Cookie and tracking policy
Version: 1.0 · Effective: 14 July 2026 · Last reviewed: 14 July 2026
Please note: This is a courtesy English translation. In case of any discrepancy, the Hungarian-language version is authoritative — available at free-association.hu/suti-tajekoztato.
0. The essentials, in one minute
- This website may use technologies that store data on your device, or read data from it. The best known of these is the cookie, but it is not the only one.
- The technologies strictly necessary for the site to function we use without your consent — the site would not work without them.
- Everything else — measurement, statistics, marketing, personalisation — happens only with your prior, explicit consent. Until you decide, these do not run. (We do not, in fact, currently use any such technology — see point 5.)
- Declining is just as easy as accepting, and carries no disadvantage: the site's content remains fully available even if you decline.
- You can change or withdraw your decision at any time, without giving a reason: at the bottom of the page, via the footer “Cookie settings” button — at any time, with a single click.
The detailed policy below explains the same in more depth.
1. Who processes your data
| Data controller | FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft. |
| Legal form | private limited company (Kft.) |
| Registered seat | Corvin sétány 3, staircase B, 9th floor, door 2, 1082 Budapest, Hungary |
| Registration / company number | 01-09-719316 (company registration number) |
| Tax number | 13112675-2-42 |
| E-mail (cookie and data protection matters) | info@free-association.hu |
| Website | free-association.hu |
| Data protection officer | We are not required to appoint a data protection officer; for cookie and data protection matters you may contact us at the e-mail address above. |
The website is developed and maintained on the controller's behalf by Kristóf Karner, sole trader (hello@weberna.hu), acting as a data processor; technical enquiries are received by the operator. For cookie and data protection matters you may contact the controller directly at the address above; where a controller decision is required, the operator forwards it to the controller. The controller's general contact details (the team members' e-mail addresses and phone numbers) are set out in the general privacy policy.
Our general privacy policy — which also covers our data processing beyond this website — is available here: free-association.hu/en/privacy-policy.
2. What this policy covers
Everyday language speaks of "cookies", but the law is technology-neutral: what matters is not what a given solution is called, but whether it stores information on the user's terminal equipment (device), or accesses information already stored there.
This policy therefore applies to each of the following technologies, wherever we use them on our site:
| Technology | What it means |
|---|---|
| HTTP cookie | A small text file stored by the browser, returned to the server with every request. |
| localStorage / sessionStorage | Data stored in the browser, written and read by the website's JavaScript code. |
| Embedded scripts and SDKs | Third-party code running on the site (e.g. measurement, advertising, chat). |
| Tracking pixel, web beacon | An invisible image or request whose loading signals that you have opened a page or an e-mail. |
What this policy does NOT cover: processing that is not based on information stored on or read from your device (for example, when you send us an e-mail). Those are governed by our general privacy policy: free-association.hu/en/privacy-policy.
3. When we ask for consent, and when we do not
These are two separate questions, and it is important to keep them apart:
(a) Are we allowed to store data on your device, or read data from it? As a rule, only with your prior consent. Exception: where the operation is carried out solely to transmit a communication, or is strictly necessary for a service you have expressly requested. In that case we do not ask for consent — but we inform you of it, here, in this document.
(b) Are we allowed to process the data so obtained as personal data? This requires a separate legal basis, as follows:
| Category | Basis for storing on / reading from the device | Basis for processing personal data |
|---|---|---|
| Strictly necessary | Exemption (no consent needed) | Performance of a contract, legitimate interest or legal obligation |
| Functional | Consent | Consent |
| Statistics / measurement | Consent | Consent |
| Marketing / advertising | Consent | Consent |
Important: if you withdraw your consent, we do not later "switch over" to another legal basis (such as legitimate interest) to continue the same processing. Withdrawal means the technology in question stops.
4. How we ask for consent
When you first visit the site, a consent management interface appears. We make the following commitments about how it works:
- Consent is prior. None of the consent-based technologies run until you decide. No data is collected behind the interface that appears.
- Nothing is pre-ticked. Not a single non-essential category is switched on by default.
- Declining is one click. The "Decline" option appears at the same level, with the same prominence, as "Accept".
- Silence is not consent. Neither scrolling on, nor closing the interface, nor navigating the site counts as consent.
- Consent can be given per category. It does not work on an "all or nothing" basis.
- No locked gate. The site's content remains fully available even if you decline every non-essential technology.
