Privacy Notice
This privacy notice summarizes how Digiösvény handles the personal data of visitors, interested parties, customers, and customer service users.
1. The Data Controller
- Data Controller
- Márton Horváth
- Business Name
- DigiXRAY Labs Web Development & Web Design
- Brand Name and Website
- Digital Trail – https://digiosveny.hu/
- Headquarters and mailing address
- Wallstraße 37, 55122 Mainz, Germany
- hello@digiosveny.hu
- Phone
- +36 70 802 4667
Data protection inquiries, requests from data subjects, objections, or withdrawals of consent may be submitted using the contact information provided above. The data controller has not appointed a separate data protection officer.
2. Source of Data and Principles of Data Processing
Data is primarily provided by the data subject when contacting us, requesting a quote, during a website audit, a project needs assessment, via email, phone, AI chat, a customer service ticket, or in the course of fulfilling a contract. Technical data may be automatically generated by the browser, the web hosting service, the security system, and—with appropriate consent—by analytics or advertising services.
If the data does not come directly from the data subject—for example, from an organizational contact person, a file provided by the Client, a public business source, or a technical service provider— the data controller shall use only the data necessary for the specific matter and shall provide the information required under Article 14 of the GDPR within the applicable time limit, unless a lawful exemption applies.
The data controller processes personal data in a manner that is limited to the purpose, to the extent necessary, accurately, securely, and for a period appropriate to the purpose. It is not necessary to submit special categories of personal data, passwords, credit card information, copies of documents, or other unnecessarily sensitive information; such data must not be provided in the free-text fields of forms or in the AI chat.
3. Legal Bases Applied
| Legal Basis | When can it be used? | A typical example |
|---|---|---|
| Article 6(1)(a) of the GDPR | Voluntary, specific, informed, and revocable consent. | No cookies, analytics, marketing, newsletters, or web push notifications are required. |
| Article 6(1)(b) of the GDPR | Performance of a contract or pre-contractual measures taken at the request of the data subject. | Request for a quote, audit request, project coordination, order placement, support. |
| Article 6(1)(c) of the GDPR | The legal obligation incumbent upon the data controller. | Accounting, tax, consumer protection, or regulatory obligations. |
| Article 6(1)(f) of the GDPR | The legitimate interest of the data controller or a third party, provided that the data subject’s rights do not take precedence. | IT security, fraud prevention, business relations, legal claims. |
In the case of data processing based on consent, consent may be withdrawn at any time with future effect. Withdrawal does not affect the lawfulness of prior data processing.
4. Web Hosting, Storage, and Security Logs
Hosting is provided by HOSTINGER operations, UAB. When the website is accessed, the server, the WordPress system, and the security solutions—including, in particular, WP Cerber Security, Security Optimizer, and the functions of the associated infrastructure—may process your IP address, access time, requested URL, referring page, browser and device characteristics, response code, and security events.
| Goal | Legal Basis | Recipients | Preservation |
|---|---|---|---|
| Website delivery, availability, troubleshooting, and prevention of attacks and abuse. | GDPR Article 6(1)(f); for the requested service, Article 6(1)(b) as necessary. For device access, the necessity exception under Section 25(2) of the TDDDG may apply. | Hosting provider, security and maintenance provider, authorized system administrator. | Standard access and security logs are retained for a short period as required for technical purposes, generally for no more than 30 days; in the event of an incident, for evidentiary purposes, or to comply with a legal obligation, they are retained until the relevant process is completed. |
Cloudflare Turnstile or another CAPTCHA solution can be used to reduce automated abuse and spam submissions. As part of this process, technical browser, device, and network data may be transmitted to the service provider as configured.
5. Contact, Audit, and Needs Assessment Forms
In the context of forms based on Elementor or Fluent Forms and direct inquiries, the following data in particular may be processed: name, email address, phone number, website address, message, project objective, service request, submission time, referring page, form and submission ID, as well as technical verification of having read this notice.
Objective: identification, responding, follow-up calls, preparing proposals or audits, needs assessment, and documenting the inquiry and subsequent project.
Legal Basis: For an interested individual, Article 6(1)(b) of the GDPR typically applies; for an organizational contact person, in addition to the contractual purpose, the legitimate interest in maintaining business relations under Article 6(1)(f) of the GDPR may also apply.
Data Reporting: Without the information marked as required, the request cannot be processed, or can only be processed to a limited extent. The phone number should be required only if the requested service actually requires a callback; in other cases, it is optional to ensure data minimization.
6. Communication via Email, Phone, and Social Media
When contacting us via email or phone, we may process the sender’s or caller’s name, email address, phone number, the content and date/time of the message or conversation, delivery and error information, as well as any replies and related attachments.
Objective: responding to inquiries, submitting quotes, fulfilling contracts, handling complaints, providing customer service, and maintaining verifiable records of business communications.
Legal Basis: Article 6(1)(b), (c), or (f) of the GDPR, depending on the nature of the matter. In the technical delivery of the email, the hosting, email account, or SMTP service provider may act as a data processor.
