Privacy Policy — ledfalszaki.hu

What data we process, why and for how long, from the request for a quote through to invoicing — and what you can do if you have a question or an objection.

This document is a translation of the Hungarian original. In the event of any discrepancy or dispute, the Hungarian version prevails. View the Hungarian original
This document is still being finalised. The parts marked in yellow (27 placeholders) are still to be confirmed; the final version will be published on the date it takes effect.
Contents (13 sections)
  1. I. The data controller and its contact details
  2. II. Key terms in brief
  3. III. Principles
  4. IV. The individual processing activities
  5. V. Transfers to third countries (outside the EU/EEA)
  6. VI. Processors and recipients
  7. VII. Data security
  8. VIII. Handling personal data breaches
  9. IX. Automated decision-making, profiling
  10. X. Your rights
  11. XI. Legal remedies
  12. XII. Children
  13. XIII. Amendment of this policy

Data controller: Toma Family Mobil Kft.

Effective from: 24 August 2026 · Version: 1.0

This policy describes what personal data we process when you use the www.ledfalszaki.hu website and the related services (requesting a quote, ordering online, concluding a contract electronically, invoicing, the newsletter, the prize game, the AI assistant, web analytics), for what purpose, on what legal basis and for how long, who has access to it, and what rights you have. This policy has been prepared on the basis of Articles 13–14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR) and Act CXII of 2011 on informational self-determination and freedom of information (Infotv., the Hungarian Information Act).

The site offers LED walls primarily to businesses and institutions, but the name, e-mail address and telephone number of the contact persons (managing directors, buyers, employees) constitute personal data even where they act on behalf of a company — this policy therefore applies to them as well.


I. The data controller and its contact details

Company nameToma Family Mobil Korlátolt Felelősségű Társaság (limited liability company)
Registered office2724 Újlengyel, Petőfi Sándor utca 48., Hungary
Company registration number13-09-172024 (Budapest Környéki Törvényszék Cégbírósága — Company Court of the Budapest Environs Regional Court)
VAT number25034046-2-13
Represented byTamás Tóth, managing director
E-mail (also for data protection matters)info@ledfalszaki.hu
Telephone+36 20 486 40 66 — calls are answered by the customer service of the manufacturing partner, also on behalf of the controller. [TOMI: ha az adatkezelő saját számot kap, ezt itt is át kell írni.]
Websitehttps://www.ledfalszaki.hu

Data protection officer: under Article 37 GDPR the controller is not obliged to designate a data protection officer and has therefore not designated one. You may contact us with data protection questions and requests at info@ledfalszaki.hu, or by post in a letter addressed to the registered office (marked "Adatvédelem" / Data protection); requests are handled by the managing director.


II. Key terms in brief

  • Personal data: any information relating to an identified or identifiable natural person (name, e-mail address, telephone number, IP address, online identifier, etc.).
  • Processing: any operation performed on personal data (collection, recording, storage, transfer, erasure, etc.).
  • Controller: the party that determines the purposes and means of the processing — in this case Toma Family Mobil Kft.
  • Processor: the party that processes personal data on behalf of and on the instructions of the controller (e.g. the hosting provider).
  • Recipient: the party to which we disclose the personal data — it may also be a controller in its own right (e.g. NAV, the manufacturing partner, the courier service).
  • Data subject: you, whose data we process.
  • Consent: your freely given, specific, informed and unambiguous indication of wishes, which you may withdraw at any time.

III. Principles

We process personal data lawfully, fairly and transparently, for specified purposes, limited to what is necessary for the purpose, accurately, only for as long as necessary and with appropriate security (Article 5 GDPR). We only ask for data that is needed to achieve the specific purpose. We do not request or process special categories of data (health, political, religious data, etc.) — please do not provide such data on the forms or to the AI assistant either.


