Privacy policy
Legal information
This notice describes what personal data we process, why, for how long, and what rights you have. In short: we ask only for what is needed to answer your enquiry, and we pass it on to no one.
The controller
- Szolgáltató neve
- Brilliance Hair Therapy Kft.
- Székhely
- Székhely: 6060 Tiszakécske, Liszt Ferenc u. 5. · Bemutatóterem: 1027 Budapest, Margit krt. 26.
- Adószám
- 32474808-2-03
- Telefon
- +36 20 285 2005
1. What we process and why
Contact form. Name, email address, phone number and town (if given), the subject of the enquiry, and the message itself. The purpose is to answer your enquiry and — where you ask for an appointment — to arrange it. The legal basis is your consent (GDPR Art. 6(1)(a)), given via the checkbox before the form is sent.
Health-related information. The form does not ask about the cause of your hair loss or your state of health. If you volunteer such information in the message field, we process it on the basis of your explicit consent under GDPR Art. 9(2)(a), solely to answer your enquiry, and with narrower access: only the practitioner carrying out the treatment can see it. If you would rather not, please write only that you would like an appointment — we can discuss the details at the consultation.
Trichoscopic examination and treatment records. These do not arise on the website but at the treatment location. We provide separate information, and ask for separate consent, about the handling of examination images and treatment history on site.
Logging and security. The server keeps a technical log (IP address, timestamp, page requested). Its purpose is operation and the prevention of abuse; the legal basis is legitimate interest (GDPR Art. 6(1)(f)).
Traffic measurement. The website uses its own cookie-free counter, which stores no IP address: it derives a daily-rotating, non-reversible identifier that identifies no one. Under the law this requires no consent. Google Analytics measures in addition only if you have expressly consented on the cookie bar.
2. How long we keep it
- Enquiries: for 1 year after the matter is closed, so that a returning question has context.
- Health information volunteered in a message: until the matter is closed, and at most 6 months — after which it is deleted from the enquiry even if the remaining data is kept.
- Technical log: at most 30 days.
- Visit counter: at most 6 months, then deleted automatically.
- Invoicing data: 8 years under Hungarian Act C of 2000 on accounting — this is required by law and cannot be deleted on request.
3. Who we share it with
We do not sell your data and do not pass it on for marketing. Only those providers have access without whom the website would not run:
- Hosting provider — serving the website and the database (details in the legal notice).
- Email provider — delivering confirmation and notification emails.
- Google Ireland Ltd. — only if you have consented to traffic measurement.
These providers act as processors: they may handle the data only on our instructions and only for the purposes above.
4. Your rights
You may ask us at any time to
- tell you what data of yours we process (access),
- correct inaccurate data (rectification),
- delete your data (erasure) — except what we must keep by law,
- restrict processing while a disputed point is clarified,
- release your data in machine-readable form (portability),
- object to processing based on legitimate interest.
You may withdraw your consent at any time — this does not affect the lawfulness of processing before the withdrawal. Please send your request to the email address in the legal notice; we reply within 30 days at the latest.
5. Remedies
If you feel the processing infringes your rights, please contact us first — most questions are settled with a single exchange of emails. Independently of that, you may lodge a complaint with the supervisory authority or go to court.
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11., Hungary
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
Web: naih.hu
If you are resident in another EU member state, you may also lodge a complaint with your own national supervisory authority.
6. Data security
The website runs over an encrypted connection (HTTPS). The admin interface is protected by a password and — under the recommended setting — two-factor authentication. Data is backed up daily.
7. Changes to this notice
If the way we process data changes, we update this notice and show the date of the change at the bottom of the page.