1. Introduction
1.1. Purpose of this Privacy Policy
The purpose of this Privacy Policy (the “Policy”) is to present, in a transparent and detailed manner, how we handle personal data in the course of the activities of Németh Vilmos e.v. (the “Data Controller”), and to inform data subjects of their rights and how to exercise them.
1.2. Legal compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): sets out uniform EU rules on the protection of personal data.
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the “Privacy Act”): the Hungarian law forming the basis of data protection regulation.
This Policy seeks to comply with the requirements set out in the above legislation.
2. Data Controller details
2.1. Name and contact details of the Data Controller
- Name: Németh Vilmos e.v. (sole trader)
- Registered seat: 6724 Szeged, Föltámadás utca 19. FSZ. 2., Hungary
- Tax number: 56715738-1-26
- E-mail: info@primetax.hu
2.2. Availability of this Privacy Policy
This Policy is available electronically at www.primetax.hu.
3. Definitions
3.1. Basic GDPR concepts
- Personal data: any information relating to an identified or identifiable natural person (“data subject”).
- Data Controller: the natural or legal person that determines the purposes and means of the processing of personal data.
- Data Processor: the natural or legal person that processes personal data on behalf of the Data Controller.
- Consent: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of their personal data.
- Data subject: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a personal data breach
A personal data breach is any event resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.
4. Data processing principles
4.1. Legal bases and principles
- Lawfulness, fairness and transparency: we process data only for specified, lawful purposes.
- Purpose limitation: only for predetermined purposes, to the extent necessary to achieve them.
- Data minimisation: we only collect and process personal data that is essential to achieving the purpose.
- Accuracy: we take care to ensure that the personal data processed is accurate and, where necessary, kept up to date.
- Storage limitation: we only store personal data for as long as necessary to fulfil the purpose.
- Integrity and confidentiality: we apply appropriate technical and organisational measures to protect personal data.
4.2. Accuracy and security of data
- Both the Data Controller and the data subject are responsible for the regular updating of data; the latter is required to notify us of any change to their personal data.
- The Data Controller does everything possible to ensure that the data on record is accurate, and protects it with appropriate security measures against unauthorised access.
5. Purposes and legal bases of data processing
5.1. Browsing and visiting the website
- Purpose: ensuring the proper functioning of the website – quality control of the service – measuring visitor numbers.
- Legal basis: consent under Article 6(1)(a) GDPR
- Data processed: IP address, browser type, operating system, internet service provider, timestamps, website visit data
5.2. Contact requests made through the website
- Purpose: providing information, maintaining contact, sending information about our services and products.
- Legal basis: consent under Article 6(1)(a) GDPR
- Data processed: name, e-mail address, phone number
5.3. Managing orders
- Purpose: processing orders, performing the contract, invoicing and delivery.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- Data processed: name, delivery and billing address, contact details (phone number, e-mail), order details.
5.4. Issuing invoices
- Purpose: compliance with applicable accounting legislation (e.g. Act C of 2000 on Accounting).
- Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
- Data processed: name/company name, address, tax number (for legal entities), and other data required for invoicing.
5.5. Use of cookies
- Purpose: ensuring the proper functioning of the website, improving user experience, analysing visitor data, marketing purposes.
- Legal basis:
- Consent (Article 6(1)(a) GDPR) – for any cookie that is not strictly necessary for the website to function.
- Legitimate interest or performance of a contract (Article 6(1)(f) or (b) GDPR) – for technical cookies that are essential for operation.
- Further details: see the “Use of cookies” section of this Policy (Section 11).
5.6. Data processing on social media platforms
- Purpose: maintaining contact, sharing information (Facebook, Instagram, etc.).
- Legal basis: voluntary decision, consent (Article 6(1)(a) GDPR).
- Note: the data processing practices of social media platforms are governed by that platform’s own privacy policy, which should be reviewed separately.
6. Scope of data processed
6.1. Types of personal data
- Contact data: name, e-mail address, phone number, address.
- Technical data: IP address, browser type, cookies, login timestamps.
- Billing data: billing name, address, tax number (for companies).
6.2. Method and duration of data storage
- In electronic form, on protected servers, secured with passwords and other protective measures.
- In paper form (where applicable), at our registered seat or place of business, in a locked location.
- Retention period: until the purpose of processing has been achieved or the applicable legal obligation has been fulfilled, or until consent is withdrawn. The data is subsequently deleted or anonymised.
