Privacy
Privacy Notice
This draft follows the verified Website 1.2 technical state and the approved processing decisions. It is not a legal compliance certificate, and live lead collection remains disabled until separately approved for release.
1. Controller
The controller is Kreatív Egészség Kereskedelmi és Pénzügyi Szolgáltató Betéti Társaság, trading under the TOCHNA brand. The official Hungarian legal name is used in this English notice.
- Short name: Kreatív Egészség Bt.
- Registered office and postal address: 8000 Székesfehérvár, Brassói utca 63., Hungary
- Tax number: 25162196-1-07
- Company registration number: 07-06-015859
- Representative as supplied: Bartók Dániel
- Contact: [email protected]
These company details were supplied by the service provider; this draft does not claim an independent company-register verification. We do not publish a telephone number.
2. Scope and information
This notice covers website visitors, people submitting project enquiries, and contacts acting for businesses or organisations. Information about a company is not necessarily personal data by itself, but information identifying an individual contact may be personal data.
The form may collect company name, contact name and email, an optional phone number and website, service area, project description, current process, desired outcome, follow-up answers, timing, optional budget range and notes. We record the language, submission time, the first-party solution-page path that led to the form, and the version and acknowledgement time of this notice.
Person-linked UTM and referrer collection is disabled by default. We do not request passwords, access keys, banking details, identity documents or file uploads.
3. Purposes and legal bases
Business enquiries
To understand and answer an enquiry, arrange discussions and prepare a possible proposal. For a company contact, the intended basis is legitimate interests under Article 6(1)(f) GDPR. Where an individual requests steps towards a contract in their own name, Article 6(1)(b) may apply; it does not automatically apply to an employee merely because their employer may contract with us.
Internal lead handling and scoring
To organise the enquiry, assign responsibility and a next step, flag possible duplicates and create a limited handling priority. The rules-based score uses the supplied budget, timing and field completeness; it is not semantic AI, does not set prices and never rejects an enquiry automatically. Omitting the optional phone number does not reduce the score. An administrator can review the priority. The intended basis is Article 6(1)(f) GDPR.
Security, abuse prevention and backup
Cloudflare Turnstile, a submission UUID and a rate-limit identifier derived from the raw IP address with a separate secret salt may protect the service. The TOCHNA rate-limit table does not store the raw IP address. Security and recovery operations rely on the legitimate interest in secure operation, with safeguards designed around Articles 25 and 32 GDPR.
Acknowledgement of this notice
The required checkbox records that you have read this notice. It is not blanket consent and it is not a marketing subscription. We do not send unsolicited marketing or newsletter emails.
4. Browser storage, cookies and bot protection
For back navigation, the draft remains only in the current page memory. The funnel does not write form data to localStorage or sessionStorage and does not send it to the server before final submission. The draft is therefore not retained after a reload or language switch. The random submission identifier used to reduce duplicate submissions also exists only in current page memory.
Turnstile loads only at the final step when lead collection is enabled. It returns a short-lived, single-use token that is validated by the server. TOCHNA does not request pre-clearance, so the widget's default operation does not require a cf_clearance cookie. Cloudflare's network and security systems may still process technical data.
5. Recipients and providers
Authorised TOCHNA administration personnel can access leads. Cloudflare Pages/Functions hosts the site and endpoint, with Turnstile for bot protection. Leads are stored in the Supabase-based CRM with Frankfurt as the primary region. GitHub Actions runs encrypted database backups and rclone uploads them to a restricted Google Drive folder. Correspondence may currently use a free Gmail account.
Cloudflare and Supabase publish data-processing terms. Before release, the contracting entity for each TOCHNA account, applicability of the GitHub DPA and the exact privacy role of free Gmail/Drive still require account-level verification. We do not assume that the Google Workspace DPA applies.
6. Processing outside the EEA
A Frankfurt primary database region does not mean that every provider operation takes place only in the EEA. Global providers may involve access or processing outside the EEA. An appropriate safeguard under GDPR Chapter V is required; account- and data-flow-level verification remains a release condition.
7. Retention
Website 1.2 does not enable automatic production deletion. A simple enquiry may be retained only while needed to handle it and must then be deleted or restricted after manual review. Correspondence that is necessary business evidence may be assigned to a separate case- or project-specific category of up to five years; this does not cover the whole mailbox and is not restarted by an automatic acknowledgement or irrelevant message. Accounting records belong to a separate statutory category.
Rate-limit records and application logs require short technical retention, but an exact automated production TTL has not yet been verified. Encrypted backups currently retain four weekly and three monthly copies; older copies are not removed after a failed new backup. After a restore, previous erasure and restriction decisions must be reapplied.
8. Your rights
You may request access, a copy, correction and, where applicable, erasure or restriction. You may object on grounds relating to your situation to processing based on legitimate interests and request human review of the score. Send requests to [email protected]. We normally respond within one month; where identity is reasonably in doubt, we request only the additional information needed and do not automatically require an identity-document copy.
9. Complaints and changes
You may complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9., Hungary; email: [email protected]; website: naih.hu. Judicial remedies are also available.
The notice version presented to you is linked to the lead. This draft is not backdated; an effective date can only be set after separate release and legal approval.
Draft identifier: TOCHNA-WEB-PRIVACY-0.10-DRAFT-20260929 · Review date: 29 September 2026.
