← Vissza a főoldalra

PRIVACY POLICY

1. Introduction

Last Updated: 22. 07. 2026.

Welcome to Chronos Web Tech Kft. ("Company", "we", "our", or "us").

We are committed to protecting your privacy and handling your personal data in a transparent, secure, and lawful manner.

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you visit our website, communicate with us, or request information regarding our IT services.

This Policy applies solely to the Website and related communications unless otherwise specified in a separate agreement.

The Company processes personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
  • applicable Hungarian data protection legislation;
  • other applicable European Union data protection laws.

2. Data Controller

The Data Controller responsible for processing personal data is:

Company Name: Chronos Web Tech Kft.

Registered Office: 8200 Veszprém Virág Benedek u. 4.

Company Registration Number: 19-09-523133

Tax Number: 32013678-2-19

Email: iroda@chronosweb.hu

Website: www.chronosweb.hu

If you have any questions regarding this Privacy Policy or the processing of your personal data, you may contact us using the contact details above.

3. Scope of this Privacy Policy

This Privacy Policy applies to:

  • visitors of the Website;
  • prospective clients requesting quotations;
  • individuals contacting us via email or contact forms;
  • representatives of our business partners;
  • individuals communicating with us regarding our services.

This Policy does not apply to third-party websites linked from our Website.

4. Definitions

For the purposes of this Privacy Policy:

Personal Data means any information relating to an identified or identifiable natural person.

Processing means any operation performed on personal data, including collection, storage, use, disclosure, deletion, or destruction.

Data Subject means the individual whose personal data is processed.

Website means the Company's public website.

Services means the information technology services offered by the Company.

GDPR means Regulation (EU) 2016/679.

5. Categories of Personal Data

Depending on your interaction with the Company, we may collect and process:

Identification Information

  • full name
  • company name
  • job title

Contact Information

  • email address
  • telephone number
  • postal address

Business Information

  • requested services
  • project description
  • estimated project budget
  • technical requirements
  • communication history

Technical Information

  • IP address
  • browser type
  • operating system
  • device identifiers
  • language settings
  • pages visited
  • access times
  • referral URLs

Communication Data

When you contact us, we may retain:

  • email correspondence
  • contact form submissions
  • attached documents
  • project inquiries
  • meeting notes
  • support communications

6. Sources of Personal Data

Personal data may be obtained:

  • directly from you;
  • through contact forms;
  • via email correspondence;
  • during online meetings;
  • through publicly available business information;
  • automatically through cookies and website technologies.

7. Purposes of Processing and Legal Bases

The Company processes personal data only where there is a lawful basis under the General Data Protection Regulation (GDPR). The categories of personal data processed, the purposes of processing, and the corresponding legal bases are set out below.

Purpose of Processing

Personal Data

Legal Basis (GDPR)

Responding to enquiries

Name, email address, phone number, company information

Article 6(1)(b) – Steps prior to entering into a contract

Preparing quotations

Contact details, project information

Article 6(1)(b)

Business communications

Contact details, correspondence

Article 6(1)(f) – Legitimate interest

Contract performance

Client and project information

Article 6(1)(b)

Compliance with legal obligations

Billing and accounting data

Article 6(1)(c)

Website security

IP address, technical logs

Article 6(1)(f)

Fraud prevention

Technical and security information

Article 6(1)(f)

Establishing, exercising or defending legal claims

Relevant personal data

Article 6(1)(f)

The Company does not process personal data for purposes incompatible with those described in this Privacy Policy.

8. Contact Forms and Quote Requests

Visitors may contact the Company through the Website's contact form, by email, telephone, or other communication channels.

When submitting an enquiry or requesting a quotation, Users may be asked to provide:

  • full name;
  • company name;
  • email address;
  • telephone number;
  • project description;
  • technical requirements;
  • other information voluntarily provided.

The Company processes this information solely for the purpose of:

  • responding to enquiries;
  • evaluating project requirements;
  • preparing commercial proposals;
  • communicating with prospective clients.

Providing personal data is voluntary; however, failure to provide certain information may prevent the Company from responding to an enquiry or preparing an accurate quotation.

Submitting an enquiry does not create any contractual relationship between the User and the Company.

9. Business Communications

The Company may process personal data exchanged during communications with clients, prospective clients, suppliers, and business partners.

Such communications may include:

  • emails;
  • telephone conversations;
  • online meetings;
  • project discussions;
  • requests for information;
  • commercial negotiations.

Communications are processed for the purposes of maintaining business relationships, providing requested information, negotiating contracts, and managing ongoing projects.