7. Rights of data subjects
7.1. Right to information
Data subjects have the right to request information about the purpose, legal basis, source, retention period of, and who has access to, the personal data processed about them.
7.2. Right to rectification
If a data subject believes that the personal data processed about them is inaccurate or incomplete, they may request that it be corrected or completed.
7.3. Right to erasure (“right to be forgotten”)
Data subjects may request the deletion of their personal data if it is no longer necessary for the purpose for which it was collected, or if they withdraw their consent and there is no other legal basis for processing.
7.4. Right to data portability
Data subjects have the right to receive the data they have provided in a structured, commonly used, machine-readable format, and to request that it be transmitted to another data controller.
7.5. Right to object
- Data subjects may object at any time to the processing of their personal data where the legal basis for processing is the Data Controller’s legitimate interest.
- Data subjects have a separate right to object to the processing of their personal data for direct marketing purposes.
8. Data security
8.1. Protection of electronic data
- Multi-level access control system.
- Regular backups.
- Antivirus protection and firewall use.
8.2. Technical and organisational measures
- Closed office network and secure Wi-Fi.
- Storage of paper-based documents in locked cabinets.
- Regular data protection training for employees and data processors.
9. Handling of data breaches
9.1. Notifying the authority (72-hour rule)
In the event of a personal data breach, the Data Controller notifies the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk to the rights and freedoms of data subjects.
9.2. Informing data subjects in the event of high risk
If a breach is likely to result in a high risk to the rights and freedoms of data subjects, the Data Controller informs the data subjects without undue delay, describing the nature of the breach and the measures taken.
10. Data processors and third parties
10.1. Hosting provider
- Name: Netlify, Inc.
- Registered seat: 101 2nd Street, San Francisco, CA 94105, USA
- Contact: privacy@netlify.com
- Data processing activity: hosting the website (serving the static site) and the technical operation of the contact form. Processes personal data solely on the instructions of the Data Controller.
- Transfer to a third country: as the provider is based in the United States, personal data may be transferred outside the European Economic Area (EEA). Netlify, Inc. participates in the EU–U.S. Data Privacy Framework, which ensures an adequate level of protection for such transfers as required by the GDPR.
11. Use of cookies
11.1. Purpose and types of cookies
- Session cookies: essential for the website to function, deleted when the browser is closed.
- Functional cookies: enhance user convenience, for example by remembering login details or the selected language.
- Analytics cookies (e.g. Google Analytics): serve statistical purposes, helping us understand user behaviour and improve the website.
- Marketing cookies: support the display of relevant advertisements and measurement of their effectiveness.
11.2. Managing user preferences
- Users can control the handling of cookies in their browser settings, including disabling or deleting them.
- Changing cookie settings may cause certain features of the website to stop working properly.
- On first visiting the website, users are given the option to accept or decline non-essential (e.g. marketing) cookies via a pop-up window.
12. Data Protection Officer
Under applicable regulation (Article 37 GDPR), the Data Controller is not required to appoint a Data Protection Officer.
13. Enforcement options for data subjects
13.1. Lodging a complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If a data subject believes that the processing of their personal data infringes applicable law, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Phone: +36 (1) 391-1400
- E-mail: ugyfelszolgalat@naih.hu
13.2. Right to judicial remedy
If their rights are infringed, data subjects may turn to the courts. Such proceedings may be brought before the competent tribunal of the data subject’s place of residence or habitual stay, at their choice.
14. Legislation underlying data processing
14.1. GDPR (Regulation (EU) 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, which aims to protect natural persons in relation to the processing of personal data and to ensure the free movement of such data within the EU.
14.2. Act CXII of 2011 on the Right of Informational Self-Determination
The Hungarian data protection act, which governs the domestic principles and limitations applicable to the processing of personal data.
14.3. Other relevant Hungarian legislation
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code.
- Act XLVIII of 2008 on the Basic Conditions of, and Certain Limitations to, Business Advertising Activity.
15. Final provisions
15.1. Validity and possibility of amending this Privacy Policy
- This Policy is effective as of 1 September 2026.
- The Data Controller reserves the right to unilaterally amend this Policy, in particular due to changes in legislation, the introduction of new data processing activities, or in order to take into account recommendations from the supervisory authority.
- Amendments will be published on the website, and by continuing to use our services after such amendments take effect, data subjects accept the new rules.
Szeged, Hungary, 29 August 2026
Németh Vilmos e.v.