Privacy policy
free-association.hu
Please note: This is a courtesy English translation. In case of any discrepancy, the Hungarian-language version is authoritative — available at free-association.hu/adatkezelesi-tajekoztato.
| Data controller | FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft. |
| Version | 1.0 |
| Effective | 14 July 2026 |
| Earlier versions | Annex 3 (version log) |
0. One-minute summary
This section does not replace the detailed policy; it only offers quick orientation.
| Question | Short answer |
|---|---|
| Who processes my data? | FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft. (Corvin sétány 3, staircase B, 9th floor, door 2, 1082 Budapest, Hungary) |
| Why? | So that we can reply to your enquiry, perform the contract, issue the invoice, and operate this website. |
| Do you sell my data? | No. We do not sell, rent out or trade personal data. |
| Do you use tracking cookies? | No. We only use cookies that are strictly necessary for the website to work. |
| How long do you keep it? | It varies by purpose — see point 4. Invoicing data: 8 years (statutory obligation). |
| How do I exercise my rights? | Write to: info@free-association.hu |
| Where can I complain? | The NAIH (naih.hu) or the courts — details in point 13. |
1. Purpose and scope of this policy
This policy describes how we process your personal data in connection with the use of the free-association.hu website (the Website), and with contacting and doing business with the controller.
Processing is carried out in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR, the General Data Protection Regulation) and applicable Hungarian law. This policy is provided under Articles 13–14 GDPR.
This policy applies to visitors to the Website, clients and prospective clients, and persons using our contact channels.
What it does not cover
- The controller's market-research (survey, fieldwork) activity. The Website is a brochure site; we do not collect survey data through it. When we survey respondents as part of research, that is governed by its own separate privacy policy, provided to the data subjects during the survey. This document does not cover that processing.
- External sites linked from the Website. These have their own data processing practices, for which we are not responsible.
2. The controller and its contact details
| Name | FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft. |
| Registered seat / postal address | Corvin sétány 3, staircase B, 9th floor, door 2, 1082 Budapest, Hungary |
| Company registration number | 01-09-719316 |
| Tax number | 13112675-2-42 |
| E-mail (data protection and general matters) | info@free-association.hu |
| E-mail (team members) | Katalin Windisch – kati@free-association.hu, Móni Lelovics – moni@free-association.hu, Gábor Kovács – gabor@free-association.hu, János Balikó – janos@free-association.hu |
| Phone | Katalin Windisch – +36 70 380 5274, Móni Lelovics – +36 70 380 5273, Gábor Kovács – +36 70 380 4333, János Balikó – +36 70 330 5999 |
| Website | https://free-association.hu |
Hosting provider: Tárhely.Eu Kft. (Ormánság utca 4, 10th floor, door 241, 1144 Budapest, Hungary), contact: support@tarhely.eu, +36 1 789 2789. The Website's data is stored in a data centre located within the European Union.
Operation of the Website: the Website is operated and maintained on the controller's behalf by Kristóf Karner, sole trader (hello@weberna.hu), acting as a data processor (see point 8 and Annex 1). Technical and operational enquiries are received by the operator at the address above; for data protection matters and to exercise your data subject rights, you may contact the controller directly at info@free-association.hu.
Data protection officer: given the nature and scale of the processing carried out on this Website (a brochure site, contact enquiries), designating a data protection officer is not mandatory in this respect and has not taken place (Article 37 GDPR). In data protection matters the controller acts directly, at the e-mail address above.
3. Principles and a few definitions
In our processing we apply the principles set out in Article 5 GDPR: lawfulness and fairness, transparency, purpose limitation, data minimisation (we process only as much data as is strictly necessary for the purpose), accuracy, storage limitation, integrity and confidentiality, and accountability.
- Personal data: any information relating to an identified or identifiable living natural person (e.g. name, e-mail address, IP address).
- Processing: any operation performed on personal data (collection, storage, use, transfer, erasure, etc.).
- Controller: the party that decides why and how data is processed. On this Website that is the controller (FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft.).
