Privacy policy
This notice describes TerraCode's data processing practices, effective from its publication date until withdrawn or amended.
1. Data controller details
- Botos János e.v.
- 1214 Budapest, Tejút utca 9. 3. em. 6. ajtó
- 61911882
- 91792028-1-43
- info@terracode.hu
- +36 30 604 5489
- Botos János (info@terracode.hu)
2. Data processing statement
This Privacy Policy and Statement ("Policy") sets out the data protection practices of Botos János, sole proprietor (operating under the brand name TerraCode, hereinafter: "Data Controller" or "we"). When you use our services, you provide us with personal data. We handle this data with the utmost care, in accordance with applicable law, and we always aim to meet your expectations regarding data processing. We treat data security as a top priority. The legislation governing our data processing activities includes in particular:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Hungary)
- The Fundamental Law of Hungary
- Act V of 2013 on the Civil Code (Hungary)
- Act C of 2003 on Electronic Communications (Hungary)
- Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Hungary)
- Act CL of 2017 on the Rules of Taxation (Hungary)
- Act C of 2000 on Accounting (Hungary)
- Act CLV of 1997 on Consumer Protection (Hungary)
- Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activity (Hungary)
The purpose of this Policy is to inform users of our services about their rights and obligations relating to the transfer, processing and protection of data, the scope of data we process, and the principles, methods, purposes, legal basis and duration of that processing.
3. Definitions
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC.
- Personal data: any information relating to an identified or identifiable natural person, such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- Special category data: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
- Processing: any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Data subject: an identified or identifiable natural person to whom personal data relates.
- Data transfer: making personal data accessible to a specified third party. Transfers to EEA member states or EU institutions are treated as transfers within Hungary.
- Erasure: rendering data unrecognisable in such a way that it is no longer possible to restore it.
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
- EEA member state: a member state of the European Union and other states party to the Agreement on the European Economic Area, and states whose citizens enjoy the same legal status as EEA nationals under an international treaty.
- Third country: any state that is not an EEA member state.
- NAIH: the National Authority for Data Protection and Freedom of Information, the Hungarian supervisory authority under the GDPR.
4. Basic principles of data processing
Personal data is:
- processed lawfully, fairly and in a transparent manner in relation to the data subject ("lawfulness, fairness and transparency");
- collected only for specified, explicit and legitimate purposes ("purpose limitation");
- adequate, relevant and limited to what is necessary for the purposes for which it is processed ("data minimisation");
- kept accurate and, where necessary, up to date; every reasonable step is taken to ensure that inaccurate personal data is erased or rectified without delay ("accuracy");
- kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which it is processed ("storage limitation");
- processed in a manner that ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("integrity and confidentiality").
As the Data Controller, I am responsible for, and able to demonstrate, compliance with the above principles ("accountability").
5. Data processed
5.1 Contact and free consultation (form)
- Data subjects
- natural or legal persons who request a free consultation or quote via the website's contact form.
- Purpose of processing
- communication, providing a quote.
- Categories of data
- name, company (optional), email address, desired system/package, current website (optional), main business goal, message.
- Legal basis
- GDPR Article 6(1)(a) (consent).
- Retention
- until consent is withdrawn.
Processing details: if you provide your data by completing the contact form, we use it to respond to your inquiry, prepare a quote, and maintain contact. Providing this data is not mandatory, but without it we cannot contact you or respond to your inquiry. You may withdraw your consent at any time without justification; this does not affect the lawfulness of processing carried out before withdrawal.
5.2 Direct marketing (email and SMS marketing)
Collecting marketing consent is already active: a separate, unchecked-by-default checkbox on the contact and booking forms lets you give consent, and we record the fact and time of that consent in the outgoing message. We do not, however, send newsletters or marketing SMS messages yet: this section describes what happens with your consent once sending begins.
- Data subjects
- natural persons who, when completing the form, have expressly consented to marketing communications via a separate, unchecked-by-default checkbox.
- Purpose of processing
- sending newsletters containing advertisements, offers and promotions by email, and marketing SMS messages.
- Categories of data
- name, email address, phone number.
- Legal basis
- GDPR Article 6(1)(a) (consent) and Section 6(1) of the Hungarian Advertising Act (Grtv.).
- Retention
- until consent is withdrawn (unsubscribed).