When you open a link to Facebook, Messenger, or WhatsApp, the relevant third-party service provider may process technical and account data at its own discretion. Digiösvény does not forward the data provided on the form to these service providers before the third-party service opens.
7. FluentCRM, Customer and Project Management
Inquiries can be recorded in the FluentCRM system, which runs on a local WordPress database. In addition to contact information, you can manage the inquiry’s source, brand, selected service path, status, project phase, last message, consent status, customer service reference, internal summary, and assigned agent.
Objective: Preventing the loss of inquiries, consistent client communication, project and grant processes, task assignment, and managing proof of consent and communication history.
Legal Basis: GDPR Article 6(1)(b) and (f); for accounting or legal documents, Article 6(1)(c). Being added to the CRM system does not in itself constitute authorization to send advertisements. Contacts may only be added to marketing automation with appropriate, documented marketing consent.
8. Customer Service Portal and SupportCandy
The following fields can be managed on the customer service portal and in the SupportCandy system: name, email, user ID or ticket ID, subject, message, category, priority, status, attachments, replies, timestamp, assigned agent, and technical log. The Email Piping feature can convert incoming emails into customer service tickets and turn replies into continuations of existing tickets.
Objective: Receiving, investigating, responding to, escalating, and verifiably resolving support, complaint, billing, data protection, or security issues.
Legal Basis: Article 6(1)(b), (c), or (f) of the GDPR, depending on the nature of the matter. Data from the customer service system may not be used for sales or advertising purposes without a separate legal basis.
Do not send unnecessary passwords, complete credit card information, sensitive personal data, or other disproportionately sensitive information in attachments.
9. AI Assistant and AI-Powered Internal Processing
The website and internal workflows may use AI features, including, in particular, the Digiösvény Omnichannel AI Bridge, the Smart Publish AI modules, the WordPress AI system, and the features of any external AI service providers that have actually been configured.
During AI chat or AI-assisted processing, the following may be processed: messages, conversation history, session IDs, technical metadata, voluntarily provided contact or project information, as well as internal summaries, topic, status, or route suggestions derived from these.
- The direct communication interface clearly indicates that the user is communicating with an AI system.
- AI responses may be incorrect; human review is required for contractual, legal, financial, data protection, or safety-critical decisions.
- Do not enter passwords, health information, identification documents, payment information, or other particularly sensitive information into the AI chat.
- When using an external AI service provider, the message and the context necessary for its operation may be transmitted to the service provider in accordance with the agreed-upon terms and conditions for data processing and data transfer.
Legal Basis: for the function requested by the user, Article 6(1)(b) of the GDPR; for customer service and process security, Article 6(1)(f); Article 6(1)(a) for non-essential tool storage or optional analysis, as well as Section 25 of the TDDDG.
A summary or route suggestion generated by AI serves as an internal decision-making aid. Digiösvény does not use any fully automated decisions that would have legal effects on the data subject or similarly significantly affect them.
10. CookieYes Consent Management
The CookieYes system manages user preferences regarding non-essential technologies. Within this framework, the following data can be managed: consent ID, country, status, date and time, audit trail, and the IP address, which is masked in accordance with the provider’s instructions.
Objective: Conducting, recording, and verifiably documenting the election.
Legal Basis: The processing of consent pursuant to Section 25 of the TDDDG, as well as Article 6(1)(c) and (f) of the GDPR, for the purposes of complying with a legal obligation and demonstrating consent.
11. Statistics, Behavioral Analysis, and Marketing
Google Analytics 4 / Site Kit, Microsoft Clarity, Google Ads, Meta Pixel, and Microsoft Advertising UET—provided that the respective service is actually configured and active—can only be used after the appropriate consent category has been enabled.
| Data Processing | Key Statistics | Legal Basis | Goal |
|---|---|---|---|
| Google Analytics 4 | Anonymized visitor, device, event, source, and session data. | Article 6(1)(a) of the GDPR; Section 25(1) of the TDDDG. | Traffic, Performance, and Content Development. |
| Microsoft Clarity | Interaction, navigation, heatmap, and session replay data; the configuration must mask the contents of the input fields. | Article 6(1)(a) of the GDPR; Section 25(1) of the TDDDG. | Analysis of usability errors and navigation patterns. |
| Advertising and Conversion Tracking | Campaign, click, event, device, and pseudonymized advertising identifiers. | Article 6(1)(a) of the GDPR; Section 25(1) of the TDDDG. | Campaign impact, conversion, and—with separate authorization—remarketing. |
The detailed list of technologies, identifiers, and durations is available at In the Cookie Policy can be found. Unnecessary meter codes must be technically blocked until the appropriate authorization is granted.
12. Web Push, PWA, and Language Preferences
Gravitec Web Push
Browser notifications may only be sent after obtaining specific permission from the browser and—where necessary—the appropriate consent. The push endpoint, browser key, device, and subscription status can be managed. Legal basis: Article 6(1)(a) of the GDPR. Permission may be revoked at any time in the notification settings of the browser or operating system.
