Legal

Privacy Policy

Effective: 20 July 2026 Version: 1.0

This policy explains what personal data is processed when you visit kristofkarner.com or contact me. The principle is simple: I process only what the work cannot be done without — and whatever can be left uncollected, I do not collect at all.

It is based on Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information (Infotv.).

1. The controller

Name
Kristóf Karner, sole trader (egyéni vállalkozó)
Registered seat
Alsó Völgy utca 14/A, 1021 Budapest, Hungary
Registration number
59509570
Tax number
90328037-1-41
Main activity
Custom software development (NACE 620101)
E-mail
kristof@kristofkarner.com
Website
kristofkarner.com

I am not required to appoint a data protection officer: I am not a public authority, my activity does not involve regular and systematic monitoring of data subjects on a large scale, and I do not process special categories of data on a large scale (Article 37 GDPR).

Further identifying details of the provider — including those of the hosting company — are in the imprint. This notice covers the processing of personal data; storage in your browser is covered separately in the cookie notice.

2. What I do not collect

This section comes first because most privacy risk disappears here. The website consists of static HTML pages with no database behind them and no tracking code. Specifically:

  • No cookies and no equivalent technology (local storage, session storage, fingerprinting). That is why there is no consent banner — there is nothing to consent to.
  • No analytics (Google Analytics or similar) and no advertising trackers (pixels, remarketing tags).
  • No embedded third-party content — no embedded maps, videos, social media widgets or external font services. Every asset loads from this site's own server, so your browser never contacts a third party.
  • No contact form, no registration and no user accounts.
  • No profiling and no automated decision-making (Article 22 GDPR).
  • I neither buy nor sell contact databases, and I do not send cold outreach.
Why this matters If a site collects nothing, there is nothing to leak, lose or misuse. This is a design decision, and the regulation has a name for it: data protection by design (Article 25 GDPR).

3. Data processed, purposes and legal bases

3.1 Visiting the website — server logs

Like every web server, the one serving this site keeps technical logs. I do not create these entries and do not combine them with other data; the hosting provider's system records them automatically.

DataPurposeLegal basisRetention
IP address, timestamp, requested path, HTTP status, user agent, referring page Operating the service, resolving faults, detecting attacks and abuse Legitimate interest — Article 6(1)(f): operating the site securely and keeping it available Per the hosting provider's log rotation, at most 30 days, then deleted automatically

Balancing test: without logging, operating and defending the site would not be feasible, while the impact on the data subject is minimal — the records are not combined with other data, are not used for monitoring or differentiation, and are deleted after a short period.

3.2 Contact by e-mail

DataPurposeLegal basisRetention
Name, e-mail address, the content of your message and any attachments, plus anything else you choose to include Answering your enquiry, preparing a quote, preparing possible cooperation Steps prior to entering into a contract, at your request — Article 6(1)(b) If no contract follows: 2 years from the end of the exchange. If one does: see 3.3

Please do not send data by e-mail that the matter does not require — in particular no passwords, banking details or health information. If access to a system is needed, we arrange that separately and securely.

3.3 Client relationship and performance of a contract

DataPurposeLegal basisRetention
Name, billing name and address, tax number, contact details, technical data covered by the engagement Delivering the service, staying in contact Performance of a contract — Article 6(1)(b) 5 years from termination of the contract (general limitation period under the Hungarian Civil Code)
Billing data on issued accounting documents Retention of accounting records Legal obligation — Article 6(1)(c), under Section 169 of Hungarian Act C of 2000 on Accounting 8 years. This period cannot be shortened and is not affected by an erasure request

3.4 Being featured as a reference

I may present completed work on this website as a reference. This normally concerns companies, so it is not personal data. Where a reference would contain a natural person's name, photograph or identifiable testimonial, I publish it only with prior consent (Article 6(1)(a)). Consent may be withdrawn at any time, without giving reasons, at kristof@kristofkarner.com; on withdrawal I remove the content without delay. Withdrawal does not affect the lawfulness of processing before it.