- Processor: a party that processes data on the controller's behalf, on its instructions (e.g. the hosting provider). It does not decide on the purposes independently.
- Data subject: the natural person to whom the personal data relates. That is: you.
4. Data processing activities
The tables below set out, activity by activity, what data we process, why, on what legal basis, and for how long. The legal bases refer to Article 6(1) GDPR.
4.1 Website visits, server and security logs
| Data processed | IP address, time of the request, the URL visited, HTTP status code, referring page (referer), browser and device identifier string (user agent) |
| Purpose | Secure and stable operation of the Website, troubleshooting, detecting and preventing abuse (e.g. denial-of-service or intrusion attempts) |
| Legal basis | Article 6(1)(f) GDPR — legitimate interest. Legitimate interest: the security and availability of the IT system. This processing is an indispensable technical corollary of providing the service. |
| Retention | 30 days from logging; in the event of a security incident, until the incident is closed |
| Is it mandatory? | The data is generated automatically when the technical connection is established; without it the Website cannot be served. |
4.2 Contacting us (e-mail, phone)
| Data processed | Name, e-mail address, phone number, company name and job title (if provided), the content of the message and the full thread of correspondence |
| Purpose | Answering the enquiry, providing a quotation, preparing to conclude a contract |
| Legal basis | Where the enquiry seeks a quotation or the conclusion of a contract: Article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract. For other enquiries: Article 6(1)(f) GDPR — legitimate interest in answering questions addressed to us and in maintaining business contact. |
| Retention | If a contract is concluded: see point 4.3. If not: 1 year from the closure of the enquiry, after which it is erased |
| Is it mandatory? | Providing data is voluntary, but without a name and an e-mail address we cannot reply. |
4.3 Contracting, provision of services, client relationship
| Data processed | Name, billing name and address, tax number, e-mail address, phone number, the contract and performance data, correspondence arising during the relationship, access and technical data needed to run the project |
| Purpose | Concluding and performing the contract, documenting performance, client relationship management, support |
| Legal basis | Article 6(1)(b) GDPR — performance of the contract. Where the client is a business entity, in respect of the data of its contact person: Article 6(1)(f) GDPR — legitimate interest in the contact necessary to perform the contract. |
| Source of the data | From you, or — in the case of a contact person — from the client employing you (Article 14 GDPR). |
| Retention | 5 years from termination of the contract (aligned with the limitation period for civil law claims); for accounting documents, 8 years (see point 4.4). |
| Is it mandatory? | Providing the data is a precondition of concluding the contract; without it the contract cannot be performed. |
4.4 Invoicing and accounting retention
| Data processed | Billing name, address, tax number, invoice data, performance and payment data |
| Purpose | Compliance with a statutory obligation: issuing invoices, accounting, data reporting to the tax authority |
| Legal basis | Article 6(1)(c) GDPR — compliance with a legal obligation [under Act CXXVII of 2007 on value added tax, Act C of 2000 on accounting, and Act CL of 2017 on the rules of taxation] |
| Retention | 8 years [Section 169(2) of Act C of 2000 on accounting]. This processing persists irrespective of any erasure request. |
| Is it mandatory? | Yes, it is required by law. Without it the service cannot be invoiced, and therefore cannot be provided. |
4.7 Cookies and similar technologies
Detailed cookie list: Annex 2.
| Data processed | Cookie identifiers, device and browser data, data on activity carried out on the Website |
| Purpose | Operating the Website; (no advertising tracking takes place) |
| Legal basis | Cookies strictly necessary for operation: Article 6(1)(f) GDPR — legitimate interest in the proper operation of the Website; these require no consent. All other cookies: Article 6(1)(a) GDPR — your prior consent [having regard to Section 155(4) of Act C of 2003 on electronic communications and Section 13/A of Act CVIII of 2001 on electronic commerce services]. |
| Retention | Varies by cookie, see Annex 2. Lifetime of the cookie recording consent: 365 days (after which we ask again) |
| Managing consent | Declining is just as easy as giving consent, and it can be changed at any time: via the footer “Cookie settings” button (consent can be modified or withdrawn at any time) |
Without consent, cookies that are not strictly necessary are not placed on your device. The Website's core functions work regardless.
