← Back to the home page
Privacy Policy

Privacy Policy

Last updated: June 16, 2026

This Privacy Policy (the “Policy”) describes how Brizz processes personal data when you visit the website (the “Website”), contact us, book an appointment, and use our services.

Our data processing complies with Regulation (EU) 2016/679 of the European Union (General Data Protection Regulation, “GDPR”), the applicable Hungarian data protection laws, and, where applicable to the data subject, the privacy laws of certain US states (e.g., the California CCPA/CPRA).

Please read this Policy carefully. If you have any questions about any part of it, you can contact us using the contact details below.

1. The data controller

The controller of the data (the “Data Controller” or “we”):

  • Name: Brizz marketing agency
  • Email: info@brizz.hu
  • Phone: +36 20 250 3808
  • Registered office: Budapest, Hungary
  • Website: https://brizz.hu

Data Protection Officer (DPO): under Article 37 of the GDPR, the Data Controller is not required to appoint a data protection officer and has not appointed one. For data protection matters, you can reach us at info@brizz.hu.

2. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Data subject: the natural person whose personal data we process.
  • Data processing: any operation performed on personal data (e.g., collection, storage, use, transfer, erasure).
  • Data controller: the party that determines the purposes and means of the data processing.
  • Data processor: the party that processes personal data on behalf of the Data Controller.
  • Consent: a freely given, specific, informed, and unambiguous indication of the data subject’s wishes.
  • Special category data: data requiring enhanced protection under Article 9 of the GDPR (e.g., health data). We do not process such data on a regular basis.

3. What data we process, for what purposes, and on what legal basis

Below we describe each of our data processing activities, the scope of the data processed, the legal basis (Article 6 of the GDPR), and the retention period.

a) Contact (contact form / email)

  • Data processed: name, email address, (optionally) phone number, and the content of your message.
  • Purpose: responding to your inquiry and staying in contact with you.
  • Legal basis: the data subject’s consent [Article 6(1)(a) GDPR] and our legitimate interest in responding to the inquiry [Article 6(1)(f)].
  • Retention period: up to 1 year after the inquiry is closed, or until consent is withdrawn.

b) Appointment booking / consultation (Decode call)

  • Data processed: name, email address, phone number, company name, the date and time of the booking, and any other information you provide.
  • Purpose: organizing and conducting the consultation.
  • Legal basis: steps taken prior to entering into a contract and performance of the contract [Article 6(1)(b) GDPR].
  • Retention period: up to 1 year after the consultation, or for the duration of the client relationship.

c) Contracting and provision of services

  • Data processed: contact and billing details, contract data.
  • Purpose: concluding and performing the contract, staying in contact, and invoicing.
  • Legal basis: performance of the contract [Article 6(1)(b) GDPR] and compliance with a legal obligation [Article 6(1)(c)].
  • Retention period: accounting records are retained for 8 years under Section 169 of Act C of 2000 on Accounting.

d) Newsletter / marketing (if you subscribe)

  • Data processed: name, email address.
  • Purpose: sending newsletters and marketing messages.
  • Legal basis: the data subject’s explicit, freely given consent [Article 6(1)(a) GDPR], which can be withdrawn at any time free of charge (unsubscribe).
  • Retention period: until consent is withdrawn.

e) Operating the Website and logging

  • Data processed: IP address, browser and device data, technical logs of the visit.
  • Purpose: the secure and proper operation of the Website and the prevention of abuse.
  • Legal basis: the Data Controller’s legitimate interest [Article 6(1)(f) GDPR].
  • Retention period: up to 12 months, or until the investigation of a security incident is closed.

4. Cookies and similar technologies

Cookies are small text files that your browser stores on your device when you visit a website. Similar technologies include local storage (localStorage) and pixels.

The Website currently stores your language preference in your browser’s local storage (localStorage, “brizz-lang” key) so that it is displayed in your chosen language on your next visit. This is strictly necessary for the operation of the Website and is not used for tracking.

Categories of cookies

  • Strictly necessary cookies: required for the basic operation of the Website (e.g., language preference, security). Their legal basis is legitimate interest, and they may be used without consent.
  • Preference cookies: store your convenience settings (e.g., language).
  • Statistics / analytics cookies: we use Google Analytics (Google LLC) and Microsoft Clarity (Microsoft Corporation) to measure traffic and usage. These are placed only with your prior consent.
  • Marketing cookies: we do not currently use marketing cookies. If we introduce them in the future, they will also be placed only with your prior consent.

Consent and managing cookies

Non-essential (analytics) cookies are placed only with your prior, explicit consent, given through the cookie banner displayed when the Website loads, in accordance with the electronic communications (ePrivacy) rules. You can change or withdraw your consent at any time using the “Cookie settings” button at the bottom of the page.

You can also manage, restrict, or delete cookies in your browser settings. Please note that disabling strictly necessary cookies may cause certain features of the Website to malfunction.

The cookies we use and the data stored

  • Google Analytics (Google LLC): _ga, _ga_*, _gid – measuring traffic and usage; lifetime up to 2 years (_gid: 24 hours). Only with consent.
  • Microsoft Clarity (Microsoft Corporation): _clck, _clsk, CLID, ANONCHK, MR, MUID, SM – anonymous behavior analysis (heatmaps, session replay); lifetime up to 1 year. Only with consent.
  • brizz-lang (local storage / localStorage): remembers your chosen language; remains in your browser until deleted.
  • brizz-consent (local storage / localStorage): stores your cookie consent.

5. Recipients and data processors

We treat your personal data confidentially. Only those members of our staff who need access to perform their duties, and who are bound by confidentiality, have access to your data.

