Privacy Policy

1. Introduction

1.1. Purpose of the privacy policy

The purpose of this Privacy Policy (hereinafter: “Policy”) is to present in a transparent and detailed manner how personal data is processed during the activities of Zolber Team Kft. (hereinafter: “Data Controller”), as well as to provide information on data subject rights and how to exercise them.

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): determines the uniform EU rules concerning the protection of personal data.
  • Act CXII of 2011 (Infotv.): the act forming the basis of Hungarian data protection regulation, which covers the right to informational self-determination and freedom of information.

This Policy strives to comply with the requirements laid out in the above legislation.


2. Data Controller Details

2.1. Name and contact details of the data controller

  • Name: Zolber Team Kft.
  • Registered office: 2120 Dunakeszi Zrínyi utca 3.
  • Company registration number: 13 09 172563
  • Tax number: 25065446-2-13
  • Representative: Temesvári Zoltán
  • E-mail: info@zolberteam.com
  • Phone number: 0670/532-3934

2.2. Availability of the privacy policy

This Policy is available in electronic form on the website www.zolberteam.hu, and can also be viewed in printed form upon request at our customer service office.


3. Definitions

3.1. Basic GDPR concepts

  • Personal data: any information relating to an identified or identifiable natural person (“data subject”).
  • Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.
  • Data Processor: the natural or legal person which processes personal data on behalf of the Data Controller.
  • Consent: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she signifies agreement to the processing of personal data relating to him or her.
  • Data Subject: any identified or identifiable natural person to whom the personal data relates.

3.2. Definition of a data breach

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.


4. Data Processing Guidelines

  • Lawfulness, fairness and transparency: We process data only for specified and lawful purposes.
  • Purpose limitation: Only for predefined purposes and to the extent necessary to achieve that purpose.
  • Data minimisation: We only collect and process personal data that is essential for achieving the purpose.
  • Accuracy: We ensure that the processed personal data is accurate and, where necessary, kept up to date.
  • Storage limitation: We store personal data only for as long as necessary for the purposes of the processing.
  • Integrity and confidentiality: We apply appropriate technical and organisational measures to ensure the security of personal data.

4.2. Accuracy and security of data

  • Both the Data Controller and the data subject are responsible for the regular updating of data; the latter is obliged to indicate if any change has occurred in their personal data.
  • The Data Controller takes all necessary steps to ensure that the registered data is accurate and protects it from unauthorised access with appropriate security measures.

5.1. Website registration

  • Purpose: Creating a user account and providing related services.
  • Legal basis:
    • Consent (GDPR Article 6(1)(a)) in cases where registration is voluntary and requested by the data subject.
    • Performance of a contract (GDPR Article 6(1)(b)) if registration is a prerequisite for providing the service.
  • Scope of processed data: Name, e-mail address, password (encrypted), date of registration, IP address.

5.2. Order management

  • Purpose: Processing orders, contract fulfillment, invoicing, and delivery.
  • Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
  • Scope of processed data: Name, delivery and billing address, contact details (phone number, e-mail), order details.

5.3. Invoicing

  • Purpose: Compliance with applicable accounting laws (e.g., Act C of 2000).
  • Legal basis: Compliance with a legal obligation (GDPR Article 6(1)(c)).
  • Scope of processed data: Name/company name, address, tax number (for legal entities), other data necessary for invoicing.

5.4. Newsletter sending

  • Purpose: Marketing communication, providing information about new products and promotions.
  • Legal basis: Consent (GDPR Article 6(1)(a)).
  • Scope of processed data: Name, e-mail address.
  • Note: You can unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or by notifying the Data Controller directly.

5.5. Use of cookies

  • Purpose: Ensuring the proper functioning of the website, improving user experience, analyzing visitor data, marketing purposes.
  • Legal basis:
    • Consent (GDPR Article 6(1)(a)) – for all cookies that are not essential for the website’s operation.
    • Legitimate interest or performance of a contract (GDPR Article 6(1)(f) or (b)) – for technical cookies essential for operation.
  • More details: See the “Use of cookies” section of this Policy (Point 11).

