Adatkezelési tájékoztató
In force from 09/09/2026. Version 2026-09-09.
Milyen személyes adatot kezelünk, milyen célból és meddig, kinek adjuk át, és milyen jogai vannak.
1. The controller and the data protection contact
Controller: AppForge Solution Korlátolt Felelősségű Társaság, represented by: Boncz Bálint, managing director, registered seat: 8992 Bagod, Vasút utca 7., customer service and postal address: 1054 Budapest, Szabadság tér 7. (Bank Center), company registration number: 20-09-079415, tax number: 32672886-2-20, email: [email protected], telephone: +36 30 583 1091. For data protection questions and to exercise your rights write to [email protected].
No data protection officer has been appointed: the controller is not a public body, does not process special categories of data at scale, and visitor tracking is consent based, neither regular nor large scale (GDPR Art. 37). The decision is recorded in the register of processing activities and is reviewed as the activity grows.
2. Terms in brief
Personal data is any information that identifies you or makes you identifiable. Processing is any operation on personal data (collecting, storing, transmitting, erasing). A processor handles data on our behalf and on our instructions. An independent controller processes data for its own purposes and on its own responsibility (for example the payment provider within its own financial obligations).
3. What we hold, why, on what basis and for how long
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Fulfilling the order and the contract | name, email, telephone, delivery and billing address, order details, the accepted version of the terms | performance of a contract, GDPR Art. 6(1)(b) | 5 years from performance (general limitation period) |
| Invoicing and accounting | billing name, address, tax number, line items, amount, payment method | legal obligation, GDPR Art. 6(1)(c), Hungarian accounting act | 8 years |
| Account and sign in | email, password hash or passkey public key, sign in link, Google, Facebook or Apple account identifier, saved addresses, order history | performance of a contract | until the account is deleted |
| Basket and checkout session | basket contents, details begun at the checkout, cookie identifier | steps prior to a contract, GDPR Art. 6(1)(b) | the basket cookie for 30 days; the checkout session is deleted after 48 hours of inactivity |
| Abandoned basket and checkout reminder emails | the email address given at the checkout, basket contents | legitimate interest, GDPR Art. 6(1)(f), with an unsubscribe link in every message | at most 7 days from abandonment |
| Withdrawal declarations | name, email, order reference, the text of the declaration, time of submission, the receipt | legal obligation, Directive 2011/83/EU as transposed | until the limitation period ends; on an erasure request the personal data is redacted and the fact of the declaration kept |
| Returns, conformity and guarantee claims | order details, description and photographs of the defect, serial number, the claim record, repair history, the guarantee certificate | legal obligation under Hungarian guarantee and claim handling rules | the claim record for 3 years; the certificate until the end of the guarantee period plus the limitation period |
| Complaint handling | the complaint, contact details, the record, the answer | legal obligation under Hungarian consumer protection law | 3 years |
| Newsletter | email, time of sign up and confirmation, IP address | consent, GDPR Art. 6(1)(a) | until you unsubscribe; afterwards a hash of the address is kept on a suppression list so we never write again |
| SMS and browser notifications about the order | telephone number, notification identifier | consent | until withdrawn |
| Reviews and questions | the name given (shown with the review), email, the review and photographs, whether the purchase is verified | contract (review invitation) and consent | while published; on request the author's name is removed |
| Review invitation email after delivery | email, the product bought | consent given at the checkout, GDPR Art. 6(1)(a) | until the invitation is sent, at most for the retention of the order |
| Loyalty programme | account identifier, points and transactions | performance of a contract | until the account is deleted |
| Gift cards | name of buyer and recipient, recipient's email, personal message, the code | performance of a contract | until redeemed, then until the limitation period ends |
| Stock and price alerts | email, the product watched | consent | until the alert is sent or withdrawn |
| Gift finder | the answers given (preferences, budget, occasion) | consent | until the end of the session; where the result is emailed, until it is sent |
| Analytics, marketing and personalisation | cookie identifiers, device data, products viewed, click identifiers (gclid, fbclid, ttclid), the fact of consent | consent, GDPR Art. 6(1)(a), ePrivacy rules | the lifetime stated in the cookie notice; measurement events for 180 days, the dispatch log for 400 days |
| Server side conversion measurement | order identifier, hashed email and telephone, click identifier | consent; nothing is sent without it | the dispatch log for 400 days |
| Affiliate programme | click identifier, order identifier, commission | legitimate interest, GDPR Art. 6(1)(f) | the click identifier for 180 days; the settlement record as an accounting record for 8 years |
| Fraud prevention and security logs | IP address, browser data, ordering pattern, failed sign ins | legitimate interest, GDPR Art. 6(1)(f) | 1 year |
| Proof of the cookie and consent decision | the decision, its time, the version of the notice, IP address, browser identifier | legal obligation, GDPR Art. 7(1) | the validity of the decision (365 days) plus 5 years |
| Log of data subject requests | the request, the answer, how identity was verified | legal obligation, GDPR Art. 12 | 5 years |
| Customer service correspondence | name, email, telephone, the matter | performance of a contract or legitimate interest | 5 years from closure |
Providing the data needed for an order is a condition of making the contract; the consent based purposes (newsletter, review invitation, cookies, gift finder) are not, and you can buy without them. Where an erasure request meets a retention duty (invoices for 8 years, claim and complaint records for 3 years, order data until the limitation period ends), the account is anonymised and the data is kept separately for that purpose only.