The Google reviews shown on the site are publicly available content published voluntarily by the reviewers, displayed here with abbreviated names.

4. Processors

A processor handles data on the controller's behalf, on their instructions. At present there is one:

Name
Tárhely.Eu Szolgáltató Kft.
Role
Hosting and e-mail services
Data involved
Server logs, content and headers of e-mail messages
Location of processing
Hungary (European Union)

Where accounting services are used, the accountant also processes the accounting records, in order to fulfil a legal obligation.

5. Access to clients' systems

This section concerns clients who engage me for work — not visitors to this website.

While building and maintaining websites and business systems, I may gain access to systems in which my client processes the personal data of third parties (for example, their customers). In those cases I act not as a controller but as a processor: I touch the data only on the client's documented instructions and only to the extent the engagement requires.

  • I keep no copies of my own, other than a temporary development copy where the work requires one, which I delete once the task is complete.
  • I never use such data for my own purposes and never pass it to third parties.
  • Access credentials are returned or revoked at the end of the engagement, or earlier on the client's request.
  • A data processing agreement under Article 28 GDPR can be concluded at any time at the client's request; for ongoing maintenance engagements I propose one myself.
  • If I detect a personal data breach in a client's system, I notify the client without delay, so that they can meet their 72-hour notification duty (Article 33 GDPR).

6. Transfers outside the EU

None take place. Serving the website and receiving and storing e-mail all happen within the European Union. The site loads no externally hosted asset — no font, script or image — so your browser initiates no connection to a provider outside the EU.

One caveat worth knowing: if you write to me from a mail provider operating outside the EU, the journey of that message begins at your own provider, which is outside my control.

7. Security measures

  • Encrypted connection: the site is served over HTTPS only, with a valid certificate.
  • Authenticated e-mail: the domain has SPF, DKIM and DMARC configured. This makes it considerably harder for anyone to send fraudulent messages in my name from my address — for instance a fake invoice with an altered bank account number.
  • Reduced attack surface: the site consists of static files. There is no database, content management system or login screen to attack.
  • Access control: provider accounts are protected by unique, strong passwords and, where available, two-factor authentication.
  • In the event of a personal data breach I notify the supervisory authority within 72 hours of becoming aware of it, and inform affected individuals where the breach is likely to result in a high risk (Articles 33–34 GDPR).

8. Your rights

You may exercise any of the following, free of charge:

  • Information and access — find out whether I process data about you and obtain a copy (Article 15).
  • Rectification — have inaccurate data corrected (Article 16).
  • Erasure — have your data deleted where the purpose has ceased (Article 17). This does not extend to accounting records, whose retention is required by law.
  • Restriction — ask that data be kept but not used while a dispute is resolved (Article 18).
  • Objection — object to processing based on legitimate interest (Article 21). This applies to the server logs.
  • Portability — receive data processed on the basis of consent or contract in a machine-readable format (Article 20).
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time. Withdrawal does not affect the lawfulness of processing before it.

Send your request to kristof@kristofkarner.com. I respond within 30 days at the latest. Where a request is complex this may be extended by two months — I will tell you within the first 30 days if that happens.

If I have reasonable doubts about your identity, I may ask for further information to verify it. The purpose is to stop anyone else from obtaining your data in your name.

9. Remedies

If you believe something has gone wrong with your data, please contact me first — most questions are settled in a single exchange. Regardless, the following remedies are always open to you:

Supervisory authority
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address
Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address
1363 Budapest, Pf. 9, Hungary
Phone
+36 1 391 1400
E-mail
ugyfelszolgalat@naih.hu
Website
naih.hu

You may also seek a judicial remedy. Proceedings may be brought before the court of your place of residence or stay, at your choice (Article 79 GDPR, Section 23 Infotv.).

10. Changes to this policy

I update this policy when the circumstances of processing change — for example if analytics were introduced in future, or if a new processor were engaged. Changes take effect on publication, and the effective date and version number always appear at the top of the document.

For material changes — such as a change in the legal basis or purpose of a processing activity — I keep earlier versions available, so it stays traceable what applied and when.

← Back to home