The Company may retain records of communications where necessary to protect its legitimate interests, comply with legal obligations, or establish, exercise, or defend legal claims.

10. Direct Marketing

The Company does not send marketing communications unless permitted by applicable law or based on the recipient's prior consent where required.

Where Users subscribe to newsletters or marketing updates, the Company may process:

  • name;
  • email address;
  • communication preferences.

Recipients may withdraw their consent at any time by using the unsubscribe link included in marketing emails or by contacting the Company directly.

Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

11. Data Retention

Personal data shall not be retained for longer than necessary for the purposes for which it was collected.

Unless a longer retention period is required by applicable law, personal data is generally retained as follows:

Category

Typical Retention Period

Contact enquiries

Up to 12 months after the last communication

Quotations

Up to 24 months

Client correspondence

Duration of the contractual relationship and applicable limitation periods

Accounting records

As required by applicable accounting and tax legislation

Website logs

Up to 12 months unless longer retention is required for security investigations

Where personal data is no longer required, it is securely deleted or anonymized.

12. International Data Transfers

The Company primarily stores and processes personal data within the European Economic Area (EEA).

Where personal data is transferred outside the EEA, the Company ensures that appropriate safeguards are implemented in accordance with Chapter V of the GDPR, including where applicable:

  • Standard Contractual Clauses (SCCs);
  • adequacy decisions adopted by the European Commission;
  • other lawful transfer mechanisms recognised under the GDPR.

The Company takes reasonable steps to ensure that all recipients maintain an appropriate level of protection for personal data.

13. Cookies and Similar Technologies

The Website uses cookies and similar technologies to ensure its proper operation, improve user experience, maintain security, and collect statistical information regarding Website usage.

Cookies are small text files stored on a user's device when visiting a website.

The Company may use the following categories of cookies:

Strictly Necessary Cookies

These cookies are essential for the operation of the Website and cannot be disabled through the Website's cookie management system.

Examples include:

  • session management
  • security
  • load balancing
  • fraud prevention
  • user preferences required for basic functionality

The legal basis for processing is Article 6(1)(f) GDPR (legitimate interest) or, where applicable, national legislation permitting strictly necessary cookies.

Functional Cookies

Functional cookies allow the Website to remember user preferences, such as language selection and interface settings.

These cookies enhance usability but are not strictly necessary.

Where required by law, they are activated only after obtaining the User's consent.

Analytics Cookies

The Company may use analytics services to better understand how visitors interact with the Website.

Analytics information may include:

  • pages visited;
  • session duration;
  • browser type;
  • device type;
  • approximate geographic region;
  • referral source.

Where legally required, analytics cookies are activated only after obtaining consent.

Marketing Cookies

If marketing technologies are implemented in the future, they will only be used after obtaining explicit consent.

Marketing cookies may be used to:

  • measure advertising effectiveness;
  • remember advertising preferences;
  • improve marketing campaigns.

The Company does not currently use marketing cookies unless explicitly stated through the Website's cookie banner.

Cookie Management

Users may modify or withdraw their cookie preferences at any time through the Website's Cookie Settings or by adjusting their browser settings.

Disabling certain cookies may affect the functionality of the Website.

14. Third-Party Service Providers

The Company may use trusted third-party providers to support the operation of the Website and the provision of its services.

Such providers may include:

  • website hosting providers;
  • cloud infrastructure providers;
  • email service providers;
  • cybersecurity providers;
  • analytics providers;
  • customer communication tools;
  • project management platforms.

Where third-party providers process personal data on behalf of the Company, appropriate Data Processing Agreements (DPAs) are concluded where required by law.

The Company carefully selects providers that implement appropriate technical and organizational security measures.

15. Security Measures

Protecting personal data is one of the Company's highest priorities.

The Company implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Such measures may include:

  • encrypted communications using TLS/HTTPS;
  • secure hosting environments;
  • role-based access control;
  • multi-factor authentication where appropriate;
  • regular software updates;
  • firewall protection;
  • endpoint security;
  • malware protection;
  • regular backups;
  • audit logging;
  • security monitoring;
  • least privilege access principles.

The Company regularly reviews and updates its security practices in light of technological developments and identified risks.

16. Sensitive Personal Data

The Company does not intentionally collect or request special categories of personal data as defined in Article 9 of the GDPR.

Users are requested not to submit sensitive personal data unless specifically requested or legally required.

If a User voluntarily provides sensitive personal data, such data shall be processed only where legally permitted and solely for the purpose for which it was provided.

Appropriate safeguards shall be applied to protect such information.

The Company does not use sensitive personal data for profiling, automated decision-making, advertising, or marketing purposes.