To provide our services, we use trusted data processors who act on our instructions and under contractual and data protection guarantees. The categories of data processors currently used:

  • Hosting and infrastructure provider: Google (Firebase Hosting) – Google LLC (USA) / Google Ireland Ltd.
  • Web analytics: Google Analytics – Google LLC (USA) and Microsoft Clarity – Microsoft Corporation (USA).
  • Appointment booking / calendar and email provider: Google (Google Workspace).

We may disclose data where required by law, or at the request of an authority or a court.

6. Transfers of data to third countries

Some of our service providers (e.g., hosting, analytics) operate outside the European Economic Area (EEA), for example in the United States. Where we transfer personal data to a third country, we do so only subject to the appropriate safeguards under Chapter V of the GDPR, in particular:

  • on the basis of an adequacy decision of the European Commission (e.g., the EU-U.S. Data Privacy Framework, where the provider is certified), or
  • by applying the standard contractual clauses (SCCs) adopted by the European Commission, with supplementary measures where necessary.

You can request information about the safeguards applied, as well as a copy of them, at info@brizz.hu.

7. Data security

We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, transfer, disclosure, erasure, or destruction (e.g., encrypted connection / HTTPS, access restrictions, regular backups).

Please note that data transmission over the internet is never entirely free of risk; we strive to provide the highest level of protection we can.

8. Rights of the data subject (EU / GDPR)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: you may request confirmation as to whether we process your data and, if so, a copy of it.
  • Right to rectification: you may request the correction of inaccurate data and the completion of incomplete data.
  • Right to erasure (“right to be forgotten”): under certain conditions, you may request the erasure of your data.
  • Right to restriction of processing: in certain cases, you may request that the processing be restricted.
  • Right to data portability: you may request, in a structured, machine-readable format, the data you have provided that we process by automated means on the basis of consent or a contract.
  • Right to object: you may object to processing based on legitimate interest, and you may object at any time to direct marketing.
  • Withdrawal of consent: you may withdraw your consent to consent-based processing at any time, free of charge (this does not affect the lawfulness of processing carried out before the withdrawal).
  • Automated decision-making: we do not make decisions based solely on automated processing that produce legal effects concerning you.

You can exercise your rights at info@brizz.hu. We will respond to your request without undue delay and in any event within 1 month (which may be extended by 2 months where justified). The information is provided free of charge.

9. Remedies and complaints

If you believe that our data processing infringes your rights, please contact us first at info@brizz.hu, and we will try to resolve the matter quickly.

You may also lodge a complaint with the supervisory authority:

  • the Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
  • Address: 1055 Budapest, Falk Miksa utca 9-11.
  • Postal address: 1363 Budapest, Pf. 9. (P.O. Box 9)
  • Phone: +36 (1) 391-1400
  • Email: ugyfelszolgalat@naih.hu
  • Website: www.naih.hu

If your rights are infringed, you may also bring the matter before a court; the action may also be brought before the regional court having jurisdiction over your place of residence or habitual residence.

10. Rights of US residents (CCPA/CPRA and other state laws)

This section applies to data subjects who reside in a US state that has a comprehensive privacy law, in particular California (CCPA, as amended by the CPRA), as well as Virginia, Colorado, Connecticut, Utah, Texas, and other states.

Categories of personal information collected (CCPA)

  • Identifiers (e.g., name, email address, phone number, IP address).
  • Customer records (e.g., company name, billing contact details).
  • Commercial information (e.g., services used).
  • Internet/network activity (e.g., interaction with the Website, where we use analytics).
  • Professional / employment-related information (e.g., job title, company).

The source of the data is primarily you directly (forms, email, booking), as well as automatic collection during your use of the Website. We process the data for the purposes described in Section 3 of this Policy.

We do not sell or “share” personal information

Within the meaning of the CCPA/CPRA, we do not sell or “share” your personal information, and we have not done so in the past 12 months.

Sensitive personal information

We do not collect or use sensitive personal information within the meaning of the CPRA, except for permitted purposes necessary for our operations.

Consumer rights

  • Right to know: you may request what personal information we have collected, from what sources, for what purposes, and with whom we have shared it.
  • Right to delete: you may request the deletion of the personal information collected about you (subject to statutory exceptions).
  • Right to correct: you may request the correction of inaccurate information.
  • Right to opt out of sale/sharing: since we do not sell or share data, this is currently not applicable.
  • Right to limit the use of sensitive information.
  • Non-discrimination: you will not be discriminated against for exercising your rights.
  • In certain states (e.g., Virginia, Colorado, Connecticut), you have the right to appeal if your request is denied.

How to exercise your rights

You may submit your request at info@brizz.hu. We will verify your identity by reasonable means. An authorized agent may also act on your behalf with appropriate proof of authorization. We will respond to your request within the time limit set by the applicable law (typically 45 days).

11. Children’s data

The Website and our services are not intended for children under 16 (under 13 in the United States), and we do not knowingly collect personal data from them. If we become aware that we are processing such data, we will delete it.

12. Changes to this Policy

We may update this Policy from time to time (e.g., due to changes in the law or new services). The current version is always available on the Website, with the “Last updated” date shown above. In the event of material changes, we will notify you in an appropriate manner.

13. Governing laws

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
  • Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Infotv.).
  • Act C of 2000 on Accounting.
  • Act CVIII of 2001 on Electronic Commerce Services (Eker. tv.).
  • Act C of 2003 on Electronic Communications (with respect to cookies / ePrivacy).
  • The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other state privacy laws.