Privacy Policy
Last updated: TODO
Data controller
TODO: identity and contact details of the data controller (name, registered address, email, EU representative if applicable).
Data we collect
- Account: email, name (Article 6(1)(b) GDPR — performance of contract)
- Orders: shipping address, order items, attestation timestamp (Article 6(1)(b))
- Payment: handled by Stripe — we never see card numbers
- Newsletter: email (Article 6(1)(a) — consent)
- Site analytics: only with cookie consent (Article 6(1)(a))
Your rights
Access, rectification, erasure, restriction, portability, and objection per GDPR Articles 15–22. Contact: TODO email. Hungarian users may also lodge a complaint with NAIH (naih.hu).
TODO: complete after legal review — retention schedule, sub-processors list, international transfer mechanism (SCCs), cookie inventory.