4. Recipients: processors and independent controllers
Our processors act only on our instructions, and we have a processing agreement with every one of them. The list is current on the effective date; a change is published as a new version of this notice.
- Payment: Stripe Payments Europe, Limited (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland) for card, Apple Pay, Google Pay and Link payments; card details go to Stripe only and the shop never sees or stores them.
- Delivery (name, address, telephone, email for the delivery): GLS General Logistics Systems Hungary Kft., Magyar Posta Zrt. (MPL), FoxPost Zrt.; the carriers are also independent controllers within the delivery itself.
- Invoicing: Billingo Technologies Zrt. (1133 Budapest, Árbóc utca 6. I. emelet, Hungary) to issue the invoice and report it to the Hungarian tax authority.
- Hosting and operations: RackForest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Zrt. (RackForest Zrt.), 1132 Budapest, Victor Hugo utca 11. 5. em. B05001., [email protected], https://rackforest.com. Content delivery and security filtering: Cloudflare, Inc. (San Francisco, USA), under the EU-US Data Privacy Framework and standard contractual clauses. The search engine (Typesense) and real time notifications run on our own servers.
- Email and SMS delivery: transactional and marketing emails are delivered by the email delivery provider in use at the time, SMS notifications by the SMS provider in use at the time; the current name and seat of each is available on request at [email protected].
- Analytics and advertising measurement, only with consent: Google Ireland Ltd. (Google Analytics 4, Google Ads, Consent Mode), Meta Platforms Ireland Ltd. (Meta Pixel and Conversions API), TikTok Technology Ltd. (TikTok Pixel and Events API), Microsoft Ireland Operations Ltd. (Microsoft Advertising UET), Pinterest Europe Ltd., each only where we have switched that platform on; the cookie notice always lists the providers actually active.
- Affiliate programme: the Dognet affiliate network, on the click identifier and the order amount only.
- Artificial intelligence: the answers given in the gift finder are sent to the configured language model provider (OpenAI, L.L.C., USA by default) to produce suggestions; no name, email or order data is attached, and please do not type personal data into the free text field. Product descriptions and content are produced without customer data.
- Authorities and courts where the law requires it; our accountant and legal counsel within their tasks.
5. Transfers outside the EEA
With Google, Meta, Microsoft, Cloudflare and OpenAI data may reach the United States; the basis is the European Commission's adequacy decision on the EU-US Data Privacy Framework and standard contractual clauses (SCC). With TikTok the basis is standard contractual clauses and the provider's supplementary safeguards. A copy of a provider's safeguards is available on request.
6. Automated decisions and profiling
We make no automated decision that has legal or similarly significant effects on you. Product recommendations, gift finder suggestions and coupon eligibility follow simple rules based on the data given and can always be ignored. When a payment is authorised the payment provider (Stripe) runs its own fraud screening, which may decline a transaction; this does not affect the conclusion of the contract, and the order can be completed with another payment method.
7. Your rights and how to exercise them
- Access: you can ask what data we hold about you and receive a copy. The data export can also be started from your account.
- Rectification: you can have inaccurate data corrected; account details can be edited directly.
- Erasure: you can ask for the account to be deleted from the account itself, with an email confirmation link. Invoicing data is kept for 8 years, complaint and claim records for 3 years and order data until the limitation period ends; those are separated and the account is anonymised.
- Restriction and objection: you can object at any time to processing based on legitimate interest (basket reminders, fraud prevention, the affiliate programme).
- Portability: you can export your data from your account in a machine readable format.
- Withdrawing consent: for the newsletter in the footer of every message, for cookies with the "Cookie settings" link at the foot of the page, for the other consents in the account or by email. Withdrawal does not affect the lawfulness of earlier processing.
We answer a request without undue delay and within 30 days at the latest; for complex or numerous requests this can be extended by two months, and we tell you within 30 days of receipt if so. Send the request to [email protected] or by post to the customer service address.
8. Security
Data travels over an encrypted connection (HTTPS), passwords are stored as one way hashes, and card details never touch our systems. Access is limited by role and staff access is logged. In the event of a personal data breach we notify the supervisory authority within 72 hours and, where the breach is likely to put you at high risk, you as well.
9. Complaints
If you believe we process your data unlawfully, please write to us first. You can complain to the Hungarian supervisory authority (Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), address: 1055 Budapest, Falk Miksa utca 9-11., postal address: 1363 Budapest, Pf.: 9., telephone: +36 1 391 1400, email: [email protected], website: https://naih.hu) or to the supervisory authority of the country you live in, and you can go to court.
10. Children
The shop is not directed at children under 16. Only a person aged 16 or over can sign up to the newsletter, which is confirmed by a separate statement at the checkout. If we learn that we hold data of a child under 16 without parental consent, we erase it.
11. Changes and versions
This notice applies from 2026-09-09, version 2026-09-09. A change is published as a new version; earlier versions stay available on this page, and the order keeps the identifier of the version in force when it was placed.