Privacy Policy
Last updated: June 16, 2026
This Privacy Policy (the “Policy”) describes how Brizz processes personal data when you visit the website (the “Website”), contact us, book an appointment, and use our services.
Our data processing complies with Regulation (EU) 2016/679 of the European Union (General Data Protection Regulation, “GDPR”), the applicable Hungarian data protection laws, and, where applicable to the data subject, the privacy laws of certain US states (e.g., the California CCPA/CPRA).
Please read this Policy carefully. If you have any questions about any part of it, you can contact us using the contact details below.
1. The data controller
The controller of the data (the “Data Controller” or “we”):
- Name: Brizz marketing agency
- Email: info@brizz.hu
- Phone: +36 20 250 3808
- Registered office: Budapest, Hungary
- Website: https://brizz.hu
Data Protection Officer (DPO): under Article 37 of the GDPR, the Data Controller is not required to appoint a data protection officer and has not appointed one. For data protection matters, you can reach us at info@brizz.hu.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Data subject: the natural person whose personal data we process.
- Data processing: any operation performed on personal data (e.g., collection, storage, use, transfer, erasure).
- Data controller: the party that determines the purposes and means of the data processing.
- Data processor: the party that processes personal data on behalf of the Data Controller.
- Consent: a freely given, specific, informed, and unambiguous indication of the data subject’s wishes.
- Special category data: data requiring enhanced protection under Article 9 of the GDPR (e.g., health data). We do not process such data on a regular basis.
3. What data we process, for what purposes, and on what legal basis
Below we describe each of our data processing activities, the scope of the data processed, the legal basis (Article 6 of the GDPR), and the retention period.
a) Contact (contact form / email)
- Data processed: name, email address, (optionally) phone number, and the content of your message.
- Purpose: responding to your inquiry and staying in contact with you.
- Legal basis: the data subject’s consent [Article 6(1)(a) GDPR] and our legitimate interest in responding to the inquiry [Article 6(1)(f)].
- Retention period: up to 1 year after the inquiry is closed, or until consent is withdrawn.
b) Appointment booking / consultation (Decode call)
- Data processed: name, email address, phone number, company name, the date and time of the booking, and any other information you provide.
- Purpose: organizing and conducting the consultation.
- Legal basis: steps taken prior to entering into a contract and performance of the contract [Article 6(1)(b) GDPR].
- Retention period: up to 1 year after the consultation, or for the duration of the client relationship.
c) Contracting and provision of services
- Data processed: contact and billing details, contract data.
- Purpose: concluding and performing the contract, staying in contact, and invoicing.
- Legal basis: performance of the contract [Article 6(1)(b) GDPR] and compliance with a legal obligation [Article 6(1)(c)].
- Retention period: accounting records are retained for 8 years under Section 169 of Act C of 2000 on Accounting.
d) Newsletter / marketing (if you subscribe)
- Data processed: name, email address.
- Purpose: sending newsletters and marketing messages.
- Legal basis: the data subject’s explicit, freely given consent [Article 6(1)(a) GDPR], which can be withdrawn at any time free of charge (unsubscribe).
- Retention period: until consent is withdrawn.
e) Operating the Website and logging
- Data processed: IP address, browser and device data, technical logs of the visit.
- Purpose: the secure and proper operation of the Website and the prevention of abuse.
- Legal basis: the Data Controller’s legitimate interest [Article 6(1)(f) GDPR].
- Retention period: up to 12 months, or until the investigation of a security incident is closed.
5. Recipients and data processors
We treat your personal data confidentially. Only those members of our staff who need access to perform their duties, and who are bound by confidentiality, have access to your data.
To provide our services, we use trusted data processors who act on our instructions and under contractual and data protection guarantees. The categories of data processors currently used:
- Hosting and infrastructure provider: Google (Firebase Hosting) – Google LLC (USA) / Google Ireland Ltd.
- Web analytics: Google Analytics – Google LLC (USA) and Microsoft Clarity – Microsoft Corporation (USA).
- Appointment booking / calendar and email provider: Google (Google Workspace).
We may disclose data where required by law, or at the request of an authority or a court.
6. Transfers of data to third countries
Some of our service providers (e.g., hosting, analytics) operate outside the European Economic Area (EEA), for example in the United States. Where we transfer personal data to a third country, we do so only subject to the appropriate safeguards under Chapter V of the GDPR, in particular:
- on the basis of an adequacy decision of the European Commission (e.g., the EU-U.S. Data Privacy Framework, where the provider is certified), or
- by applying the standard contractual clauses (SCCs) adopted by the European Commission, with supplementary measures where necessary.
