Privacy Policy
How UPRIVE collects, uses, and protects your personal data.
We use PostHog analytics (EU servers) only if you accept it in the cookie banner. It measures visits, records sessions to help us fix problems, and sets a cookie that recognises your returning visits for up to a year. Text you type into forms is never recorded. You can withdraw your consent at any time under Cookie settings in the footer, and the cookie is then deleted.
I. Introduction
UPRIVE Design Studio Korlátolt Felelősségű Társaság (hereinafter: the "Controller"), as the operator of the website under the domain www.uprive.design (hereinafter: the "Website"), is committed to compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the "GDPR"), and with Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: the "Privacy Act"). The security and proper processing of the personal data processed by the Controller are of paramount importance to the Controller.
The Controller processes personal data in the course of visits to the Website, registration and the use of the services. In this connection, the Controller provides the following notice (hereinafter: the "Privacy Notice").
The purpose of the Privacy Notice is to set out, in accordance with the applicable legal requirements, among other things, the purposes for which, the period for which, the legal basis on which and the manner in which the Controller processes the personal data under its control, and the options available to Data Subjects to enforce their rights and seek remedies in relation to those processing activities.
Should any question or comment arise in connection with what is set out in this Privacy Notice, the Controller may be contacted at the email address hello@uprive.design or by post, by letter sent to the address of the Controller's registered seat.
II. Key definitions
The most important terms used in the Privacy Notice are summarised below:
- Personal data: any information relating to the Data Subject on the basis of which the Data Subject is identified or identifiable. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. The Controller sets out in this Privacy Notice exactly which personal data it collects about the Data Subject.
- Processing: any operation or set of operations performed on data, regardless of the procedure applied, in particular its collection, capture, recording, organisation, storage, alteration, use, retrieval, transfer, disclosure to the public, alignment or combination, blocking, erasure and destruction, and the prevention of any further use of the data.
- Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In respect of the processing activities set out in this Privacy Notice, UPRIVE Design Kft. is the controller.
- Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Data Subject: an identified or identifiable natural person. Persons visiting the Website and persons using the services available on the Website qualify as Data Subjects.
- Authority: the Hungarian National Authority for Data Protection and Freedom of Information (address 1055 Budapest, Falk Miska u. 9-11., email ugyfelszolgalat@naih.hu, website http://naih.hu, telephone +36 (1) 391-1400).
III. The Controller and its representative
Controller:
The Controller is the operator of the Website.
Name: UPRIVE Design Kft.
Registered seat and postal address: 4400 Nyíregyháza, Ungvár sétány 11. D. ép. 3. em. 9. ajtó
Company registration number: 15-09-092131
Email: hello@uprive.design
Representative of the Controller:
Postal address: 4400 Nyíregyháza, Ungvár sétány 11. D. ép. 3. em. 9. ajtó
Email: hello@uprive.design
IV. Principles of data processing
The data processing principles that the Controller observes in the course of its processing activities are summarised below.
- Lawfulness, fairness and transparency: The personal data of the Data Subject are processed exclusively in a lawful and fair manner and in a manner that is transparent to the Data Subject. The Controller makes the current text of the Privacy Notice available to Data Subjects free of charge, among other means, by publishing it on the Website.
- Purpose limitation: The Controller may process personal data exclusively for the explicit and legitimate purposes set out in this Privacy Notice.
- Storage limitation: The Controller stores the personal data of the Data Subject in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Data minimisation: The Controller processes only the personal data that are necessary and relevant in relation to the purpose of the processing.
- Accuracy: The Controller's aim is that the personal data already recorded are kept up to date and accurate at all times in relation to the purposes of the processing, and the Controller takes every reasonable step to achieve this aim. Data Subjects have the opportunity to notify the Controller of any change in their personal data by email or by letter sent by post and, in the case of registration, by modifying their profile data.
- Principle of data protection / integrity and confidentiality: The Controller treats the protection of the personal data provided as a matter of paramount importance and therefore takes all technical and organisational measures that are necessary and reasonably expected for this purpose and that are in keeping with the state of the art at any given time, by which it ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Accountability: The Controller is responsible for compliance with the above principles and must be able to demonstrate such compliance.
V. Processing activities
V.1. Contact and requests for information
- Purpose of the processing: Through its published contact details and through the "contact form" available on the Website, the Controller provides an opportunity for anyone to request information about the Controller's activities and services and to make contact with the Controller.
