;
  • confidentiality obligations for staff and contributors;
  • limiting access to personal data to what is necessary.

Complete security of data transmitted over the internet cannot be guaranteed, but the Controller takes all reasonable measures to protect data appropriately.

27. Personal data breaches

A personal data breach is a breach of security leading to the accidental or unlawful:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • or unauthorised access to personal data.

The Controller investigates and documents personal data breaches.

If a breach is likely to result in a risk to the rights and freedoms of data subjects, the Controller notifies the supervisory authority within the statutory deadline.

If a breach is likely to result in a high risk to the data subject's rights and freedoms, the Controller also informs the data subject without undue delay.

28. Your rights

Data subjects have the following rights regarding the Controller's processing.

28.1. Right to be informed

You have the right to clear, plain-language information about how your personal data is processed.

28.2. Right of access

You can ask whether the Controller processes your personal data.

If it does, you have the right to know in particular:

  • the data processed;
  • the purpose of processing;
  • the legal basis;
  • the recipients;
  • the retention period;
  • the source of the data;
  • your rights.

You also have the right to request a copy of your personal data.

28.3. Right to rectification

You can ask for inaccurate data to be corrected and incomplete data to be completed.

28.4. Right to erasure

You can ask for your personal data to be erased, in particular where:

  • the data is no longer needed for the purpose it was collected for;
  • you have withdrawn consent and there is no other legal basis;
  • you have lawfully objected to the processing;
  • the processing is unlawful;
  • the law requires erasure.

The right to erasure does not apply, among other cases, where processing is necessary:

  • to comply with a legal obligation;
  • to establish, exercise or defend legal claims;
  • or for another purpose defined in the GDPR.

For example, invoice data that accounting law requires to be kept cannot be erased before the mandatory retention period ends, even on request.

28.5. Right to restriction of processing

You can ask for processing to be restricted where:

  • you contest the accuracy of the data;
  • processing is unlawful but you oppose erasure;
  • the Controller no longer needs the data but you need it for legal claims;
  • you have objected and the objection is being assessed.

28.6. Right to data portability

You have the right to receive the data you provided to the Controller in a structured, commonly used and machine-readable format, where:

  • processing is based on consent or a contract; and
  • processing is carried out by automated means.

You can also ask for the data to be transmitted directly to another controller, where technically feasible.

28.7. Right to object

On grounds relating to your particular situation, you can object at any time to processing based on Article 6(1)(f) GDPR (legitimate interest).

If you object, the Controller may no longer process the data unless it demonstrates compelling legitimate grounds that override your rights and freedoms, or the processing relates to establishing, exercising or defending legal claims.

28.8. Right to withdraw consent

Where processing is based on consent, you can withdraw it at any time without giving reasons.

Withdrawal does not affect the lawfulness of processing before withdrawal.

28.9. Information about recipients

You can ask the Controller to tell you which recipients it has informed of any rectification, erasure or restriction.

28.10. Right to lodge a complaint and seek judicial remedy

You can lodge a complaint with the supervisory authority and, if your rights are infringed, go to court.

29. Handling your requests

You can submit requests through the following contacts:

Email: [email protected]

Postal address: Alap Design & Code Bt., Petőfi utca 46, 2nd floor, door 22, 7623 Pécs, Hungary

Before fulfilling a request, the Controller may ask for additional information to confirm your identity if it has reasonable doubts about who is making the request.

The Controller responds without undue delay, and at the latest within one month of receiving the request.

Where necessary, taking into account the complexity and number of requests, this may be extended by two further months. The Controller will tell you about any extension and the reasons within the original one-month period.

As a rule, requests are handled free of charge.

If a request is manifestly unfounded or excessive, in particular because it is repetitive, the Controller may charge a reasonable fee or refuse to act on it.

30. Remedies

30.1. Complaints to the Controller

You can first contact the Controller:

Email: [email protected]

Postal address: Petőfi utca 46, 2nd floor, door 22, 7623 Pécs, Hungary

30.2. Complaints to the supervisory authority

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary

Postal address: PO Box 9, 1363 Budapest, Hungary

Email: [email protected]

Phone: +36 1 391 1400

NAIH's current contact details are on the Authority's official website.

30.3. Judicial remedy

If your rights are infringed, you can go to court.

Such cases fall within the jurisdiction of the regional courts (törvényszék). At your choice, proceedings may also be brought before the regional court for your place of residence or stay.

31. Data of minors

The Controller's services are aimed mainly at businesses and adults.

The website does not offer services specifically for children.

Minors should, where possible, contact the Controller with the involvement of their legal guardian.

If the Controller becomes aware that it is processing a minor's data without an appropriate legal basis, it takes the necessary steps to erase the data or establish a proper legal basis.

32. Links to external websites

The website may contain links to other providers or websites.

The operators of those websites are responsible for their own data processing.

The Controller is not responsible for the content, operation or privacy practices of external websites.

We recommend reading the privacy policy of any external website you visit.

33. Accuracy of data

You are responsible for making sure the data you provide is accurate, complete and up to date.

You may not provide another person's personal data without an appropriate legal basis or authorisation.

You must notify the Controller if the data you provided changes or becomes inaccurate.

34. Changes to this policy

The Controller may amend this privacy policy, in particular in the event of:

  • changes in legislation;
  • changes in regulatory practice;
  • the introduction of a new service;
  • the use of a new processor;
  • changes to how the website works technically;
  • changes to processing activities.

The amended policy takes effect when published on the website.

The Controller shows the current effective date at the top of the policy.

If a change significantly affects data subjects' rights or key aspects of processing, the Controller may also inform data subjects separately.

35. Final provisions

This privacy policy is effective from 14 June 2026.

For matters not covered by this policy, the Controller acts in accordance with the GDPR, the Hungarian Act on the Right to Informational Self-Determination, the Hungarian Civil Code, the Hungarian Accounting Act, and other applicable Hungarian and EU law.

Pécs, 14 June 2026

Alap Design & Code Bt.