Wombat Solution
References Services Wombat ShieldNew About FAQ Contact
EN HU
  • References
  • Services
  • Wombat ShieldNew
  • About
  • FAQ
  • Contact
Book a meeting
Legal

Privacy Notice

How Wombat Solution Kft. collects, uses and protects the personal data of website visitors, clients, contractual partners and other contacts.

Controller
Wombat Solution Kft.
Effective
15 December 2022
Version
1.0

Contents

  1. 01 Data Controller
  2. 02 Scope & Legal Framework
  3. 03 Definitions
  4. 04 Categories of Data
  5. 05 Purposes & Legal Bases
  6. 06 Retention Period
  7. 07 Recipients & Processors
  8. 08 International Transfers
  9. 09 Data Security
  10. 10 Data Breach Notification
  11. 11 Cookies
  12. 12 Your Rights
  13. 13 Automated Decision-Making
  14. 14 Provision of Data
  15. 15 Procedural Rules
  16. 16 Remedies
  17. 17 Other Provisions
  18. 18 Contact & Amendments

01 Data Controller

Company
Wombat Solution Kft.
Registered seat
1173 Budapest, Pesti út 83. Fsz. 2. ajtó, Hungary
Company reg. no.
01-09-409903
Tax number
32165146-2-42
EU VAT number
HU32165146
Bank account
12600016-11258208-11861121 (Wise Europe SA)
Email
hello@wombatsolution.com
Data Protection Officer
not appointed (not required under GDPR Art. 37)

The Company acts as data controller for the personal data described in this notice and is committed to lawful, transparent and secure processing.

02 Scope & Legal Framework

This notice covers the processing of personal data of visitors, clients, contractual partners and other contacts. Processing complies with Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).

03 Definitions

Personal data
any information relating to an identified or identifiable natural person ("data subject").
Processing
any operation performed on personal data (e.g. collection, storage, use, disclosure, erasure), automated or not.
Controller
the entity determining the purposes and means of processing - here, the Company.
Processor
a party processing personal data on behalf of and under the instructions of the controller.
Third party
any person or body other than the data subject, controller or processor.
Consent
a freely given, specific, informed and unambiguous indication of the data subject's agreement to processing.
Data breach
a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

04 Categories of Data

Depending on the relationship, we process:

  • identification and contact data (name, company, email, phone, address);
  • billing and tax data;
  • contractual and communication records;
  • technical data (IP address, browser, log data) generated during website and service use.

05 Purposes & Legal Bases

Contract performance (Art. 6(1)(b))
provision of development, hosting, SEO, automation and consulting services.
Legal obligation (Art. 6(1)(c))
issuing and retaining invoices under Act C of 2000 on Accounting.
Legitimate interest (Art. 6(1)(f))
service security, log analysis, fraud prevention, business communication.
Consent (Art. 6(1)(a))
newsletter, non-essential cookies, marketing.

06 Retention Period

Accounting documents are retained for 8 years (Act C of 2000, § 169). Contract-related data are kept until the expiry of the relevant limitation period (generally 5 years). Data processed on the basis of consent are stored until consent is withdrawn.

07 Recipients & Processors

We use processors acting on our instructions, including hosting and infrastructure providers, accounting and payment service providers, and email/communication tools. Processors handle data only to the extent and for the purposes defined by the Company. No data are sold to third parties.

08 International Transfers

Where a processor is located outside the EEA, transfers take place only with adequate safeguards under the GDPR (e.g. adequacy decision or Standard Contractual Clauses).

09 Data Security

We apply appropriate technical and organisational measures - access control, encryption in transit, regular backups, patch management and monitoring - to protect data against unauthorised access, loss or alteration.

10 Data Breach Notification

In the event of a personal data breach the Company documents the incident and, where it is likely to result in a high risk to the rights and freedoms of natural persons, notifies the affected data subjects and the supervisory authority (NAIH) without undue delay, in line with GDPR Articles 33-34.

11 Cookies

The website uses essential cookies required for operation, and - subject to your consent - analytics and functional cookies. You may manage cookie preferences at any time in the cookie banner or your browser settings.

12 Your Rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. Requests can be sent to the contact in Section 1.

13 Automated Decision-Making

The Company does not carry out automated decision-making - including profiling - that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22).

14 Provision of Data

Providing identification, contractual and billing data is a statutory and contractual requirement; without it the contract cannot be concluded or performed and lawful invoices cannot be issued. Providing data for the newsletter and marketing is voluntary and based on your consent, which may be withdrawn at any time.

15 Procedural Rules

The Company handles data subject requests without undue delay, at the latest within one month (30 days) of receipt. If a request cannot be fulfilled, the Company states the reasons for refusal in writing within the same deadline. Exercising these rights is free of charge, save for manifestly unfounded or excessive requests.

16 Remedies

You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

Address
1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address
1363 Budapest, Pf. 9.
Email
ugyfelszolgalat@naih.hu
Phone
+36 1 391 1400
Website
naih.hu

You may also seek a judicial remedy before the competent court.

17 Other Provisions

The Company does not verify the personal data provided; the data subject is responsible for the accuracy of the data they supply and warrants that they use only their own email address. Investigating authorities, the supervisory authority (NAIH) or other bodies authorised by law may request the Company to disclose data or provide documents. The Company does not record telephone conversations and does not operate an electronic surveillance (CCTV) system. Processing not listed in this notice is subject to information provided at the time of data collection.

18 Contact & Amendments

For any data protection matter contact us via the details in Section 1. The Company reserves the right to amend this notice, with prior notice to data subjects; the current version is always available on the Company's website.

Questions about your data? Write to us at hello@wombatsolution.com

Back to the homepage
Wombat Solution

Web development and maintenance team from Budapest. We build websites, webshops and custom web apps for businesses across Europe and beyond, from audit to launch, with monthly maintenance.

EN HU
Menu
  • References
  • Services
  • Wombat Shield New
  • Client feedback
  • Frequently Asked Questions
  • Privacy policy
Contact
  • hello@wombatsolution.com
  • +36 20 327 9828
© 2026 Wombat Solution Ltd. All rights reserved. Made in Budapest, Hungary