Privacy policy

Privacy Policy

1. Introduction

The purpose of this notice is to set out the data protection and data-processing policy of

Name: AnyRF Kft.

Registered office: Kőműves utca 23., Érd, 2030, Hungary

Company registration No.: 13-09-209833

Tax number: 28985367-2-13

EU VAT number: HU28985367

Representative: Milán Szakács

E-mail: info@anyrf.hu

Website: https://anyrf.hu/

hereinafter referred to as the Data Controller or AnyRF Kft.

that it applies in the course of its operation and economic activity, and to ensure that data subjects receive appropriate information about the handling of their personal data. The Data Controller is committed to fully complying with the legal provisions on the processing of personal data, as set out below, throughout its activities.

In drawing up these rules, the Data Controller has taken particular account of:

  • the Fundamental Law of Hungary;
  • Act CVIII of 2001 on certain aspects of electronic commerce services and information-society services;
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: the "Info Act");
  • Act V of 2013 on the Civil Code (hereinafter: the "Civil Code");
  • Act VI of 1998 promulgating the Strasbourg Convention of 28 January 1981 for the Protection of Individuals with regard to Automatic Processing of Personal Data;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

The Data Controller declares that in the course of its operation it obtains only personal data that the data subject voluntarily provides, or where the data subject consents to the recording, processing and use of those data.

Data subjects, by accepting this Privacy Policy, declare that they have read, understood and accepted the provisions and information set out herein and that they give their consent to the processing of their data.

2. Definitions used in this notice

Data processing (technical): the performance of the technical tasks associated with data-handling operations;

Data handling / processing: any operation or set of operations performed on data, regardless of the procedure used, in particular collecting, recording, organising, storing, altering, using, querying, transmitting, disclosing, aligning or combining, blocking, erasing and destroying the data, as well as preventing further use of the data, and the taking of photographs, audio or video recordings;

Data Controller: the natural or legal person, or organisation with legal personality, which, alone or jointly with others, determines the purposes of the data processing, makes and implements (or has implemented through a designated data processor) the decisions concerning data processing (including the means used);

Data transfer: making data available to a specified third party;

Data erasure: rendering data unrecognisable in such a way that its restoration is no longer possible;

Personal-data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed;

Data subject: the natural person whose personal data are processed;

Third party: any natural or legal person, or any other body, that is not the data subject, the Data Controller, the data processor or the persons authorised to process personal data under the direct authority of the Data Controller or the data processor;

Consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of personal data relating to them — whether fully or for specific operations;

Customer: any natural or legal person, or unincorporated entity, that uses, subscribes to, or otherwise takes advantage of the Data Controller's services;

Personal data: data relating to an identified natural person — in particular their name, identification number, or one or more factors specific to their physical, physiological, mental, economic, cultural or social identity — and any inference drawn from such data concerning the data subject, which is not a matter of public interest or required to be made public. Personal data includes, but is not limited to, name, address, phone number and e-mail address;

Objection: a declaration by the data subject objecting to the processing of their personal data and requesting that the processing be discontinued or that the data processed be erased;

Website: the internet site at https://anyrf.hu/.

3. Data-processing principles

The data processing carried out by the Data Controller complies with the data-protection principles set out in the GDPR and the Info Act:

Lawfulness, fairness and transparency: Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.

Purpose limitation: Personal data must be collected only for specified, explicit and legitimate purposes, and not further processed in a manner incompatible with those purposes.

Data minimisation: Personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

Accuracy: Personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay.

Storage limitation: Personal data must be stored in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data are processed.

Integrity and confidentiality: Personal data must be processed in a manner that ensures appropriate security of the data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

Accountability: The Data Controller is responsible for compliance with these principles and must be able to demonstrate that compliance.

In addition to the data-processing principles above, the requirement of appropriate information can be identified as a common requirement: regardless of the legal basis of processing, the Data Controller must inform data subjects about how their data are processed.

4. Scope of data processed, purpose, legal basis and duration

4.1 Data processing related to the Data Controller's services

In the course of providing the services listed on the Website, the Data Controller records and processes personal data that the data subjects provide to it.

Scope of data processed

****

Purpose of processing

****

Legal basis

****

Duration of processing

Until the data subject requests erasure of the data, or for a maximum of 5 years from the performance or termination of the service contract — i.e. the general limitation period under the Hungarian Civil Code.

4.2 Newsletter subscription

Data subjects may subscribe to the Data Controller's newsletter via the Website or other online interfaces:

Scope of data processed

The data subject's name and e-mail address.

Purpose of processing

To inform the data subject, via the newsletter, of current offers, promotions and content relevant to the Data Controller's services.

Legal basis

The data subject's voluntary consent.

Duration of processing

Until the data subject requests erasure or withdraws the newsletter subscription.