4.12 References and case studies
We may present our completed work and our clients as references on the Website. Where this involves naming an identifiable person or business, we do so only with the prior consent of the party concerned or on the basis of a corresponding contractual stipulation (Article 6(1)(a) and (b) GDPR). Consent may be withdrawn at any time, in which case we remove or anonymise the reference.
4.14 Establishment and defence of legal claims
In the event of a legal dispute, official proceedings or debt management, we may use the above data to establish, exercise or defend a claim. Legal basis: Article 6(1)(f) GDPR — legitimate interest in enforcing legal claims. Retention: until the claim becomes time-barred, or until the proceedings are closed by a final decision.
5. Processing based on legitimate interest
Wherever we rely on legitimate interest (Article 6(1)(f) GDPR), we have carried out a balancing test in advance: we examined whether our purpose could be achieved by less intrusive means, and whether our interest is proportionate to your rights and freedoms. In every case the outcome was that the processing is proportionate, that data subjects can reasonably expect it, and that its impact on them is minimal.
We will send you a summary of the balancing test free of charge on request — write to: info@free-association.hu. You may object at any time to processing based on legitimate interest (see point 12).
6. Recipients, processors
We do not sell, rent out or trade personal data.
We transfer data only within the following circle:
- Processors — who process data on our instructions, under a written processor agreement (Article 28 GDPR), solely for the purpose specified in that agreement (hosting, e-mail, operation, invoicing, etc.). Their current list: Annex 1.
- Independent controllers — who also process the data for their own purposes and on their own legal basis (e.g. an accountant within the scope of their statutory obligations).
- Authorities and courts — solely on the basis of a statutory obligation, to the extent of their request.
We keep the list of processors continuously up to date. Before engaging a new processor, we examine whether it provides appropriate guarantees for meeting the requirements of the GDPR.
7. Transfers outside the European Economic Area
We strive to keep data within the EEA, and wherever there is a realistic alternative we choose a provider operating in the EEA.
Where this is not possible (typically in the case of certain United States providers), the transfer takes place only with one of the valid safeguards under Chapter V of the GDPR. The safeguard actually applied may differ by provider, which is why we indicate it per provider in Annex 1. The possible safeguards are:
- an adequacy decision of the Commission (Article 45 GDPR) — e.g. the provider's certified participation in an applicable adequacy framework;
- standard contractual clauses adopted by the Commission (SCCs — Article 46(2)(c) GDPR), where necessary with supplementary technical and organisational measures (e.g. encryption, pseudonymisation) and a prior transfer impact assessment.
Our commitment: if an adequacy decision ceases to apply or becomes invalid, we will switch the transfer concerned to another valid safeguard without delay, or suspend it in the absence of one.
We provide information about the safeguards applied, and a copy of them, on request: info@free-association.hu.
8. Separating the operation of the site from research activity
- Operation of the Website. The Website is operated and maintained on the controller's behalf by an external developer. In respect of the personal data processed on the Website, the developer is a processor: it accesses the data solely on the controller's written instructions, under a processor agreement (Article 28 GDPR), to the extent necessary to run the system, and does not decide independently on the purposes of processing. The controller remains the controller (FREE ASSOCIATION RESEARCH Piackutató és Tanácsadó Kft.).
- Separation of market-research activity. The controller's main activity is market and public opinion research. The processing carried out in that context — during questionnaires, interviews and fieldwork — does not take place on this Website and is not covered by this policy; it has its own legal basis and its own separate privacy policy, which data subjects (respondents) receive during the survey. This policy covers only the processing connected to the Website, to contact made through it, and to the related business relationship.
9. Data security
We apply technical and organisational measures proportionate to the risk, in accordance with Article 32 GDPR. These include, among others:
- Encryption: the Website is available exclusively over TLS (HTTPS); data is also stored encrypted at rest wherever the provider supports this.