17. Automated Decision-Making

The Company does not make decisions based solely on automated processing, including profiling, that produce legal effects concerning individuals or similarly significantly affect them.

Should such processing be introduced in the future, Users will be informed in accordance with applicable data protection legislation.

18. Artificial Intelligence Technologies

The Company may use artificial intelligence-assisted tools to improve internal productivity, documentation, software development, quality assurance, or customer support.

Where AI-assisted technologies are used, the Company implements appropriate safeguards to protect confidential information and personal data.

The Company does not use personal data collected through the Website to train publicly available artificial intelligence models.

Where AI systems process personal data on behalf of the Company, appropriate contractual and technical safeguards shall be implemented.

19. Google Services

The Company may integrate or use Google services in connection with its Website or the provision of its Services, including but not limited to Google Analytics, Google Maps, Google reCAPTCHA, Google Workspace, Google Calendar, or Google OAuth authentication.

Where Google services are used, personal data may be processed in accordance with Google's own Privacy Policy and applicable contractual arrangements.

The Company shall access only the minimum amount of data necessary to provide the requested functionality.

20. Google User Data

Where a User voluntarily connects a Google Account to a service provided by the Company (for example through Google OAuth or Google Calendar integration), the Company shall process only the data necessary to provide the requested functionality.

Google user data:

  • is processed solely for the purpose explicitly requested by the User;
  • is never sold;
  • is never used for advertising purposes;
  • is never used to create user profiles for marketing;
  • is never disclosed to third parties except where necessary to provide the requested service or where required by law.

The Company does not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.

The use of information received from Google APIs shall comply with the Google API Services User Data Policy, including the Limited Use requirements.

21. Data Retention and Deletion

Personal data shall be retained only for as long as necessary to fulfil the purposes described in this Privacy Policy or as required by applicable law.

Where a User requests deletion of personal data, the Company shall erase such data without undue delay unless:

  • retention is required by law;
  • the data is necessary for the establishment, exercise, or defence of legal claims;
  • another lawful basis for retention applies.

Where Google integrations are used:

  • disconnecting the Google Account or revoking permissions will terminate future access to Google user data;
  • authentication tokens will be securely revoked or deleted;
  • cached Google data, where applicable, will be deleted within a reasonable period unless legal obligations require otherwise.

Users may also request deletion of their personal data by contacting the Company using the contact details provided in this Privacy Policy.

22. Data Subject Rights

Subject to applicable law, Users have the following rights under the GDPR:

  • the right to access personal data;
  • the right to rectification;
  • the right to erasure ("right to be forgotten");
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object to processing;
  • the right to withdraw consent at any time where processing is based on consent;
  • the right not to be subject to decisions based solely on automated processing where applicable.

Requests concerning these rights may be submitted using the contact details provided in this Privacy Policy.

The Company shall respond within the time limits established by applicable law.

23. Complaints

If a User believes that the processing of personal data infringes applicable data protection laws, the User has the right to lodge a complaint with the competent supervisory authority.

For processing activities carried out in Hungary, complaints may be submitted to:

National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary

Website: https://naih.hu

Users may also seek judicial remedies where permitted by applicable law.

24. Third-Party Websites

The Website may contain links to external websites operated by third parties.

The Company is not responsible for the privacy practices, security measures, or content of third-party websites.

Users are encouraged to review the privacy policies of any external websites they visit.

25. Children's Privacy

The Website and Services are intended primarily for business users and adults.

The Company does not knowingly collect personal data from children under the age required by applicable law without appropriate legal consent.

If the Company becomes aware that personal data relating to a child has been collected unintentionally, reasonable steps shall be taken to delete such information promptly.

26. Changes to this Privacy Policy

The Company reserves the right to amend this Privacy Policy at any time in order to reflect changes in applicable legislation, business operations, technological developments, or regulatory requirements.

The latest version shall always be published on the Website.

Where required by law, Users shall be notified of material changes before they become effective.

The "Last Updated" date at the beginning of this Privacy Policy indicates the date of the latest revision.

27. Contact

Questions regarding this Privacy Policy or the processing of personal data may be directed to:

Chronos Web Tech Kft.

Registered Office: 8200 Veszprém, Virág Benedek u. 4., Hungary

Email: iroda@chronosweb.hu

Website: www.chronosweb.hu

The Company will make reasonable efforts to respond to all privacy-related enquiries without undue delay.

Document Information

Document Name: Privacy Policy

Version: 1.0

Effective Date: 20. 07. 2026.

Last Updated: 22. 07. 2026.

Document Owner: Chronos Web Tech Kft.

Classification: Public