Legal information

Privacy Policy

This English text is a courtesy translation, provided for convenience only. In the event of any discrepancy, the Hungarian version — Adatvédelmi irányelvek — is the legally binding one.

Entry into force: 28 January 2022 · Last amended: 13 July 2026

I. General provisions

The purpose of this notice is to ensure that interiorvibe.hu (hereinafter: the Data Controller) proceeds, in every area of the services it provides, on the basis of and in accordance with the provisions set out in this Privacy Notice when processing personal data. The Data Controller is committed to protecting the personal data of its users and clients, and furthermore regards it as especially important to respect the right of its clients to informational self-determination. The Data Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the highest possible degree of security of the personal data processed. The Data Controller protects personal data by appropriate measures against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental destruction and damage.

In establishing these rules the Data Controller took particular account of the provisions of the Infotv. (Act CXII of 2011 on Informational Self-Determination and Freedom of Information; hereinafter: Infotv.), as well as of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR Regulation”; hereinafter: General Data Protection Regulation).

The scope of this Privacy Notice extends to all data processing activities of the Data Controller concerning natural persons, in particular to the data processing activities carried out on its website [https://interiorvibe.hu/] and on its social media pages [https://www.facebook.com/interiorvibestudio/] and [https://www.instagram.com/interiorvibestudio].

The Notice enters into force on the day of its publication on the website of the Data Controller. The day of publication is 28 January 2022. The day of the last amendment of the Notice: 13 July 2026. The Data Controller reserves the right to amend the Privacy Notice unilaterally, without prior notification of users.

The Data Controller processes exclusively the data provided by users or specified by law, for the purposes set out below. In the case of processing based on voluntary consent, the user may withdraw this consent at any stage of the processing. The scope of the personal data processed must be proportionate to the purpose of the processing and may not go beyond it.

The Data Controller does not verify the personal data provided to it. The user is responsible for the data provided by the User, and for the accuracy and truthfulness thereof. The Data Controller is not liable for damage arising from data provided erroneously or deliberately incorrectly, even if it could have recognised the erroneous nature of the data.

Personal data may be processed exclusively by those staff members of the Data Controller who are authorised to do so, on the basis of the provisions of this notice. The Data Controller does not transfer the personal data processed by it to any third party other than the Data Processors specified in the notice. The Data Processors are entitled to act exclusively in accordance with the contract concluded with the Data Controller and the instructions received from it. The Data Processors are entitled to engage a further data processor only with the consent of the Data Controllers.

II. Principles relating to the processing of personal data

Personal data:

  1. shall be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
  2. shall be collected only for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; in accordance with Article 89(1), further processing for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes shall not be considered to be incompatible with the initial purposes (“purpose limitation”);
  3. shall be adequate and relevant from the point of view of the purposes of the processing, and shall be limited to what is necessary (“data minimisation”);
  4. shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate from the point of view of the purposes of the processing are erased or rectified without delay (“accuracy”);
  5. shall be kept in a form which permits identification of data subjects for no longer than is necessary for achieving the purposes of the processing of the personal data; personal data may be stored for a longer period only insofar as the personal data will be processed, in accordance with Article 89(1), for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes, subject also to the implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subjects (“storage limitation”);
  6. shall be processed in such a manner that, through the application of appropriate technical or organisational measures, the appropriate security of the personal data is ensured, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (“integrity and confidentiality”).

The data controller is responsible for compliance with the above and must furthermore be able to demonstrate such compliance (“accountability”).

III. Identity of the Data Controller

The data controller: Interior Info Kft. (registered office / postal address: 2161 Csomád, Kossuth Lajos út 47.; tax number: 29230660-2-13; e-mail: hello@interiorvibe.hu).

IV. Definitions

Personal data: any data on the basis of which a natural person can be identified;

“any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier, for example a name, a number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” [General Data Protection Regulation, Article 4].

Data subject (user): any specified natural person who is identified on the basis of personal data or who is – directly or indirectly – identifiable.

Consent of the data subject: the voluntary, express and unambiguous consent of the data subject to the processing of his or her personal datum or data;

“any freely given, specific, informed and unambiguous indication of the data subject's wishes by which the data subject, by a statement or by an act unmistakably expressing affirmation, signifies agreement to the processing of personal data relating to him or her” [General Data Protection Regulation, Article 4].