4.3 Cookies

A cookie is a small text file stored on the data subject's computer or mobile device for the lifetime configured in the cookie, and reactivated on subsequent visits. Its purpose is to record information about the visit and the user's personal settings; this information cannot be linked back to the visitor as an identifiable person. Cookies help to make the Website more user-friendly and to enhance the data subject's online experience. If the data subject does not consent to the Data Controller's use of cookies while browsing the Website, parts of the Website may not function fully. More detailed information about the cookies used by the Data Controller is available in the Cookie Notice.

Scope of data processed

The Data Controller stores all analytics information without any name or other personal data of the data subject.

Purpose of processing

Storing the data subject's personal settings.

Legal basis

The data subject's voluntary consent.

Duration of processing

The data subject can delete cookies stored on their computer or mobile device at any time via their browser settings.

4.4 Contracts with partners

When a contract is concluded between the Data Controller and a partner, the parties identify in the contract those personal data of the contact person that are indispensable for the communication required to perform the contract.

Scope of data processed

The data subject's name, phone number, job title and e-mail address.

Purpose of processing

Business-to-business communication and performance of the contracts.

Legal basis

Processing necessary for the performance of contractual obligations.

Duration of processing

Until termination of the contractual relationship, or for the general limitation period prescribed by applicable law.

4.5 Contact via the Website and customer-service data processing

Data subjects can contact the Data Controller directly via the Contact function on the Website, or by phone with the Data Controller's customer-service staff.

Scope of data processed

The data subject's name, company name (optional), e-mail address, phone number, and any other personal data voluntarily provided during the phone call or in the message.

Purpose of processing

Communication between the data subject and the Data Controller, quality assurance, customer service and issue handling.

Legal basis

The data subject's voluntary consent.

Duration of processing

The Data Controller stores personal data obtained in this way for a maximum of 5 years.

5. Data processors

5.1 The following data processors may, as necessary and in line with the relevant data-processing principles, access certain categories of personal data.

Data processor

Contact

Activity

****

****

Accounting and payroll

****

****

Marketing, ad management, PR

Billingo Technologies Zrt.

Website: https://www.billingo.hu/

Website development

Magic Qube Kft.

Registered office: 7081 Simontornya, Gyár utca 13.; tax number: 32800555-2-17; e-mail: office@magicqube.com

Website development (subcontractor)

Versanus Kft.

Tel.: +36 30 951 3744; Address: 1138 Budapest, Mura utca 4. 9th floor, door 7

Website domain provider

Tárhely.Eu Szolgáltató Kft.

Website: https://tarhely.eu/

Online hosting services

In addition to the above data processors, certain personal data may also be accessed and acted upon by persons in an employment or contractual relationship with the Data Controller. The persons identified in this section handle the data confidentially: under their contracts with the Data Controller, the Data Controller's employees and contractual partners providing services to it are bound by an obligation of secrecy, under which they may not process the data they learn beyond the purposes of their relationship with the Data Controller and may not transmit it to third parties. The duties, access rights and obligations of persons involved in data processing are governed by the Data Controller's internal policies and data-processing agreements. Employees are liable under employment law and contractual partners under civil law for compliance with these rules.

5.2 Other data-processing activities involving cookies
A) Google Analytics and Tag Manager integration

We collect technical data about visits to the Website and use of the service via Google Analytics. The data collected by Analytics (e.g. device type, browser type, language settings, referring URL, browser IP address and other geographic information) is stored anonymously and independently of personal data, and is used for statistical analysis to optimise the usability and marketing of the system.

Google Tag Manager (GTM) is a tool that enables tags used on your Website or application to be managed simply and centrally, without modifying code directly on the page.

B) Meta Pixel

Used on the Website to measure visitor activity (page views, add-to-cart, purchases) and to support remarketing for Meta advertising.

C) Instagram Pixel (Meta)

Collects conversion and activity data on visitor behaviour for Instagram advertising.

D) LinkedIn Pixel (LinkedIn Insight Tag)

Tracks activities related to LinkedIn advertising on the Website and measures conversions and audience-interest data.

E) TikTok Pixel

Tracks events and conversions related to TikTok advertising on the Website, used to measure and optimise campaign performance.

6. Data transfer

As a general rule, the Data Controller does not transfer the data it processes to third parties. Data may only be transferred if the data subject has expressly and previously consented to it, or if it is required by law, or if it is requested under the authority of law by a competent authority.

7. Data security

The primary repository for the data is the Data Controller's IT system.

The Data Controller stores the personal data named above on the server of its IT data processor.

The Data Controller undertakes to ensure data security in accordance with the requirements of the GDPR and the Info Act.