- We record what you chose. We store the fact of your decision, the version of this policy and the categories you selected (in your browser) — this is our burden of proof, and your guarantee that we will not ask again needlessly.
5. Which technologies we use
5.1 Strictly necessary
Without these the site does not work: security, session handling, remembering your cookie decision. They cannot be switched off, and we do not ask for consent to them.
| Name / identifier | Type | Provider | Purpose | Lifetime | Outside the EEA |
|---|---|---|---|---|---|
cmplz_* (e.g. cmplz_consented_services, cmplz_policy_id) | HTTP cookie | Complianz consent manager (own solution) — first party, independent controller | Storing your cookie decision (accept / decline / category settings) and the accepted version of this policy, so that we do not have to ask again on every page load. | 365 days | no |
cmplz_banner-status, cmplz_saved_categories | HTTP cookie | Complianz consent manager (own solution) — first party, independent controller | Recording the display state of the consent interface and the saved categories (so that the dismissed banner does not reappear). | 365 days | no |
5.2 Functional
Convenience features: language selection, display settings, showing embedded content (video, map). They can be switched off — in which case the feature concerned will not be available, but the site still works.
For this category we use no cookies. The embedded map in the Contact section (OpenFreeMap) serves a convenience purpose, but places no cookie and stores nothing on your device; for information about it see point 6.
5.3 Statistics / measurement
These would measure how the site is used: which sub-pages are popular, where visitors get stuck. They can be switched off, and switching them off does not affect how the site works.
We currently use no statistics or web-analytics technology.
5.4 Marketing / advertising
These would serve to measure the effectiveness of our advertising and — with your consent — to display personalised ads, including on other websites. They can be switched off, and switching them off does not affect how the site works.
We currently use no marketing or advertising technology.
The table columns are: name/identifier · type · provider (first or third party; independent controller or processor) · purpose · lifetime · transfer outside the EEA.
6. Third parties
Some technologies are provided not by us but by a third party. An important distinction:
- Processor — processes the data on our instructions, for our purposes, and may not use it for its own.
- Independent controller — also processes the data for its own purposes, under its own rules. In that case it is responsible for its own processing, and it is worth reading its policy too.
The tables in point 5 indicate, for each provider, which case applies.
We currently use the technology of a single third party: the map in the Contact section loads the vector tiles of OpenFreeMap (operated by Hyperknot Software Kft., Hungary) — an open map service based on OpenStreetMap data. This service places no cookie and stores nothing on your device; when the map is displayed, however, your IP address — as with any image loaded over the internet — reaches the provider and the Cloudflare CDN delivering the tiles. According to the provider's own notice, IP addresses are not logged by default (in the event of a security incident, for at most 30 days). The provider is independently responsible for its own processing; its notice: https://openfreemap.org/privacy/. We currently engage no third party for measurement, statistics or advertising purposes.
7. Transfers outside the European Economic Area
We currently transfer no data outside the EEA by means of cookies or similar technology stored on your device. The operator of OpenFreeMap, which serves the map in the Contact section (Hyperknot Software Kft.), is a Hungarian — therefore EEA-based — company; the tiles are delivered via the Cloudflare CDN, with requests from the EU served from within the EEA. The map uses no cookies (see point 6).
Should we in future engage a provider that processes data outside the EEA (typically in the United States), we would do so only with appropriate safeguards. The safeguard actually applied would then be indicated per provider in the point 5 tables; it is typically one of the following:
- an adequacy decision of the European Commission for the country or framework concerned;
- standard contractual clauses (SCCs) adopted by the European Commission, with supplementary technical and organisational measures;
- the data subject's explicit consent, after being informed of the risks.
If a safeguard ceases or becomes invalid for a given provider, we suspend the technology concerned until the situation is resolved.
8. How long we store, and when we ask again
The lifetime of each technology varies; exact values are given per technology in the point 5 tables.
The validity of your decision: we retain your consent for 365 days, after which we ask again. If, in the meantime, there is a material change in which technologies we use, or for what purpose, we ask again before expiry.
We also respect a refusal. If you decline, we do not ask again on every single visit; at least 365 days passes before the next prompt.
Retention of the consent decision: we store your consent decision in your browser (in the strictly necessary cmplz_ cookie above) for 365 days; beyond this we keep no separate, server-side log linked to your person. We store this to enforce legal claims and to meet our burden of proof.