Processing: any operation performed on personal data, e.g.: recording, categorisation, alteration, transmission, erasure;

“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” [General Data Protection Regulation, Article 4].

Data controller: the natural or legal person who determines the purposes and means of the processing – alone or jointly with others; in the case of the services referred to in this Notice, interiorvibe.hu qualifies as the data controller;

“the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may also be provided for by Union or Member State law” [General Data Protection Regulation, Article 4].

Data processor: “the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller” [General Data Protection Regulation, Article 4]; in the case of the services referred to in this Notice, the data processors may be the service providers listed in Chapter VI of this Notice;

Personal data breach: an unexpected event in the course of which the personal data stored by the data controller may be damaged or destroyed, and furthermore unauthorised persons may gain unauthorised access to them;

“a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” [General Data Protection Regulation, Article 4].

Website: the https://interiorvibe.hu/ internet site operated by the Data Controller, and the subpages of this website.

Service(s): the services operated by the Data Controller and provided by the Data Controller, which are available on the website.

V. Scope, legal basis, purpose and duration of the personal data processed

1. Personal data provided in the contact form and in the consultation request form

Personal dataPurpose of the processing
NameNecessary for making contact and for keeping in contact, and furthermore for identifying the user.
E-mail addressNecessary for making contact and for keeping in contact.
Company nameNecessary for making contact and for keeping in contact, and furthermore for identifying the user.
Telephone numberNecessary for making contact and for keeping in contact.
Data of the property (location, size, condition, planned timing)Necessary for clarifying the consultation request and for personalised preparation.
Time of sending the messagePerformance of a technical operation.

Legal basis of the processing: The legal basis for the processing of the personal data provided in the contact form and in the consultation form is the voluntary consent of the data subject.

Duration of the processing: The duration of the processing of the data lasts until the withdrawal of the data subject's consent or until their request for erasure, but at most for 2 years from the last contact.

VI. Data processors

1. Hosting provider / IT service provider

Name of the data processor:Tárhely.Eu Szolgáltató Kft.
Registered office:1144 Budapest, Ormánság utca 4. X. emelet 241.
Company registration number:01 09 909968
Tax number:14571332242
E-mail address:support@tarhely.eu
Telephone number:+36 1 789 2 789
Privacy policy:Yes (https://tarhely.eu/dokumentumok/adatvedelmi_szabalyzat.pdf)
Activity carried out by the data processor:Hosting service, server service, domain service.
Scope of the data processed by the data processor:The network identity of the data subject: the IP address of their computer and the software environment used by the data subject, as well as the time of their visit and the addresses of the pages viewed.
Scope of the data subjects:Natural persons visiting the website.
Purpose of the processing:Ensuring the operation of the website.
Duration of the processing, deadline for the erasure of the data:The data recorded by the server operated by the hosting provider are stored for 30 days, after which they are retained exclusively in anonymised form as visitor statistics.
Legal basis of the processing:The consent of the data subject.

2. Customer relationship management (CRM) system and chat service

Name of the data processor:HighLevel Inc. (“GoHighLevel”, LeadConnector)
Registered office:400 North Saint Paul St., Suite 920, Dallas, Texas 75201, United States of America
E-mail address:privacy@gohighlevel.com (EU data protection contact: privacy@rickert.de)
Privacy policy:Yes (https://www.gohighlevel.com/privacy-policy)
Activity carried out by the data processor:Operation of a customer relationship management (CRM) system, form and chat service.
Scope of the data processed by the data processor:Data provided through the forms and the chat function of the website: name, e-mail address, telephone number, the content of the message, as well as any further data voluntarily provided by the data subject in connection with the enquiry.
Scope of the data subjects:Natural persons who make contact through the website or request a consultation.
Purpose of the processing:Making contact, keeping in touch, managing enquiries and client relationships.
Duration of the processing, deadline for the erasure of the data:Until the data subject withdraws their consent or requests erasure.
Legal basis of the processing:The consent of the data subject.
Transfer of data to a third country:The data may also be stored on servers operating in the United States of America. HighLevel Inc. and LeadConnector LLC hold certification under the EU–U.S. Data Privacy Framework; the transfer of data takes place with the safeguards set out in Chapter V of the GDPR.

VII. Cookies

The meaning of a cookie: files or pieces of information that the user's internet browser downloads from a website and stores on the user's device. Cookies, on the one hand, collect information about the visitors to the website and their devices and, on the other hand, remember the individual settings of the visitors, which may also be used later.