- Access management: the principle of least privilege; individual accounts, strong passwords, use of a password manager, two-factor authentication in every system where it is available.
- Logging and monitoring: security logs, regular updates, timely patching of vulnerabilities.
- Backups: regular, tested backups; verification that backups can be restored.
- Data minimisation as a security measure: what is not stored cannot be stolen — so we do not collect more data than necessary, and we erase it when the retention period expires.
- Organisational measures: confidentiality obligations, processor agreements, keeping a record of processing activities (Article 30 GDPR), an incident-handling procedure.
No internet service, however, can guarantee complete security. If you notice a data protection flaw or vulnerability, please report it responsibly to: info@free-association.hu — we take such reports seriously and are grateful for them.
10. Personal data breach
In the event of a personal data breach we investigate the matter without delay and — where it is likely to result in a risk to the rights of data subjects — notify the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware of it (Article 33 GDPR).
Where the breach is likely to result in a high risk, we also inform the data subjects without undue delay, in plain language (Article 34 GDPR). We keep an internal record of breaches.
11. Automated decision-making, profiling and artificial intelligence
Automated decision-making: We make no decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).
Profiling: We neither carry out nor permit profiling for advertising purposes on the Website.
Artificial intelligence: In operating the website and processing visitors' data we use no automated system based on artificial intelligence, and we neither use nor permit the use of visitors' personal data for training any AI model.
Wherever an AI system interacts with you directly or produces content intended for you, we state this clearly and visibly, in line with Article 50 of Regulation (EU) 2024/1689 (the AI Act). We do not use data originating from you to train AI models, and we require the same of the providers we engage.
12. Your rights
Under the GDPR you have the following rights. Exercising these rights is free of charge.
| Right | What does it mean? |
|---|---|
| Access (Article 15) | You may ask whether we process your data and, if so, request a copy of it. |
| Rectification (Article 16) | You may request the correction of inaccurate data and the completion of incomplete data. |
| Erasure (Article 17) | You may request the erasure of your data (e.g. if it is no longer needed, or you have withdrawn your consent). Erasure is not possible where retention is required by law (e.g. the 8-year accounting retention) or is necessary to enforce a legal claim. |
| Restriction of processing (Article 18) | You may request that your data be kept "locked", stored only — e.g. while you contest its accuracy. |
| Data portability (Article 20) | You may request data processed by automated means on the basis of consent or a contract in a structured, commonly used, machine-readable format (e.g. JSON, CSV), and have it transmitted to another controller. |
| Objection (Article 21) | You may object at any time to processing based on legitimate interest. We will then cease the processing unless we can demonstrate compelling legitimate grounds. Where you object to direct marketing, we cease processing immediately and unconditionally. |
| Withdrawal of consent (Article 7(3)) | For processing based on consent (e.g. newsletter, non-essential cookies) you may withdraw your consent at any time, as easily as you gave it. This does not affect the lawfulness of processing before withdrawal. |
| Complaint and judicial remedy (Articles 77, 79) | See point 13. |
How can you exercise your rights?
Write to: info@free-association.hu — there is no set form; an everyday e-mail is enough.
- Response time: without undue delay, within the deadline prescribed by law. If the request is complex or if there are many requests, that deadline may be extended as provided by law; we will inform you of any extension and its reason.
- Identification: if we have reasonable doubts about your identity, we may request additional information. We do this solely to protect your data — we do not ask for more data than is strictly necessary for identification.
- Cost: exercising your rights is free of charge. Where a request is manifestly unfounded or excessive — in particular because of its repetitive character — we may charge a reasonable fee or refuse to act on it (Article 12(5) GDPR).
13. Remedies
1. It is worth contacting us first. Most questions or complaints are resolved fastest this way: info@free-association.hu
2. You may turn to the supervisory authority. You have this right even if you have not contacted us first.
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf.: 9., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: naih.hu
If your habitual residence or place of work is in another EU Member State, you may also turn to the supervisory authority there.