PWA and Service Session
The Smart Publish AI PWA or other installable web application features may use service workers, caching, and local settings to provide the requested functionality. Tracking is not required; these features can only be used with consent.
TranslatePress
A local identifier or cookie may be used to store language preferences. The purpose is to ensure that the language selected by the user is displayed. The legal basis, depending on the requested function, is Article 6(1)(b) or (f) of the GDPR, as well as the necessity exception under Section 25(2) of the TDDDG.
13. Recipients, Data Processors, and Third Countries
As necessary, the following groups of recipients may have access to personal data:
- HOSTINGER operations, UAB, and authorized infrastructure providers;
- email, SMTP, maintenance, security, backup, and technical service providers;
- CookieYes, Cloudflare, Gravitec, and the provider of the feature that is actually enabled;
- Google, Microsoft, Meta, or the actual AI service provider, provided that the appropriate functionality and legal basis exist;
- an accountant, legal representative, insurance company, government agency, or court, if justified by a legal obligation or the enforcement of a claim.
As a general rule, the core data for Elementor, Fluent Forms, FluentCRM, and SupportCandy—which operate within WordPress—is stored in the website’s own hosting database; however, this does not preclude the use of a separate service provider for licensing, email, AI, security, or integration features.
Transfers outside the European Economic Area may only take place with the safeguards provided for in Chapter V of the GDPR: an adequacy decision—for example, the EU-U.S. Privacy Shield for eligible U.S. recipients—or on the basis of standard contractual clauses adopted by the European Commission and supplementary measures as necessary.
14. Retention Periods
| Data Set | Main Preservation Rule |
|---|---|
| Server and Security Log | For a short period of time determined by technical necessity, generally no more than 30 days; in the event of an incident, until the investigation and claims process are concluded. |
| Unsuccessful inquiry or request for a quote | No more than 6 months from the date the inquiry is substantively closed, unless a legal claim, repeated contact, or specific consent justifies a longer retention period. |
| Contract and Project Communication | During the performance of the contract, and thereafter for a period commensurate with the statute of limitations for civil claims and the need for evidence. |
| Business letters, invoices, and tax documents | Depending on the type of document, the period is 6, 8, or 10 years under German law. |
| Customer Service Ticket | As a general rule, 3 years after closure; in the case of contractual, billing, complaint, or legal dispute-related materials, the longer statutory or claim enforcement period applies. |
| Marketing or Push Notification Consent | Until revoked; proof of consent may be retained for a limited period necessary to enforce legal claims. |
| Statistical and Marketing Identifiers | For the period specified in the Cookie Notice and the consent panel, or until consent is withdrawn. |
| AI Chat and AI Summary | Session data is retained for as long as technically necessary; case-related content is retained in accordance with the retention policy for the specific case. |
Upon expiration of the retention period, the data must be deleted or irreversibly anonymized, unless there is a further lawful basis for retention.
15. Rights of the Data Subject
Under the terms of the GDPR, you may request:
- information and access to processed data;
- correcting inaccurate data and supplementing missing data;
- erasure or restriction of data processing;
- data portability in the case of automated data processing based on consent or a contract;
- objection to data processing based on Article 6(1)(f) of the GDPR;
- withdrawal of consent for the future;
- a request for human intervention if, under applicable law, an automated decision would affect the individual.
The request is the hello@digiosveny.hu may be sent to the address provided. The data controller may request additional information, to the extent necessary, to verify the identity of the individual and the validity of the request.
Right to File a Complaint
A complaint may be filed, in particular, with the authority with jurisdiction over the data controller’s registered office:
- Authority
- The Data Protection and Freedom of Information Commissioner of the Land of Rhineland-Palatinate
- Visiting Address
- Hintere Bleiche 34, 55116 Mainz, Germany
- Mailing Address
- P.O. Box 30 40, 55020 Mainz, Germany
- Phone
- +49 (0) 6131 8920-0
- poststelle(at)datenschutz.rlp.de
- Website
- https://www.datenschutz.rlp.de/
The data subject may also contact another EU supervisory authority based on their usual place of residence, place of work, or the location of the alleged infringement.
16. Profiling and Automated Decision-Making
With the user’s consent, analytics and marketing systems may create a pseudonymized interest or campaign profile. The CRM and AI systems can classify inquiries by topic, status, risk, or the next required step.
Digiösvény does not use any fully automated decision-making processes that would have legal effects on the data subject or similarly significantly affect them. Offers, contracts, complaints, data protection requests, payment issues, and significant customer decisions are all subject to human review.
17. Amendments to the Prospectus and Related Documents
This privacy policy may be amended if there are changes to the service, the technology used, the list of data processors, or legal requirements. The current version is available on this page, with the date of any material changes indicated.
Document version: PRIV-2026-08-10. This document must be reviewed in the event of any significant changes to the services, the technical system, or applicable law.