In order to provide a customised service, the Data Controller, or the operator of the website, places on the user's computer – where the user / data subject consents to this – a small data packet, a so-called cookie, and reads it back during a subsequent visit. If the browser sends back a previously saved cookie, the service provider managing the cookie is able to link the current visit of the user with earlier ones, but exclusively with regard to its own content. Cookies therefore make the use of the website easier, as they improve the user experience. Given that the data recorded by cookies cannot be linked to personal data, the Data Controller does not process personal data through the use of cookies. The processing of the data serves exclusively statistical purposes.

The operator of the website is able to place and analyse cookies only if the visitor (data subject) gives their consent to this in the pop-up message shown when the website loads, thereby permitting the analysis. The legal basis of the processing is therefore the voluntary consent of the data subject.

Once cookies have been accepted, the system of the Data Controllers automatically records the following data:

The following types of cookies can be distinguished:

The purpose of session / temporary cookies (session cookies) is to allow visitors to browse the website of the Data Controller fully and smoothly, and to use its functions and the services available there. The validity period of this type of cookie lasts until the end of the session (browsing); when the browser is closed, this type of cookie is automatically deleted from the computer or from the other device used for browsing.

Stored / persistent cookies are those cookies that are used every time the user visits the site. The persistent cookies required for analysis show where the user went within the website, which pages and products they viewed, and what they did. It remains on the client machine depending on the lifetime of the cookie. Functions such as Google Analytics may use them. These cookies do not contain personal data and are not suitable for identifying the visitor.

The user is able to delete the cookie from their own computer, and may also disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under the Privacy settings, under the designation cookie (in Hungarian: süti). By disabling the use of cookies, the user acknowledges that without cookies the operation of the given page is not fully functional. If the user consents to the placement of cookies and does not delete them subsequently, the cookies are automatically deleted after 180 days.

VIII. Google Ads, Google Analytics, Facebook, Microsoft Clarity

The Data Controller also uses the third-party cookies of Google Analytics on its website. By using the Google Analytics statistical service, the Data Controller collects information about how visitors use the website. On the basis of the information saved by the cookies, Google evaluates how the User used the website and also prepares reports for the operator of the website in connection with website activity. It uses the data for the purpose of developing the website and improving the user experience. These cookies likewise remain on the computer of the visitor, or on the other device used for browsing, in its browser, until they expire or until the visitor deletes them. The lifetime of the cookies created by Google Analytics varies: the _ga cookie remains on the device of the visitor for up to 2 years, while the other analytics cookies remain for a shorter period.

The user can prevent the storage of cookies by setting their browser accordingly; in this case, however, it may happen that not all functions of the website will be fully usable. The user can prevent Google from collecting and processing the data generated by the cookies and relating to the user's use of the website – including the IP address – by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu

The Data Controller uses the Microsoft Clarity analytics service on its website for behavioural analytics. Clarity shows, by means of aggregated heatmaps and session replays, how visitors use the website (for example clicks, scrolling, pages viewed); the Data Controller uses the information thus obtained exclusively to develop the website and to improve the user experience. By default, Clarity masks and anonymises the text content entered into forms (for example name, e-mail address, telephone number), so that it is not recorded in the session recordings. During the use of the service, Microsoft may place cookies on the device of the visitor (for example: _clck, _clsk, CLID, ANONCHK, MR, MUID, SM), which serve to distinguish visitor sessions and to operate the service.

Further information about the data processing of Microsoft Clarity and about the Microsoft privacy statement: https://privacy.microsoft.com/hu-hu/privacystatement

The Data Controller runs so-called remarketing advertisements through the advertising systems of Facebook and Google AdWords. These service providers may collect or receive data from the website of the Data Controller and from other internet locations by using cookies, web beacons and similar technologies. By using this data they provide measurement services and target advertisements. The advertisements targeted in this way may appear on further websites belonging to the partner network of Facebook and Google. The remarketing lists do not contain the personal data of the visitor and are not suitable for personal identification.

The Data Controller uses cookies in order to display personalised advertisements to potential users via Google and Facebook.