- Categories of data processed: name, telephone number, email address.
- Data Subjects: the person making contact or requesting information.
- Legal basis of the processing: the consent of the Data Subject [Article 6(1)(a) GDPR]. The processing takes place expressly at the initiative of the Data Subject.
- Duration of the processing: The processing continues until the withdrawal of the Data Subject's consent, but for no longer than 5 years.
V.2. Website analytics and session recordings
- Purpose of the processing: to measure how visitors use the Website (for example which pages they view, how long they stay and where they arrive from), to record visits as session recordings (mouse movements, clicks, scrolling and page changes) and to detect technical errors, so that the Controller can fix problems and improve the Website. Text typed into form fields is masked in the recordings and is not recorded.
- Categories of data processed: a random identifier stored in a cookie and in the browser's local storage, IP address and the approximate location derived from it (country and city), browser, device and operating system type, screen size, the referring website, the pages viewed and the actions taken on them, technical error messages, and the session recording.
- Data Subjects: visitors to the Website who accept analytics in the cookie banner.
- Legal basis of the processing: the consent of the Data Subject [Article 6(1)(a) GDPR]. Analytics starts only after the Data Subject clicks "Accept" in the cookie banner. The Data Subject can withdraw consent at any time under "Cookie settings" in the footer of the Website. After that the analytics cookie is deleted and no further data is collected.
- Duration of the processing: session recordings are kept for 30 days. Other analytics data is kept for no longer than 7 years. The analytics cookie expires after 1 year.
- Processor: PostHog Inc. (https://posthog.com). The data is stored on PostHog's servers in the European Union (Frankfurt, Germany).
V.3. Cookies and browser storage
The Website stores the following items in the Data Subject's browser:
- NEXT_LOCALE (cookie, necessary): remembers the language of the Website. It is deleted when the browser is closed.
- uprive-consent-v1 (local storage, necessary): remembers the Data Subject's choice in the cookie banner. It is kept until the Data Subject deletes it in the browser.
- ph_[key]_posthog (cookie and local storage, analytics, only with consent): a random identifier that lets the analytics service recognise returning visits. It expires after 1 year and is deleted when consent is withdrawn.
- __ph_opt_in_out_[key] (local storage, analytics): remembers that the Data Subject withdrew consent, so that no further data is collected. It is kept until the Data Subject deletes it in the browser.
VII. Enforcement of rights and remedies
Rules on the exercise of Data Subjects' rights:
The Controller is obliged to provide the requested information without undue delay and in any event within one month of the request for information. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Controller informs the Data Subject of any such extension within one month of receipt of the request, together with the reasons for the delay.
If the Controller does not take action on the request of the Data Subject, the Controller informs the Data Subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and of the possibility of lodging a complaint with the Authority and seeking a judicial remedy.
Where the Controller has reasonable doubts concerning the identity of the person submitting the request, the Controller may also request the provision of additional information necessary to confirm the identity of that person.
Communication with the Controller:
Communication between the Data Subject and the Controller takes place by email or by post. In exercising the rights of Data Subjects, the Controller may be contacted by letter sent by post to its registered seat or by email.
Right of access
The Data Subject is entitled to request confirmation from the Controller at any time as to whether or not his or her personal data are being processed and, where such processing is ongoing, the Data Subject has the right of access to the personal data being processed, to the extent set out below.
In the context of access, the information provided by the Controller regarding the processing may cover, in particular, the following:
- the source of the personal data processed,
- the purpose and legal basis of the processing,
- the categories of personal data processed,
- where the personal data processed are transferred, the recipients of the transfer (including recipients in third countries and international organisations),
- the retention period of the personal data processed and the criteria used to determine that period,
- the rights of the Data Subject under the Privacy Act and the GDPR, and a description of how those rights may be exercised,
- where automated decision-making or profiling is used, the fact of such use,
- the circumstances of any personal data breaches that have occurred in connection with the processing of the Data Subject's personal data, their effects and the measures taken to address them, and
- the right to lodge a complaint with the supervisory authority.
