Privacy Policy

Effective from: 21 February 2024

1. Introduction

It is very important to us that we comply with current data protection laws and regulations. The following sections provide detailed information about the measures taken by Brick + Data Kft. to protect personal data and our data collection processes.

The data controller is Brick + Data Kft.

Contact details

  • Full legal name: BRICK + DATA Korlátolt Felelősségű Társaság
  • Email address: [email protected]
  • Postal address: 3 Kardhegy Street, Budapest 1116, Hungary

2. Types of personal data and the legal basis for processing

Personal data means any information that makes it possible to identify an individual.

We process the following types of personal data on www.brickdata.hu, based on the legal grounds specified below.

Communication data

This includes any message you send to us through the website, by email, via social media or through any other form of communication.

We process and retain this data so that we can fulfil orders and use it as a basis for decisions in the event of potential legal claims.

The legal basis for processing is the user’s demonstrable interest in our activities, as expressed through messages addressed to us.

Customer data

This includes all data related to the purchase of our services, such as:

  • the customer’s name;
  • billing address;
  • email address;
  • telephone number;
  • details of the purchased service.

We process this data to successfully fulfil orders and maintain legally compliant records of purchases.

The legal basis for storing this data is the performance of the contract concluded between the customer and Brick + Data Kft.

User data

This includes data generated while using the website that allows us to:

  • ensure the technical operation of the website;
  • maintain the security of the website;
  • store backups relating to user activity;
  • provide access to the most relevant content possible.

The legal basis for processing this data is the user’s clear interest in our activities and the need to ensure the technical operation of the website.

Technical data

This includes data generated while using the website, such as:

  • IP address;
  • login information;
  • browser data;
  • time spent on individual pages;
  • page views and navigation paths;
  • the number and time of website visits;
  • time zone;
  • details of the device used to view the website.

This data is collected by the analytics software we use.

We process this data to:

  • analyse user behaviour on the website;
  • maintain the secure operation of the website;
  • understand the effectiveness of our marketing decisions.

The legal basis for processing this data is the user’s clear interest in our activities. This allows us to process the data in accordance with applicable security requirements and improve the effectiveness of our operations.

Marketing data

This includes the visitor’s preferences regarding marketing content. We process this data so that we can send advertisements relating to services in which the user has expressed an interest.

The legal basis for processing this data is the user’s clear interest in our activities. This allows us to process the data in accordance with applicable security requirements and improve the effectiveness of our operations.

We may occasionally use the collected data to:

  • display targeted and relevant advertisements on the Facebook™ platform;
  • advertise through various dynamic advertising platforms;
  • measure the effectiveness of our advertisements.

The legal basis for processing this data is the user’s clear interest in our activities.

Special categories of personal data

As part of our activities, we do not collect special categories of personal data such as:

  • ethnic origin;
  • religious beliefs;
  • information relating to a person’s sex life or sexual orientation;
  • political opinions;
  • trade union membership;
  • health data;
  • genetic or biometric information.

3. Methods of data collection

We may collect personal data directly from users, for example when they:

  • place an order;
  • send us a message.

Certain data may be collected automatically while the website is being used, for example through cookies and similar technologies. These technologies only become active after the user has given their consent.

For more information, please read our Cookie Policy.

We may receive certain data from external partners, including:

  • analytics providers such as Google, which is a partner located outside the EU;
  • advertising networks such as Facebook™, which is a partner located outside the EU;
  • payment service providers such as PayPal, which is a partner located outside the EU, and Barion.

4. Practical measures relating to data protection

Protecting user data and complying with applicable regulations are extremely important to the data controller. We have therefore implemented the following measures:

  • Following a data protection impact assessment of the website, we prepared a list of the data collected, the necessity and legal basis of its collection, and its compliance with applicable legislation.
  • We treat data protection as a priority on www.brickdata.hu and have made significant efforts to ensure the secure handling of information collected through the website.
  • We use an SSL certificate across the entire website to protect data submitted through forms and generated while using the website.
  • We use premium security software to protect the website and stored data against brute-force attacks, malware and other threats.
  • Customer and user data are stored in the website’s databases in encrypted, pseudonymised form, making them unreadable to external parties.
  • Through forms provided in this Privacy Policy, users can request information about the processing of their personal data and ask for their data to be modified or deleted.
  • In the course of our business activities, it may occasionally be necessary to provide data to service partners, such as hosting providers or email marketing services. In such cases, we always select partners that comply with the requirements of the GDPR. In the case of US-based partners, we require participation in the EU–US Privacy Shield data protection framework and enter into a data processing agreement with them to ensure the responsible handling of personal data.

5. Marketing communications

Marketing communications are essential to our business activities. The legal basis for the related data processing is the user’s interest in our services or their explicit consent.

Under the European Union’s Privacy and Electronic Communications Regulations (PECR), we send marketing messages to users who:

  • have purchased from us; or
  • have explicitly consented to receiving marketing messages.

We always provide a clear and easily accessible way to withdraw consent and unsubscribe from marketing messages.