IV. The individual processing activities

4.1 Quote request forms (call-back request, detailed quote request, product-page quote request)

Data processedCall-back request: name, telephone number. Detailed quote request: name, e-mail address, telephone number, company name, VAT number, location/town, message, desired size, environment (outdoor/indoor), intended use. Product-page quote request: the above + up to 3 uploaded photographs of the site (the browser reduces the image to a maximum of 1600 px before upload). Technical data: the time of submission and the IP address of the sender (for the purposes of abuse filtering and of being able to prove the submission; legal basis: Article 6(1)(f) GDPR). [TOMI: az IP-cím megőrzési idejéről dönteni kell — jelenleg nincs külön törlése, az érdeklődéssel együtt marad meg.]
PurposePreparing a quote at your request, making contact, assessing the site and your requirements, calling you back.
Legal basisArticle 6(1)(b) GDPR — taking steps at the request of the data subject prior to entering into a contract. If you provide your data as a contact person on behalf of a company: Article 6(1)(f) GDPR — the legitimate interest of the company in responding to a business enquiry (we have carried out the balancing test and will make it available on request).
Provision of dataVoluntary, but without a name and at least one contact detail we cannot provide a quote.
RetentionIf no contract is concluded: [TOMI: döntés — javaslat 5 év, Ptk. 6:22. § szerinti általános elévülési idő] from the expiry of the validity of the quote. If a contract is concluded: as set out in point 4.3 (8 years). We keep the uploaded photographs for the same period; at your request we delete them earlier if they are no longer needed for preparing the quote.
Storage, recipientsThe website server (Railway — see Chapter V) and the internal customer relationship management (CRM) system (4.2). The manufacturing partner, to the extent necessary for manufacturing/site survey (Chapter VI).
PhotographsPlease try to ensure that no identifiable persons appear in the site photographs; if they do, we use the photograph solely for the technical survey of the site and do not publish it.

4.2 Customer relationship management (CRM) system and logging of quote openings

Data processedThe data of enquirers and customers under points 4.1, 4.3 and 4.4; a timeline (when and what event took place: quote, e-mail, call, order); internal notes; tasks; tags (e.g. which product group you enquired about); quotes, orders, contracts, invoices. The quote is accessible via a unique, unguessable browser link; the system logs the time of opening and the IP address of the opener.
PurposeManaging the customer relationship, tracking quotes and orders, performing the contract; the logging of quote openings serves to evidence delivery of the quote and to detect abuse (unauthorised opening).
Legal basisArticle 6(1)(b) GDPR (preparation and performance of a contract); as regards the internal notes, tags and the opening log, Article 6(1)(f) — legitimate interest (efficient customer management, evidencing, security).
AccessSolely the two internal employees of the controller, with personally attributable Google account log-in (Google OAuth — on log-in Google only passes the employee's name and e-mail address to the system). Access is logged and permission-based.
RetentionUntil the deadlines set out in points 4.1 and 4.3; the internal notes and tags are deleted together with the customer data. The opening log is deleted together with the quote.
Automated decisionTagging has no legal effect and serves internal organisation only; there is no automated decision-making (Chapter IX).

4.3 Online ordering and conclusion of contracts electronically

Data processedBilling name, address, VAT number; e-mail address, telephone number; place of performance; name and contact details of the contact person; the content of the order. Electronic signature: the image of the signature drawn on screen; for authenticating the signature, a one-time SMS code sent to the telephone number provided; audit log: IP address, timestamp, browser identifier (user agent), the result of the verification of the SMS code.
PurposeConcluding the contract, identification, subsequent evidencing of the conclusion and content of the contract (a form suitable for identifying the person making the statement and the time of the statement under Section 6:7(3) of the Hungarian Civil Code; Article 25(1) of the eIDAS Regulation — an electronic signature shall not be denied legal effect solely on the ground that it is in electronic form), performance of the order.
Legal basisArticle 6(1)(b) GDPR — performance of a contract; as regards the audit log, Article 6(1)(f) — legitimate interest (evidencing, prevention of abuse) and Article 6(1)(c) within the scope of the obligation to retain accounting vouchers.
RetentionThe contract and the supporting audit log: 8 years from the termination of the contract (Section 169(2) of the Hungarian Accounting Act, Számv. tv.).
RecipientsThe SMS provider (which sees the telephone number in order to deliver the one-time code): seeme.hu (confirmed in the code: server/lib/sms.mjshttps://seeme.hu/gateway) [TOMI: az üzemeltető cég neve/székhelye az adatfeldolgozói listába]; the manufacturing partner and the courier service, to the extent necessary for performance (Chapter VI).

