Legal

Privacy Policy

Last updatedOn this page17 sections

Questions about your data?

Write to me directly, I reply personally.

alex@foldvari.chSee the full Legal Notice (Impressum)

Overview

This page explains what personal data this website collects, why, on what legal basis, who it is shared with, how long it is kept and what rights you have. I only collect what is needed to run the site, respond to enquiries and, with your consent, measure my advertising.

Data controller

The controller responsible for the processing described here is Alex Földvári. The full legal identity and address are in the Legal Notice (Impressum). For any data-protection request you can contact:

A Data Protection Officer is not legally required for this processing and none has been appointed; please direct all data-protection requests to the contact address above.

Categories of personal data

The categories of personal data I process are: (1) identity and contact data you provide (name, email, phone, message content); (2) technical and usage data (IP address, anonymised for analytics and only briefly kept in security logs, device, browser and operating system, pages viewed, referrer, approximate country); (3) online identifiers stored in cookies or local storage (session id, campaign / attribution ids, analytics and advertising cookie ids); (4) consent data (your cookie choices, the policy version and a timestamp); and, only with Marketing consent, (5) hashed identifiers sent to Meta (your email, phone, first and last name and a pseudonymous session id, each SHA-256 hashed). I do not intentionally process special categories of data.

Analytics (Google Analytics 4)

With your Analytics consent, this site loads Google Analytics 4 to understand how visitors use the site. GA4 processes:

  • Anonymised IP address (IP anonymisation is enabled by default in GA4).
  • Device, browser and operating system information.
  • Pages visited, time spent and referrer (which site you came from).
  • Approximate location (country / city level), derived from the IP address.
  • Pseudonymous user and session identifiers stored in cookies.

Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 31 revFADP). Provider: Google Ireland Ltd / Google LLC (USA). You can withdraw consent at any time via Cookie settings.

First-party website statistics

With your Analytics consent, the site keeps simple, first-party visit statistics on my own infrastructure (no third-party advertising network). This processes:

  • A pseudonymous session id and campaign attribution (UTM tags; the fbclid ad-click id only with Marketing consent), stored in your browser.
  • The pages and key actions on the site (landing, opening a form, submitting a lead).
  • A coarse country (derived from your IP at the edge; the raw IP is not stored) and device type.
  • Your consent choices, so I can tell consented from non-consented traffic.

Legal basis: your consent (Art. 6(1)(a) GDPR) in the EU/EEA/UK; in Switzerland the overriding legitimate interest in basic, first-party reach measurement (revFADP). Stored with my hosting/database processors (Vercel, Supabase), not shared with advertising networks.

Marketing (Meta Pixel & Conversions API)

Only if you allow Marketing, this site loads the Meta (Facebook) Pixel and may also send the same events server-side through the Meta Conversions API, so I can measure how my Facebook/Instagram ads perform and reach relevant audiences. It processes:

  • Cookies _fbp and _fbc (a browser id and the ad-click id), each lasting up to about 90 days.
  • The fbclid click identifier added to the URL when you arrive from a Meta ad.
  • Your IP address and user agent, sent both by the browser pixel and server-side by the Conversions API when you submit a form.
  • Pages visited and actions taken (page view, content view, contact, lead / form submission).
  • A pseudonymous event id used to deduplicate the browser and server-side events.
  • For the Conversions API (server-side): your email, phone number, first and last name and a pseudonymous session identifier, each hashed with SHA-256 before sending (never in plain text), to improve the match quality of the measurement.
  • Advanced matching (only if it is enabled for the Pixel): the contact details you enter in the contact or callback form (email, phone, name) are read by the Pixel, hashed with SHA-256 in your browser and sent to Meta in hashed form only, again solely to improve match quality.

Recipients: Meta Platforms Ireland Ltd (Ireland) and Meta Platforms, Inc. (USA), acting as (joint) controllers for their own ad purposes. Transfers to the USA rely on the EU-US and Swiss-US Data Privacy Framework, with EU Standard Contractual Clauses as a fallback. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time via Cookie settings. Hashed data is still personal data, not anonymous.

Contact & lead data

When you reach out by email, phone, WhatsApp or the contact / callback form, your name, contact details and message are used to handle your request. Form submissions are stored and managed in my CRM, operated by an EU-based provider on my behalf. With Marketing consent, the fact that you submitted a form (with your email/phone hashed) is also reported to Meta to measure ad performance.

In the contact and callback forms the fields marked as required (your name and at least one contact channel, that is email or phone, and for a callback a phone number) are necessary so I can identify you and reply; without them I cannot process your request. Any further details you add are optional.

Email addresses and phone numbers submitted through the forms on this site are used solely to answer your enquiry. They are never given, sold, rented or otherwise transferred to any other party for the purpose of sending advertising, and they are never added to a marketing or lead-generation list.

Legal basis: steps taken at your request prior to a possible contract and my legitimate interest in responding to enquiries (Art. 6(1)(b) and (f) GDPR). Providing your data is voluntary, but without it I cannot reply.

Cookies & local storage in use

The following cookies and browser-storage items may be used. Necessary items are always active; Analytics and Marketing items are only set according to your choice.