Rectification
The Data Subject is obliged to notify the Controller in writing of any change in his or her personal data. The Controller gives effect to the change of data within 8 days of receipt of the request. If the Data Subject fails to report a change in his or her personal data without delay, the Data Subject bears the consequences. If the personal data provided are inaccurate and accurate personal data are available to the Controller, the Controller rectifies the personal data automatically.
Erasure
The Data Subject has the right to obtain from the Controller the erasure of personal data concerning him or her without undue delay, and the Controller is obliged to erase personal data concerning the Data Subject without undue delay, in particular where one of the following grounds applies:
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed,
- the Data Subject withdraws the consent on which the processing is based and there is no other legal ground for the processing (the withdrawal does not affect the lawfulness of the processing retroactively),
- the Data Subject objects to processing based on legitimate interest,
- the personal data have been unlawfully processed by the Controller,
- the personal data have to be erased for compliance with a legal obligation under Union or Member State law to which the Controller is subject, or
- the personal data were collected in relation to the offer of information society services referred to in Article 8(1) GDPR.
Even where one of the above grounds applies, the Controller is not obliged to erase the personal data processed if the processing is necessary:
- for exercising the right of freedom of expression and information,
- for compliance with an obligation under Union or Member State law to which the Controller is subject which requires the processing of personal data, or on grounds of public interest,
- for statistical purposes or archiving purposes, or for scientific or historical research purposes, in so far as erasure is likely to render impossible or seriously impair that processing, or
- for the establishment, exercise or defence of legal claims.
Right to restriction of processing
The Data Subject has the right to obtain from the Controller restriction of processing where one of the following conditions is met:
- the Data Subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the Controller to verify the accuracy of the personal data,
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead,
- the Controller no longer needs the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise or defence of legal claims, or
- the Data Subject has objected to the processing, in which case the restriction applies for the period pending the verification whether the legitimate grounds of the Controller override those of the Data Subject.
Where processing has been restricted as set out above, such personal data may, with the exception of storage, only be processed with the Data Subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest. Where the restriction of processing is lifted, the Controller informs the Data Subject who requested the restriction of this fact in advance.
Objection to processing
The Data Subject has the right to object, on grounds relating to his or her particular situation, at any time to the processing of his or her personal data under this Privacy Notice that is based on legitimate interest. In that case, the Controller may no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or which relate to the establishment, exercise or defence of legal claims.
Initiating proceedings before the Authority
The Data Subject may initiate an investigation by the Authority by way of a notification, on the grounds that an infringement of rights has occurred in connection with the processing of his or her personal data, or that there is an imminent risk of such an infringement. The investigation of the Authority is free of charge, and the costs of the investigation are advanced and borne by the Authority. No one may suffer any disadvantage on account of having made a notification to the Authority.
Contact details of the Authority: address 1055 Budapest, Falk Miska u. 9-11., email ugyfelszolgalat@naih.hu, website http://naih.hu, telephone +36 (1) 391-1400.
Enforcement of rights before the courts
In the event of an infringement of his or her rights, the Data Subject may bring an action against the Controller before the courts. The adjudication of such an action falls within the competence of the regional court (törvényszék). As a general rule, the regional court of the Controller's registered seat has territorial jurisdiction over the action, but the action may also be brought, at the Data Subject's choice, before the regional court of the Data Subject's place of residence or place of stay. The territorial jurisdiction of the regional court can be checked using the "Bíróság kereső" (court finder) application available on the website www.birosag.hu. The regional court proceeds in the case as a matter of priority.
Compensation
Any person who has suffered damage as a result of an infringement of the data protection legislation is entitled to compensation from the Controller for the damage suffered.
The Controller is liable for any damage caused by processing that infringes the data protection legislation.
The Controller is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
VIII. Data security
The Controller ensures the security of the processing and, to that end, takes the necessary and appropriate technical and organisational measures. It ensures the confidentiality of the personal data (protecting them, for example, against disclosure to the public and unauthorised access), their integrity (against alteration, modification and erasure) and their availability (accessibility and recoverability).
In the course of its processing and related organisational activities, the Controller takes into account the state of the art and the development of science and technology at any given time. In order to maintain data security, it endeavours to apply the most secure technology available, or technology that guarantees a level of data security appropriate to the degree of risk, so as to protect the rights and freedoms of natural persons.
The Controller reserves the right to amend the Privacy Notice unilaterally at any time.
Budapest, 15 August 2024