4.4 Invoicing and NAV online invoice data reporting

Data processedThe mandatory content of the invoice (Section 169 of the Hungarian VAT Act, Áfa tv.): the customer's name, address, VAT number (if any), the details of the supply; the e-mail address for delivering the electronic invoice.
PurposeIssuing and delivering the invoice, bookkeeping, fulfilling tax obligations.
Legal basisArticle 6(1)(c) GDPR — legal obligation: Section 159 of the Hungarian VAT Act (issuing invoices), Annex 10 thereto (online invoice data reporting to NAV, the Hungarian tax authority), Section 169 of the Hungarian Accounting Act.
Retention8 years following the year in which the invoice was issued (Section 169(2) of the Hungarian Accounting Act).
RecipientsNAV (Nemzeti Adó- és Vámhivatal — the Hungarian National Tax and Customs Administration) — the mandatory recipient of the invoice data reporting (a controller in its own right, not a processor); the accountant [TOMI: név, székhely] — processor / controller in its own right within the scope of bookkeeping tasks.

4.5 Sending e-mails (quote, reminders, contract, invoice, notifications) and open tracking

Data processedE-mail address, name, the content of the message (quote, contract, invoice, notification). The quote e-mails contain a tiny transparent image (tracking pixel): if the e-mail client downloads it, the system records the time of opening and the IP address requesting it.
PurposeDelivering the quote, the contract, the invoice and the related notifications; on the 2nd, 7th and 14th day after the quote, a reminder that the quote is still open and that we are happy to help if you have questions; open tracking shows whether the quote has arrived and been opened, so that we do not send unnecessary reminders.
Legal basisDelivery: Article 6(1)(b) GDPR. The quote reminders: Article 6(1)(b) and (f) — messages relating to the quote prepared at your request, not advertisements promoting a new offer [TOMI/JOGÁSZ: ha az emlékeztetők más termékre is ajánlanak, az már Grt. 6. § szerinti reklám → hozzájárulás kell]. Open tracking: Article 6(1)(f) — legitimate interest (evidencing delivery, avoiding unnecessary messages); we have carried out the balancing test.
ObjectionYou may object to open tracking at any time (info@ledfalszaki.hu), and in most e-mail clients you can also prevent it technically by switching off the automatic downloading of images. You may unsubscribe from the reminders at any time using the link in the e-mail or by replying to it.
RetentionThe messages are kept until the retention periods set out in points 4.1/4.3; the opening log is kept together with the quote.
RecipientsWe send outgoing messages through an SMTP provider: RackForest Kft. (1132 Budapest, Victor Hugo utca 18-22. 3rd floor 3008., Hungary) — the mail service runs on their server, confirmed from DNS (MX → mail.ledfalszaki.hu).

4.6 Newsletter subscription

Data processedE-mail address, the time and source of the subscription (form / prize wheel), the fact of consent; the time of unsubscription.
PurposeSending news, promotions, new products and professional content by e-mail (commercial advertising).
Legal basisArticle 6(1)(a) GDPR — your consent; the prior, unambiguous and express consent required by Section 6(1)–(2) of Act XLVIII of 2008 on commercial advertising activity (Grt., the Hungarian Advertising Act). We keep the register of consents required by Section 6(5) of that Act.
UnsubscribingEvery newsletter contains an unsubscribe link at the bottom; you may also unsubscribe at any time at info@ledfalszaki.hu. Unsubscribing is free of charge, requires no reasons, and does not affect the lawfulness of the earlier processing.
RetentionUntil the withdrawal of consent (unsubscription). We retain the fact and time of the unsubscription for [TOMI: javaslat 5 év] in order to maintain the suppression list, so that we no longer send you messages (register under Section 6(5) of the Hungarian Advertising Act).
RecipientsRackForest Kft., which operates the mail server (see the list of processors in Chapter VI).

4.7 Prize wheel game (discount code in exchange for an e-mail address)

The prize wheel is currently switched off; this point takes effect when the controller activates it. [TOMI: élesítéskor dátum + külön játékszabályzat-oldal.]
Data processedE-mail address, the time of the spin, the discount won and the unique discount code (KEREK-…), the expiry and redemption of the code. We store the timestamp of the spin in your browser (see the Cookie Policy).
PurposeParticipation in the game, issuing the unique discount code and checking its redemption (one e-mail address may receive one code within 30 days); and sending the newsletter — the e-mail address taking part in the game is also added to the newsletter list. We indicate this separately and comprehensibly in the text of the consent before the spin; you may unsubscribe from the newsletter at any time in accordance with point 4.6, and any code already issued remains valid.
Legal basisArticle 6(1)(a) GDPR — consent (for both the game and the newsletter; Section 6 of the Hungarian Advertising Act). Applying the discount when the code is redeemed: Article 6(1)(b).
RetentionThe game data (e-mail + code) is retained for [TOMI: javaslat 1 év — a beváltási viták rendezéséhez] from the expiry of the code (30 days from issue), and the newsletter consent until it is withdrawn.
NoteEvery segment wins, and the draw is a weighted random one — it is not based on your personal characteristics, so it is neither profiling nor automated decision-making (Chapter IX).