An unsubscribe link is included at the bottom of every email. Users can also request removal from our database by contacting us at [email protected].

After unsubscribing from marketing communications, we may only send messages relating to the fulfilment of orders.

6. Information concerning the sharing of personal data

To maintain our normal business operations, it may occasionally be necessary to share certain personal data with our partners, including:

  • IT service providers and providers that perform troubleshooting and maintenance on IT systems;
  • professional partners, such as lawyers, accountants, bankers and insurers;
  • government authorities that require reports about our activities;
  • payment service providers that securely process bank card details.

International data transfers

To maintain our business operations, it may occasionally be necessary to share user data with service providers operating outside the European Economic Area (EEA).

Countries outside the EEA may not provide the same level of protection for personal data. European legislation therefore prohibits the transfer of personal data in the absence of appropriate safeguards.

Whenever personal data is transferred outside the EEA, we take the following measures in addition to those described in Section 4 to ensure that the data is handled securely:

  • We only transfer data to countries that the European Commission considers to provide an adequate level of data protection.
  • We only use US-based services that participate in the EU–US Privacy Shield data protection framework.

If these conditions are not met, we request the user’s explicit consent before carrying out the data transfer. Consent may be withdrawn at any time.

Links to external websites

This website may occasionally contain links to external websites or embedded code that enables external services to operate.

Clicking these links or using embedded solutions may allow external partners to collect data about users.

Although we make every effort to review our partners appropriately, we have no control over their privacy practices and cannot accept responsibility for how they process personal data.

7. Data retention periods

We retain user data only for as long as required by our legal, accounting or reporting obligations, or for as long as necessary to operate the service.

When determining the appropriate retention period, we consider:

  • the amount of data;
  • the nature of the data;
  • the sensitivity of the data;
  • the potential consequences of a data breach.

For taxation purposes, we are required to retain customers’ billing and purchase data for at least eight years to comply with our legal obligations.

Under certain circumstances, we may use anonymised data for statistical purposes. Such data may be retained indefinitely without further notice.

8. Visitors’ rights

The General Data Protection Regulation (GDPR) provides European Union citizens with the following rights.

Access to personal data

Website users are entitled to request a copy of the personal data stored about them by www.brickdata.hu.

Under normal circumstances, we fulfil such requests free of charge and within 14 days of receiving them.

In the event of repeated, abusive or unfounded requests, Brick + Data Kft. may charge a reasonable fee for providing the data or may require additional time to fulfil the request.

To prevent misuse, Brick + Data Kft. may request proof of identity before disclosing personal data.

To request access to your personal data, contact us at [email protected].

Rectification of personal data

If personal data has changed or was provided incorrectly, the user is entitled to request its rectification.

To request the rectification of personal data, contact us at [email protected].

Requesting the deletion of personal data

Users are entitled to request the deletion of their personal data. We fulfil such requests free of charge and within 14 days of receiving them.

Once personal data has been deleted, the associated user account will no longer be accessible. As a result, any purchased services may also become unavailable, as the personal data linked to the user account may be required to access the service.

To prevent misuse, Brick + Data Kft. may request proof of identity before deleting personal data.

To request the deletion of personal data, contact us at [email protected].

Requesting restriction of personal data processing

Users are entitled to request that the disclosure of their personal data to third parties, such as service providers, be restricted. The request may also specify the service providers to which the restriction should apply.

Please note that cooperation with certain service providers may be essential for the operation of the website. One example is the Barion payment service provider. Restricting access for such providers may make certain website services unavailable to the user.

To prevent misuse, Brick + Data Kft. may request proof of identity before restricting the transfer of personal data.

To request a restriction on the transfer of personal data, contact us at [email protected].

Right to lodge a complaint

In Hungary, the official authority responsible for data protection is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).

Users can find further information about their data protection rights on the NAIH website.

  • Name: Hungarian National Authority for Data Protection and Freedom of Information
  • Address: 22/C Szilágyi Erzsébet Avenue, Budapest 1125, Hungary
  • Postal address: PO Box 5, Budapest 1530, Hungary
  • Telephone: +36 1 391 1400
  • Fax: +36 1 391 1410
  • Email: [email protected]
  • Website: http://www.naih.hu

9. Anonymised data and cookies

On the www.brickdata.hu website, in email messages and in advertisements, we use cookies and similar technologies, including:

  • tracking codes;
  • remarketing tags;
  • pixels.

These technologies only become active after the user has given their consent.

They help us better understand users’ behaviour and interests, enabling us to provide a higher-quality and more effective service.

Our aim is to make www.brickdata.hu as user-friendly and personalised as possible.

Users who wish to prevent these technologies from recording non-personal data can do so by:

  • adjusting their preferences through the cookie notice displayed on the website;
  • disabling cookies in their browser;
  • using the Your Online Choices tool.

Further information about the cookies and tracking technologies used on www.brickdata.hu is available in our Cookie Policy.

Brick+Data logó
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.