3. You may turn to the courts. In the event of an infringement relating to the processing of your data, you may bring court proceedings. Adjudication falls within the competence of the regional court (törvényszék) and — at your choice — proceedings may also be brought before the regional court of your place of residence or stay. The list and contact details of the regional courts: birosag.hu
14. Children's data
The Website is not intended for persons under 18, and we do not knowingly collect data from persons under 16. In Hungary, in the case of information society services, the consent of a child under the age of 16 to processing is valid only with the authorisation or approval of the holder of parental responsibility (Article 8 GDPR).
If we become aware that we are processing the data of a child under 16 without appropriate authorisation, we erase the data without delay. If, as a parent, you notice such a case, please let us know: info@free-association.hu
15. Amendments to this policy
We review this policy at least once a year, and additionally whenever we start a new processing activity, engage a new processor, or the legal environment changes.
European data protection regulation is currently in transition (including the rules on cookies, AI systems and breach notification). We follow the changes and update this policy accordingly.
- Amendments are recorded in Annex 3 (version log).
- In the event of a material change (e.g. a new processing purpose, a new legal basis, a new recipient in a third country) we inform you in advance, visibly on the Website or — for newsletter subscribers — by e-mail.
- If the amendment concerns processing based on consent, we ask for new consent; earlier consent does not automatically extend to the new purpose.
Annex 1 — Data processors and recipients
The list below reflects the position as at 14 July 2026.
| Provider | Activity | Registered seat / place of processing | Transfer safeguard (outside the EEA) | Privacy policy |
|---|---|---|---|---|
| Tárhely.Eu Kft. | Web hosting — serving and storing the website | Ormánság utca 4, 10th floor, door 241, 1144 Budapest, Hungary | Within the EEA (Hungary) | https://tarhely.eu |
| Next-IT Consulting Kft. | Domain and DNS services, and hosting of the @free-association.hu mailboxes (receiving enquiries) | Rózsa utca 34/1, 1161 Budapest, Hungary | Within the EEA (Hungary) | https://next-it.eu |
| Kristóf Karner, sole trader | Development and maintenance of the website on the controller's behalf (technical access to the system) | Hungary (within the EEA) | Within the EEA (Hungary) | hello@weberna.hu |
| OpenFreeMap (operated by Hyperknot Software Kft.) | Serves the vector tiles of the map in the Contact section (an open map service based on OpenStreetMap data). It places NO COOKIE and stores nothing on your device; when the map loads, however, the provider — and the Cloudflare CDN delivering the tiles — receives your IP address. According to the provider's own notice, IP addresses are not logged by default (in the event of a security incident, for at most 30 days). It acts as an independent controller, under its own notice | Hungary | Within the EEA (Hungary). The tiles are delivered via the Cloudflare CDN; requests from the EU are served by a server within the EEA (verified: Paris) | https://openfreemap.org/privacy/ |
Where "Within the EEA" is indicated, no transfer to a third country takes place, so no separate safeguard is required.
Annex 2 — Cookie list
| Cookie / stored key | Provider | Category | Purpose | Lifetime | Consent required? |
|---|---|---|---|---|---|
cmplz_* (e.g. cmplz_consent_status) | Own (first party) — Complianz consent manager | Strictly necessary | Recording and remembering your cookie consent decision (accept / decline / settings) | 365 days | No |
cmplz_saved_categories / cmplz_banner-status | Own (first party) — Complianz consent manager | Strictly necessary | Recording the banner's display state and the saved categories | 365 days | No |
Categories:
- Strictly necessary — indispensable for the Website to work (e.g. remembering the cookie setting). May be used without consent.
- Statistical — serves to measure traffic. Only with consent.
- Marketing — serves to target and measure advertisements. Only with consent.
- Embedded content (third party) — arises when an embedded element of an external provider (e.g. a map) is loaded. Only with your consent, after the content is loaded.
You can also delete or block cookies in your browser at any time. This may limit certain functions of the Website.
Annex 3 — Version log
| Version | Date | Change |
|---|---|---|
| 1.0 | 14 July 2026 | First publication. |
This policy is effective from 14 July 2026. If you have any questions, write to: info@free-association.hu