4.8 AI assistant ("Ádám" chatbot)

Data processedThe text you type into the chat window (questions), the assistant's answers, timestamp. If the text you type contains an e-mail address or a telephone number, the system saves it as an enquiry (lead) together with the text of the question, so that one of our colleagues can contact you. The last 20 messages of the conversation are stored in your browser until the tab is closed (see the Cookie Policy). The chat log does not contain IP addresses.
PurposeAnswering your questions immediately on the basis of the website's knowledge base; monitoring and improving the quality of the service (log); making contact if you provide contact details.
Legal basisArticle 6(1)(a) GDPR — consent, which you give by starting the conversation (by sending the first message) after the chat window has informed you about the transfer of data abroad. For the transfer to a third country: Article 49(1)(a) GDPR — explicit consent having been informed of the risks (see Chapter V) [TOMI: jogi döntés].
Recipient / processorIn order to generate the answer, the text you type (and the history of the conversation) is transferred via an API to the language model provider DeepSeek (Hangzhou DeepSeek Artificial Intelligence Co., Ltd., China). For details, see Chapter V.
What not to providePlease do not enter special categories of data (state of health, political opinions, religion, etc.), bank card, password or identity document data, or the data of other persons. The assistant's answer is for information only and does not constitute an offer.
RetentionChat log: there is currently no automatic deletion, conversations are kept for the lifetime of the system. [TOMI: a rotáció beállítása — javaslat 90 nap; fejlesztési feladat is.] Enquiries saved with contact details are handled as set out in point 4.1.

4.9 Web analytics

A) Google Analytics 4 (measurement ID: G-K602W94NYX) and Google Search Console

Data processedA pseudonymised visitor identifier stored in cookies (_ga, _ga_K602W94NYX), the pages viewed, duration, referring page, device and browser type, approximate (country/city level) geographical location; Google anonymises the IP address and does not store it. Advertising-related storage and personalisation are switched off.
PurposeMeasuring the traffic and use of the website, improving the content and the user experience. Search Console shows, in aggregate, the impressions achieved in Google Search, without any personal data of the visitor.
Legal basisArticle 6(1)(a) GDPR and Section 13/A(4) of the Hungarian E-Commerce Act (Ektv.) — your consent, which you give in the cookie banner. In the absence of consent the measurement does not start and no cookie is placed on your device. (Verified on 24 August 2026: gtag.js is loaded only after acceptance.) Consent may be withdrawn at any time by reopening the cookie banner (footer: "Cookie settings").
ProcessorGoogle Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland); the data may also be processed on the servers of Google LLC (USA) — on the basis of its certification under the EU–US Data Privacy Framework (DPF) (Chapter V).
RetentionUser-level data in GA4: 14 months [TOMI: a GA4 admin → Adatmegőrzés beállítása ellenőrizendő; a Google alapértelmezése 2 hónap, a 14 hónapot külön be kell kapcsolni]; the expiry of the cookies is set out in the Cookie Policy.

B) Own, cookie-free visit counter (the feature exists and is operational: server/lib/latogatas.mjs)

Data processedThe path viewed, the day, the host name of the referring page (not the full address), and a pseudonymised browser fingerprint: the first 16 characters of a SHA-256 digest formed from the calendar day, the IP address and the browser identifier. We do not store the IP address itself. Because the digest changes from day to day, visits cannot be linked across days. To be candid about its limitation: the way the digest is formed is known, so for an ALREADY KNOWN IP address and browser it can be checked back whether they visited the site on a given day — it cannot, however, be reversed.
PurposeSimple, cookie-free visit counting.
Legal basisArticle 6(1)(f) GDPR — legitimate interest (measuring the operation of the service with the least possible processing of data).
Retention400 days — the system automatically deletes rows older than that every six hours (server/lib/latogatas.mjs).

