Privacy notice
1. Purpose and scope of this notice
This privacy notice explains how Gábor Fleck (hereinafter: the Controller) processes the personal data of visitors to the botanique.pro website (hereinafter: the Website) and of those who make contact via the Website.
The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR) and the applicable Hungarian legislation.
2. The Controller’s details
Controller: Gábor Fleck, private individual
Website: botanique.pro
Data protection contact: hello@botanique.pro
The Controller has not appointed a data protection officer, as it is not required to do so given the nature and scope of the processing carried out.
3. Source of the data processed
Personal data come directly from the data subject when the data subject uses the contact form, sends an email, or sets their cookie choice. When the Website is used, certain technical data are transmitted automatically by the visitor’s browser and device to the providers that ensure the operation and security of the Website and — where consent is given — the measurement of its traffic.
4. Making contact
4.1. Data processed
When the contact form is used, the Controller processes the following data:
- name;
- email address;
- the subject of the enquiry;
- the content of the message;
- the time of submission;
- technical data necessary for the secure operation of the form.
The checkbox on the contact form serves to confirm that the data subject has read this notice. The checkbox is not for marketing purposes and is not a general consent to data processing.
Please do not include special categories of personal data in your message — such as health data, or information concerning religious or political beliefs, or sex life or sexual orientation — nor data relating to other persons unless it is strictly necessary for the enquiry.
4.2. Purpose of the processing
The purpose of the processing is to receive, understand and answer the enquiry, to maintain the necessary contact, and to prepare any collaboration or other legal relationship.
4.3. Legal basis for the processing
- Where the enquiry is aimed at preparing a contract or collaboration entered into at the data subject’s request, the legal basis is Article 6(1)(b) GDPR: taking steps prior to entering into a contract.
- For other general, professional, press or information-seeking enquiries, the legal basis is Article 6(1)(f) GDPR: the Controller’s legitimate interest in receiving and answering the enquiries it receives.
Processing based on legitimate interest does not entail a disproportionate interference with the rights and freedoms of the data subject, since the processing is initiated by the data subject and the Controller uses only the data necessary to reply and to maintain contact.
4.4. Whether providing the data is necessary
Providing the name, email address, subject and message is necessary for the Controller to identify and answer the enquiry. Without these data the form cannot be submitted and a reply cannot be ensured.
4.5. Retention period
The Controller retains the data relating to the enquiry for a maximum of 12 months from the closure of the matter and then erases them, unless further retention is necessary for the performance of a concluded contract, for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims. In such cases the data may be retained for as long as necessary for the relevant purpose.
5. Operation and security of the Website
5.1. Technical and log data
When the Website is accessed, technical data may be processed for the operation of the hosting, content-delivery and security infrastructure, in particular:
- IP address;
- the time of the request and of access;
- the address of the page or resource opened;
- browser and device information;
- referring page;
- data relating to security events and errors.
The purpose of the processing is to make the Website available, to maintain network and IT security, to detect and prevent abuse and automated attacks, and to investigate technical errors.
The legal basis for the processing is Article 6(1)(f) GDPR: the Controller’s legitimate interest in operating the Website securely and reliably.
The technical and security data are retained by the Controller and by the provider of the infrastructure only for as long as necessary to provide the service, to handle security events and to prevent abuse. The specific retention period depends on the type of data, the nature of the security event and the provider’s technical settings.
5.2. Cloudflare Turnstile
The contact form is protected against automated submissions and abuse by Cloudflare Turnstile. To this end, the service may process the technical data strictly necessary for the check — such as the IP address, browser and device characteristics, and the result of the security check. Turnstile does not have access to the name, email address or message entered in the form fields.
The purpose of the processing is to protect the security of the form and the Website, and its legal basis is legitimate interest under Article 6(1)(f) GDPR. The processing necessary for the operation of Turnstile may not be used for marketing or profiling purposes.
6. Traffic measurement – Google Analytics 4
The Website uses Google Analytics 4 to understand traffic and usage in aggregate. Google Analytics loads only if the visitor has given prior consent to this in the cookie settings.
6.1. Categories of data processed
The service may process, among others, the following data:
- online identifiers and cookie identifiers;
- device, browser and operating-system data;
- pages viewed, visit and interaction data;
- the time and duration of the visit;
- referring page;
- approximate geographic location;
- technical and location data derived from the IP address during transmission.
The Controller does not send Google Analytics any name, email address or data entered in the contact form fields.
6.2. Purpose and legal basis
The purpose of the processing is to produce aggregate traffic statistics, to understand how the Website is used, and to improve the content and the user experience.
The legal basis for the processing is consent under Article 6(1)(a) GDPR. Refusing consent does not restrict the use of the Website’s basic functions.
