Privacy Policy
This notice explains what personal data the Képesbolt platform processes, for what purposes and on what legal bases, who receives the data, how long it is retained and what rights data subjects have — under Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011.
Effective from 1 August 2026
This is an informational translation provided for convenience. In case of any discrepancy, the Hungarian version prevails.
1. Controller
- Controller: Imre Dobó, sole proprietor (operator of the Képesbolt platform)
- Seat: Hajnal utca 14. 2/13., 4029 Debrecen, Hungary
- Tax number: 53669401-1-29
- Email: doboimre86@gmail.com
- Phone: +36 30 609 5404
- No data protection officer has been appointed (not required under Article 37 GDPR).
2. Dual role: controller and processor
If you bought photos in a gallery and wish to exercise your data subject rights, please contact the Photographer operating that gallery as controller first. The platform assists in fulfilling every such request according to the Photographer's instructions.
3. Data, purposes, legal bases, retention
| Data / subjects | Purpose | Legal basis | Retention |
|---|---|---|---|
| Photographer account data — name, email, password (hashed), studio name, plan and billing data | creating and performing the service contract, invoicing | Art. 6(1)(b) GDPR; accounting documents: Art. 6(1)(c) | 30-day grace period after account deletion; accounting documents: 8 years (Act C of 2000, Section 169) |
| Photographer API keys — invoicing, payment and Google Drive credentials | operating the integrations connected by the photographer | Art. 6(1)(b) | encrypted (AES-256-GCM) for the life of the account |
| Customer / parent data — name, email, phone, billing and delivery data, order contents | fulfilling photo orders in the Photographer's galleries | the platform is a processor — the Photographer is the controller and defines the legal basis | per the Photographer's instructions; deletion per the DPA on termination |
| Children's images — photos in kindergarten, school and family galleries | displaying galleries and fulfilling orders | the platform is a processor — obtaining parental consent (Hungarian Civil Code 2:48) is the Photographer's responsibility | until the gallery or account is deleted |
| Gallery visit log — IP address, user agent, email for email-gated galleries | visit statistics for the Photographer, abuse prevention | processing on the Photographer's behalf; Art. 6(1)(f) for security | [TO BE VERIFIED — recommended max. 12 months] |
| Download tokens — unique download links for purchased photos | secure delivery of digital photos | Art. 6(1)(b) | 30 days, then automatically invalidated and deleted |
| Newsletter subscribers — email, optional name | launch and product news | Art. 6(1)(a) — consent with double opt-in | until consent is withdrawn (unsubscribe) |
| Marketing leads — data submitted on contact and signup forms | responding to enquiries | Art. 6(1)(a) — consent | until withdrawal, max. 2 years after last activity [TO BE VERIFIED] |
4. Children's data — special care
Galleries largely contain photos of minors. A child's likeness is personal data requiring special care. Obtaining and keeping records of parental consent for taking and publishing the photos is the Photographer's responsibility. The platform provides built-in safeguards: password protection, email gate, scheduled access and expiry, watermarking, right-click protection and search engine exclusion (noindex).
5. Recipients
| Recipient | Role | Location / safeguard |
|---|---|---|
| Google Ireland Ltd. (Google Drive) | photo storage in the Photographer's own Drive account | Ireland (EU); US transfers: EU-US Data Privacy Framework + SCC |
| SMTP2GO Ltd. | transactional emails | New Zealand — EU adequacy decision |
| Barion Payment Zrt. / OTP Mobil Kft. (SimplePay) | card payments via the Photographer's own account | Hungary (EU) |
| Stripe Payments Europe Ltd. | card payments via the Photographer's own account | Ireland (EU); US transfers: EU-US DPF + SCC |
| KBOSS.hu Kft. (Számlázz.hu) / Billingo Technologies Zrt. | invoicing in the Photographer's name via their own account | Hungary (EU) |
| Newsletter delivery | currently the platform's own system via SMTP2GO | [TO BE VERIFIED if an external provider is added] |
| Cloudflare, Inc. | CDN, DDoS protection, DNS | USA — certified under the EU-US Data Privacy Framework |
| Hostinger International Ltd. | server infrastructure (VPS) | Cyprus (EU); EU data centre [TO BE VERIFIED] |
6. Third-country transfers
Data is primarily stored and processed within the EU. Where providers transfer data to third countries (notably the USA), transfers rely on Chapter V GDPR safeguards: adequacy decisions (EU-US Data Privacy Framework; New Zealand adequacy) or the Commission's Standard Contractual Clauses (SCC).
7. Security measures
- TLS/HTTPS everywhere;
- API keys and access tokens stored encrypted (AES-256-GCM);
- passwords hashed with bcrypt;
- tenant-level access separation — every photographer sees only their own data;
- time-limited, unique download tokens (30 days);
- httpOnly, secure session cookies; gallery access cookies contain no passwords;
- regular backups [TO BE VERIFIED — backup schedule].
8. Data subject rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). Requests are received at doboimre86@gmail.com and answered within 1 month (Art. 12). Requests concerning customer or child data controlled by a Photographer are forwarded to the Photographer, and we assist in fulfilling them.
9. Remedies
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH) — Falk Miksa utca 9-11., 1055 Budapest, Hungary; postal address: 1363 Budapest, Pf. 9.; email: ugyfelszolgalat@naih.hu; web: www.naih.hu
- You may also bring the case before a court — at your choice, the regional court of your place of residence (Act CXII of 2011, Section 23; Art. 79 GDPR).
10. Final provisions
This notice is effective from 1 August 2026 (v1.0). Updates are published on this page; registered photographers are notified of material changes by email. Cookie use is described in the separate Cookie notice.
This document is an informational template — legal review is in progress.