C) Cookie-free event measurement

Data processedCertain events in the use of the site: the day, the type of event (e.g. clicks on the telephone number or the e-mail address, use of the calculator and the wall-size planner, viewing a price on a product page, reading depth), the path of the page and the value of the event. We store no IP address, and we use neither cookies nor browser storage.
PurposeMeasuring which parts of the site actually help the decision — which calculators are used, where people place a call.
Legal basisArticle 6(1)(f) GDPR — legitimate interest (developing the service with the least possible processing of data; the data cannot be linked to a person).
Retention[TOMI: jelenleg nincs automatikus törlés — javaslat 400 nap, a látogatásszámlálóval azonosan.]

4.10 Server logs

Data processedIP address, the time of the request, the URL requested, the HTTP response code, the browser identifier (user agent).
PurposeOperating the service securely, detecting errors and abuse (attacks).
Legal basisArticle 6(1)(f) GDPR — legitimate interest (network and information security, recital (49) GDPR).
Retention[TOMI: az alkalmazás saját hibanaplója — javaslat 30 nap]; Railway retains its platform logs in accordance with its own rules: 7 days on the Hobby/Trial plan, 30 days on the Pro plan, and at most 90 days on the Enterprise plan [TOMI: melyik előfizetési szinten vagyunk] .

4.11 Cookies and browser storage

The cookies and local storage keys (localStorage/sessionStorage) used by the website — by name, purpose, expiry and provider — are set out in the separate Cookie Policy: /en/cookie-policy. Non-necessary (statistical) cookies are only placed on your device with your consent (Section 13/A(4) of the Hungarian E-Commerce Act, Ektv.).

4.12 Contacting us by e-mail or telephone

If you write directly to info@ledfalszaki.hu or call us, we process the data you provide (name, contact details, the content of the message) for the purpose of answering your enquiry, on the basis of Article 6(1)(b) or (f) GDPR; we keep the correspondence for [TOMI: javaslat 5 év] from the closure of the matter, or, where a contract is concluded, as set out in point 4.3.


V. Transfers to third countries (outside the EU/EEA)

RecipientCountryFor whatSafeguard
Railway Corporation (hosting, server)Registered office: 548 Market St PMB 68956, San Francisco, California 94104, USA. The service and the data volume physically run in the EU: europe-west4 (the Netherlands). EU representative: DP-Dock GmbH, Attn. Railway Corp, Ballindamm 39, 20095 Hamburg, Germany (railway-corp@gdpr-rep.com)All data provided through the website (the server and the database run here)Railway's data processing agreement (DPA) incorporates the standard contractual clauses (SCC) adopted by the European Commission: https://railway.com/legal/dpa
Google (Analytics, Search Console, employee OAuth log-in, possibly SMTP)Ireland / USAAnalytics data, the name and e-mail address of the employeesGoogle Ireland Ltd. is an EU processor; Google LLC is among the certified organisations of the EU–US Data Privacy Framework — under the Commission's adequacy Decision (EU) 2023/1419 the transfer is permitted.
Google Fonts (web fonts)Ireland / USAWhen the font file is requested, your browser's IP address and user agentThis happens on every page of the site, before the cookie decision as well, because the font is needed to render the page; it sets no cookie. Legal basis: GDPR Art. 6(1)(f) — legitimate interest in a consistent appearance. Google participates in the EU–US Data Privacy Framework (DPF). [TOMI: ez a kérdés megszüntethető azzal, ha a betűtípusokat saját szerverre költöztetjük — kb. fél napos fejlesztés, és akkor ez a sor törölhető.]
DeepSeek (AI assistant)ChinaThe text typed into the chat and the history of the conversationThere is no adequacy decision issued by the European Commission in respect of China. Risks: under Chinese law state bodies may access data processed at the provider; EU-level remedies and data subject rights cannot be enforced there, or only to a limited extent; the provider may process the submitted texts in accordance with its own terms. Safeguards that we apply: the system sends only the text you type, and does not send your name, IP address or account data; before you type, the window warns you not to provide personal or special categories of data; by starting the conversation you explicitly consent, under Article 49(1)(a) GDPR, to the transfer with the risks described. [TOMI: JOGI DÖNTÉS — három lehetőség: (1) a DeepSeek-kel SCC-t tartalmazó adatfeldolgozási szerződés kötése, ha a szolgáltató ilyet kínál (ekkor a garancia az SCC lesz, a 49. cikk helyett 46. cikk (2) c)); (2) a 49. cikk (1) a) szerinti kifejezett hozzájárulás a fenti szöveggel — ez az EDPB 2/2018 iránymutatása szerint eseti, nem rendszeres továbbításra való, ezért kockázatos; (3) EU-ban működő modellszolgáltatóra váltás, amivel ez a fejezet törölhető.]
SMS provider (seeme.hu)Hungary (expected)Telephone number, the SMS codeNo transfer to a third country if the provider is Hungarian.

