Legal information

Privacy notice

What data do we process, why do we need it and what control do you have? This overview helps you find the detailed answers.

How long do we keep your data?

A summary of the periods stated in this notice. Follow the section links for exceptions and conditions.

Scroll sideways to view the table.

Retention periods and links to detailed conditions
PrivacyPeriod and detailed conditions
Contact and quote requestsUntil consent is withdrawn, or, if no contract is concluded, for one year after the offer expires; if a contract is concluded, for eight years. III.1.
Google Analytics cookies and dataThe listed cookies: two years. GA4 event-level data: two months. User-level data: fourteen months. III.2.1.
Google Ads cookiesTypically 90 days. III.2.2.
Cookie consent statusStored in the browser's local storage and removable at any time. We request a new choice when rules affecting consent change. III.2.1.
Rate-limit identifierUp to 24 hours after the last submission, in server memory; removed when the process restarts. III.3.
Hosting provider logsStored by the provider for a short, limited period. The detailed notice does not specify a numerical duration. III.3.
Business outreach databaseUp to twelve months; deleted without delay on objection. Separate rules apply to the suppression list. III.4.

Effective date: 15 September 2025 · Last updated: 24 September 2026

The Prometheus Digital Kft. (the Controller) considers this legal notice binding. It undertakes to ensure that all processing connected with its activities complies with this policy, applicable national legislation and European Union law.


I. Identity of the Controller

Company name
Prometheus Digital Kft.
Registered office
1125 Budapest, Hableány utca 6/A
Company registration number
01-09-434076
Tax number
32910128-2-43
Represented by
Árpád Bretz, managing director
E-mail
info@prometheusdigital.hu
Phone
+36 30 922 2042
Privacy contact
Árpád Bretz, info@prometheusdigital.hu

The Controller is not required to appoint a data protection officer (DPO) under Article 37 GDPR. Please contact the person above with privacy questions.

II. Legislation governing processing

The following legislation applies:

  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data.
  • Information Act: Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
  • E-commerce Act: Hungarian Act CVIII of 2001 on Electronic Commerce Services.
  • Accounting Act: Hungarian Act C of 2000 on Accounting (retention of records).
  • ePrivacy / electronic communications rules: rules on storing information on a user's device (cookies) and the required prior consent [Directive 2002/58/EC on privacy and electronic communications, and section 155(4) of Hungarian Act C of 2003 on Electronic Communications].

III. Data categories, purposes and legal bases

1. Contact and quote requests

  • Data processed: Name, email address, phone number, message content and, if you arrive by clicking an advertisement, the campaign identifiers attached to your enquiry (the link's utm_* parameters, ad-click identifier [e.g. gclid] and landing-page address). These are used only to identify which advertisement led to the enquiry. We temporarily store an ad-click identifier in your browser only if you consent to the marketing cookie category (see section 2).
  • Purpose: Responding to enquiries, preparing quotes and taking steps towards a contract.
  • Legal basis: (i) Your consent to contact and respond to your enquiry [Article 6(1)(a) GDPR]; (ii) where your enquiry concerns a specific quote or contract, steps taken at your request before entering into a contract [Article 6(1)(b) GDPR]. We apply one legal basis to a particular processing operation at a time. Ticking the checkbox relates to consent-based processing and is not a contractual declaration.
  • Nature of providing data: Completing the form is voluntary, not a statutory or contractual obligation. However, your name and email address (or phone number) are needed to respond; without them, we cannot contact you. If a contract is concluded, billing details are required by accounting legislation.
  • Retention: Until consent is withdrawn, or, if no contract is concluded, for one year after the offer expires. If a contract is concluded, eight years under the Accounting Act.

1.1. Online appointment booking

We use Google Calendar appointment booking for 30-minute consultations. The embedded calendar connects to Google only after you select ‘Choose a time’, in a separate booking dialog. On narrow phones, without JavaScript or via the new-tab link, you go directly to Google's booking page.

  • Loading external content: this happens only at your explicit choice. Google then receives technical data, such as your IP address and browser information, and may use cookies to operate its service. Closing the calendar removes the embed; it does not delete data already created in the external service.
  • Booking purpose and data: your selected time, name, email address and information supplied when booking are needed to organise the consultation. The two founders, Árpád Bretz and Félix Bary, manage bookings. The contact conditions above apply to these enquiries.
  • Separate from tracking: opening the calendar does not enable analytics or marketing cookies. We measure opening clicks only with analytics consent, without transmitting personal data or booking details. An opening click is not treated as a completed booking.
  • Other ways to contact us: using the calendar is optional. The contact form, email and phone remain available. Details of Google's processing are in its Privacy Policy .