9. What happens if you decline
Most policies keep quiet about this, so we spell it out:
- The full content of the site remains available. We restrict nothing.
- Consent-based scripts are not loaded. They do not run in "silent mode" — they do not run at all.
- One thing we do store: the fact of the refusal itself, in a strictly necessary cookie. This is needed so that we do not ask again on every page load — in other words, this cookie protects precisely your decision.
10. How to change your decision
At any time, without giving a reason, just as easily as you gave it.
- On our site: at the bottom of the page, via the footer “Cookie settings” button — at any time, with a single click.
- In your browser: you can view, delete and block cookies at any time in your browser's settings (typically under "Privacy" or "Security"). Note: deleting in the browser also removes the strictly necessary cookies, so we will ask for your decision again afterwards.
Withdrawal takes effect for the future. It does not make processing carried out lawfully before withdrawal unlawful retroactively — but from the moment of withdrawal we stop the technology concerned.
11. Browser-level signals
If your browser sends a machine-readable privacy signal (such as Global Privacy Control), we do not currently take it into account automatically; please give your decision via the consent interface. As the site currently uses no consent-based technology whatsoever, this has no practical effect for now — as soon as we introduce any measurement or advertising technology, we will also enable automatic honouring of browser-level signals.
Should the law in future require browser- or system-level consent signals to be honoured, we will introduce this together with an update to this policy.
12. Your rights
In relation to data stored on or read from your device, you have the following rights:
| Right | What it means |
|---|---|
| Withdrawal of consent | At any time, without giving a reason, free of charge. See point 10. |
| Access | You may ask whether we process data about you and, if so, what. |
| Rectification | You may request the correction of inaccurate data. |
| Erasure | You may request the erasure of the data ("right to be forgotten"). |
| Restriction of processing | You may request that the data only be stored and not used. |
| Data portability | You may request the data processed on the basis of your consent in a machine-readable format. |
| Objection | You may object to processing based on legitimate interest. |
| Automated decision-making | You may request that a decision with legal effect on you not be based solely on automated processing. |
How to exercise these: write to info@free-association.hu. We reply within one month at the latest; in complex cases this may be extended by two months, of which we inform you before the deadline expires. The reply is free of charge.
13. Complaints and remedies
If you feel a breach has occurred, please contact us first — most matters are resolved with a single exchange of e-mails. Independently of this, and bypassing it, you may also:
Turn to the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: https://naih.hu
(The Authority accepts formal submissions primarily via electronic administration; the e-mail address is for general customer-service enquiries.)
Turn to the courts: you may also bring proceedings before the regional court with jurisdiction over your place of residence or stay, as you choose.
14. Minors
Our website is not intended for minors, and we do not knowingly collect data on persons under 16. If we become aware that we are processing such data, we erase it without delay. If, as a parent or guardian, you notice such a case, please let us know: info@free-association.hu.
15. Changes to this policy
We review this policy:
- regularly, at least every six months;
- on an ad hoc basis, if we introduce a new technology, change provider, or the legal environment changes materially.
If a change affects something you previously consented to — for example, we seek access for a new purpose or a new provider — we ask again. Previous consent does not automatically extend to the new processing.
This is the first, 1.0 version of this policy; there is no earlier version yet. We will inform you of future changes on this page, and make earlier versions available on request at the e-mail address above.
16. Contact
For cookie and data protection matters: info@free-association.hu.
Annex — Legal background
This policy has been prepared on the basis of the following:
- GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data
- ePrivacy Directive — Directive 2002/58/EC (as amended by Directive 2009/136/EC), in particular Article 5(3)
- Eht. — Act C of 2003 on electronic communications
- Infotv. — Act CXII of 2011 on informational self-determination and freedom of information
- Elkertv. — Act CVIII of 2001 on electronic commerce services
- the relevant guidelines of the European Data Protection Board (EDPB), including Guidelines 05/2020 on consent and Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive
- the relevant practice and guidance of the NAIH
Expected change: in November 2025 the European Commission tabled the Digital Omnibus legislative package, which would move the consent rules for cookies from the ePrivacy Directive into the GDPR and broaden the range of purposes usable without consent. The package remains under the legislative procedure through 2026; if adopted, its provisions will become applicable after a transition period following entry into force. Until that happens, the legislation listed above remains applicable unchanged. We will provide for any change by updating this policy.
Last legal review: 14 July 2026