We do not transfer data to any other third country. On request we will make available a copy of the relevant safeguards (contracts).


VI. Processors and recipients

NameRegistered officeRoleWhat data, for what purpose
Railway Corp.San Francisco, CA, USAprocessor (hosting, running the application)the entire data set of the website and the API, logs
Google Ireland Ltd.Dublin, Irelandprocessor (Analytics, Search Console); controller in its own right for the log-in (Google account)analytics data; employee name + e-mail for the OAuth log-in; [TOMI: ha Gmail/Workspace SMTP: a kimenő levelek]
Hangzhou DeepSeek Artificial Intelligence Co., Ltd.Hangzhou, Chinaprocessor (language model)the text typed into the chat
[TOMI: SMS-szolgáltató — seeme.hu üzemeltetője, név, székhely]Hungaryprocessortelephone number, one-time code
RackForest Kft. (SMTP, mail server)1132 Budapest, Victor Hugo utca 18-22. 3rd floor 3008., Hungary [TOMI: a Railway `SMTP_HOST` beállításából megerősítendő]processore-mail address, name, the content of the message
[TOMI: könyvelő neve, székhelye][TOMI]processor / controller in its own right (bookkeeping)data of invoices and contracts
Nemzeti Adó- és Vámhivatal (NAV — Hungarian National Tax and Customs Administration)1054 Budapest, Széchenyi u. 2.recipient, controller in its own right (legal obligation)invoice data (Annex 10 to the Hungarian VAT Act)
KORÁD-TRADE Kft. (manufacturing partner)Registered office: 9300 Csorna, Andrássy út 33/A; showroom and workshop: 9025 Győr, Töltésszer utca 3., Hungary [TOMI: a székhely cégjegyzékből megerősítendő]recipient, controller in its own right within the scope of its own performance tasksthe name, address, telephone number and place of performance needed for manufacturing, delivery and on-site installation
[TOMI: futárszolgálat neve][TOMI]recipient, controller in its own rightname, delivery address, telephone number for delivery

We conclude data processing agreements with the processors in accordance with Article 28(3) GDPR, or accept the provider's general data processing terms; they may process the data solely on our instructions and for the stated purpose. Upon request from a court or an authority, we disclose the data prescribed by law.


VII. Data security

In accordance with Article 32 GDPR we apply technical and organisational measures proportionate to the risk, in particular:

  • the website and the API are accessible only over an encrypted (HTTPS/TLS) connection; e-mail traffic takes place over an encrypted channel;
  • the administration and CRM interface is protected by a password or by personally attributable Google account log-in and is accessible only to the two authorised employees; permissions are withdrawn immediately when employment ends;
  • quotes are accessible via a link with a unique, unguessable identifier, and openings are logged;
  • the audit log of the electronic contract (IP, timestamp, browser, SMS authentication) supports the fact that the contract cannot subsequently be altered;
  • regular backups are made of the server data [TOMI: a Railway Volume mentési gyakorisága rögzítendő]; passwords and API keys are not stored in the code but in environment variables;
  • we took into account the security measures contractually undertaken by our processors when selecting them;
  • employees receive data protection training and have access to the data only to the extent necessary for their tasks;
  • the server stores the uploaded photographs in the form already reduced by the browser, in a separate directory, and they are not publicly accessible.

VIII. Handling personal data breaches

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. Upon detecting a breach:

  1. we begin the investigation and the remedial action without delay;
  2. if the breach is likely to result in a risk to the rights of the data subjects, we notify NAIH within 72 hours of becoming aware of it (Article 33 GDPR);
  3. if it is likely to result in a high risk, we also inform the data subjects without undue delay (Article 34 GDPR);
  4. we keep an internal record of every breach — irrespective of the notification obligation (Article 33(5) GDPR): the circumstances of the breach, its effects and the measures taken.

Our processors are obliged to notify us without undue delay of any breach they detect.


IX. Automated decision-making, profiling

The controller does not apply decision-making based solely on automated processing which produces legal effects concerning the data subject or similarly significantly affects them within the meaning of Article 22 GDPR, and does not carry out profiling. The interest tags used in the CRM serve internal organisation, and no automatic decision concerning you is made on their basis. The draw of the prize wheel is a weighted random one and is not based on your personal characteristics. The answers of the AI assistant are for information only and have no contractual legal consequences.