Processing details: marketing consent is always a separate, voluntary action, independent of the contact or booking request; a single checkbox may not cover both general processing and marketing consent at the same time. The absence of consent does not affect a request for a quote or a booking. You may withdraw your consent at any time, free of charge and without justification: for email marketing, via the "Unsubscribe" link at the bottom of the newsletter; for SMS marketing, by notifying the Data Controller using the contact details in Section 1.
5.3 Appointment booking
- Data subjects
- natural persons who book a time slot for the free 20-minute diagnostic call via the website.
- Purpose of processing
- confirming the booked appointment, holding the meeting, communication.
- Categories of data
- the selected date and time slot, name, phone number (optional), message ("how can we help"), and your email address (the booking is sent by email via your mail client, so your email address is captured in that message).
- Legal basis
- GDPR Article 6(1)(a) (consent).
- Retention
- until consent is withdrawn, or until the meeting and any related follow-up communication is concluded.
Processing details: the data selected during booking is pre-filled into an email that you send to the Data Controller. Providing consent is voluntary; without it we cannot confirm the booking. Consent can be withdrawn at any time, free of charge and without justification, using the contact details in Section 1.
6. Data security
I safeguard the security of the personal data I process through technical and organisational measures and established procedures. Data is protected against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental loss or damage and inaccessibility resulting from changes in the technology used. Personal data is accessible only to the Data Controller and to partners involved in processing who are bound by confidentiality, and only to the extent necessary for their tasks.
To ensure data security:
- possible risks are assessed and taken into account when designing and operating the IT systems, with continuous efforts to reduce them;
- emerging threats and vulnerabilities (such as computer viruses, intrusions, denial-of-service attacks, etc.) are monitored so that preventive or corrective action can be taken in time;
- IT equipment and paper-based information are protected against unauthorised physical access and environmental hazards (e.g. water, fire, power surges);
- IT systems are monitored to detect potential problems and incidents;
- reliability is a key criterion when selecting service providers involved in operations.
7. Data transfers and disclosures
Personal data of individuals using our service is transferred or disclosed only to the partners/processors listed in this section, and to authorities upon official request. A written agreement covering the details of processing is in place with every partner or processor involved in our data processing activities, or the provider's own standard data processing terms are accepted.
Contracted partners involved in processing (Processors):
Vercel Inc. (website hosting and runtime infrastructure provider)
- Registered office
- 340 S Lemon Ave #4133, Walnut, CA 91789, USA
Nature of processing: operation of the infrastructure serving the website. Vercel does not have access to the content of the contact forms, but as part of its technical operation it logs every page request (IP address, browser type, requested URL, timestamp). Under the GDPR, an IP address is personal data, so Vercel qualifies as a processor even if a visitor never submits a form. Third country: yes (USA). Transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and/or, where applicable, the EU-U.S. Data Privacy Framework.
HighLevel Inc. (GoHighLevel / GHL) (CRM system; storage and management of data submitted via the contact form and booking flow)
- Registered office
- 400 North Saint Paul Street Suite 920, Dallas, TX 75201, USA
Nature of processing: storing data submitted through the website's forms and booking flow in a CRM system, supporting communication and quote preparation. Third country: yes (USA). Transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or another appropriate safeguard under GDPR Article 46.
Google Ireland Limited (Google Workspace, operator of the info@terracode.hu mailbox)
- Registered office
- Gordon House, Barrow Street, Dublin 4, Ireland
Nature of processing: contact and booking enquiries arrive by email into the Data Controller's Google Workspace mailbox; the provider may technically have access to message content. Third country: the Data Controller's contracting party is within the EEA (Ireland). Google's sub-processors may include entities outside the EEA; these are covered by Google's Cloud Data Processing Addendum and the Standard Contractual Clauses referenced therein.
Where a processor processes data outside the European Economic Area (EEA), in a third country (e.g. the USA), the transfer is based on Standard Contractual Clauses approved by the European Commission or another appropriate safeguard under GDPR Article 46.
8. Data subject rights
8.1 Right to prior information
Data subjects have the right to receive transparent, clear and easily accessible information in writing from the Data Controller before processing of their personal data begins. This information must be provided at the latest at the time the personal data is obtained. If the Data Controller intends to further process the personal data for a purpose other than that for which it was collected, the data subject must be informed of that other purpose prior to such further processing.