  • foldvari:sid (first-party, this site): pseudonymous session id for first-party visit statistics. Category: Analytics. Duration: persistent until you clear it.
  • foldvari:attribution (first-party): which campaign / UTM (and, with Marketing consent, fbclid) brought you here. Category: Analytics / Marketing. Duration: persistent until you clear it.
  • cookie-consent-v2 (first-party): stores your cookie choices, the policy version and timestamp. Category: Necessary. Duration: persistent until you clear it.
  • _ga / _gid / _gat (Google Analytics): analytics and request throttling. Category: Analytics. Duration: up to 2 years (_ga), 24 hours (_gid), 1 minute (_gat).
  • _fbp / _fbc (Meta): browser id and ad-click id for advertising measurement. Category: Marketing. Duration: about 90 days.

A short-lived, strictly necessary token for security/anti-spam may also be used by the contact form. You can review or change your choice at any time via Cookie settings in the footer.

Recipients & processors

I do not sell your data. It is shared only with the service providers needed to run the site, each under a data-processing agreement (GDPR Art. 28) where applicable:

  • Vercel Inc. (USA): hosting and delivery of the website and its serverless functions; security logs may briefly contain your IP. Transfer safeguard: EU-US Data Privacy Framework / Standard Contractual Clauses.
  • Supabase, Inc. (USA; database hosted in the EU region, Zurich/Frankfurt): stores the first-party website-statistics events. Transfer safeguard: Standard Contractual Clauses.
  • My CRM provider (EU): stores and manages your contact / lead submissions on my behalf.
  • Google Ireland Ltd / Google LLC (USA): Google Analytics 4, only with Analytics consent. Transfer safeguard: EU-US / Swiss-US Data Privacy Framework + SCCs.
  • Meta Platforms Ireland Ltd / Meta Platforms, Inc. (USA): Meta Pixel & Conversions API, only with Marketing consent. Transfer safeguard: EU-US / Swiss-US Data Privacy Framework + SCCs.

Data security

I take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, disclosure or alteration, and I review them as the site evolves. These include encryption in transit (HTTPS/TLS), access controls and least-privilege access to the CRM and database, hosting with reputable providers (Vercel, Supabase) that maintain their own security measures under data-processing agreements, pseudonymisation of analytics identifiers, and short retention of security logs. No method of transmission or storage is completely secure, but I use measures appropriate to the risk.

Server log files

When you visit the site, my hosting provider (Vercel) automatically processes standard server log data, including your IP address, the date and time of the request, the page requested, the referrer and your browser / user agent, in order to deliver the site securely, keep it stable and detect or prevent abuse. The legal basis is my legitimate interest in the secure and reliable operation of the website (Art. 6(1)(f) GDPR; overriding legitimate interest under the revFADP). These logs are kept only for a few days and are not combined with the consent-based analytics described above.

Data retention

I keep personal data only as long as needed for the purpose it was collected for:

  • Contact / lead data (CRM): up to 24 months after our last contact, then deleted, unless a contract or legal obligation requires longer.
  • First-party website statistics: up to 14 months, then deleted or aggregated.
  • Google Analytics 4: per GA4 settings (currently 14 months for user-level data).
  • Meta Pixel / Conversions API data: per Meta’s retention policy; the _fbp/_fbc cookies expire after about 90 days.
  • Consent records: about 12 months together with the policy version, as proof of consent; hosting/security logs: a few days.

Your rights

Under the GDPR (EU/EEA), the UK GDPR and the Swiss revFADP you have the right to access your personal data, to have it corrected or deleted, to restrict or object to its processing, to data portability, and to withdraw any consent at any time without affecting prior processing. To exercise these rights, contact me at the email above; requests are handled free of charge and within the statutory deadline (one month under the GDPR; generally within 30 days for access under the revFADP).

You also have the right to lodge a complaint with a supervisory authority. Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, edoeb.admin.ch. Hungary: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11, naih.hu. EU/EEA visitors may also contact their local data protection authority.

Independently of any complaint to a supervisory authority, you also have the right to an effective judicial remedy and may bring proceedings directly against the controller (or a processor) before the competent court. In Hungary, under Section 23 of the Info Act (Act CXII of 2011) and Art. 79 GDPR, you may choose the court (törvényszék) of your place of residence or stay. In Switzerland the ordinary civil courts are competent for data-protection claims under the revFADP. Going to a supervisory authority does not remove your right to go to court.

Advertising profiling

With Marketing consent, data shared with Meta may be used by Meta to build audiences and personalise and optimise advertising (profiling). I do not take any decision producing legal or similarly significant effects about you by solely automated means. You can withdraw Marketing consent at any time and also manage personalised ads in your Meta account settings.

Children

This site and its services are intended for adults and are not directed at children. I do not knowingly collect personal data from children under the applicable digital-consent age (16 by default under the GDPR; 16 in Hungary). If you believe a child has provided data, contact me and I will delete it.

Changes to this policy

This policy may be updated from time to time. The date at the top of the page reflects the latest version; significant changes that require it will be re-notified via the cookie banner.