This notice explains how personal data is processed when you use rajzterminator.hu (the "Website") and its services. Processing complies with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), Hungarian Act CXII of 2011 on Informational Self-Determination (Info. Act), Act CVIII of 2001 on Electronic Commerce Services, Act C of 2000 on Accounting and Act CL of 2017 on Taxation.
1. DATA CONTROLLER
Name: Győrfi Péter „Pedro" (sole trader)
Address: 9700 Szombathely, Március 15. tér 1. 2/19, Hungary
Registration no.: 40478491 · Tax no.: 75107941-1-38
E-mail: rajzterminator@gmail.com
Phone: +36 30 356 1287
The Data Controller has not appointed a Data Protection Officer (DPO); the Info. Act and GDPR do not require it in this case.
2. DEFINITIONS
- Personal data: any information relating to an identified or identifiable natural person.
- Data subject: you, the Website visitor or the natural person using the service.
- Processing: any operation performed on personal data (collection, storage, use, transfer, deletion, etc.).
- Processor: a third party that processes personal data on behalf of the Data Controller.
3. PRINCIPLES OF PROCESSING
The Data Controller applies the GDPR Art. 5 principles:
- Lawfulness, fairness and transparency
- Purpose limitation – data is used only for the purposes stated below.
- Data minimisation – only what is necessary is collected.
- Accuracy – inaccurate data is corrected without delay.
- Storage limitation – data is stored only for the defined retention periods.
- Integrity and confidentiality – appropriate technical and organisational measures protect data.
- Accountability – the Data Controller is responsible for compliance and able to demonstrate it.
4. PURPOSES, CATEGORIES, LEGAL BASES AND RETENTION
4.1. Contact via e-mail, phone, Messenger, WhatsApp
Data: name, e-mail, phone number, message content, and information you voluntarily provide (event date, location, guest count; for caricature-from-photo: submitted photos).
Purpose: replying to the enquiry, quoting, ongoing contact.
Legal basis: GDPR Art. 6(1)(b) – steps prior to and performance of contract.
Retention: if no contract is concluded, up to 1 year from the enquiry.
4.2. Contract performance and invoicing
Data: name, billing address, tax number if applicable, performance data.
Legal basis: GDPR Art. 6(1)(b) and (c) – contract and legal obligation (Hungarian Accounting Act and Tax Procedure Act).
Retention: accounting documents 8 years (Sec. 169 Accounting Act).
4.3. Caricature ordered from a photo
Data: photograph(s) sent by e-mail.
Legal basis: GDPR Art. 6(1)(b).
Retention: up to 30 days after delivery, then securely deleted. Where other persons appear on the photo, the sender warrants that they have obtained their consent.
4.4. Server logs (Website operation)
Data: visit timestamp, IP address, requested URL, HTTP status, User-Agent (logged automatically by Netlify).
Legal basis: GDPR Art. 6(1)(f) – legitimate interest in secure operation and abuse prevention.
Retention: per the hosting provider's log retention policy (typically 30 days).
4.5. Google Fonts
The Website loads web fonts from Google Fonts (Google Ireland Ltd.). When the browser fetches these, Google may log your IP address and User-Agent under its own privacy notice: policies.google.com/privacy. No cookies are set by the service.
4.6. Social media links
Social media buttons in the footer are plain external links – no data is transmitted to Meta or TikTok before you click. No embedded plug-ins, iframes or tracking pixels are used.
4.7. Analytics
The Website currently uses no analytics service. If one is added in the future, prior consent will be requested via a cookie banner in line with GDPR Art. 7 and the Hungarian E-Commerce Act.
4.8. Photographs taken at events
Data: photographs taken by the Data Controller or their agent at events (corporate events, weddings, private events, etc.) on which the data subjects (client, guests, subjects of the drawings) become visible.
Purpose: reference display in the Website's gallery and on the social media pages linked from the Website (Facebook, Instagram, TikTok) to promote the Data Controller's service.
Legal basis: GDPR Art. 6(1)(a) – the data subject's prior, explicit and voluntary consent, obtained on-site at the event or via the arrangement with the client.
Retention: until consent is withdrawn. Consent can be withdrawn at any time, without justification, at rajzterminator@gmail.com; upon withdrawal the affected image is removed from the Data Controller's own channels without undue delay. Withdrawal does not affect previous lawful processing.
5. COOKIES AND SIMILAR TECHNOLOGIES
The Website does not use its own HTTP cookies. Browser storage is used only where strictly necessary.
5.1. Strictly necessary / functional
rt-exit-popup(sessionStorage) – flags that the exit-intent notice has been shown in the current session. Removed when the browser closes.- Service Worker cache – stores static resources for offline use and faster load. Contains no personal data; can be cleared any time in browser settings.
5.2. Statistical / analytics
Not used at present. If introduced later, prior explicit consent will be required.
5.3. Marketing / advertising
Not used. No first-party or third-party advertising, remarketing or conversion tracker is installed.
5.4. Deleting stored data
You may clear localStorage, sessionStorage and Service Worker cache at any time via your browser's privacy settings. This does not affect lawful use of the Website.
6. PROCESSORS
- Netlify, Inc. (USA, EU-US Data Privacy Framework member) – hosting, server logs.
- Google Ireland Ltd. – Google Fonts CDN, Gmail e-mail service.
- Meta Platforms Ireland Ltd. – Facebook/Instagram profile, Messenger, WhatsApp – external links only.
- TikTok Technology Ltd. (Ireland) – external link only.
7. INTERNATIONAL TRANSFERS
Netlify servers may be located in the USA. Transfer is based on the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, where necessary, EU Standard Contractual Clauses.
8. SECURITY
In line with GDPR Art. 32 the Data Controller applies appropriate measures, including HTTPS/TLS, strict HTTP security headers (CSP, HSTS, X-Frame-Options, Referrer-Policy), password-protected e-mail account with two-step verification, and permanent deletion of submitted photos after the drawing is delivered.
9. YOUR RIGHTS
Under GDPR Art. 15–22 you have the right to access, rectification, erasure ("right to be forgotten"), restriction, data portability, objection, and – where processing is based on consent – to withdraw that consent (without affecting previous lawful processing). Requests can be sent to rajzterminator@gmail.com or by post; we reply free of charge within 30 days.
10. AUTOMATED DECISION-MAKING
No automated decision-making or profiling is carried out.
11. DATA BREACH HANDLING
Any data breach that is likely to result in a risk to the rights and freedoms of natural persons is notified to the Hungarian supervisory authority (NAIH) within 72 hours (GDPR Art. 33). Where the risk is high, affected data subjects are also informed directly (GDPR Art. 34).
12. COMPLAINTS AND REMEDIES
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), naih.hu, 1055 Budapest, Falk Miksa u. 9-11, or seek judicial remedy at the competent Hungarian court.
13. AMENDMENTS
The Data Controller reserves the right to amend this notice unilaterally. Any changes are published on the Website; the current version is always available at /en/privacy.html.
Effective from 2026-07-25.