Privacy Policy
This notice explains what personal data the Képesbolt platform processes, for what purposes and on what legal bases, who receives the data, how long it is retained and what rights data subjects have — under Regulation (EU) 2016/679 (GDPR) and Hungarian Act CXII of 2011.
Effective and last updated: 26 August 2026
This is an informational translation provided for convenience. In case of any discrepancy, the Hungarian version prevails.
1. Controller
- Controller: Imre Dobó, sole proprietor (operator of the Képesbolt platform)
- Seat: Hajnal utca 14. 2/13., 4029 Debrecen, Hungary
- Tax number: 53669401-1-29
- Email: doboimre86@gmail.com
- Phone: +36 30 609 5404
- No data protection officer has been appointed (not required under Article 37 GDPR).
2. Dual role: controller and processor
If you bought photos in a gallery and wish to exercise your data subject rights, please contact the Photographer operating that gallery as controller first. The platform assists in fulfilling every such request according to the Photographer's instructions.
3. Data, purposes, legal bases, retention
| Data / subjects | Purpose | Legal basis | Retention |
|---|---|---|---|
| Photographer account data — name, email, password (hashed), studio name, plan and billing data | creating and performing the service contract, invoicing | Art. 6(1)(b) GDPR; accounting documents: Art. 6(1)(c) | 30-day grace period after account deletion; accounting documents: 8 years (Act C of 2000, Section 169) |
| Photographer API keys — invoicing, payment and Google Drive credentials | operating the integrations connected by the photographer | Art. 6(1)(b) | encrypted (AES-256-GCM) for the life of the account |
| Customer / parent data — name, email, phone, billing and delivery data, order contents | fulfilling photo orders in the Photographer's galleries | the platform is a processor — the Photographer is the controller and defines the legal basis | per the Photographer's instructions; deletion per the DPA on termination |
| Children's images — photos in kindergarten, school and family galleries | displaying galleries and fulfilling orders | the platform is a processor — obtaining parental consent (Hungarian Civil Code 2:48) is the Photographer's responsibility | until the gallery or account is deleted |
| Gallery visit log — IP address, user agent, email for email-gated galleries | visit statistics for the Photographer, abuse prevention | processing on the Photographer's behalf; Art. 6(1)(f) for security | up to 12 months; the Photographer may request earlier deletion |
| Download tokens — unique download links for purchased photos | secure delivery of digital photos | Art. 6(1)(b) | 30 days, then automatically invalidated and deleted |
| Browser-local product-design draft — editor state, version history and original image files not yet submitted | restoring the design after a reload; the data remains only in the customer's browser IndexedDB until save or order is requested | technical delivery of the product-design feature requested by the customer; the server does not receive the local draft by itself | rolling 30 days after last use, or earlier manual deletion or successful approval |
| Newsletter subscribers — email, optional name | launch and product news | Art. 6(1)(a) — consent with double opt-in | until consent is withdrawn (unsubscribe) |
| Marketing leads — data submitted on contact and signup forms | responding to enquiries | Art. 6(1)(a) — consent | until withdrawal, but no longer than 2 years after the last documented activity; unconfirmed subscriptions: 30 days |
4. Children's data — special care
Galleries largely contain photos of minors. A child's likeness is personal data requiring special care. Obtaining and keeping records of parental consent for taking and publishing the photos is the Photographer's responsibility. The platform provides built-in safeguards: password protection, email gate, scheduled access and expiry, watermarking, right-click protection and search engine exclusion (noindex).
5. Recipients
| Recipient | Role | Location / safeguard |
|---|---|---|
| Google Ireland Ltd. (Google Drive) | Google Drive-based photo storage, protected previews and order folders | Ireland (EU); US transfers: EU-US Data Privacy Framework + SCC |
| Sand Dune Mail Ltd. (SMTP2GO) | transactional, confirmation and — with consent — newsletter emails | 96-106 Manchester Street, Christchurch 8011, New Zealand (EU adequacy decision); according to the provider's notice, EEA users' personal data is stored in the EEA. Privacy · Sub-processors |
| Barion Payment Zrt. / OTP Mobil Kft. (SimplePay) | card payments via the Photographer's own account | Hungary (EU) |
| Stripe Payments Europe Ltd. | card payments via the Photographer's own account | Ireland (EU); US transfers: EU-US DPF + SCC |
| KBOSS.hu Kft. (Számlázz.hu) / Billingo Technologies Zrt. | invoicing in the Photographer's name via their own account | Hungary (EU) |
| Newsletter provider selected by the Photographer (MailerLite, Mailchimp, Brevo, ActiveCampaign or Klaviyo) | syncing the Photographer's own subscribers, only when the Photographer enables the integration | the Photographer selects and connects the provider with their own account; that provider's privacy terms apply |
| Cloudflare, Inc. | CDN, DDoS protection, DNS | USA — certified under the EU-US Data Privacy Framework |
| Hostinger International Ltd. | server infrastructure (VPS) | provider seated in Cyprus (EU); VPS data centre in Frankfurt, Germany (EU) |
6. Third-country transfers
Data is primarily stored and processed within the EU or EEA. Where providers or their sub-processors transfer data to a third country — notably the USA or New Zealand — transfers rely on Chapter V GDPR safeguards: adequacy decisions (EU-US Data Privacy Framework; New Zealand adequacy) or, where no adequacy decision applies, the Commission's Standard Contractual Clauses (SCC).
7. Security measures
- TLS/HTTPS everywhere;
- API keys and access tokens stored encrypted (AES-256-GCM);
- passwords hashed with bcrypt;
- tenant-level access separation — every photographer sees only their own data;
- time-limited, unique download tokens (30 days);
- httpOnly, secure session cookies; gallery access cookies contain no passwords;
- daily automated database backups retained for 14 days, plus a backup before each version deployment.
8. Data subject rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21) and withdrawal of consent (Art. 7(3)). Requests are received at doboimre86@gmail.com and answered within 1 month (Art. 12). Requests concerning customer or child data controlled by a Photographer are forwarded to the Photographer, and we assist in fulfilling them.
9. Remedies
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH) — Falk Miksa utca 9-11., 1055 Budapest, Hungary; postal address: 1363 Budapest, Pf. 9.; email: ugyfelszolgalat@naih.hu; web: www.naih.hu
- You may also bring the case before a court — at your choice, the regional court of your place of residence (Act CXII of 2011, Section 23; Art. 79 GDPR).
10. Final provisions
This notice is effective from 26 August 2026 (v1.1). Updates are published on this page; registered photographers are notified of material changes by email. Cookie use is described in the separate Cookie notice.
Internal AI assistant
The internal assistant uses Ollama Cloud. Messages and relevant account data may be transmitted to this provider. Képesbolt logs conversations and actions for platform administrators; logs currently have no fixed automatic expiry. Read the AI information page for data flows, history, human review and contact information.
This document applies to the Képesbolt platform. Purchases made in a gallery are governed by the legal documents of the Photographer operating that gallery.