You can request information about the safeguards applied, as well as a copy of them, at info@brizz.hu.
7. Data security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, transfer, disclosure, erasure, or destruction (e.g., encrypted connection / HTTPS, access restrictions, regular backups).
Please note that data transmission over the internet is never entirely free of risk; we strive to provide the highest level of protection we can.
8. Rights of the data subject (EU / GDPR)
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: you may request confirmation as to whether we process your data and, if so, a copy of it.
- Right to rectification: you may request the correction of inaccurate data and the completion of incomplete data.
- Right to erasure (“right to be forgotten”): under certain conditions, you may request the erasure of your data.
- Right to restriction of processing: in certain cases, you may request that the processing be restricted.
- Right to data portability: you may request, in a structured, machine-readable format, the data you have provided that we process by automated means on the basis of consent or a contract.
- Right to object: you may object to processing based on legitimate interest, and you may object at any time to direct marketing.
- Withdrawal of consent: you may withdraw your consent to consent-based processing at any time, free of charge (this does not affect the lawfulness of processing carried out before the withdrawal).
- Automated decision-making: we do not make decisions based solely on automated processing that produce legal effects concerning you.
You can exercise your rights at info@brizz.hu. We will respond to your request without undue delay and in any event within 1 month (which may be extended by 2 months where justified). The information is provided free of charge.
9. Remedies and complaints
If you believe that our data processing infringes your rights, please contact us first at info@brizz.hu, and we will try to resolve the matter quickly.
You may also lodge a complaint with the supervisory authority:
- the Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9-11.
- Postal address: 1363 Budapest, Pf. 9. (P.O. Box 9)
- Phone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
- Website: www.naih.hu
If your rights are infringed, you may also bring the matter before a court; the action may also be brought before the regional court having jurisdiction over your place of residence or habitual residence.
10. Rights of US residents (CCPA/CPRA and other state laws)
This section applies to data subjects who reside in a US state that has a comprehensive privacy law, in particular California (CCPA, as amended by the CPRA), as well as Virginia, Colorado, Connecticut, Utah, Texas, and other states.
Categories of personal information collected (CCPA)
- Identifiers (e.g., name, email address, phone number, IP address).
- Customer records (e.g., company name, billing contact details).
- Commercial information (e.g., services used).
- Internet/network activity (e.g., interaction with the Website, where we use analytics).
- Professional / employment-related information (e.g., job title, company).
The source of the data is primarily you directly (forms, email, booking), as well as automatic collection during your use of the Website. We process the data for the purposes described in Section 3 of this Policy.
We do not sell or “share” personal information
Within the meaning of the CCPA/CPRA, we do not sell or “share” your personal information, and we have not done so in the past 12 months.
Sensitive personal information
We do not collect or use sensitive personal information within the meaning of the CPRA, except for permitted purposes necessary for our operations.
Consumer rights
- Right to know: you may request what personal information we have collected, from what sources, for what purposes, and with whom we have shared it.
- Right to delete: you may request the deletion of the personal information collected about you (subject to statutory exceptions).
- Right to correct: you may request the correction of inaccurate information.
- Right to opt out of sale/sharing: since we do not sell or share data, this is currently not applicable.
- Right to limit the use of sensitive information.
- Non-discrimination: you will not be discriminated against for exercising your rights.
- In certain states (e.g., Virginia, Colorado, Connecticut), you have the right to appeal if your request is denied.
How to exercise your rights
You may submit your request at info@brizz.hu. We will verify your identity by reasonable means. An authorized agent may also act on your behalf with appropriate proof of authorization. We will respond to your request within the time limit set by the applicable law (typically 45 days).
11. Children’s data
The Website and our services are not intended for children under 16 (under 13 in the United States), and we do not knowingly collect personal data from them. If we become aware that we are processing such data, we will delete it.
12. Changes to this Policy
We may update this Policy from time to time (e.g., due to changes in the law or new services). The current version is always available on the Website, with the “Last updated” date shown above. In the event of material changes, we will notify you in an appropriate manner.
13. Governing laws
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
- Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Infotv.).
- Act C of 2000 on Accounting.
- Act CVIII of 2001 on Electronic Commerce Services (Eker. tv.).
- Act C of 2003 on Electronic Communications (with respect to cookies / ePrivacy).
- The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other state privacy laws.