X. Your rights

Under Articles 15–22 GDPR you have the following rights. You may send your request to info@ledfalszaki.hu or by post to the registered office. We reply to the request without undue delay and at the latest within one month; this period may be extended by up to two further months in view of the complexity of the request, of which we inform you within one month (Article 12(3) GDPR). The information and the action are free of charge, except for manifestly unfounded or excessive requests, in particular because of their repetitive character (Article 12(5)). In case of doubt we may request confirmation of your identity (Article 12(6)).

RightWhat it meansGDPR
AccessYou may ask for confirmation as to whether we process your data and, if so, request a copy of it as well as information about the purpose, the recipients, the retention, your rights and the source of the data.Article 15
RectificationYou may request the rectification of inaccurate data and the completion of incomplete data.Article 16
Erasure ("right to be forgotten")You may request the erasure of your data if, for example, it is no longer needed, you have withdrawn your consent, you have objected, or the processing is unlawful. We cannot erase it while a legal obligation (e.g. the 8-year accounting retention) or the establishment of a legal claim justifies the processing.Article 17
RestrictionYou may request that we do not process your data — other than storing it — for example while we verify its accuracy, or if you request restriction instead of erasure.Article 18
Data portabilityYou may receive the data processed by automated means on the basis of consent or a contract in a structured, commonly used, machine-readable format, and may request its transmission to another controller.Article 20
ObjectionYou may object to processing based on legitimate interest (e.g. logging of quote openings, e-mail open tracking, the visit counter, server logs) at any time, on grounds relating to your particular situation; we then continue to process the data only if compelling legitimate grounds justify it. You may object at any time and without giving reasons to processing for direct marketing (advertising) purposes — we then no longer process the data for that purpose.Article 21
Withdrawal of consentWhere processing is based on consent (newsletter, prize wheel, chatbot, analytics cookies) you may withdraw your consent at any time and without giving reasons; this does not affect the lawfulness of the processing before the withdrawal.Article 7(3)
Exemption from automated decisionsWe do not apply such decision-making (Chapter IX).Article 22

We inform every recipient to whom the data has been disclosed of any rectification, erasure or restriction, unless this proves impossible or involves disproportionate effort (Article 19).


1. Complaint to us. Please turn to us first with any complaint about data processing (info@ledfalszaki.hu) — we do our best to resolve it as quickly as possible.

2. Supervisory authority. You have the right to lodge a complaint with the supervisory authority (Article 77 GDPR; investigation under Section 52 of the Hungarian Information Act), in particular in the Member State of your habitual residence:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH — the Hungarian National Authority for Data Protection and Freedom of Information)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Telephone: +36 1 391 1400 · Fax: +36 1 391 1410
E-mail: ugyfelszolgalat@naih.hu · Web: https://www.naih.hu

3. Court. If in your view we have processed your data contrary to the GDPR, you may bring proceedings before a court (Article 79 GDPR). At your choice, the action may also be brought before the regional court (törvényszék) of your domicile or place of residence (Section 23(3) of the Hungarian Information Act); adjudication of the case falls within the competence of the regional court. The court deals with the case as a matter of priority. In the event of damage you may claim compensation, and in the event of a violation of your personality rights you may claim a grievance award (Article 82 GDPR; Section 2:52 of the Hungarian Civil Code).


XII. Children

Our services are not addressed to persons under the age of 16. For the use of an information society service, the consent of a child under the age of 16 is valid only with the authorisation of the holder of parental responsibility (Article 8(1) GDPR). If we become aware that a person under the age of 16 has provided their data without such authorisation, we delete it.


XIII. Amendment of this policy

The controller may amend this policy unilaterally, in particular in the event of a change in legislation, a new service or a new processor. The version in force at any given time is available at https://www.ledfalszaki.hu/en/privacy-policy; we also notify newsletter subscribers and customers of any material change by e-mail. Earlier versions are made available on request.

VersionDateChange
1.024 August 2026first release

Effective from:

Related

Why we are the safe choice
  • In-house manufacturing and on-site installation
  • A licensed electrical engineer on every project
  • Warranty + service team in Hungary
  • On the market since 2014 — Kormos Ádám, villamosmérnök-oktató, 30 év tapasztalat
Opten „A” minősítés 2025Bisnode / Dun & Bradstreet „A”Minősített tanúsítvány