8.2 Right of access
Data subjects have the right to obtain confirmation from the Data Controller as to whether personal data concerning them is being processed, and, where that is the case, access to the personal data and information such as the purposes of processing, the categories of data, the recipients, the envisaged retention period, and the existence of automated decision-making, including profiling. The Data Controller will provide a copy of the personal data undergoing processing; a reasonable administrative fee may be charged for further copies.
8.3 Right to rectification
Data subjects have the right to obtain, without undue delay, the rectification of inaccurate personal data concerning them, including having incomplete personal data completed.
8.4 Right to erasure ("right to be forgotten")
Data subjects have the right to obtain the erasure of personal data concerning them without undue delay, among other cases, where the data is no longer necessary, consent is withdrawn, or the data subject objects to processing and there are no overriding legitimate grounds.
8.5 Right to restriction of processing
Data subjects have the right to obtain restriction of processing, among other cases, where the accuracy of the data is contested, or where the processing is unlawful but the data subject opposes erasure and requests restriction instead.
8.6 Right to notification regarding rectification, erasure or restriction of processing
Data subjects have the right to request information about the recipients to whom their personal data has been disclosed. The Data Controller must inform each such recipient of any rectification, erasure or restriction, unless this proves impossible or involves disproportionate effort.
8.7 Right to data portability
Data subjects have the right to receive personal data they have provided to the Data Controller in a structured, commonly used, machine-readable format, and to transmit that data to another controller, where processing is based on consent or contract and carried out by automated means.
8.8 Right to object
Data subjects have the right to object, on grounds relating to their particular situation, to processing carried out in the public interest or for the purposes of the legitimate interests pursued by the Data Controller or a third party, including profiling based on those provisions.
8.9 Automated decision-making and profiling
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
8.10 Right to be informed of a personal data breach
Data subjects have the right to be informed by the Data Controller of a personal data breach concerning them where that breach is likely to result in a high risk to the rights and freedoms of natural persons.
8.11 Right to lodge a complaint with a supervisory authority
Every data subject has the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the GDPR. Hungarian supervisory authority: National Authority for Data Protection and Freedom of Information (NAIH) (postal address: 1363 Budapest, Pf. 9., Hungary; registered office: 1055 Budapest, Falk Miksa utca 9-11., Hungary; website: www.naih.hu; phone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu).
8.12 Right to an effective judicial remedy against a supervisory authority
Without prejudice to any other administrative or non-judicial remedy, every natural and legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.
Contact details for exercising your rights:
- By post: 1214 Budapest, Tejút utca 9. 3. em. 6. ajtó, Hungary
- By email: info@terracode.hu
- We are unable to provide information relating to personal data by phone, as we cannot verify the identity of the caller.
9. Cookie policy
9.1 What are cookies?
Cookies are small text files placed on your device (computer, smartphone, tablet) by the website through your browser. Some cookies are essential for the site to function, while others serve statistical or marketing purposes.
9.2 Consent to the use of cookies
Necessary cookies are used automatically, as the website could not function properly without them. Statistical and marketing cookies are placed only with your prior, explicit consent, which you can give, refuse, or change at any time via the cookie settings banner on the website.
9.3 Cookie categories we use
Necessary cookies: essential for the basic functioning of the website (e.g. remembering your cookie preferences), these cannot be disabled. Analytics cookies: help us understand how visitors use the website (e.g. Google Analytics). Marketing cookies: used for personalised advertising and campaign measurement (e.g. Meta/Google Ads pixel).
9.4 Managing and disabling cookies
Modern browsers allow you to change your cookie settings. You can configure your browser to prevent the automatic acceptance of optional cookies in the future. You may withdraw or change your consent to statistical and marketing cookies at any time via the cookie settings interface on the website.
9.5 Your rights regarding cookie processing
Under the GDPR, you are also entitled to the rights set out in Section 8 of this Policy in relation to cookie-based processing.
9.6 Data controller and processors
Data Controller: Botos János, sole proprietor (as set out in Section 1). Processors: the partners listed in Section 7, as well as the providers operating statistical/marketing cookies (e.g. Google, Meta), where you have consented to the relevant cookie category.
9.7 Amendments to this Policy
The Data Controller reserves the right to amend this Policy at any time. Data subjects will be notified of amendments upon their next visit to the website. The amended Policy takes effect upon publication.