Cloudflare Turnstile and Cloudflare cookies

To prevent the unauthorized, automated use of contact and other forms, as well as to filter out spam and malicious bot traffic, our website uses the Cloudflare Turnstile service.

During the operation of the service, certain technical data of the website visitor may be transmitted to Cloudflare, Inc. The transmitted and processed data may specifically include:

  • the user’s IP address,
  • technical data of the browser and device, such as User-Agent information,
  • certain technical characteristics of the network connection,
  • traffic and request data related to the use of the website,
  • and other technical information necessary for the detection of bot traffic.

The purpose of data processing is to determine whether the website and its forms are being used by a real user or an automated system, thereby ensuring the secure operation of the website and preventing abuse.

In providing the service, Cloudflare may use technical cookies or similar technologies necessary for operation and security checks. Depending on the Cloudflare configuration used, this could be, for example, the cf_clearance cookie, which can be used to store the result of a successfully completed security check. The purpose of these technologies is to maintain the security of the website, detect automated and malicious traffic, and handle repeated security checks.

Further information regarding the data processing carried out by Cloudflare Turnstile can be found in the following documents:

Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/

Cloudflare Turnstile privacy policy: https://www.cloudflare.com/turnstile-privacy-policy/

5.6. Social media data processing

  • Purpose: Contact, sharing information (Facebook, Instagram, etc.).
  • Legal basis: Voluntary decision, consent (GDPR Article 6(1)(a)).
  • Note: The independent data processing practices of social media platforms should be reviewed in the privacy policy of the respective platform.

6. Scope of Processed Data

6.1. Types of personal data

  • Identification data: name, username, password (encrypted).
  • Contact data: e-mail address, phone number, address.
  • Technical data: IP address, browser type, cookies, login time.
  • Billing data: billing name, address, tax number (for companies).

6.2. Method and duration of data storage

  • In electronic form on protected servers, secured with passwords and other security solutions.
  • In paper form (if any) at the registered office or site, in a locked area.
  • Storage period: until legal obligations are fulfilled and the data processing purpose is achieved, or until consent is withdrawn. Following this, the data is deleted or anonymized.

7. Rights of Data Subjects

7.1. Right to be informed

The data subject is entitled to request information on the purposes, legal basis, sources, and duration for which their personal data is processed, and who has access to it.

7.2. Right to rectification

If the data subject believes their processed personal data is inaccurate or incomplete, they may request its rectification or completion.

7.3. Right to erasure (“right to be forgotten”)

The data subject may request the deletion of their personal data if the data is no longer necessary for its original purpose, or if the data subject withdraws their consent and there is no other legal basis for the processing.

7.4. Right to data portability

The data subject has the right to receive the personal data they have provided in a structured, commonly used, and machine-readable format, and may request the transmission of this data to another data controller.

7.5. Right to object

  • The data subject may object at any time to the processing of their personal data if the legal basis for processing is the legitimate interest of the Data Controller.
  • The data subject has a specific right to object to the processing of personal data for direct marketing purposes.

8. Data Security

8.1. Protection of electronic data

  • Multi-level authorization system.
  • Regular backups.
  • Use of antivirus software and firewalls.

8.2. Technical and organisational measures

  • Use of a closed office network and secure Wi-Fi.
  • Storage of paper-based documents in locked cabinets.
  • Regular data protection training for employees and data processors.

9. Handling of Data Breaches

9.1. Reporting breaches to authorities (72-hour rule)

In the event of a personal data breach, the Data Controller shall notify the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.

9.2. Informing data subjects in case of high risk

When the personal data breach is likely to result in a high risk to the rights and freedoms of data subjects, the Data Controller shall communicate the breach to the data subjects without undue delay, describing the nature of the breach and the measures taken.


10. Data Processors and Third Parties

10.1. Hosting provider

  • Name: Tárhely.Eu Szolgáltató Kft.
  • Registered office: 1097 Budapest, Könyves Kálmán körút 12-14.
  • Contact: utalas@tarhely.eu, +36 1 789-2-789
  • Data processing activity: web server operation, technical maintenance. Processes personal data only on the instructions of the Data Controller.