The necessary access controls, internal organisational and technical measures applied during operation of the IT systems ensure that data cannot fall into the hands of unauthorised persons and that unauthorised persons cannot delete, extract or modify the data. The Data Controller also enforces data-protection and data-security requirements vis-à-vis its data processors.

The Data Controller maintains a register of any personal-data breaches and, where necessary, informs the data subject and, if required, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).

Personal data are accessible to persons acting in the Data Controller's interest — in particular agents and employees — to whom such access is necessary for the performance of their duties, and who are aware of and understand the obligations relating to the processing of those data.

The Data Controller pays particular attention to ensuring that all of its agents and employees know its internal data-protection protocol and process personal data accordingly.

The Data Controller undertakes to ensure data security using the most up-to-date and appropriate equipment and security rules, with particular attention to preventing unauthorised access to the data and unlawful disclosure, erasure or destruction. It takes every reasonable step to prevent accidental damage to or destruction of the data. The Data Controller also imposes the above obligations on its employees involved in data-processing activities.

Under no circumstances does the Data Controller collect special-category data, i.e. data relating to racial origin, national or ethnic minority status, political opinions or party affiliation, religious or other philosophical beliefs, trade-union or interest-group membership, health, addiction, sex life, or criminal convictions.

8. Rights of the data subject during processing

Within the period of data processing, data subjects have the following rights:

Right to information

The Data Controller must provide information about the essential aspects of the processing in an appropriate, simple and intelligible form that is easy to find (online or offline). At the time personal data are obtained, or where the data subject subsequently requests information, the Privacy Policy must be provided to the data subject and a declaration confirming that they have read, understood and accepted its provisions must be signed by them.

The data subject may at any time request information about the personal data concerning them that the Data Controller processes. Such information may be requested at the e-mail address indicated in the privacy notice for that processing, by post, or by phone. The Data Controller is required to provide the requested information within 30 days of the request.

Right to erasure

The data subject has the right to request that the Data Controller erase personal data concerning them without undue delay, and the Data Controller is obliged to do so without undue delay. Where the Data Controller has made the data available to third parties, it must inform all those to whom it has disclosed the data to delete any references and personal data stored with them. The aim is for the data to "disappear" from the available databases, unless there is a legal or reasonable obstacle to this.

Erasure does not have to be carried out where the processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for the establishment, exercise or defence of legal claims;
  • for compliance with a legal obligation;
  • for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, where erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing.

The Data Controller also erases personal data appearing in its documentation when the purpose of processing the personal data has ceased to exist.

For paper-based documentation, destruction must be carried out and recorded by minutes, so that it can later be proven to the competent authority.

Right to rectification

The data subject may indicate that the processed data are inaccurate and may request that other data be entered in their place. The Data Controller is responsible for the accuracy of the data and must verify their accuracy from time to time.

Right to restriction of processing

The data subject may request the Data Controller to restrict the processing of their personal data — for example, in an unresolved or disputed situation. Where processing is restricted, such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

Right to data portability

The data subject may request that the personal data processed about them be provided in a structured, commonly used and machine-readable format (e.g. .doc, .pdf, etc.), and has the right to transmit those data to another controller without hindrance from the original controller. This makes it easier for data subjects to move their personal data from one controller to another.

Right to object

The data subject has the right to object at any time to processing of their personal data for a specific reason, where they have not given consent to such processing.

Where the data subject wishes to exercise these rights, this entails identification, and the Data Controller will necessarily need to communicate with them; identification will therefore require the provision of personal data (but identification can only be based on data that we already process about you). Your complaints regarding data processing will be retained in our e-mail account for the period set out in this notice for complaint handling.

The Data Controller responds to data-processing complaints without delay, and in any case no later than 30 days.

9. Remedies

The data subject is entitled to lodge a complaint with NAIH (1055 Budapest, Falk Miksa u. 9–11.; www.naih.hu; tel.: +36 (1) 391-1400; fax: +36 (1) 391-1410; e-mail: ugyfelszolgalat@naih.hu) or to enforce their rights relating to the processing of personal data before the court having jurisdiction under Act CXXX of 2016 on the Code of Civil Procedure.

10. Final provisions

If the Data Controller wishes to carry out further processing of personal data for a purpose other than that set out in this notice, it will inform the data subject of the new purpose of the processing before doing so. Processing for the new purpose may only begin after that — and, where the legal basis is consent, only if the data subject also consents to the processing after receiving the information.

The Privacy Policy is in force until revoked; its personal scope extends to all organisational units of the Data Controller, their data processors, employees, officers and persons in a mandate relationship with them.

The Privacy Policy must be reviewed annually and whenever EU or domestic legislation changes.

The Data Controller reserves the right to amend this policy and to modify it as appropriate in response to changes in European Union or Hungarian legislation.