2. Website visits — analytics and marketing cookies

2.1. Analytics cookies — Google Analytics

  • Data processed: Google Analytics activates only after consent. It then processes device and browser type, pages viewed and approximate location at country/city level. Google Analytics 4 does not store your full IP address.
  • Purpose: Website statistics: analysing popular content and traffic sources to guide content and navigation improvements.
  • Legal basis: The data subject's explicit consent [Article 6(1)(a) GDPR]. Analytics cookies can be accepted or rejected separately by category in the cookie banner. Google Analytics activates only after explicit consent to the analytics category.
  • Cookies used (created only after consent): _ga (distinguishes users, two years), _ga_<measurement-id> (session state, two years).
  • Google Analytics data retention: event-level data is retained for two months and user-level data for fourteen months, as configured in Google Analytics. Aggregated statistics remain available longer without personal data.
  • Storing consent: We store cookie consent status in your browser's localStorage, not in a cookie. The pd-consent key records whether any consent has been given; the pd-consent-meta key stores your category-level choices, the time of the decision and the notice version (Article 7(1) GDPR — accountability). This is not a cookie, is not sent to the server and can be deleted at any time. If notice content affecting consent changes, the previous choice expires and the banner reappears.

2.2. Advertising (marketing) cookies — Google Ads

  • Data processed: Google Ads tracking activates only after explicit consent to the marketing category. It then processes the ad-click identifier, arrival from an advertisement, the occurrence and time of a conversion action (such as submitting a form), device and browser data, and approximate location derived from IP address.
  • Purpose: Measuring advertising results and conversions, evaluating advertising spend and personalising advertisements.
  • Legal basis: The data subject's explicit consent [Article 6(1)(a) GDPR]. The marketing category can be accepted or rejected independently of analytics in the cookie banner, and consent can be withdrawn at any time via ‘Cookie preferences’ in the footer. We then delete the advertising cookies we have set.
  • Cookies used (created only after consent): _gcl_au and other _gcl_* advertising identifiers (linking ad clicks to conversions, typically 90 days).
  • Before consent: until you decide, Google's tracking script does not load, and your IP address is not sent to Google through these scripts. We use Google's basic consent mode: no data is sent without consent.

3. Server logs and abuse prevention

  • Data processed: The hosting provider (Vercel) may create technical logs while serving the website, including IP address, timestamp and request details. Our server code also rate-limits contact-form submissions to prevent abuse. For this, it keeps a pseudonymous identifier derived from the request's IP address in server memory, with submission timestamps. This is a hash salted with a random key held only in the running process's memory, which cannot be reversed without that key. We do not store the IP address itself for this purpose. We also keep an aggregatedaily submission counter that cannot be linked to a person, solely to detect traffic suggesting abuse.
  • Purpose: Operating the website, troubleshooting and maintaining service security, including filtering mass automated form submissions that could prevent genuine enquiries from being delivered.
  • Legal basis: The Controller's legitimate interest in operating the site securely and preventing network abuse [Article 6(1)(f) GDPR; see Recital 49]. We have carried out a legitimate interests assessment, with a summary available on request. You can object under the right to object (see V.6).
  • Retention: The provider retains logs for a short, limited period, then deletes them automatically. The pseudonymous rate-limit identifier is kept for no more than 24 hours after the last submission, the longest rate-limit window, then deleted automatically. It is also removed whenever the server process restarts. It is not stored permanently, used for profiling or used for another purpose.

4. Public business contact data used for direct marketing

To introduce our services, we send business enquiries to publicly listed business contact details. Because this data is not collected directly from the data subject, we provide the following information under Article 14 GDPR.

  • Data sources: We collect data only from publicly accessible sources: the business's own public website and public Google Business Profile. We do not buy databases or obtain data from data brokers.
  • Data categories: Company name, website, publicly listed business email address and phone number; where publicly listed, the contact person's name and role; also the date of outreach and whether a reply was received.
  • Purpose and legal basis: Introducing our services and initiating business contact. Legal basis: the Controller's legitimate interest [Article 6(1)(f) GDPR] in developing relationships with businesses for which our services may be relevant. A summary of the legitimate interests assessment is available free of charge on request.
  • Retention period: Up to twelve months in the outreach database. On objection, the data is deleted without delay.
  • Data processors: Email campaigns use Instantly, operated by Foo Monk LLC, Wyoming, USA; Google Workspace provides email services. See section IV for the processor table and third-country transfers.
  • Suppression list: On objection or unsubscribe, we delete the data but retain the email address and domain on a separate suppression list solely to prevent further outreach. Legal basis: compliance with the obligation under Article 21(3) GDPR [Article 6(1)(c)]. On request, we also delete all data from the suppression list.
  • Your rights: Sections V and VIII explain your rights of access, rectification, erasure, restriction and objection, and your right to contact the supervisory authority, NAIH.

