This Privacy Policy (the "Policy") informs you about the personal data processing activities carried out in connection with the operation of the TaxEZ web-based application (the "Service") and the taxez.hu website (the "Website"), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR") and Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (the "Infotv."). This document is an informal English translation prepared for the convenience of non-Hungarian-speaking users. In the event of any discrepancy, the Hungarian-language version shall prevail and shall be the legally binding document.
| Company name/Name of sole trader | Mate Svecz │ TaxEZ |
|---|---|
| Registered seat / correspondence address | 7 Tamasi Aron street, Kalocsa, 6300 Hungary |
| Registration number | 62667696 |
| Tax number | 92276390-1-23 |
| E-mail contact | info@taxez.hu |
| Data protection contact | mate.svecz@taxez.hu |
(hereinafter: the "Data Controller" or "Service Provider")
Terms used in this Policy (personal data, processing, controller, processor, data subject, consent, personal data breach, etc.) have the meaning set out in Article 4 of the GDPR.
The Data Controller processes personal data lawfully, fairly and transparently, for specified purposes, to the extent and for the period necessary for those purposes, and with security measures ensuring appropriate confidentiality and integrity.
Data processed: e-mail address and password (stored exclusively in secure, encrypted/hashed form).
Purpose: to provide access to the Service, to identify the User account, and for technical communication necessary to provide the Service.
Legal basis: Article 6(1)(b) GDPR — performance of a contract with the Client, or steps taken prior to entering into a contract at the Client's request.
Retention period: for the duration of the User account, and for up to 30 days following termination of the contract (for technical deactivation and archiving purposes), or for as long as necessary to enforce legal claims, or as required by law.
How passwords are handled: the User account is created by the Data Controller and is assigned a system-generated, single-use default password, sent to the Client at the e-mail address provided at registration. The Client must change this password to a password known only to itself immediately after first login. The password — in every state, including the default password — is stored in the Data Controller's systems exclusively using one-way encryption (hashed form); it is never stored in readable form and cannot subsequently be decrypted by the Data Controller.
Data processed: data voluntarily provided by the prospective Client (e.g. name, e-mail address, company name, message content) when contacting erdeklodes@taxez.hu or requesting a demonstration.
Purpose: to respond to inquiries, present the Service, and prepare for contract conclusion.
Legal basis: Article 6(1)(b) GDPR (pre-contractual steps) or, where no contract is concluded, Article 6(1)(f) GDPR (legitimate interest in responding to business inquiries).
Retention period: 1 year following the closure of the inquiry, unless a contract is concluded.
Data processed: the Client's (as a business entity) invoicing name, registered seat/billing address, tax number, and the name and e-mail address of its contact person, where provided.
Purpose: to invoice the Service fee and comply with accounting and tax obligations.
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation, pursuant to the record-keeping rules of Act C of 2000 on Accounting and Act CXXVII of 2007 on Value Added Tax.
Retention period: 13 (thirhteen) years from the date of issue, in accordance with statutory accounting record-retention obligations.
Invoices are issued through the Számlázz.hu platform, with KBOSS.hu Kereskedelmi és Szolgáltató Kft. (registered seat: 1031 Budapest, Záhony utca 7., Hungary; company registration number: 01-09-303201; tax number: 13421739-2-41) acting as data processor.
Data processed: data technically recorded when using the Service (e.g. login timestamps, IP address, error messages, log entries).
Purpose: to ensure the secure operation of the Service, to prevent and detect unauthorised access or misuse, and to troubleshoot technical issues.
Legal basis: Article 6(1)(f) GDPR (legitimate interest in IT security).
Retention period: up to 12 months from the date of logging, unless a longer period is required to investigate a security incident.
5.1. Certain Modules of the Service access the Client's invoicing data, or publicly available data in the HTA or EU VIES systems (e.g. tax number verification), on the Client's behalf and instructions, through the Client's own technical user registered with the HTA Online Invoice system.
5.2. In this context, the Data Controller acts as the Client's data processor: the Client is the data controller with respect to the personal data of its own customers, partners, or natural persons named on invoices issued or received. The Data Controller processes such data solely on the Client's instructions, to the extent necessary to provide the Service, and does not use it for its own purposes.
5.3. The Data Controller and the Client may enter into a separate Data Processing Agreement, in accordance with applicable law, setting out in detail the processor activity described in this section.
| Processor | Activity | Contact details |
|---|---|---|
| Rackforest Zrt. | Hosting and server operation | 1132 Budapest, Victor Hugo utca 11., 5th floor, B05001, Hungary; tax number: 14671858-2-41 |
| KBOSS.hu Kft. (Számlázz.hu) | Invoicing service | 1031 Budapest, Záhony utca 7., Hungary; company registration number: 01-09-303201; tax number: 13421739-2-41 |
In addition to the processors listed above, the Data Controller uses the following third-party services for the operation of the Website, which may transmit technical data (e.g. IP address) between the browser and the relevant server: Google Fonts (Google Ireland Limited) for typefaces, and the cdnjs.cloudflare.com content delivery network operated by Cloudflare, Inc. for loading the Font Awesome icon set. Use of these services is technically necessary for the Website to display correctly.
The Data Controller primarily processes personal data within the European Economic Area (EEA). The third-party font and icon providers referred to in Section 6 operate global content delivery networks, which may involve technical data transfers outside the European Union. These providers act in accordance with applicable data protection law, including GDPR transfer mechanisms. The Data Controller does not transfer Clients' data provided in connection with the Service (e-mail address, password, invoicing data) to third countries.
8.1. The Website may use browser-based, strictly necessary local storage to remember display preferences (e.g. dark/light mode), which is not capable of tracking the user outside the Website and does not serve marketing or analytics purposes.
8.2. The Website does not currently use marketing, analytics, or third-party tracking cookies. Should the Data Controller introduce such technologies in the future, this Policy will be updated accordingly and, where required by law, prior user consent will be requested.
Under Articles 15–22 GDPR, data subjects may exercise the following rights by contacting info@taxez.hu:
The Data Controller will respond to requests without undue delay, and in any event within 1 month of receipt; this period may be extended by a further 2 months where necessary, taking into account the complexity of the request, with the data subject informed accordingly.
If a data subject believes the Data Controller has infringed applicable data protection law, they may lodge a complaint with the following supervisory authority or bring proceedings before a court:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Data subjects may also seek judicial remedy; such proceedings fall within the jurisdiction of the regional court (törvényszék) and may be brought before the court competent for the data subject's place of residence or habitual stay, at the data subject's choice.
The Data Controller applies appropriate technical and organisational measures to protect personal data — in particular passwords — including storing passwords in an irreversible (hashed) form, using encrypted (HTTPS) connections, restricting access on a need-to-know basis, and relying on the physical and IT security measures provided by its hosting provider.
In the event of a personal data breach (e.g. unauthorised access or data loss), the Data Controller acts in accordance with Articles 33–34 GDPR, notifying NAIH within 72 hours where required, and informing affected data subjects where the breach is likely to result in a high risk to their rights and freedoms.
The Data Controller reserves the right to unilaterally amend this Policy, in particular in the event of legislative changes or an expansion of the Service. The current version is always available on the Website; in the case of material changes, the Data Controller will also notify data subjects by e-mail.
This Privacy Policy enters into force on 10 August 2026 and supersedes all prior versions.