Further information about the privacy policies of Google and Facebook can be read at the following addresses: https://policies.google.com/privacy and https://www.facebook.com/about/privacy/

YouTube videos may be embedded on certain subpages of the website of the Data Controller. When the playback of an embedded video is started, the operator of YouTube (Google Ireland Limited) may place cookies on the device of the visitor and may collect data in connection with the viewing of the video; without starting the video, such data collection typically does not take place. Further information is available in the privacy policy of Google: https://policies.google.com/privacy

IX. Security of the processing

Taking into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of the processing and the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and the data processor implement appropriate technical and organisational measures in order to ensure a level of data security appropriate to the risk, including inter alia, as appropriate:

  1. the encryption of personal data;
  2. ensuring the ongoing confidentiality, integrity, availability and resilience of the systems and services used for processing personal data;
  3. the ability to restore access to personal data and the availability of the data in a timely manner in the event of a physical or technical incident;
  4. a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of the processing.

Communication of a personal data breach to the data subject:

The data subject does not have to be informed if any of the following conditions is met:

If the data controller has not yet notified the data subject of the personal data breach, the supervisory authority, having considered whether the personal data breach is likely to result in a high risk, may order that the data subject be informed.

X. Data protection officer

No data protection officer has been designated. This is because the Data Controller does not qualify as a public authority or as a body performing a public task, its activities do not include any operation which requires regular and systematic monitoring of users on a large scale, and furthermore the Data Controller does not process special categories of data, nor personal data relating to decisions establishing criminal liability and to criminal offences, and therefore the Data Controller is not obliged to designate a data protection officer.

XI. The rights of data subjects in relation to data processing

The right of access

The data subject may request information as to whether the processing of their personal data is ongoing, and if so, which of their personal data the Data Controller processes, on what legal basis, for what processing purpose, from what source and for how long. Upon such a request the Data Controller shall send information without delay, but within 30 (thirty) days at the latest, to the e-mail contact address provided – or to the postal address requested by the data subject. The Data Controller provides the information in a concise, transparent, intelligibly worded and clear form.

The right to rectification

The data subject may request the Data Controller to rectify or modify any of their data, or to complete incomplete data. The Data Controller shall act on a request to that effect without delay, but within 30 (thirty) days at the latest, and shall send information to the e-mail contact address provided – or to the postal address requested by the data subject – on the fact that the modification of the data has taken place.

The right to erasure

The data subject may request the erasure of the data relating to them. If the data subject withdraws their consent in respect of the data processed on the legal basis of consent, the personal data processed shall be erased. The Data Controller shall arrange for the erasure of the data without delay, but within 30 (thirty) days at the latest, and shall send information to the e-mail contact address provided – or to the postal address requested by the data subject – on the fact that the erasure of the data has taken place.

We shall furthermore erase the personal data of the data subject if their processing is unlawful, if the purpose of the processing has ceased, if they are incomplete or incorrect and this condition cannot lawfully be corrected – provided that erasure is not precluded by law – or if the time limit laid down by law for the storage of the personal data has expired, or if erasure has been ordered by a court or by the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH, the Hungarian National Authority for Data Protection and Freedom of Information).

The right to restriction of processing

The data subject may request the data controller to restrict the processing where one of the following applies:

The right to data portability

The data subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, widely used, machine-readable format, and to transmit those data to another data controller.

The right to object

The data subject has the right to object to the processing. The Data Controller shall examine the objection within the shortest possible time from the submission of the request, but within 15 days at the latest, and shall take a decision on the question of whether it is well founded. It shall send information on its decision to the person submitting the request to the e-mail contact address – or to the postal address requested by the data subject.

XII. Legal remedies available in relation to data processing

In the event of an infringement of their rights, the data subject may bring court proceedings against the Data Controller or against its activities. The court shall deal with the case out of turn. The adjudication of the case falls within the competence of the törvényszék (regional court). The court shall proceed out of turn. The court with venue for the proceedings is the court of the place of the registered office of the data controller, however, the proceedings may – at the choice of the data subject – also be brought before the törvényszék of the place of residence or place of stay of the data subject.

The data subject may lodge a complaint with the Nemzeti Adatvédelmi és Információszabadság Hatóság against the Data Controller or against the data processing. The contact details of the Office are as follows:

Nemzeti Adatvédelmi és Információszabadság Hatóság
Registered office:1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address:1530 Budapest, Pf.: 5.
E-mail:ugyfelszolgalat@naih.hu
Website:http://www.naih.hu
Telephone:06 (1) 391-1400
Fax:06 (1) 391-1410
Privacy Policy | InteriorVibe Studio