IV. Data processors

The Controller uses the following data processors to provide its services:

Company nameActivityLocation
Vercel Inc.Hosting and server-side technical logsUSA
Resend (operated by Plus Five Five, Inc.)Forwarding contact-form messages by email to the Controller's mailbox; sending takes place in the European Union (Ireland)EU (Ireland) / USA
Google Ireland Ltd.Email (Google Workspace), web analytics (Google Analytics, only with consent), advertising and conversion tracking (Google Ads, only with marketing consent)EU / USA
Instantly (operated by Foo Monk LLC)Business email campaigns (direct marketing under section III.4)USA

Google Ads' role. For advertising processing under Google Ads, Google acts under its own contractual terms as an independent controller rather than a processor, and also uses advertising data for its own purposes. Google's own Privacy Policy governs this processing and is available at policies.google.com/privacy . Processing starts only with your marketing consent.

Transfers to a third country (USA). The Vercel Inc., Google and Resend (Plus Five Five, Inc.) are certified participants in the EU-U.S. Data Privacy Framework , which provides an adequate level of protection under the Commission's adequacy decision [Article 45 GDPR]. Resend also sends form messages using infrastructure in the European Union (Ireland). Transfers to Instantly (Foo Monk LLC) rely on the European Commission's Standard Contractual Clauses [Article 46(2)(c) GDPR]. The data processing agreement containing these clauses forms part of the provider's contractual terms, takes effect on acceptance and is publicly available on its website.

V. Your rights and how to exercise them

1. Access (Article 15 GDPR)

You have the right to confirmation of whether we process your personal data and, if so, access to that data and related information.

2. Rectification (Article 16 GDPR)

You have the right to have inaccurate personal data corrected without undue delay on request.

3. Erasure (‘right to be forgotten’, Article 17 GDPR)

You have the right to request erasure without undue delay when the data is no longer needed, you withdraw consent, you object to processing or the data was processed unlawfully.

4. Restriction (Article 18 GDPR)

You may request restriction if you dispute accuracy, processing is unlawful but you oppose erasure, or we no longer need the data but you require it for legal claims.

5. Data portability (Article 20 GDPR)

You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format.

6. Objection (Article 21 GDPR)

You may object at any time, on grounds relating to your situation, to processing based on legitimate interests, including server logging and rate limiting under section III.3. We then stop processing unless compelling legitimate grounds override your interests. For objections to direct marketing [Article 21(2)–(3) GDPR], there is no balancing: the objection is unconditional and we delete your data for that purpose without delay or further assessment — see the highlighted information in section III.4.

7. Withdrawing consent

You can change or withdraw analytics consent at any time using ‘Cookie preferences’ in the footer to reopen the banner, or by clearing your browser's localStorage. You can request erasure of personal data by emailing info@prometheusdigital.hu . Withdrawal doesn't affect the lawfulness of earlier processing. We delete previously set analytics cookies from your browser when consent is withdrawn. Withdrawal ends consent-based processing prospectively; consent records required for accountability under Article 5(2) GDPR and accounting records remain stored under their respective legal bases for their required retention periods.

8. Exercising rights and response times

Send a request to info@prometheusdigital.hu to exercise your rights. We respond without undue delay and within one month. This can be extended by two months depending on complexity and the number of requests [Article 12(3) GDPR]. Information and action are generally free. If we have reasonable doubts about identity, we may request additional information necessary to confirm it [Article 12(6) GDPR].

VI. Automated decision-making

The Controller does not use decision-making or profiling based solely on automated processing within the meaning of Article 22 GDPR.

VII. Data security

The Controller protects personal data with appropriate technical and organisational measures (Article 32 GDPR): encrypted HTTPS/TLS transmission, access limited to what is necessary and trusted processors only.

VIII. Complaints

If you believe your rights have been infringed, we suggest first contacting us at info@prometheusdigital.hu . If this does not resolve the issue, you may complain to the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary.
Postal address: 1363 Budapest, PO Box 9, Hungary.
Website: www.naih.hu