Privacy Policy

Last updated: September 3, 2026

1. Identity and Contact Details of the Data Controller

The devduo.eu website (the Website) is operated under the DEV DUO brand name by the sole trader identified below, who qualifies as the data controller within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR) in respect of all processing carried out through the Website:

Name: József Tar, sole trader (egyéni vállalkozó)
Registered seat: Zápolya utca 16. 1. a., 2120 Dunakeszi, Hungary
Tax number: 91621728-1-33
Registration number: 61558557
Registering authority: Ministry of the Interior of Hungary, register of sole traders
E-mail: jozsef@devduo.eu
Website: https://devduo.eu

DEV DUO is not a separate legal entity; it is a brand name used by the sole trader identified above. At the hajnalka@devduo.eu address shown on the Website, Hajnalka Maró acts as a contributor, in the name and on behalf of the data controller; responsibility for the processing lies with the data controller identified above.

For any data protection matter, or to exercise your rights as a data subject, the controller can be reached at jozsef@devduo.eu or by post at the address above.

2. Purpose and Scope of This Notice

This notice has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information.

It covers visits to the Website, use of the contact form available on the Website, e-mail correspondence with the controller, and the contractual relationship with clients. It does not cover the processing carried out by external websites linked from the Website (for example LinkedIn).

3. Data Protection Officer

Under Article 37 GDPR the controller is not required to designate a data protection officer and has not designated one. Data protection matters can be raised directly with the controller using the contact details in Section 1.

4.1. Contact Form

Data processed: the name, e-mail address, selected subject of the enquiry, the message text and any further information you voluntarily include in the message.

Purpose: receiving and answering your enquiry, preparing quotations, and conducting pre-contractual discussions.

Legal basis: Article 6(1)(b) GDPR, namely steps taken at your request prior to entering into a contract. Where an enquiry is not aimed at concluding a contract, the legal basis is the legitimate interest under Article 6(1)(f) GDPR in responding to business enquiries addressed to the controller.

Storage: form submissions are not stored in a separate database. When the form is submitted, the data is delivered as an e-mail message to the controller's mailbox and is stored there.

Retention: if no contract results from the enquiry, the data is deleted 1 year after the last substantive contact. If a contract is concluded, the retention periods in Section 4.3 apply. At your request we delete the data earlier, unless retention is required by law.

4.2. E-mail and Social Media Correspondence

Data processed: e-mail address, the name and signature given in the message, and the content of the correspondence.

Purpose: answering enquiries, keeping in contact, preparing quotations.

Legal basis: Article 6(1)(b) GDPR (pre-contractual steps or performance of a contract), or failing that the legitimate interest under Article 6(1)(f) GDPR in handling incoming enquiries.

Retention: correspondence is kept for 1 year after the last substantive contact, or for the periods set out in Section 4.3 where a contractual relationship exists.

The controller maintains a LinkedIn profile. Processing carried out on the LinkedIn platform is the responsibility of LinkedIn Ireland Unlimited Company as an independent controller; if you contact us via LinkedIn, that platform's own privacy notice also applies.

4.3. Client Contracts and Invoicing

Data processed: the client's name, billing name and address, tax number, contact e-mail address and phone number, the content of the contract, and data relating to performance and payment.

Purpose: concluding and performing the contract, accounting for fees, issuing invoices, and pursuing or defending legal claims.

Legal basis: Article 6(1)(b) GDPR for the performance of the contract; Article 6(1)(c) GDPR (legal obligation) for compliance with accounting and tax obligations.

Retention: accounting records are retained for 8 years under Section 169(2) of Hungarian Act C of 2000 on Accounting. Contractual documentation and related correspondence are retained for 5 years from termination of the contract, corresponding to the general limitation period under the Hungarian Civil Code.

4.4. Technical Log Data (Server Logs)

For the Website to function, the hosting provider's systems automatically log the technical details of visits.

Data processed: the device's IP address, the time of the request, the page requested, the HTTP response code, the browser and operating system type (user agent), and the referring page.

Purpose: ensuring the secure and uninterrupted operation of the Website, and detecting and remedying malfunctions and abuse (such as automated attacks).

Legal basis: the legitimate interest under Article 6(1)(f) GDPR in the operational security of the Website and the protection of the IT system. The controller has assessed this legitimate interest and concluded that the processing is proportionate to the rights of data subjects, as the data involved is minimal and is not used for profiling or for identifying individuals.

Retention: log files are stored in the hosting provider's systems, typically for no more than 30 days, after which they are deleted automatically. The controller accesses this data only on an ad hoc basis for troubleshooting.

5. Cookies and Browser Storage

The Website does not use analytics, statistical, marketing or advertising cookies, and does not employ any web analytics service (such as Google Analytics), social media pixel or advertising tracker.

The Website stores nothing in your browser at all: it uses no cookies and places no entries in your browser's local or session storage. The display language is determined by the page address (URL), which requires no storage of any kind.

Should we introduce analytics or marketing cookies in the future, we would use them only on the basis of your prior, informed consent, provide a consent management interface, and update this notice in advance.

6. Processors and Recipients of Personal Data

The controller does not sell or rent personal data and discloses it to third parties only through the processors listed below, to the extent necessary to provide the service. Processors may process the data only on the controller's documented instructions and may not use it for their own purposes. A data processing agreement under Article 28 GDPR is in place with each processor.

Hosting and operation of the Website:
Vercel Inc. (440 N Barranca Ave #4133, Covina, CA 91723, United States)
Data processed: technical log data necessary to serve the Website, and contact form data at the moment of e-mail transmission.

E-mail delivery service (forwarding contact form messages):
Resend, Inc. (2093 Philadelphia Pike #1919, Claymont, DE 19703, United States)
Data processed: the name, e-mail address, subject and message submitted through the form, together with technical delivery data.