10.2. Accountant and other partners

The Data Controller may use an accountant, courier service, marketing agency, and other partners for the processing of personal data.

  • Accountant: Kovács Andrea, Robál Kft. Activity: accounting, payroll, tax-related tasks.

The Data Controller always enters into a written contract with these partners (data processors) in compliance with GDPR requirements. The contracts stipulate that the partners may only process the data based on the Data Controller’s instructions, for the specified purpose, and for the necessary duration.


11. Use of Cookies

11.1. Purpose and types of cookies

  • Session cookies: essential for the operation of the website, deleted when the browser is closed.
  • Functional cookies: improve user comfort, for example, by remembering login details or the selected language.
  • Analytical cookies (e.g., Google Analytics): serve statistical purposes, helping to understand user behavior and improve website functionality.
  • Marketing cookies: support the display of relevant advertisements and the measurement of ad effectiveness.

11.2. Managing user settings

  • Users can control the management of cookies in their browser settings, enabling them to disable or delete them.
  • When modifying cookie settings, some functions of the website may not operate properly.
  • Upon the first visit to the website, it is possible to accept or reject non-essential (e.g., marketing) cookies via a pop-up window.

12. Data Protection Officer

12.1. Conditions and tasks of appointment

Under Article 37 of the GDPR, the Data Controller is obliged to designate a Data Protection Officer (DPO) if its core activities:

  • consist of processing operations which require regular and systematic monitoring of data subjects on a large scale, or
  • consist of processing on a large scale of special categories of data.

The tasks of the officer include:

  • continuously monitoring compliance with the GDPR,
  • advising the Data Controller and the employees,
  • cooperating with the supervisory authority (NAIH) and acting as a contact point for data subjects.

12.2. Status and contact details

The Data Protection Officer reports directly to senior management and cannot be instructed regarding the exercise of their tasks.

  • Name: Temesvári Zoltán
  • Contact: zoltan.temesvari@zolberteam.com, 0670/532-3934

If the Data Controller is not obliged to appoint a DPO but designates one anyway, it appropriately informs the data subjects of this in this Policy.


13. Enforcement of Data Subject Rights

13.1. Filing a complaint with the National Authority for Data Protection and Freedom of Information (NAIH)

If the data subject believes that the processing of their personal data violates applicable laws, they may file a complaint with the National Authority for Data Protection and Freedom of Information:

  • Address: 1055 Budapest, Falk Miksa utca 9-11.
  • Phone: +36 (1) 391-1400
  • E-mail: ugyfelszolgalat@naih.hu

13.2. Right to an effective judicial remedy

In the event of a violation of their rights, the data subject may turn to court. The lawsuit can also be initiated—at the data subject’s choice—before the regional court having jurisdiction over the data subject’s place of residence or stay.


14. Applicable Legislation

14.1. GDPR (Regulation (EU) 2016/679)

Regulation (EU) 2016/679 of the European Parliament and of the Council, aimed at protecting natural persons with regard to the processing of personal data and ensuring the free movement of such data within the EU.

14.2. Act CXII of 2011 on the Right of Informational Self-Determination

The Hungarian data protection act regulating the domestic principles and limitations of the processing of personal data.

14.3. Other relevant Hungarian legislation

  • Act C of 2000 on Accounting.
  • Act V of 2013 on the Civil Code (Ptk.).
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.

15. Final Provisions

15.1. Scope and possible amendments of the Privacy Policy

  • This Policy is effective from July 21, 2026.
  • The Data Controller is entitled to unilaterally amend the Policy, in particular to reflect legislative changes, the introduction of new data processing activities, or recommendations from the supervisory authority.
  • Amendments will be published on the website, and upon taking effect, data subjects accept the new rules by continuing to use the services.

Dated: Budapest, July 21, 2026.

Zolber Team Kft.

Temesvári Zoltán

Let’s work together!