6.3. Data protection limitations
The Google Analytics settings apply the following limitations:
- Google Signals is switched off;
- no remarketing or ad personalisation;
- no own user identifier (User ID);
- the Controller does not carry out individual visitor profiling;
- data sharing with Google products is limited to the minimum necessary for operation;
- the retention period for user- and event-level data is set to 2 months.
The aggregate reports of Google Analytics may, even after the user- and event-level retention period has expired, contain statistical data from which the data subject cannot be directly identified.
6.4. Withdrawing consent
The visitor may withdraw or change their consent at any time via the Cookie settings available on the Website. Withdrawal does not affect the lawfulness of processing carried out before withdrawal on the basis of valid consent.
7. Cookie settings
The Website may use, without consent, the technical solutions strictly necessary for its operation, as well as the setting that stores the visitor’s cookie choice. Analytics cookies and similar technologies are activated only after prior consent.
A detailed list of the cookies, their purpose and their lifetime is set out in the separate Cookie notice.
8. Processors and recipients
8.1. Cloudflare
Provider: Cloudflare, Inc.
Registered office: 101 Townsend Street, San Francisco, California 94107, USA
Role: infrastructure relating to domain-name management, hosting and content delivery, network and IT security, Turnstile spam protection, server-side processing of the contact form and forwarding of the message by email.
Cloudflare processes the technical data necessary to provide the service, and the message data during form forwarding, on the Controller’s instructions. Turnstile on its own does not have access to the content of the form fields.
Privacy information: Cloudflare Privacy Policy
8.2. Zoho Mail
Provider in the European Union: Zoho Corporation B.V.
Registered office: Beneluxlaan 4 B, 3527 HT Utrecht, The Netherlands
Role: receiving, transmitting and storing email messages in the Controller’s Zoho Mail account.
The Controller uses a Zoho account assigned to the European data centre region.
Privacy information: Zoho Privacy Policy
8.3. Google Analytics
Provider in the European Economic Area: Google Ireland Limited
Registered office: Gordon House, Barrow Street, Dublin 4, Ireland
Role: where consent is given, measuring the Website’s traffic with Google Analytics 4.
Privacy information: Google Privacy Policy
The Controller transfers personal data to other recipients only where it has an appropriate legal basis for doing so, or where the transfer is required by law or by an official or court order.
9. Transfers outside the European Economic Area
Cloudflare, Zoho and Google operate international infrastructure. In connection with certain services or support functions, personal data may also be processed in countries outside the European Economic Area.
Such transfers take place on the basis of the applicable adequacy decisions, the EU–US Data Privacy Framework where applicable, the standard contractual clauses adopted by the European Commission, and, where necessary, supplementary technical and organisational measures.
The data subject may obtain further information about the transfer safeguards applied in the providers’ privacy documents, or from the Controller at hello@botanique.pro.
10. Rights of the data subject
Under the conditions of the GDPR, the data subject has the right to:
- request information about the processing of their personal data;
- request access to the personal data processed and a copy thereof;
- request the rectification of inaccurate data and the completion of incomplete data;
- request the erasure of their personal data;
- request the restriction of processing;
- withdraw their consent at any time;
- object, on grounds relating to their particular situation, to processing based on legitimate interest;
- request data portability where the applicable conditions are met;
- lodge a complaint with the supervisory authority;
- seek a judicial remedy.
The fulfilment of requests relating to erasure, restriction and other data-subject rights may be limited by statutory exceptions, for example where the retention of the data is necessary for compliance with a legal obligation or for the enforcement of a legal claim.
The Controller does not carry out decision-making based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them.
11. Submitting data-subject requests
The data subject may submit their request to hello@botanique.pro. The Controller answers the request without undue delay, as a rule within one month of receipt. Where necessary — under the conditions of the GDPR — this period may be extended by a further two months; the Controller provides information about the extension and its reasons within one month.
Where the Controller has reasonable doubts about the identity of the person submitting the request, it may request additional, proportionate information necessary to confirm identity.
12. Complaints and remedies
If the data subject considers that the processing of their personal data infringes data protection rules, they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Email: ugyfelszolgalat@naih.hu
Website: naih.hu
The data subject is also entitled to bring the matter before a court. The proceedings may — at the data subject’s choice — also be brought before the regional court of the data subject’s place of residence or stay.
13. Data security
The Controller applies technical and organisational measures proportionate to the risk of the personal data processed, against unauthorised access, alteration, disclosure, transfer, erasure, loss or damage of the data. This includes in particular encrypted data transmission, restriction of access, appropriate protection of accounts, spam and abuse protection, and regular review of the providers’ settings.
14. Changes to this notice
The Controller may amend this notice if the Website’s functions, the processing practices, the providers or the legal environment change. The version in force at any given time is available on the Website, with the effective and update dates shown at the beginning of the document.