E-mail mailbox service (the @devduo.eu addresses):
Zoho Corporation B.V. (Beneluxlaan 4B, 3527 HT Utrecht, Netherlands)
Data processed: the full content of incoming and outgoing correspondence, and sender and recipient details.

In addition, personal data may be disclosed to the controller's accountant for the fulfilment of accounting obligations, and to competent authorities (such as the tax authority, courts or investigating authorities) where required by law. In the latter case the controller discloses only the data necessary and specified in the request.

7. Transfers to Third Countries

Of the processors listed in Section 6, Vercel Inc. and Resend, Inc. are established in the United States, so using their services involves a transfer of personal data outside the European Union, to a third country.

These transfers take place with the safeguards required by Chapter V GDPR: on the basis of the European Commission's adequacy decision of 10 July 2023 concerning the EU–US Data Privacy Framework, or, where a given provider is not certified under that framework, on the basis of the Standard Contractual Clauses adopted by the European Commission, together with supplementary technical and organisational measures.

Zoho Corporation B.V. is established in the European Union (Netherlands); the controller uses the e-mail service through its European Union data centre.

Further information about the safeguards applied, and a copy of the Standard Contractual Clauses, may be requested using the contact details in Section 1.

8. Data Security Measures

In accordance with Article 32 GDPR, the controller applies technical and organisational measures appropriate to the level of risk in order to protect personal data. These include in particular:

  • serving the Website and all data transmitted through it over an encrypted channel (HTTPS/TLS)
  • protecting e-mail mailboxes with strong passwords and two-factor authentication (2FA)
  • restricting access to personal data to those who genuinely need it to perform a given task
  • imposing confidentiality obligations on contributors
  • keeping provider systems up to date and applying security updates
  • assessing the data security guarantees offered by processors when selecting them

9. Your Rights as a Data Subject

Under Chapter III GDPR you have the following rights in connection with the processing of your personal data:

  • Right of access (Article 15 GDPR): you may request confirmation of whether we process your personal data and, if so, obtain a copy of the data processed together with information on the purposes, legal basis, recipients and retention period.
  • Right to rectification (Article 16 GDPR): you may request the correction of inaccurate data and the completion of incomplete data.
  • Right to erasure (Article 17 GDPR): you may request the deletion of your data where processing is no longer necessary, where you have objected to the processing, or where the processing is unlawful. Erasure cannot be requested for data whose retention is required by law (for example accounting records).
  • Right to restriction of processing (Article 18 GDPR): you may request the restriction of processing, for example where you contest the accuracy of the data, for the period needed to verify it.
  • Right to data portability (Article 20 GDPR): you may receive the data you provided that is processed by automated means on the basis of consent or a contract, in a structured, commonly used, machine-readable format, and may request its transmission to another controller.
  • Right to object (Article 21 GDPR): you may object to processing based on legitimate interests. In that case the controller may no longer process the data unless it demonstrates compelling legitimate grounds which override your interests.
  • Right to withdraw consent (Article 7(3) GDPR): where processing is based on consent, you may withdraw it at any time without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

10. How Requests Are Handled

You may submit your request to the e-mail or postal address given in Section 1. Submitting a request is free of charge.

The controller will inform you of the action taken without undue delay and in any event within 1 month of receipt of the request. That period may be extended by a further 2 months where necessary, taking into account the complexity and number of requests, and the controller will inform you of any such extension within 1 month of receipt of the request.

Where the controller has reasonable doubts concerning the identity of the person making the request, it may request additional information necessary to confirm your identity. The sole purpose of this is to prevent personal data from being disclosed to an unauthorised person.

If the controller does not take action on your request, it will inform you without delay and at the latest within 1 month of the reasons, and of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.

11. Remedies

If you believe that the processing of your personal data infringes the applicable rules, we encourage you to contact the controller first; we investigate all reports without delay.

Independently of this, you may lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: https://naih.hu

You may also bring an action before the courts. Such cases fall within the competence of the regional courts (törvényszék) and, at your choice, may be brought before the regional court of your place of residence or stay. The court deals with such cases as a matter of priority.

12. Automated Decision-Making and Profiling

The controller does not carry out automated decision-making or profiling on the basis of personal data, including automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning the data subject or similarly significantly affects them.

13. Nature of the Data Provision

Completing the contact form and providing your data is voluntary; it is neither required by law nor a contractual obligation. Providing the data is, however, a precondition of contact: without it we cannot respond to your enquiry. Where a contract is concluded, providing the data required for invoicing is a statutory obligation, and without it the contract cannot be performed.

14. Handling of Data Breaches

In the event of a personal data breach, the controller will notify the Hungarian National Authority for Data Protection and Freedom of Information without undue delay and in any event within 72 hours, unless the breach is unlikely to result in a risk to the rights of data subjects. Where the breach is likely to result in a high risk, the data subjects concerned will also be informed directly and without delay. The controller maintains a record of all data breaches.

15. Children's Data

The services offered on the Website are intended for business clients and are not directed at persons under the age of 16. The controller does not knowingly collect personal data from persons under 16. If we become aware that we hold such data, we delete it without delay.

16. Changes to This Notice

The controller reserves the right to amend this notice unilaterally, in particular in the event of changes in legislation or changes to the services or the processors engaged. The version in force at any given time is available on the Website, showing the date of the last amendment. In the case of material changes, current clients will also be notified by e-mail.

17. Contact

For any question, request or complaint concerning the processing of personal data, please contact us at:
József Tar, sole trader
Zápolya utca 16. 1. a., 2120 Dunakeszi, Hungary
E-mail: jozsef@devduo.eu, hajnalka@devduo.eu